<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/hacking"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Hacking ]]></title>
                <link>https://www.itpro.com/uk/security/hacking</link>
        <description><![CDATA[ All the latest hacking content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 28 May 2026 11:14:08 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Hackers are turning up at law firms to gain physical access to machines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/hackers-are-turning-up-at-law-firms-to-gain-physical-access-to-machines</link>
                                                                            <description>
                            <![CDATA[ The FBI is warning companies to look out for fake IT staff ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RRTUidymkRvpRbyDRqH3Vg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 May 2026 11:14:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:description>                                                            <media:text><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:text>
                                <media:title type="plain"><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers posing as IT experts are showing up in person at law firms, the FBI has <a href="https://www.ic3.gov/CSA/2026/260526.pdf">warned</a>.</p><p>In the past, the Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, sent <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing emails</a> purportedly charging small 'subscription fees'. To cancel the fake subscription, the victim was instructed to call the threat actor, who then emailed the victim a link to download remote access software.</p><p>Now, though, the group is using phone calls and phishing emails to pose as IT support, gaining access to the victims' computers and exfiltrating data. </p><p>And while this is often done through legitimate <a href="https://www.itpro.com/mobile/remote-access/368050/best-free-remote-desktop-software-2023">remote access tools</a>, the group has also been sending individuals in person to the victim company's location to gain physical access to machines.</p><p>"This is a pretty natural evolution of extortion operations. We spent years building detections around <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> and exploits, and now attackers are shifting toward social engineering, trusted tooling, and physical access," commented Gabrielle Hempel, security operations strategist at Exabeam. </p><p>"Physical security fell by the wayside when organizations began to move their data to the cloud, but if your security model assumes that the threat actor is always on the other side of the internet, you have a problem." </p><p>The group's first step is to either directly call or send phishing emails urging employees to call 'IT support'. While on the phone, the SRG actor directs the employee to grant access to a remote desktop session. </p><p>If that attempt fails, though, SRG sends a threat actor to the victim's location to gain access and insert a storage device into the victim's computer. The hacker tells the victim they need to image the device or create a <a href="https://www.itpro.com/backup/29847/best-free-backup-software">backup file</a> to address potential impacts from the phishing email.</p><p>Once they've got access to the victim's device, they minimally escalate privileges and quickly pivot to data exfiltration without encryption, using Windows Secure Copy ( WinSCP) or a hidden or renamed version of 'Rclone'.</p><p>"SRG actors use the exfiltrated victim data to extort the victim by sending a ransom email threatening to sell or post the data online," the FBI said. "SRG actors also call employees or clients of a victim company to pressure the victim to begin ransom negotiations." </p><p>While SRG has hit companies in a number of sectors, including the insurance, finance, and healthcare industries, it's consistently been targeting US-based law firms since spring 2023.</p><p>"The group is leaning into trust by posing as IT support, walking employees through remote access, then moving quickly to steal data before anyone realizes something is wrong," warned Nick Tausek, lead security automation architect at Swimlane.</p><p>"That makes this especially dangerous for law firms. These environments hold sensitive client records, privileged communications, financial details, and case information. If that data is stolen, the damage does not stop at the victim organization. Clients can be pressured, legal strategies can be exposed, and employees can become targets for follow-up scams."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data was likely leaked in council hack  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/data-was-likely-leaked-in-council-hack</link>
                                                                            <description>
                            <![CDATA[ London council warns data was copied in last week's attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ouPui3pjeP7t4etqeeYNy9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qZBigH5tvnCwcpAuByckU8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 01 Dec 2025 10:48:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qZBigH5tvnCwcpAuByckU8-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking on keyboard]]></media:description>                                                            <media:text><![CDATA[Hacking on keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking on keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qZBigH5tvnCwcpAuByckU8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A London council is warning residents that their data may have been leaked following a cyber attack last week. </p><p>The Royal Borough of Kensington and Chelsea (RBKC) was one of<a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u> three councils knocked partially offline temporarily</u></a> last Monday, alongside neighbouring Hammersmith and Fulham and Westminster City Council. </p><p>RBKC has now confirmed that it's spotted a data breach as a result of last week's hacking attack, with the other councils working to discover if that's the case for their residents too. </p><p>"We have now obtained evidence on our systems that shows some data has been copied and then taken away," the RBKC council said in a <a href="https://www.rbkc.gov.uk/newsroom/we-are-responding-cyber-security-issue"><u>statement</u></a>. "At this moment in time, we believe the breach only impacts historical data."</p><p>The council added: "It is important to say we still have access to this information, it has not been stolen, but it is possible it could end up in the public domain. As a priority we are checking if this contains any personal or financial details of residents, customers, and service users — but this will take some time."</p><p>Westminster <a href="https://www.westminster.gov.uk/news/cyber-security-incident-friday-28-november-update"><u>said</u></a> it was investigating with a team of specialists to determine if any data was taken, while Hammersmith and Fulham Council was examining if data was copied from its records, in particular information dating from 2006 to 2020. </p><h2 id="old-data-is-still-a-risk">Old data is still a risk</h2><p>The National Cyber Security Centre (NCSC) has warned that any residents or service users of those councils should be "extra vigilant" when called, emailed or sent text messages purporting to be from one of the three impacted authorities. </p><p>Indeed, Keven Knight, CEO of Talion, said hackers can still wreak plenty of havoc using older data.  </p><p>"It doesn’t matter how old the data is; some of it will still be relevant and could put citizens and employees at risk," he said in a statement sent to <em>ITPro.</em></p><p>"The data held by councils will often relate to personal information, such as home addresses, emails, full names, dates of birth and financial information," Knight added. "This is the type of information that can’t be changed easily. This means it's now in the hands of a threat actor, and victims will be exposed to an increased risk of phishing."</p><p>He also warned that criminals could try to use the breach to scam residents. "This could be malicious communications around the breach, where they try to encourage victims to disclose more sensitive information or ask them to click on links or open attachments," he said. "As a result, all correspondence around the incident must be treated with caution."</p><p>The RBKC added: "We are working with the Met Police and crime agencies on an investigation, in an effort to establish who did this, why, and if at all possible, bring them to justice."</p><h2 id="shared-services-shared-outage">Shared services, shared outage</h2><p>RBKC first spotted the attack on Monday, and it appears as though the two neighbouring councils were impacted because they share some IT services. </p><p>"We detected a cybersecurity incident affecting shared IT systems used by Westminster City Council, the Royal Borough of Kensington and Chelsea, and the London Borough of Hammersmith and Fulham," noted a <a href="https://www.westminster.gov.uk/news/cyber-security-incident-friday-28-november-update"><u>statement on the Westminster website</u></a>. "Immediate steps were taken to contain the issue and protect our systems."</p><p>Hammersmith and Fulham Council said <a href="https://www.lbhf.gov.uk/news/2025/11/it-update"><u>in a statement on its website</u></a> that some online systems remained unavailable, but stressed there was no evidence its systems had been compromised and that any impact was "due to a cybersecurity incident in a neighbouring borough." </p><p>Westminster added that it may take several weeks "to return to full business as usual". However, it noted that most services are up and running, though there may be delays accessing some services. RBKC said it expects at least two weeks of "significant disruption" but was opening in-person customer service at Kensington Town Hall for emergency assistance.</p><h2 id="hackney-not-hacked">Hackney not hacked</h2><p>Hackney Council has denied it was also hit by the hacking attack that hit those west London councils, contrary to some media reports. </p><p>"Hackney Council is unaffected by the cyber attack that is reported to be affecting some councils in London," the spokesperson said in a <a href="https://news.hackney.gov.uk/news/hackney-council-unaffected-by-cyber-incident"><u>statement on the Hackney Council website</u></a>. "Media reports suggesting otherwise are mistaken."</p><p>Hackney will be keen to assure residents that it hasn't been affected in this round of attacks after the council was hit by a <a href="https://www.itpro.com/security/357405/hackney-council-services-disrupted-months-cyber-attack"><u>serious ransomware incident in 2020</u></a> that also led to a <a href="https://www.itpro.com/security/hacking/358256/hackers-publish-hackney-council-data-online-after-2020-attack"><u>data breach</u></a>, which saw it reprimanded by the Information Commissioner's Office. </p><p>Hammersmith and Fulham <a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u>said earlier this year</u></a> that it was seeing 20,000 attempted attacks every day, while the <a href="https://www.itpro.com/security/cyber-attacks/hammersmith-and-fulham-council-cyber-attacks"><u>Information Commissioner's Office said</u></a> attempts against local authority systems were up by 58% between 2022 and 2023. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacking is not a crime, criminal activity is ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/hacking-is-not-a-crime-criminal-activity-is</link>
                                                                            <description>
                            <![CDATA[ We need to be clearer about the difference between hacking and cyber crime ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">saKVTXTYP5inzDkkfgE5Ma</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/v274Th96q48snC6N7CoQVo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Nov 2023 12:06:55 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Nov 2023 15:05:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/v274Th96q48snC6N7CoQVo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A black and white hand outstretched, beneath five white asterisks representing a hacker seizing a password. Both are set against a solid  red background.]]></media:description>                                                            <media:text><![CDATA[A black and white hand outstretched, beneath five white asterisks representing a hacker seizing a password. Both are set against a solid  red background.]]></media:text>
                                <media:title type="plain"><![CDATA[A black and white hand outstretched, beneath five white asterisks representing a hacker seizing a password. Both are set against a solid  red background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/v274Th96q48snC6N7CoQVo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>I started my cyber security career not as a writer, but as a hacker in the truest sense of the word. In the late 1980s and early 1990s I explored other people’s networks for educational, rather than criminal, reasons. I was keen to learn about the emerging online world and for me, hands-on experience was how I could do that most effectively.</p><p>Certainly, I strayed into the darker shades of grey when it came to my virtual travels, but I never set out to do harm or steal. Fast-forward 35 years or so and for most people, in my experience, hacking often conjures up one of four visions:</p><ul><li>The hoodie-wearing teenager installing <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, stealing data (or draining bank balances), defacing sites in the name of political activism, or hitting services with <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>distributed denial of service (DDoS) attacks</u></a>.</li><li>Organized criminal gangs stealing data and/or extorting victims. <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>Ransomware</u></a> groups have become the focus of much of this attention today, but these are far from the only players in cyber crime.</li><li>State-sponsored actors involved in commercial/industrial/political espionage.</li><li>Law enforcement or government agencies carrying out surveillance or gathering information to build a case.</li></ul><p>This commonality here is criminality and harm, apart from the fourth example which often sits in a grey area. To be honest, people are more likely to refer to the agencies performing these activities as spooks or spies than hackers. </p><p>But for me, a hacker doesn’t neatly fit into any of these molds. Someone who drives a car could do so with harmful intent, such as escaping a robbery or harming pedestrians, but you wouldn’t label all drivers as criminals. So why should the same logic not apply to hackers? </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YbcC8yDvBUesBTFirmL6G4" name="230713-F-VS111-1805.png" caption="" alt="Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background." src="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Marc DeNofio / The Aerospace Corporation)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/why-space-force-wants-white-hats-to-attack-a-satellite" target="_blank">Why the Space Force wants white hats to attack a satellite</a></p></div></div><p>Some criminals hack, but not all hackers are criminals. Some hacking is harmful, but not all hackers cause harm. And some hackers, I would argue the vast majority in the 2020s, are highly skilled professionals and not criminals. Hacking is not a crime; criminal activity is a crime. Surely that’s not too hard to comprehend?</p><h2 id="why-does-it-matter-if-hacking-is-legal">Why does it matter if hacking is legal?</h2><p>Many people argue that these semantics don’t matter. But they are very wrong indeed. It matters how we describe hackers and hacking because that accepted public understanding of the terms informs a broader narrative that can have serious consequences. I’m not talking about feelings being hurt if someone on Facebook thinks you are a criminal rather than a skilled professional because you call yourself a hacker. This isn’t to belittle that hurt, as it can be very real within the cyber security profession where <a href="https://www.itpro.com/security/work-related-stress-keeps-cyber-security-professionals-awake-at-night"><u>stress levels are already through the roof</u></a>. </p><p>But for the purposes of this argument, I’m discussing issues that could impinge on an individual’s freedom in a worst-case scenario. The pejorative use of hacking has informed legal definitions and still does today. Let’s look at what the Crown Prosecution Service (CPS) has to say, shall we? In an <a href="https://www.cps.gov.uk/crime-info/cyber-online-crime"><u>explainer</u></a> that defines various types of cybercrime, the CPS states that:</p><p>“Hacking is the unauthorized use of or access into computers or networks by using security vulnerabilities or bypassing usual security steps to gain access. Criminals may hack systems or networks to steal money or information, or simply to disrupt businesses.”</p><p>Tell that to the security professionals who earn their living as <a href="https://www.itpro.com/security/should-your-business-start-a-bug-bounty-program">bug bounty</a> hunters, who provide a service to vendors and users alike by finding previously unknown security vulnerabilities. And by doing so, enable vendors to patch them before users can be targeted by the actual criminals. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zcgryVGkujpbfYJvspEN6b" name="Three ways to evolve your security operations_listing.jpg" caption="" alt="Red whitepaper cover with image of office building from the ground up" src="https://cdn.mos.cms.futurecdn.net/zcgryVGkujpbfYJvspEN6b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><em>Examine security operation modernization strategies and find out why your current security approach might not be working<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/three-ways-to-evolve-your-security-operations">DOWNLOAD NOW</a></p></div></div><p>While it’s fair to argue that those working as part of a vulnerability discovery platform will have authorized access from the vendors, this isn’t the case for those discovering and disclosing vulnerabilities outside of such platforms. Is their work any less valuable because they were not authorized to find a security problem that could have impacted, in many cases, millions of users? Is their work to be painted with the brush of criminality rather than portrayed as the good deed it actually is? </p><p>There are certainly hackers who disclose such vulnerabilities in the hope of gaining financial rewards, but the majority of people I know working outside of vendor-confirmed platforms do so because they are passionate about making software and services more secure. Financial reward is often a secondary <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets">motivation for hackers</a>.</p><p>All of this means the CPS definition would be far more accurate if it was preceded by one single word: criminal. Criminal hacking is all the things the CPS says. Hacking is demonized here unfairly. If I were to define the internet as being a place where criminals commit fraud without any further explanation, would that be acceptable? No, of course not. Yet the internet is used for those things by those groups, just as criminals use hacking for criminal activity. </p><h2 id="the-legal-threat-to-better-cyber-security">The legal threat to better cyber security</h2><p>Then there’s the <a href="https://www.itpro.com/it-legislation/28174/what-is-the-computer-misuse-act"><u>Computer Misuse Act (CMA 1990)</u></a>. As the date attached to it rightly suggests, this originated in a very different time in terms of the impact the online and digital world had upon every aspect of life, both at work and home. I have previously argued that the CMA is a product of an era before the World Wide Web and that the limitations it places on cyber security professionals could be causing harm.</p><p>In fairness, moves are underway to update the CMA with regard to a statutory legal defense for ‘<a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained"><u>ethical hacking</u></a>’. But these moves are incredibly slow and it is time for such potential amendments to be put to bed.</p><p>Casey Ellis is the founder of one of the biggest crowdsourced cybersecurity platforms, Bugcrowd, which incorporates both bug bounty platforms and <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing"><u>penetration-testing</u></a>-as-a-service. Ellis is concerned that the UK needs to mirror reforms around ethical hacking as has happened with the 1986 Computer Fraud and Abuse Act in the US. The deadline for submissions for anyone involved in the cybersecurity industry to add their views to the consultation process has now passed. Only time will tell if enough people have made a convincing argument to nudge the UK government into making changes. But a longer wait could be ahead if the snail’s pace at which the process has moved so far is anything to go by. </p><p>“Poor legal protection for ethical hackers could have the chilling effect whereby those who could contribute to making the internet a safer place become afraid to do so,” Ellis says as the consultation period draws to a close. “To be even clearer,” he continues, “people build software, people make mistakes, and mistakes create vulnerabilities. Amid the worldwide <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge"><u>shortage of skilled cyber security professionals</u></a>, Bugcrowd wants organizations and law enforcement to still benefit from ‘Neighborhood Watch for the internet’ by decriminalizing and encouraging anyone from the ethical hacking community to assist. </p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=53601829&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“Those ethical, well-meaning, and responsible researchers should not be put in a position where they may be at risk of legal jeopardy. The UK needs a revised Act that not only better defines the difference between the activities of malicious attackers who have no intent to obey the law in the first place and those who hack in good faith, discovering and disclosing vulnerabilities so they can be addressed before they are exploited.”</p><p>This illustrates just how important semantics, definitions, and words are when it comes to our understanding of hacking and the laws that apply to it. The CMA itself states that it exists to “make provision for securing computer material against unauthorized access or modification; and for connected purposes”. </p><p>This is as clear as mud and in effect makes the act of hacking the criminal offence, rather than acknowledging that malicious hacking and criminals that happen to hack are the real problems.</p><h2 id="valuable-examples-of-ethical-hacking-xa0">Valuable examples of ethical hacking </h2><p>Positive hacking tales show both the value of hacking and how hackers can be well rewarded for their efforts without embracing criminality. </p><p>The latest and, in purely financial terms, the greatest Pwn2Own Vancouver competition has been and gone. This global hacking event was a must-watch fixture in the diary for those looking to and many others since it all kicked off back in 2005. Organized by the Trend Micro Zero-Day Initiative, Pwn2Own gathers together some of the best hacking brains, both as individuals and teams, which then compete against the clock and each other to “pwn” a given target. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JC2YWbFc3zjKzcDQ7quFCj" name="GettyImages-1680279193-meta-crop.jpg" caption="" alt="The Meta logo (a stylized 'M' next to the word 'Meta) written in blue on a frosted glass window, with blue lights visible behind the glass." src="https://cdn.mos.cms.futurecdn.net/JC2YWbFc3zjKzcDQ7quFCj.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/meta-ditching-its-responsible-ai-team-doesnt-bode-well" target="_blank">Meta ditching its responsible AI team doesn&apos;t bode well</a></p></div></div><p>Pwn is slang meaning to utterly defeat an opponent or in hacking terms successfully attack a victim using a <a href="https://www.itpro.com/tag/zero-day-exploit"><u>zero-day exploit</u></a> to execute remote code, escalate privileges, or access a system that should remain inaccessible. The targets this year included the likes of Adobe, Apple, Microsoft, Oracle, Tesla, Ubuntu and VMware. It should be noted that there was nothing illicit about Pwn2Own as each year the targets sign up to be part of the event and authorize the hacking attempts within certain parameters. </p><p>Those who successfully execute a zero-day exploit against each target are rewarded both in cash and kudos. This year, the total amount of prize money awarded was $1,035,000. That was divided between a handful of hackers and hacking teams, one of which also walked away with a Tesla Model 3. The kudos element is by way of points awarded for each exploit that rack up until one team is crowned “Master of Pwn” at the end of the event. </p><p>This year, it was team Synacktiv that dominated Pwn2Own on both counts, winning $530,000 and winning the kudos title with 53 points. In second place, to put the Synacktiv success in some perspective, was the STAR Labs team with $195,000 and 19.5 points. </p><p>All of this goes to show why hacking is such a force for good. All the exploits and their underlying vulnerabilities were immediately disclosed to the vendors so that they could be patched. The full technical disclosures aren’t made public until such a time that those patches are available and users have had time to update their software and systems. </p><p><em>This content originally appeared on ITPro&apos;s sibling magazine PC Pro. For more information and to subscribe, please visit PC Pro&apos;s </em><a href="https://subscribe.pcpro.co.uk/"><em>subscription site</em></a><em>.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the Space Force wants white hats to attack a satellite ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/why-space-force-wants-white-hats-to-attack-a-satellite</link>
                                                                            <description>
                            <![CDATA[ Authorities hope the first-of-its-kind competition could bring benefits to the cyber sector ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GuKbKtQCqPMgNeEnKmeNqf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Nov 2023 07:00:21 +0000</pubDate>                                                                                                                                <updated>Wed, 08 Nov 2023 13:34:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ James O&#039;Malley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png">
                                                            <media:credit><![CDATA[Marc DeNofio / The Aerospace Corporation]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:description>                                                            <media:text><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[ Moonlighter satellite, a small cube-shaped craft with solar panel wings on either side, against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YbcC8yDvBUesBTFirmL6G4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A US space launch is a very high-security affair. Systems are locked down, many of the staff hold national security clearance, and the rocket and its payload are carefully protected.</p><p>But when SpaceX launched its CRS-28 resupply mission to the International Space Station (ISS) in June, it did so carrying a special satellite that the US military was actively encouraging people to hack.</p><p>Run by the US Space Force, Hack-a-Sat was essentially a game of Capture the Flag. Organizers tasked <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker"><u>ethical hackers</u></a> with flexing their skills to break into a satellite and discover a special code, in a race against four other competing teams. The military hopes that this will also help raise awareness around cyber threats to space hardware.</p><p>The diminutive 34 x 11 x 11cm “cube” satellite is named Moonlighter and was deployed into low Earth orbit after about a month aboard the ISS, and was the target in this year’s Hack-A-Sat competition.</p><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XwWCccN8DFYGdyRyZj9Eo3" name="GettyImages-1423513491-email-BEC-crop.jpg" caption="" alt="A CGI render of a white envelope being shot at from all directions by arrows with red-tips, to represent business email compromise (BEC)." src="https://cdn.mos.cms.futurecdn.net/XwWCccN8DFYGdyRyZj9Eo3.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec" target="_blank"><strong>What is Business Email Compromise (BEC)?</strong></a></p></div></div><p>The event brings skilled cyber enthusiasts together to build enthusiasm for careers in the sector and specifically attract raw talent to the field of cyber security for vital communications satellites. This could help protect government assets from a new generation of threat actors, and address the <a href="https://www.itpro.com/security/strain-of-cyber-skills-deficit-still-impacting-firms-despite-global-workforce-surge"><u>ongoing cyber skills deficit</u></a>.</p><p>“They started to go and ask all the different organizations within the government and military saying, ‘Hey, can you let these hackers, these top cybersecurity enthusiasts, go and hack into your systems?’, and their first response was, ‘Absolutely not. No way’,” says Captain Kevin Bernert, the Space Force’s Hack-A-Sat program manager.</p><p>But Captain Bernert’s team persisted. In the first few years, the competition was run on <a href="https://www.itpro.com/virtualisation/31628/what-is-server-virtualisation"><u>virtual machines (VMs)</u></a> down on Earth, or actual space hardware planted firmly on the ground. This year, Moonlighter was actually put orbit where it patiently waited to be hacked.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="koNvE9zmQFam7EYpnGTT9m" name="ThreatLabz Report_The state of encrypted attacks_listing.jfif.jpg" caption="" alt="Whitepaper cover with title over image of high rise buildings with red circular digital icons dotted around" src="https://cdn.mos.cms.futurecdn.net/koNvE9zmQFam7EYpnGTT9m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Discover how the encrypted threat landscape has changed over time<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-report-the-state-of-encrypted-attacks">DOWNLOAD NOW</a></p></div></div><p>It’s a real test for the competitors, as there are specific difficulties that we don’t need to deal with down on Earth. “With space vehicles orbiting the Earth at high speeds, you only have a certain amount of opportunities to make contact with that vehicle,” says Bernert. </p><p>Hackers trying to send a command package, for example, might not know if it was successfully executed until the next time they can make contact. Other challenges include limited <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth"><u>bandwidth</u></a> and tricky power management. Hackers must be careful about how much energy their code uses on a device powered by only a solar panel.</p><p>Would-be attackers also need to take into account complex orbital mechanics to establish a connection with their target. Other aspects of the competition will be more familiar.</p><p>“It&apos;s still essentially a computer,” says Bernert. “You still have to apply all the cyber security principles. Now, it&apos;s just in a more rigorous domain.”</p><h2 id="cyber-attack-innovation">Cyber attack innovation</h2><p>To communicate with the satellite in orbit, teams will use the same ground stations that are used for ordinary satellites. Moonlighter has been sandboxed so that even though the satellite is in space, nothing too dramatic can be compromised. </p><p>“It works just like any other satellite would work in Low Earth Orbit,” says Bernert. “We don&apos;t have a propulsion system on it, so they won&apos;t be able to just send it off into deep space or into the Earth&apos;s atmosphere.” The satellite also has a built-in “reset” button that the military can use to restore the sandbox to a blank slate.</p><p>The competition is as realistic as possible and the organizers urge teams to pick members who have skills in the different disciplines such a complex hacking task requires, including radio communications, exploit development, satellite operations. and astrophysics.</p><p>Bernert is confident that by tapping into this “untraditional” pool of individuals, the task can be solved in innovative ways. But even with the right people, winning the competition will require an effective strategy.</p><p>“We let the competitors get creative with how they want to go about denying or degrading their competitors&apos; satellites, but we also give them the opportunity to have game theory get involved,” says Bernert, describing how teams will have to choose between playing aggressively, to capture their opponents’ flags, or as in a real cyber-conflict, choosing to play more defensively to protect their own.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jcRn6x39ApowgWbrWX2wmA" name="GettyImages-1210827873-North Korea- Cyber.jpg" caption="" alt="A hooded figre standing in front of a digital version of the North Korean flag" src="https://cdn.mos.cms.futurecdn.net/jcRn6x39ApowgWbrWX2wmA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks" target="_blank"><strong>Should your business worry about North Korean cyber attacks?</strong></a></p></div></div><p>Even after the winners have been crowned and the Moonlighter satellite has been successfully compromised, the real-world stakes of the competition remain very much front of mind for those participating. Bernert’s hope, and that of Space Force, is that this can put <a href="https://www.itpro.com/security/cyber-attacks/ncsc-new-class-of-russian-cyber-attackers-seek-to-destroy-critical-infrastructure"><u>threats to critical infrastructure</u></a> in context.</p><iframe width="100%" height="200px" frameborder="0" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><p>“People are realising that it&apos;s not just limited to specific nations with large military budgets – it&apos;s becoming a lot more proliferated and more accessible to everybody,” he says. </p><p>“With that, obviously, comes the need to make sure that systems that are now being procured and launched in rapid quantities are cyber secure, because so much of our lives for pretty much everybody across the globe is tied directly to safe satellite vehicle operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two-thirds of ethical hackers using generative AI in bug hunting ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/two-thirds-of-ethical-hackers-using-generative-ai-in-bug-hunting</link>
                                                                            <description>
                            <![CDATA[ The report found that more and more ethical hackers are leveraging generative AI tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r6kka56sJ6635WR3q4vKjS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Oct 2023 13:06:16 +0000</pubDate>                                                                                                                                <updated>Mon, 30 Oct 2023 16:28:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is a staff writer at ITPro, ChannelPro, and CloudPro, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:description>                                                            <media:text><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:text>
                                <media:title type="plain"><![CDATA[lots of lime-coloured padlocks set against a green background, with one orange padlock in the middle that&#039;s unlocked]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zwqDDCyttCAQQ9fnt5F8rX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Generative AI tools are being used by a growing number of ethical hackers to support their work hunting for vulnerabilities, according to a new report.</p><p>A study from bug bounty platform HackerOne found that over half of ethical hackers participating in programs use <a href="https://www.itpro.com/technology/artificial-intelligence/are-we-in-the-middle-of-a-generative-ai-bubble">generative AI</a> in some capacity. </p><p>Nearly two-thirds (61%) said they are actively using and developing generative AI-based hacking tools in a bid to find more vulnerabilities, expand capabilities, and streamline efficiency. </p><p>The use of <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">generative AI tools</a> aren’t just limited to the technical aspects of bug hunting, HackerOne revealed. </p><p>Two-thirds (66%) of <a href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">ethical hackers</a> said they plan to use generative AI to write better reports while 53% said the technology is being used to support <a href="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference">writing code</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="m3oV8ZhyVSLVyjF7UJrPA9" name="m3oV8ZhyVSLVyjF7UJrPA9.jpg" caption="" alt="A close up shot of someone pressing a keyboard key on a laptop covered in blue and red lighting" src="https://cdn.mos.cms.futurecdn.net/m3oV8ZhyVSLVyjF7UJrPA9.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">What is ethical hacking? White hat hackers explained</a><a data-analytics-id="inline-link" href="https://www.itpro.com/hacking/32717/what-can-an-ethical-hacker-do-for-my-business">What can an ethical hacker do for my business?</a></p></div></div><p>One-third (33%) said generative AI is also being used to “reduce language barriers” for bug hunters. </p><p>Despite an appetite among ethical hackers to integrate generative AI tools within workflows, HackerOne’s study pointed to a lingering hesitancy among many with regard to long-term security risks. </p><p>More than one-quarter (28%) of hackers told the firm they were particularly concerned about criminal exploitation of generative AI tools while 18% held concerns over a potential increase in insecure code. </p><p>Nearly half (43%) of hackers said that generative AI could lead to an increase in vulnerabilities moving forward. </p><h2 id="generative-ai-llm-bug-hunting">Generative AI LLM bug hunting</h2><p>HackerOne’s study also revealed that 61% of program participants plan to specifically target vulnerabilities identified in the OWASP Top 10 flaws for <a href="https://www.itpro.com/technology/artificial-intelligence/openai-others-pushing-false-narratives-about-llms-says-databricks-cto">large language models</a> (LLMs).</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CZGRPmo3S5zynJBv3QLkjb" name="ThreatLabz State of Phishing Report_thumb.jfif.jpg" caption="" alt="Whitepaper cover with title over image of colleagues chatting in an office with red circular digital icons around them" src="https://cdn.mos.cms.futurecdn.net/CZGRPmo3S5zynJBv3QLkjb.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><em>Learn about the tactics used in phishing attacks and prevent costly data breaches from affecting your organization<br></em><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/threatlabz-2023-phishing-report">DOWNLOAD NOW</a></p></div></div><p>OWASP recently published its top ten vulnerabilities for LLM applications. The most common vulnerabilities identified included prompt injection, in which an attacker manipulates the operation of an LLM through specifically crafted inputs. </p><p>Generative AI-related supply chain vulnerabilities were also highlighted in the list. </p><p>OWASP has determined that the LLM supply chain has glaring vulnerabilities which have the potential to impact the “integrity of training data, machine learning (ML) models, and deployment platforms”.</p><p>“Supply chain vulnerabilities in LLMs can lead to biased outcomes, security breaches, and even complete system failures,” HackerOne said.</p><h2 id="record-payouts-for-bugs">Record payouts for bugs</h2><p>This news from HackerOne comes as the bug bounty platform announces a payout milestone for users.</p><p>The firm revealed that since its inception in 2012, it has paid out over $300 million in rewards to security researchers. The size of payouts have also been steadily rising in recent years, HackerOne said.</p><p>The median price of a bug on the HackerOne platform has now reached $500, marking an increase from $400 in 2022.</p><p>More than two dozen researchers have also been paid over $1 million in rewards, HackerOne said, with the largest payout of $4 million announced in August.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 100,000 hackers have details exposed through malware on cyber crime forums ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/more-than-100000-hackers-have-details-exposed-through-malware-on-cyber-crime-forums</link>
                                                                            <description>
                            <![CDATA[ Hackers accidentally falling foul of malware is becoming more common, researchers said ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WpjKSNd62FkMPuxb9wRPoZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/drDKL7xjbVTRfkTSEyMcXc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Aug 2023 10:31:30 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 15:07:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/drDKL7xjbVTRfkTSEyMcXc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers exposed: A multicoloured padlock on a dark background with fingerprints overlaid all ove rthe image, denoting identity and cyber security]]></media:description>                                                            <media:text><![CDATA[Hackers exposed: A multicoloured padlock on a dark background with fingerprints overlaid all ove rthe image, denoting identity and cyber security]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers exposed: A multicoloured padlock on a dark background with fingerprints overlaid all ove rthe image, denoting identity and cyber security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/drDKL7xjbVTRfkTSEyMcXc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have revealed that more than 100,000 hackers could be operating on compromised devices due to their involvement on cyber crime forums. </p><p>A study from Hudson Rock identified around 120,000 devices infected with malware that contained login credentials for cyber crime forums. </p><p>The firm said that many of the individuals operating with compromised machines may have inadvertently infected their devices with info-stealing <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, which led to their details being leaked. </p><p>Much of the information analyzed in the study was publicly available.</p><p>“Using Hudson Rock’s cyber crime intelligence database, which consists of over 14,500,000 computers infected by info-stealing malware, we analyzed 100 of the leading cyber crime forums,” the firm said. </p><p>“Researchers found that a staggering 120,000 infected computers, many of which belong to hackers, had credentials associated with cyber crime forums.”</p><p>Researchers said that hackers compromised through their involvement in cyber crime forums had a “substantial amount” of data exposed, which could point to their real-world identities. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRrgzsXGoa6Lpzkz6LcgbX" name="AI and cyber security_listing.jpg" caption="" alt="Purple whitepaper cover with white text over background image of suited female wearing glasses" src="https://cdn.mos.cms.futurecdn.net/LRrgzsXGoa6Lpzkz6LcgbX.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Understand why AI is crucial to cyber security, how it fits in, and its best use cases</em>.</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/ai-and-cyber-security">DOWNLOAD FOR FREE</a></p></div></div><p>Credentials found on infected devices included emails and usernames, as well as auto-fill data containing personal details such as names, addresses, and phone numbers. </p><p>System information, such as computer names and IP addresses, were also listed among the exposed information. </p><p>The “vast majority” of recorded info-stealer infections were attributed to RedLine, Raccoon, and Azorult, the study found. </p><h2 id="cyber-crime-forum-leaks">Cyber crime forum leaks</h2><p>A range of notorious cyber crime forums was analyzed in the study, with some offering a huge trove of leaked information on members. </p><p>The forum with the highest number of infected users was identified as ‘Nulled.to’, which accounted for more than 57,000 compromised users. </p><p>‘Cracked.io’ and ‘Hackforums.net’ were also found to have a high volume of compromised users operating on the sites. </p><p>This isn’t the first instance in which cyber criminals have inadvertently infected their own devices with malware, Hudson Rock revealed. Previous analysis from the firm found that, <a href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been"><u>prior to its takedown</u></a>, the popular RaidForums had more than 7,000 compromised users. </p><p>“It is not uncommon for hackers to accidentally get infected by info-stealers, just as employees of highly technical companies often do. For example, raidforums.com, a prominent cyber crime forum that was shut down by law enforcement has over 7,000 compromised users in Hudson Rock’s database, many of which are hackers.”</p><p>Research from the firm in July showcased a real-world example of this, detailing an incident in which a notable threat actor, dubbed ‘La_Citrix’, infected their own device. </p><p>The threat actor in question is known for selling access to company Citrix/VPN/RDP servers and leaking info-stealer logs from computer infections, the firm said. </p><p>This hacker was found to have been using their own personal computer in their activities, and their involvement in cyber crime forums had resulted in their information being exposed. </p><p>“Data from La_Citrix’s computer such as ‘Installed Software’ reveals the real identity of the hacker, his address, phone, and other incriminating evidence such as ‘qTox’, a prominent messenger used by <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> groups, being installed on the computer.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anonymous Sudan: Who are the hackers behind Microsoft’s cloud outages? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/anonymous-sudan-who-are-the-hackers-behind-microsofts-cloud-outages</link>
                                                                            <description>
                            <![CDATA[ The highly aggressive ‘hacktivist’ group is thought to have links to the pro-Russian Killnet hacker collective ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FJwYRMPhRvRKBEXGVbHC65</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7o5bTsgk2WQmvHemkMXts3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 19 Jun 2023 11:02:15 +0000</pubDate>                                                                                                                                <updated>Mon, 19 Jun 2023 15:59:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7o5bTsgk2WQmvHemkMXts3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anonymous Sudan: Stock photo of a hacker typing on keyboard in darkness]]></media:description>                                                            <media:text><![CDATA[Anonymous Sudan: Stock photo of a hacker typing on keyboard in darkness]]></media:text>
                                <media:title type="plain"><![CDATA[Anonymous Sudan: Stock photo of a hacker typing on keyboard in darkness]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7o5bTsgk2WQmvHemkMXts3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has revealed that threat actor group Anonymous Sudan was behind a recent spate of outages that affected cloud services earlier this month. </p><p>In an advisory published at the weekend, the tech giant revealed that a series of outages were caused by highly effective distributed denial of service (DDoS) attacks. </p><p>Azure, Outlook, and <a href="https://www.itpro.com/cloud/cloud-storage/367988/idrive-vs-onedrive"><u>OneDrive</u></a> customers were left in the dark for hours due to the incidents, prompting a rapid investigation by Microsoft’s threat analysts. </p><p>“Beginning in early June 2023, Microsoft identified surges in traffic against some services that temporarily impacted availability,” Microsoft said in its advisory. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bvmLpWwnDGsuH7nN6zDy2n" name="The right workload in the right cloud_listing.jpg" caption="" alt="Whitepaper cover with title over an image of a city with a lightning bolt shaped cloud above in the blue sky" src="https://cdn.mos.cms.futurecdn.net/bvmLpWwnDGsuH7nN6zDy2n.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The right workload in the right cloud</strong></p><p class="fancy-box__body-text"><em>A guide to multi-cloud management</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-management/the-right-workload-in-the-right-cloud"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Microsoft promptly opened an investigation and subsequently began tracking ongoing <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>DDoS</u></a> activity by the threat actor that Microsoft tracks as Storm-1359.”</p><p>Microsoft noted that, to date, it has seen no evidence that customer data has been accessed or compromised.</p><p>The investigation by Microsoft revealed that the attacks specifically targeted level 7 web traffic using a number of methods. These included cache bypass, slowloris, and HTTP(S) flood attacks.</p><p>The latter of these attacks, Microsoft explained, aims to exhaust system resources by leveraging a high volume of SSL/TLS ‘handshakes’ and HTTP(S) requests processing. </p><p>“In this case, the attacker sends a high load (in the millions) and HTTP(S) requests that are well distributed across the globe from different source IPs. This causes the application backend to run out of compute resources (CPU and memory),” Microsoft’s advisory read. </p><p>In response, Microsoft said it hardened layer 7 protections, including “tuning Azure Web Application Firewall (WAF) to better protect customers from the impact of similar DDoS attacks”.</p><h2 id="who-is-behind-anonymous-sudan">Who is behind Anonymous Sudan?</h2><p>Anonymous Sudan is one of the newcomers to the global threat landscape, having officially launched operations in January 2023, assembling on the <a href="https://www.itpro.com/security/cyber-security/364260/how-telegram-became-ukraine-digital-ally-russia-war"><u>Telegram</u></a> messaging platform according to security firm CyberCX. </p><p>CyberCX said the use of the Anonymous Sudan name was an “apparent reference to a 2019 operation by Anonymous”. </p><p>The group, which describes itself as a <a href="https://www.itpro.com/hacking/30203/what-is-hacktivism"><u>‘hacktivist’</u></a> organization has already gained notoriety through a series of major attacks. </p><p>In March, the group threatened to disrupt Melbourne Fashion Week shows, citing opposition to a clothing line that displayed the term ‘God walks with me’. </p><p>While this preceded a broader spate of attacks against Australian organizations, at the time the move against Melbourne Fashion Week suggested that the group may have had religious motivations. </p><p>The group is also behind an apparent attack on the European Investment Bank (EIB). Anonymous’ DDoS attack against EIB follows recent threats made against the bank. </p><p>EIB confirmed the attack in a statement via Twitter on 19 June, adding that the incident was affecting the availability of the EIB and EIF websites. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">We are currently facing a cyber attack which affects the availability of https://t.co/P3qatt3Uz5 and https://t.co/bGl0aO1Gwl. We are responding to the incident.<a href="https://twitter.com/EIB/status/1670783791600656384">June 19, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>At present, there is no clear-cut information on the scale or severity of the attack. However, security researcher Kevin Beaumont commented on Twitter that it has “absolutely no financial impact whatsoever”. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">For anybody wondering, it has absolutely no financial impact whatsoeverWhat Killnet and Anonymous Sudan tend to do is look at things like share price changes and market moves and link them to their actions incorrectlyEg they linked MSFT share price moves to DDoS. No real link<a href="https://twitter.com/GossiTheDog/status/1670774213383188480">June 19, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>“What Killnet and Anonymous Sudan tend to do is look at things like share price changes and market moves and link them to their actions incorrectly,” he said. “Eg they linked MSFT share price moves to DDoS. No real link.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9trkJWQXGPZq5ZryjQrwJB" name="GitOps and Shift Left security_thumb.jpg" caption="" alt="Whitepaper cover with title and logo over image of a female worker facing the camera, writing on a clear board in a meeting with colleagues sat behind her" src="https://cdn.mos.cms.futurecdn.net/9trkJWQXGPZq5ZryjQrwJB.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Walking the line: GitOps and Shift Left security</strong></p><p class="fancy-box__body-text"><em>Scalable, developer-centric supply chain security solutions</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/walking-the-line-gitops-and-shift-left-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>However, analysis by CyberCX suggests that the group is unlikely to be a legitimate hacktivist group. Similarly, the firm said that the group is unlikely to be geographically linked to Sudan itself. </p><p>“Anonymous Sudan has no known overlap with the original membership of the 2019 Sudan operation, which was anti-Russia and pro-Ukraine, and has been denounced by a prominent Anonymous account,” the firm said. </p><p>CyberCX said that, based on current assessments of the group’s operations, Anonymous Sudan is likely affiliated with the Russian state. </p><p>The group is publicly aligned with pro-Russian threat actors, and is known to be a member of the pro-Russian <a href="https://www.itpro.com/security/cyber-warfare/367859/russian-killnet-cyber-attacks-begin-on-italian-linked-businesses"><u>Killnet hacker collective</u></a>. </p><p>Observations of the group’s tradecraft also align with Russian-style tactics, CyberCX added, including the targeting of Western organizations in the government, healthcare, transport, and media sectors. </p><p>“CyberCX assesses that there is a real chance that Anonymous Sudan is affiliated with the Russian state,” the firm said. “Persistent low-level disruption of Western countries is consistent with established Russian information warfare strategies.”</p><p>“Anonymous Sudan also primarily posts in English and Russian, with its first Arabic post more than a month after its creation.”</p><p>Anonymous Sudan has been highly aggressive since emerging earlier this year, and CyberCX said it expects the group to continue ramping up operations in the months ahead. </p><p>“Anonymous Sudan is likely to continue to increase its tempo of operations over the next three months,” the firm said. “Anonymous Sudan now has more than 60,000 followers on its Telegram channel and reactions to its post have dramatically increased through May.”</p><p>“The group’s apparent access to significant resources and its dubious ideological associations means that it poses an atypical threat.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Barracuda Networks says hacked devices “must be immediately replaced” despite patches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/barracuda-networks-says-hacked-devices-must-be-immediately-replaced-despite-patches</link>
                                                                            <description>
                            <![CDATA[ Seven-month exploitation of a critical vulnerability enabled persistent backdoor access in its email security gateway devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vYfzzGT59nVwtY36bAxK9S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jun 2023 10:05:44 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 09:45:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:description>                                                            <media:text><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:text>
                                <media:title type="plain"><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A critical vulnerability in Barracuda Networks’ email security gateway (ESG) devices now means all devices must now be replaced.</p><p>The order came directly from the security company this week which said devices should be replaced regardless of whether the zero-day vulnerability was patched.</p><p>Barracuda updated its security advisory and also communicated the instruction to customers via the user interface of their ESG devices.</p><p>“Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG,” the company said. “Impacted ESG appliances must be immediately replaced regardless of patch version level.”</p><p>Barracuda has not offered any further description as to why the devices must be fully replaced, but it may be due to the malware installed after exploiting the vulnerability allowing for persistent backdoor access for attackers.</p><p>The firm, which has more than 200,000 customers globally, has been engaging affected clients since news of the vulnerability emerged in late May. </p><h2 id="barracuda-esg-vulnerability-what-happened">Barracuda ESG vulnerability - what happened?</h2><p>Last month, Barracuda said it detected “anomalous traffic” <a href="https://www.itpro.com/security/barracuda-network-appliance-vulnerability-actively-exploited-for-seven-months"><u>originating from its email security gateway appliances</u></a>. A subsequent investigation identified a critical vulnerability exploit, tracked as CVE-2023-28681, in the appliance. </p><p>Initially, the company issued a patch to remediate the vulnerability for all ESG appliances globally. A script was deployed to contain the incident and prevent unauthorized access methods, Barracuda said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kTsiQoiFtbpj9ToE5cqEQ" name="The (hard) key to stop phishing_listing.jpg" caption="" alt="Blue webinar screen with title and contributor images" src="https://cdn.mos.cms.futurecdn.net/kTsiQoiFtbpj9ToE5cqEQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The (hard) key to stop phishing</strong></p><p class="fancy-box__body-text"><em>How Cloudflare stopped a targeted attack and you can too</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-hard-key-to-stop-phishing"><strong>WATCH FOR FREE</strong></a></p></div></div><p>However, last week the company revealed that further analysis of the incident found the vulnerability had been actively exploited for several months before it was discovered and patched. </p><p>Barracuda said the “earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022”.</p><p>The vulnerability enabled threat actors to obtain “unauthorized access to a subset of ESG appliances”, it added. The company said that <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> was identified on a subset of appliances, offering would-be attackers persistent backdoor access. </p><p>Two particular malware strains were uncovered by Barracuda during its post-mortem analysis of the incident. </p><p>The first was SALTWATER, a “<a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>trojanized</u></a> module for the Barracuda SMTP daemon that contains backdoor functionality”. </p><p>The second malware strain, known as SEASPY, was also identified. SEASPY also offered attackers backdoor functionality with persistence, while disguising itself as a legitimate Barracuda Networks service. </p><p>No other Barracuda products, including its <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a> email security services, were affected by the vulnerability, Barracuda said. </p><p><em>ITPro </em>approached Barracuda Networks for comment on the latest update. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ No, Microsoft SharePoint isn’t cracking users’ passwords ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/no-microsoft-sharepoint-isnt-cracking-users-passwords</link>
                                                                            <description>
                            <![CDATA[ The discovery sparked concerns over potentially invasive antivirus scanning practices by Microsoft ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">K6kGumBxCtcKtVSpuz8shJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 May 2023 10:53:40 +0000</pubDate>                                                                                                                                <updated>Wed, 17 May 2023 13:04:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:description>                                                            <media:text><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft SharePoint logo displayed on a smartphone and Microsoft logo in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jEFkuVZwPpaoNN7CMiaP6n-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security professionals have raised concerns that Microsoft SharePoint appears to be ‘breaking into files’ and scanning users’ password-protected ZIP archives. </p><p>The discovery was made by Andrew Brandt, a principal security researcher at Sophos, after he found that files containing malware for research purposes were scanned by Microsoft’s 365 virus detection software. </p><p>Brandt outlined his claims in a Mastodon thread, revealing that several password-protected ZIP files had been flagged as ‘malware detected’ by <a href="https://www.itpro.com/security/antivirus/367785/best-business-antivirus"><u>antivirus software</u></a>. </p><p>Following the <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware </u></a>flag, Brandt noted that this “limits what I can do with those files - they are basically dead space now”. </p><p>“Apparently Microsoft SharePoint now has the ability to scan inside of password-protected ZIP archives,” he wrote. </p><p>“How do I know? Because I have a lot of ZIPs (encrypted with a password) that contain malware, and my typical method of sharing those is to upload those passworded ZIPs into a Sharepoint directory.</p><p>“This morning, I discovered that a couple of password-protected ZIPs are flagged as "Malware detected" which limits what I can do with those files - they are basically dead space now.”</p><p>The discovery sparked initial concerns that Microsoft is actively scanning password-protected files, raising concerns over security and privacy. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XLoUwV2iUi4cPwrDUKxR6k" name="Defence in depth_listing.jpg" caption="" alt="Whitepaper cover with title over purple shaded image of female worker peering over the top of an office cubicle" src="https://cdn.mos.cms.futurecdn.net/XLoUwV2iUi4cPwrDUKxR6k.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Defence in depth: Closing the gaps in Microsoft 365 security</strong></p><p class="fancy-box__body-text"><em>Exploring the security challenges facing organisations with a reliance on Microsoft 365</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/microsoft-office/356963/defence-in-depth-closing-the-gaps-in-microsoft-365-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>One user suggested that the practice is a reason why they’re “moving away from MS cloud” and that it crosses “ethics boundaries”. </p><p>“There is a bit of an ethics boundary being crossed here when they are starting to just break into files and archives under the guise of ‘security’ (which may just be used as a facade for them).”</p><p>In a reply on the <a href="https://infosec.exchange/@threatresearch/110373860063222707" target="_blank"><u>Mastodon thread</u></a>, Brandt noted that SharePoint uses a “word list” to check and potentially flag the content of files. </p><p>Given the password was ‘infected’ - a common archive password used in the cyber security community - SharePoint appears to have flagged this particular file. </p><p>“[SharePoint] says it uses a word list,” he said. “The password was ‘infected’ which is not in the least bit secure, but I hadn’t seen it poking around inside of passworded ZIPs before now, and was under the impression it wouldn’t do that.” </p><p>Brandt added that while this practice is understandable from a generalist perspective, for malware analysts in particular it could prove inhibitive. </p><p>“While I totally understand doing this for anyone other than a malware analyst, this kind of nosy, get-inside-your-business way of handling this is going to become a big problem for people like me who need to send their colleagues malware samples,” he said. </p><p>“The available space to do this just keeps shrinking and it will impact the ability of malware researchers to do their jobs.”</p><h2 id="file-scanning-practices">File scanning practices</h2><p>Although this has raised some concerns over the scanning of files, the practice is well-documented by Microsoft in an <a href="https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-malware-protection-for-spo-odfb-teams-about?view=o365-worldwide#what-happens-if-an-infected-file-is-uploaded-to-sharepoint-online" target="_blank"><u>explainer for its built-in antivirus protection</u></a> for SharePoint, OneDrive, and Microsoft Teams. </p><p>“The <a href="https://www.itpro.com/business-operations/productivity/368063/microsoft-365-vs-google-workspace"><u>Microsoft 365</u></a> virus detection engine scans files asynchronously (at some time after upload). If a file has not yet been scanned by the asynchronous virus detection process, and a user tries to download the file from the browser or from Teams, a scan on download is triggered by SharePoint before the download is allowed,” the explainer reads. </p><p>“All file types are not automatically scanned. Heuristics determine the files to scan. When a file is found to contain a virus, the file is flagged.” </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">So, Microsoft's scanner started detecting malware in password-protected ZIP archvies and people are losing their shit because they have no goddamn clue how anti-virus programs work.https://t.co/P0a5QFPrRXStrap in, kids, because I'm in a lecturing mood. Thread:<a href="https://twitter.com/VessOnSecurity/status/1658373432562597889">May 16, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>In a Twitter thread reacting to the news, Dr. Vesselin Vladimirov Bontchev (@‘VessOnSecurity’) said the practice isn’t quite as concerning as it seems. </p><p>“Scanners have been doing this since the ‘90s,” he wrote. “I think McAfee’s scanner was the first to try the password ‘infected’ if it encountered an <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption"><u>encrypted</u></a> ZIP archive.”</p><p>Bontchev pointed out that the practice of ‘protecting’ a ZIP archive potentially containing malware has traditionally been a tactic to improve safety and prevent unknowing users from downloading malicious software. </p><p>“The idea here is not secrecy. The idea is safety. These archives with malware are (or at least were) often sent by email from one researcher to another,” he explained. </p><p>“It&apos;s easy to mistype someone&apos;s email address and we wanted to make sure that if some random person, other than the intended recipient, received the malware by mistake, they wouldn&apos;t infect themselves by accidentally running it.”</p><p><em>ITPro</em> has approached Microsoft for comment on the matter. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nintendo hacker forced to pay company 25-30% of earnings for life ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/nintendo-hacker-forced-to-pay-company-25-30-of-earnings-for-life</link>
                                                                            <description>
                            <![CDATA[ Gary Bowser pled guilty to hacking charges in 2021 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CzJTMGJ6t7kd7HwAVyaGPi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ze9fCCRKvmJwzxgUKHeqkP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Apr 2023 10:35:58 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Apr 2023 12:14:03 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ze9fCCRKvmJwzxgUKHeqkP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Lego statue of Bowser from the Mario franchise looms over guests in a convention hall, with Bowser on the right of the frame and guests on the left. Behind them, a large sign reads &#039;amiibo&#039;, and a bright red wall carries the Nintendo Switch logo in white.]]></media:description>                                                            <media:text><![CDATA[A Lego statue of Bowser from the Mario franchise looms over guests in a convention hall, with Bowser on the right of the frame and guests on the left. Behind them, a large sign reads &#039;amiibo&#039;, and a bright red wall carries the Nintendo Switch logo in white.]]></media:text>
                                <media:title type="plain"><![CDATA[A Lego statue of Bowser from the Mario franchise looms over guests in a convention hall, with Bowser on the right of the frame and guests on the left. Behind them, a large sign reads &#039;amiibo&#039;, and a bright red wall carries the Nintendo Switch logo in white.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ze9fCCRKvmJwzxgUKHeqkP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>After serving a prison sentence, a former Nintendo hacker has been ordered to pay between 25-30% of his salary to the company for the rest of his working life.</p><p>Gary Bowser had previously been a key member of hacking group Team Xecuter which developed and sold chips that allowed pirated games to be played on various game consoles, including the Nintendo Switch, 3DS, and NES.</p><p>Nintendo pursued legal action against the group for damaging its business model. The firm has sought $10 million in damages from Bowser, 53, which he will now be forced to pay back through docked wages.</p><p>During the court proceedings, Bowser alleged that he had been the group’s “salesman” and earned a total of $320,000 from his Team Xecuter activities. </p><p>He owned the website MaxConsole, which at the time was being used to secretly advertise Team Xecuter products. </p><p>In 2021, Bowser pled guilty to two <a href="https://www.itpro.com/security/cyber-warfare/370379/uks-offensive-hacking-force-scale-operations-governments-request"><u>hacking</u></a> charges and acknowledged his participation in cyber criminal activity. </p><p>He was sentenced to 40 months in prison and told to pay $4.5 million by the judge, a separate fine from the settlement for Nintendo. </p><p>His early release has come as a result of good behavior while in prison, as well as in acknowledgment of time served while awaiting trial. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fH6a2vHv2sK7hBPF2aUo7k" name="Solving the cloud-native app puzzle with CNAPP_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/fH6a2vHv2sK7hBPF2aUo7k.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: TrendMicro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Solving the cloud-native app puzzle with CNAPP</strong></p><p class="fancy-box__body-text"><em>The value of integrating cloud-native application protection into security and development</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/solving-the-cloud-native-app-puzzle-with-cnapp"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>He is currently being held in a separate facility pending his transfer to Canada.</p><p>Bowser’s lawyer has claimed that his client lost 90lbs (40kg) in the time between his arrest and court appearance.</p><p>In court transcripts, first <a href="https://www.axios.com/2022/06/06/nintendo-hacker-court-transcript" target="_blank"><u>reported</u></a> by <em>Axios</em>, US District Judge Robert Lasnik stated that there was a “role to be played here in terms of a message” when it came to Bowser’s sentence.</p><p>“Nintendo appreciates the hard work and tireless efforts of federal prosecutors and law enforcement agencies to curb illegal activities on a global scale that cause serious harm to Nintendo and the video game industry,” the firm stated in a <a href="https://www.businesswire.com/news/home/20220210005971/en/Leader-of-Video-Game-Hacking-Group-Sentenced-to-40-Months" target="_blank"><u>press release</u></a> following the sentence in 2022.</p><p>Bowser <a href="https://www.youtube.com/watch?v=IGHDuYkdK7M" target="_blank"><u>told</u></a> YouTuber NckMoses05 that he has already paid $175 in $25 monthly payments, through his job at the federal prison in which he was incarcerated.</p><p>He also said that the $4.5 million will not have to be paid back once he is transferred back to his home country of Canada.</p><p>Commentators on the story are largely divided on Nintendo’s decision to pursue legal action against Bowser so heavily.</p><p>Some have argued that <a href="https://twitter.com/AjMurray21/status/1648611221778702337?cxt=HHwWgoC97fzKheEtAAAA" target="_blank"><u>it’s unjust</u></a> and that the move will condemn Bowser to a life of <a href="https://twitter.com/Vigilante_Blade/status/1648141659090067457" target="_blank"><u>“extreme poverty”</u></a>.</p><p>Others highlighted the fact that Team Xecuter has acted maliciously in the past not only to the companies which its piracy adversely impacts, but its users too, arguing that the group deserved such a punishment.</p><p>The group’s SX OS, <a href="https://www.itpro.com/business-operations/productivity/368060/top-10-best-free-software-for-small-businesses"><u>software</u></a> to allow pirated games to run on Nintendo Switch, included code that could render the owner’s console unusable forever if users operated outside the terms of its license.</p><p>While Bowser was extradited to the US from his then home the Dominican Republic, Louarn has not been extradited to date, and Chen remains unaccounted for.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">I wonder how many people know Gary Bowser, the guy Nintendo had arrested, was part of team xecuter, who are infamous for incredibly scummy business practices with their Switch modchips<a href="https://twitter.com/SCS_Shoug/status/1648384845448355850">April 18, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p><em>ITPro</em> has approached Nintendo for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK criminal records office suffers two-month "cyber security incident" ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/370400/uk-criminal-records-office-suffers-two-month-cyber-security-incident</link>
                                                                            <description>
                            <![CDATA[ ACRO was forced to shut its systems offline and security experts are suggesting ransomware may be involved ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eSB6DHRDyMumDod3CBBeL8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5qWnAs7TwRGBwhu4zWh4mk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Apr 2023 19:40:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5qWnAs7TwRGBwhu4zWh4mk-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two police officers wearing fluorescent jackets standing with their back to the camera]]></media:description>                                                            <media:text><![CDATA[Two police officers wearing fluorescent jackets standing with their back to the camera]]></media:text>
                                <media:title type="plain"><![CDATA[Two police officers wearing fluorescent jackets standing with their back to the camera]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5qWnAs7TwRGBwhu4zWh4mk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s national office for managing criminal record information (ACRO) has confirmed it’s currently trying to recover from a two-month “cyber security incident”.</p><p>Few details were revealed by the organisation and other authorities, other than that the attack took place between 17 January and 21 March 2023.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations" data-original-url="/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations">Rubrik confirms data breach but evades Cl0p ransomware allegations</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/370364/lazarus-blamed-3cx-attack-byte-to-byte-code-match-discovered" data-original-url="/security/malware/370364/lazarus-blamed-3cx-attack-byte-to-byte-code-match-discovered">Lazarus blamed for 3CX attack as byte-to-byte code match discovered</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/370369/western-digital-suffers-cyber-attack-shuts-down-systems" data-original-url="/security/cyber-attacks/370369/western-digital-suffers-cyber-attack-shuts-down-systems">Western Digital suffers cyber attack, shuts down systems</a></p></div></div><p>There is currently no evidence that personal data or payment information has been affected by the incident, ACRO told <em>ITPro</em>. </p><p>ACRO was forced to take its website offline on 21 March.</p><p>The same day, ACRO’s customer service Twitter account alerted customers that the outage was due to “essential website maintenance” and that online applications were unavailable.</p><p>The organisation has still not publicly alerted customers of a cyber security incident via official channels.</p><p>Some members of the cyber security industry have suggested the incident is related to a <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> attack.</p><p>Asked by <em>ITPro</em>, neither ACRO, the <a href="https://www.itpro.com/security/370303/ncsc-launches-free-browser-security-threat-checks-smbs" data-original-url="https://www.itpro.com/security/370303/ncsc-launches-free-browser-security-threat-checks-smbs">National Cyber Security Centre (NCSC)</a>, nor the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> commented on the involvement of ransomware. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1643615960916455424"></a></p></blockquote><div class="see-more__filter"></div></div><p>“We are aware of a cyber security incident affecting the ACRO Criminal Records Office website and are working with national agencies to fully investigate,” ACRO told <em>ITPro</em>. </p><p>“We take data security very seriously and as soon as we were made aware of this incident we took the customer portal offline. At this time we have no conclusive evidence that personal data has been affected by the cyber security incident."</p><p>ACRO is currently working with authorities to investigate the incident further. </p><p>The organisation’s website is currently displaying a single page with essential customer information only, directing them to ACRO’s Twitter account for up-to-date guidance.</p><p>According to its customer service Twitter account, ACRO was initially forced to accept applications for police certificates by post only. </p><p>A week later it set up dedicated email addresses to receive applications for both police certificates and international child protection certificates.</p><p>ACRO has a number of core duties, one of which is to check if a suspect in the UK has a record of criminal convictions from other countries.</p><p>It also provides police certificates for those who wish to emigrate from the UK, or need a visa to live or work aborad. </p><p>The document is usually required by foreign embassies and equivalent institutions to grant entry into their respective countries.</p><p>International child protection certificates are required for individuals who wish to work with children in countries outside the UK.</p><p>Individuals can also file <a href="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request" data-original-url="https://www.itpro.com/data-protection/31623/what-is-a-subject-access-request">subject access requests</a> to ACRO to obtain copies of police records about them.</p><h2 id="analysis-of-the-acro-cyber-incident">Analysis of the ACRO cyber incident</h2><p>The timeframe of the incident will undoubtedly spark criticism of ACRO and its handling of the case.</p><p>Failing to inform the public about a cyber attack for nigh-on three months will be seen as a major miscalculation by whoever’s decision to was to keep this under wraps.</p><p>‘Cyber attack’ isn’t the exact verbiage used by ACRO, but the incident is more than likely to be characterised as just that, and it wouldn’t be the first organisation to shy away from what some consider to be ‘scary’ wording of an incident.</p><p>Earlier this year Minneapolis Public Schools went so far as to refer to its incident as an “<a href="https://its.mpls.k12.mn.us/mps_systems_data">encryption event</a>”, prompting mockery from many corners of the cyber security community.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Pcw3mLqCD4eDFGUvcwCHzD" name="Pcw3mLqCD4eDFGUvcwCHzD.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/Pcw3mLqCD4eDFGUvcwCHzD.png" mos="https://cdn.mos.cms.futurecdn.net/Pcw3mLqCD4eDFGUvcwCHzD.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Mapping the digital attack surface</strong></p><p class="fancy-box__body-text">Why global organisations are struggling to manage cyber risk</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370166/mapping-the-digital-attack-surface" data-original-url="/security/cyber-security/370166/mapping-the-digital-attack-surface">FREE DOWNLOAD</a></p></div></div><p>The attack was later claimed by the Medusa ransomware operation.</p><p>Concerning incident disclosures, it is widely considered best practice in the security industry that transparency is best for both the attacked organisation, and its customers and stakeholders.</p><p>Clearly communicating the ways ACRO’s staff have been making productive steps towards responsibly remediating the issue would have made for better optics here.</p><p>We don’t know for sure if ACRO knew about the incident from 17 January, but it did confirm that’s when it first started. The office may have only been made aware of the attack at a later date.</p><p>As <a href="https://twitter.com/ACRO_Police_CST/status/1643654602426916866">confirmed</a> by ACRO on Wednesday evening, it has “allocated more resources” to its staff to deal with mounting enquiries. </p><p>It has asked individuals travelling after 1 June to wait until 7 May to submit their certificate applications so they can respond to requests “in a timely manner”.</p><p>The office is evidently strained as a result of the attack and it will be hoping for a fast recovery. </p><p>With the NCSC engaged, ACRO would likely have been advised to hire third-party incident response specialists to help it with the recovery.</p><p>If ransomware is involved, it’s likely that the NCSC will be leading negotiations with the threat actors.</p><p>A rare insight into how the NCSC negotiates with cyber criminals was made public earlier this year after LockBit <a href="https://www.itpro.com/security/ransomware/370124/lockbit-leaks-44gb-royal-mails-data-sets-fresh-ps33-million-ransom" data-original-url="https://www.itpro.com/security/ransomware/370124/lockbit-leaks-44gb-royal-mails-data-sets-fresh-ps33-million-ransom">published its entire chat history between it and Royal Mail International</a>.</p><p>The disclosure from ACRO today raises more questions than it answers.</p><p>Over the coming days, it will need to publicly disclose the incident through its own channels, not just comments made to the media, and explain why it took so long to inform the public of the truth behind all the disruption.</p><p>It will also need to outline how it plans to recover, providing clear estimated time frames, and offer more to convince that the sensitive data it safeguards remains safe.</p><p>If an attacker were to have access to an individual’s criminal records, for example, the damage they could do could theoretically be far greater than what could be achieved with just a name, home address, and phone number - the type of data often stolen in cyber attacks.</p><p>It would also make the data highly valuable, worthy of the lofty ransoms often demanded by modern-day cyber criminals.</p><p>Ultimately, ACRO has a great deal to answer for, and the public will undoubtedly be demanding greater transparency from a public office with the keys to such important and sensitive information. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Rorschach ransomware almost twice as fast as LockBit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/370386/new-rorschach-ransomware-almost-twice-as-fast-as-lockbit</link>
                                                                            <description>
                            <![CDATA[ The sophisticated strain is made of cherry-picked code from other leading lockers and operated by an unknown group ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i5rsoCFLr9iriLxJ2vERnw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z9K3MEMPwGaMFWeTCBKgd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Apr 2023 10:31:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z9K3MEMPwGaMFWeTCBKgd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ink blots form a Rorschach test, on a piece of folded paper lit in blue lighting and viewed through a slightly distorted lens]]></media:description>                                                            <media:text><![CDATA[Ink blots form a Rorschach test, on a piece of folded paper lit in blue lighting and viewed through a slightly distorted lens]]></media:text>
                                <media:title type="plain"><![CDATA[Ink blots form a Rorschach test, on a piece of folded paper lit in blue lighting and viewed through a slightly distorted lens]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z9K3MEMPwGaMFWeTCBKgd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered one of the fastest-encrypting ransomware strains, dubbed 'Rorschach', which has also displayed sophisticated evasion capabilities in attacks around the world.</p><p>The ransomware was detected in an attack against an undisclosed US-based company’s Windows environment, and quickly identified as a particularly efficient and apparently unaffiliated strain.</p><p>Check Point Research published details on Rorschach in a <a href="https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware">blog post</a>, describing it as “one of the fastest ransomware out there” due to its impressive optimisation and sophisticated cryptography method.</p><p>In encryption tests within a controlled environment, Rorschach was able to encrypt 220,000 files in 270 seconds, a full 150 seconds faster than the self-proclaimed “fastest” ransomware <a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter" data-original-url="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit 3.0</a>.</p><p>This is achieved with a mix of the curve25519 and hc-128 algorithms, through which it encrypts only sections of files for more efficient encryption.</p><p>Researchers speculated that Rorschach is capable of even greater speeds through adjustments to its command line argument, cementing it as the new threat where encryption times are concerned.</p><p>Rorschach appears to contain the best code snippets from a range of other ransomware strains.</p><p>Both Check Point and Group-IB researchers noted that the code Rorschach uses to kill services is identical to that found in <a href="https://www.itpro.com/security/ransomware/360095/babuk-ransomware-returns-to-target-corporate-networks" data-original-url="https://www.itpro.com/security/ransomware/360095/babuk-ransomware-returns-to-target-corporate-networks">Babuk ransomware</a>, while the classes it uses to rename encrypted machine files appear to have been lifted from LockBit 2.0.</p><p>Aside from its cryptographic sophistication, the strain operates in a standard pattern for ransomware. It disables certain services to avoid detection, kills the firewall, and deletes shadow volumes to prevent file recovery.</p><p>Ransom notes that researchers found on infected systems have borrowed the structure from those found in attacks by <a href="https://www.itpro.com/security/ransomware/369435/yanluowang-ransomware-leaks-suggest-pseudo-chinese-persona-revil-links" data-original-url="https://www.itpro.com/security/ransomware/369435/yanluowang-ransomware-leaks-suggest-pseudo-chinese-persona-revil-links">Yanluowang</a>, though the ransom note in a different variant of Rorschach <a href="https://asec.ahnlab.com/en/47174">identified</a> by AhnLab was closer structure to the <a href="https://www.itpro.com/technology/cryptocurrencies/359601/hackers-swindled-over-90m-in-bitcoin-with-darkside-ransomware" data-original-url="https://www.itpro.com/technology/cryptocurrencies/359601/hackers-swindled-over-90m-in-bitcoin-with-darkside-ransomware">DarkSide</a> group.</p><p>The notes demonstrated that the threat actors behind Rorschach have a strong command of English, setting them apart from other groups such as LockBit whose notes comprise broken English sentences.</p><p>The group does not use threats of <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">double extortion</a> in its notes, simply urging companies to pay or be attacked again.</p><p>Rorschach is tracked by Group-IB as ‘BabLock’, and in January 2023 was tracked in attacks against industrial targets across Europe, Asia, and the Middle East.</p><p>Devices in Russian and other languages dominant in post-Soviet territories were left unharmed by the ransomware.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cDuYPAWDnMxAG5xUHEbeqe" name="cDuYPAWDnMxAG5xUHEbeqe.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/cDuYPAWDnMxAG5xUHEbeqe.png" mos="https://cdn.mos.cms.futurecdn.net/cDuYPAWDnMxAG5xUHEbeqe.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The near and far future of ransomware business models</strong></p><p class="fancy-box__body-text">What would make ransomware actors change their criminal business models?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models" data-original-url="/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models">FREE DOWNLOAD</a></p></div></div><p>“We believe that the group BabLock is not related to any particular RaaS affiliate programme and that it performs 'quiet' occasional attacks using proprietary ransomware,” stated Group-IB in a <a href="https://www.group-ib.com/blog/bablock-ransomware">blog post</a>.</p><p>Unusual features within Rorschach have made it difficult to detect and root out once identified.</p><p>It uses the ‘syscall’ instruction to directly call on system APIs to dodge <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus software</a>. The strain is also partly autonomous, and was found to self-propagate when executed on a Windows Domain Controller through the creation of group policies to spread to all connected workstations, much like <a href="https://www.itpro.com/security/ransomware/362173/fbi-warns-of-sophisticated-lockbit-20-ransomware" data-original-url="https://www.itpro.com/security/ransomware/362173/fbi-warns-of-sophisticated-lockbit-20-ransomware">LockBit 2.0</a>.</p><p>Initial analysis of Rorschach was hindered by the quality of the obfuscation that its developers used to shield its code, another indication of its creators’ skill. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370362/new-cylance-ransomware-strain-experts-speculate-notorious-members" data-original-url="/security/ransomware/370362/new-cylance-ransomware-strain-experts-speculate-notorious-members">New Cylance Ransomware strain emerges, experts speculate about its notorious members</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni" data-original-url="/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni">Former NCSC chief Ciaran Martin pinpoints critical national infrastructure (CNI) as the next big ransomware target</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations" data-original-url="/security/ransomware/370265/rubrik-confirms-data-breach-but-evades-cl0p-ransomware-allegations">Rubrik confirms data breach but evades Cl0p ransomware allegations</a></p></div></div><p>Reverse-engineered samples revealed a hidden list of arguments that can be passed to Rorschach to control its actions, such as whether it self-deletes, which paths to delete, or whether the sample requires a password to operate.</p><p>Check Point noted that its list of arguments is not exhaustive, and that other found arguments implied that Rorschach is capable of operating across networks.</p><p>The strain’s adaptability is what led Check Point to dub it ‘Rorschach’, with researchers having noted that “each person who examined the ransomware saw something a little bit different”.</p><p>Having operated for some months undetected, and without a clear self-identifcation, it is not clear whether Rorschach will expand its operations or seek to adopt double extortion methods.</p><p>At present, researchers have urged IT administrators to continue following best practices, and remain vigilant against this aggressive new strain.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK’s offensive hacking force plans to scale operations to meet government's demands ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/370379/uks-offensive-hacking-force-scale-operations-governments-request</link>
                                                                            <description>
                            <![CDATA[ The NCF conducts cyber operations "on a daily basis" to protect UK national security and counter growing cyber threats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dEYg22ev7os61VTqPpMMfE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Apr 2023 11:45:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:description>                                                            <media:text><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK’s National Cyber Force (NCF) has revealed plans to scale operations amid rising demands from the government to ramp up offensive hacking capabilities.</p><p>In a report offering a <a href="https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1148278/Responsible_Cyber_Power_in_Practice.pdf">unique insight into the NCF’s ongoing expansion</a>, the offensive cyber force said it needs to “scale up to meet the requirements government has of it” and is rapidly expanding personnel and capabilities to meet current demand. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369293/gchq-calls-for-greater-quantum-investment-chinese-tech-dominance" data-original-url="/business/policy-legislation/369293/gchq-calls-for-greater-quantum-investment-chinese-tech-dominance">GCHQ chief calls for greater quantum investment, warns of looming Chinese tech dominance</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni" data-original-url="/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni">Former NCSC chief Ciaran Martin pinpoints critical national infrastructure (CNI) as the next big ransomware target</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/370334/uk-crime-fighters-several-thousand-cyber-criminals-ddos-for-hire-honeypot" data-original-url="/security/cyber-crime/370334/uk-crime-fighters-several-thousand-cyber-criminals-ddos-for-hire-honeypot">UK crime fighters wrangle “several thousand” potential cyber criminals in DDoS-for-hire honeypot</a></p></div></div><p>The NCF is currently in the process of establishing a new permanent base of operations as Samlesbury in Lancashire, which it said will enable the force to “increase operational output”. </p><p>Samlesbury, a 45-minute drive from GCHQ operations in Manchester, was <a href="https://www.itpro.com/security/cyber-warfare/361102/samlesbury-unveiled-as-new-national-cyber-force-location" data-original-url="https://www.itpro.com/security/cyber-warfare/361102/samlesbury-unveiled-as-new-national-cyber-force-location">selected as the site for the NCF headquarters in 2021</a>.</p><p>As part of this expansion and recruitment drive, the NCF revealed that it plans to further invest in offensive hacking capabilities to contend with escalating global threats. </p><p>The report said that “significant capability investment” will be required to “keep pace with the changing nature of technology” and mitigate increasingly sophisticated cyber threats currently faced by the UK. </p><p>The NCF specifically highlighted rapid technological developments as a key operational challenge, noting that “fundamental changes to the future shape of the internet and globalisation of technology could raise significant complications”. </p><p>“Our adversaries are global and use a wide array of cyber and digital technologies,” the report said. “We need to have the technical ability and readiness to reach these adversaries wherever they are and irrespective of how they are using cyber technology.”</p><p>Closer integration with defence partners, including GCHQ, the <a href="https://www.itpro.com/security/367722/mod-pledges-resilience-to-all-known-vulnerabilities-by-2030" data-original-url="https://www.itpro.com/security/367722/mod-pledges-resilience-to-all-known-vulnerabilities-by-2030">Ministry of Defence</a> (MOD), and the Secret Intelligence Service (SIS) will also be a key objective for the NCF moving forward.</p><p>The NCF noted that it must “integrate effectively with other parts of government and with a wider range of partners and allies”. </p><p>This includes law enforcement, government policy departments, the private sector, and a “growing number of international allies”. </p><p>“More broadly, we are working with the private sector, academia, think tanks, and wider civil society to harness the best thinking available to enable our mission,” the NCF said.</p><h2 id="ncf-faces-operational-challenges">NCF faces operational challenges</h2><p>The NCF noted that it faces several significant challenges as operations continue to accelerate. Relevant skills and expertise are currently a key issue facing the force.</p><p>Its status as a relatively new organisation is also presenting challenges due to its combination of elements from both the intelligence community and the armed forces, the report warned. </p><p>“This means that investment in organisational development is important. Not least given the often very different cultures, processes, and professional experiences of the constituent organisations.”</p><p>Similarly, the Samlesbury headquarters development will also require a “high degree of planning and preparation” before it can become fully effective in its capabilities, the NCF said.</p><h2 id="what-does-the-ncf-do">What does the NCF do? </h2><p>The NCF conducts cyber operations “on a daily basis” to protect against threats to British national security or the country’s economic well-being.</p><p>While much of the work conducted by the offensive hacking force is highly secretive, in recent years the NCF has led operations focused on protecting military deployments overseas, disrupting terrorist groups, and countering <a href="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect" data-original-url="https://www.itpro.com/security/cyber-warfare/365716/hactivism-russia-ukraine-having-opposite-effect">state-backed disinformation</a> campaigns, it revealed.</p><p>The centre has also worked to counter “sophisticated, stealthy, and continuous cyber threats” facing the UK amid a significant increase in cyber criminal and <a href="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks" data-original-url="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks">state-backed attacks</a> in recent years. </p><p>“NCF routinely plans and conducts operations to support and protect military operations and help ensure they safely meet their mission objectives,” the report said.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="geKvNYhKdcjCQaTpUuaAmA" name="geKvNYhKdcjCQaTpUuaAmA.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/geKvNYhKdcjCQaTpUuaAmA.png" mos="https://cdn.mos.cms.futurecdn.net/geKvNYhKdcjCQaTpUuaAmA.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Supply chain as kill chain</strong></p><p class="fancy-box__body-text">Security in the era Zero Trust</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370164/supply-chain-as-kill-chain" data-original-url="/security/cyber-security/370164/supply-chain-as-kill-chain">FREE DOWNLOAD</a></p></div></div><p>“This can include disrupting physical threats, protecting supply chains, and <a href="https://www.itpro.com/security/ransomware/370176/defending-against-malware-attacks-starts-here" data-original-url="https://www.itpro.com/security/ransomware/370176/defending-against-malware-attacks-starts-here">disrupting hostile malware</a> which could threaten operational readiness.”</p><p>A core tenet of the NCF’s approach is the ‘doctrine of cognitive effect’ - whereby the force uses techniques that have the potential to “sow distrust, decrease morale, and weaken our adversaries’ abilities to plan and conduct their activities effectively”. </p><p>“This can include preventing terrorist groups from publishing pieces of extremist media online or making it harder for states to use the internet to spread disinformation by affecting their perception of the operating environment,” the NCF said. </p><p>There are strict limitations set on the NCF, however. While the organisation represents the tip of the spear for the UK’s offensive cyber activities, NCF operations are conducted following a “well-established legal framework”. </p><p>This includes the Intelligence Services Act 1994 (ISA), the Investigatory Powers Act 2016 (IPA) and the Regulation of Investigatory Powers Act 2000 (RIPA).</p><p>NCF activities are also subject to approval by government ministers, judicial oversight, and parliamentary scrutiny, the organisation said. </p><p>“The NCF always acts within the law,” the report said. “Decisions to approve operations are informed by legal advice on relevant domestic and international law.”</p><p>NCF cyber capabilities are also developed so as to ensure that technologies or techniques can be “controlled effectively” and are predictable. </p><p>“A core part of responsible cyber operations is the design and use of capabilities in a way that is predictable and controllable, and where the risks are proportionate to the outcome required,” the report said. “We carefully design our capabilities to achieve this end.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK crime fighters wrangle “several thousand” potential cyber criminals in DDoS-for-hire honeypot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/370334/uk-crime-fighters-several-thousand-cyber-criminals-ddos-for-hire-honeypot</link>
                                                                            <description>
                            <![CDATA[ The sting follows a recent crackdown on DDoS-for-hire services globally ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lavu3tcbRvELhZmgwVrnU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gqnvjgo5gFCmZDfTmf4MFG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Mar 2023 10:56:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gqnvjgo5gFCmZDfTmf4MFG-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[National Crime Agency (NCA) logo on a plaque attached to its headquarters]]></media:description>                                                            <media:text><![CDATA[National Crime Agency (NCA) logo on a plaque attached to its headquarters]]></media:text>
                                <media:title type="plain"><![CDATA[National Crime Agency (NCA) logo on a plaque attached to its headquarters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gqnvjgo5gFCmZDfTmf4MFG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Thousands of suspected cyber criminals have exposed their identities after falling for a honeypot sting run by UK law enforcement.</p><p>The UK's National Crime Agency (NCA) created a fake DDoS-for-hire website that saw scores of users hand over information that will now be used to investigate them.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website" data-original-url="/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website">Pro-Russia Killnet hackers claim DDoS attack on EU Parliament website</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368868/lockbit-ransomware-more-aggressive-ddos-attack" data-original-url="/security/ransomware/368868/lockbit-ransomware-more-aggressive-ddos-attack">LockBit hacking group to be 'more aggressive' after falling victim to large-scale DDoS attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again" data-original-url="/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again">Record for the largest ever HTTPS DDoS attack smashed once again</a></p></div></div><p>The operation saw several fake websites created purporting to offer cyber criminal services. The sting was part of a global law enforcement operation to clamp down on cyber criminals using DDoS tactics to target online businesses and users.</p><p>During the operation, the NCA said that “several thousand” people accessed the websites and provided details in order to access criminal services.</p><p>Investigators revealed that details given by prospective customers have been collated and will be used to target criminals.</p><p>“All of the NCA-run sites, which have so far been accessed by around several thousand people, have been created to look like they offer the tools and services that enable cyber criminals to execute these attacks,” the NCA said in a statement. </p><p>“However, after users register, rather than being given access to cyber crime tools, their data is collated by investigators. </p><p>The NCA’s site domain was replaced with a splash page warning users that their data has been collected. The agency said that UK-based users will be contacted and “warned about engaging in cyber crime”. </p><p>The move by the NCA follows a recent crackdown on DDoS-for-hire services globally. In December last year, 48 of the world’s most popular <a href="https://www.itpro.com/security/distributed-denial-of-service-ddos/369722/us-begins-seizure-48-ddos-for-hire-international-operation" data-original-url="https://www.itpro.com/security/distributed-denial-of-service-ddos/369722/us-begins-seizure-48-ddos-for-hire-international-operation">booter sites were taken offline</a> in a coordinated sting involving the FBI, NCA, and Europol. </p><p>Collectively, the sites taken down in this operation were used to carry out more than 30 million attacks in recent years. </p><h2 id="ddos-as-entry-level-cyber-crime">DDoS as entry-level cyber crime</h2><p>DDoS-for-hire services – also known as ‘booter services’ - enable users to set up accounts and coordinate <a href="https://www.itpro.com/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again" data-original-url="https://www.itpro.com/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again">DDoS attacks</a> “in a matter of minutes”, according to the NCA. </p><p>In the past, these attacks have <a href="https://www.itpro.com/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again" data-original-url="https://www.itpro.com/infrastructure/network-internet/368857/record-for-largest-ever-https-ddos-attack-smashed-again">proven highly effective</a> against businesses, critical national infrastructure, and public services.</p><p>DDoS attacks have been a frequent attack method <a href="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website" data-original-url="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website">leveraged by Russian state-linked hacker groups</a> targeting Ukrainian public services since the onset of the conflict in February last year. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="goH3DUReMuea7tNkdVG39a" name="goH3DUReMuea7tNkdVG39a.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/goH3DUReMuea7tNkdVG39a.png" mos="https://cdn.mos.cms.futurecdn.net/goH3DUReMuea7tNkdVG39a.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The IT manager's guide to getting home in time for dinner</strong></p><p class="fancy-box__body-text">A cloud based networking solution that does away with configurations</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/370217/the-it-managers-guide-to-getting-home-in-time-for-dinner" data-original-url="/security/network-security/370217/the-it-managers-guide-to-getting-home-in-time-for-dinner">FREE DOWNLOAD</a></p></div></div><p>Alan Merrett from the NCA’s National Cyber Crime Unit described booter services as a “key enabler” of cyber crime, adding that they provide criminals with easily accessible tools to wreak havoc. </p><p>“The perceived anonymity and ease of use afforded by these services means that DDoS has become an attractive entry-level crime, allowing individuals with little technical ability to commit cyber offences with ease,” he said. </p><p>“Traditional site takedowns and arrests are key components of law enforcement’s response to this threat. However, we have extended our operational capability with this activity, at the same time as undermining trust in the criminal market.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacker who ran BreachForums could face 20 years in prison ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370295/hacker-who-ran-breachforums-could-face-20-years-in-prison</link>
                                                                            <description>
                            <![CDATA[ The hacker behind BreachForums is thought to have been involved in a string of cyber attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u13Ymzxqt82bu89e2XRbBz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Mar 2023 11:38:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:description>                                                            <media:text><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:text>
                                <media:title type="plain"><![CDATA[FBI headquarters on Pennsylvania avenue sign with traffic reflections at night]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/odXzaq87teCWmTNFDtx2qE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The alleged administrator of leading online hacking community BreachForums has been arrested following a US police operation last week. </p><p>Conor Brian Fitzpatrick, who goes by the online moniker of ‘Pompompurin’, was arrested and charged with conspiracy to commit access device fraud, according to court documents filed in the US.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been" data-original-url="/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been">Authorities finally confirm leading hacker platform RaidForums has been seized</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/361553/fbi-hacker-selling-robinhood-data-hacking-forum" data-original-url="/security/data-breaches/361553/fbi-hacker-selling-robinhood-data-hacking-forum">FBI hacker is selling Robinhood customer data on hacking forum</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369966/yandex-data-breach-reveals-source-code-littered-with-racist-language" data-original-url="/security/data-breaches/369966/yandex-data-breach-reveals-source-code-littered-with-racist-language">Yandex data breach reveals source code littered with racist language</a></p></div></div><p>According to court filings, the FBI agent leading the investigation, John Longmire, said that Fitzpatrick identified himself as Pompompurin and admitted to running the forum upon his arrest.</p><p>“When I arrested the defendant on 15 March 2023, he stated to me in substance and in part that: a) his name was Conor Brian Fitzpatrick; b) he used the alias 'Pompompurin', and c) he was the owner and administrator of 'BreachForums', the data breach website referenced in the Complaint,” Longmire wrote. </p><p>If convicted, Fitzpatrick could face up to 20 years in prison under <a href="https://www.law.cornell.edu/uscode/text/18/1029">federal sentencing guidelines</a>. </p><p>Penalties for access device fraud can “differ based on certain variables”, including whether the individual has been previously charged in connection with similar access device crimes. </p><p>A conviction for a first-time offence can result in a fine of up to $25,000 and/or a prison term of up to ten or 15 years. However, in a case of a previous or subsequent offence, this could see the plaintiff receive a sentence of 20 years. </p><p>Fitzpatrick is thought to have been involved in a number of high-profile cyber attacks in recent years, including several against the FBI itself. </p><p>In 2021, Fitzpatrick claimed responsibility for an attack that distributed <a href="https://www.itpro.com/security/cyber-security/361537/fbi-hacked-fake-cyber-attack-warnings" data-original-url="https://www.itpro.com/security/cyber-security/361537/fbi-hacked-fake-cyber-attack-warnings">thousands of fake cyber security warnings</a> from the FBI’s official email account.</p><p>Similarly, he has been linked to the breach of the FBI’s security information-sharing scheme, Infragard, and <a href="https://www.itpro.com/security/data-breaches/361553/fbi-hacker-selling-robinhood-data-hacking-forum" data-original-url="https://www.itpro.com/security/data-breaches/361553/fbi-hacker-selling-robinhood-data-hacking-forum">the Robinhood data breach</a>. </p><p><a href="https://www.bloomberg.com/news/articles/2023-03-17/dark-web-breachforums-operator-charged-with-computer-crime">Reports from <em>Bloomberg</em></a> noted that Fitzpatrick was released on $300,000 bail conditions and will appear before a Virginia court on 24 March. </p><h2 id="what-is-breachforums">What is BreachForums? </h2><p>BreachForums is one of the most popular hacker communities globally, with thousands of members.</p><p>The site is a popular dumping ground for <a href="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust" data-original-url="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust">ransomware gangs</a> leaking stolen data, with databases belonging to nearly 1,000 organisations available on the site.</p><p>Just last week, a hacker operating under the alias of ‘Kernelware’ leaked data stolen from Swiss cyber security firm Acronis to the forum. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4eRfmiXyLuCUJqizfhK2R7" name="4eRfmiXyLuCUJqizfhK2R7.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4eRfmiXyLuCUJqizfhK2R7.png" mos="https://cdn.mos.cms.futurecdn.net/4eRfmiXyLuCUJqizfhK2R7.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The essential guide to preventing ransomware attacks</strong></p><p class="fancy-box__body-text">Vital tips and guidelines to protect your business using ZTNA and SSE</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370178/the-essential-guide-to-preventing-ransomware-attacks" data-original-url="/security/ransomware/370178/the-essential-guide-to-preventing-ransomware-attacks">FREE DOWNLOAD</a></p></div></div><p>Fitzpatrick is thought to have been a notable member on RaidForums during its heyday and launched the successor site in the wake of <a href="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been" data-original-url="https://www.itpro.com/security/hacking/367417/authorities-finally-confirm-leading-hacker-platform-raidforums-has-been">RaidForums’ takedown</a> by law enforcement in April last year. </p><p>RaidForums launched in 2015 and rose to prominence rapidly amid a surge in cyber criminal activity in recent years.</p><p>Portuguese national Diogo Santos Coelho, the creator of the forum, was arrested by UK law enforcement in January last year for his involvement in the illicit website.</p><p>In the wake of Fitzpatrick's arrest, BreachForums was expected to continue operating. </p><p>In posts discussing the arrest on BreachForums, a user by the name of ‘Baphomet’ said they planned to assume responsibility for the running of the site and sought to calm user fears of a looming takedown.</p><p>However, Baphomet issued an update to users informing them that the site would be taken down amidst suspicions that Pompompurin's account had been used to access the forum after his arrest. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1638073772786712578"></a></p></blockquote><div class="see-more__filter"></div></div><p>"This will be my final update from Breached as I've decided to shut it down," Baphomet said. "I'm aware this news will not please anyone, but it's the only safe decision now that I've confirmed that the glowies [law enforcement] likely have access to Poms machine."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: The changing face of cyber warfare ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/370287/podcast-transcript-the-changing-face-of-cyber-warfare</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of ITPro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aEwKVdkGTLFeHUpb7Wb1WW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jUKfnLMei9xZ6YFaSJLtcM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Mar 2023 09:59:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jUKfnLMei9xZ6YFaSJLtcM-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The words &amp;#039;Transcript: The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:description>                                                            <media:text><![CDATA[The words &amp;#039;Transcript: The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:text>
                                <media:title type="plain"><![CDATA[The words &amp;#039;Transcript: The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jUKfnLMei9xZ6YFaSJLtcM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode</em> '<a href="https://www.itpro.com/security/cyber-warfare/370284/itpro-podcast-the-changing-face-of-cyber-warfare" data-original-url="https://www.itpro.com/security/cyber-warfare/370284/itpro-podcast-the-changing-face-of-cyber-warfare">The changing face of cyber warfare</a>’. <em>We apologise for any errors.</em></p><h2 id="rory-bathgate">Rory Bathgate</h2><p>Hi, I'm Rory Bathgate.</p><h2 id="jane-mccallion">Jane McCallion</h2><p>And I'm Jane McCallion.</p><h2 id="rory">Rory </h2><p>And you're listening to the IT Pro podcast, where today we're discussing cyber warfare.</p><h2 id="jane">Jane </h2><p>It’s been over a year since Russia’s unprovoked invasion of Ukraine, and in that time cyber warfare in the region has seen a marked increase. Ukrainian government networks, as well as civilian targets, have been hit with a range of cyber attacks including spear phishing, wiper malware, and leaks of sensitive data.</p><h2 id="rory-2">Rory </h2><p>Google recorded a 250% increase in Russian cyber attacks against Ukraine in 2022 compared to 2020. NATO members have also been impacted by online criminal activity, with ransomware targeting Poland and the UK’s National Cyber Security Centre urging vigilance against the continued threat posed by Russian-sponsored groups.</p><h2 id="jane-2">Jane </h2><p>Today, we're speaking to Daniel Thanos, head of Arctic Wolf Labs, to explore the practices of Russian and Russian state-sponsored threat actors, and what is being done to stop them.</p><h2 id="daniel-thanos">Daniel Thanos </h2><p>Yes, absolutely. When it comes to, within the context of the Ukrainian and Russian war, it's an act of cyber war against each other. It's interesting in that previously, groups that would have been working together or individually been working together within the ransomware context have actually split apart. So for example, we had the Conti leaks, this was a very famous somewhat state-affiliated ransomware group with the Russian government, but they had a lot of Ukrainian members. And as a result of the of the war, some of them leaked all the internal communications and tradecraft in disagreement, obviously, with the war and disagreement with Conti's statements saying that they're gonna be kind of supporting the Russian state as it persecuted this war. So there's definitely been impacts in terms of the ransomware operators themselves. And because they're not purely Russian, per se. That's one impact for sure. The other impact, of course, has been just as you've mentioned there's been a lot of attacks happening back and forth between Ukraine and Russia. The Ukrainians are highly skilled in this area, they have been able to penetrate and leak a lot of information about Russian military personnel operations, the government itself, and create a flood of embarrassing information. They've also been very active in what I call the info war space that's basically, you know, hacking with the purpose of disseminating information to the population, especially Russia as much as you can. Give them the fact that to some degree they're cocooned from reality, they only get the reality that their government chooses to deliver to them. So a lot of cyber operations are kind of involved in, you know, getting the truth to them as well. And on the Russian side, of course, it's just business as usual in the sense that they've always tried to attack critical infrastructure in Ukraine, some of the first instances of successful cyber attacks against the power system, for example, have happened in Ukraine, and that was even before the war. And all of those activities obviously have only increased. And they are, the Russians are first-tier cyber warfare operators, and that that activity has not, has not ceased, we saw the wiper activities, as you mentioned, and obviously they're gonna continue to take those opportunities as are available. However, what has also happened in the war, there's been a real big escalation in kinetic attacks against critical infrastructure. So it's now not that they're bothering to do things in the in the cyber realm, they're literally bombing the infrastructure, and of course that also impacts the cyber realm because you have less and less systems online when you don't have power. So obviously they're taking a very different tactic there. But one interesting angle that I do see in all of this though, essentially the satellites system that's been provided to them by Starlink. That's a big game changer, because that's really hard to attack because it's mobile and you can set those up anywhere. And so to some degree that's become like a communication backbone in Ukraine. And so I'm curious to see if Russian cyber actors try to attack that, or try to target it accordingly as well in the process.</p><h2 id="rory-3">Rory </h2><p>In defining some of this wider context, you've talked about state sponsored groups. I was wondering if for those who don't know, you could lay out some of the differences between other threat actor groups, ransomware groups, such as maybe LockBit, and state sponsored groups. You mentioned Conti, we've also seen Sandworm and a great deal of threat actors in and around cyber, yes.</p><h2 id="daniel">Daniel</h2><p>Yeah, there's also folks we've done some recent research on and published on our website called Karakurt too. These names are popping up everywhere and they're metastasizing. But here's the thing, the best analogy that I like to use is this kind of like piracy of old. And what do I mean by that? So, you know, going back many years to the to the age of pirates and privateers. Usually, what would happen is one country would essentially issue a licence to pirates, as long as they pirated the opposing country, right? And so these were kind of one man's privateer was another person's pirate. So, it's kind of the same way here too. So what happens is that you have ransomware groups, to some degree, because they're allowed to operate with impunity. A lot of the Russian-based groups one way or the other, they do have, they basically have licence. So they're basically privateers on the high cyber seas. And just like pirates of old they like to build brand and notoriety, because that increases their likelihood of collecting their ransom. Because when people realise that they're potent, they're serious, when they say "I have your data, I will leak it", they have the notoriety. And that's how they kind of get get their payout. Now, some groups are more closely-affiliated to the government than others. And that could be because quite literally, you might have members of the group that it's kind of like their moonlighting job. They literally they can be folks that are involved in state cyber operations, but by night this is like their freelance gig, and they're just part of the ransomware gangs and it's just understood that they're kind of allowed to do that to create more revenue for themselves. Other ransomware groups maintain affiliation because they're being directed, kind of loosely directed by a state actor. So it's like, "geez, we would really like it if you could go cause some havoc in some key sectors against these target states", right? And so they will kind of get like some loose guidance, or some suggestions that they act on. Some of them just like Conti in the beginning they kind of viewed themselves, I guess, as more like hacktivists, or an arm of the Russian warfare operation. So obviously, there must have been key individuals there that were very closely affiliated and had relationships. Now, with that said, I will tell you that the nature of the threat is metastasising. And there's, because of the war there's just like many other young men, people in these groups are fleeing Russia. Not all of them want to be part of this conflict. And they're going out into other countries, we're seeing evidence of new groups being established, we see evidence, recent evidence of basically anonymous-type ransomware attacks where it's like, they're not raising the black flag and saying, "I'm this group or that group". They're just anonymous, and they're still like asking for ransom. And what that tells me is there we may be seeing because of threats becoming more diffuse, and they're operating in countries where they don't necessarily have free sanction, they have to be a little bit more careful. So they're not looking to draw as much attention, but it's almost like their trade and they've got to apply it, and they've got to make their money. So we're seeing already beginning to see evidence of that, no branding or nothing just just anonymous attacks, but they're still looking to kind of collect their collective ransom. And they're demanding less. So that again, that could be because you're seeing more freelance activities as the threat kind of becomes more ubiquitous.</p><h2 id="jane-3">Jane </h2><p>See, that's interesting you say that, because I was going to ask if there been a change in say, the volume of cyber attacks coming from Russia based on the fact that there has now been conscription of young men for the past few months, some of whom will definitely have been members of these cyber gangs, if you will. Is it then that the volume is the same, but the people have moved? Or that people who may have been say, more part of these patriotic hacking groups are now off doing freelance extortion on the side while they're in other nations? What impact are you seeing?</p><h2 id="daniel-2">Daniel</h2><p>Yeah, so let's look at the trend. When the when the war first started, definitely there was a, I would say there was a reduction in activity for sure. We saw that in our incident response business, there's levels of predictability and they were trending. And it went down, it went down because I think there was a lot of initial focus with these groups joining, as you said, cyber patriot groups or again a lot of them, I believe a lot of these folks kind of moonlight and they actually do work in government cyber operations. Or they can be military affiliated. And so obviously their focus changed, but now as the war is kind of dragging on, I think we're seeing a lot of people pivot back to having to make their money. So activity has started to trend up again. But I think what's happening is the threats are just becoming more distributed, more diffuse, because I think they're just like everyone else as we mentioned before, you have a lot of a lot of talent and malicious talent in this area leaving the country. And they're just setting up shop elsewhere, and they're now beginning to organise themselves. There's also a lot of specialisation happening, and that's been happening even before the war in Ukraine where people that actually execute the ransomware attacks are different than the people that get initial access, the initial access brokers. And then the people that develop the tools, the malicious tools, basically rent it to help to the people that do the attacks. So this specialisation has been happening for a while, I think to some degree now, this is like only going to accelerate it as well. And the activity is basically going up again, and I think it's just because it took time, that there was a big distraction in this war. But now I think a lot of folks are going back into their trade, if you will, back to their craft. And as they leave the country, and they just self-organise in different ways they have to be a little bit more stealthy in terms of not attracting as much attention. Because again, they don't have that free sanction to do whatever they want. So it's just that the nature of the threat changes, and the nature of their operational security changes. But now it's going up again. And then even within Russia itself, for the people that are there that are more state-affiliated or outright just work for the state. Yeah, I believe as the sanctions start to really bite and decoupling between Russia and the West increases, and depending on the trajectory of the war and Russian losses and challenges you may see the Russians also pivot back to increased operations, focused on disruptive and disrupting attacks as well.</p><h2 id="jane-4">Jane </h2><p>I want to talk tactics a little bit, so going back to something that you said a little bit earlier on, which is that there's been a drop in cyber attacks and kind of a move to more kinetic attacks. When the cyber war was being theorised about before the invasion of Ukraine actually happened, two of the big theories were that a physical traditional kinetic war would be preceded potentially by a big uptick in cyber attacks to kind of prepare the ground. And also potentially even that critical infrastructure would be hit by crippling cyber attacks, to kind of mean that you then don't need to worry about hitting a power station or whatever, because it's already offline. Now, it sounds to an extent that what you're saying is that's not really what happened, that this cyber war in reality is quite different to what was theorised. Is that sort of a fair assessment?</p><h2 id="daniel-3">Daniel</h2><p>I think the outcome that the Russians certainly wanted happen differently. What I will tell you is if you talk to people that have been involved in the Ukrainian CERT, the folks that are actually involved in the cyber defence of Ukraine, they have thwarted a lot of attacks. And they continue to do so every day. So I think there's also been like, let's be frank, the Western world has also surged in resources and expertise to, to help Ukraine in this in this realm, too. So, and there's been a lot of volunteer effort as well. So my statement on that would be: if the Russians could have caused havoc that way,they would have. But what you don't always get in the news is the unsuccessful attempts. So I have no doubt that they attempted many things, but I also have no doubt that Ukraine was well prepared. Because cyber warfare has now become a standard doctrine, and it is a preceding tactic before you go into full kinetic warfare. So electronic warfare is like an older version of this, but it's the same thing, it's based on the same doctrine. So you know, before you go bomb someone, you scramble their communications, you bring down their communications, you scramble their radar. It's much the same thing within in the cyber realm as well, because more and more systems have become computerised. And the best way to catch your enemy in a situation where they can't respond is to attack them on the cyber realm, because it's cheap, and it's effective. Now, the other issue is that what I attack with the cyber realm usually does mean I can recover. So just going back to my experience, I've done security for critical infrastructure and I was involved with a few US presidential commissions in this area, and what I will tell you is that there's a very narrow set of cyber attacks that are possible that can actually harm physical infrastructure, especially in the power grid. And that's pretty hard to execute. Most of the attacks that you're going to get, your enemy is able to within a certain period of time recover from it. And usually what you're doing is, when you're attacking, it's just that you want a certain window where there's confusion, things are down, then you're taking kinetic action, then you're out again. And usually you're not going to get to repeat that attack. Because once your enemy has figured out what you did, usually those methods are not available to you again. Now in the case of Ukraine, because they've already endured a lot of these attacks and attempts, I think they were well positioned to be able to defend themselves against the onslaught of things that I'm sure the Russians repeatedly tried. And we saw some things get through with the wiper attacks and whatnot. But if you attack someone enough, what you're doing is you're encouraging them to build defences. So it's kind of like exercising a muscle, right? If you force someone to use it, they're they're going to increase their capabilities.</p><h2 id="rory-4">Rory </h2><p>You've talked a bit about some of the attacks on critical national infrastructure with things like wiper attacks. I was wondering if there was a difference in tactics with the attacks that we've seen on Ukrainian businesses in the region, or whether there's a really kind of a shared tactic there?</p><h2 id="daniel-4">Daniel </h2><p>Yeah, at the end of the day these tactics are all shared. So all that's a different is essentially the payload that I'm delivering. So if my objective is different, so my objective is to exfiltrate information, it's not that I need to kind of burn the place down on my way out. If my objective is destructive, then obviously I'm going to wipe your servers, I'm going to try to do as much damage. So what I'm trying to do is essentially, I'm trying to impact your availability. So in the security industry, we like to talk about confidentiality, integrity, and availability, it's like this triad of security. And so if my objective is to essentially bring down a system and do a disruptive attack, what really I'm doing is I'm just trying to impact your availability, right? If my objective is to steal information with the intent of causing you reputational damage, or using that in an info war campaign of some type, because information I've stolen is somehow embarrassing to you, or kind of degrades trust in you or your institutions. That's an attack on your confidentiality. And if I'm trying to attack a system, such that I'm injecting false data to cause it to process something wrong, or kind of lose trust in it. That's like attacking the integrity of a system. And those are kind of like the kind of ways you can think about it.</p><h2 id="jane-5">Jane </h2><p>So we've spoken a lot about what's happening between Russia and Ukraine. Now obviously, while NATO as an organisation and NATO countries are not involved in the war itself, they're supplying a lot of support to Ukraine. So when it comes to cyber attacks that are coming out of Russia, are they also targeting NATO organisations, whether that is governmental or private businesses, or whatever? Or are they just focusing all their efforts on Ukraine?</p><h2 id="daniel-5">Daniel </h2><p>So two comments on that. First thing is even before the war in Ukraine, Russia has been a prolific threat actor, they've always targeted NATO countries. They've targeted them for the purposes of espionage, they've targeted them for the purposes of causing disruption through their ransomware affiliates. And that doctrine hasn't changed, right? They also target for the purpose of again, information warfare, causing confusion in your enemy, that doctrine hasn't changed. So that they will continue to target even now, so if they've targeted before the war they're going to continue to target during the war and so that won't change. What happened though is, like we discussed before, in the initial stages I think they just got really, really focused on their target which was Ukraine and they really focused their operations there. Because the government there in Russia was thinking that they could blitzkrieg their way through Ukraine, and basically just decapitate the government to take over the country. Now, as that hasn't happened, and thank God it hasn't because of the bravery of the Ukrainian people. But as that hasn't happened they, to some degree, they have to continue to sustain their national security objectives, and even in the face of this war. So their intelligence programmes aren't going to change, their intelligence programmes against NATO aren't going to change, they're only going to intensify. Because now as a result of this war, and as a result of their disastrous policies, they're going to get exactly what they didn't want which is an expansion of NATO. So NATO now is going to become an even bigger threat to them, and so you can you can be guaranteed that they're going to only increase their cyber operations against it. And they're gonna have to increase their intelligence gathering now. So and they're going to have to, as per their policy in the past, they love causing division and disunity within the alliance. And so they're going to be executing cyber backed espionage, to find ways to do that, to find what are the divisions when it comes to Europe? I have no doubt that they're trying to collect intelligence around whether they cause an energy crisis, or what's going on with energy planning. All of these things are going to be levers that they need or leverage that they need to try to, at some point or another, try to negotiate something and try to meet some of the objectives they have in mind when it comes to Ukraine. And they know that, I have to believe that most people in Russia understand that they're not going to be able to conquer Ukraine, but they're going to have to figure out a way to meet some of the objectives they had in mind. And the only way to do that is to is to create divisions in the alliance, exploit divisions in the alliance, and they're going to have to collect a great deal of intel to figure out how to do that across many non-obvious sources. So that means there's going to be an increase in cyber operations, not necessarily destructive. They're going to be more focused on just day in and day out espionage and intelligence gathering.</p><h2 id="rory-5">Rory </h2><p>I'm curious, you mentioned sanctions earlier, you talked a bit about that. Sanctions were some of the earliest actions that were taken against Russia, and some were even specifically targeted to cut funding for Russian threat actors. Are these working currently? And what other methods are currently being used to tackle Russian threat actors?</p><h2 id="daniel-6">Daniel </h2><p>Yeah, that's a great question. And there's definitely a cyber angle to it as well. I think, again, just me reading the information that I'm sure other people have read. Initially, it hasn't had as broad of an impact, I think, as many anticipated. And that's just because of the complexities of our globalised economy. So as we tried to kind of tighten the screws on Russia, really what we did was we caused the price of gas and oil to go higher. So there are still people that, even if you're let's say cutting down the size of their market, if the product that they're selling is still going up in value, even if they have a smaller market to sell to, because make no mistake there's still people buying Russian gas and oil. And I'm sure there's even people that are trying to find ways to like skirt sanctions, there's been some interesting research out there by a lot of security researchers observing Russian ships getting to certain countries and then turning off their transponders, and the ship goes somewhere, it docks and then it kind of goes back to Russia. And that ship happens to be something that can transport oil or gas, there's a lot of that activity. So going on, I mean, we've pushed the price of gas higher because of this war. So overall, I think we know that it didn't create as much impact as anticipated. But the other thing too is sanctions take time to really take hold. When sanctions were initially issued, they weren't as severe as the ladder that's been growing, the ladder of sanctions. Because I guess the intent in that area is essentially, to try to try to get them to think about their behaviour and see if you can kind of change that behaviour, but obviously it's not changing. And so therefore that ladder keeps going up. The other issue too, is that it will take time to investigate and find all of the sanction evaders and the systems of evasions that they're setting up, because I have to believe that the Russian government clearly understood what would happen in regards to sanctions, should they take the actions that they took, and I'm sure they are had already built an extensive network to help in in establishing various types of evasions. These things are very sophisticated. And especially when you throw in things crypto and all of these emerging FinTech things into the mix, there's just, there's a network of possibilities that are out there that they can use. And the other thing too, to understand as well is that the a lot of the oligarchy is kind of one and the same with the state. And their companies and their networks, when required, are used in service of the state. And it took a lot of time to even get a lot of governments to go after specific oligarchs, and go after their assets, and go after their companies. So there's still a lot of things to be done in that realm as well. So we're not really necessarily seeing the full effect of sanctions yet, because from the point of declaring a sanction, to the point of enforcing a sanction, those are two different things. All that stuff takes a lot of time, and it takes a lot of investigation to figure out all the evasions that are happening there, and then it takes a lot of diplomacy. Because when you have large countries like India still buying Russian gas and oil, and you have large markets like China, which is happy this is happening because now they're getting Russian gas at awesome discounts, you have to begin to strong arm there too. So it's basically like, you need to create consequences for those that continue to support this warlord.</p><h2 id="jane-6">Jane </h2><p>So Daniel, in the round what has all of this taught us about the nature and potential severity of cyber warfare? What can our listeners learn from all of this?</p><h2 id="daniel-7">Daniel</h2><p>I think it's like anything else that is kind of new and we have theories of it, but then we discover it in practice. I think the most important takeaway is that, we have a tendency sometimes to overestimate, and underestimate threats. And usually the truth is going to be somewhere in between, so if you're imagining a worst case scenario, it's usually not quite that, but if you're also imagining a best case scenario, it's not going to be that. The truth is always going to lie somewhere in between. Especially for critical infrastructure, there's a lot of things that need to happen in order for you to get successful attacks in those areas. And usually, unless these things have been pre-planned for years, and there's still physical components to these attacks and insiders, and a whole bunch of things that you need to do to score impact. So I like to use the Stuxnet example of old, when we successfully impacted the Iranian nuclear programme and really screwed around with centrifuges, that operation was not a spur of the moment response. It was probably a good one to two years of planning and development, and it required inside access and physical access. So that's why it was more in the realm of intelligence agencies and national security agencies, strong components within espionage and so on and so forth, executed these things. So it's not the same as cyber warfare mirroring what happens in a battlefield, which is like "I'm loading up a shell, I'm aiming some artillery to a certain latitude and longitude and firing the shell". So cyber warfare is not as kinetic, in the sense of it's not as fast acting as some would believe. Real cyber warfare takes time, and it takes a lot of planning to be to be executed, and of course its impact can be quite wide. But I think it's cyber warfare that has wider impacts or more constant impact, is like a lot of these ransomware attacks because definitely, they can be disruptive, we've seen that with colonial gas in the US which was a minor operator, but critical to the supply chain. They didn't have the capabilities to defend themselves. And they caused shortages and impact. They didn't destroy infrastructure, per se, but they caused serious impact. And even something like that, it takes time to plan and execute those things. So it's not like a spur of the moment type action.</p><h2 id="rory-6">Rory </h2><p>Well, Daniel, thanks so much for being on the show.</p><h2 id="daniel-8">Daniel</h2><p>It was a real pleasure to be here. Thank you for some great thoughtful questions.</p><h2 id="rory-7">Rory </h2><p>As always, you can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk. </p><h2 id="jane-7">Jane </h2><p>You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro Podcast wherever you find podcasts. And if you're enjoying the show, why not tell a friend or colleague about us? </p><h2 id="rory-8">Rory </h2><p>We'll be back next week with more from the world of it. But until then, goodbye.</p><h2 id="jane-8">Jane</h2><p>Goodbye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ITPro Podcast: The changing face of cyber warfare ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/370284/itpro-podcast-the-changing-face-of-cyber-warfare</link>
                                                                            <description>
                            <![CDATA[ Russian-sponsored cyber attacks may not have had the feared impact, but for Europe they’re here to stay ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5J5yVgLAUmfxzaLsEUR3Am</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TqUuVBRPWyTkorDjcLpnDY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Mar 2023 07:32:15 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Apr 2023 13:09:16 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TqUuVBRPWyTkorDjcLpnDY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The words &amp;#039;The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:description>                                                            <media:text><![CDATA[The words &amp;#039;The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:text>
                                <media:title type="plain"><![CDATA[The words &amp;#039;The changing face of cyber warfare&amp;#039;, with &amp;#039;cyber warfare&amp;#039; in yellow and the rest in white against a dark satellite view of Earth with city lights glowing and ITPro Podcast logo in the corner]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TqUuVBRPWyTkorDjcLpnDY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s been over a year since Russia’s unprovoked invasion of Ukraine, and for those in the tech sector cyber warfare has defined the conflict. Ukrainian organisations, both public and private, have been subject to attacks including wiper malware, spear phishing, and data breaches.</p><p>National cyber security agencies, as well as teams of security experts from throughout the field, remain on high alert for heightened Russian cyber activity. Understanding the strategies of these hackers, as well as their individual motivations, has been key to retaining the integrity of targeted systems.</p><p>In this episode, Jane and Rory speak to Daniel Thanos, head of Arctic Wolf Labs, to discuss the current state-sponsored threat group landscape, and how the terms of the conflict have shifted over time.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=53232388&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“Some groups are more closely affiliated to the government than others. And that could be because quite literally you might have members of the group that it’s their moonlighting job, they literally can be folks that are involved in state cyber operations but by night this is like their freelance gig.”</p><p>“I think the outcome that the Russians certainly wanted, happened differently. What I will tell you is if you talk to people that I've been involved in the Ukrainian CERT, the folks that are actually involved in the cyber defence of Ukraine, they have thwarted a lot of attacks. And they continue to do so every day.”</p><p>“Their intelligence programmes against NATO aren't going to change, they're only going to intensify. Because now as a result of this war, and as a result of their disastrous policies, they're going to get exactly what they didn't want, which is an expansion of NATO. So NATO now is going to become an even bigger threat to them. And so you can be guaranteed that they're going to only increase their cyber operations against it.”</p><p><a href="https://www.itpro.com/security/cyber-warfare/370287/podcast-transcript-the-changing-face-of-cyber-warfare" data-original-url="https://www.itpro.com/security/cyber-warfare/370287/podcast-transcript-the-changing-face-of-cyber-warfare"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/business-strategy/disaster-recovery-dr/369886/intellias-disaster-recovery-russia-ukraine-war" data-original-url="https://www.itpro.com/business-strategy/disaster-recovery-dr/369886/intellias-disaster-recovery-russia-ukraine-war">Intellias: Disaster recovery during Russia's war on Ukraine</a></li><li><a href="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine" data-original-url="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine">Microsoft: Russia increasingly timing cyber attacks with missile strikes in Ukraine</a></li><li><a href="https://www.itpro.com/security/malware/369633/crywiper-trojan-disguises-as-ransomware-kaspersky" data-original-url="https://www.itpro.com/security/malware/369633/crywiper-trojan-disguises-as-ransomware-kaspersky">'CryWiper' trojan disguises as ransomware, says Kaspersky</a></li><li><a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">The new wave of cyber security threats facing critical national infrastructure (CNI)</a></li><li><a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">What is cyber warfare?</a></li><li><a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Russian cyber attacks on Ukraine: What we know so far</a></li><li><a href="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine" data-original-url="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine">Microsoft: Russia increasingly timing cyber attacks with missile strikes in Ukraine</a></li><li><a href="https://www.itpro.com/security/369438/uks-6m-cyber-support-package-for-ukraine-revealed-for-first-time" data-original-url="https://www.itpro.com/security/369438/uks-6m-cyber-support-package-for-ukraine-revealed-for-first-time">UK's £6m cyber support package for Ukraine revealed for first time</a></li><li><a href="https://www.itpro.com/security/33996/critical-infrastructure-at-risk-again-from-stuxnet-like-attack" data-original-url="https://www.itpro.com/security/33996/critical-infrastructure-at-risk-again-from-stuxnet-like-attack">Critical infrastructure at risk again from Stuxnet-like attack</a></li><li><a href="https://www.itpro.com/security/32264/stuxnet-is-back-iran-admits" data-original-url="https://www.itpro.com/security/32264/stuxnet-is-back-iran-admits">Stuxnet is back, Iran admits</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT admins notified as Microsoft revokes previously recommended Exchange antivirus exclusions ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/370131/microsoft-instructs-exchange-admins-to-remove-antivirus</link>
                                                                            <description>
                            <![CDATA[ The tech giant warned that using the exclusions may prevent companies from detecting IIS webshells or backdoor modules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eGhVn6goxKeRaFx3BkoQhv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uysvAeXT4doKihhCPviKUf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Feb 2023 12:35:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uysvAeXT4doKihhCPviKUf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital umbrella in neon blue blocking rainfall made up of neon red binary code, connoting antivirus]]></media:description>                                                            <media:text><![CDATA[Digital umbrella in neon blue blocking rainfall made up of neon red binary code, connoting antivirus]]></media:text>
                                <media:title type="plain"><![CDATA[Digital umbrella in neon blue blocking rainfall made up of neon red binary code, connoting antivirus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uysvAeXT4doKihhCPviKUf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has urged admins to remove antivirus exclusions it previously recommended to improve security.</p><p>Providing an organisation's IT estate is using Microsoft Defender on a fully up-to-date Exchange Server 2019, then the rules it previously recommended can be removed with no risk to performance or stability.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368409/exploited-server-backdoor-undetected-in-most-organisations" data-original-url="/security/cyber-attacks/368409/exploited-server-backdoor-undetected-in-most-organisations">Actively exploited server backdoor remains undetected in most organisations' networks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368652/microsoft-warns-hackers-turning-to-iis-exploits-to-create-backdoors" data-original-url="/security/cyber-attacks/368652/microsoft-warns-hackers-turning-to-iis-exploits-to-create-backdoors">Microsoft warns hackers turning to IIS exploits to create backdoors in businesses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369346/fully-undetectable-powershell-backdoor-hiding-as-windows-update" data-original-url="/security/vulnerability/369346/fully-undetectable-powershell-backdoor-hiding-as-windows-update">Undetectable PowerShell backdoor discovered hiding as Windows update</a></p></div></div><p>"We also believe that these exclusions can also be safely removed from servers running Exchange Server 2016 and Exchange Server 2013," it said in a blog post.</p><p>"When running on Exchange Server 2013 or Exchange Server 2016, keep an eye on the server and watch for issues. If any issues arise on any Exchange Server version, simply put the exclusions back in place, and report the issue to us."</p><p>The exclusions in question specifically relate to Temporary ASP.NET Files and Inetsrv folders, and <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell</a> and w3wp processes. Now, "it would be much better, Microsoft said, for IT admins to instead scan the files and folders.</p><p>The folders that are affected are:</p><ul><li>%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files</li><li>%SystemRoot%\System32\Inetsrv</li></ul><p>The processes that are affected are:</p><ul><li>%SystemRoot%\System32\WindowsPowerShell\v1.0\PowerShell.exe</li><li>%SystemRoot%\System32\inetsrv\w3wp.exe</li></ul><p>Keeping the exclusions in place could even prevent detections of backdoor malware and IIS webshells, Microsoft added. Cyber criminals turned to <a href="https://www.itpro.com/security/cyber-attacks/368652/microsoft-warns-hackers-turning-to-iis-exploits-to-create-backdoors" data-original-url="https://www.itpro.com/security/cyber-attacks/368652/microsoft-warns-hackers-turning-to-iis-exploits-to-create-backdoors">malicious IIS modules</a> in droves last year as a way to gain a more secure foothold in a target's IT environment.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="24wofwQovdLTfB5NmEHDRR" name="24wofwQovdLTfB5NmEHDRR.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/24wofwQovdLTfB5NmEHDRR.jpg" mos="https://cdn.mos.cms.futurecdn.net/24wofwQovdLTfB5NmEHDRR.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Modernise your server infrastructure for speed and security</strong></p><p class="fancy-box__body-text">Infrastructure lifecycle automation paves the way for an adaptive, resilient organisation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/server-storage/servers/362204/modernise-your-server-infrastructure-for-speed-and-security" data-original-url="/server-storage/servers/362204/modernise-your-server-infrastructure-for-speed-and-security">FREE DOWNLOAD</a></p></div></div><p>“In most cases, the actual backdoor logic is minimal and cannot be considered malicious without a broader understanding of how legitimate IIS extensions work, which also makes it difficult to determine the source of infection,” said Hardik Suri, senior security researcher at Microsoft, at the time.</p><p>A year earlier in August 2021, researchers discovered <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> which was able to <a href="https://www.itpro.com/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software" data-original-url="https://www.itpro.com/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software">install a backdoor on Microsoft's IIS</a>.</p><p>The malware, IISpy, was able to evade detection and manipulate the server's logging to perform espionage. It was found present on IIS servers in the US, Canada, and the Netherlands, and was suspected to have affected more servers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber criminal groups wooing hackers with seven-figure salaries and holiday pay ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-crime/369970/cyber-criminal-groups-wooing-hackers-with-seven-figure-salaries-and-holiday</link>
                                                                            <description>
                            <![CDATA[ Paid leave, competitive salaries, and ‘friendly team’ environments were among the benefits highlighted by dark web job ads ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7KouBg9AmtDphLPvKrK86N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8ZSWrM99LKzvSWQBesAZ4g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 31 Jan 2023 12:01:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8ZSWrM99LKzvSWQBesAZ4g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person at a computer looking dejected with one hand on their head staring at computer code]]></media:description>                                                            <media:text><![CDATA[A person at a computer looking dejected with one hand on their head staring at computer code]]></media:text>
                                <media:title type="plain"><![CDATA[A person at a computer looking dejected with one hand on their head staring at computer code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8ZSWrM99LKzvSWQBesAZ4g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminal groups have been found to be attracting hackers and tech professionals alike with white-collar employment benefits and huge salaries as high as $1.2 million.</p><p>Analysis from Kaspersky found that the spike in cyber crime over the last two years has prompted some groups to accelerate hiring to keep pace with demand. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369940/ncsc-warns-uk-state-sponsored-spear-phishing-attacks-russia-iran" data-original-url="/security/cyber-security/369940/ncsc-warns-uk-state-sponsored-spear-phishing-attacks-russia-iran">NCSC warns UK under state-sponsored spear-phishing attacks from Russia and Iran</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/367337/treasure-hunter-dark-web-marketplace-hydra-seized-and-shuttered-by" data-original-url="/security/cyber-crime/367337/treasure-hunter-dark-web-marketplace-hydra-seized-and-shuttered-by">'Treasure hunter' dark web marketplace Hydra seized and shuttered by German cyber police</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/366336/strengthening-cyber-security-in-the-age-of-the-dark-web" data-original-url="/security/366336/strengthening-cyber-security-in-the-age-of-the-dark-web">Strengthening cyber security in the age of the dark web</a></p></div></div><p>Researchers at the firm analysed more than 200,000 employment ads posted on dark web pages between January 2020 and June 2022. </p><p>The result concluded that the volume of ads increased rapidly during the onset of the pandemic, surpassing an average of 10,000 ads per quarter - a figure that peaked in March 2020. </p><p>“A total of roughly 200,000 employment-related ads were posted on the dark web during the period in question,” researchers said. “The largest number of these, or 41% of the total, were posted in 2020.”</p><p>"Posting activity peaked in March 2020, possibly caused by a pandemic-related income drop experienced by part of the population,” the security firm added. </p><p>Dedicated 'hacker’ roles weren’t the only area in which cyber criminal groups were found to be seeking additional expertise.</p><p>Groups increasingly sought out staff to fill developer, admin, and designer positions while other in-demand roles included <a href="https://www.itpro.com/business-strategy/careers-training/369795/software-engineering-salaries-top-1m-in-silicon-valley" data-original-url="https://www.itpro.com/business-strategy/careers-training/369795/software-engineering-salaries-top-1m-in-silicon-valley">software engineers</a> and network testers. </p><p>Job ads seeking developers were the most frequent, the study revealed, accounting for 61% of the total. Similarly, developers also topped the list of the best-paid dark web-sourced <a href="https://www.itpro.com/business-strategy/careers-training/358679/it-job-market-remains-strong-despite-record-unemployment" data-original-url="https://www.itpro.com/business-strategy/careers-training/358679/it-job-market-remains-strong-despite-record-unemployment">IT roles</a>, with the largest monthly salary standing at $20,000. </p><h2 id="employee-incentives">Employee incentives </h2><p>Dark web job listings highlighted by Kaspersky bore similarities to an average tech sector job advert. Groups seeking new starts frequently offered a range of incentives such as holiday pay, flexible working hours, and future employee referral bonuses. </p><p>“Employers on the dark web seek to attract applications by offering favourable terms of employment, among other things,” researchers said. “The most frequently mentioned advantages included <a href="https://www.itpro.com/business-strategy/flexible-working/369931/turning-back-the-clock-on-hybrid-work-is-a-huge-mistake" data-original-url="https://www.itpro.com/business-strategy/flexible-working/369931/turning-back-the-clock-on-hybrid-work-is-a-huge-mistake">remote work</a>, full-time employment, and flextime.” </p><p>“You can also come across paid time off, paid sick leaves, and even 'a friendly team' listed among the terms of employment.” </p><p>Some groups were also found to conduct regular performance reviews, researchers found. This practice was commonplace in the <a href="https://www.itpro.com/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher" data-original-url="https://www.itpro.com/security/ransomware/363893/conti-ransomware-data-leaked-ukranian-researcher">Conti cyber crime group</a> and saw employees granted bonuses based on exemplary performance or fines due to poor productivity. </p><h2 id="risk-and-reward">Risk and reward </h2><p>The reasoning behind some dark web users seeking roles can vary, researchers suggested. Some may be seeking alternative income streams while others may have lost jobs during the onset of the pandemic in 2020. </p><p>“People may have several reasons for going to a dark web site to look for a job. Many are drawn by expectations of easy money and large financial gain,” researchers wrote. </p><p>The study also noted that while some jobs advertised on the dark web offered more than what an individual could earn legally, there was little difference between the average level of IT professionals’ pay on both sides of the legal divide.</p><p>“Although dark web jobs could be expected to pay higher than legitimate ones, we did not detect a significant difference between the median levels of <a href="https://www.itpro.com/business-strategy/careers-training/369778/how-it-professionals-can-boost-their-career-in-the-new" data-original-url="https://www.itpro.com/business-strategy/careers-training/369778/how-it-professionals-can-boost-their-career-in-the-new">IT professionals</a>’ compensation in the cyber criminal ecosystem and the legitimate job market.” </p><h2 id="accelerating-operations">Accelerating operations</h2><p>Rik Ferguson, VP of security intelligence at Forescout, told <em>IT Pro</em> this research highlights the growing sophistication of cyber criminal groups and their demand for technical expertise across a range of fields. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rNAQoa9nwMcMG72HQokQfh" name="rNAQoa9nwMcMG72HQokQfh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" mos="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Storage's role in addressing the challenges of ensuring cyber resilience</strong></p><p class="fancy-box__body-text">Understanding the role of data storage in cyber resiliency</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber" data-original-url="/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber">FREE DOWNLOAD</a></p></div></div><p>“For many years now, cyber crime has been a highly distributed and specialised field. One criminal gang might contract out specific requirements to independent specialists offering services such as 'crypting', escrow, money mules, coding, and many more,” he said. </p><p>“Recently though, some of the more established and successful ransomware threat actors (<a href="https://www.itpro.com/security/369783/lockbit-issues-rare-apology-for-toronto-sickkids-ransomware-attack" data-original-url="https://www.itpro.com/security/369783/lockbit-issues-rare-apology-for-toronto-sickkids-ransomware-attack">LockBit</a> for example) have hired professionals, particularly in software development, directly into their operation.”</p><p>Ferguson added that this recruitment trend could be due to a need to improve operational efficiency and maximise the impact of offensive capabilities. </p><p>“Some of this is for efficiency, the ability to control the development of a more effective 'product' and thus recruit more affiliates to spread the ransomware,” he said. “Some of it may well be driven by competitive and confidentiality concerns around keeping their operation insulated, both from their criminal competition and from law enforcement.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US extradites French ShinyHunters hacker, faces 123 years in prison ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369967/us-extradites-french-shinyhunters-hacker-faces-123-years-in-prison</link>
                                                                            <description>
                            <![CDATA[ The hacker is believed to be a member of the hacking group known for its spree of data breaches across 2020 and 2021 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nvA2Ky9Z7fXMZEDCEQasx9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oYDfG52QZQa82XWH3MszoP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Jan 2023 10:45:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oYDfG52QZQa82XWH3MszoP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hacker wearing black gloves using a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A hacker wearing black gloves using a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A hacker wearing black gloves using a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oYDfG52QZQa82XWH3MszoP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US has successfully extradited a French hacker accused of committing cyber crime on behalf of the ShinyHunters group.</p><p>Sebastien Raoult, 21, faces a maximum prison sentence of 123 years if found guilty on all charges on his nine-count indictment.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets" data-original-url="/security/hacking/357971/how-do-hackers-choose-their-targets">How do hackers choose their targets?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act" data-original-url="/security/357833/cyber-professionals-worried-theyve-violated-the-computer-misuse-act">80% of cyber professionals say the Computer Misuse Act is working against them</a></p></div></div><p>The allegations against him include conspiracy to commit computer fraud and abuse, conspiracy to commit wire fraud, four counts of wire fraud, and three counts of aggravated identity theft for using other people’s login credentials.</p><p>Originally arrested in Morrocco last year, Raoult was finally extradited to the US last week and will be kept in detention until April to face his next hearing.</p><p>His alleged crimes included hacking into running phishing pages that imitated legitimate businesses to steal login credentials. These were then used to hack into corporate systems and steal information of value.</p><p>“Too many bad actors believe they can illegally access proprietary information and personal financial information by hiding behind a keyboard,” <a href="http://intrusion">said</a> Nick Brown, US attorney for the Western District of Washington. </p><p>“FBI Seattle Cyber Task Force and our experienced cyber unit is working diligently to identify, arrest, and prosecute those who seek to victimise people, businesses, and industries in the Western District of Washington and around the world.”</p><h2 id="what-is-the-shinyhunters-hacking-group">What is the ShinyHunters hacking group?</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XDpMcyCkWZKyuSYDHyEDuV" name="XDpMcyCkWZKyuSYDHyEDuV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" mos="https://cdn.mos.cms.futurecdn.net/XDpMcyCkWZKyuSYDHyEDuV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>IDC MarketScape: Worldwide unified endpoint management services</strong></p><p class="fancy-box__body-text">2022 vendor assessment</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services" data-original-url="/security/endpoint-security/369801/idc-marketscape-worldwide-unified-endpoint-management-services">FREE DOWNLOAD</a></p></div></div><p>The ShinyHunters group is believed to have been formed in 2020 and participated in various cyber criminal activities including hacking, phishing, stealing data, and extorting victims.</p><p>ShinyHunters’ Twitter profile display picture is set as an image of Umbreon, a Pokémon character, suggesting the name of the group is derived from the game’s task of hunting for rare, shiny creatures.</p><p>The group hasn’t been in operation for long, in comparative terms, but it has claimed a large number of successful data breaches, including one on Microsoft in May 2020 which saw the theft of more than 500GB worth of source code from its private <a href="https://www.itpro.com/open-source/31833/what-is-github" data-original-url="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> page.</p><p>Other notable incidents claimed by ShinyHunters include those affecting <a href="https://www.itpro.com/security/hacking/355790/massive-wishbone-app-hack-exposes-40m-users-data" data-original-url="https://www.itpro.com/security/hacking/355790/massive-wishbone-app-hack-exposes-40m-users-data">Wishbone</a> and Tokopedia, both also in May 2020, <a href="https://www.itpro.com/security/data-breaches/358406/pixlr-data-breach-exposes-over-19m-users-info" data-original-url="https://www.itpro.com/security/data-breaches/358406/pixlr-data-breach-exposes-over-19m-users-info">Pixlr</a>, Mashable, and Pluto TV.</p><p>Unlike its <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets" data-original-url="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets">target selection</a>, which never followed any obvious patterns, ShinyHunters’ attack methods were more uniform in nature.</p><p>Members would typically steal legitimate login credentials through <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a> or buy them on the black market. </p><p>Those would then be used to access private information from businesses to steal, sell, and leverage in <a href="https://www.itpro.com/security/ransomware/369222/what-is-triple-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/369222/what-is-triple-extortion-ransomware">extortion</a> scenarios.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: The problem with APIs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/application-programming-interface-api/369956/the-it-pro-podcast-the-problem-with-apis</link>
                                                                            <description>
                            <![CDATA[ With API attacks on the rise, knowing your attack surface is crucial ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wDF3u57u6LB7CeLDggb5qH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AUzviU6XSmBNTGGrhF5M8j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Jan 2023 13:15:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AUzviU6XSmBNTGGrhF5M8j-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode number 158 and title &amp;#039;The problem with APIs&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode number 158 and title &amp;#039;The problem with APIs&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode number 158 and title &amp;#039;The problem with APIs&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AUzviU6XSmBNTGGrhF5M8j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Application programming interfaces, or APIs, have become an integral part of maintaining an online business, and are often indispensable for cross-functionality and user experience.</p><p>However, the increased use of APIs has led to a rise in attacks against them. This can in turn cause breaches of company data or even full account takeovers. Improperly-managed APIs are a key attack surface and firms would do well to treat this seriously as threat actors step up their efforts at exploitation.</p><p>In this episode, Rory and Jane are joined by Yaniv Balmas, VP of security research at Salt Security, to discuss the risks that come with using APIs and how to mitigate against them.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52558420&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights-2">Highlights</h2><p>“When you're speaking a different language than the service is expecting to hear, there could be one of many, many, many issues that will follow starting from very simple things like, you know, simple error page or server crash or something like that. And ranging up into, you know, information disclosure, full account takeovers, and stuff like that.”</p><p>“As time passes, yeah, more attackers join this API attacking club, and that's why we see this increase. And if you're asking my predictions on the future I don't see that stopping or, you know, start being in lower volumes. Quite the opposite.”</p><p>“If it's a third party tool that you're using, then you need to test it to make sure that, you know, it complies with everything and that it stops everything, all the relevant API attacks. And then finally, once you've deployed your solution, that's not enough because this world is constant, it's dynamic. It's constantly changing. There are always new attacks, every day you hear about new techniques and a new attack.”</p><p><a href="https://www.itpro.com/development/application-programming-interface-api/369955/podcast-transcript-the-problem-with-apis" data-original-url="https://www.itpro.com/development/application-programming-interface-api/369955/podcast-transcript-the-problem-with-apis"><em>Read the full transcript here.</em></a></p><h2 id="footnotes-2">Footnotes</h2><ul><li><a href="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced" data-original-url="https://www.itpro.com/development/application-programming-interface-api/358546/nearly-every-company-surveyed-experienced">90% of businesses experienced API security vulnerabilities in 2020</a></li><li><a href="https://www.itpro.com/security/vulnerability/369800/luxury-cars-emergency-vehicles-vulnerable-remote-takeover" data-original-url="https://www.itpro.com/security/vulnerability/369800/luxury-cars-emergency-vehicles-vulnerable-remote-takeover">Research: Luxury cars and emergency services vehicles vulnerable to remote takeover</a></li><li><a href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">Hyundai vulnerability allowed remote hacking of locks, engine</a></li><li><a href="https://salt.security/blog/4-things-to-know-about-your-car-and-api-security">4 Things to Know about Your Car and API Security</a></li><li><a href="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know" data-original-url="https://www.itpro.com/application-programming-interface-api/33557/the-api-economy-what-your-business-needs-to-know">The API economy: What your business needs to know</a></li><li><a href="https://www.itpro.com/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach" data-original-url="https://www.itpro.com/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach">T-Mobile customers at heightened risk of phishing attacks in wake of data breach</a></li><li><a href="https://www.itpro.com/security/368704/twitter-api-leaks-found-in-over-3200-apps-prompt-security-concerns" data-original-url="https://www.itpro.com/security/368704/twitter-api-leaks-found-in-over-3200-apps-prompt-security-concerns">Twitter API keys found leaked in over 3,200 apps, raising concerns for linked accounts</a></li><li><a href="https://www.itpro.com/strategy/27631/could-apis-be-your-business-secret-weapon-1" data-original-url="https://www.itpro.com/strategy/27631/could-apis-be-your-business-secret-weapon-1">Could APIs be your business' secret weapon?</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: The problem with APIs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/development/application-programming-interface-api/369955/podcast-transcript-the-problem-with-apis</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nHVDE9BrNP6HxN8Bh4sbR2</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ip6nasbMxYdw39sPVKxYXc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 27 Jan 2023 13:15:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ip6nasbMxYdw39sPVKxYXc-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with subheading &amp;#039;Transcript&amp;#039; and the episode title &amp;#039;The problem with APIs&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with subheading &amp;#039;Transcript&amp;#039; and the episode title &amp;#039;The problem with APIs&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with subheading &amp;#039;Transcript&amp;#039; and the episode title &amp;#039;The problem with APIs&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ip6nasbMxYdw39sPVKxYXc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>​​This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/development/application-programming-interface-api/369956/the-it-pro-podcast-the-problem-with-apis" data-original-url="https://www.itpro.com/development/application-programming-interface-api/369956/the-it-pro-podcast-the-problem-with-apis">The problem APIs</a>'<em>. We apologise for any errors.</em></p><h2 id="rory-bathgate-2">Rory Bathgate </h2><p>Hi, I'm Rory Bathgate.</p><h2 id="jane-mccallion-2">Jane McCallion</h2><p>And I'm Jane McCallion.</p><h2 id="rory-9">Rory </h2><p>And you're listening to the IT Pro Podcast, where today we're discussing API vulnerabilities.</p><h2 id="jane-9">Jane </h2><p>Application programming interfaces, or APIs, have become an integral part of maintaining an online business, and can be incredibly useful in facilitating cross-functionality and improving user experience.</p><h2 id="rory-10">Rory </h2><p>However, the increased use of APIs has led to a rise in attacks against them, which can lead to breaches of company data or even full account takeovers.</p><h2 id="jane-10">Jane </h2><p>Today, we're speaking to Yaniv Balmas, VP of Security Research at Salt Security, to discuss the threats facing businesses that use APIs and how to mitigate them.</p><p>Yaniv, thanks so much for joining us.</p><h2 id="yaniv-balmas">Yaniv Balmas </h2><p>Hi, it's a pleasure being here. Thanks for inviting me.</p><p>Rory </p><p>So to start off with Yaniv, if you wouldn't mind, could you start by unpacking the concept of APIs and where they're commonly used?</p><h2 id="yaniv">Yaniv </h2><p>Well yeah, it's actually pretty easy to understand. APIs are sort of a language. And that's a language that modern services, online services talk. So you know that everyone, in every company, every business today that wishes to go online has some kind of services published over the internet. And the way or the language that allows users or machines to interact with the service is called APIs. That's basically what it is.</p><h2 id="jane-11">Jane </h2><p>And so obviously, we're here to talk about security problems with APIs, what kind of attacks are levelled against them? And are they more vulnerable than any other kind of potential attack surface?</p><h2 id="yaniv-2">Yaniv </h2><p>Well as I said, APIs are a language and language is a complex thing. Basically, there isn't only one language, there are several languages in which this service talks and people can basically invent their own languages as well. Now, inventing languages or using languages, or languages in general as I said, are a complex thing. And it's very easy to make mistakes, or to have flaws in this language, or words that don't come into place and stuff like that. When you do it in normal language, your sentence will be misunderstood maybe. When this happens with services, the consequences can be much more severe. When you're speaking a different language than the service is expecting to hear, there could be one of many, many, many issues that will follow starting from very simple things like, you know, simple error page or server crash or something like that. And ranging up into, you know, information disclosure, full account takeovers, and stuff like that. That's the consequences of languages or API errors in our day and age.</p><h2 id="rory-11">Rory </h2><p>So a lot of businesses use APIs to communicate between different servers or different front end and back end websites. Do you think that there's a tendency for businesses to maybe spread themselves too thin with their APIs? Or are businesses adopting them on too broad a scale?</p><h2 id="yaniv-3">Yaniv </h2><p>So if you look at, you know, the growth of APIs over the past, I don't know not a lot, five, six years. I mean, if we would draw it on a graph, it would be an exponentially growing graph really, really high. So everybody, basically everybody wants to have online services today. And if you don't, if you're a business, and you don't have an online service, probably you're gonna move to doing that or you will be basically out of business. So everybody's rushing to put services and to define new APIs, and to put them out there. And you know, basically, human nature to favour functionality over securities, it will always be functionality first, these this is what my customers expect to have. So I will first give them that and then I will go and dive deep and check if everything is secure, or no and that is not a specific problem with APIs. It's with every new technology anywhere, right? But this dramatic increase in usage of APIs is what makes this really, really, really important today and the amount of issues flows vulnerabilities that we have seen in APIs is absolutely breathtaking. I mean, it's there's just so many issues out there that still needs to be addressed.</p><h2 id="jane-12">Jane </h2><p>So Yaniv, when we're talking about this talk from sort of a fairly technical-type view, a slightly abstract type view. To put this into concrete terms for our listeners, what does an API attack look like? What is an example of an API attack?</p><h2 id="yaniv-4">Yaniv </h2><p>Okay, let me give you a pretty naive example. It's very understandable, you don't need to be really technical to understand it. And I think it showcases also the potential impacts. So let's assume that you're using some kind of, let's say, online document service. Okay? So using this service, you can basically edit documents, you can view them, you can delete them, you can share them and everything, everything else. Now, think about it for a second, what happens when you try to delete a document? Basically, your computer following your click on delete the document, will send the request to the server and this request will go to the API of the of the service, right? And it will say, "okay, operation, delete", and document ID, "this is the document ID that I want you to delete". The document should be deleted right? Now, there's a really important thing here. Because the server must make sure that the document that you are requesting to be deleted, is actually owned by you, it's your document, you actually have permissions to delete it. And when the server fails to do that, that's where vulnerability has happened. So and you know, it sounds, it might sound like a pretty naive example. But you'd be surprised of how many of these exact examples do we find each and every day. So basically, if I were an attacker, that would allow me to pretty easily delete every document in the system or a specific users' document, all I need to know is the document ID. Sometimes it's easier to know that, sometimes it's harder to know that. But in both cases, it is possible. That specific vulnerability, by the way, is called 'BOLA' - broken object level authorization. So that's the technical term for that.</p><h2 id="jane-13">Jane </h2><p>So it sounds almost like it's a configuration problem, rather than a problem with APIs. in and of themselves.</p><h2 id="yaniv-5">Yaniv </h2><p>I wouldn't call that a configuration problem. I would call that a software engineering problem, a bug somebody... that definition, basically, we just described every vulnerability out there, whether it's APIs or not APIs, or software engineering bugs, and that's no different.</p><h2 id="rory-12">Rory </h2><p>So to get specific, Salt's Q3 2022 report found that your customers experienced a 117% increase in API attack traffic, while their overall API traffic grew by 168%. What's leading to these attacks? And are these numbers likely to remain high?</p><h2 id="yaniv-6">Yaniv </h2><p>What's leading to these attacks? Well look, the vulnerabilities are out there. It's a relatively new field, as we said, which is why the vulnerabilities are there in the first place. But you know, from the other side of that, attackers whether they are cyber criminals or just kids playing with APIs, nations trying to do things, they are new to that field as well. So they are learning how to attack as well as we are learning how to defend. And as time passes, yeah, more attackers join this API attacking club, and that's why we see this increase. And if you're asking my predictions on the future, I don't see that stopping or, you know, start being in lower volumes. Quite the opposite. I see that keep increasing, and even increasing more than what we've just seen. So there's, there could be a pretty direct relation between the growth of APIs and the growth in the number of attacks.</p><h2 id="jane-14">Jane </h2><p>Kind of from my point of view, it's a bit easy to be, I want a better word than 'cynical' because I don't want myself to show myself in a terrible light, however, about these kinds of numbers here, 117 and 168 look massive, but it depends on your starting point. Obviously, if your overall API traffic is growing by 168, and your starting point was several thousand, then that's kind of a big number. But if your API attack numbers are 117% sure, but if that's your starting point was two, then that's it's a big increase but the actual numbers are smaller than it appears. So do you know what we're looking at in terms of those? The actual comparison between API traffic and API attack traffic?</p><h2 id="yaniv-7">Yaniv </h2><p>Yes, of course. And I think it all boils down to the question of how do we actually get those statistics? There could be many ways to do that. So we can, for example, count each and every request and count each request has an attack. We don't do that. Because if you do that, numbers will be dramatically higher. We try to aggregate attacks and kind of, you know say "okay, all of these requests, it may be ten requests, a thousand requests, a hundred thousand requests. All of these relates to the same attacker in the same attack", and that's counted is one. So when you say the number, if you want, if somebody else would have counted it, it might be a million. It all depends on how you count. And let me tell you, report or no report, statistics, or no statistics me and my group and other people deal with these cases each and every day. And let me tell you, this is an issue. It's a real issue. It's everywhere. We see vulnerabilities everywhere, and we also see attacks everywhere. You don't you don't necessarily need to believe us when we say that, but you know, just go and read the news. I think that almost every week or so, there's another catastrophe being published with another huge vendors’ APIs. So it's really apparent that this issue is out there, and the numbers are really high.</p><h2 id="jane-15">Jane </h2><p>I'm sorry, I know a bit of a follow up question. Rory's not getting any questions today. Talking around all this, do you have any insight on who these attackers actually are? You kind of mentioned nation states and professional hackers, and what we would have called script kiddies back in the day. Yeah with API attacks, is it more appealing to any one of them than others, to somebody doing more sophisticated stuff? Or is it across the board, everybody's going down this route?</p><h2 id="yaniv-8">Yaniv </h2><p>That's a pretty good question. And you know, in fact, one of the hardest thing to do when you're analysing attack is to understand who exactly is the attacker and what is the motivation? It's not always possible, it is possible sometimes. I can tell you that look, let's take our attackers' spectrum and divide it into, let's say, three major parts. As we said, there is the very, very high end, which is nation state sponsored attacks, right? They are cutting edge, they have unlimited budget and unlimited resources. Whether or not you look at attacks, or you identified if they are attacking, I can assure you that in a very high probability they are already playing this game, right? But that's very specific. And probably if it's nation state, then the targets are also pretty specific. Depends on the nation, probably. But that's one part of them. That's not a surprise, because they do everything from everything, right? The middle part of that, the more let's say technological researchers, hackers, whatever you want to call them. Yeah, they are slowly starting to move to this area. And you see a lot of more research being published on APIs. So they are basically motivated, usually, by financial. So they are cyber criminals. They want to attack you, because at the end of the day they want to steal your money in that way or the other. And they do it really well today with other attack vectors, other than APIs. And slowly we see them, you know, starting to realise that, "okay, that's also an attack vector. And it's out there, might be easier to do than, you know, the other attacks that I'm doing". So we see a gradual shift of cybercrime going into API attacks. But then there's the, that's the really interesting part of that, there is the low end of that, as you said, the 'script kiddies'. Just you know, some people playing with computers, not necessarily very technologically advanced. They don't know anything. The nature of API attacks, you know, maybe finding a vulnerability in APIs might not be that easy. But once you found this vulnerability, it's so easy to replicate that. Any kid basically can just, you know, pick up his computer and do that. It's really that easy. And in, you know, in this day and age where information sharing is just everywhere, you just need, it's like, it's like fire, spreading fire. If just someone would identify that, post that in the wrong forum, you will immediately see just a few hours later, a bunch of attacks happening on that specific vector. And that's, I would say that that's not very common for all attack vectors. I'm not talking about APIs for others, sometimes the technological bar is pretty high. So even if you know the vulnerability, it's not really trivial to use that in APIs. That's not the case. If you know the vulnerability, it's completely effortless to do that, which is basically what makes them even more dangerous in my mind. Yeah.</p><h2 id="rory-13">Rory </h2><p>So it's, in some ways, it's a path of least resistance thing where it's just APIs are, in some ways, the go-to for an easy attack on an organisation?</p><h2 id="yaniv-9">Yaniv </h2><p>If you're a good researcher, or a good hacker, a path of least resistance is always the way that you go. You will never want to waste too much time or effort on doing something if you have an easier option to do that. </p><h2 id="rory-14">Rory </h2><p>Right, yeah. On a specific example of API attacks, security researchers recently discovered API flaws that allowed them to remotely unlock luxury cars, and access functions such as parking cameras. You, in fact, commented on that for us in the article we published on it a short time ago. Cars are kind of a flashy example, but is business hardware similarly vulnerable to attacks such as these.</p><h2 id="yaniv-10">Yaniv </h2><p>The problem is not with the hardware. It's, yeah, the hardware is there. And APIs can communicate with hardware just as well as they communicate with software. Basically, APIs is, as I said, it's the language, it's what wraps your technology, whatever it will be. An embedded device, a web service or anything else, right? So cars in that respect, are no different than any other online services. The only question is, what functionality is exposed over these APIs? And as you saw from the published research, and as we see from other very similar research that we internally did, yes car manufacturers as all other businesses, they tend to publish a lot of services out there. And to expose them over APIs, as I said, in favour of the customers to make their life easier to make the cars more accessible. It's all about functionality. And, again, as I said, security always comes second. And that's a wonderful example for that.</p><h2 id="jane-16">Jane </h2><p>Yeah, I suppose if you can remotely turn off my heated seat, then you know I'll have a cold bum, but it's not going to be the worst thing in the world. Whereas if you can remotely disable or mess with my cruise control or rev limiter or anything like that, then that's going to be a bit more of an issue.</p><h2 id="yaniv-11">Yaniv </h2><p>Exactly. Just, you know, initiate your ABS when you're not expecting it. Think about the consequences. </p><h2 id="jane-17">Jane </h2><p>Yeah.</p><h2 id="rory-15">Rory </h2><p>So with all of that in mind, with that kind of terrifying example, what measures can an IT decision maker implement to protect APIs against attacks?</p><h2 id="yaniv-12">Yaniv </h2><p>Well, the first thing you need to do when you want to protect something is to understand that there is something that needs to be protected. Unfortunately, in many cases, that's not how it happens. I think many organisations, many businesses today, especially if they are not coming from the technology market, they are not really aware of the risks in APIs. I mean, they understand that they expose more functionality there, and they don't understand that it comes with a risk. And I think that understanding the risk is the first step, it's almost 50%, of finding the solution to that. And really, by the way, in Salt Labs, that's our main goal is to educate people to shout out that, "hey, guys, these wonderful new APIs that you have out there, they're wonderful. That's right. But they're also an issue and you need to understand that". But once you understand that there is an issue there, then really there are a lot of things that can be done. And it's really not very different from dealing with any other type of vulnerability that you have. So if this is a product that you are developing, if it's code that you wrote, then you need to practise secure development and to understand the common API issues and address them in the development stage. If it's a third party tool that you're using, then you need to test it to make sure that, you know, it complies with everything and that it stops everything, all the relevant API attacks. And then finally, once you've deployed your solution, that's not enough because this world is constant, it's dynamic. It's constantly changing. There are always new attacks, every day you hear about new techniques and a new attack. So a good idea would also be to monitor in real time your API traffic, try to understand what it means and look for any anomalies. So there are things that you might know, I mean, you know what to look for and other things, you know, that they could be there, but you don't exactly know what to look for. So monitoring for anomalies could really help you out in, you know, pinpointing those places where something bad could happen. And then finally, there's not maybe not related to the vulnerabilities themselves, but you need a good incident response. So if something does happen, you need to make sure you know how to deal with that. And to kind of confine the impact, so it won't be too dramatic. So that's my two cents of protecting APIs.</p><h2 id="jane-18">Jane </h2><p>I mean, this is all well and good for larger companies who have their own IT departments, who are doing their own development. The UK or Great Britain was famously demeaned by Napoleon, actually, as "a nation of shopkeepers". And we still, maybe not shopkeepers, but we are most of our companies operating here, most of our businesses are small businesses, micro businesses, maybe medium at the top end something like 99%. How can these organisations that almost certainly rely on external IT companies, whether that's sort of a some kind of channel partner, or they've just outsourced the whole thing because they're a three person band, and their speciality is audio mastery, or whatever. What should they be doing? Is there anything that they can actively do to protect themselves? Or is this something they should be looking for, and discussing with whoever they are working with?</p><h2 id="yaniv-13">Yaniv </h2><p>Yeah, so I think the, if you ask me personally, I think the second option is the more realistic one, right? Because if you're a small or medium business you don't do any development, you only trust third-party vendors to provide everything that you need, then you need to trust this vendor to be able to handle API security as well. And it's no different than you go and buy your own, I don't know, Windows operating system right? Now you trust Microsoft to make sure that this operating system will not have any vulnerabilities, and they are doing a pretty good job of that. Not, it's not dramatic of course, there are vulnerabilities, but they've been doing an increasingly good job at that over the past years. And the same expectations should stand for APIs as well. If you're uneducated in that, if you're not technological, it will be very hard for you to try and test how good this product handles API issues. But it's really the same thing with any other type of vulnerabilities. So yeah, again, API in these regards is not very different, you're just taking it one level higher. So if you don't, if you can't protect or make sure your APIs are protected, then your vendor should do that for you. So it takes the problem to the vendors' front door, and now they need to address that. Some, by the way, address that pretty well. Others, not yet.</p><h2 id="rory-16">Rory </h2><p>So having discussed all of this, given the fact that API's are apparently such a popular attack vector, does the benefit of using them really outweigh the risk?</p><h2 id="yaniv-14">Yaniv </h2><p>Can you imagine your life without APIs? Well, maybe you know, maybe you don't know what APIs are. Let's assume that. But let me tell you that today, according to statistics that we didn't do, we looked at other who did these specific statistics, around 80% of all your web traffic is routed through APIs in that way or another think about it. When you're shopping online you're using APIs. When you want to check your COVID certificate, you're using APIs. When you want to do a voice recording and store it in the cloud, you're using APIs. Almost everything, every function that you are using today, over the web is using APIs. So I would say that, you know, taking APIs down because they are risky. In my personal opinion, wouldn't not be the smart thing to do. Yeah, we need to grow forward with technology makes our lives easier. It moves us forward. But yes, we must always understand that new technology comes with new risks, and we need to address them. The real problem comes when we don't understand that there is a risk, or if we don't address it. If we will do both of them, we'll be in a much better situation than we are today. And I think that slowly, gradually, we are getting there. We're still not there, it will take some time. But this podcast might also help a bit in doing that, I hope.</p><h2 id="jane-19">Jane </h2><p>Well, unfortunately, that's all we've got time for this week. But thank you very much to Yaniv Balmas of Salt Security for joining us.</p><h2 id="yaniv-15">Yaniv </h2><p>Thank you very much. It was my pleasure.</p><h2 id="jane-20">Jane </h2><p>Thank you. As always, you can find links to all of the topics we've spoken about today in the show notes, and even more on our website at itpro.co.uk.</p><h2 id="rory-17">Rory </h2><p>You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro podcast wherever you find podcasts. And if you're enjoying the show, why not tell a friend or colleague about us.</p><h2 id="jane-21">Jane </h2><p>We'll be back next week with more from the world of it. But until then, goodbye goodbye</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA: Phishing campaign targeting US federal agencies went undetected for months ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/369942/cisa-phishing-campaign-federal-agencies-undetected-for-months</link>
                                                                            <description>
                            <![CDATA[ Threat actors used legitimate remote access software to maliciously target federal employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gRhdcSP5BVzXPatsqLBvLs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jan 2023 13:08:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:description>                                                            <media:text><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US' Cybersecurity and Infrastructure Security Agency (CISA) has revealed that several federal civilian executive branch (FCEB) agencies have fallen victim to a widespread phishing campaign.</p><p>The campaign abused legitimate remote monitoring and management (RMM) software and emails were sent to staff starting in the middle of 2022. The majority were themed around helpdesk emails falsely notifying victims that they had been sent an accidental refund, or needed to cancel a subscription. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/programming-languages/369932/report-regulatory-monetary-incentives-adopt-safe-programming-languages" data-original-url="/development/programming-languages/369932/report-regulatory-monetary-incentives-adopt-safe-programming-languages">Report: Regulatory and monetary incentives needed to adopt safer programming languages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage" data-original-url="/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage">Mailchimp data breach impact unravels as second customer reveals extent of damage</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369252/cisa-issues-orders-to-polish-vulnerability-detection-in-federal-agencies" data-original-url="/security/369252/cisa-issues-orders-to-polish-vulnerability-detection-in-federal-agencies">CISA issues fresh orders to polish security vulnerability detection in federal agencies</a></p></div></div><p>Links included in the emails led to a first-stage malicious domain which would launch an executable that connected to a second-stage domain that downloaded an RMM program. </p><p>CISA said threat actors would remotely monitor the victim’s screen and instruct them to access their bank account, then alter the balance to make it seem as though the victim had been sent money. They would then instruct for the 'excess' amount to be sent back to an account set up for the scam.</p><p>Although the agency did not provide specifics on the scam, its description bears a strong resemblance to the methods used prevalently by online scammers targeting vulnerable civilians.</p><p>Often claiming to be calling from tech support at a large company, such as Microsoft, they would block the victim's view of their display using the RMM tools and use a browser's 'inspect element' function to make the bank balance appear as though it had changed.</p><p>According to CISA's account, the threat actors used <a href="https://www.itpro.com/mobile/remote-access/368052/what-is-anydesk" data-original-url="https://www.itpro.com/mobile/remote-access/368052/what-is-anydesk">AnyDesk</a> and ScreenConnect as portable executables, which can run without administrator privileges and are not flagged as malicious by <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> programs or <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">malware removal tools</a>.</p><p>This allowed the software to run without being approved by network administrators at the affected agencies, and could have facilitated an attack on devices that shared an intranet with that of the victim.</p><p>Another method saw threat actors send victims emails urging victims to call a phone number on similar financial pretences to the emails containing links. They would then be urged to manually navigate to one of the threat actors’ malicious domains.</p><p>In June 2022, one FCEB employee called the number and was given instructions to open a malicious domain on their device. At the time the CISA detected the campaign in October 2022, traffic was being sent and received between a compromised FCEB server and the malicious domain ‘myhelpcare[.]cc’.</p><p>"Targets can include managed service providers (MSPs) and IT help desks, which regularly use legitimate RMM software for technical and security end-user support, network management, endpoint monitoring, and to interact remotely with hosts for IT-support functions," the CISA said.</p><p>"These threat actors can exploit trust relationships in MSP networks and gain access to a large number of the victim MSP's customers. MSP compromises can introduce significant risk - such as <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> and <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a> - to the MSP’s customers."</p><p>The CISA has urged organisations to follow best practices for blocking phishing emails, and train employees to recognise techniques used by <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineers</a>.</p><p>It has additionally recommended the use of enhanced application controls to prevent the installation and execution of portable unauthorised RMM software, and for RMM ports to be blocked at network perimeters.</p><p>In an <a href="https://www.cisa.gov/uscert/ncas/alerts/aa23-025a">advisory</a>, the CISA noted that the threat actors behind the campaign appear to have run it for profit only but that similar techniques could be used by threat actors for significant harm.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L47gbigPjNi8zfgWvSgmk3" name="L47gbigPjNi8zfgWvSgmk3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" mos="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 Magic quadrant for Security Information and Event Management (SIEM)</strong></p><p class="fancy-box__body-text">SIEM is evolving into a security platform with multiple features and deployment models</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security" data-original-url="/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security">FREE DOWNLOAD</a></p></div></div><p>The CISA, National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) SAID that threat actors could have sold remote access to victim accounts to more dangerous groups such as advanced persistent threat actors (APTs).</p><p>The agencies also warned that the attacks prove the potential for legitimate <a href="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions" data-original-url="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions">RMM programs</a> to be used by threat actors to seize control of devices remotely, and bypass administrator controls to launch <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> operations.</p><p>“In October, CISA identified a widespread cyber campaign in which cyber criminal actors leveraged RMM software to gain command and control of devices and accounts,” said the NSA in its <a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3277084/nsa-cisa-and-ms-isac-release-guidance-for-securing-remote-monitoring-and-manage">press release</a>.</p><p>“Malicious cyber actors could leverage these same techniques to target National Security Systems (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) networks and use legitimate RMM software on both work and home devices and accounts. Other RMM software solutions could be abused to similar effect.”</p><p>Over the past 12 months, the CISA has enacted strong, government-wide policies to strengthen the nation's cyber security posture. A notable example from the past year, was the bill that passed in August <a href="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military" data-original-url="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military">outlawing software containing any vulnerabilities</a> to ensure secure-by-design federal systems.</p><p>In November 2021, it also launched a 'mandatory patch list' for FCEB agencies to abide by. This was comprised of the most dangerous and commonly exploited security vulnerabilities, complete with deadlines for each agency by which to apply the patches.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GoTo admits hackers stole customer backups in LastPass breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369934/goto-admits-hackers-stole-customer-backups-in-lastpass-breach</link>
                                                                            <description>
                            <![CDATA[ In addition to losing encrypted backups such as hashed passwords, the firm has confirmed hackers stole an encryption key relating to the data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fFEhvD47SGgL8xAw9eMrwX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 25 Jan 2023 12:51:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:description>                                                            <media:text><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:text>
                                <media:title type="plain"><![CDATA[A gloved cartoon hand inserts a key, the teeth of which are asterisks, into a keyhole against a red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Xc9cJjVRxpdm2RMqm7XXPY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Communications firm GoTo has revealed that threat actors stole encrypted customer backups and sensitive product information in a November 2022 attack, which also affected subsidiary LastPass.</p><p>The firm has stated that account usernames, salted and hashed passwords, and multi-factor authentication (MFA) settings were included in the stolen information which was taken from a third-party cloud storage service in the November incident. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LTMrgEvSNMdUH7gB9RYH7b" name="LTMrgEvSNMdUH7gB9RYH7b.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" mos="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Automate security intelligence with IBM Security QRadar SIEM</strong></p><p class="fancy-box__body-text">Simplify and improve threat detection, investigation and response with reducing overheads</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem" data-original-url="/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem">FREE DOWNLOAD</a></p></div></div><p>Although this customer backup data is encrypted, the company believes that the threat actor behind the attack also stole an encryption key for a portion of the stolen backups.</p><p>GoTo stated that the key related to a “portion” of the data, but did not elaborate on which files are vulnerable to decryption by the threat actor.</p><p>As GoTo does not store payment details, nor collect or store user addresses, dates of birth, or other such identifiable information, data of this kind was not included in the breach.</p><p>The company has also warned that backups relating to other services it runs were stolen, such as its <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private network (VPN)</a> product Hamachi and <a href="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions" data-original-url="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions">remote access applications</a> Central and Pro.</p><p>GoTo subsidiary LastPass had commenced an investigation in collaboration with Mandiant following <a href="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach" data-original-url="https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach">a breach in November 2022</a> that saw threat actors access a third-party cloud storage system used by both LastPass and GoTo.</p><p>“At this time, we have no evidence of exfiltration affecting any other GoTo products other than those referenced above or any of GoTo’s production systems," said Paddy Srinivasan, CEO at GoTo, in a <a href="https://www.goto.com/blog/our-response-to-a-recent-security-incident" data-original-url="https://www.goto.com/blog/our-response-to-a-recent-security-incident#">blog post</a>.</p><p>"We are contacting affected customers directly to provide additional information and recommend actionable steps for them to take to further secure their account."</p><p>GoTo has stated it will provide advice for next steps for making affected accounts secure. Customers who were impacted by the breach will have passwords reset as a precautionary measure, and MFA settings reauthorised.</p><p>The firm has also committed to migrating accounts to an <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy" data-original-url="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity management</a> platform, to further secure accounts against possible future action.</p><p>This is the third attack impacting GoTo and its subsidiaries in the past 12 months. In August 2022 a <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">hacker exfiltrated LastPass source code</a>, though Karim Toubba, CEO at the firm, denied that customer information had been impacted in this breach. </p><p>Since then, the <a href="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely" data-original-url="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely">LastPass admitted encrypted password vaults were stolen</a>, and that names, email addresses, phone numbers and payment information. This has prompted concerns that stolen data could be used for mass <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage" data-original-url="/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage">Mailchimp data breach impact unravels as second customer reveals extent of damage</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach" data-original-url="/security/369900/t-mobile-customers-at-heightened-risk-of-phishing-attacks-in-wake-of-data-breach">T-Mobile customers at heightened risk of phishing attacks in wake of data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></p></div></div><p>“Any breach is unfortunate for all those impacted,” said Javvad Malik, lead security awareness advocate at KnowBe4.</p><p>“While in this case the data was encrypted, the fact that the decryption keys were also stolen renders the encryption worthless. Therefore, impacted customers should treat this as a complete breach of all data and take the necessary steps to protect themselves from any fallout. </p><p>“This can include changing their passwords and being on the lookout for any phishing or social engineering scams which can be crafted using the stolen data.”</p><p><em>IT Pro</em> has approached GoTo for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GTA V vulnerability exposes PC users to partial remote code execution attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/369913/gta-v-vulnerability-exposes-pc-users-to-remote-code-execution-attacks</link>
                                                                            <description>
                            <![CDATA[ Millions of GTA Online players could fall prey to malware or data corruption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HdBNYgRAENLu5ZNoGZ7o</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T45WaGYqUqvirnyJ75xPAB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Jan 2023 12:22:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T45WaGYqUqvirnyJ75xPAB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Rockstar Games logo appearing against a backdrop of the most recent games it has released]]></media:description>                                                            <media:text><![CDATA[Rockstar Games logo appearing against a backdrop of the most recent games it has released]]></media:text>
                                <media:title type="plain"><![CDATA[Rockstar Games logo appearing against a backdrop of the most recent games it has released]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T45WaGYqUqvirnyJ75xPAB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Popular video game Grand Theft Auto V (GTA V) has been found to contain a flaw allowing for partial remote code execution (RCE), amidst calls for users to avoid the game entirely until a fix has been released. </p><p>Hackers had initially used the flaw to give themselves elevated levels within the game and ban other users, but it has since become apparent that the same exploits can be used to achieve partial RCE on victims' PCs. </p><p>If threat actors use the flaw to achieve full RCE, they could launch malware on the devices of victims using the game as a staging point.</p><p>As the extent of actions that can be carried out using the vulnerability are still being analysed, community members have urged others to stay away from the game.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1616610298022211585"></a></p></blockquote><div class="see-more__filter"></div></div><p>Reports have indicated that hackers have even been able to force themselves into private online sessions between friends, meaning that all online use of the game could be considered unsafe.</p><p>Twitter user ‘Tez2’ was among the first to warn that the flaw allows for partial remote code execution. They have since <a href="https://twitter.com/TezFunz2/status/1616848878095015936?cxt=HHwWgIC9pZ_fmfAsAAAA">tweeted</a> that “Rockstar is aware and has been logging any affected account before the first mod menu started abusing the new exploits”.</p><p>The flaw has been assigned <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24059">CVE-2023-24059</a> and is awaiting a CVSSv3 severity score.</p><p>“With online gaming being extremely popular and lucrative, there have always been criminals, and mischief-makers online who have tried to hack the system into getting easy victories, or social engineering other players," said Javvad Malik, lead security awareness advocate at KnowBe4.</p><p>"However, having such a vulnerability in such a popular game is rare, and it can potentially have a huge impact on players. As soon as a patch is available, people should install it to prevent being victims.”</p><p>The game’s community on Reddit began to warn about the vulnerability on 20 January, and a day later a community moderator issued a <a href="https://www.reddit.com/r/gtaonline/comments/10hsosu/mass_reporting_the_dangerous_pc_exploit">post</a> urging users to report the issue to Rockstar and to refrain from playing the game. </p><p>In the same post, a temporary fix for account corruption was noted: deleting the “Rockstar Games” from a device’s Documents folder, and reloading the game.</p><p>However, this is only useful to those seeking to continue playing the game, and will not remedy potential <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> or file deletion that arises as a result of RCE.</p><p>GTA V is the second best-selling game of all time, having sold over 170,000,000 copies to date. It is available on a large number of platforms, though it is the PC edition that contains the flaw. Those who use their laptop for both work and personal use, rather than a designated <a href="https://www.itpro.com/laptops/23742/best-laptops" data-original-url="https://www.itpro.com/laptops/23742/best-laptops">business laptop</a>, could be at risk from the flaw.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/routers/361953/netusb-flaw-exposes-millions-of-routers-to-remote-code-execution" data-original-url="/hardware/routers/361953/netusb-flaw-exposes-millions-of-routers-to-remote-code-execution">NetUSB flaw exposes millions of routers to remote code execution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/362061/dark-souls-servers-taken-offline-after-rce-flaw-identified" data-original-url="/security/vulnerability/362061/dark-souls-servers-taken-offline-after-rce-flaw-identified">Dark Souls servers taken offline after RCE flaw identified</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/368570/roblox-hacker-posts-stolen-documents-online" data-original-url="/security/phishing/368570/roblox-hacker-posts-stolen-documents-online">Roblox hacker posts stolen documents online</a></p></div></div><p>The game has been a hotspot of hacking activity for some years, Rockstar has struggled to keep GTA Online servers clean of hackers seeking to cheat for advantage, or get legitimate users banned. At time of writing, Rockstar has not issued a statement addressing the issue on its social media channels. </p><p>Comparisons can be drawn with a similar incident from January 2022, in which the game <a href="https://www.itpro.com/security/vulnerability/362061/dark-souls-servers-taken-offline-after-rce-flaw-identified" data-original-url="https://www.itpro.com/security/vulnerability/362061/dark-souls-servers-taken-offline-after-rce-flaw-identified">Dark Souls’ servers were taken offline</a> following the identification of an RCE vulnerability in the game’s servers.</p><p>A streamer was able to run a <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">Powershell</a> script on another steamer’s device using the flaw, in a demonstration of its dangerous potential in the hands of malicious hackers.</p><p>The flaw affected multiplayer servers in the games Dark Souls: Remastered, Dark Souls: Prepare to Die Edition, Dark Souls 2, and Dark Souls 3. It took creator Bandai Namco seven months to put servers back online in the aftermath. GTA Online servers remain active despite the threat.</p><p><em>IT Pro</em> has approached Rockstar Games for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MSI to release securer BIOS settings after critical flaw discovered ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/369903/msi-to-release-securer-bios-settings-after-critical-flaw-discovered</link>
                                                                            <description>
                            <![CDATA[ The firm has admitted it essentially disabled Secure Boot on its motherboards in an attempt to improve customisability ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4jLQnWt384fLqgJV7zLNsM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Cte9yH3YPqcuu3oFMf258o-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Jan 2023 12:17:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Cte9yH3YPqcuu3oFMf258o-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The MSI logo on a wall at a conference, lit in red LED lighting]]></media:description>                                                            <media:text><![CDATA[The MSI logo on a wall at a conference, lit in red LED lighting]]></media:text>
                                <media:title type="plain"><![CDATA[The MSI logo on a wall at a conference, lit in red LED lighting]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Cte9yH3YPqcuu3oFMf258o-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Micro-Star International (MSI) has announced it will release new BIOS files for its motherboards following the discovery of Secure Boot settings that left approximately 290 of the company’s motherboards vulnerable to malware.</p><p>Motherboards made by the company came with insecure security options by default, in a setting that the firm has now committed to changing in a future update.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KoCPGWaMFabR4Q4NgSnY4D" name="KoCPGWaMFabR4Q4NgSnY4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" mos="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Threat hunting for MSPs</strong></p><p class="fancy-box__body-text">Are you ready to take your Managed Security Service to the next level?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps" data-original-url="/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps">FREE DOWNLOAD</a></p></div></div><p>Security researcher Dawid Potocki was the first to publish findings on the vulnerability after discovering that his firmware accepted any OS image, whether or not it carried a legitimate signature.</p><p>Potocki discovered that MSI had set its Secure Boot as ‘Enabled’, but the default on motherboards was ‘Always Execute’ resulting in any OS image being accepted by the firmware.</p><p>Users seeking the Microsoft-recommended Secure Boot settings would have to manually go into motherboard settings and change ‘Image Execution Policy’ to ‘Deny Execute’.</p><p>Secure Boot is a firmware process that protects the Unified Extensible Firmware Interface (UEFI), the internal architecture that handles the booting of <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system" data-original-url="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">operating systems</a> within a computer. It validates the safety of files launched when a device starts by verifying each carries a valid signature and kills processes that fail these checks.</p><p>Threat actors that compromise core systems could take full control of a victim’s machine, leading to extensive data loss, or install <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> such as a <a href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit" data-original-url="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit">rootkit</a> that persists even after a full <a href="https://www.itpro.com/operating-systems/microsoft-windows/358036/how-to-reinstall-windows-10-without-losing-data" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/358036/how-to-reinstall-windows-10-without-losing-data">system reinstall</a>. </p><p>An MSI spokesperson told <em>IT Pro</em> that the choice to roll out the decreased security measures came about after a review of “the product characteristic of our motherboard and target audience in the consumer market”. The firm stressed that it is in compliance with Microsoft's design guidance.</p><p>“We preemptively set Secure Boot as Enabled and 'Always Execute' as the default setting to offer a user-friendly environment that allows multiple end-users flexibility to build their PC systems with thousands, or more, of components that included their built-in option ROM, including OS images, resulting in higher compatibility configurations,” MSI <a href="https://www.reddit.com/r/MSI_Gaming/comments/10g9v3m/msi_statement_on_secure_boot">stated</a> on its dedicated subreddit.</p><p>“In response to the report of security concerns with the preset bios settings, MSI will be rolling out new BIOS files for our motherboards with 'Deny Execute' as the default setting for higher security levels. </p><p>“MSI will also keep a fully functional Secure Boot mechanism in the BIOS for end-users so that they can modify it according to their needs.”</p><p>When IT teams or individual users can expect to receive the update has not been revealed by MSI.</p><p>The post on its subreddit has already received critical responses, pointing out that the insecure default settings were not made clear in any of the firm’s BIOS update changelogs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369491/lenovo-patches-thinkpad-yoga-ideapad-uefi-secure-boot-vulnerability" data-original-url="/security/vulnerability/369491/lenovo-patches-thinkpad-yoga-ideapad-uefi-secure-boot-vulnerability">Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/368655/researchers-uncover-mysterious-windows-rootkit-actively-exploited-2016" data-original-url="/security/malware/368655/researchers-uncover-mysterious-windows-rootkit-actively-exploited-2016">Researchers uncover 'mysterious' Windows rootkit being actively exploited since 2016</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit" data-original-url="/security/cyber-attacks/360526/what-is-a-rootkit">What is a rootkit?</a></p></div></div><p>The full list of affected motherboards was listed by Potocki on a <a href="https://github.com/Foxboron/sbctl/issues/181">GitHub repository</a> in December, along with instructions for manually fixing the issue.</p><p>Potocki identified that the issue was first introduced in an update released around Q3 2021, but was unable to determine the specific version.</p><p>In November 2022, <a href="https://www.itpro.com/security/vulnerability/369491/lenovo-patches-thinkpad-yoga-ideapad-uefi-secure-boot-vulnerability" data-original-url="https://www.itpro.com/security/vulnerability/369491/lenovo-patches-thinkpad-yoga-ideapad-uefi-secure-boot-vulnerability">Lenovo patched ThinkPad, Yoga, and IdeaPad</a> devices due to a vulnerability that allowed for UEFI Secure Boot to be deactivated.</p><p>At the time, concerns were raised over the potential for businesses to fall vulnerable to malware such as <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> through the vulnerability, particularly given the propensity for laptops such as these to be used in an office environment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Ads malvertising campaign prompts questions around Search security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369892/google-ads-malvertising-campaign-prompts-questions-around-search-security</link>
                                                                            <description>
                            <![CDATA[ A leading security researcher has called into question why Google still allows malware links to top search results ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5PuVkfbQkhJvcdrRaRKqs6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Jan 2023 12:59:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:description>                                                            <media:text><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Paid advertising links on Google Search are being used by cyber criminals to push malware, in a strategy that could threaten businesses looking to use free software.</p><p>Top listings on the search engine that purport to link to legitimate software websites were instead found to be decoys leading to websites containing malware such as infostealers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results" data-original-url="/security/368621/hackers-hiding-malicious-links-in-top-google-search-results">Hackers hiding malicious links in top Google search results, researchers warn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/32128/google-at-20-how-a-search-engine-changed-the-business-world" data-original-url="/network-internet/32128/google-at-20-how-a-search-engine-changed-the-business-world">Google at 20: How a search engine changed the business world</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/369517/google-agrees-record-3915m-settlement-in-us-digital-tracking-case" data-original-url="/security/privacy/369517/google-agrees-record-3915m-settlement-in-us-digital-tracking-case">Google agrees record $391.5m settlement in US digital tracking case</a></p></div></div><p>The abuse of Google's ubiquitous search engine was brought to light after a cryptocurrency influencer mistakenly downloaded a malicious package after clicking on an advertising link for popular streaming software OBS.</p><p>After running the executable file provided on the website, the victim's accounts on Substack and Twitter were hacked, and their NFT wallet was stolen.</p><p>Security researcher Will Dormann detailed the issue in a Twitter <a href="https://twitter.com/wdormann/status/1614675821578395655">thread</a>, and openly questioned why Google-owned threat analyser VirusTotal cannot be used to automatically check sponsored links for malware.</p><p>The popular file and link-checking website was <a href="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal" data-original-url="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal">acquired by Google</a> in 2012, and flagged the malvertising links used in the campaign as threats when manually fed into the system.</p><p>Despite this, Google had not prevented the links from being blacklisted on their Ads platform, seemingly accepting money from threat actors without checking the listed links for threats at all.</p><p>In other cases, Dormann noted that VirusTotal didn’t flag links as malicious even though inspection of the packages they pushed contained highly suspicious Powershell commands.</p><p>He alleged that the threat actor behind this package is still paying Google for fake listings on software such as VLC Media Player, Rufus, and uTorrent.</p><p><a href="https://www.itpro.com/business-strategy/smb/360136/the-most-significant-challenges-facing-smbs-post-pandemic" data-original-url="https://www.itpro.com/business-strategy/smb/360136/the-most-significant-challenges-facing-smbs-post-pandemic">Small and medium businesses</a> could be at particular risk from this campaign, as these firms typically rely on free media and <a href="https://www.itpro.com/business-operations/productivity/355569/optimize-your-workflow-our-9-best-productivity-apps" data-original-url="https://www.itpro.com/business-operations/productivity/355569/optimize-your-workflow-our-9-best-productivity-apps">productivity software</a>, the likes of which are being mimicked.</p><p>Some software developers appear to be aware of the issue, as those behind Notepad++ appear to have spent money to ensure their software appears in results first. OBS has issued an official warning and linked the only legitimate site from which its software may be obtained.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1615033901809913856"></a></p></blockquote><div class="see-more__filter"></div></div><p>Malvertising, the method through which malicious software or links are hidden in seemingly safe advertising, is often used by hackers on untrustworthy websites behind suspicious banner ads. </p><p>“Protecting users is our top priority,” said a Google spokesperson in response to a request from <em>IT Pro</em>.</p><p>“We take dishonest business practices very seriously and consider them to be an egregious violation of our policies. Where we find ads that breach our policies we take immediate action.”</p><p>Google's <a href="https://support.google.com/adspolicy/answer/6008942?hl=en">ad policy</a> prohibits the posting of links that hide malware, and in January 2021 the firm began to ask advertisers registered in certain countries to <a href="https://support.google.com/adspolicy/answer/10268745">verify their identity</a>.</p><p>The company did not directly respond to questions regarding why it has not implemented automatic VirusTotal scans for links on their platform.</p><h2 id="malvertising-a-deeper-issue">Malvertising: A deeper issue</h2><p>The HP Wolf Security Threat Research Team published a <a href="https://threatresearch.ext.hp.com/adverts-mimicking-popular-software-leads-to-malware">report</a> on malvertising campaigns that used fake listings for popular free software as an attack vector.</p><p>Programs such as Audacity, Teams, Discord, and the Adobe Creative Cloud suite of apps were used as bait by threat actors to distribute malware.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KoCPGWaMFabR4Q4NgSnY4D" name="KoCPGWaMFabR4Q4NgSnY4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" mos="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Threat hunting for MSPs</strong></p><p class="fancy-box__body-text">Are you ready to take your Managed Security Service to the next level?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps" data-original-url="/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth" data-original-url="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth">Vidar Stealer</a>, a malware strain used to steal data such as passwords and cryptocurrency wallets from victims, was one such program spread in the campaign, along with the <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus" data-original-url="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojan</a> IcedID which is used to steal financial credentials and compromise corporate networks.</p><p>Researchers noted that malicious packages downloaded through the campaign were large, with one example being 343MB. This is believed to be an <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> evasion tactic, as larger files can circumvent automatic scans with some software.</p><p>“Many organisations use software distribution systems, which means that the software does not have to be downloaded by the end user but is provided by the system administrator,” said Patrick Schläpfer, malware analyst at HP Wolf Security.</p><p>“If you even block the download of such software for end users, you greatly limit this attack vector and are even more protected against such attacks.”</p><p>The use of Google Ads to deliver malware was also previously highlighted in July 2022 when Malwarebytes researchers warned of <a href="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results" data-original-url="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results">Google search results hiding malicious links</a>. The sophisticated campaign used inline frames to push malicious domains onto users without revealing their URLs.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Royal Mail ransom note leaked, LockBit’s role remains uncertain ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/369860/royal-mail-ransom-note-leaked-lockbits-role-remains-uncertain</link>
                                                                            <description>
                            <![CDATA[ The prolific ransomware operation has denied involvement but researchers remain sceptical ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qQNkXuvkvcz1tDqJXVXajR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/87hgKreegcXy3Wnkj5P225-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Jan 2023 10:10:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/87hgKreegcXy3Wnkj5P225-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Royal Mail van parked in a fleet]]></media:description>                                                            <media:text><![CDATA[Royal Mail van parked in a fleet]]></media:text>
                                <media:title type="plain"><![CDATA[Royal Mail van parked in a fleet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/87hgKreegcXy3Wnkj5P225-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>After having been linked with the “cyber incident” affecting the UK’s Royal Mail Group, the LockBit ransomware operation has denied its members were behind the assumed attack.</p><p>Ransom notes began printing at Royal Mail’s sorting office in Mallusk, Northern Ireland, on Thursday evening revealing threats of data leakage if a ransom wasn’t paid, the <em>Belfast Telegraph</em> <a href="https://www.belfasttelegraph.co.uk/news/northern-ireland/royal-mail-operations-hub-in-mallusk-hit-by-cyber-attack-as-printer-spurts-out-ransom-demands-42279337.html">reported</a>.</p><p>Images of the ransom note, which claimed to be authored by the operators of <a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter" data-original-url="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit Black</a> - the gang’s third <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">version</a> of the ransomware (also known as LockBit 3.0) that shares code with Black Matter’s payload - were shared widely throughout the evening.</p><p>The note claimed Royal Mail’s data were “stolen and encrypted”, and that it would be published on its deep web-based leak site if the ransom was not paid. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1613583665740615682"></a></p></blockquote><div class="see-more__filter"></div></div><p>Also included were two URLs that led to online portals through which the hackers could be contacted, and a decryption ID to enter once one of the contact sites were accessed.</p><p>The URLs are thought to be the same as those found on the ransom note received by the <a href="https://www.itpro.com/security/cyber-attacks/369637/second-cyber-attack-french-hospital-forcing-patients-to-be-relocated" data-original-url="https://www.itpro.com/security/cyber-attacks/369637/second-cyber-attack-french-hospital-forcing-patients-to-be-relocated">André Mignot hospital in Versailles</a> last month.</p><p>The attack forced patients to be moved and was later attributed to LockBit Black ransomware, however, the decryption IDs were not issued by LockBit itself in this case.</p><p>Per a <a href="https://www.bleepingcomputer.com/news/security/royal-mail-cyberattack-linked-to-lockbit-ransomware-operation">report</a> from <em>Bleeping Computer,</em> which contacted LockBit, the ransomware gang has denied involvement in the attack on the British multinational postal company.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LTMrgEvSNMdUH7gB9RYH7b" name="LTMrgEvSNMdUH7gB9RYH7b.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" mos="https://cdn.mos.cms.futurecdn.net/LTMrgEvSNMdUH7gB9RYH7b.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Automate security intelligence with IBM Security QRadar SIEM</strong></p><p class="fancy-box__body-text">Simplify and improve threat detection, investigation and response with reducing overheads</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem" data-original-url="/security/369799/automate-security-intelligence-with-ibm-security-qradar-siem">FREE DOWNLOAD</a></p></div></div><p>Security researchers have raised questions over the legitimacy of LockBit’s denial. </p><p>The builder for <a href="https://twitter.com/3xp0rtblog/status/1572510793861836802">LockBit Black was leaked</a> in September by a group which claimed to have hacked LockBit’s servers.</p><p>This means that hackers, in theory, don’t need to be official ‘affiliates’ of LockBit’s <a href="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service" data-original-url="https://www.itpro.com/security/29332/the-rise-of-ransomware-as-a-service">ransomware as a service (RaaS)</a> programme in order to launch attacks using its software.</p><p>However, the contact URLs supplied in the note directed to LockBit’s website and the decryption ID initially worked, but after the ransom note was leaked, researchers have reportedly said the ID is no longer valid.</p><p>If the decryption ID did work at some point in time, as one expert <a href="https://twitter.com/UK_Daniel_Card/status/1613815371475324928">confirmed</a>, it could either mean LockBit actually did conduct the attack, or an unaffiliated attacker launched the ransomware while also having privileged access to LockBit’s official website so they could create a negotiation chat portal for Royal Mail.</p><p>Asked for confirmation of the leak’s legitimacy, the UK’s National Cyber Security Centre (NCSC) and Royal Mail both told <em>IT Pro</em> that they would not be disclosing any details at the time of writing.</p><p>The National Crime Agency (NCA), also involved in the ongoing investigations, did not respond to requests for comment.</p><h2 id="what-is-the-cyber-incident-at-royal-mail">What is the “cyber incident” at Royal Mail?</h2><p>Royal Mail confirmed on Wednesday evening that it was suffering the effects of a “cyber incident” which continues to ‘severely disrupt’ the international shipping branch of its business.</p><p>“We are temporarily unable to despatch items to overseas destinations,” read its <a href="https://personal.help.royalmail.com/app/answers/detail/a_id/12556/~/service-update">incident update page</a>. “We strongly recommend that you temporarily hold any export mail items while we work to resolve the issue. Items that have already been despatched may be subject to delays. We would like to sincerely apologise to impacted customers for any disruption this incident is causing.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369783/lockbit-issues-rare-apology-for-toronto-sickkids-ransomware-attack" data-original-url="/security/369783/lockbit-issues-rare-apology-for-toronto-sickkids-ransomware-attack">LockBit issues rare apology for Toronto SickKids ransomware attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369449/lockbit-repeats-pr-stunt-as-thales-ransomware-investigation-reveals-no-breach" data-original-url="/security/ransomware/369449/lockbit-repeats-pr-stunt-as-thales-ransomware-investigation-reveals-no-breach">LockBit repeats 'PR stunt' as Thales ransomware investigation reveals no breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter" data-original-url="/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">Latest LockBit ransomware strain 'strikingly similar' to BlackMatter</a></p></div></div><p>Very few details of the incident have been revealed other than that the NCSC and NCA are involved in the investigation, and the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico" data-original-url="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> has also been informed.</p><p>Royal Mail has never described the incident as an ‘attack’ and all parties involved have yet to confirm that the incident is ransomware in nature.</p><p>“We are aware of an incident affecting Royal Mail Group Ltd and are working with the company, alongside the National Crime Agency, to fully understand the impact,” the NCSC said in a brief official statement.</p><p>As of Friday, Royal Mail’s overseas shipping processes remain severely disrupted.</p><p><em>IT Pro</em> will continue to report on the story as it develops.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Something you are, or something you have, could be more important than a password you know in the near future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gFLpzoAsrEnfKmzKDL7anB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 13:05:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VcYM9FMqT7ivC3FzghbsLW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords: they can be tricky at the best of times. Proper password hygiene is one of the most important factors in endpoint security, as it keeps sensitive data secure and prevents threat actors from getting into important systems. </p><p>But despite the risks, the use of weak or recycled passwords continues to be a problem even amongst IT professionals. While systems such as two factor authentication have been used as an extra layer of security, groups like the FIDO Alliance and World Wide Web Consortium have been working to make passwords a thing of the past, in favour of more secure methods.</p><p>This week, we spoke to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to explore the solutions driving secure sign ons, and how the sector can adapt to this change.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights-3">Highlights</h2><p>“The criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet.”</p><p>“The concept of security authentication has always been based around, sort of, one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password.”</p><p>“Anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them.”</p><p><a href="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless"><em>Read the full transcript here.</em></a></p><h2 id="footnotes-3">Footnotes</h2><ul><li><a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/security/29705/what-are-biometrics" data-original-url="https://www.itpro.com/security/29705/what-are-biometrics">What are biometrics?</a></li><li><a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">What is two-factor authentication?</a></li><li><a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue" data-original-url="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">What is multi-factor authentication (MFA) fatigue and how do you defend against attacks?</a></li><li><a href="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication" data-original-url="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication">How to implement passwordless authentication</a></li><li><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">Best password managers</a></li><li><a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">Best free password managers</a></li><li><a href="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better" data-original-url="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better">The sooner the FIDO Alliance can shut down passwords, the better</a></li><li><a href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security" data-original-url="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security">Will FIDO passwordless authentication save cyber security?</a></li><li><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: Going passwordless ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/enterprise-security/369815/podcast-transcript-going-passwordless</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uoaH42Y3cyW7SJ5m8ruydz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Jan 2023 12:40:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;Going passwordless&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PbzYT7jCw5MrPbZDydLWCY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>​​This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless" data-original-url="https://www.itpro.com/security/enterprise-security/369814/the-it-pro-podcast-going-passwordless">Going passwordless</a>'. <em>We apologise for any errors.</em></p><h2 id="rory-bathgate-3">Rory Bathgate </h2><p>Hi, I'm Rory Bathgate. </p><h2 id="jane-mccallion-3">Jane McCallion </h2><p>And I'm Jane McCallion </p><h2 id="rory-18">Rory</h2><p>And you're listening to the IT Pro Podcast, where this week we're discussing passwordless security.</p><h2 id="jane-22">Jane </h2><p>Good password hygiene is one of the most important factors in endpoint security. If passwords are managed improperly, threat actors can access critical systems, and the use of weak or recycled passwords continues to be a problem even amongst IT professionals.</p><h2 id="rory-19">Rory </h2><p>In place of legacy systems such as one time passcodes sent via SMS, groups like the FIDO Alliance and World Wide Web Consortium are working to make passwords a thing of the past.</p><h2 id="jane-23">Jane </h2><p>Today, we're speaking to Richard Meeus, EMEA director of security & technology strategy for Akamai Technologies, to discuss the solutions that can enable more secure sign ons, and how the sector is handling this change. Richard, thank you for joining us.</p><h2 id="richard-meeus">Richard Meeus </h2><p>Thank you very much, delighted to be here.</p><h2 id="jane-24">Jane </h2><p>So everyone's been using passwords on their computers for decades. How come now they're being called insecure?</p><h2 id="richard">Richard</h2><p>Well, I don't think it's now that they're being thought of as being insecure, I think they've been insecure for a long time. I mean, passwords have been utilised as an authentication mechanism for centuries. And it's always been fairly trivial to find out what they were. What we've been doing recently is with a plethora of websites and services, especially after the pandemic that everybody went online. Everybody reused the same passwords. People, humans, users we're rubbish at passwords, we have a limited capacity to remember passwords. And therefore we tend to use the same one repeatedly. Or we just try and be very clever and add a ‘1’ to the end, to try and make it uncrackable. And because of this, the criminals know this, the criminals know that we are bad with passwords, and we just use something like our pet's name or something like that. And it's relatively easy for people to get the passwords or, as most commonly happens, an organisation will be breached and their password and username database will be leaked out onto the internet. And then, those usernames and passwords are reused against websites all over the planet. And if you look at some of the database repositories, the legitimate repositories which are used for you to see if you have had your username and password put out onto the internet, there's about 10 million — 10 billion sorry, username and password combinations in there. That's a lot more than the internet-connected population. In fact, it's about four times more than the internet connected population. So there's a good chance there's a criminal somewhere who has your username and your password, and is trying them on a number of websites. Right now. What we want to do is move to a situation where that risk is mitigated to a certain degree.</p><h2 id="rory-20">Rory </h2><p>With this risk of reusing passwords, certainly, or generating weak passwords. I know that a lot of businesses rely on things like password managers, can those be continued to be relied upon by businesses?</p><h2 id="richard-2">Richard </h2><p>I think password managers, as well as with organisations looking to protect their users, it's important that password managers are used properly. A password manager is a great tool, I use one for my home business use for creating complex passwords, complex unique passwords. So I don't know what my passwords are, because they are a random bunch of 25 alphanumeric and special characters. I have no idea what they are. And the password manager remembers that, so every single asset that I talk to has a unique password. Password managers, I think, are very useful especially in the short term and within enterprises. It's not so great for end users because the vulnerable people in society, and people who are not familiar with technology, may find them quite difficult to use. But in enterprises they're certainly very useful because it allows you to create complex, distinct, unique user passwords for every single application that you go to. My passwords are often 25 characters long and a stream of unrecognisable characters, and numbers, and estimation marks, and question marks, and special characters that will be impossible to guess or impossible to do a brute force hack upon. So I think they definitely have a position, especially in the enterprise.</p><h2 id="jane-25">Jane </h2><p>I mean, Richard, once again, I also use password managers. Are there risks associated with those? Recently we have seen LastPass, breached. And every time I see something like that my heart goes in my mouth. And then you realise, actually, your passwords are typically safe. But is there any kind of real chance that either the database itself could be breached particularly say, if you're reusing password for them? Or something a bit more sophisticated than that?</p><h2 id="richard-3">Richard</h2><p>Well, I think a lot of the time, there's always been that concern about “if I put all my eggs in one basket, is that creating more of a risk? I think that's been the typical response to people not wanting to use password managers. But I think when you actually look at the security that is around the actual passwords, and how they're stored and how they're utilised, I think that that overweighs any of that concern about the risk about having all your passwords in one basket, or eggs in one basket. So I don't think there's a chance that if you, people do use them, I think they are very good, they're very useful. It again, outweighs the risk of just having very simple passwords that you can try to remember.</p><h2 id="jane-26">Jane </h2><p>Yeah. </p><h2 id="rory-21">Rory </h2><p>So in response to this, to focus on passwordless security as an option. When someone says passwordless security, I mainly think of biometric security, fingerprints, facial recognition. Is this the most promising avenue for this technology? And what are some of the other methods that are in place?</p><h2 id="richard-4">Richard</h2><p>Yeah, well I mean the concept of security authentication has always been based around sort of one of three concepts. So there's something you know, which is a password, something you are, which is your biometric. So use your face print or your thumbprint, or something like that. Or something you have, which could be a USB token, or something that you can punch numbers into as a handheld device. So one of those three things, and we've relied upon the something you know, predominantly, which is the password. And we tend to use the something you have, like the USB key, or the something you are like the biometrics as an additional level and commonly called this is like two factor or multi factor authentication. So that what the concept is of going passwordless, is actually shifting away from using passwords as the primary method of authentication. And say, why do we need to use passwords as a primary, when we can use one of the other two, such as having a hardware device or using biometrics to do that first part of authentication? Obviously, there are many benefits to using the hardware device, or your thumbprint, or your face print. Because they're not likely to have the same level of simplicity around them. You know, it's not going to be quite as simple as password 123, when you're talking about your thumbprint, so there's a lot of sort of intrinsic benefit to that already.</p><h2 id="jane-27">Jane </h2><p>I mean, when we're talking about this, we've sort of talked to him a little bit. When we talk about passwords you're speaking about moving the second part of two factor authentication to the front, the something you have, the something you are. Are we talking about getting rid of passwords completely, or do they become the second part of this 2FA? Or is it going to be my face and my token?</p><h2 id="richard-5">Richard</h2><p>Passwords can still be used, but I would suggest that they are taken away largely completely, because they prove that they can't really be utilised effectively or securely. Certainly, if you have a three factor authentication it’s often used when you're going into very secure facilities. Where you have to sort of take in your access card, do a thumbprint, and then you have to type a PIN code in there. And then the PIN code would be sort of synonymous with your normal password. So that sort of three factor authentication will still be relevant in a lot of cases. But I think the concept of using a password to log on to a website will eventually go away, because it's not an effective way to access that level and proportionate that level risk.</p><h2 id="rory-22">Rory </h2><p>And when you're talking about, I guess, in some cases this is consumers would be able to use, say a passkey, a physical passkey to verify their identity on a multitude of different accounts. In an enterprise model, could this be hard to, this specific something you have, could that be hard to implement in that if you left the company, you'd have to return what you had. It would potentially be harder than do changing a password?</p><h2 id="richard-6">Richard</h2><p>Absolutely, I think the same thing you have part is an interesting concept about what it can actually be. And something, because I think everybody's sort of familiar with the, the old dongles which have the sort of rotating password pass key on them, that have been around from people like RSA for many, many years. And if you look in your desk drawer, you'll probably find two or three of them where the batteries died that you've had from many years ago. And that's not an unusual situation. And so there is an overhead to managing all those additional keys, and people will forget them, people will lose them. So there is an additional overhead in terms of that. So ideally, you want to try and use something that you already have, and you're never likely to let go of. And that's probably something like a mobile phone. And you can use a mobile phone as the something you have component. And it also allows you to do the something you are component because it allows you to do, especially with the modern smartphones, the biometrics and things like facial recognition and fingerprint recognition.</p><h2 id="jane-28">Jane </h2><p>And I suppose if you've got company provided phones, then it's as easy as just returning the phone or remotely wiping it or any of that kind of thing if somebody leaves the company but they are, for whatever reason, not returning the phone.</p><h2 id="richard-7">Richard</h2><p>Yes, if you're provided a company phone you will normally have some sort of MDM, some mobile device management software on the phone. Whereas as soon as they leave the company or as soon as the employment is terminated, then it's a question of just hitting a button on the central console and it would remove any of those components. </p><h2 id="jane-29">Jane </h2><p>Yeah, I've thought of all kinds of nefarious things for employees to do. I think most of us more inclined to sort of lose our phone, on a train or whatever as well. </p><h2 id="richard-8">Richard </h2><p>Yeah,absolutely. But also remembering that without the knowledge of where you're going, and what you're going to, because you still have to get the thumbprint to actually authenticate because it's part of that you would have something you have, something you are. Smartphones make it very easy to do two factor authentication, by taking the biometrics and the something you have. So that gives you the two factor based on that. So if you do lose your phone, they may be able to guess the pin number or the swipe pattern you have to get into the phone. But it's unlikely then they'll have the biometrics to actually get through the next level, to get on to the corporate assets as required. </p><h2 id="jane-30">Jane</h2><p>Sure.</p><h2 id="rory-23">Rory </h2><p>Through things like FIDO, there's been talks — I know that some manufacturers at Google Apple, Microsoft, have been in talks — to standardise this kind of technology that you're talking about. So that regardless of the hardware you were using, like the standardised keys across either your business interactions, or on a consumer basis across all of your different accounts, do you think a unified approach like that will be necessary to avoid there being a different kind of tool sprawl for businesses and consumers in the future where they're having to oh, you know, “which passkey am I going to be doing through my phone?”</p><h2 id="richard-9">Richard</h2><p>I think there's going to be an argument for that. Not quite sure what things are going to happen in the short term, but it remains to be seen. I do think the work that FIDO is doing to promote easier and more secure access online is something that will be followed by more and more organisations. The current iteration, which is FIDO2, so fast identity online version two, even goes so far as to provide solutions that allow you to do phish proof MFA, because that is also a problem with MFA. It's not 100%. It's a lot better than not having multi factor authentication. But MFA is not 100%, and with the next generation, which is FIDO2, it will be phish proof. Again, it's never going to be 100%, but it's going to be a lot closer to where we want it to be.</p><h2 id="jane-31">Jane </h2><p>So Richard, you've mentioned, FIDO2 briefly there. Could you tell us a bit more sort of what that's about?</p><h2 id="richard-10">Richard</h2><p>Yeah, so FIDO2 is a methodology to make MFA sort of even better, because surprisingly, MFA doesn't solve all problems. You know, we think that it's going to address all of our authentication issues, but it doesn't and there's been several organisations that have been breached fairly publicly. So a very well known video game manufacturer, a well known taxi company, a global taxi company has recently been breached by what's called an MFA bypass. And an MFA bypass technique basically means that the device is talking to the website or the application, and the device that is doing the multi factor authentication are not linked. So this means that if you have stolen credentials, you can put those into the asset, put those into the website, the website will respond with an MFA challenge. And the attackers realise that the MFA challenge is going to be sent to the user, and they will try and persuade them to actually accept the challenge. And it's surprisingly easy to do that, with things like push MFA challenges. If you start sending people that at 3am in the morning, it's remarkable how quickly people will just click on ‘accept’, rather than have to listen to the bing, bing, bing, bing, bing, bing, constantly being reminded in the middle of the night. And this is what's happened to many, many organisations, is that because the device that’s making the request to the asset and the device are not linked, you can get this what's called push MFA or MFA bypass. So what FIDO2 wants to do is to locally connect the devices making the request to the origin and your external device. Now, you can do this through a USB key, plug the USB key into your device, they're now locally linked. Or you can do it through NFC, or you can do it as we do with Akamai, you can link them together through cryptographic keys. So my phone and my laptop are cryptographically linked, which basically means that the MFA is not valid unless it comes from my laptop. So if my credentials are stolen, and somebody tries to log in in another part of the world, and then tries to do a push MFA exertion on me, it won't even happen because the request has to come from my laptop. And this is what FIDO2 is doing, it’s ensuring that local MFA connectivity before it actually goes on to the next stage. And by doing this, it gets round a lot of the big MFA bypasses that have happened this year.</p><h2 id="jane-32">Jane </h2><p>So this all sounds really great. And as a consumer, I can see myself adopting it. I already have, I use my thumb on my phone, people use their faces on their phone. And, you know, really consumers can turn on a penny when it comes to adopting new technology, anything like that. For businesses, it can be a little bit more difficult, especially if there's some kind of integration that they need to do with legacy systems. So how quickly can that be done? I mean, is it a problem? Am I throwing up a problem where one doesn't exist? But if I'm not, how can this be managed, and how quickly can things change?</p><h2 id="richard-11">Richard</h2><p>I think with enterprise, it'll be a lot easier than it will be for consumers. For two different reasons. The main reason for consumers is that there will be a long tail of users who, for want of a better word, maybe a sort of Luddite about adopting the new technology. There are many people who don't want to have a smartphone with biometric controls on them for whatever reason. So for a service, such as public services, public sector, where they have to provide a fully inclusive service, there's gonna be a long tail of people there who won't fit into the parameters where you can do that full technology, but for multi factor authentication using biometrics or smartphone, so there will have to be solutions there to cater for those people. But with the enterprise, you have a lot more control. And you can certainly start linking all of your assets to talk to a central identity provider, be it Active Directory or some other form. And once you have authenticated with your main IDP, your main identity provider that can provide authentication tokens to every single other device within your estate, meaning once you're logged in, you're logged in across your estate. And that identity is protected by authentication through multifactor.</p><h2 id="jane-33">Jane </h2><p>So the other way around to what you find quite often then, is that for businesses actually, this is quite easy. I mean, are there any sort of key hurdles that might hold up passwordless security in businesses or is it really just as easy as kind of going, “right this is our, you know, the method that we do now internally, at least. And, and off we go”?</p><h2 id="richard-12">Richard</h2><p>There's always going to be some legacy applications that don't have the ability to use authentication. So there's a functionalities like OAuth, which allows applications to be authenticated elsewhere. If they don't have the functionality to have that capability, then you're going to have to have another way of authenticating with those legacy applications. So it's not necessarily going to be applicable across the board. But most modern organisations will have the facility to deploy the majority of their applications through that one password, or one authentication process, and then being able to pass that assertion through to all the relevant applications.</p><h2 id="rory-24">Rory </h2><p>Do you think that implementing a system like this might also help with oversight of who has access to which systems? Because currently, obviously with passwords, it's very easy within an organisation for someone to ping a password across on a Google chat to someone who maybe shouldn't have access to, to a back end system. So using authenticators might also improve observability across the system?</p><h2 id="richard-13">Richard </h2><p>I think there's a potential for that, I think that where that particular area’s going is more into is looking at the authorisation component. So with identity, you’ve got the identification, which is the username, you've got the authorisation. Sorry, the authentication, which is the something you are, something you have, something you are. And then there's the authorisation component, and authorisation is something that's being looked at when you look at things like zero-trust network access, which is a way of giving users access just to applications that they need. So it's really sort of going down heavy on lease privilege. This is a really good way to ensure that only the users authorised to access an application, get that level of access. Which means that anybody else does not have that level of access. So, if you gave somebody else a password, you'd have to have the username and have the password, but they still wouldn't be authorised, they still wouldn't physically be able to get to that particular asset. And I think that's why a lot of organisations are looking into it. Because I know zero trust is a word that bandied around a lot with, with wanton carelessness, sometimes, but it fundamentally comes down to lease privilege, which is something that IT professionals have been familiar with for many, many years. And that's where it's trying to get to, if you don't have the right identity, authentication and authorisation, you can't actually get to that application.</p><h2 id="jane-34">Jane </h2><p>So Richard, if the worst does happen, and a business is hit by a cyberattack, can using a passwordless solution help minimise the impact? Or does it just minimise the risk?</p><h2 id="richard-14">Richard</h2><p>That's a really good question. I think initially, it minimises the risk. Because I think if you, there was a report I think in the Verizon data breach incident report last year, that credential vulnerabilities were responsible for 84% of all breaches. So if you can get to addressing that vulnerability, that reduces the risk significantly of having a breach. So I think that's the first aspect. Once somebody has got inside your organisation, then absolutely, having good identity controls is in place, but it's a little bit late at that point, you then need to be looking at other security elements to be able to protect your organisation. And that can be through things like zero trust, network access, or micro segmentation to throw another technology into the mix to prevent them moving laterally through your organisation. But I think this is where passwords can be used, especially within the enterprise as part of a layered security model of trying to reduce the risk at all levels, reduce the level at authentication time, reduce the risk at connection time, whether connecting via IP or just the application layer, and then reducing the risk of moving throughout an organisation when deployed as part of a managed strategy, then you're able to reduce the risk at all levels as best as possible.</p><h2 id="jane-35">Jane </h2><p>Yeah, and I think you've kind of hit on something important there really, which is whether this is passwordless or really any other kind of security technology, or any technology, that it's not a panacea, it's not a cure-all, it has to be used as part of a wider security strategy. Whether that's training or like you say, other technologies that can help the progress or at least to slow the progress of anybody who's staging an attack. Is that a fair observation?</p><h2 id="richard-15">Richard</h2><p>Absolutely. I think that there aren’t many things that as security professionals we can do, that actually makes things easier for end users. Normally, we are seen as the Department of No, the Fun Police. So I think that anything that we can do within security that actually makes lives easier for end users, and makes them more secure, is a good thing. And reducing passwords, reducing the use of passwords is a good thing, because nobody likes them. Nobody likes them, nobody likes trying to have to remember them. There's always a challenge, there’s always some times you forget, or whatever. It's a problem. It's a massive security risk. So getting rid of that pain point from users would be a boon I would say.</p><h2 id="rory-25">Rory </h2><p>So you think that there's real potential for this to improve, maybe, productivity within the workforces? Or at least improve the use of access for vital systems within workforces?</p><h2 id="richard-16">Richard</h2><p>Absolutely. I think when you look at most organisations where you have, you know, probably thousands of applications within an organisation, although most users will only have access or need to use 10 or 20 of them. The ability to reduce the access to just the applications you need, and the ability to have to worry about a password is fantastic. At Akamai we've been passwordless for many years now. So I don't use a password to log on. I don't use a password to access applications, it's just all done through passwordless technology. And that makes it a lot easier for me not having to worry about, “oh, I need to access that particular system. Where is it located? What password do I need?” All that, it's a lot easier to use? And yes, it's anything that gets rid of that, “oh, what's the password for that application that I haven't used for two months?” Anything gets around that problem, which everybody has, if you can get if you can solve it, it's bound to help all sorts of users.</p><h2 id="jane-36">Jane </h2><p>So Richard, at Akamai you are ahead of the curve. But how far away do you think we are from universal adoption of this kind of security across businesses?</p><h2 id="richard-17">Richard</h2><p>I think that's a very difficult question. Because there are many companies and many verticals that are on all sorts of that journey, all different areas of the passwordless adoption journey. I think people will want to go there because the benefits are manifold. But there is always going to be an issue with inclusivity. Because you have to make sure that everybody is catered for. And if you can't cater to everybody, then there's always going to be an issue. So in the consumer space, I think it's going to be utilised to enable users, I still think you're going to have to have passwords for inclusivity. But if you're using it in the consumer space, and you want to get access to all of your favourite music sites, or TV sites, or shopping sites without having to remember a password all the time, I think people are going to embrace that. And that it will be seen as a benefit not only for the consumers, but also the vendors as well. In the enterprise space, I think that organisations will want to go down this level to a certain degree, I think there's always going to be legacy applications that won't suit that. Or the infrastructure will not benefit it as a whole. But I think overall, it's certainly a methodology that will be broadly adapted. The big vendors, as you mentioned at the beginning, are doing this. Microsoft has things like Microsoft Hello, which allows you to do passwordless authentication. It's something that's being adopted through many different vectors, so it will increase. Am I going to put a date on it and say you have no more passwords in five years. That’s a crystal ball I would love to have, but I couldn't say that.</p><h2 id="jane-37">Jane </h2><p>No fun, no fun.</p><h2 id="rory-26">Rory </h2><p>Well, Richard, thank you so much for being on the show.</p><h2 id="richard-18">Richard</h2><p>Thank you Rory, thank you Jane. It's been a pleasure. Thank you very much indeed for having me.</p><h2 id="jane-38">Jane </h2><p>Thank you. As always, you can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk</p><h2 id="rory-27">Rory </h2><p>You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review</p><h2 id="jane-39">Jane </h2><p>I will be back next week with more from the world of it but until then goodbye. </p><h2 id="rory-28">Rory</h2><p>Goodbye</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rapid7 hires whistleblower Peiter "Mudge" Zatko a year after Twitter sacking ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/careers-training/369805/rapid7-hires-whistleblower-peiter-zatko-year-after-twitter-sacking</link>
                                                                            <description>
                            <![CDATA[ Zatko will advise clients at the security firm, in his first public role since launching his whistleblower campaign against Twitter ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wYoBdFU4vwcQJefMmwFKb3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/da43F93TELqYu78EsTWcQf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Jan 2023 12:59:30 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/da43F93TELqYu78EsTWcQf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A telephoto shot of Peiter Zatko, a white man with a goatee in a suit, testifying before the Senate Judiciary Committee on data security]]></media:description>                                                            <media:text><![CDATA[A telephoto shot of Peiter Zatko, a white man with a goatee in a suit, testifying before the Senate Judiciary Committee on data security]]></media:text>
                                <media:title type="plain"><![CDATA[A telephoto shot of Peiter Zatko, a white man with a goatee in a suit, testifying before the Senate Judiciary Committee on data security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/da43F93TELqYu78EsTWcQf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Peiter Zatko has taken up a position at security firm Rapid7, his first job since being fired as head of security at Twitter.</p><p>The veteran hacker and security expert is expected to work closely with consulting clients at the firm. <em>The Washington Post</em> <a href="https://www.washingtonpost.com/technology/2023/01/04/mudge-finds-a-new-job">reported</a> that Zatko will act in an advisory capacity at the company, and will maintain a position similar to that of an executive.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rNAQoa9nwMcMG72HQokQfh" name="rNAQoa9nwMcMG72HQokQfh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" mos="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Storage's role in addressing the challenges of ensuring cyber resilience</strong></p><p class="fancy-box__body-text">Understanding the role of data storage in cyber resiliency</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber" data-original-url="/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber">FREE DOWNLOAD</a></p></div></div><p>“Peiter and I have a longstanding relationship and have spoken at length about the importance of data and research when it comes to measuring cyber security programme effectiveness,” said Corey Thomas, CEO at Rapid7, in a statement to <a href="https://www.siliconrepublic.com/business/pieter-zatko-rapid7"><em>Silicon Republic</em></a>.</p><p>“In order to move our industry forward, we must educate organisations on how and what to measure to ensure we are making the right investment.</p><p>“Peiter’s extensive experience in this field and his work around measuring cyber security practices will be invaluable for both Rapid7 and our customers. I am very much looking forward to working with him in the coming months.”</p><p>Zatko left Twitter firm in January 2022, amidst a shakeup in the chain of command shortly after former CEO Parag Agrawal succeeded Jack Dorsey. Months after, Zatko submitted more than 200 pages of complaints to the Securities and Exchange Commission (SEC) detailing alleged malpractice by the company.</p><p>In August 2022, Zatko’s whistleblower complaints were published. Within, he alleged Twitter security was highly inadequate, with around half of its employees able to access sensitive user data, and that the company operated in direct violation of the law and FTC decrees. He followed his complaints by testifying before the Senate Judiciary Committee in September 2022.</p><p>Other accusations by Zatko include that <a href="https://www.itpro.com/security/privacy/368874/india-forced-twitter-to-hire-a-government-agent-whistleblower-claims" data-original-url="https://www.itpro.com/security/privacy/368874/india-forced-twitter-to-hire-a-government-agent-whistleblower-claims">Twitter knowingly gave Indian government agents access to user data</a> after demands by the Indian government, and that executives had misled users and the Federal Trade Commission (FTC) on matters of <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection</a>. Investigations into Zatko’s claims by the SEC, FTC and other regulators in Europe are ongoing.</p><p>Up until its acquisition by Elon Musk, Twitter continued to state that Zatko’s termination had been a result of poor leadership and workplace performance, and denied the claims.</p><p>Elon Musk unsuccessfully attempted to use <a href="https://www.itpro.com/marketing-comms/social-media/369095/elon-musk-condemns-twitters-data-security-lapses" data-original-url="https://www.itpro.com/marketing-comms/social-media/369095/elon-musk-condemns-twitters-data-security-lapses">Zatko’s claims</a> as a reason to <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/368500/elon-musk-pulls-out-of-twitter-deal" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/368500/elon-musk-pulls-out-of-twitter-deal">back out of his $44 billion acquisition of Twitter</a>, and notably drew attention to the supposedly large number of bots operating on the platform.</p><p>Zatko had alleged that Agrawal and others had repeatedly published misleading information regarding the number of <a href="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce" data-original-url="https://www.itpro.com/network-internet/bots/360765/bad-bots-make-up-huge-slice-of-internet-traffic-and-target-e-commerce">automated bots</a> on Twitter.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/368874/india-forced-twitter-to-hire-a-government-agent-whistleblower-claims" data-original-url="/security/privacy/368874/india-forced-twitter-to-hire-a-government-agent-whistleblower-claims">India forced Twitter to hire a government agent, whistleblower claims</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/369595/best-twitter-alternatives-for-businesses-and-it-professionals" data-original-url="/marketing-comms/social-media/369595/best-twitter-alternatives-for-businesses-and-it-professionals">Best Twitter alternatives for businesses and IT professionals</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/marketing-comms/social-media/369095/elon-musk-condemns-twitters-data-security-lapses" data-original-url="/marketing-comms/social-media/369095/elon-musk-condemns-twitters-data-security-lapses">Elon Musk condemns Twitter's data security lapses</a></p></div></div><p>Prior to his time at Twitter, Zatko had led cyber security research at the <a href="https://www.itpro.com/technology/34730/10-amazing-darpa-inventions" data-original-url="https://www.itpro.com/technology/34730/10-amazing-darpa-inventions">Defense Advanced Research Projects Agency (DARPA)</a>, where he headed up a number of projects and helped shape the US Department of Defense framework for assessing military cyber security.</p><p>He subsequently worked with Google’s Advanced Technology and Projects group (ATAP), a technology incubator intended to produce innovative tech solutions and support a wide range of research.</p><p>Zatko had also become a widely-known member of the <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">ethical hacking</a> group Cult of the Dead Cow in the 1980s under the name ‘Mudge’, and also used this handle as a member of the Boston hacker collective L0pht Heavy Industries.</p><p><em>IT Pro has reached out to Rapid7 for comment.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ China-backed hackers take down Amnesty International Canada for three weeks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369656/china-backed-hackers-take-down-amnesty-international-canada-for-three-weeks</link>
                                                                            <description>
                            <![CDATA[ Cyber security experts linked state-sponsored APTs to the tools and methodology of the attack, which may have been intended as a covert campaign ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Kytjm2YyRqHhLDVmgmh4U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FaReWHXkRoUmCghWxHFfMF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Dec 2022 13:16:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FaReWHXkRoUmCghWxHFfMF-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A sign bearing the Amnesty International logo is held up in front of a skyscraper]]></media:description>                                                            <media:text><![CDATA[A sign bearing the Amnesty International logo is held up in front of a skyscraper]]></media:text>
                                <media:title type="plain"><![CDATA[A sign bearing the Amnesty International logo is held up in front of a skyscraper]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FaReWHXkRoUmCghWxHFfMF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amnesty International Canada confirmed that it was the victim of a Chinese state-backed threat actor in October which took its systems down for three weeks in an apparent espionage operation.</p><p>No evidence has been found to suggest that sensitive information was exfiltrated in the incident but Chinese state-backed cyber attackers are known for prioritising espionage as a key mission objective.</p><p>Once aware of the breach, Amnesty International Canada began an investigation of its network with the assistance of cyber security experts and forensic investigators, who determined that an advanced persistent threat group (APT) was behind the attack. Security firm Secureworks drew a link between the evidence and known methodology of China-backed hackers.</p><p>The threat actors were reportedly attempting to monitor the organisation's network without being detected, perhaps with the intention of building a list of contacts and Amnesty International activity, per <em>CBC News.</em></p><p>"The assessment that this breach was likely perpetrated by a Chinese state-sponsored threat group was based on several factors," Mike McLellan, director, counter threat unit at Secureworks told <em>IT Pro.</em></p><p>"Firstly, the tools, techniques and infrastructure we identified are consistent with those we have previously associated to Chinese threat groups.</p><p>"Secondly, the nature of Amnesty International Canada as an organisation, and more specifically the information that was targeted, would be of direct interest to the Chinese state. And thirdly, the length of time the threat actors were in the environment, coupled with the absence of any apparent attempt to monetise their access, for example by deploying ransomware, points towards espionage rather than financial gain as the motivation for the attack."</p><p>"This assessment is based on the nature of the targeted information as well as the observed tools and behaviours, which are consistent with those associated with Chinese cyber espionage threat groups," read the Secureworks report, via <a href="https://www.cbc.ca/news/politics/amnesty-international-canada-cyber-attack-china-1.6674788"><em>CBC News</em></a>.</p><p>Secureworks keeps a detailed <a href="https://www.secureworks.com/research/threat-profiles" rel="noopener noreferrer" target="_blank">catalogue</a> of threat actor profiles, with information on the states to which each threat group is linked, their known aliases, and the tools characteristic of each group. It has listings for ten such Chinese threat actors, with listed tools including <a href="https://www.itpro.com/malware/29515/hackers-spread-hidden-malware-to-227-million-people-via-ccleaner" rel="noopener noreferrer" target="_blank" data-original-url="https://www.itpro.com/malware/29515/hackers-spread-hidden-malware-to-227-million-people-via-ccleaner">CCleaner</a> and <a href="https://www.itpro.com/security/ransomware/361160/mandiant-releases-details-on-maverick-fast-attack-ransomware-group-fin12" rel="noopener noreferrer" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/361160/mandiant-releases-details-on-maverick-fast-attack-ransomware-group-fin12">PowerShell Empire</a>.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEepSJfbVh7mxRAUSTFsXo" name="dEepSJfbVh7mxRAUSTFsXo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" mos="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 IBM's Security X-Force cloud threat landscape report</strong></p><p class="fancy-box__body-text">Recommendations for preparing and responding to cloud breaches</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report" data-original-url="/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report">FREE DOWNLOAD</a></p></div></div><p>“As an organisation advocating for human rights globally, we are very aware that we may be the target of state-sponsored attempts to disrupt or surveil our work,” said Ketty Nivyabandi, secretary general of Amnesty International Canada in the organisation’s <a href="https://amnesty.ca/news/news-releases/cyber-breach-statement">blog post</a> on the incident.</p><p>“These will not intimidate us and the security and privacy of our activists, staff, donors, and stakeholders remain our utmost priority.”</p><p>“This case of cyber espionage speaks to the increasingly dangerous context which activists, journalists, and civil society alike must navigate today. Our work to investigate and denounce these acts has never been more critical and relevant. We will continue to shine a light on human rights violations wherever they occur and to denounce the use of digital surveillance by governments to stifle human rights,” she added.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1599861968638119937"></a></p></blockquote><div class="see-more__filter"></div></div><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/369651/millions-in-us-covid-funds-seized-from-china-backed-hackers" data-original-url="/business/policy-legislation/369651/millions-in-us-covid-funds-seized-from-china-backed-hackers">US seizes millions in stolen COVID relief funds by China-backed hackers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">The new wave of cyber security threats facing critical national infrastructure (CNI)</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369236/us-military-contractor-hacked-through-microsoft-exchange" data-original-url="/security/vulnerability/369236/us-military-contractor-hacked-through-microsoft-exchange">US military contractor hacked through Microsoft Exchange vulnerabilities, custom exfiltration tools</a></p></div></div><p>Cyber security agencies such as the US Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) have <a href="https://www.itpro.com/security/cyber-security/367420/nation-state-hacking-tools-target-ot-businesses" data-original-url="https://www.itpro.com/security/cyber-security/367420/nation-state-hacking-tools-target-ot-businesses">warned businesses that nation-state hacking tools</a> are being used to compromise <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">critical national infrastructure (CNI)</a>. </p><p>On 6 December, the US Secret Service <a href="https://www.itpro.com/business/policy-legislation/369651/millions-in-us-covid-funds-seized-from-china-backed-hackers" data-original-url="https://www.itpro.com/business/policy-legislation/369651/millions-in-us-covid-funds-seized-from-china-backed-hackers">seized millions in COVID funds stolen by China-backed hackers</a>, tracked as APT41, in a first-of-its-kind fraud linked to a nation state. APT41 has previously been credited for the <a href="https://www.itpro.com/security/vulnerability/365718/chinese-apt41-hackers-compromised-us-state-governments" data-original-url="https://www.itpro.com/security/vulnerability/365718/chinese-apt41-hackers-compromised-us-state-governments">hacking of six US government networks</a>, and a number of arrests have been made around individuals associated with the group.</p><p><a href="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks" data-original-url="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks">Chinese cyber attacks</a> have continued to dominate headlines, even as Russian-backed threat actors continue <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">cyber attacks on Ukraine</a>, and warnings that they could <a href="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine" data-original-url="https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine">attack other European nations</a>. </p><p><em>This article was updated to include a comment by Secureworks.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft: Russia increasingly timing cyber attacks with missile strikes in Ukraine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-warfare/369638/microsoft-russia-coordinating-cyber-attacks-missile-strikes-ukraine</link>
                                                                            <description>
                            <![CDATA[ The tech giant also warned that other European nations could be targeted by pro-Russian threat actors seeking to weaken supply chains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3XJAEDSxXTEHNEDn6fj8XC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8TMxhmpPnyT43pPKfAujqY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 05 Dec 2022 11:54:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8TMxhmpPnyT43pPKfAujqY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Ukrainian flag generated digitally in the form of data]]></media:description>                                                            <media:text><![CDATA[The Ukrainian flag generated digitally in the form of data]]></media:text>
                                <media:title type="plain"><![CDATA[The Ukrainian flag generated digitally in the form of data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8TMxhmpPnyT43pPKfAujqY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has revealed that Russia is increasingly combining cyber attacks against Ukraine with strikes using conventional weaponry such as missiles, in a multi-pronged offensive that could extend beyond the borders of the conflict.</p><p>Research conducted by Microsoft has shown that 55% of the 50 or so Ukrainian organisations hit by Russian malware since February are responsible for critical infrastructure, such as energy, water, emergency services, and healthcare - sectors that have also been the focus of intense missile strikes.</p><p>In recent months, affected organisations have largely been located in and around the areas of heaviest physical conflict, such as Kyiv and the country’s south.</p><p>As cyber and kinetic attacks continue to line up, Microsoft has also pointed to mounting evidence that Russia seeks to carry out cyber attacks outside of Ukraine. These have caused strategic damage to supporters of the country in parallel to its continued bombardment of Ukrainian targets.</p><p>Attacks on European states could be carried out with the goal of disabling supply chains crucial for maintaining support to Ukraine, Microsoft said, pointing to its recent warnings over the <a href="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses" data-original-url="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses">Prestige ransomware targeting Poland</a> as proof that such a campaign has already begun.</p><p>In a <a href="https://blogs.microsoft.com/on-the-issues/2022/12/03/preparing-russian-cyber-offensive-ukraine">blog post</a> on its outlook, Microsoft warned that attacks on Ukrainian <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">critical national infrastructure (CNI)</a> are likely to continue through the winter.</p><p>At the end of October, missile strikes left 80% of Kyiv without running water, while missile strikes left 10 million premises without power - conditions that have caused particular worry as Ukraine enters its coldest months.</p><p><a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Russian cyber attacks on Ukraine</a> have largely been carried out by a threat group tracked by Microsoft as IRIDIUM, which has close ties to Russia’s Main Intelligence Directorate, otherwise known as the GRU.</p><p>Historical attacks credited to IRIDIUM include the <a href="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack" data-original-url="https://www.itpro.com/malware/25804/ukrainian-power-grid-downed-by-cyber-attack">crippling of Ukraine’s power grid in 2015</a> and 2016 through the Disakil Trojan. 2017’s infamous <a href="https://www.itpro.com/malware/34381/what-is-notpetya" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> attack, which used a highly destructive wiper <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> that targeted Ukrainian infrastructure, is another example of IRIDIUM's work. It eventually caused over $10 billion to companies like Maersk and Merck. </p><p>Since the invasion, the organisation has launched more wiper variants such as <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Hermetic Wiper</a>, a malware and believed to have been specifically designed in anticipation of the invasion. In recent months, as Russia lost land and suffered defeats across Ukraine, IRIDIUM has increased activity with wipers such as Caddywiper and <a href="https://www.itpro.com/security/cyber-attacks/364040/big-tech-fights-russia-cyber-offensive-vs-ukraine" data-original-url="https://www.itpro.com/security/cyber-attacks/364040/big-tech-fights-russia-cyber-offensive-vs-ukraine">Foxblade</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369438/uks-6m-cyber-support-package-for-ukraine-revealed-for-first-time" data-original-url="/security/369438/uks-6m-cyber-support-package-for-ukraine-revealed-for-first-time">UK's £6m cyber support package for Ukraine revealed for first time</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/367633/national-security-leaders-fear-ukraine-conflict-could-inform-a-blueprint-cyber-war" data-original-url="/security/367633/national-security-leaders-fear-ukraine-conflict-could-inform-a-blueprint-cyber-war">National security leaders fear Ukraine conflict could inform a 'blueprint' for cyber war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website" data-original-url="/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website">Pro-Russia Killnet hackers claim DDoS attack on EU Parliament website</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEepSJfbVh7mxRAUSTFsXo" name="dEepSJfbVh7mxRAUSTFsXo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" mos="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 IBM's Security X-Force cloud threat landscape report</strong></p><p class="fancy-box__body-text">Recommendations for preparing and responding to cloud breaches</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report" data-original-url="/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report">FREE DOWNLOAD</a></p></div></div><p>In this next step of the campaign, researchers also warned that Russia is likely to use mass <a href="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation" data-original-url="https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation">disinformation</a> to stoke concerns around the <a href="https://www.itpro.com/server-storage/data-centres/369089/gartner-predicts-energy-crisis-will-hit-data-centre-budgets-by" data-original-url="https://www.itpro.com/server-storage/data-centres/369089/gartner-predicts-energy-crisis-will-hit-data-centre-budgets-by">energy crisis</a>, in an attempt to shift public opinion in favour of ending the war on terms agreeable to the Kremlin.</p><p>German and Czech entities were named as having existing sympathy with Russia, and there is concern that social media could enable pro-Russian talking points to gain traction in these regions off the back of seemingly-rational economic concerns.</p><p>“Clandestine cyber warfare is rapidly becoming a thing of the past,” said Nadir Izrael, CTO and co-founder at Armis.</p><p>“We now see brazen cyber attacks by nation-states, often with the intent to gather intelligence, disrupt operations, or outright destroy data. Based on these trends, all organisations should consider themselves possible targets for <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber warfare</a> attacks and secure their assets accordingly.”</p><p>In response to the attacks, Microsoft has reaffirmed its commitment to identifying threat actors who seek to attack key Ukrainian and European supply chains, and submit reports on Russia-sponsored cyber operations to both partners and the public.</p><p>Alongside its information gathering and reporting efforts, Microsoft will also continue its active defence of the cyber landscape, with a stated goal of protecting Ukrainian academics, journalists, and nonprofits that are crucial to shedding light on the attacks being perpetrated by Russia.</p><p>Representatives within Microsoft’s Digital Diplomacy and Democracy Forward teams will also talk to victims and their governments to organise a unified response to state-sponsored cyber attacks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT Pro News in Review: Hyundai vulnerability fixed, Meta served GDPR fine, Salesforce co-CEO resigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/business-strategy/369634/it-pro-news-in-review-december_1</link>
                                                                            <description>
                            <![CDATA[ Catch up on the biggest headlines of the week in just two minutes ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kGop1qQCyojPBMzxymf74</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FfEWGp3R89vkvykpTQ2tRX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Dec 2022 13:27:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FfEWGp3R89vkvykpTQ2tRX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A thumbnail for the IT Pro News in Review video showing the Hyundai, Meta, and Salesforce logos displayed on a blue digital background]]></media:description>                                                            <media:text><![CDATA[A thumbnail for the IT Pro News in Review video showing the Hyundai, Meta, and Salesforce logos displayed on a blue digital background]]></media:text>
                                <media:title type="plain"><![CDATA[A thumbnail for the IT Pro News in Review video showing the Hyundai, Meta, and Salesforce logos displayed on a blue digital background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FfEWGp3R89vkvykpTQ2tRX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/w8mCf8adPSM" allowfullscreen></iframe></div></div><p>Welcome to IT Pro's News in Review, a weekly bite-sized bulletin of the top tech stories of the week, for the week ending 2nd December, 2022.</p><p>This week's stories:</p><ul><li><a href="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine" data-original-url="https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine">Hyundai vulnerability allowed remote hacking of locks, engine</a></li><li><a href="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine" data-original-url="https://www.itpro.com/business/policy-legislation/369609/unacceptable-data-scraping-lands-meta-228m-fine">"Unacceptable" data scraping lands Meta a £228m data protection fine</a></li><li><a href="https://www.itpro.com/business/business-operations/369621/salesforce-co-ceo-bret-taylor-resigns-cryptic-message" data-original-url="https://www.itpro.com/business/business-operations/369621/salesforce-co-ceo-bret-taylor-resigns-cryptic-message">Salesforce co-CEO Bret Taylor resigns with cryptic parting message</a></li></ul><p>You can find more videos like this in our video library and even more on <a href="https://www.youtube.com/user/itpro" rel="noopener" target="_blank">our YouTube channel</a>. Let us know what you think of this week's video – you can also find us on <a href="https://www.facebook.com/ITProUK" rel="noopener" target="_blank">Facebook</a>, <a href="https://www.linkedin.com/company/itpro-uk" rel="noopener" target="_blank">LinkedIn</a> and <a href="https://twitter.com/ITPro" rel="noopener" target="_blank">Twitter</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'CryWiper' trojan disguises as ransomware, says Kaspersky ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369633/crywiper-trojan-disguises-as-ransomware-kaspersky</link>
                                                                            <description>
                            <![CDATA[ The destructive wiper mocks up files as if encrypted, while in reality overwriting all but core system files ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dgqqaXAYjFmByeU4WSZ7Fm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 02 Dec 2022 12:46:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:description>                                                            <media:text><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:text>
                                <media:title type="plain"><![CDATA[Toy horse on a digital screen to symbolise the attack of the Trojan virus]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4x8LJKuPeaTUDqefPN5aAD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new wiper trojan, disguised as a ransomware payload, has been discovered in the wild by researchers, raising questions about the reason for its existence and the identity of its operators.</p><p>CryWiper, named for the distinctive ‘.cry’ extension which it appends onto files, appears on first impression to be a new ransomware strain. Victims’ devices are seemingly encrypted and a ransom note is left demanding money be sent to a <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">bitcoin</a> wallet address. However, the files are actually corrupted beyond recovery.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eNyWocwZkU6AFRW4cbpF2B" name="eNyWocwZkU6AFRW4cbpF2B.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" mos="https://cdn.mos.cms.futurecdn.net/eNyWocwZkU6AFRW4cbpF2B.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Getting board-level buy-in for security strategy</strong></p><p class="fancy-box__body-text">Why cyber security needs to be a board-level issue</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy" data-original-url="/security/cyber-security/369454/getting-board-level-buy-in-for-security-strategy">FREE DOWNLOAD</a></p></div></div><p>Kaspersky researchers laid out findings that prove the malware is actually a wiper that corrupts all but the most critical system files, overwriting each with data produced through a pseudo-random number generator. </p><p>Once on a victim’s system, CryWiper sends the name of the victim’s device to a command and control (C2) server, waiting for an activation command to launch an attack.</p><p>This follows a similar methodology to ransomware, with functions performed including the deletion of volume shadow copy to prevent files from being restored and scheduling itself in Windows Task Scheduler to ensure that it restarts every five minutes.</p><p>CryWiper also ceases MS SQL, MySQL, MS Active Directory, and MS Exchange services, so that files associated with them are not prevented from being corrupted.</p><p>Researchers <a href="http://www.kaspersky.com/blog/crywiper-pseudo-ransomware/46480">noted</a> that it disables connection to infected devices through <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp" data-original-url="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp">remote desktop protocol (RDP)</a> too, and posited that this is to frustrate the efforts of security teams responding to the incident.</p><p>This marks a divergence from typical ransomware behaviour, as payloads generally maintain RDP access in order to facilitate lateral attacks across networks.</p><p>A wiper is a <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> strain designed to destroy systems indiscriminately, or otherwise cause chaos and destruction on a victim’s device. Wipers have been widely used in <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Russia’s cyber war against Ukraine</a>, and form part of a malware arsenal that has formed the backbone of the growing <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">threat against critical national infrastructure (CNI)</a>.</p><p>An email address provided in the ransom text file has been in use since 2017, linking it to several former <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware families</a>. No conclusive identification has yet been made linking any of the groups.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up" data-original-url="/security/ransomware/369506/ransomware-why-do-businesses-still-pay-up">Ransomware: Why do businesses still pay up?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses" data-original-url="/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses">Microsoft warns of 'Prestige' ransomware targeting business in Ukraine, Poland</a></p></div></div><p>In a Russian-language <a href="https://securelist.ru/novyj-troyanec-crywiper/106114">blog post</a> unpacking the technical details of the malware, Kaspersky researchers drew further similarities between CryWiper and another wiper observed attacking public infrastructure in Ukraine earlier this year, known as IsaacWiper.</p><p>Both wipers use the same pseudo-random generator, ‘Mersenne Vortex’, and are the only two to do so due to the relative complexity of the algorithm compared to other options.</p><p>“It’s not common practice, however, deploying destructive payloads that contain ransom notes, with no intention to receive a ransom has been seen before,” said Andy Norton, European cyber risk officer at Armis.</p><p>“<a href="https://www.itpro.com/malware/34381/what-is-notpetya" data-original-url="https://www.itpro.com/malware/34381/what-is-notpetya">NotPetya</a> is an example of a previous wiper attack. Plausible deniability is one reason to add false flags to malware payloads, another tactic is to invent fictitious threat actor groups, such as the 'Cutting Sword of Justice' again with the reason to deflect attribution of the attack.”</p><p>At the time of writing, Kaspersky has only observed targeted CryWiper attacks within the Russian Federation. Given the unknown nature of the group behind CryWiper, as well as the strategic intent of the trojan at this stage, businesses should remain alert to the telltale signs of the payload.</p><p>To avoid compromise, Kaspersky recommends close oversight of remote network connections, the use of <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> tunnels for RDP access, as well as strong rather than <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">common passwords</a>, and <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a> where possible.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass admits 'elements' of customer data accessed in breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/369623/lastpass-admits-elements-of-customer-data-accessed-in-breach</link>
                                                                            <description>
                            <![CDATA[ The password manager denies the exfiltration of any password data in an attack that also hit affiliate GoTo ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s5VbBwKbC6km6Jk5epf2qH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Dec 2022 12:23:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:description>                                                            <media:text><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:text>
                                <media:title type="plain"><![CDATA[The word LastPass, next to four asterisks indicating a password]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/M3NLuNwjS2FQFXDJMSyYAL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password manager firm LastPass has revealed that it was subject to another security breach in which a threat actor accessed a system used by the firm, as well as some customer information.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dEepSJfbVh7mxRAUSTFsXo" name="dEepSJfbVh7mxRAUSTFsXo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" mos="https://cdn.mos.cms.futurecdn.net/dEepSJfbVh7mxRAUSTFsXo.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 IBM's Security X-Force cloud threat landscape report</strong></p><p class="fancy-box__body-text">Recommendations for preparing and responding to cloud breaches</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report" data-original-url="/cloud/cloud-security/369568/2022-ibms-security-x-force-cloud-threat-landscape-report">FREE DOWNLOAD</a></p></div></div><p>LastPass said that unusual activity was detected on a third-party cloud storage platform used by LastPass. Following the launch of an investigation involving cyber security firm Mandiant, it was established that a threat actor accessed some customer information.</p><p>There is no evidence to suggest that customer passwords were affected or obtained in the attack, and LastPass states that all passwords remain securely <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encrypted</a>.</p><p>The incident follows a similar attack in August in which a <a href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">hacker stole LastPass source code</a>. In that case, the hacker made use of a compromised developer account to breach the company’s development environment and then stole source code and technical information. At the time, the firm denied that any customer data or password vaults were stolen.</p><p>In the statement announcing the recent incident, LastPass CEO Karim Toubba linked the two attacks by suggesting that it was information stolen in the August incident that enabled this new attack.</p><p>“We have determined that an unauthorised party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” said Toubba in a <a href="https://blog.lastpass.com/2022/11/notice-of-recent-security-incident">blog post</a>. “Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture.</p><p>“We are working diligently to understand the scope of the incident and identify what specific information has been accessed. In the meantime, we can confirm that LastPass products and services remain fully functional.”</p><p>LastPass affiliate GoTo (formerly LogMeIn) was also affected in the attack; the two companies share the same third-party cloud storage service. </p><p>In a <a href="https://www.goto.com/blog/our-response-to-a-recent-security-incident">blog post</a> covering the incident, GoTo CEO Paddy Srinivasan said that the company “detected unusual activity within our development environment and third-party cloud storage service”.</p><p>The company stated that all its products and services remain operational and that it is deploying further security measures and monitoring to prevent further activity from threat actors.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen" data-original-url="/security/hacking/368898/lastpass-breach-ceo-says-no-evidence-of-customer-data-being-stolen">LastPass breach: CEO says 'no evidence' of customer data being stolen</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="/software/368077/best-password-managers-in-2022">Best password managers</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a></p></div></div><p>GoTo has not offered further information on the specific activity performed within its development environment, and unlike LastPass made no mention of customer information being affected.</p><p>"Third-party cloud storage certainly poses risks for organisations," said Javvad Malik, lead security awareness advocate at KnowBe4, to <em>IT Pro.</em> "This will vary depending on the nature of data that is stored or processed on the third-party cloud.</p><p>"Data can sometimes be considered similar to chemical elements. On their own, maybe a certain element is stable and benign. But mix it with other stable elements under the right conditions and you could end up with something volatile. </p><p>"Similarly, we cannot completely dismiss any data breach as completely benign. There is always something that can be taken which could be combined with other data elements, or saved for future use. So while the risk may be low, we cannot say there is no risk at all. In all of this though, it is important to commend LastPass for their exemplary transparency in their incident response."</p><p><a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">Password managers</a> are a popular solution for storing logins securely, and can be extremely beneficial for business use especially in roles burdened with a large number of critical passwords.</p><p>In addition to safely storing passwords, such managers also generate cryptographically secure passwords that are far more difficult for hackers to guess than the <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">more commonly used ones</a>.</p><p>LastPass has urged customers to follow its recommended security practices and is working with GoTo, Mandiant, and law enforcement services to investigate the issue.</p><p><em>IT Pro</em> has approached GoTo for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hyundai vulnerability allowed remote hacking of locks, engine ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369617/hyundai-vulnerability-allowed-remote-hacking-of-locks-engine</link>
                                                                            <description>
                            <![CDATA[ Researchers discovered flaws in a number of apps linked to car brands that allowed for personal details and remote control of vehicles using easily-obtained IDs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">i8ZbxHzNYiVmtEjxPnd238</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Nov 2022 13:03:41 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:description>                                                            <media:text><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:text>
                                <media:title type="plain"><![CDATA[A phone screen displaying the Hyundai logo, with a car&amp;#039;s dashboard in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PsNDgsB39eqkzsJDBUMT4M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have discovered a vulnerability affecting Hyundai and Genesis cars, which would have allowed hackers to remotely control functions such as the door locks and engine. </p><p>The exploit impacts cars by Hyundai and Genesis released since 2012 and targets a weakness in the use of insecure vehicle data in mobile apps intended for use by the owners of the vehicles.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4qUL44hnm28GfMZkPQvas" name="4qUL44hnm28GfMZkPQvas.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4qUL44hnm28GfMZkPQvas.png" mos="https://cdn.mos.cms.futurecdn.net/4qUL44hnm28GfMZkPQvas.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Forrester Wave API management solutions, Q3 2022</strong></p><p class="fancy-box__body-text">The 15 providers that matter most and how they stack up</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/application-programming-interface-api/369374/the-forrester-wave-api-management" data-original-url="/development/application-programming-interface-api/369374/the-forrester-wave-api-management">FREE DOWNLOAD</a></p></div></div><p>The API calls used to control the locks, horn, engine, headlights, and boot controls of cars were easily exploitable, and could be backwards engineered to give hackers full remote access to the car's functions, the researchers said.</p><p>In a <a href="https://twitter.com/samwcyo/status/1597695281881296897">thread</a> on Twitter, bug bounty hunter Sam Curry explained the process in full. Within the affected apps, functionality like locking and unlocking the user’s car was secured behind an access token, a JSON web token generated from an authenticated email account, checked against the HTTP request made in the app and the car’s vehicle identification number (VIN). </p><p>However, the regular expression (regex) used to accept email strings as valid allowed for the inclusion of special characters. Curry and fellow researchers quickly discovered that by appending a carriage return line feed (CRLF) character at the end of an email address that already existed on the system, they could send an HTTP request to a secure endpoint. This contained a list of vehicles registered to the given address, allowing for the VINs of any chosen customer to be harvested.</p><p>Using the faked JWT, the researchers sent an unlock vehicle request to a car owned by a collaborator, and received “200 OK” back at the same time as the car's locks responded to the request.</p><p>Once the manual process had been figured out, the researchers were able to massively reduce the steps a threat actor would have to take, using a simple <a href="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference" data-original-url="https://www.itpro.com/development/programming/368567/coding-vs-programming-vs-scripting-whats-the-difference">script</a> written in <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer" data-original-url="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer">Python</a>. Using this, all that was required was the victim’s email address to gain access to their car, and commands could be run entirely within the program.</p><p>"Hyundai worked diligently with third-party consultants to investigate the purported vulnerability as soon as the researchers brought it to our attention," a Hyundai spokesperson told <em>IT Pro</em>. </p><p>"Importantly, other than the Hyundai vehicles and accounts belonging to the researchers themselves, our investigation indicated that no customer vehicles or accounts were accessed by others as a result of the issues raised by the researchers. </p><p>"We also note that in order to employ the purported vulnerability, the e-mail address associated with the specific Hyundai account and vehicle as well as the specific web-script employed by the researchers were required to be known. Nevertheless, Hyundai implemented countermeasures within days of notification to further enhance the safety and security of our systems. We value our collaboration with security researchers and appreciate this team’s assistance."</p><p>Earlier in the year, Curry and other researchers stress-tested a number of similar telematics apps, with the common link of developer SiriusXM Connected Vehicle Services (SiriusXM), as outlined in a subsequent Twitter <a href="https://twitter.com/samwcyo/status/1597792097175674880">thread</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/25250/researchers-prove-self-driving-cars-can-be-hacked" data-original-url="/security/25250/researchers-prove-self-driving-cars-can-be-hacked">Researchers prove self-driving cars can be hacked</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022" data-original-url="/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022">Revealed: The top 200 most common passwords of 2022</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch" data-original-url="/security/vulnerability/369147/11-million-tesla-cars-recalled-over-software-glitch">1.1 million Tesla cars recalled over software glitch</a></p></div></div><p>“We take the security of our customers’ accounts seriously and participate in a bug bounty program to help identify and correct potential security flaws impacting our platforms," a Sirius XM Connected Vehicle Services spokesperson told <em>IT Pro</em>.</p><p>"As part of this work, a security researcher submitted a report to Sirius XM's Connected Vehicle Services on an authorization flaw impacting a specific telematics program. The issue was resolved within 24 hours after the report was submitted. At no point was any subscriber or other data compromised nor was any unauthorised account modified using this method.”</p><p>SiriusXM provides connected vehicles systems for cars from a number of household automotive brands. Researchers discovered that through the use of only the VIN of a customer’s car, it was possible to not only remotely activate vehicle features, but to also fetch a customer’s user profile within the NissanConnect app. This contained details including the victim’s name, phone number, and address. Similar vulnerabilities were replicated in the apps of Honda, Infiniti, FCA, and Acura.</p><p>Derek Abdine, CEO at <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">artificial intelligence (AI)</a> company furl, <a href="https://twitter.com/dabdine/status/1597876317025812480">responded</a> to Curry with the claim that VINs are widely available on dealership websites.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1597876317025812480"></a></p></blockquote><div class="see-more__filter"></div></div><p>All vulnerabilities were reported to the relevant companies, which have patched the vulnerabilities.</p><p>Concerns around the vulnerability of cars that connect to apps have been around for years. In 2016, the <a href="https://www.itpro.com/security/hacking" data-original-url="https://www.itpro.com/hacking/26234/fbi-issues-connected-car-hacking-warning">FBI warned connected cars can be hacked</a>, and particularly stressed the risk posed by cars that connect to mobile devices. The same year, <a href="https://www.itpro.com/security/27278/tesla-patches-model-s-after-chinese-hack" data-original-url="https://www.itpro.com/security/27278/tesla-patches-model-s-after-chinese-hack">Chinese hackers remote targeted a Tesla</a>, with security researchers as Tencent’s Keen Labs passing the details of the successful attack onto the EV firm to patch.</p><p><em>This article originally stated that Hyundai cars could be accessed without the need for a victim's email address. This was inaccurate, and the article has now been updated to reflect this.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pro-Russia Killnet hackers claim DDoS attack on EU Parliament website ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/369592/killnet-hackers-claim-ddos-attack-on-eu-parliament-website</link>
                                                                            <description>
                            <![CDATA[ The attack was launched shortly after MEPs voted to brand Russia a state-sponsor of terrorism for its invasion of Ukraine ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sAsqTqCwYL4PPyk4ZFEJ8r</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uTSncYvJbVKiWdnhg4b4p5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Nov 2022 11:35:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uTSncYvJbVKiWdnhg4b4p5-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[EU parliament ]]></media:description>                                                            <media:text><![CDATA[EU parliament ]]></media:text>
                                <media:title type="plain"><![CDATA[EU parliament ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uTSncYvJbVKiWdnhg4b4p5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian-aligned hackers have claimed responsibility for a cyber attack on the European Parliament's website on Wednesday. </p><p>The website was forced offline for around two hours after the pro-Russia Killnet hacking group launched a distributed denial of service (DDoS) attack against it - an attack method the group has widely adopted in its ongoing efforts to target pro-Ukrainian authorities.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L47gbigPjNi8zfgWvSgmk3" name="L47gbigPjNi8zfgWvSgmk3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" mos="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 Magic quadrant for Security Information and Event Management (SIEM)</strong></p><p class="fancy-box__body-text">SIEM is evolving into a security platform with multiple features and deployment models</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security" data-original-url="/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security">FREE DOWNLOAD</a></p></div></div><p>The attack came just after members of the parliament voted to designate Russia as a state sponsor of terrorism following its invasion of Ukraine.</p><p>European Parliament President Roberta Metsola said in a <a href="https://twitter.com/EP_President/status/1595443471518777345">tweet</a> at the time that the website was facing "a sophisticated cyberattack”.</p><p>“A pro-Kremlin group has claimed responsibility. Our IT experts are pushing back against it and protecting our systems. This, after we proclaimed Russia as a state-sponsor of terrorism,” she added. “My response: #SlavaUkraini.”</p><p>Yesterday, politicians voted to declare Russia a state sponsor of terrorism, however, this is largely a token gesture as it doesn’t have legal powers to enforce this decision.</p><p>"The deliberate attacks and atrocities committed by Russian forces and their proxies against civilians in Ukraine, the destruction of civilian infrastructure and other serious violations of international and humanitarian law amount to acts of terror and constitute war crimes," said a <a href="https://www.europarl.europa.eu/news/en/press-room/20221118IPR55707/european-parliament-declares-russia-to-be-a-state-sponsor-of-terrorism">statement</a> from the European Parliament.</p><p>Killnet claimed responsibility for the attack via its <a href="https://t.me/killnet_reservs/3710">Telegram channel</a>. "Strap-on shelling of the server part of the official website of the European Parliament!" one message read.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="/security/28026/what-is-a-ddos-attack">What is a DDoS attack?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cyber-attacks/31436/what-is-a-cyber-kill-chain" data-original-url="/cyber-attacks/31436/what-is-a-cyber-kill-chain">What is a cyber kill chain?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368760/south-korean-public-sector-organisations-targeted-by-gwisin-ransomware" data-original-url="/security/ransomware/368760/south-korean-public-sector-organisations-targeted-by-gwisin-ransomware">South Korean public sector organisations targeted by Gwisin ransomware</a></p></div></div><p>"It cannot be understated the ease with which Killnet are able to launch these relatively low-sophistication attacks and make global headlines," said Justin Fier, vice president of tactical risk and response at Darktrace. "The group has no shortage of ‘reservists’ who they can call up to launch such an attack as part of their so-called ‘<a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">hacktivism</a>’ – as seen in attacks on JP Morgan and the Lithuanian government earlier this year. The process for launching an attack such as this for one of their affiliates can be as simple as entering a URL into their attack tool software and hitting ‘run’.</p><p>“<a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">DDoS attacks</a>, which are often fairly easy to recover from, are Killnet’s modus operandi, which the group use to make a political statement and cause <a href="https://www.itpro.com/security/ransomware/361981/ransomware-only-the-bravest-businesses-will-survive" data-original-url="https://www.itpro.com/security/ransomware/361981/ransomware-only-the-bravest-businesses-will-survive">reputational damage</a> rather than cause any kind of financial harm. We must be careful in pointing the finger at the Russian state – cyber attribution and deciphering the extent of state-level tasking is difficult, with blurred lines between state-aligned, state-involved and state-directed increasing the risk of escalation, collateral and <a href="https://www.itpro.com/security/hacking/368848/the-it-pro-podcast-does-threat-attribution-matter" data-original-url="https://www.itpro.com/security/hacking/368848/the-it-pro-podcast-does-threat-attribution-matter">misattribution</a>. Nonetheless, it does mount valid concerns that these citizen-led operations could become more destructive or that states could use these groups as a deniable proxy."</p><p>Killnet has risen to prominence in the past year since the war in Ukraine began and has claimed a number of attacks on various organisations and authorities that are against Russia's objectives.</p><p>Italy has been a particular focus of the group and the country has been the target of a large number of attacks against organisations within it over the past few months. </p><p>In May, Killnet <a href="https://www.itpro.com/security/cyber-warfare/367859/russian-killnet-cyber-attacks-begin-on-italian-linked-businesses" data-original-url="https://www.itpro.com/security/cyber-warfare/367859/russian-killnet-cyber-attacks-begin-on-italian-linked-businesses">carried out</a> a spate of attacks on organisations that had links to Italy and in June, also attacked the <a href="https://www.itpro.com/security/ransomware/368266/vice-society-ransomware-palermo-details-recovery-strategy" data-original-url="https://www.itpro.com/security/ransomware/368266/vice-society-ransomware-palermo-details-recovery-strategy">Italian municipality of Palermo</a> in an incident believed to have involved ransomware.</p><p>In August, Estonia <a href="https://www.itpro.com/security/cyber-warfare/368844/estonia-fends-off-major-cyber-attack-following-soviet-era-monuments" data-original-url="https://www.itpro.com/security/cyber-warfare/368844/estonia-fends-off-major-cyber-attack-following-soviet-era-monuments">successfully withstood and survived</a> its "most extensive cyber attack since 2007" soon after it removed Soviet monuments from a region dominated by ethnic Russians, an attack that was also attributed to Killnet.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: How secure is metaverse tech? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech</link>
                                                                            <description>
                            <![CDATA[ If we're not careful, the risks of this new frontier could outweigh the rewards ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hiH2QHFVmKCi5G9beQYTZw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Nov 2022 18:35:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Metaverse technology: although it still hasn’t found its feet, it’s the headline-grabbing area of development that has seen massive investment in just the past few years. Meta has spent over $15 billion on the tech through its Reality Labs division, and Microsoft, Apple, Nvidia, and more have all begun development using variations on metaverse tech.</p><p>But like any new technology, metaverse tech will also usher in new security risks, from innovative threat actors and existing vulnerabilities inherited by building this new frontier on legacy architecture.</p><p>This week, we spoke to Rick McElroy, Principal Cyber Security Strategist at VMware, about the opportunities and challenges metaverse tech, and what we can do while it’s still in its infancy.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=51929629&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights-4">Highlights</h2><p>“The cool part of all of it is, we actually get to design it. Right? Like, we're humans, we're now working on some in the future. And so we do get to look at the past, have those design considerations? And then really move forward with like, how can we start to fundamentally get rid of some of these things from the beginning, because we know that they're going to happen, right? And so I hope the opportunity is exciting for folks that are working on those projects.”</p><p>“I can tell you, I've talked to no CISOs over the last 18 months where it's at the top of their project list. Generally speaking, ransomware is still at the top of that list. Again, the security fundamentals of being able to patch as quickly as possible, and then of course, recover from some types of these attacks.”</p><p>“We're not writing a new internet protocol for the metaverse, it's going to be IPv6 and IPv4. Generally speaking, it'll be IPv6, because it's a lot of new companies that are adopting it. Manipulation of that TCP/IP stack is still real, those threats exist all the time, adversaries take advantage.”</p><p><a href="https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech" data-original-url="https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech"><em>Read the full transcript here.</em></a></p><h2 id="footnotes-4">Footnotes</h2><ul><li><a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">What is Web3 and will it revolutionise the internet again?</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/359093/microsoft-signs-22bn-deal-to-supply-us-army-with-hololens" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/359093/microsoft-signs-22bn-deal-to-supply-us-army-with-hololens">Microsoft signs $22bn deal to supply US Army with HoloLens devices</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/361676/apple-mixed-reality-ar-headet-2022-launch-analyst" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/361676/apple-mixed-reality-ar-headet-2022-launch-analyst">Apple's mixed reality headset could debut in 2022</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business">Why AR, not VR, is the next big thing in business</a></li><li><a href="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker" data-original-url="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker">Meta's earnings are 'cause for concern' and 2023 looks even bleaker</a></li><li><a href="https://www.itpro.com/technology/voice-assistant/367610/future-of-virtual-assistants-lies-in-the-metaverse" data-original-url="https://www.itpro.com/technology/voice-assistant/367610/future-of-virtual-assistants-lies-in-the-metaverse">The future of virtual assistants might lie in the metaverse</a></li><li><a href="https://www.mentalfloss.com/article/55136/did-pentagon-really-ban-furbys" data-original-url="https://https://www.mentalfloss.com/article/55136/did-pentagon-really-ban-furbys">Did the Pentagon really ban Furbys?</a></li><li><a href="https://www.itpro.com/security/368221/what-is-metaverse-security" data-original-url="https://www.itpro.com/security/368221/what-is-metaverse-security">What is metaverse security?</a></li><li><a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points" data-original-url="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">How to protect your endpoints</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip" data-original-url="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">What is TCP/IP?</a></li><li><a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip" data-original-url="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">Whatever happened to IPv6?</a></li><li><a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">What is zero trust?</a></li><li>What is GDPR? Everything you need to know, from requirements to fines</li><li><a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">What is the California Consumer Privacy Act (CCPA)?</a></li><li><a href="https://www.itpro.com/business-operations/sales/366246/understanding-pci-compliance-the-role-of-the-channel" data-original-url="https://www.itpro.com/business-operations/sales/366246/understanding-pci-compliance-the-role-of-the-channel">Understanding PCI compliance: The role of the channel</a></li><li><a href="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7" data-original-url="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7">What is Wi-Fi 7?</a></li><li><a href="https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack" data-original-url="https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack">US unveils next-gen encryption tools to withstand quantum computing attacks</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/368873/seven-steps-to-keeping-metaverse-meetings-safe-and-secure" data-original-url="https://www.itpro.com/business-strategy/collaboration/368873/seven-steps-to-keeping-metaverse-meetings-safe-and-secure">Seven steps to keeping metaverse meetings safe and secure</a></li><li><a href="https://www.itpro.com/business/business-strategy/369294/meta-deepens-metaverse-partnership-with-microsoft-and-accenture" data-original-url="https://www.itpro.com/business/business-strategy/369294/meta-deepens-metaverse-partnership-with-microsoft-and-accenture">Meta deepens metaverse partnership with Microsoft and Accenture, still lacks compelling business case</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/361197/immersive-tech-can-be-more-than-just-a-gimmick" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/361197/immersive-tech-can-be-more-than-just-a-gimmick">Immersive tech can be more than just a gimmick</a></li><li><a href="https://www.itpro.com/business-strategy/digital-transformation/368403/siemens-and-nvidia-partner-on-industrial-metaverse" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/368403/siemens-and-nvidia-partner-on-industrial-metaverse">Siemens and Nvidia partner on industrial metaverse concept</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned" data-original-url="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned">Into the metaverse: Everything we learned from our virtual tour</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/362032/metaverse-waste-of-time-effort-and-processing-power" data-original-url="https://www.itpro.com/business-strategy/collaboration/362032/metaverse-waste-of-time-effort-and-processing-power">The metaverse is a waste of time, effort and processing power</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: How secure is metaverse tech? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mzq5HmLipZZjt4E3zeQ67Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Nov 2022 18:35:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech" data-original-url="https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech">How secure is metaverse tech?</a>’ <em>We apologise for any errors.</em></p><h2 id="rory-bathgate-4">Rory Bathgate</h2><p>Hi, I’m Rory Bathgate. And you’re listening to the IT Pro Podcast, where this week we’re considering the risks and rewards of metaverse technology. In just the past few years alone, metaverse technology has seen massive growth and investment. Facebook retooled itself as Meta last year, and the company has subsequently spent over $15 billion on the tech through its Reality Labs division. Meanwhile, other big names in tech such as Microsoft and Nvidia have announced forays into metaverse tech themselves, and McKinsey says that in all, over $120bn was spent on metaverse tech in the first five months of 2022. But like with all innovations in the tech industry, metaverse tech carries the potential to bring many vulnerabilities along with its proposed benefits, with existing vulnerabilities carried across to this new frontier along with the potential for novel threats that make use of metaverse technology also becoming an issue. This week, we’re speaking to Rick McElroy, Principal Cyber Security Strategist at VMware, about the challenges posed by metaverse tech, and what can be done to address these while it’s still in its infancy. Rick, thanks so much for being on the show.</p><h2 id="rick-mcelroy">Rick McElroy </h2><p>Hey, thanks for having me. </p><h2 id="rory-29">Rory </h2><p>So just to start off with, what do you see as the main business use cases for Metaverse technology?</p><h2 id="rick">Rick </h2><p>Oh, that's interesting. I personally, think about the cost savings of sending humans like myself all over the globe, to whether that's facilitation of a meeting, audit, controls some sort of incident response engagement, there is a huge cost to transporting humans all over the globe to do their job, right. There's a huge cost to educate those humans. You just got back from VMware Explorer. And I think certainly organisations have explored something like virtualized conferences during the pandemic. And then I would say, as that starts to mature, as it starts to become more real, I do expect organisations to, to achieve some cost savings by being able to bring together people remotely in these types of areas. I certainly think I'm in the education space. This is a huge area where you can have virtualized universities where there's better connection than we do from an online university perspective. And so I do think, you know, some of those verticals are exploring those areas today. </p><h2 id="rory-30">Rory </h2><p>Fantastic. So you mainly see it as one of many tools to bring into the workplace, not necessarily radically changing how offices work in any way, potentially, but maybe for specific use cases, such as in education and in conferencing?</p><h2 id="rick-2">Rick </h2><p>I think potentially, in the end. But if you look at what happened over the pandemic, so the realism of having to send employees home caused a lot of organisations to have to change technologies change process, do all of these things. Well, we're back on the other side. And some companies have decided to start to bring people back to offices. And so it is a long tail, especially inside of organisations to adopt technology. When you look at certain verticals, certainly the federal vertical, the state and local verticals and municipalities and governments, they're just a little slower to bring that tech in, right? And so I know, meta, and all the good folks are instantly gonna see some consumer adoption. But I think in organisations, there'll be a vetting period. </p><h2 id="rory-31">Rory </h2><p>That's interesting that there might be a public private, delayed adoption. I mean, of course, that's something that we see across the tech sector. But it's interesting that you mentioned that. So assuming that metaverse technology does really take off in a big way, and certainly a lot of really large tech firms like Microsoft, Apple, of course, Meta. They all seem to think it will. What are some of the immediate cyber security concerns that it will raise? </p><h2 id="rick-3">Rick </h2><p>Well, I think the first one for me is we're building a bunch of new tech on top of old technology. So if you look at the back end of what's being built, it's still sitting on top of Linux servers with containers, which we fundamentally know are insecure based on lots of threat analysis, and lots of consulting with companies. And then of course, watching what the attackers are doing, right? So my first concern is, with any new technology, not building that with the misuse cases in mind, as a rush to market generally becomes, I think, concerning from a security and risk perspective. And so, I think having some thoughtfulness as we start to deliver some of this new technology specific areas that I think about: we haven't quite nailed identity yet, and misuse of identity. So those are key areas that I think if we dragged relying on passwords into the metaverse, that's probably a path that we know. It's a recipe towards breaches and towards some of that disastrous results. But I think if we're thoughtful about things like identities, if we're thoughtful about controls that we put in place to help identify folks, so that they can't run scams or report some of the misinformation that we see from other platforms, those types of things, great. But I think we're moving a little faster than then I think the security and privacy community's comfortable with.</p><h2 id="rory-32">Rory </h2><p>Yeah, I mean, you know, you're a cybersecurity expert yourself. I think there are a lot of cybersecurity experts right now who are shaking their heads going. No, we've, you know, we want to move away from the whole password headache and towards something more more secure something, you know, this is a software error. This is a technology in its infancy, maybe we can design something from the ground up, you know, is properly secured by design. On that note, there's been talk I know around continuous digital authentication, and the role that that can play in the metaverse or in metaverse tech, I should say. So, could you talk a bit about that? For those who don't know, could you lay out what it is in brief and how it could help in this role?</p><h2 id="rick-4">Rick </h2><p>Yeah, absolutely. The idea of a continual, you know, authentication strategy. Most people are familiar with a one time authentication, I go to a website, I need a service, it has a login, I use a username and password, good to go, right? Continual auth moves towards using factors to continually authenticate the device, the identity of the human that's on the device. And then of course, other factors, one of which will probably be biometrics as we start to look towards that future with Meta. But I think the intrinsic risk is really, you know, this idea of to actually get to a place where you can use continual auth on an identification, it butts up against privacy. Right, so for nations that are concerning, and certainly citizens that are concerned about privacy, as we start to gather this data, it clearly butts up against the line of privacy. And I think for some of the organisations that are involved in the build out of the metaverse, or whatever we wind up adopting as that nomenclature in the future, hey've shown that they haven't been good shepherds of privacy today. And so I think them having some transparency and addressing their current issues would help alleviate some of the concerns in the future.</p><h2 id="rory-33">Rory </h2><p>That's interesting. And on that point of the nomenclature, I think, certainly right now there is a tendency to talk about the metaverse, which is often I guess, just by name association, and by the amount of money that they've poured into it already associated with Reality Labs, other researchers at Meta, and with Meta itself. Do you think that we need to be having conversations right now around maybe broadening the term out and not letting it fall into the hands of a very choice few players and maybe broadening the technology out in its infancy?</p><h2 id="rick-5">Rick </h2><p>Well, I mean, I certainly think it's brilliant. I will credit that. I mean, it's pretty brilliant, what they did. Um, that being said look Apple is, you know, currently developing their technology and platforms. So I have a feeling their ecosystem is going to do what Apple's ecosystem does right. And so I do see them as a major player in this market moving forward, but that's all going to look different. Look, I think Apple has taken a different stand on privacy and security than some of the other vendors, I appreciate what they've done. They've certainly helped to secure these devices, I think they've enabled a world, or are starting to enable the world where we're not just ad tracks, and all of this private data is floating around for those purposes. And so I think, having a vision towards that, as we start to deliver that it's going to benefit all of the consumers of that technology, right? And so I do think we have to broaden this out, because they think if we continually say "one organisation is going to own the future of a virtual reality world," that's probably going to be incorrect. There'll be a number of technology players, Nvidia is doing some really cool things with this digital clone of Earth and being able to, you know, look at storm patterns, and all of this really cool stuff. We know, the military is embracing AR and VR for training purposes, to drive down the cost of, you know, sending munitions down range, and again, being able to do that stuff. And so I do, but I think fundamentally, we have to ask ourselves the question, what do we want in this future? And I think everybody needs a voice at that table. Certainly security should be at the table, but there needs to be other consumer voices there as well, to advocate for things like what happens when we have cyber stalking and bullying, how are we going to do this? What are we going to do when you have completely made up personas in a in a virtualized reality? That look like me that talk like me, how am I as a consumer going to be able to vet Rory on the other end of this call in a virtualized world, to know that that's actually who it is that I'm talking to, and then take action based on that. And you can imagine, in a corporation where a CEO can tell a CFO to wire transfer hundreds of thousands of dollars outside of a company, that's going to become a problem. We were already seeing that in the current version of the digital world that we have. And we will certainly see massive amounts of scam and fraud inside of you know, the metaverse virtual reality, whatever we call that,</p><h2 id="rory-34">Rory </h2><p>Right I mean, I know that there are already, you do see reports around deep fakes being used for job interviews. And some of that might be at the moment, again, still in its early stages. But certainly, I can see the potential for identity fraud and phishing to kind of take on a whole new, a whole new identity in this new realm. I guess on that note, what do you what do you think, like a metaverse threat actor will look like?</p><h2 id="rick-6">Rick </h2><p>It's very interesting. So what I think about is how cybercriminals always look at technology, right? And so again, because I got to wear this adversarial hat for a long time, and still do, and we think about the misuse cases, right? So it's pretty typical developer wants to get the thing working. How do we do this at scale? How do we make sure we're not burning people's eyeballs out or engaging the brain? These are all considerations as we're strapping things to our faces, right? From our perspective, we look at misuse cases. So how can I start to deny service to that thing, so that I can make the consumer or the organisation pay me some sort of extortion? Right? How can I start to — and you've seen some of this in attempts of virtualized worlds. How can I do something like digital mods that fill up a space that's supposed to be a safe space that's created for something right, so I'm interfering, you know, on those fronts, and then, of course, I'm how can I get to the money, right? So if the answer is, well, it's easier for me to go into the metaverse and scam a nother human than it is for me to create a bunch of malware that I then have to test, send out, figure out who QAs it, get somebody to click on a link, like I know we purport that it's fairly easy to trick humans. But that being said, we've got a bunch of technology to do that. That won't exist in the metaverse, right. So you can expect a number of security companies to start to address the risks as well. And then certainly, as companies start to adopt it, I mean, I think back to something simplistic, like when, when Furbies came out, right? And then the DoD banned them from the Pentagon because they recorded conversations, or Google Glass was banned from Google campuses when it came out because it recorded right. And so how does the other person know that the conversations report being recorded? Did they consent? All of those things, those are all considerations from a legal perspective and a risk perspective, we're gonna have to build into this new world. And I think, look, the cool part of all of it is, we actually get to design it. Right? Like, we're humans, we're now working on some in the future. And so we do get to look at the past, have those design considerations? And then really move forward with like, how can we start to fundamentally get rid of some of these things from the beginning, because we know that they're going to happen, right? And so I hope the opportunity is exciting for folks that are working on those projects.</p><h2 id="rory-35">Rory </h2><p>I had never heard about that Furby ban. That's, that's incredible. It does raise kind of an interesting point, though, which is that certain dichotomies that currently exist in the sector are going to, I guess, necessarily have to be carried over into metal as tech, such as public and private sector. If you're talking about educational bodies, but also government entities, perhaps even like you're saying the Department of Defence wanting to use metaverse tech versus versus private companies, are the necessary discussions around that happening right now? Or do you think there's there's too much focus on the maybe the private sector applications, the business applications of this tech right now?</p><h2 id="rick-7">Rick </h2><p>I think governments across the globe are struggling with the tech that they have, and so they're hesitant to start to adopt it. Certainly, you know, folks like DARPA, and some of the research agencies have, that's what they do. But I think more broadly, as you look at governments, they're really struggling with patching. They're, they're struggling with endpoint detection and response and being able to report that they've had a breach. Right? So you see, new executive orders new legislation across the globe, to try to get them to a place where it's reasonable security to build on top of, and so I do expect for the next few years, they have some fundamental projects and some heavy lifts that they're going through. Great, we encourage it, we're helping them as much as possible along with, I think, a lot of other vendors, but then they'll start to build upon that right. And so getting something like continual authentication over the technology they have, they they they're going to have to figure that process out, they're gonna have to figure the tech out, and then they can build on it, right? And so my expectation in the future is the work they're doing now, from a security fundamentals perspective, will benefit them in the future.</p><h2 id="rory-36">Rory </h2><p>That's fantastic. So you mentioned you made a reference there to some of the work that VMware has been doing in this space. And in, in general, across the across the industry. Seeing, or given that this is something that is likely to create massive waves in the tech sector, however, it turns out, what is VMware specifically currently doing in anticipation of this sort of big shift?</p><h2 id="rick-8">Rick </h2><p>Well, look, I mean, I think we have to work on this idea that things are born secure. So so you'll hear us say this a lot. You'll hear us talk about this a lot. What does that mean? It means that the design considerations for security and misused or thought about upfront, and then technology enables developers to be able to deliver that in a way that covers the full lifecycle. Now look, that's a whole mouthful, all of the security professionals that are listening in the IT professionals will understand parts and pieces of that, maybe that is a big piece is your secure software design lifecycle. A big piece is going to be the ability to contextualise all of the data and telemetry to be able to do you know, behavioural analysis to find the bad guys. That being said, what we're really working on, is this idea that applications and infrastructure are born secure, maintained throughout the entire lifecycle of that workload, that application, that server in a secure fashion, and then eventually turned off securely, right? So whether that's an encryption of data and deletion, whether that's ensuring that your data is backed up to an air gapped environment, that then is restored clean, all of those things is really, I think, what VMware is working on, because we understand, we're the fundamental virtualization technology that lives underneath all of this, right? And so, when we look at it, it's a stack, we have to provide, I think, strong prevention and detection controls there that other people can rely on build the top up, and that's what we're focused on.</p><h2 id="rory-37">Rory </h2><p>And in your discussions with customers, is this coming up more and more as a concern, or maybe something that they're excited about that you're having to then discuss with them about the actual reality of it?</p><h2 id="rick-9">Rick </h2><p>I'm very lucky, I live on the West Coast of America, and I work with West Coast companies. So we have a tendency to move a little faster than I think a whole lot of other places. So yes, I would say Northern California is already in some cases adopting, you see a lot of companies that are being built around it right to do those things. That being said, the rest of the globe, intentionally is a little slower, right? I mean, after all, these are the pioneers that are proving the tech and all of that stuff, right. So I get to see a little preview, I get to see some of the folks that are working on it. And then I think I have a pretty strong idea, as I talk to people about it. I can tell you, I've talked to no CISOs over the last 18 months where it's at the top of their project list. Generally speaking, ransomware is still at the top of that list. Again, the security fundamentals of being able to patch as quickly as possible, and then of course, recover from some types of these attacks. And then what they're really concerned about is the fewest number of tools to do the security job. So they're retooling. They're rebuilding their processes in an automated fashion, to again, with this eye towards being able to deliver quickly these other solutions coming down the road. And so fundamentally, we're fixing a bunch of stuff and architectures, to allow for the future and rapid delivery of these solutions.</p><h2 id="rory-38">Rory </h2><p>That raises an interesting question about kind of, fixing the environment we have now before moving into this new space. Do you think that, whereas people are currently kind of talking around the metaverse technology as this, this whole new realm to exist in but in its current form, it's going to have to be entrenched in a lot of the systems that we already have. Do you think that there's a potential for some of the worst problems that we're currently experiencing to currently be carried over into into Metaverse technology?</p><h2 id="rick-10">Rick </h2><p>Yes. And I'll give you one brief example. We're not writing a new internet protocol for the metaverse, it's going to be IPv6 and IPv4. Generally speaking, it'll be IPv6, because it's a lot of new companies that are adopting it. Manipulation of that TCP/IP stack is still real, those threats exist all the time, adversaries take advantage. And so again, we're using insecure protocols today that a bunch of technology had to be built on top of, to allow for things like transport layer security, session layer security, cryptography, the data at rest, all of those things, right. And so here's the good news. The good news is, we've proven a bunch of this technology over the last 25 years. I would certainly hope that again, as organisations are implementing this technology and organisations are building this technology, that we take those lessons and build them in. And crypto, in my humble opinion, it's a must like, like the fact that we are even telling consumers to consider using a VPN, like, no, your application should have good strong encryption built into it. And the consumer should not have to be concerned about the transport layer security. Now it's great that they are, I encourage everybody today to be, but that's just one small example of how the underlying, you know, internet protocols if at all are, you know, easily subverted and built on top of. And then of course, you know, Linux operating systems are still going to be in play, right? You know, things like software defined radio attacks for the chips in the motherboards, the firmware that sits underneath of all of that those are all part of the supply chain of the metaverse, and will need good security controls.</p><h2 id="rory-39">Rory </h2><p>Is there a risk that we're moving too quick with Metaverse tech right now, and we risk sort of building it on top of all of these systems and reaching a point maybe in five to ten years where it's too late, we can't pull those systems out from underneath metaverse tech?</p><h2 id="rick-11">Rick </h2><p>It's a good question. I think I have a futurist hat that I wear, and a technology hat. And I do love the future of technology. But then I have a very realist, a little bit pessimistic brain as well, which keeps me in security. So I think the pure security professionals, and if you asked any hacker, we would say yes, we're entirely moving too fast. But I think we would have said that of almost any technology. So that being said, I think there is a speed market and a balance here. Look, you've got to create a market, you got to sell into a market so that you can prove a market, go secure the market, right? And so those pieces don't exist in vacuums. And so I do think we have to move fast in certain areas. Certainly, I think I have some caution about just moving super fast when it comes to like, video game markets and stuff. Which is, fine and probably going to be where we see the largest spread of the technology first. So no, look, security is never going to get our way because if we did, it would take another 10-15 years of development. So we have to be realistic as well and say, look, I think there are amazing use cases in the future, you know, this idea that I can perform surgeries or consult for, you know, in a third world country where maybe they don't have access to surgeons. This is amazing, you know that what we're talking about here, I think, being able to bring humans together in a way, that's not a zoom box. I know the last two and a half years zoom boxes have been killing me, right? So at some point, I do think like it's going to be fun, it'll be really cool,some of the stuff we see from an AR perspective or, you know, walking into office buildings, those types. But yes, the the adversaries are going to take advantage. And they're going to look for us to make some mistakes along this development path. And they'll take advantage of it.</p><h2 id="rory-40">Rory </h2><p>So with that in mind, is this something that security teams and individual companies, on a customer by customer basis, should be worrying about yet, in anticipation of implementing this? Or is this more of a, like you were saying, a kind of secure by design concern for those architects that are leading the way in the sector.</p><h2 id="rick-12">Rick </h2><p>I think if you're bleeding edge companies, certainly you're going to look to move as fast as possible, especially if you're diversifying your business portfolio as well, where you have an existing, you know, social or web company that I think could benefit from that adoption, you're gonna move a little faster. So it is probably a design consideration over the next three years for those types of organisations. Generally speaking, again, the design consideration the architecture, discussions that we're having, fundamentally revolve around things like continual authentication, zero trust, enabling, you know, again, born secure applications, where we understand vulnerabilities that exist, and then we're able to rapidly do those. Because we ran really fast to get to this point. And so there's a little bit of reworking we have to do in architectures, and most of it has to do with cloud, right? So if you think about how we used to do security versus how we're doing it now a lot of people are reworking it. Metaverse will be a consideration as part of this strategy, only because we know the metaverse will be powered by the cloud. And generally speaking, if you're accounting for some of the cloud security components, you'll be accounting for things that you need in the metaverse as well.</p><h2 id="rory-41">Rory </h2><p>So with those security concerns to one side for a second. On a regulatory basis, how is the metaverse — this is a very broad question — but how is the metaverse going to be regulated?</p><h2 id="rick-13">Rick </h2><p>This is a great question. I generally think regulation will follow all other regulations for tech, which means it'll be late to the table. Now, I don't say that to knock legislators or regulators. Generally, it's just the way that it goes, they have to figure it out. You know, clear considerations we're going to have to think about upfront: what do we do on education especially for, you know, children? Right? And who, you know, how is that going to work? And I have a whole lot of questions, right, I got a lot of nieces and nephews, that'll probably wind up strapping a headset on at some point. But as you can imagine, if you're a parent, you have major concerns over how that works in a non-physical way today. Now, I would also say, from a safety perspective, at least in America, there's probably some benefit to moving towards these models as well, right. So I think it'll be per-vertical. I think some of the, again, some of the some of the industries will move a little bit faster than the other ones. And then what we'll see is iterations through regulations over time, right. So we know GDPR didn't get it exactly right the first time and there's the you know, we know the California Privacy Act had to change. So we'll put something out there, it'll iterate, but it probably won't be fast enough to satisfy anybody's needs. Because generally speaking again, when it comes to things like cybercrime and theft, we have to observe the behaviour, laws across the globe have to be created, they have to be voted on democracies, take a little take a little while to get that done right. And then we see some benefit from it. So I do think, particular to regulations in the industry that are helpful, something like PCI DSS, I think, is has been more meaningful for credit card encryptions and to disrupt credit card theft. So adoptions of models like that, instead of adopting, you know, models that add a bunch of overhead for no particular reason than to add the overhead right. I think there's an effective way to do that.</p><h2 id="rory-42">Rory </h2><p>It's interesting, you mentioned GDPR. But considering these issues across different continents across different countries, do you think also that this focus currently on the metaverse as if it's going to be one unified entity as opposed to a series of different metaverses used by different organisations, different entities will run into issues like data sovereignty as well, that maybe could stymie this unified vision that people are currently talking about?</p><h2 id="rick-14">Rick </h2><p>I think the metaverse will follow the real world Internet, and we thought that the internet was gonna wind up 'The Internet'. It's not actually true. There's a lot of different internets, and a lot of different rules, especially depending on how you're governed, right? So no, I don't expect that say the CCP's version of the metaverse is going to be the exact same as the UK's, or the exact same as the US's. Certainly I think, the local citizen, and the consumers are going to have a big say, because they're voting with dollars, right? But I think each government has had to, again, based on risk, based on breaches, based on privacy, has had to sort of draw that line. And so what we've ended up with is a lot of different internets, and a lot of different piles of data around. I think the metaverse is is certainly going to find that, and I can't imagine that authoritarian governments across the globe are going to want to facilitate open access to information and not having a big say in how that's developed.</p><h2 id="rory-43">Rory </h2><p>On that point of having a say, do you think that some sort of framework that companies could agree to that that governments could agree to around metaverse tech is necessary? Or or will it just naturally fall into, like you're saying, a geographic perspective?</p><h2 id="rick-15">Rick </h2><p>No, I think generally technology happens to follow that right? So whether it's IEEE standards, ISO standards that you know, NIST standards, will certainly account for it as well. And so I would assume NIST is probably already looking at some guidance around metaverse. I'm probably not in the room for like the draft discussion, but at some point, it'll come out for a draft form. We as security professionals, with the way on it will iterate through the changes make some recommendations. But yeah, I would expect there'll be specific, you know, standards for metaverse for things like communications, interoperability, all of those things. And if, if you're going to win in that space, you're going to have to be open. Like, I think it's gonna be really hard to go down the path of a closed technology unless you're someone like Apple who already has a massive consumer base</p><h2 id="rory-44">Rory </h2><p>To kind of round off the discussion: to turn one of the earliest questions I asked on its head, we've talked about a lot of the security drawbacks of metaverse tech. But given that we have an opportunity to, as you say, kind of author our own future with this technology, what are some of the real benefits or potential benefits that to security specifically, that that could be be achieved through metaverse technology?</p><h2 id="rick-16">Rick </h2><p>Well, I'll tell you one that I think about all the time. And you hear this from security professionals: I have a team of people that help me, that team might be called the manage detection and response team, it could be called managed security provider, you know, we have all kinds of names for our third parties. But one of the hardest things to achieve is the context of what's happening in the environment, right, the familiarity of each one of these humans, or these groups of humans working together to drive a singular outcome. So, when it comes to upfront consulting, when it comes to architecture design, when it comes to incident response, when it comes to facilitating incident response across the globe, being able to do briefings, man, again, I think have disparate teams sit in a room like we're with each other on a virtualized whiteboard. It's one of the hardest things that I have a problem with today, with the technology that we have in place for remote work. And yes, I know there's tonnes of companies. Yes, we've used all the tech, it is not the same as sitting down real time with six people, when someone has their hands on a whiteboard, eraser. And we're just iterating through stuff, it's just not right. So I think I'm hopeful from that perspective. And then I certainly think from, you know, from my own home life, look, again, I have to get on planes all the time, my friends all have to get on planes, we are trading off that work life balance. And I think, for us, and our experience of burnout and fatigue, and the hours, I do think particular to cybersecurity, there will be an impact to that. And then I hope, if we actually do our jobs right, with continual identity authentication, maybe we can get to a place where we start to eliminate some of this fraud, and the scams, that one human purports to another human, because all they're doing is lying and tricking the other human. So maybe we can think about those use cases in the metaverse and drive some of them down, right? And I don't know how we do that yet. Some people would say we're gonna adopt MRI technology, other people you know, it gets a little dystopian, too, right. That being said, we do have a chance to design it, we do have a chance to consider it. And so what I'm looking for, for these organisations that are building this technology, and the developers, and the architects is like proof, prove that is trustworthy. Give me the transparency that we need to adopt it. Because I think we want to, we love the future, we love it. But it's just a little risky, and so you got to give us what we need to lead the organisations to this change.</p><h2 id="rory-45">Rory </h2><p>Well it certainly sounds like if we play our cards, right, there's, there's lots to look forward to.</p><h2 id="rick-17">Rick </h2><p>Absolutely, I think it's, it's just, it's really cool, right? I mean, we're at a point where we can, we can play with our own reality in a way that's safe, we can move significant chunks of pieces, like, you know, this idea that Nvidia did with this digital Earth. And being able to use actual weather models, and what happens if we, you know, move that, like putting all those pieces together that has a huge value to humanity. And that's the exciting future that I want to make sure, you know, we safeguard and shepherd this technology through.</p><h2 id="rory-46">Rory </h2><p>Fantastic. Well, Rick, thank you so much for being on the show. </p><h2 id="rick-18">Rick </h2><p>Thanks for having me.</p><h2 id="rory-47">Rory </h2><p>As always, You can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk. You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro Podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review. We'll be back next week with more insight from the world of IT but until then, goodbye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Revealed: The top 200 most common passwords of 2022 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022</link>
                                                                            <description>
                            <![CDATA[ While the most common passwords worldwide are largely the same, gender and region did have an effect on frequency ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dLk6ZWjqWnfuPacRknr8AW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Nov 2022 10:58:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:description>                                                            <media:text><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Sequential strings of numbers and ‘password’ remain the most popular password choices for users around the world despite their insecurity.</p><p>Annual research into the top 200 most popular passwords has been published by NordPass also revealed that in the UK, names of football teams also ranked highly among the most-used passwords of the year.</p><p>For example, ‘liverpool’ was the fourth most popular password of the year, while ‘arsenal’, ‘chelsea’, and ‘liverpool1’ were all in the top 15.</p><p>Regional results from the likes of France revealed similarly insecure password practices, but the actual passwords themselves differed. For example, 'azerty' was the third most popular password in the country - the equivalent of 'qwert' on a French keyboard layout.</p><p>NordPass also included datasets sorted by user gender, revealing some notable differences in password frequency. In the US, the most used password by users identifying as women was ‘guest’ versus the old favourite of ‘12345’ among users identifying as men.</p><p>Both genders in the UK used ‘password’ and ‘123456’ as their top choices, but stark differences were visible in the remainder of the top five results: ‘charlie’, ‘tigger’, and ‘sunshine’ versus ‘mosh2021’, ‘12345’, and ‘liverpool’ were the results for women and men respectively.</p><p>Data from all 30 countries, however, revealed general uniformity in passwords, with only the inclusion of ‘bigbasket’ as the seventh most-used password by women worldwide standing out as an anomaly.</p><p>The most secure password to make <a href="https://nordpass.com/most-common-passwords-list">the top 200 list</a> was ‘9136668099’, which NordPass estimates would take hackers around four days to crack. However, beyond this figure, it is still far from a secure password, as it contains no letters or special characters whatsoever.</p><p>Regularly updating one’s password is good security practice, and experts recommend straying away from using easy-to-guess words or phrases, or anything that a threat actor could link to you with no trouble.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/368049/best-password-managers-for-business" data-original-url="/software/368049/best-password-managers-for-business">Best password managers for business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369442/cisco-announces-duo-passwordless-authentication-for-single-sign-on-sso-apps" data-original-url="/security/369442/cisco-announces-duo-passwordless-authentication-for-single-sign-on-sso-apps">Cisco announces Duo Passwordless Authentication for Single Sign On (SSO) apps</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password" data-original-url="/security/cyber-security/357510/the-it-pro-podcast-how-hackers-steal-your-password">The IT Pro Podcast: How hackers steal your password</a></p></div></div><p>There are a range of <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password-cracking techniques used by hackers</a> but brute force attacks, in which hackers guess a victim’s password using various forms of trial and error, are common. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sr7PL6RyX4xfWCPshjfCie" name="sr7PL6RyX4xfWCPshjfCie.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" mos="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a better password strategy for your business</strong></p><p class="fancy-box__body-text">Exploring the strategies and exploits that hackers are using to circumvent password security measures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business" data-original-url="/security/369393/building-a-better-password-strategy-for-your-business">FREE DOWNLOAD</a></p></div></div><p>Hackers can use powerful hardware such as <a href="https://www.itpro.com/hardware/components/369322/nvidias-rtx-4090-is-a-powerful-password-cracking-tool" data-original-url="https://www.itpro.com/hardware/components/369322/nvidias-rtx-4090-is-a-powerful-password-cracking-tool">GPUs for password-cracking</a>, which can cut down the time required to unearth credentials, but the simplest brute force attacks simply involve trying common passwords until access is granted - reason enough for users to stray away from using anything that resembles a password in the top 200.</p><p>Employees should not be using shared passwords across multiple logins, particularly for accounts pertaining to sensitive business data, to prevent data breaches. Businesses are often urged to use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication</a> in addition to a strong password policy, to ensure that unwanted individuals have overcome that extra hurdle in order to access sensitive accounts.</p><p>It can be difficult to remember a series of strong, unique passwords - some businesses have said <a href="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember" data-original-url="https://www.itpro.com/security/32680/the-best-passwords-are-the-ones-you-cant-remember">forgettable passwords are the best</a> - and for this reason many businesses opt to use <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">password managers</a>.</p><p>These can be used to create distinct passwords for all of a user’s accounts, and store them all behind a master password (used to access the password manager itself).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US federal agency breached by Iranian state-backed hackers via Log4Shell exploit ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369531/us-federal-agency-breached-by-iranian-state-backed-hackers-via-log4shell-exploit</link>
                                                                            <description>
                            <![CDATA[ The initial intrusion was discovered in February but a full incident response wasn't launched until June ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8ZEH3kPKQ9yV47EYnBnBjA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N4xvDLYtVcnfGxpNwvhoNB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Nov 2022 10:33:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N4xvDLYtVcnfGxpNwvhoNB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The White House is the daytime]]></media:description>                                                            <media:text><![CDATA[The White House is the daytime]]></media:text>
                                <media:title type="plain"><![CDATA[The White House is the daytime]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N4xvDLYtVcnfGxpNwvhoNB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US government has revealed Iranian state-sponsored cyber attackers successfully breached a federal agency by exploiting Log4Shell.</p><p>The Iranian-backed hackers have not been attributed to any known threat actor at this time, but the hackers used their access to deploy the XMRig crypto miner and the Mimikatz credential harvester.</p><p>According to a joint advisory published by CISA and the FBI, the attack took place in February 2022 but a full incident response engagement wasn’t carried out until June.</p><p>The resulting investigation revealed the threat actor had gained initial access to the federal agency’s VMware Horizon server by exploiting the Log4Shell vulnerability, which was discovered in late 2021.</p><p>After gaining initial access, the Iran-backed hackers ran commands to disable Windows Defender from running <a href="https://www.itpro.com/security/malware/357313/how-do-computer-viruses-spread" data-original-url="https://www.itpro.com/security/malware/357313/how-do-computer-viruses-spread">virus</a> scans on downloaded tools before deploying the XMRig <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining" data-original-url="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency mining</a> tool on the VMware Horizon server.</p><p>The attackers then moved laterally across the network and used Mimikatz to harvest credentials and create a domain administrator account.</p><p>This was then used to implant the Ngrok reverse proxy tool - often associated with malicious activity - on multiple hosts to establish persistence and proxy the attackers remote desktop protocol (RDP) connections.</p><p>“From mid-June through mid-July 2022, CISA conducted an on-site incident response engagement and determined that the organisation was compromised as early as February 2022, by likely <a href="https://www.itpro.com/security/cyber-warfare/369033/microsoft-iranian-hackers-breached-albanian-government-more-than-a-year-before-main-hack" data-original-url="https://www.itpro.com/security/cyber-warfare/369033/microsoft-iranian-hackers-breached-albanian-government-more-than-a-year-before-main-hack">Iranian government-sponsored APT actors</a> who installed XMRig crypto mining software,” the advisory read. </p><p>“The threat actors also moved laterally to the domain controller, compromised credentials, and implanted Ngrok reverse proxies.”</p><h2 id="failure-to-patch">Failure to patch?</h2><p>The discovery of the <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability" data-original-url="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell vulnerability</a> in December 2021 caused major unrest in the cyber security community.</p><p>The degree to which enterprise software was vulnerable to the security flaw - the highest estimates were in the region of 90% of all applications - was a particular concern. </p><p>Log4Shell’s discovery came just weeks after CISA introduced its ‘madatory patch programme’ - a list of the most commonly exploited vulnerabilities that all federal agencies had to patch by a specific deadline. </p><p>CISA issued an emergency directive adding Log4Shell to the list of vulnerabilities that had to <a href="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management" data-original-url="https://www.itpro.com/security/27713/the-importance-and-benefits-of-effective-patch-management">patched</a> across all federal agencies on 10 December, and set a deadline for patching the flaw by 24 December.</p><p><em>IT Pro</em> asked CISA in November 2021, after the first deadline to patch the initial list of known vulnerabilities had passed, whether all federal agencies had successfully patched all flaws by the set deadline. The US’ cyber security agency declined to confirm that all agencies had met that deadline.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability" data-original-url="/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">What is the Log4Shell vulnerability?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/361907/ftc-threatens-legal-action-companies-failing-to-patch-log4shell" data-original-url="/security/cyber-security/361907/ftc-threatens-legal-action-companies-failing-to-patch-log4shell">FTC threatens legal action against companies failing to patch Log4Shell</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/botnets/367007/linux-botnet-spreads-using-log4shell-flaw" data-original-url="/security/botnets/367007/linux-botnet-spreads-using-log4shell-flaw">Linux botnet spreads using Log4Shell flaw</a></p></div></div><p>"The breach of a US government agency is realistically one of the many breaches that will come to light where threat actors successfully exploit Log4Shell,” said Bob Huber, CSO at Tenable. </p><p>“In the coming days, Tenable will release an alert examining the impact of Log4Shell, in which we found that nearly three out of four organisations are still vulnerable to the flaw.</p><p>"The reality is that full remediation of Log4Shell is difficult to achieve given its prevalence and the fact that whenever an organisation adds new assets, it could be reintroducing the vulnerability. The best way to thwart attackers is to remain diligent and consistent in remediation efforts."</p><p>One of the initial concerns with Log4Shell was organisaitons’ ability to detect whether the vulnerable log4j component was present in any of their software products. </p><p>Paul Baird, UK chief technical security officer at Qualys, told <em>IT Pro</em> that detection was a challenge for all organisations and that others may not be able to change the version of the log4j component as it may break their application.</p><p>“Patching issues like log4j is necessary – all the security experts in the world will tell you to patch immediately or as soon as you can,” said Baird. </p><p>“But you can only patch what you know about, and it is not as easy as just apply a patch - you have to know your infrastructure and have good rollback plans in the event that something goes wrong. A lot of organisations don't have good <a href="https://www.itpro.com/strategy/29648/how-to-create-a-business-continuity-plan" data-original-url="https://www.itpro.com/strategy/29648/how-to-create-a-business-continuity-plan">business continuity plans</a> including <a href="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy" data-original-url="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy">backups</a>, so they tend to just add the system to a risk register and accept the risk.</p><p>“This is a problem for <a href="https://www.itpro.com/business-strategy/public-sector/367242/uk-government-public-sector-it-playbook" data-original-url="https://www.itpro.com/business-strategy/public-sector/367242/uk-government-public-sector-it-playbook">security teams in the public sector</a> because they are very stretched and there are so many priorities fighting for their attention. However, fixing known problems is the best defence.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Australia considers ransomware payment ban, additional Medibank files leaked ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/369511/australia-considers-ransomware-payment-ban-further-medibank-leaks</link>
                                                                            <description>
                            <![CDATA[ REvil has claimed responsibility for the attack amidst continued refusal by Medibank to pay the ransom ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6TkM9rqGRw7BQZeSTkn3uv</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zva3WuJMgvYyqzCj8CdfZg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Nov 2022 13:21:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zva3WuJMgvYyqzCj8CdfZg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Australian coast, showing a beach and a city]]></media:description>                                                            <media:text><![CDATA[The Australian coast, showing a beach and a city]]></media:text>
                                <media:title type="plain"><![CDATA[The Australian coast, showing a beach and a city]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zva3WuJMgvYyqzCj8CdfZg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Australian government has said it is considering the introduction of legislation that would ban companies from paying ransom demands set by hackers in ransomware attacks.</p><p>In an interview on Australia’s <em>ABC</em>, home affairs minister Clare O’Neil said that there are “some really big policy questions that we’re going to need to think about and consult on, and we’re going to do that in the context of the cybersecurity strategy”.</p><p>When directly asked if the government could seek to bar companies from providing threat actors with ransom payments, O’Neil responded “that’s correct”.</p><p>O'Neil's comments come in the wake of a series of high-profile cyber attacks on Australian private sector businesses that left millions of its citizens' records exposed.</p><p>Medibank is the latest of eight high-profile Australian firms to be hit by <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> attacks, having disclosed on 19 October that it had been hit by a <a href="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks" data-original-url="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks">cyber attack</a> now believed to have <a href="https://www.itpro.com/security/cyber-attacks/369463/medibank-hack-affects-millions-refuses-to-pay-ransom" data-original-url="https://www.itpro.com/security/cyber-attacks/369463/medibank-hack-affects-millions-refuses-to-pay-ransom">affected 9.7 million past and present customers</a>.</p><p>Other attacks include one against <a href="https://www.itpro.com/security/cyber-attacks/369216/systemic-id-problems-for-10-million-warns-minister" data-original-url="https://www.itpro.com/security/cyber-attacks/369216/systemic-id-problems-for-10-million-warns-minister">telco giant Optus, affecting 10 million Australians</a>, and a service <a href="https://www.itpro.com/security/cyber-attacks/369428/ransomware-attack-australian-defence-comms-platform" data-original-url="https://www.itpro.com/security/cyber-attacks/369428/ransomware-attack-australian-defence-comms-platform">used by the Australian Department of Defence</a>. </p><p>The REvil ransomware group has claimed responsibility for the Medibank attack, posting stolen data on its leak blog in numerous stages. Records belonging to an additional 500 Medibank customers were posted on 13 November, including their names, addresses, email addresses, and unique customer numbers.</p><p>In a post on the REvil blog, the group taunted Medibank, stating “we warned you, we always keep our word, if we wouldn't receive a ransom - we should post this data, because nobody will believe us in the future.” In the same post, it was announced that the next batch of data will be posted on Friday.</p><p>When it first reported the attack, Medibank indicated that it was <a href="https://www.itpro.com/security/ransomware/369342/medibank-negotiates-with-hackers-who-stole-data-in-cyber-attack" data-original-url="https://www.itpro.com/security/ransomware/369342/medibank-negotiates-with-hackers-who-stole-data-in-cyber-attack">negotiating with the hackers</a> behind the attack, while trying to ascertain if data had been stolen.</p><p>However, since establishing the scale of the breach, the firm has refused to make a <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">ransom payment</a> to the group behind the attack, stating that cyber security experts have said it is unlikely that the threat actor would remain true to their word in returning unpublished data.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zxgJhZ9MYsxYh8heefErtH" name="zxgJhZ9MYsxYh8heefErtH.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/zxgJhZ9MYsxYh8heefErtH.png" mos="https://cdn.mos.cms.futurecdn.net/zxgJhZ9MYsxYh8heefErtH.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The long road ahead to ransomware preparedness</strong></p><p class="fancy-box__body-text">Getting to the bigger truth</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369492/the-long-road-ahead-to-ransomware-preparedness" data-original-url="/security/ransomware/369492/the-long-road-ahead-to-ransomware-preparedness">FREE DOWNLOAD</a></p></div></div><p>The REvil group has long been a threat to businesses, and has claimed <a href="https://www.itpro.com/security/ransomware/360122/up-to-1500-organizations-compromised-in-kaseya-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/360122/up-to-1500-organizations-compromised-in-kaseya-ransomware-attack">attacks against Kaseya</a>, and <a href="https://www.itpro.com/security/ransomware/368955/revil-claims-ransomware-attack-on-multi-billion-dollar-manufacturing-giant-midea-group" data-original-url="https://www.itpro.com/security/ransomware/368955/revil-claims-ransomware-attack-on-multi-billion-dollar-manufacturing-giant-midea-group">August's attack on the Midea Group</a>. It was the subject of a series of mass arrests in November 2021 carried out by the US Department of Justice, Interpol, Europol, and authorities from Romania alongside 17 other countries, after which its activity seemingly shut down before <a href="https://www.itpro.com/security/ransomware/367455/revil-ransomware-groups-infrastructure-comes-back-online-hinting-at" data-original-url="https://www.itpro.com/security/ransomware/367455/revil-ransomware-groups-infrastructure-comes-back-online-hinting-at">resuming activity in mid 2022</a>. </p><p>Along with the medical data that it is threatening to continue posting, REvil claimed to have access to “source codes, list of stuff, and some files obtained from medi filesystem from different hosts”. Along with Medibank customers, the attack is believed to have affected customers of Medibank’s subsidiary Ahm, as well as a number of international customers.</p><h2 id="what-action-can-the-australian-government-take">What action can the Australian government take?</h2><p>“The Medibank breach has taken Australia by storm, so it is not surprising the government is analysing how to handle cyber incidents moving forward, but isolated knee-jerk responses will only make the problem worse,” said Jordan Schroeder, managing CISO at security service Barrier Networks.</p><p>“Banning ransomware payments would be a move to make attacks on Australian organisations less attractive to cyber criminals, but it won’t stop them entirely. Attacks will still occur and in these situations, companies would have absolutely no chance of recovery, which will potentially cost more than a ransom demand.</p><p>“Furthermore, making ransomware payments illegal in one jurisdiction could push the payment of ransomware underground, which will hide these crimes and make coordinated responses with law enforcement difficult, or it could even force companies to use third parties in other jurisdictions to make payments on their behalf, which will not solve the problem.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/369463/medibank-hack-affects-millions-refuses-to-pay-ransom" data-original-url="/security/cyber-attacks/369463/medibank-hack-affects-millions-refuses-to-pay-ransom">Medibank admits ransomware attack is far worse than previously thought</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" data-original-url="/security/ransomware/367624/the-rise-of-double-extortion-ransomware">The rise of double extortion ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369352/ransomware-activity-down-11-worldwide-in-q3-but-rise-expected" data-original-url="/security/ransomware/369352/ransomware-activity-down-11-worldwide-in-q3-but-rise-expected">Ransomware activity down 11% worldwide in Q3, but rise expected</a></p></div></div><p>“A better focus for the Australian government just now could be on equipping organisations with better defences against ransomware. This would include raising awareness around cybercrime techniques and introducing legislation on minimum cybersecurity requirements for businesses.”</p><p>Following the attacks, the Australian government has also formed a task force, composed of officers from both the AFP and the Australian Signals Directorate (ASD), the federal agency responsible for intercepting and extracting information from foreign electronic communications. This will hunt cyber criminals on a permanent basis.</p><p>Additionally, the <a href="https://www.itpro.com/business/policy-legislation/369370/australian-government-to-increase-maximum-data-breach-penalty" data-original-url="https://www.itpro.com/business/policy-legislation/369370/australian-government-to-increase-maximum-data-breach-penalty">maximum data breach penalty will be increased</a> for repeated or serious privacy breaches in Australia. The former ceiling of AU$2.2 million will rise to the greatest of $50 million (AUD), three times the value of benefits obtained through the improper use of data, or 30% of an accused company’s adjusted turnover across a defined period. </p><p>Data breaches should be prevented as a matter of course within companies as a result of proper <a href="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures" data-original-url="https://www.itpro.com/data-protection/28177/data-protection-policies-and-procedures">data protection policies and procedures</a>, rather than simply to avoid fines. In addition to the legal and ethical ramifications of improper data handling, processing, or disposal, companies that engage in bad practice will incur a great deal of <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">reputational damage</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lenovo patches ThinkPad, Yoga, IdeaPad UEFI secure boot vulnerability ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/369491/lenovo-patches-thinkpad-yoga-ideapad-uefi-secure-boot-vulnerability</link>
                                                                            <description>
                            <![CDATA[ Mistakenly used drivers could allow hackers to modify the secure boot process ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jy2SdXBjQEfyrP5jq8Cd2y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LzEuB4gZzVBMq7M2Q9iePE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Nov 2022 17:05:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LzEuB4gZzVBMq7M2Q9iePE-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Lenovo logo on a laptop, against a black background]]></media:description>                                                            <media:text><![CDATA[The Lenovo logo on a laptop, against a black background]]></media:text>
                                <media:title type="plain"><![CDATA[The Lenovo logo on a laptop, against a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LzEuB4gZzVBMq7M2Q9iePE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lenovo has released patches to address two vulnerabilities that could have allowed cyber criminals to run malicious code through the deactivation of UEFI Secure Boot.</p><p>Researchers at ESET first discovered the vulnerabilities, <a href="https://support.lenovo.com/us/en/product_security/LEN-94952">tracked</a> as CVE-2022-3430 and CVE-2022-3431, which, if exploited, could lead to threat actors circumventing the basic security functions of a victim’s <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system" target="_blank" data-original-url="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system">operating system (OS)</a>. These bugs carry a severity rating of ‘high’.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wnmQ9imps85axutghCiKXL" name="wnmQ9imps85axutghCiKXL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wnmQ9imps85axutghCiKXL.png" mos="https://cdn.mos.cms.futurecdn.net/wnmQ9imps85axutghCiKXL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Five common data security pitfalls</strong></p><p class="fancy-box__body-text">Learn how to improve your security posture</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369383/five-common-data-security-pitfalls" data-original-url="/security/369383/five-common-data-security-pitfalls">FREE DOWNLOAD</a></p></div></div><p>The vulnerabilities affect 25 devices across the <a href="https://www.itpro.com/hardware/laptops/356848/lenovo-thinkbook-plus-review-lifting-the-lid-on-productivity" data-original-url="https://www.itpro.com/hardware/laptops/356848/lenovo-thinkbook-plus-review-lifting-the-lid-on-productivity">ThinkBook</a>, <a href="https://www.itpro.com/hardware/laptops/359681/lenovo-yoga-9i-14in-shadow-black-review-betrayed-by-its-own-ambitions" data-original-url="https://www.itpro.com/hardware/laptops/359681/lenovo-yoga-9i-14in-shadow-black-review-betrayed-by-its-own-ambitions?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+ITPro%2FToday+%28IT+PRO+-+Today%29">Yoga</a> and <a href="https://www.itpro.com/hardware/laptops/366969/lenovo-ideapad-duet-5-chromebook-review-a-confident-convertible" data-original-url="https://www.itpro.com/hardware/laptops/366969/lenovo-ideapad-duet-5-chromebook-review-a-confident-convertible">IdeaPad</a> ranges in total, although not all these devices are affected by both vulnerabilities. As these devices are heavily used in business settings, employees could be adversely affected by the flaw and potentially sustain damage to sensitive data.</p><p>The flaw, which sits within a driver in the affected devices, allows for attackers to alter a variable in non-volatile random access memory (NVRAM) to modify the secure boot setting of a device. This was not due to an error in the code of the affected drivers, but rather because the affected devices were mistakenly equipped with drivers intended for use only during manufacturing, with relaxed control over secure boot settings from within the OS.</p><p>UEFI flaws are severe, as they allow for threat actors to alter critical device processes, and potentially install <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> within the victim’s flash memory. For example, threat actors could use such a flaw to install a <a href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit" data-original-url="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit">rootkit</a>, which could carry out malicious activity while remaining very hard to detect, and can even survive OS reinstallation.</p><p>“Secure boot is built on a hierarchy of trust typically rooted in technologies fixed in the hardware of a device,” Professor John Goodacre, director of the UKRI’s Digital Security by Design challenge and professor of computer architectures at the University of Manchester.</p><p>“Such systems are used to ensure that despite any exploitation of a vulnerability during the normal operation of a system it can be recovered through a reboot. It is therefore essential that by design, the secure boot of a system cannot be altered while in normal operation. Unfortunately, all software should be considered to contain vulnerabilities, and therefore it’s essential that during normal operation no mechanisms can circumvent secure boot. </p><p>“Although a move to using digital secure by design execution of software will significantly reduce the opportunity to exploit vulnerabilities, any mechanism in which an exploitation of normal operations can take control of secure boot means they are open to <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> and other denial of service attacks and highlights the need for trust across the various components of secure boot.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/360526/what-is-a-rootkit" data-original-url="/security/cyber-attacks/360526/what-is-a-rootkit">What is a rootkit?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/368655/researchers-uncover-mysterious-windows-rootkit-actively-exploited-2016" data-original-url="/security/malware/368655/researchers-uncover-mysterious-windows-rootkit-actively-exploited-2016">Researchers uncover 'mysterious' Windows rootkit being actively exploited since 2016</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/vulnerability/369439/openssl-3-vulnerability-patch-for-security-scare" data-original-url="/security/vulnerability/369439/openssl-3-vulnerability-patch-for-security-scare">OpenSSL 3.0 vulnerability: Patch released for security scare</a></p></div></div><p>The Ideapad Y700-14ISK is affected by a third vulnerability, tracked as CVE-2022-3432, which comprises another driver flaw that results in a similar modification of the secure boot sweating. However, Lenovo will not release a fix for this as the device has exceeded its developer support lifecycle.</p><p>This is not the first time that Lenovo has had to release such a patch. In April, ESET researchers discovered more than <a href="https://www.itpro.com/security/367449/millions-of-lenovo-laptops-thought-to-be-vulnerable-to-newly-discovered-uefi" data-original-url="https://www.itpro.com/security/367449/millions-of-lenovo-laptops-thought-to-be-vulnerable-to-newly-discovered-uefi">100 Lenovo models vulnerable to UEFI malware attacks</a>, also as a result of manufacturing drivers mistakenly left on the devices.</p><p>Similar concerns have been raised in the past, with <a href="https://www.itpro.com/security/vulnerability/359988/secure-boot-flaws-could-enable-hackers-to-take-control-of-dell" data-original-url="https://www.itpro.com/security/vulnerability/359988/secure-boot-flaws-could-enable-hackers-to-take-control-of-dell">Dell BIOS vulnerabilities</a> found in 2021 enabling threat actors to execute malicious code at UEFI level on an estimated 30 million devices, and researchers from Advanced Intelligence and Eclypsium having found a <a href="https://www.itpro.com/security/malware/357994/new-trickbot-variant-can-interfere-with-uefi-and-bios" data-original-url="https://www.itpro.com/security/malware/357994/new-trickbot-variant-can-interfere-with-uefi-and-bios">variant of the Trickbot malware</a> that can brick devices at UEFI level in 2020. </p><p>ESET recommends that those using the affected devices update their firmware version immediately.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yanluowang ransomware leaks suggest pseudo Chinese persona, REvil links ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/369435/yanluowang-ransomware-leaks-suggest-pseudo-chinese-persona-revil-links</link>
                                                                            <description>
                            <![CDATA[ It's the second major ransomware organisation to have been rocked this year after internal chat logs were leaked by anonymous hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7jdEERgrq9vbKrJJPYbh6m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BRAvsmRa4oYkmULN9aNPQH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Nov 2022 12:02:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BRAvsmRa4oYkmULN9aNPQH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A simple graphic of a white laptop on a red background, with a distorted red padlock showing on the laptop&amp;#039;s otherwise black screen]]></media:description>                                                            <media:text><![CDATA[A simple graphic of a white laptop on a red background, with a distorted red padlock showing on the laptop&amp;#039;s otherwise black screen]]></media:text>
                                <media:title type="plain"><![CDATA[A simple graphic of a white laptop on a red background, with a distorted red padlock showing on the laptop&amp;#039;s otherwise black screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BRAvsmRa4oYkmULN9aNPQH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Chat data from the Yanluowang ransomware organisation has been leaked online revealing a fake Chinese persona and potential links with other ransomware organisations.</p><p>Yanluowang is named after the Chinese and Buddhist mythological figure Yanluo Wang but chat data revealed those involved in the organisation spoke in Russian.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="iZbRits5t8eoFtzAsZbNoV" name="iZbRits5t8eoFtzAsZbNoV.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/iZbRits5t8eoFtzAsZbNoV.jpg" mos="https://cdn.mos.cms.futurecdn.net/iZbRits5t8eoFtzAsZbNoV.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The big book of ZTNA security use cases</strong></p><p class="fancy-box__body-text">Know your ZTNA protection index</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/remote-access/369413/the-big-book-of-ztna-security-use-cases" data-original-url="/mobile/remote-access/369413/the-big-book-of-ztna-security-use-cases">FREE DOWNLOAD</a></p></div></div><p>In February 2022, the most prominent member of the group who operates using the alias ‘Saint’ also responded in a discussion related to arrests of former REvil members saying five of the individuals in a linked news report were “former classmates”.</p><p>REvil is still in operation but its dominance of the ransomware landscape ended in 2021 following a <a href="https://www.itpro.com/security/ransomware/361480/three-revil-ransomware-gang-members-arrested-following-international" data-original-url="https://www.itpro.com/security/ransomware/361480/three-revil-ransomware-gang-members-arrested-following-international">coordinated international law enforcement operation</a> to arrest many of its core members. </p><p>It’s believed the remaining lower-level cyber criminals either stayed with the organisation or moved on to work for more lucrative rivals.</p><p>The leaked messages did not explicitly tie Saint to the REvil gang nor does it reveal any more about the relationship between Saint and the arrested REvil members.</p><p>Many additional messages using the Russian language were leaked and more active aliases were also named, including ‘Killanas’ which was the second most-active user in the organisation behind Saint.</p><p>Killanas is believed to have had a role in handling <a href="https://www.itpro.com/development/34728/learn-to-code-for-free-the-best-uk-coding-and-app-development-courses" data-original-url="https://www.itpro.com/development/34728/learn-to-code-for-free-the-best-uk-coding-and-app-development-courses">code</a> assignments, according to KELA’s <a href="https://twitter.com/Intel_by_KELA/status/1587123877041381376">analysis</a>, which also identified ‘Felix’ as a tester and ‘Stealer’ as another organisation member.</p><p>Chat logs between Felix and Stealer appeared to indicate that an <a href="https://www.itpro.com/security/ransomware/358735/ransomware-operators-exploiting-vmware-esxi-flaws" data-original-url="https://www.itpro.com/security/ransomware/358735/ransomware-operators-exploiting-vmware-esxi-flaws">ESXi version</a> of Yanluowang <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> was under development - an approach VMware recently <a href="https://blogs.vmware.com/security/2022/09/esxi-targeting-ransomware-the-threats-that-are-after-your-virtual-machines-part-1.html">branded</a> “a devastating threat”.</p><p>A conversation between Saint and Killanas also hinted at the group's use of Nyx ransomware, KELA said.</p><p>Also included in the leak were what the leaker claimed to be source code snippets from both the ransomware locker program's builder and decryption process but the authenticity of these has yet to be verified.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1587141260112007171"></a></p></blockquote><div class="see-more__filter"></div></div><p>The security community has never confidently or publicly identified the location of the hackers behind the Yanluowang ransomware operation to be either Russia or China and using a false persona to evade <a href="https://www.itpro.com/security/hacking/368848/the-it-pro-podcast-does-threat-attribution-matter" data-original-url="https://www.itpro.com/security/hacking/368848/the-it-pro-podcast-does-threat-attribution-matter">attribution</a> is an uncommon tactic.</p><p>Publication of the stolen files came as security researchers noticed Yanluowang’s leak blog was defaced on Monday to show the gang itself had been hacked. The hacker left the message “Time’s up!” along with links to download the stolen chat files.</p><p>Yanluowang was previously known for successfully conducting ransomware attacks on high-profile organisations such as Cisco and its security arm <a href="https://www.itpro.com/security/data-breaches/368794/cisco-talos-confirms-data-breach-ransomware-gang" data-original-url="https://www.itpro.com/security/data-breaches/368794/cisco-talos-confirms-data-breach-ransomware-gang">Cisco Talos</a>. The data from the former was made public <a href="https://www.itpro.com/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may" data-original-url="https://www.itpro.com/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may">last month</a>.</p><p>The ransomware group also becomes the second major organisation to have its internal chat data leaked this year.</p><p>Russia-linked Conti dominated the ransomware landscape for much of 2021 and the start of 2022 until a Ukrainian cyber security researcher leaked a trove of chat logs and later its source code that led to the group’s demise.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may" data-original-url="/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may">Cisco confirms data breach following Yanluowang ransomware attack in May</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368794/cisco-talos-confirms-data-breach-ransomware-gang" data-original-url="/security/data-breaches/368794/cisco-talos-confirms-data-breach-ransomware-gang">Cisco Talos confirms data breach after ransomware gang 'forces' incident disclosure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="/security/29241/what-are-the-different-types-of-ransomware">What are the different types of ransomware?</a></p></div></div><p>The incident was <a href="https://www.trellix.com/en-gb/about/newsroom/stories/research/conti-leaks-examining-the-panama-papers-of-ransomware.html">dubbed</a> “the Panama Papers of ransomware” and was thought to have been a politically motivated attack following Conti’s public support of <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">Russia in its invasion of Ukraine</a>.</p><p>Conti and its affiliates were able to conduct a small number of other <a href="https://www.itpro.com/security/ransomware/367704/ransomware-group-conti-threatens-to-overthrow-costa-rican-government" data-original-url="https://www.itpro.com/security/ransomware/367704/ransomware-group-conti-threatens-to-overthrow-costa-rican-government">high-profile attacks</a> before it shut down for good in June 2022.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Second-ever OpenSSL critical vulnerability teased, 10 years after Heartbleed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369419/second-ever-openssl-critical-vulnerability-teased-10-years-after-heartbleed</link>
                                                                            <description>
                            <![CDATA[ All OpenSSL versions beyond 3.0 are at risk, with more details due to be released alongside a patch on 1 November ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bm3pTLhyk4xUKjam8sSRc1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Oct 2022 10:39:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg">
                                                            <media:credit><![CDATA[Bigstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:description>                                                            <media:text><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:text>
                                <media:title type="plain"><![CDATA[Bright blue code appearing on screen to denote hacking]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KAE3tGXMEcRfgDxLP9qFH4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The OpenSSL Project, which runs the widely-used OpenSSL library, has announced it will issue a critical vulnerability patch on 1 November. </p><p>The announcement marks the first OpenSSL critical vulnerability patch since 2016, and only the second in the project’s history. Full details of the flaw will be revealed at the time of the patch to reduce the possibility of attackers reverse engineering to develop an exploit.</p><p>However, it has already been stated that the vulnerability does not affect versions earlier than OpenSSL 3.0, with the patch forming part of the 3.07 release. This appears to mean that devices which run versions before 3.0, which was released in 2021, should remain unaffected by the vulnerability.</p><p>“Given the number of changes in 3.0 and the lack of any other context information, such scouring is very highly unlikely,” said Mark J Cox, former head of product security at Red Hat and one of the co-founders of OpenSSL, responding to a question in his original announcement <a href="http://twitter.com/iamamoose/status/1584908434855628800?t=phPCO2jxhUSsr_x334xuVA&s=19">tweet</a>.</p><p>While the 2016 flaw allowed for remote execution of code, it was only active for four days before being caught and patched. In contrast, the newly-announced vulnerability affects all versions after 3.0 which was released in September 2021.</p><p>OpenSSL is the most popular open source <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption" data-original-url="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">cryptography</a> library in the world and is used by the majority of <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTPS</a> websites as well as on a range of web servers. As such, a critical vulnerability within its code could represent a serious threat to a wide range of businesses, as well as to individual privacy online.</p><p>The OpenSSL Project <a href="https://www.openssl.org/policies/general/security-policy.html">policy</a> states that in the event of an upcoming patch to a flaw rated ‘critical’ in severity, a warning will be made publicly available to notify users of the exact date and rough time at which the patch will be made available.</p><p>Alongside this, select organisations will be given patches early, as well as briefings on the exact nature and seriousness of the flaw.</p><p>Some are already drawing comparisons between the upcoming announcement and 2014’s Heartbleed vulnerability, tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2014-0160">CVE-2014-0160</a>, which garnered widespread media attention and concern in 2014 as it allowed threat actors to view data on any website utilising OpenSSL.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7482i6KDvixdNzMG9kSCyL" name="7482i6KDvixdNzMG9kSCyL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/7482i6KDvixdNzMG9kSCyL.png" mos="https://cdn.mos.cms.futurecdn.net/7482i6KDvixdNzMG9kSCyL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The financial services survival guide</strong></p><p class="fancy-box__body-text">How uncertainty and disruption is forcing financial services to innovate</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/finance/369314/the-financial-services-survival-guide" data-original-url="/business-operations/finance/369314/the-financial-services-survival-guide">FREE DOWNLOAD</a></p></div></div><p>It is also likely to add to <a href="https://www.itpro.com/development/open-source/369079/organisations-are-scaling-back-their-open-source-software-due-to" data-original-url="https://www.itpro.com/development/open-source/369079/organisations-are-scaling-back-their-open-source-software-due-to">growing fear of using open source</a> solutions amongst companies, especially in the wake of the damaging <a href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability" data-original-url="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">Log4Shell vulnerability</a>.</p><p>“The announcement of the new OpenSSL critical vulnerability immediately brought back not-so-fond memories of Heartbleed or - more recently - the Log4J vulnerability,” said Mattias Gees, container product lead at Venafi.</p><p>“Heartbleed had a significant impact on all operations teams worldwide, and since then IT infrastructure has become ten times more complicated. The attack vector has become a lot larger, and rather than just having to examine their <a href="https://www.itpro.com/612016/what-is-virtualisation" data-original-url="https://www.itpro.com/612016/what-is-virtualisation">VMs</a>, organisations need to start preparing to patch all their container images in response to this announcement.</p><p>“We also now know that OpenSSL versions prior to 3.0 are not impacted, and a lot of operating systems use OpenSSL 1.1, so these environments won’t be impacted. This knowledge will allow cybersecurity and operations teams to dismiss large sections of their infrastructure, and hopefully make the impact of this vulnerability smaller than initially expected. But platform engineering teams should keep investing in better auditing of their environments and their dependencies for the next threat, which is always just around the corner.”</p><h2 id="what-was-the-heartbleed-vulnerability">What was the Heartbleed vulnerability?</h2><p>In 2014, security researchers discovered a flaw within the OpenSSL software library, which could be exploited by threat actors in order to track the activity of targets online, as well as serruptiously steal data entered on web pages. At the time of identification, some researchers worried that <a href="https://www.itpro.com/security/22101/heartbleed-bug-everything-you-need-to-know" data-original-url="https://www.itpro.com/security/22101/heartbleed-bug-everything-you-need-to-know">Heartbleed</a> may have been exploited in the wild since 2012.</p><p>This was possible due to a coding error in the ‘heartbeat’ extension within OpenSSL, through which users could test transport layer security (TLS) encryption by sending data (typically a text string) and an integer representing the number of characters in the string to a computer or server device, which would then ‘echo’ the string back exactly.</p><p>As it was possible to send a string of a length equivalent to 64 KiB of data, that much memory was reserved for returns using the extension. However, it was discovered that if users only sent a nominal amount of data, but a length figure equal to 64KiB, the computer at the end would echo back the data sent, along with 64-1KiB of data from its memory buffer. This could reveal passwords entered, private server keys, sensitive user cookies — whatever happened to be in the memory at the time of the request.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability" data-original-url="/security/zero-day-exploit/361819/what-is-log4shell-log4j-vulnerability">What is the Log4Shell vulnerability?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/development/open-source/369079/organisations-are-scaling-back-their-open-source-software-due-to" data-original-url="/development/open-source/369079/organisations-are-scaling-back-their-open-source-software-due-to">Organisations are scaling back their open source software due to security fears – Anaconda</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday" data-original-url="/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday">Microsoft still searching for zero-day fixes following Patch Tuesday</a></p></div></div><p>As a result, threat actors were unable to specify precisely what data they would expose through each attack, but through repeat executions were able to invisibly monitor activity on any website which used OpenSSL, and exfiltrate data without any possibility of detection.</p><p>Given the scale at which OpenSSL is used throughout the internet, from financial services to critical backend apps, the Heartbleed vulnerability prompted considerable alarm within the cyber security community. Although a fix was quickly released, the fact that attacks carried out using the vulnerability left no trace made it hard to say for certain just how far reaching its impact was, and whose data has been stolen. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The sooner the FIDO Alliance can shut down passwords, the better ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better</link>
                                                                            <description>
                            <![CDATA[ Passwords aren’t going anywhere, but that hasn’t stopped the dream of a passwordless  future – and it seems that Apple, Google and Microsoft agree ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iKFMFGrvWDr7QCNH2Kp9Mx</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 22 Oct 2022 07:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Davey Winder ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/qKL6BZiS7oo9Hmyy2yd3WJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:description>                                                            <media:text><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:text>
                                <media:title type="plain"><![CDATA[A greyscale hand emerging from a hole, removing a password string, against a blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tnGuFCY2FyEpSeUB67FPs3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>I hate passwords with a vengeance, mainly because they’re so badly abused, from a cyber security perspective, by so many people. I’m not just talking about the person on the Clapham omnibus who keeps their passwords simple and shared between multiple accounts and services, but service providers as well. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/368004/how-to-test-password-strength-using-these-free-tools" data-original-url="/software/368004/how-to-test-password-strength-using-these-free-tools">How to test password strength using these free tools</a></p></div></div><p>In 2022, I would have liked to think the days of stupidly short character limits, along with rules forbidding special characters, would be long gone, but that’s not the case. Yes, Virgin Media, I am looking firmly in your “email passwords can be no longer than ten digits and contain no special characters” direction. </p><p>Of course, Virgin Media isn’t the only culprit. It’s still possible to find those who see password creation as some kind of Krypton Factor challenge where you have to use at least one number, uppercase, and special character, except for certain banned special characters of course – oh, and no repetition – all within a given maximum length password. </p><p>Not only is this daft, it’s also insecure; it makes it easier for those who would <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">crack your password</a> to do just that. If I know the maximum length of a string and the formatting rules, well, it becomes a lot less time-consuming for my password-cracking techniques to discover. </p><h2 id="ditching-passwords-for-passwordless-authentication">Ditching passwords for passwordless authentication</h2><p>Why are these stupid rules there in the first place? Because someone, at some point before login security hygiene realised the error of its ways, had to tick a compliance checkbox. That legacy has never gone away. This gets even more bizarre when, in the case of Virgin Media email accounts, you look at its own recommendations for creating a strong password, which includes things it won’t let its own customers do. These are things like using more than ten characters (“your password will be more secure and harder to crack, the longer it is”) or special characters (“strong passwords include... symbols or special characters”). </p><p>That <a href="https://www.virginmedia.com/help/security/how-to-create-a-strong-password">particular password advice page</a> gets it wrong when it says you should aim for “8 to 12 characters”. The days of such a short password string being considered secure have long since gone; I use 25 as my secure baseline now, and certain high-value accounts will get ramped up to 50. Where the Virgin Media advice gets it right is using a <a href="https://www.itpro.com/software/368077/best-password-managers-in-2022" target="_blank" data-original-url="https://www.itpro.com/software/368077/best-password-managers-in-2022">password manager</a> makes this a lot easier to accomplish, not only in terms of creating a random, long and secure password in the first place but being able to use them without being some kind of memory savant. Well, not use them if you are one of their customers, obviously. Another bit of correct advice – to use <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" target="_blank" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a> as a double-lock – is blunted somewhat by the fact that they don’t support this either.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication" data-original-url="/security/367243/how-to-implement-passwordless-authentication">How to implement passwordless authentication</a></p></div></div><p>This is where Apple, Google and Microsoft step forward in an unlikely alliance against password insecurity. The basis of the announcement, made by the three tech giants simultaneously, is to rid “password friction” by moving closer, more quickly, to <a href="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication" target="_blank" data-original-url="https://www.itpro.com/security/367243/how-to-implement-passwordless-authentication">passwordless authentication</a>. </p><p>As I’ve said, time and time again, <a href="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers" target="_blank" data-original-url="https://www.itpro.com/security/information-security-infosec/361806/skip-three-words-use-password-managers">password managers are your friend</a>; your very secure friend. Unfortunately, while password manager usage has taken off with more tech-minded users, the general public considers these applications a step too far. Why so? Friction. It’s much easier, it takes less time, to simply use that weak password everywhere. Until the inevitable day arrives when doing so leads to a data breach or worse, when things come tumbling down around them. </p><p>The conclusion is that better security, and stronger password hygiene, will only become something approaching any kind of norm if it comes with as little friction as possible. Hence, the move by these three tech behemoths to commit to a joint effort that extends support for a common passwordless authentication standard. </p><h2 id="embracing-fido-s-passwordless-future">Embracing FIDO’s passwordless future</h2><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="sr7PL6RyX4xfWCPshjfCie" name="sr7PL6RyX4xfWCPshjfCie.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" mos="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Building a better password strategy for your business</strong></p><p class="fancy-box__body-text">Exploring the strategies and exploits that hackers are using to circumvent password security measures</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business" data-original-url="/security/369393/building-a-better-password-strategy-for-your-business">FREE DOWNLOAD</a></p></div></div><p>That standard is the <a href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security">Fast ID Online (FIDO) Alliance</a>, which uses mobile devices to authenticate apps and websites instead of passwords. The most important part of this “passwordless pact” is that this will happen cross-platform rather than have a proprietary lock. The idea is you will be able to, for example, log into an account on your laptop using your smartphone, assuming it’s in range, by tapping an automatic notification asking if that’s you trying to sign in. At worst, it involves entering a PIN or biometric authentication, like scanning your fingerprint or using Face ID. </p><p>I’m all in favour of this move towards less friction – note the distinction between less friction and frictionless – in a cross-platform methodology to provide stronger authentication for people who don’t really understand what good security is, let alone care. Using your smartphone as a passkey store makes perfect sense from the ‘something you have, something you are, something you know’ perspective. An iPhone user is already used to using Face ID, most Android users are the same with fingerprint scanning, and many laptops users are accustomed to <a href="https://www.itpro.com/microsoft-windows/33595/windows-10-gains-fido-certification-for-biometric-logins" target="_blank" data-original-url="https://www.itpro.com/microsoft-windows/33595/windows-10-gains-fido-certification-for-biometric-logins">Windows Hello</a>. </p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=44789851&theme=light&playlist=false&playlist-continuous=false&autoplay=false&live-autoplay=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true&color=ffe019"></iframe><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security" data-original-url="/security/cyber-security/368478/will-fido-passwordless-authentication-save-cyber-security">Will FIDO passwordless authentication save cyber security?</a></p></div></div><p>Sure, it’s not perfect. Nothing is ever perfect, and that is truer in cyber security than most areas. However, if a threat actor needs to have physical access to your smartphone and your login username and your face or fingerprints or PIN), that’s a pretty secure scenario for the vast majority of users and use cases. If you are an outlier in terms of risk then the chances are you will already be using strengthened authentication measures anyway. </p><p>As my friend, Jake Moore, a former digital forensics police officer and current global cyber security advisor at ESET, says: “It is encouraging that Microsoft, Google, and Apple are attempting to pave the way to make account access secure as well as convenient. This isn’t something that can be achieved overnight, but it highlights that more needs to be done when it comes to password security. Cyber criminals will inevitably attempt to circumnavigate by looking for ways to exploit this method as nothing remains hack-proof, but like with any early adoption of new technology, this is a great start and we are likely to see a decent version of this in the near future.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware activity down 11% worldwide in Q3, but rise expected ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/369352/ransomware-activity-down-11-worldwide-in-q3-but-rise-expected</link>
                                                                            <description>
                            <![CDATA[ LockBit increased its share of the landscape even as attacks declined, while new groups have capitalised on the fall of Conti ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b4fuFgJsifNb9hd26Dp4Yi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tFeFJScbw97cukyfWG8SCh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Oct 2022 11:22:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tFeFJScbw97cukyfWG8SCh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI render of the Earth, focused on EMEA, surrounded by data points and red padlock symbols]]></media:description>                                                            <media:text><![CDATA[A CGI render of the Earth, focused on EMEA, surrounded by data points and red padlock symbols]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI render of the Earth, focused on EMEA, surrounded by data points and red padlock symbols]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tFeFJScbw97cukyfWG8SCh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new report has found that global ransomware activity dropped throughout the third quarter as the order of dominant groups in the landscape shifted, but that businesses should expect a surge by threat actors in Q4 to exploit consumer trends.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TDddJPsRCmdrr35SdPri7g" name="TDddJPsRCmdrr35SdPri7g.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TDddJPsRCmdrr35SdPri7g.jpg" mos="https://cdn.mos.cms.futurecdn.net/TDddJPsRCmdrr35SdPri7g.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to reduce the risk of phishing and ransomware</strong></p><p class="fancy-box__body-text">Top security concerns and tips for mitigation</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware" data-original-url="/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware">FREE DOWNLOAD</a></p></div></div><p>The number of ransomware attacks in Q3 2022 was down 10.5% on Q2, according to the latest <a href="https://www.digitalshadows.com/blog-and-research/ransomware-in-q3-2022">report</a> by cyber security firm Digital Shadows. This was driven in part by the sudden cessation of activity by the <a href="https://www.itpro.com/security/ransomware/367623/costa-rica-declares-state-of-emergency-following-conti-ransomware-attack" data-original-url="https://www.itpro.com/security/ransomware/367623/costa-rica-declares-state-of-emergency-following-conti-ransomware-attack">Conti</a> group, as well as a reorganisation of leading groups over July and August.</p><p><a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter" data-original-url="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit 3.0</a>, the latest strain by the LockBit group of threat actors, consolidated its lead across the landscape in Q3, accounting for 35.1% of all activity across the period, compared to 32.8% in Q2. The group's rise, even as its overall activity declined, has been matched by the growth of a number of new groups, including Black Basta, Hive Leaks, and <a href="https://www.itpro.com/security/ransomware/368699/european-energy-company-and-gas-pipeline-hacked-by-alphv-ransomware" data-original-url="https://www.itpro.com/security/ransomware/368699/european-energy-company-and-gas-pipeline-hacked-by-alphv-ransomware">Alphv</a>, which account for 9%, 8%, and 7% of activity respectively.</p><p>Digital Shadows suggests that these groups have directly taken advantage of the gap in the market left by Conti, which after threatening to <a href="https://www.itpro.com/security/ransomware/367704/ransomware-group-conti-threatens-to-overthrow-costa-rican-government" data-original-url="https://www.itpro.com/security/ransomware/367704/ransomware-group-conti-threatens-to-overthrow-costa-rican-government">overthrow the Costa Rican government</a> in May, apparently shut down in June. The group’s website has disappeared, and a drop off in activity right at the end of Q2 has been linked directly to the group’s apparent cessation of attacks.</p><p>Groups that bucked the trend with increased activity across the period include ‘AvosLocker’ (up 50%) and Hive Leaks (up 80.8%). The latter operates the <a href="https://www.itpro.com/security/368462/microsoft-identifies-sophisticated-hive-ransomware-variant-written-in-rust" data-original-url="https://www.itpro.com/security/368462/microsoft-identifies-sophisticated-hive-ransomware-variant-written-in-rust">Hive</a> payload, which was singled out by Microsoft in Q3 for its sophisticated functions, and for being written in the programming language <a href="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust" data-original-url="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust">Rust</a>, which is becoming a <a href="https://www.itpro.com/careers/29133/the-top-programming-languages-you-need-to-learn" data-original-url="https://www.itpro.com/careers/29133/the-top-programming-languages-you-need-to-learn">popular programming language</a> for hacker groups.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="6FHzJPokAvJ84gVZr3efbK" name="" alt="A graph showing that LockBit made up the vast majority of ransomware attacks in Q3 2022" src="https://cdn.mos.cms.futurecdn.net/6FHzJPokAvJ84gVZr3efbK.jpg" mos="https://cdn.mos.cms.futurecdn.net/6FHzJPokAvJ84gVZr3efbK.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Some within the <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> community have suggested that Hive is composed of former Conti actors, or is even a continuation of the same group. Investigative journalist and cyber crime expert Brian Krebs <a href="https://twitter.com/briankrebs/status/1531651750117134337">tweeted</a> that attacks on Costa Rica appeared to have been committed by Hive, but that “with Conti apparently in the process of rebranding, it could just as well be the same criminals involved.”</p><p>However, Emisoft threat analyst Brett Callow subsequently <a href="https://twitter.com/brettcallow/status/1529470995114799104">tweeted</a> a screenshot from Hive’s website that states “we are not related with Conti”. No evidence yet links any emerging group with Conti.</p><p>Around 39% of all attacks across Q3 were made against victims within the United States, reflective of the consolidation of wealthy companies within the country. France and Spain followed, with the UK the fourth most targeted in the same period, accounting for 4.8% of victims. This marks a fall from the UK’s third place in Q2, and appears to have been driven by a surge in attacks in France and Spain, including Hive's attack on <a href="https://www.itpro.com/security/368903/altice-reportedly-hit-by-hive-ransomware-attack" data-original-url="https://www.itpro.com/security/368903/altice-reportedly-hit-by-hive-ransomware-attack">French telco giant Altice</a> in August.</p><p>Indeed, while almost all countries saw decreased ransomware attacks in Q3, France, Spain and Israel saw rises. Spain was an outlier, with a 66% rise in ransomware activity across the quarter tied to a surge by the group ‘Sparta Blog.’</p><p>The industrial goods and services sector remained the most targeted sector throughout the period, recording nearly double the attacks of the technology sector, the next most targeted. As the <a href="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far" data-original-url="https://www.itpro.com/security/cyber-warfare/363385/russia-cyber-attacks-ukraine-what-we-know-so-far">war in Ukraine</a> drags on, attacks on supply chains and <a href="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national" data-original-url="https://www.itpro.com/security/cyber-security/368440/the-new-wave-of-cyber-security-threats-facing-critical-national">critical national infrastructure (CNI)</a> continue to rise, and <a href="https://www.itpro.com/security/malware/368764/defence-enterprises-and-government-agencies-in-russia-and-ukraine-targeted-by-state-hackers" data-original-url="https://www.itpro.com/security/malware/368764/defence-enterprises-and-government-agencies-in-russia-and-ukraine-targeted-by-state-hackers">state-backing</a> of ransomware attacks will continue to increase such action.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses" data-original-url="/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses">Microsoft warns of 'Prestige' ransomware targeting business in Ukraine, Poland</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369222/what-is-triple-extortion-ransomware" data-original-url="/security/ransomware/369222/what-is-triple-extortion-ransomware">Will triple extortion ransomware truly take off?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="/security/29241/what-are-the-different-types-of-ransomware">What are the different types of ransomware?</a></p></div></div><h2 id="bracing-for-a-rise-in-q4">Bracing for a rise in Q4</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="dbqqiERr7VPoqmV88Xp8Em" name="" alt="A graph showing ransomware activity decreased in Q3 2022, but increased again in September and is forecast to maintain high activity in Q4" src="https://cdn.mos.cms.futurecdn.net/dbqqiERr7VPoqmV88Xp8Em.jpg" mos="https://cdn.mos.cms.futurecdn.net/dbqqiERr7VPoqmV88Xp8Em.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Digital Shadows forecasts a rise in activity in Q4 2022. This is not unusual, as commercial events such as Black Friday and Cyber Monday often coincide with an increase in malicious activity online, while online shopping around Christmas is exploited by threat actors with <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><p>After falling prey to a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack" data-original-url="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attack</a> in August, which took down its website for several days, the LockBit group vowed to <a href="https://www.itpro.com/security/ransomware/368868/lockbit-ransomware-more-aggressive-ddos-attack" data-original-url="https://www.itpro.com/security/ransomware/368868/lockbit-ransomware-more-aggressive-ddos-attack">be ‘more aggressive’</a> and stated that it was recruiting new members. This may be linked to the increase of attacks at the end of Q3, and indeed the LockBit group saw its highest ever share of international ransomware activity at 40%.</p><p>Concerns have also been raised due to the alleged leak of a LockBit 3.0 ‘builder’ in September. If legitimate, this would allow rival threat actors to create their own version of LockBit ransomware, and as such the leak could precede a spike in use of the highly-effective <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> throughout Q4 and beyond.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Undetectable PowerShell backdoor discovered hiding as Windows update ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/vulnerability/369346/fully-undetectable-powershell-backdoor-hiding-as-windows-update</link>
                                                                            <description>
                            <![CDATA[ SafeBreach researchers identified the backdoor, which they say went undetected on all major antivirus programs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fus1tu4RGExa8FVeYBumvB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Pma4CdvF8sC4uQDjrLtjoD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Oct 2022 11:29:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Pma4CdvF8sC4uQDjrLtjoD-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Two screens showing computer code with a red box displaying the word &amp;#039;PowerShell&amp;#039;]]></media:description>                                                            <media:text><![CDATA[Two screens showing computer code with a red box displaying the word &amp;#039;PowerShell&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[Two screens showing computer code with a red box displaying the word &amp;#039;PowerShell&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Pma4CdvF8sC4uQDjrLtjoD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security firm SafeBreach has warned of a fully undetectable (FUD) PowerShell backdoor using a novel attack methodology.</p><p>The vulnerability, which researchers discovered in the wild, uses a <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell</a> script to create a scheduled task in the victim’s system, disguised as a <a href="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update" data-original-url="https://www.itpro.com/operating-systems/27717/how-to-fix-a-stuck-windows-10-update">Windows update</a>. To enhance the deception, the task executes a script named ‘updater.vbs’ from a fake update folder located in the victim’s appdata folder.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3DZhQDJwxTFW2pV3wWSxmJ" name="3DZhQDJwxTFW2pV3wWSxmJ.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/3DZhQDJwxTFW2pV3wWSxmJ.jpg" mos="https://cdn.mos.cms.futurecdn.net/3DZhQDJwxTFW2pV3wWSxmJ.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Solve cyber resilience challenges with storage solutions</strong></p><p class="fancy-box__body-text">Fundamental capabilities of cyber-resilient IT infrastructure</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368460/solve-cyber-resilience-challenges-with-storage-solutions" data-original-url="/security/368460/solve-cyber-resilience-challenges-with-storage-solutions">FREE DOWNLOAD</a></p></div></div><p>SafeBreach noted that this novel vector of attack makes it particularly dangerous, as <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> aggregator VirusTotal found the attack was able to bypass all security software tested. The backdoor has thus been marked as FUD in a <a href="https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor">blog post</a> by SafeBreach.</p><p>Attacks originate with a <a href="https://www.itpro.com/business-strategy/collaboration/364002/google-docs-vs-microsoft-word-online" data-original-url="https://www.itpro.com/business-strategy/collaboration/364002/google-docs-vs-microsoft-word-online">Word</a> document, named ‘Apply Form.docm’, containing a macro code that deploys a malicious PowerShell script. Researchers identified the document as having been created in August 2022 in Jordan. The file’s Metadata, containing the term ‘Linkedin based job application’, suggests a link to the <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns that have <a href="https://www.itpro.com/security/phishing/362291/linkedin-phishing-attacks-increased-by-232-in-february" data-original-url="https://www.itpro.com/security/phishing/362291/linkedin-phishing-attacks-increased-by-232-in-february">seen a surge on LinkedIn</a> in 2022.</p><p>Prior to execution of the updater script, two separate PowerShell scripts titled ‘Script.ps1’ and ‘Temp.ps1’ are created, and their contents are stored in <a href="https://www.itpro.com/security/hacking/361312/a-quarter-of-all-malicious-javascript-is-obfuscated" data-original-url="https://www.itpro.com/security/hacking/361312/a-quarter-of-all-malicious-javascript-is-obfuscated">obfuscated</a> form within text boxes in the Word document. Script1.ps1 is used to establish a connection with the malicious operator’s command and control (C2) server, seeking commands to be executed. Commands are sent in the form of <a href="https://www.itpro.com/security/29671/what-is-aes-encryption" data-original-url="https://www.itpro.com/security/29671/what-is-aes-encryption">Advanced Encryption Standard (AES)</a> 256 CBC encrypted strings, which are then decrypted through the <a href="https://www.itpro.com/business/policy-legislation/369293/gchq-calls-for-greater-quantum-investment-chinese-tech-dominance" data-original-url="https://www.itpro.com/business/policy-legislation/369293/gchq-calls-for-greater-quantum-investment-chinese-tech-dominance">GCHQ</a>-made web app CyberChef.</p><p>Commands begin with a value of 0,1 or 2, which each invoke different responses from the Temp.ps1 script. Those that begin with 0 will be executed, with the output then encrypted using the same key, and uploaded to a URL through the C2. Commands that begin with 1 are read from a path designated through the C2 and executed, while those that begin with 2 are written to a designated path and executed.</p><p>SafeBreach researchers identified the exact URL the script connects to, using an <a href="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security" data-original-url="https://www.itpro.com/network-internet/30416/http-vs-https-what-difference-does-it-make-to-security">HTTP</a> GET request. When contacted for the first time, this returns a unique victim ID. The first test run by the team returned the number 70, leading to the conclusion that approximately 69 victims have been affected by the backdoor so far. Through the coding flaw of these predictable IDs, researchers wrote a script acting like each prior victim, and recorded the C2 commands received.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday" data-original-url="/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday">Microsoft still searching for zero-day fixes following Patch Tuesday</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses" data-original-url="/security/ransomware/369328/prestige-ransomware-targets-ukraine-poland-businesses">Microsoft warns of 'Prestige' ransomware targeting business in Ukraine, Poland</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/367380/linkedin-is-filled-with-deepfake-virtual-employees" data-original-url="/technology/artificial-intelligence-ai/367380/linkedin-is-filled-with-deepfake-virtual-employees">LinkedIn is filled with deepfake 'virtual employees'</a></p></div></div><p>Based on this information, SafeBreach has found that 66% of commands sent thus far have been data exfiltration requests, while a minority have sought to delete files from victims’ public folders, list files in their special folders, or return their <a href="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference" data-original-url="https://www.itpro.com/infrastructure/network-internet/358606/static-ip-vs-dynamic-ip-whats-the-difference">IP address</a>.</p><p>“Our research team believes this threat is significant because it is fully undetectable and was shown to bypass all the security vendors' scanners under VirusTotal.com,” Tomer Bar, director of security research at SafeBreach told <em>IT Pro</em>.</p><p>“We strongly recommend that all security teams use the <a href="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting" data-original-url="https://www.itpro.com/security/cyber-security/368481/what-is-threat-hunting">indicators of compromise (IOCs)</a> we identified to better detect and protect themselves against this threat. We also suggest that the security mistakes we discovered by this threat actor be used by blue teams in their future digital forensics and incident response (DFIR) investigations.”</p><p>SafeBreach has added coverage for this backdoor on its security platform, and has listed all of the IOCs and PowerShell scripts it discovered within its blog post declaring the risk.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fortinet reiterates call to mitigate against active zero-day, as customers delay fixes ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369336/fortinet-call-to-mitigate-against-active-zero-day-customers-delay-patches</link>
                                                                            <description>
                            <![CDATA[ A large number of customers have yet to apply mitigations necessary to avoid the critical vulnerability ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9RdGZ55UybYuRFKADTSuWz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EbCCK9B4A8MjWT59KzrtnU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Oct 2022 15:50:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EbCCK9B4A8MjWT59KzrtnU-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Fortinet logo on a phone, with blue binary code in the background]]></media:description>                                                            <media:text><![CDATA[The Fortinet logo on a phone, with blue binary code in the background]]></media:text>
                                <media:title type="plain"><![CDATA[The Fortinet logo on a phone, with blue binary code in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EbCCK9B4A8MjWT59KzrtnU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Fortinet has issued an urgent warning to customers advising once again to update devices against a zero-day vulnerability that has been exploited at least once in the wild.</p><p>FortiOS, FortiProxy, and FortiSwitchManager are all affected by the <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day</a>, an authentication bypass flaw which allows threat actors to run operations on a device’s administrative interface. Tracked as <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40684">CVE-2022-40684</a>, the vulnerability carries a CVSS score of 9.6, and is therefore considered critical.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nAkAthFBggqpbeuovZyehc" name="nAkAthFBggqpbeuovZyehc.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nAkAthFBggqpbeuovZyehc.png" mos="https://cdn.mos.cms.futurecdn.net/nAkAthFBggqpbeuovZyehc.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Facilitating Fintech</strong></p><p class="fancy-box__body-text">Reducing the risk of potential data interception among fintech solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/369240/facilitating-fintech" data-original-url="/security/369240/facilitating-fintech">FREE DOWNLOAD</a></p></div></div><p>Before going public with the zero-day on October 10, Fortinet privately contacted the owners of potentially affected devices on October 6, with a list of recommended mitigations. However, the company has said that, at the time of writing, many devices have still not been updated or had <a href="https://www.fortiguard.com/psirt/FG-IR-22-377">mitigations</a> applied, leaving a large number of customers at risk of cyber attacks and opening networks to threats such as <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a>, and <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">data breaches</a>.</p><p>FortiProxy OS versions 7.0.0 to 7.2.1 are affected by the flaw, along with FortiProxy versions 7.0.0 to 7.2.0, and FortiSwitchManager 7.0.0 and 7.2.0. In response, the company has released a number of updates, as well as <a href="https://www.fortiguard.com/psirt/FG-IR-22-377">manual workarounds</a> for the three affected services.</p><p>“After multiple notifications from Fortinet over the past week, there are still a significant number of devices that require mitigation, and following the publication by an outside party of POC code, there is active exploitation of this vulnerability,” reads Fortinet’s <a href="https://www.fortinet.com/blog/psirt-blogs/update-regarding-cve-2022-40684">blog post</a> on the update.</p><p>“Based on this development, Fortinet again recommends customers and partners take urgent and immediate action as described in the public Advisory.”</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/368870/nec-and-fortinet-partner-to-deliver-high-performance-security-5g-networks" data-original-url="/mobile/5g/368870/nec-and-fortinet-partner-to-deliver-high-performance-security-5g-networks">NEC and Fortinet partner to deliver high-performance security for 5G networks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday" data-original-url="/security/369296/microsoft-still-searches-for-zero-day-fixes-following-patch-tuesday">Microsoft still searching for zero-day fixes following Patch Tuesday</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/endpoint-security/34536/mastering-endpoint-security-implementation" data-original-url="/endpoint-security/34536/mastering-endpoint-security-implementation">Mastering endpoint security implementation</a></p></div></div><p>The exploit has now been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">‘known vulnerabilities’ catalogue</a>, which is <a href="https://www.itpro.com/security/cyber-security/367816/cisa-adds-41-vulnerabilities-to-catalog-of-exploited-bugs" data-original-url="https://www.itpro.com/security/cyber-security/367816/cisa-adds-41-vulnerabilities-to-catalog-of-exploited-bugs">regularly updated</a> with threats that the agency considers an active threat to federal operations. As a result of being added to the list, federal agencies have until November 1 to patch all Fortinet equipment and apply appropriate mitigations.</p><p>“This is a critical vulnerability,” stated Avishai Avivi, CISO at SafeBreach.</p><p>“It basically allows the malicious actor to take control of the organisation’s firewall. We join Fortinet in their recommendation. With this being a zero-day vulnerability, we also strongly recommend that organisations take steps to validate their firewall configuration.</p><p>"If an attacker manages to take control of the <a href="https://www.itpro.com/security/firewalls/368739/fortinet-unveils-fastest-compact-firewall-for-hyperscale-data-centers-and" data-original-url="https://www.itpro.com/security/firewalls/368739/fortinet-unveils-fastest-compact-firewall-for-hyperscale-data-centers-and">firewall</a>, they can modify the firewall configuration to remove protection, add potential vectors for the attacker to use, and even add users. This is also an important reminder that companies should always keep a <a href="https://www.itpro.com/backup/29847/best-free-backup-software" data-original-url="https://www.itpro.com/backup/29847/best-free-backup-software">backup</a> copy of their firewall configuration files.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>