APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn

International hacking groups are exploiting vulnerabilities in virtual private network technologies to steal user credentials and monitor sensitive traffic, the United Kingdom’s National Cyber Security Centre said, amid recent warnings that the Chinese government has used similar tactics to collect intelligence. The NCSC, an offshoot of Britain’s intelligence agency, the GCHQ, said on Oct. 2 hackers are leveraging outdated versions of Palo Alto Networks, Fortinet and Pulse Secure products. The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Agency published its own advisory on the vulnerabilities, which attackers could use to take over an affected system, on Oct. 4. Neither warning speculates on who may be behind the attack, though the alerts come after Microsoft in August said Manganese, a Chinese hacking collective also known as APT5, was focusing attacks on Pulse Secure and Fortinet products. Pulse Secure, Palo Alto and Fortinet have each released security updates for all of […]

The post APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn appeared first on CyberScoop.

Continue reading APT groups are exploiting outdated VPNs to spy on international targets, U.K. and U.S. warn

Top UK Official Derides Huawei Claiming it has ‘Bad Security’

A top UK government cyber-official has called out the telecom supplier, long suspected to use its infrastructure sales as a base for industrial espionage. Continue reading Top UK Official Derides Huawei Claiming it has ‘Bad Security’

Once again, it’s 123456: the password that says ‘I give up’

A new survey says 46% of users find security confusing, which helps explain how that old clunker keeps popping to the top of breach lists. Continue reading Once again, it’s 123456: the password that says ‘I give up’

Experts to help boards tackle cybersecurity threats

A consortium of UK cyber security experts including UCL academics is to support global businesses to tackle online threats and protect themselves from cybercrime. The Cyber Readiness for Boards project, which is jointly funded by the National Cyber Sec… Continue reading Experts to help boards tackle cybersecurity threats

Serious ‘category one’ cyberattack not far off – warns security chief

Britain’s National Cyber Security Centre’s Ciaran Martin has warned it’s only a matter of time before the UK suffers a category one (C1) cyberattack. Continue reading Serious ‘category one’ cyberattack not far off – warns security chief

U.K. cyber agency tells government to handle Russian anti-virus software with caution

The United Kingdom’s national cyberthreat monitoring agency is advising some of the country’s agencies to quit using Russian anti-virus software. The warning is a change in tone from the National Cyber Security Centre’s longstanding position that the agency does not mandate or ban any products. NCSC head Ciaran Martin sent a public letter on Friday to the U.K.’s permanent secretaries about the “supply chain risk in cloud-based products.” Moscow-based cybersecurity company Kaspersky Lab has been under particular scrutiny in the United States for supposedly enabling Russians to steal information from intelligence authorities through software backdoors. The U.S. Department of Homeland Security ordered in September that all federal agencies purge Kaspersky software from their networks. “The specific country we are highlighting in this package of guidance is Russia,” Ciaran writes. “The NCSC advises that Russia is a highly capable cyber threat actor which uses cyber as a tool of statecraft. This includes espionage, disruption and influence operations. Russia has the intent to […]

The post U.K. cyber agency tells government to handle Russian anti-virus software with caution appeared first on Cyberscoop.

Continue reading U.K. cyber agency tells government to handle Russian anti-virus software with caution