Home Blog Page 221

What Every Employee Can Do to Strengthen Security at Home (Part-2)

Remote Security Policy, Remote Work Jeopardizes Corporate Network Security: Report

In the first part of this series, I wrote about some ways to secure home networks, password creation guidelines, two-factor authentication, and mobile security. In this article, I will cover application security and OS security. As we’re becoming more comfortable working from home, hackers are increasingly targeting remote workers. I would first like to discuss a few simple rules that would help remote workers prevent a cyberattack.

By Brian Pereira, Principal Editor, CISO MAG

Rule #1: The cardinal rule is, keep your office device and home device separate. DO NOT use the same device for official and personal work. Never allow your family members to use your office laptop or install games or apps on it.

Rule #2: Uninstall all unnecessary apps from your office laptop. Make sure you are using original versions (not cracked) of the operating system and the applications.

Rule #3: Update your OS and apps regularly – on both your laptop and smartphone. There will always be weaknesses in software and hackers will look for those and exploit them. Software developers patch their apps and release new versions. Yes, OS updates can take a long time and will require you to restart your laptop (several times). Schedule your OS updates for early morning or late at night.

Rule #4: Change passwords every 30 days or so. DO NOT use the same password across cloud services. There are password managers that can help you remember all those passwords, but I would not recommend those. Write passwords in a little red book and store it at the back of your drawer or in a safe at home! Use password phrases that you can remember, with a mix of upper and lower case letters.

Rule #5: Change the default admin password on your home router. Home routers and access points have default usernames and passwords like “ADMIN”. Just read the router manual and you’ll see it. It is easy for a  tech-savvy neighbor to guess the default password and hack into your home Wi-Fi network for free connectivity. The hacker will also be able to take control of all the connected devices in your home and steal data and other passwords.

Windows Security Tips

There are also a few other things that can be done to strengthen Windows 10 security on your office laptop. That comes with a caveat: your office IT administrator may have already tightened controls, so end users may not be able to change these settings. However, you can always check these Windows settings.

  1. Rename the admin account – “Admin” or “Administrator” are names that hackers look for. So, if you can, rename the admin account to something that is not so obvious. Use “Edit Group Policy” in Windows 10 to do this. (Ask your office IT administrator).
  1. Delete/disable extra admin accounts – Admin accounts have the most privileges and hackers always look for these accounts. There is a possibility that your IT team created multiple admin accounts while maintaining your laptop. Search for those extra admin accounts and delete them. Run the “msc” Windows utility to do this. (Ask your office IT administrator).
  1. Disable the Guest account – It has minimum privileges and is meant for temporary use. But it can be exploited by hackers. So, disable it after it has served its purpose. Use “Edit Group Policy” in Windows 10 to disable the Guest account. (Ask your office IT administrator).
  1. Increase security of UAC – User Account Control limits privileges and access of users, depending on their profiles. Start > Control Panel > System & Security. Under “System & Maintenance” click “Change User Account Control Settings”.
  1. Use Windows Encrypting File System (EFS) – Right-click on a file or folder > Properties > General tab > “Advanced” button.
  1. Use Windows Bitlocker drive encryption – Type “Manage Bitlocker” in the search box near the “Start” button.
  1. Disable Jumplists (recently opened) – Start > Settings > Personalization. Select the “Start” option and turn off various options.
  1. Set a user account password for your office laptop – Start > Settings > Personalization > Lock Screen. Go to “Sign-in” options. (Only the Administrator account will be able to change this – so contact your system administrator).
  1. Disable file sharing – Start > Control Panel > View by large icons > File Explorer Options > View Tab > Scroll down the “Advanced Settings Pane” and uncheck “Use Sharing Wizard (Recommended)”.

Well, if you’re unable to find all these security and privacy features in Windows 10, ask your office IT administrator to assist you.

To be continued…

Part-1: What Every Employee Can Do Now to Strengthen Security at Home

Data Breaches Impact Employees’ Work-Life-Balance: Kaspersky

Employee habits

Data breaches are unfortunate events in present digital lives. Billions of people have had their personal data exposed as data leaks increase in scale. Apart from a spectrum of collateral damage and hefty fines, the data breaches also cause a severe impact on employees’ personal lives, a new report from Kaspersky revealed.

The report, “Taking care of corporate security and employee privacy: Why cyber-protection is vital for both businesses and their staff,” highlighted the human side of cybersecurity incidents by analyzing the stress and losses that employees face after corporate data breaches. The report revealed that 30% of employees who were involved in the aftermath of a security incident missed an important personal event, had to work overnight (32%), or suffered additional stressors (33%). A quarter of respondents said that they have canceled their vacations due to data breach issues (27%).

Nearly half of SMBs (48%) and enterprises (53%) have experienced at least one data breach last year, according to the report. It is said that work-related stress invades work-life balance, impacts efficiency and motivation, while 76% of employees stated it impacts personal relationships, and 16% reported they ended up quitting their job. The report also revealed that security incidents may contribute to negative work experience, with 33% of administrators feeling stressful, than they would usually.

The image reveals the personal consequences that security personnel face following a data breach:

Image source: Kaspersky

“If a data breach occurs, IT and IT security teams have to investigate the incident, make the necessary updates, fix the system and take measures to prevent an attack being repeated. As a result, a third of managers worked overnight or had to incur overtime at work (33% for SMBs and 32% for enterprises). This can also result in other tasks and deadlines being pushed back in more than a quarter of both SMBs (27%) and enterprises (26%),” the report added.

Kaspersky also recommended few steps that would help organizations mitigate the impact of a breach on its staff. These include:

  • In the time of crisis, be transparent with your people
  • It is best to prepare a list of steps for an IT department in case of an incident
  • If a breach occurs, focus on properly investigating the causes and consequences instead of just searching for any guilty staff
  • Any crisis can be seen as a time of opportunity
  • Create a corporate culture where all employees understand the importance of cybersecurity

Foreign State Hackers Target Coronavirus Research Centers in US: FBI

Patchwork BADNEWS, APT31 threat group

Cybersecurity leaders from the FBI said certain state-backed threat actors broke into the U.S. research institutions, which are working on COVID-19-related research, according to a Reuters report. Tonya Ugoretz, Deputy Assistant Director at FBI and head of the bureau’s Cyber Readiness and Intelligence Branch, warned that foreign government-sponsored hackers have targeted the U.S. in different ways, including attempts to steal information from the national health care sector and COVID-19 research centers. “We have certainly seen reconnaissance activity and some intrusions into some of those institutions, especially those that have publicly identified themselves as working on COVID-related research,” Ugoretz said.

Ugoretz has made the revelation during an Aspen Institute online discussion held recently. However, she did not reveal which countries were behind the cyber intrusions. She also highlighted that people have asked for information about the research and vaccines for the ongoing medical emergency. It is said that state-backed attackers have often targeted the biopharmaceutical industry in the country. However, she said, “The sad flipside is that it kind of makes them a mark for other nation-states that are interested in gleaning details about what exactly they’re doing and maybe even stealing proprietary information that those institutions have.”

The FBI has been urging the public to be vigilant during the ongoing pandemic as hackers and scammers are trying to exploit the uncertainty. The bureau also admitted that it has seen a spike in cybercrimes since the onset of the Coronavirus outbreak.

83% of Health Care Devices in U.S. at Risk

According to a research from Atlas VPN, most health care organizations in the U.S. are running their medical devices on outdated software and operating systems, leaving them vulnerable to cyberattacks. It revealed that 83% of health care providers in the U.S. are running on outdated software. Around 1.2 million IoT devices used in thousands of health care organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020. The research also revealed that 27% of medical devices are still running Windows XP or old versions of Linux OS. Due to the severity of the Coronavirus threat, the health care sector leaves many connected medical devices vulnerable to potential cyberthreats.

Miscreants Hack Over 25,000 Accounts Including WHO, Gates Foundation, NIH Accounts

Regina police station hacking, hacking, email and passwords hacked

The cybersecurity of many businesses worldwide has been in question since the beginning of the COVID-19 pandemic, as threat actors have used it to leverage various malicious attacks. However, the concerns seem to have elevated, as national and international bodies like the World Health Organization (WHO), Gates Foundation, National Institute of Health (NIH), among others, now face the wrath. Nearly 25,000 of their employees’ email addresses and passwords have been leaked and posted on the underground forums.

SITE Intel Group finds the Leak

The data leak was first noticed by the SITE Intelligence Group, which monitors and analyzes the dark web for cybersecurity threats from online extremists and terrorist groups. The report from SITE stated that NIH was the worst affected with 9,938 leaked email addresses and passwords, followed by the Centers for Disease Control and Prevention at 6,857. Similarly, the World Bank had 5,120, and WHO had 2,732 employee email credentials being leaked. SITE also found that the data dump carries email addresses and passwords of a virology center in Wuhan, which has been at the center of many conspiracy theories related to the ongoing pandemic.

Experts Speak

Robert Potter, an independent Australian cybersecurity expert, the authenticity of the leaked data in a tweet, as he could verify some of the email addresses and passwords of WHO employees. However, he mentioned a possibility that this data could be from an earlier attack as health care organizations tend to take cybersecurity lightly at times.

According to the Official Cybercrime Report published by Cybersecurity Ventures, the global pandemic of COVID-19 will continue to have a massive impact on cyberspace. The damages caused by cybercrimes are poised to double amid the Coronavirus outbreak. Cybercrimes will cost the world $6 trillion annually by 2021, up from $3 trillion in 2015.

French Fitness Tech Firm Kinomap Suffers Data Breach; Exposes 42 Mn User Records

106 million Thailand visitors

An unsecured database is a reason for yet another major data breach incident. Researchers at vpnMentor found an open database, which belongs to fitness tech company Kinomap, exposing 42 million records (40GB data) of its users for at least a month. The database includes personal identity data (PII) of users from across 80 countries, including North America, Australia, Japan, the U.K., Belgium, Finland, Hungary, Portugal, France, Germany, the U.S., Canada, and South Korea.

The exposed PII included full names, home country, email addresses, usernames, Kinomap account details, gender, timestamps for exercises and the date they joined Kinomap. vpnMentor stated that it notified the French firm on March 28, 2020, immediately after the discovery. The database was fixed on April 12, 2020, after the French data protection regulator had been informed.

Kinomap creates interactive workout videos with various types of fitness machines, including Peloton products, along with coaching, and personal trainer videos, which are uploaded by Kinomap users and professional trainers from around the world.

“Many of the entries contained links to Kinomap user profiles and records of their account activity. Similar to social media accounts, Kinomap profiles can reveal considerable personal details about a user. If a malicious hacker had discovered this database, they could easily combine the information contained in numerous ways, creating highly effective and damaging fraud schemes and other forms of online attack,” vpnMentor said in a statement.

The researchers also claimed that they found access keys for the Kinomap API, which cybercriminals could exploit to hijack accounts. The PII could also be used to launch phishing attacks and identity fraud or to secretly install malware on target devices.

They warned that attackers may target online exercise apps like Kinomap, which have received increased demand due to the current stay-at-home scenario. “With millions of people across the globe now under quarantine at home due to the Coronavirus pandemic, the impact of a leak like this grows exponentially. Unable to access their usual forms of exercise, many people will be turning to apps like Kinomap to stay fit and upbeat during the crisis,” the researchers added.

Could Your IoT Device Get You into Trouble with Data Privacy Laws?

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

We live in an age where privacy is hard to come by. If you go online, you’ve got sites tracking your every move. Even offline, your privacy is limited – every company you deal with wants to collect that valuable personal information. This article is about Data privacy of IoT devices.

They may want to use it later to sell you something or sell it to someone else. There’s nothing more valuable today than data. The collection of data is something that, up until now, we’ve tacitly accepted.

 By Chris Usatenko, Growth Marketing and Cybersecurity Expert Writer

Should We Accept this Lack of Privacy?

After all, what’s the alternative? Giving up all internet use and never dealing with a company offline again?. But, let’s be honest – who really wants to do that? Considering the separation anxiety that most of us experience when separated from our phones, it’s not a viable option.

So, instead, we accept that companies will collect data and trust them to keep it safe. The number of high-profile hacks that have occurred over the past few years has proven that this is an unsafe strategy.

The Capital One Hack a few months ago, and the Cambridge Analytica scandal proved that it’s not just malicious hackers that we must worry about. In the former case, the hacker was hoping someone would recognize her skills and offer her a job.

The Cambridge Analytica scandal revealed murkier motives. The data gathered was used to influence the  U.S. presidential election. Still, both cases proved that data is not always collected by identity thieves and shady underworld figures.

Infographic: Awesome Security Facts 2019

What’s the Solution?

The solution that we’ve come up with so far is to demand better regulation. The new legislation is putting the onus on data gatherers to protect against a breach. The GDPR regulations that came into effect last year were one of the first far-reaching pieces of legislation in this regard.

Under this legislation, any companies that have clients in Europe are expected to maintain certain “norms.” Some of the regulations are simple – you must provide proof that subscribers opted into a mailing list if required.

Some are more onerous. Did you know, for example, that businesses that engage in “large-scale data handling” must employ a data protection officer?

The GDPR was designed to force companies to protect their client’s privacy better. But it’s only a smattering of what’s to come. Similar legislation will be enacted around the world.

An Interesting Regulation

Now, reading through texts on laws can be boring, but one piece of recent legislature caught our eye. It’s a bill that was enacted in California last September. This bill deals specifically with IoT devices. Or more specifically, that IoT devices must contain security to protect the devices from unauthorized access.

The bill also states that companies must take reasonable steps to prevent the disclosure of data contained on the devices. Combined with strict privacy laws passed in June, it’s clear that the state is taking privacy very seriously.

Why Should Companies Producing IoT Devices Take Note?

Let’s say that you create a simple smart sensor to control the temperature in the home. All it does is to monitor the ambient temperature in the room. It then adjusts according to your preferences. How could that possibly impact privacy?

Let’s look at it another way. That device is only collecting one form of data – the temperature. It might not seem to have value for you. But those devices are programmed with consumer preferences.

Data Sharing May Land You in Trouble

That data may well be valuable to a company working on a new air-conditioning system. Your company could even make a little extra cash by selling the data. Naturally, you wouldn’t hand over the personal names of the clients. You’d just give the data and the general area it comes from.

And, that could land you in trouble. It’s true that you’re not sharing their personal data. But the way privacy laws are headed; the courts might not view this as being as harmless as you think.  Unless you have the express consent of each client to share their data, you shouldn’t be handing it over to anyone.

Data privacy of IoT devices

Now, let’s look at part of what the California Bill’s intent was. The Bill states that companies must take reasonable measures to ensure that their systems are protected from unauthorized access.

If your IoT device is not secure enough, your company could land up in trouble. Why would a hacker want to gain control of your smart sensor?

Let’s consider a  conspiracy theory for a second. They hack the sensor of a company’s CEO. They change their personal preferences so that the temperature in the room is constantly warmer than it should be. They do this in the hopes of throwing off the CEO’s game.

Now, as I said, this sounds like a ridiculous conspiracy theory. But it could happen. Perhaps it’s the CEO’s ex-wife trying to make his life miserable. While it sounds outlandish, consider the other smart devices that we have now.

Editor’s note: While this may seem like a harmless prank, a sensor could be connected to an enterprise network. Weak security on the sensor can comprise the enterprise network as it provides an entry-point to a hacker. And that could result in data theft or a privacy breach as systems are compromised.

Things like home monitoring systems with nanny cams, smart cars, and so on. These devices can all be controlled remotely through apps on your phone or laptop. This makes things convenient for you, but also for the hacker.

If they hack the nanny cam, they can see exactly what’s going on inside your home. There are several reasons that they might want to do this:

  • To see what you have that’s worth stealing
  • They might redirect the cameras so that they can see the screen of your laptop. This could be useful in picking up your usernames and passwords.
  • It could be used to take pictures of you that could cause embarrassment and also lead to blackmail if they threaten to publish these online.

Using Your Device as an Access Point

But there’s another danger. And it’s one that many experts in the field think is the real issue with IoT devices. It could provide an access point to the smart hub of your home.

Now, the hub itself will usually be secure. If your device isn’t as secure, hackers could use it to access the smart hub. The hub that all your devices connect to and sync with. Like your smartphone, laptop, and so on.

You might think that it’s not your company’s problem. After all, it was the buyer’s decision to connect everything up to the smart hub. Except that in the California Bill, it’s clear that lawmakers are shifting the onus to manufacturers.

And, while there’s very little in terms of specific legislation out there to deal with this issue, that’s bound to start changing. If your device has a security flaw that hackers can exploit, the court could well rule that your company is liable for the breaches.

Final Notes

IoT is something that has captured the public interest and is becoming a part of our lifestyle, both in the office and at home. Companies offering smart devices could well take advantage of these trends. They have to do so carefully, though. They must keep privacy laws in mind when creating their software/firmware.

If they don’t, they might find themselves answerable to the long arm of the law.

About the Author

Chris is a growth marketing and cybersecurity expert writer. He’s passionate about cybersecurity and has published hundreds of articles in this area. He’s particularly interested in big data breaches and big data companies.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

India Flags Zoom App as Unsafe, Releases Advisory for Safe Use

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

The Zoom video-conferencing app has been facing privacy risks amid the ongoing COVID-19 pandemic. There are several privacy and security concerns associated with the app that resulted in severe criticism and cyberthreats globally. Recently, Zoom came under the Indian government’s radar due to growing security concerns around it. The Cyber Coordination Centre (CyCord), under the Ministry of Home Affairs (MHA) in India, recently released a detailed advisory on the usage of the app.

The advisory asked government representatives to avoid using the Zoom platform for official purposes, citing it as unsafe. The advisory also listed certain guidelines for safe usage of Zoom by private entities and individuals for unofficial purposes. These include:

  • Set new user ID and password for each meeting
  • Enable the meeting room
  • Disable join before host
  • Allow screen sharing by host only
  • Disable allow removed participants to re-join
  • Restrict or disable file transfer option
  • Lock meeting once all attendees have joined
  • Restrict the recording feature
  • End meeting (and not just leave, if you are the administrator)

In response to the Indian government’s advisory, Zoom authorities stated that the company is discussing potential ways to reinstate the confidence of Indian users on its platform. It also plans to bring the end-to-end encryption on the platform for video meetings, which is only applicable to the textual conversations so far.

The latest move comes after several companies warned about security issues from using Zoom. Recently, Germany and Taiwan have banned the use of Zoom in their nations. The New York City officials stated that schools in the City will no longer be allowed to use Zoom for online teaching. Also, the Australia’s Defense Force and its MPs are barred from using Zoom services.

Security Flaws in Zoom App

Security researchers claimed that the Zoom application is vulnerable to remote attacks. According to cybersecurity expert Mitch@_g0dmode, Zoom’s video conferencing software for Windows is vulnerable to “UNC path injection” flaw that could let hackers steal Windows passwords and execute arbitrary commands on their devices. Soon after the vulnerability was identified, the company fixed the issue by releasing a patch. The CEO of Zoom, Eric Yuan, addressed the security issues and stated that a patch has been released to fix the UNC vulnerability. The fix will be pushed out automatically to all the users.

247 Canadians from MS Zaandam Cruise Face Unintentional Data Breach

canada

A data breach by Global Affairs Canada (GCA) has exposed personally identifiable information (PII) including passport information of 247 Canadians aboard the Coronavirus affected MS Zaandam cruise ship. The unintentional data breach was caused by an “administrative error” as per the information shared with CBC.

MS Zaandam, a Holland America Line cruise liner, was docked at Fort Lauderdale (Florida) on April 2, 2020, The cruise was carrying 247 Canadian nationals among others that faced the  Coronavirus infection and were left stranded for more than four weeks, as against their original voyage that should have ended within two weeks. The already traumatized Canadian passengers, however, are now dealing with another issue — that of an unintentional data breach.

The Unintentional Data Breach

The GCA kept all the Canadian citizens on-board MS Zaandam and updated them about its efforts for a quick and safe passage for their return to Canada. During this process, on April 1, 2020, GCA mistakenly sent them an email attachment consisting of PII details of all the 247 passengers including their address, date of birth, email, phone number, and passport number. The GCA promptly registered their mistake and sent an apologetic follow-up email to everyone explaining the unintentional data breach. They requested the passengers to keep an eye on their finances and private details for suspicious activities and to subscribe for a credit monitoring service.

U.K. FCAs Accidental Data Breach

Earlier in February 2020, the U.K.’s Financial Conduct Authority (FCA) admitted that it accidentally exposed the confidential details of around 1,600 consumers who complained against it, in response to a Freedom of Information (FoI) request for data. In an official notice, the regulator stated that certain underlying classified information like names, addresses, and phone numbers of complainants may have been accessible on its website. However, the company clarified that no financial, payment card, passport, or other identity information was exposed in the incident.

According to FCA, the exposed information is related to the individuals who complained between January 2, 2018, and July 17, 2019. FCA removed the relevant data from its website immediately after noticing the data breach.

Cybercriminals Trade 267 Mn Facebook Accounts’ Info on Dark Web

Cloud of Logs dark web market

Cybersecurity firm Cyble found hackers selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums. In a blog post, Cyble claimed that the records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

“One of the threat actors have dropped an online bomb by dropping the identities of 267 million Facebook Users for 500 Euros,” the post read.

The exposed information includes email addresses, names, first name, last name,  last connection, status, age, phone numbers, Facebook IDs, dates of birth, age, and other personal data. However, the company clarified that none of the records include passwords. However, the information is enough for hackers to launch phishing campaigns and other online frauds, experts stated.

Cyble researchers were able to download and verify the records. It is said that the affected users may access this data on Cyble’s data breach monitoring platform. “At this stage, we are not aware of how the data got leaked at the first instance, it might be due to a leakage in third-party API or scrapping. Given the data contains sensitive details on the users, it might be used by cybercriminals for phishing and spamming,” the researchers added.

Since there is a rise in potential phishing attacks, Cyble suggested that users strengthen the privacy settings on their Facebook profiles and be vigilant on suspicious emails and text messages.

Same Records on Different Hacking Forum

In December 2019, security researcher Bob Diachenko and security firm Comparitech discovered an open Elasticsearch database that contained over 267 million Facebook records, mostly of U.S. users. The records included information like names, phone numbers, and Facebook IDs.

According to the researcher, the incident occurred due to illegal scraping operation or Facebook API abuse by cybercriminals in Vietnam. The exposed data was also posted on a hacker forum for download. Diachenko stated that 267,140,436 records were exposed in the incident, which could be used by attackers to launch SMS spam and phishing campaigns. Commenting on the reason for data leak, Diachenko said that Facebook’s API could have a security hole that would allow intruders to access personal data even after access was restricted or hackers might have stolen by scraping publicly visible profile pages.

NCSC Launches “Suspicious Email Reporting Service” To Prevent Email Scams

Bait attacks, Email Attacks

The U.K.’s National Cyber Security Centre (NCSC) urged people to report suspicious emails to Suspicious Email Reporting Service (SERS) in order to prevent the growing phishing and cyberattacks amid the COVID-19 pandemic. The agency asked people to forward any suspicious emails or links to [email protected].

What Happens When You Report?

The NCSC’s automated program will review suspicious emails and website links and remove sites that are found to be phishing scams. If any other malicious activity is discovered, the NCSC may:

  • Seek to block the address the email came from, so it can no longer send emails
  • Work with hosting companies to remove links to malicious websites
  • Raise awareness of commonly reported suspicious emails and methods used (via partners)

The new reporting initiative is part of the government’s “Cyber Aware” campaign, which was launched to advise people on protecting passwords, devices, and accounts. The NCSC claimed that it has taken down more than 2,000 Coronavirus-themed online scams intended to steal personal information, fake online shops selling fraudulent Coronavirus products, and malware distribution sites.

NCSC Chief Executive Officer, Ciaran Martin, said, “Technology is helping us cope with the coronavirus crisis and will play a role helping us out of it — but that means cybersecurity is more important than ever. With greater use of technology, there are different ways attackers can harm all of us. But everyone can help to stop them by following the guidance campaign we have launched today. But even with the best security in place, some attacks will still get through.”

“That is why we have created a new national reporting service for suspicious emails – and if they link to malicious content, it will be taken down or blocked. By forward messages to us, you will be protecting the U.K. from email scams and cybercrime,” Martin added.

NCSC and CISA’s Joint Advisory on Cyberthreats

Earlier this month, Cybersecurity officials from the NCSC, the U.S. Department of Homeland Security (DHS), and the Cybersecurity and Infrastructure Agency (CISA) released a joint advisory describing the growing number of attackers and other malicious groups in the U.K. and the U.S. The agencies stated that cybercriminals and advanced persistent threat (APT) groups are targeting individuals and organizations with a variety of ransomware and malware attacks, thereby exploiting the COVID-19 outbreak for their personal gain.

The advisory also included a non-exhaustive list of indicators of compromise (IOCs) for cyberattacks detection and mitigation advice. It offers practical advice that individuals and organizations need to follow to mitigate the risk of being affected by cyberattacks. The IOCs provided within the accompanying .csv and .stix files of the advisory are based on analysis from CISA, NCSC, and other industry experts.