New defense method enables telecoms, ISPs to protect consumer IoT devices

Instead of relying on customers to protect their vulnerable smart home devices from being used in cyberattacks, Ben-Gurion University of the Negev (BGU) and National University of Singapore (NUS) researchers have developed a new method that enables tel… Continue reading New defense method enables telecoms, ISPs to protect consumer IoT devices

Microsoft releases new encryption, data security enterprise tools

Microsoft has released (in public preview) several new enterprise security offerings to help companies meet the challenges of remote work. Double Key Encryption for Microsoft 365 Secure information sharing is always a challenge, and Microsoft thinks it… Continue reading Microsoft releases new encryption, data security enterprise tools

Internet security is improving, but exposures still run rampant

Rapid7’s research found that the security of the internet overall is improving. The number of insecure services such as SMB, Telnet, rsync, and the core email protocols, decreased from the levels seen in 2019. Vulnerabilities and exposures still … Continue reading Internet security is improving, but exposures still run rampant

In about-face, UK bans Huawei from 5G networks

The United Kingdom on Tuesday said it was banning Huawei equipment from the country’s high-speed 5G networks in a dramatic reversal and a blow to the Chinese technology giant. Starting in January 2021, U.K. telecommunications operators will be barred from buying Huawei 5G technology, and all Huawei equipment will be removed from 5G networks by the end of 2027, said Digital, Culture, Media and Sport Secretary Oliver Dowden. Citing both security concerns with Huawei and supply-chain restrictions from recent U.S. sanctions on the Chinese company, Dowden told British lawmakers that in the coming years, Britain “will have implemented in law an irreversible path for the complete removal of Huawei equipment from our 5G networks.” The decision is a victory for the Trump administration, which has for years pressured U.S. allies to abandon Huawei, one of the world’s top suppliers of 5G equipment. U.S. officials charge that the Chinese government could […]

The post In about-face, UK bans Huawei from 5G networks appeared first on CyberScoop.

Continue reading In about-face, UK bans Huawei from 5G networks

Federal agencies recommend blocking Hong Kong-US undersea cable over national security concerns

The Departments of Defense, Justice, and Homeland Security urged U.S. regulators to block an application for an undersea cable connection between Hong Kong and the U.S. over concerns that it could expose sensitive communications to the Chinese government. The federal agencies, known as Team Telecom or the Telecom Committee, on Wednesday recommended the Federal Communications Commission deny the Pacific Light Cable Network (PLCN) undersea cable connection between the U.S. and Hong Kong amid concerns surrounding the Chinese government-linked ownership of the PLCN. A significant investor in the PLCN, Pacific Light Data Co. Ltd., is a subsidiary of the fourth largest telecommunications services provider in China, Dr. Peng Telecom & Media Group Co. Ltd., according to the Justice Department. U.S. intelligence officials have maintained that Chinese intelligence laws can make it compulsory for companies in China to comply with Beijing’s intelligence requests. “The Committee’s recommendation was based on … Dr. Peng Group’s relationship with [People’s Republic of China] […]

The post Federal agencies recommend blocking Hong Kong-US undersea cable over national security concerns appeared first on CyberScoop.

Continue reading Federal agencies recommend blocking Hong Kong-US undersea cable over national security concerns

Zero-day flaws in widespread TCP/IP library open millions of IoT devices to remote attack

19 vulnerabilities – some of them allowing remote code execution – have been discovered in a TCP/IP stack/library used in hundreds of millions of IoT devices deployed by organizations in a wide variety of industries and sectors. “Affe… Continue reading Zero-day flaws in widespread TCP/IP library open millions of IoT devices to remote attack

Shoddy US government review of Chinese telcos endangered national security, Senate panel finds

For decades, the U.S. government’s process for reviewing the cybersecurity risks of Chinese telecommunications companies operating in the U.S. has been so haphazard that it has “endangered our national security,” a bipartisan Senate review released Tuesday found. The Senate Permanent Subcommittee on Investigations said that the group responsible for these kinds of reviews, made up of national security officials from the Departments of Defense, Homeland Security, and Justice, largely failed to rein in Chinese telecommunications companies because of an “informal” process, insufficient resourcing, and a lack of statutory authority. Federal Communications Commission commissioners have likened the group’s review to an “inextricable black hole,” the report said. As a result of minimal oversight from the group, known as “Team Telecom,” Chinese state-owned telecommunications companies have been able to operate with relative impunity, even as concerns have mounted that Chinese state-owned companies could be enabling espionage backed by the Chinese government within the […]

The post Shoddy US government review of Chinese telcos endangered national security, Senate panel finds appeared first on CyberScoop.

Continue reading Shoddy US government review of Chinese telcos endangered national security, Senate panel finds

Coronavirus conspiracy theorists threaten 5G cell towers, DHS memo warns

Telecommunications providers should have robust security measures in place at 5G cell towers following a series of physical attacks from conspiracy theorists and other extremists, the Department of Homeland Security advised industry executives in a confidential memo last week. The advisory from DHS’s Cybersecurity and Infrastructure Security Agency (CISA) comes after a spate of attacks on cell towers in Europe, and as agency officials reckon with other COVID-19-related threats, ranging from data theft to fraud. “While the U.S. has not seen similar levels of attacks against 5G infrastructure linked to the pandemic, the tactics used in Western Europe [have] begun to migrate to the U.S,” says the memo, obtained by CyberScoop. Conspiracy theorists erroneously claim that 5G networking equipment weakens the immune system, or spreads coronavirus. The anti-5G fervor has perhaps been at its most destructive in the United Kingdom, where people have damaged more than 70 cell towers since the coronavirus outbreak. But multiple incidents in the U.S. […]

The post Coronavirus conspiracy theorists threaten 5G cell towers, DHS memo warns appeared first on CyberScoop.

Continue reading Coronavirus conspiracy theorists threaten 5G cell towers, DHS memo warns

‘Greenbug’ hacking group hits three telecom firms in Pakistan

For the past several months, suspected Iranian hackers have been rooting around the IT systems of at least three telecommunications companies in Pakistan, accessing data servers when it suits them, according to cybersecurity company Symantec. The report, published Tuesday, points the finger at a group called Greenbug, which used virtual “tunnels” to quietly stay connected to victim machines. The telecom data could offer a trove of information to spy on targets in Pakistan, and the hackers were determined to access the company’s networks. “As we would close one door, they would attempt to come back through another,” said Jon DiMaggio, senior cyberthreat analyst at the Symantec Enterprise Division, recalling Greenbug’s drive to stay on the Pakistani telecom companies’ networks after being discovered. Analysts told CyberScoop that the report is another example of the challenges some telecom providers have in keeping spies out of their networks. Eighteen different hacking groups linked to various governments went after telecom companies […]

The post ‘Greenbug’ hacking group hits three telecom firms in Pakistan appeared first on CyberScoop.

Continue reading ‘Greenbug’ hacking group hits three telecom firms in Pakistan

Nvidia acquires Cumulus Networks

Nvidia today announced its plans to acquire Cumulus Networks, an open-source centric company that specializes in helping enterprises optimize their data center networking stack. Cumulus offers both its own Linux distribution for network switches, as well as tools for managing network operations. With Cumulus Express, the company also offers a hardware solution in the form […] Continue reading Nvidia acquires Cumulus Networks