Posts

Showing posts with the label iot

The Linux Flaw you can't afford to Ignore (CVE-2021-3156)

Image
Linux and Unix operating systems require regular patching like any IT system, but as security professionals, ethical hackers, and criminal hackers will tell you, regular Linux and Unix patching is often neglected. CVE-2021-3156 sudo Vulnerability Last week (26th January 2021) a new critical rated Linux\Unix vulnerability was made public under  CVE-2021-3156 . Specifically, the vulnerability is within the 'sudo' program, which is an abbreviation of ' superuser do ', well that's how I remember it. Sudo is a powerful and fundamental program found within all Linux and Unix distributions, allowing users to execute programs with the security privileges of another user. A typical use of sudo is where you need to run a program with privilege level (i.e. administrator) access rights. The sudo 'heap overflow' vulnerability was discovered by Qualys researchers, the exploit  allows any unprivileged user to gain root level (i.e. administrative) privileges.   Qualys has p...

Cyber Security Roundup for December 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, November 2020. Manchester United FC remains impacted by a seemly major cyber-attack, which I covered in a blog post titled  The Multi-Million Pound Manchester United Hack . At this point, United have provided few details about their cyber-attack which has been impacting club's IT systems for well over a week. However, the UK media are widely reporting United's leaky IT defences was unable to prevent a ransomware attack and data theft.   London's Hackney Borough Council have also been tight-lipped about what they describe as " a serious cyber-attack "  which has impacted its service delivery to Londoners. Like United, this attack has all the hallmarks of a mass ransomware outbreak. Both Manchester United and Hacknet Council said they are working UK's National Cyber Security Centre (NCSC). Man.Utd hit by ransomware, w...

Passwords are and have always been an Achilles Heel in CyberSecurity

Image
LogMeOnce , a password identity management suite provider, has published a detailed interview with myself titled ' Passwords are and have always been an Achilles Heel in CyberSecurity '. In the Q&A I talk about Passwords Security (obviously), Threat Actors, IoT Security, Multi-Factor Authentication (MFA), Anti-Virus, Biometrics, AI, Privacy, and a bit on how I got into a career in Cybersecurity. Quotes “I’m afraid people will remain the weakest link in security, and the vast majority of cybercriminals go after this lowest hanging fruit. It’s the least effort for the most reward.” "There is no silver bullet with password security, but MFA comes close, it significantly reduces the risk of account compromise" "The built-in biometric authentication capabilities of smartphones are a significant advancement for security" "Cybercriminals go after this lowest hanging fruit, the least effort for the most reward." "As technology becomes more sec...

Cyber Security Roundup for March 2020

Image
A roundup of UK focused Cyber and Information Security News, Blog Posts, Reports and general Threat Intelligence from the previous calendar month, February 2020. Redcar and Cleveland Borough Council became the latest UK organisation to become the victim of a mass ransomware attack  which started on 8th February.  The north-east Council's servers, PCs, mobile devices, websites and even phone lines have been down for three weeks at the time of writing. A Redcar and Cleveland councillor told the Guardian it would take several months to recover and the cost is expected to between £11m and £18m to repair the damage done . A significant sum for the cash-strapped council, which confirmed their outage as ransomware caused 19 days after the attack. The strain of ransomware involved and the method initial infiltration into the council's IT systems has yet to be confirmed. The  English FA shut down its investigation into allegations Liverpool employees hacked into Manchester ...

Keys to the Kingdom, Smart Cities Security Concerns

Image
By Sean Wray, VP NA Government Programs, Certes Networks Smart cities seem inevitable. According to IDC , Smart City initiatives attracted technology investments of more than £63 billion globally in 2018, and spending is estimated to grow to £122 billion in 2022. Similarly, in 2018, the number of major metropolitan cities relying on or developing a comprehensive smart city plan – as opposed to implementing a few innovative projects without an overall smart plan – dramatically increased. In the US, for example cities like Philadelphia, Newark and Chicago all have goals to upgrade and to become leading ‘SMART’ cities, while UK innovation is being spearheaded by major conurbations such as Bristol, London and Manchester . A significant investment is being made by cities in data connectivity providing a number of technologies such as Wi-Fi 6, smart grid, and IoT sensor devices, all promising to enhance overall visibility and security. However, as we extend the reach of technolog...

Securing Interactive Kiosks IoTs with the Paradox OS

Image
Article by Bernard Parsons, CEO, Becrypt Whether it is an EPOS system at a fast food venue or large display system at a public transport hub, interactive kiosks are becoming popular and trusted conduits for transacting valuable data with customers. The purpose of interactive kiosks, and the reason for their increasing prevalence, is to drive automation and make processes more efficient. For many businesses and government departments, they are the visible and tangible manifestations of their digital transformation. Kiosks are information exchanges, delivering data and content; ingesting preferences, orders and payments. With so much data going back and forth, there is huge value, however, wherever there is value you’ll find malicious and criminal activities seeking to spoil, subvert or steal it . Three categories of Cyber Threat Kiosks are just the latest in a long line of data-driven objects that need protecting. At stake is the very heart (and public face) of digitally evo...

Cyber Security Roundup for January 2020

A roundup of UK focused cyber and information security news stories, blog posts, reports and threat intelligence from the previous calendar month, December 2019. Happy New Year!  The final month of the decade was a pretty quiet one as major security news and data breaches go, given cybers attack have become the norm in the past decade. The biggest UK media security story was saved for the very end of 2019, with the freshly elected UK government apologising after it had accidentally published online the addresses of the 1,097 New Year Honour recipients.  Among the addresses posted were those of Sir Elton John, cricketer and BBC 'Sports Personality of the Year' Ben Stokes, former Conservative Party leader Iain Duncan Smith, 'Great British Bakeoff Winner' Nadiya Hussain, and former Ofcom boss Sharon White.  The Cabinet Office said it was " looking into how this happened ", probably come down to a 'user error' in my view. An investigation by The Tim...

Accelerated Digital Innovation to impact the Cybersecurity Threat Landscape in 2020

Image
Its December and the Christmas lights are going up, so it can't be too early for cyber predictions for 2020.   With this in mind,  Richard Starnes, Chief Security Strategist at Capgemini , sets out what the priorities will be for businesses in 2020 and beyond. Richard Starnes, Chief Security Strategist, Capgemini Accelerated digital innovation is a double-edged sword that will continue to hang over the cybersecurity threat landscape in 2020.  As businesses rapidly chase digital transformation and pursue the latest advancements in 5G, cloud and IoT, they do so at the risk of exposing more of their operations to cyber-attacks. These technologies have caused an explosion in the number of end-user devices, user interfaces, networks and data; the sheer scale of which is a headache for any cybersecurity professional.  In order to aggressively turn the tide next year, cyber analysts can no longer avoid AI adoption or ignore the impact of 5G.  AI ...

Cyber Security Businesses: Solving Challenges Through New Technologies

From everyday transactions to transport planning, as our world becomes more dependent on technology, cybersecurity risks are becoming more common, and more dangerous.  Luckily, there’s a range of cybersecurity businesses and start-ups attempting to solve this issue through innovative new technologies. We look at some recent projects and partnering opportunities tackling cybersecurity challenges.  Antivirus Software From Japan Established in 2007, a Japanese company has developed security software to detect unknown threats. They have developed a heuristic application consisting of five engines to detect malware and protect users. These engines include ; Static analyses Sandbox runs programs on a virtual environment Dynamic analyses (monitors the behaviour of currently running programs) Machine learnings Vulnerability attack protection The advantage of this technology is that it does not depend on pattern files. So far, the programs have detected several major threa...

Researchers find security flaws in ‘Amazon’s Ring Video Doorbell Pro’ IoT device

Image
Bitdefender researchers have discovered an issue in ‘ Amazon’s Ring Video Doorbell Pro ’ IoT device that allows an attacker to intercept the owner’s Wi-Fi network credentials. During the configuration stage, the mobile app sends the Wi-Fi network credentials in plaintext to the Ring Video Doorbell Pro. This then allows the hacker to sniff the packets and find out the sensitive data it needs to connect to the user’s WiFi. Once in possession of a user’s WiFi password, an attacker has full access to the network. And it’s no secret that an internal network can be very lax. In fact, many devices such as Smart TVs allow interaction without any authentication whatsoever – even if a device was under attack, there is no trace left and users will have no idea they were even a victim. Examples of possible things an attacker might do without your knowledge: Interact  with all devices within the household network  Intercept network traffic and run ‘man-in-the-middle’ attacks ...

The Business of Organised Cybercrime

Image
Guest article by David Warburton, Senior Threat Research Evangelist, F5 Networks Team leader, network administrator, data miner, money specialist. These are just some of the roles making a difference in today’s enterprises. The same is also true for sophisticated cybergangs. Many still wrongly believe that the dark web is exclusively inhabited by hoodie-clad teenagers and legions of disaffected disruptors. The truth is, the average hacker is just a cog in a complex ecosystem more akin to that of a corporate enterprise than you think. The only difference is the endgame, which is usually to cause reputational or financial damage to governments, businesses and consumers. There is no way around it; cybercrime is now run like an industry with multiple levels of deceit shielding those at the very top from capture. Therefore, it’s more important than ever for businesses to re-evaluate cybercriminal perceptions and ensure effective protective measures are in place. Current perceptions surround...