Hackers Target Bahrain Airport, News Sites to Mark Uprising

Hackers said they had taken down the websites of Bahrain’s international airport and state news agency on Tuesday to mark the 12-year anniversary of an Arab Spring uprising in the small Gulf country.

A statement posted online by a group calling itself Al-Toufan, or “The Flood” in Arabic, claimed to have hacked the airport website, which was unavailable for at least a half hour in the middle of the day. It also claimed to have taken down the website of the state-run Bahrain News Agency, which was sporadically unavailable.

The group posted images showing 504 Gateway Timeout Errors, saying the hacking was “in support of the revolution of our oppressed people of Bahrain.”

The same group appears to have hacked and changed articles on the website of Akhbar Al Khaleej, a pro-government newspaper in Bahrain, hours earlier. The newspaper’s website was still down Tuesday.

There was no immediate comment from authorities.

Feb. 14, 2011, marked the first day of protests led by Bahrain’s Shiite majority against the Sunni monarchy. Bahrain ultimately quashed the uprising by force with the support of Saudi Arabia and the United Arab Emirates, but has continued to see sporadic unrest over the years.

Authorities have imprisoned Shiite activists, deported others, stripped hundreds of their citizenship and closed down a leading independent newspaper.

The same shadowy group of hackers targeted government websites during elections held in November that were boycotted by a banned Shiite opposition group and others.

Related: Cyberattacks Target Websites of German Airports, Admin

Related: US Airport Websites Hit by Suspected Pro-Russian Cyberattacks

Hackers Target Bahrain Airport, News Sites to Mark Uprising




ESXiArgs Ransomware Hits Over 3,800 Servers as Hackers Continue Improving Malware

There have been some new developments in the case of the ESXiArgs ransomware attacks, including related to the encryption method used by the malware, victims, and the vulnerability exploited by the hackers.

After the US Cybersecurity and Infrastructure Security Agency (CISA) announced the availability of an open source tool designed to help some victims of the ESXiArgs ransomware recover their files without paying a ransom, the FBI and CISA released a document providing recovery guidance.

The FBI and CISA are aware of more than 3,800 servers that were compromised around the world in ESXiArgs ransomware attacks. 

Currently, the Shodan and Censys search engines show 1,600-1,800 hacked servers, but there is indication that many impacted organizations have started responding to the attack and cleaning up their systems.

Reuters has conducted an analysis and determined that the victims include Florida’s Supreme Court and universities in the United States and Europe.

An analysis of the file-encrypting malware deployed in the ESXiArgs attacks showed that it has targeted files associated with virtual machines (VMs). However, experts noticed that the ransomware mainly targeted VM configuration files, but did not encrypt the flat files that store data, allowing some users to recover their data.

The tool released by the US government reconstructs the encrypted configuration files based on the unencrypted flat files. 

However, Bleeping Computer reported on Wednesday that some victims have been targeted with a new version of the ESXiArgs malware, one with a different encryption process that involves encrypting more data, which prevents the recovery of files. 

Until now, the ransomware did not encrypt the majority of data in large files, but the new version of the malware encrypts a far more significant amount of data in large files. Up until now, researchers have not found any flaws in the actual encryption, making it impossible to restore encrypted files.

It has been assumed that the ESXiArgs attacks leverage CVE-2021-21974 for initial access. This is a high-severity remote code execution vulnerability in VMware ESXi that VMware patched in February 2021. The issue is related to OpenSLP.

VMware has not confirmed exploitation of CVE-2021-21974, but it did say that there is no evidence of a zero-day vulnerability being leveraged in the attacks.

However, threat intelligence company GreyNoise is not convinced that there is enough evidence that CVE-2021-21974 is being exploited. GreyNoise pointed out that several OpenSLP-related vulnerabilities have been found in ESXi in recent years, and any of them could have been exploited in the ESXiArgs attacks, including CVE-2020-3992 and CVE-2019-5544. 

Data collected by cloud security company Wiz showed that, as of February 7, 12% of ESXi servers were unpatched against CVE-2021-21974 and vulnerable to attacks. 

The attacks have yet to be attributed to a known threat actor, but the evidence collected so far suggests that the file-encrypting malware is based on Babuk source code that was leaked in 2021. 

“Due to the relatively low ransom demand (2 BTC) and widespread, opportunistic targeting, we assess with moderate confidence this campaign is not tied to ransomware groups known for ‘Big Game Hunting’,” said SOC-as-a-service provider Arctic Wolf. “More established ransomware groups typically conduct OSINT on potential victims before conducting an intrusion and set the ransom payment based on perceived value.”

Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event

Related: VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities

https://www.securityweek.com/esxiargs-ransomware-hits-over-3800-servers-as-hackers-continue-improving-malware/




Minister: Cybercrimes Now 20% of Spain’s Registered Offenses

Spain’s government on Wednesday pledged stronger action against cybercrime, saying it has come to account for about a fifth of all offenses registered in the country.

Interior Minister Fernando Grande-Marlaska said police would be given additional staff, funding and resources to address online crime. He said reported cases of cybercrime were up 72% last year compared to 2019, and 352% compared to 2015.

“The … decline in conventional crime and the increase in cybercrime has brought us to a turning point: today, one in every five crimes in Spain is committed online,” he told a press conference in Madrid.

Almost 90% of cybercrimes reported last year involved online fraud schemes, Grande-Marlaska said. “This … has a remarkable and negative impact on national interests, institutions, companies and citizens,” he added.

On Tuesday, Spain’s defense minister approved the creation of a new military cyberoperations training school to further reinforce national security online.

Spain is among the countries that suffer the largest numbers of remote online attacks in the world, according to data from antivirus protection specialist ESET. Small businesses are particularly affected.

José Cano, Research Director at market intelligence firm IDC Spain, said a lack of talent and skills had left Spanish businesses exposed to the increasing sophistication of online criminals, who are innovating to bypass multi-factor authentication and other safeguards.

“Cyber-resilience is not only about enterprise value and reducing business risk, but also about national economic security,” Cano said. “European companies, especially Spanish companies, will increasingly incorporate cyber-resilience planning into their business and security strategies.”

https://www.securityweek.com/minister-cybercrimes-now-20-of-spains-registered-offenses/




Australian Man Sentenced for Scam Related to Optus Hack 

Australian authorities this week announced the sentencing of a Sydney man for attempting to blackmail Optus customers using leaked data stolen during a September 2022 data breach at the wireless carrier.

The Optus hack resulted in the theft of personal information belonging to 9.8 million customers, including names, birth dates, physical and email addresses, and phone numbers. For 2.1 million customers, numbers associated with identification documents were also compromised.

The incident was disclosed on September 22, with the attackers leaking the personal information of roughly 10,000 individuals a few days later.

The attackers demanded a $1 million ransom in cryptocurrency, threatening to release more of the stolen information each day until a payment was made.

On October 6, the Australian Federal Police announced the arrest of a Sydney man who attempted to use the leaked data to extort money from individuals impacted by the data breach.

The man, now 20, sent text messages to more than 90 Optus customers, demanding that they transfer $2,000 AUD (roughly $1,300 USD) to a bank account in the name of the scammer.

The youngster pleaded guilty on November 8 to two “counts of using a telecommunications network with intent to commit a serious offense […], where the serious offense is blackmail”, the Australian authorities say.

The individual was sentenced to 18-month community correction order and 100 hours of community service.

Related:Email Hack Hits 15,000 Business Customers of Australian Telecoms Firm TPG

Related: Hackers Leak Australian Health Records on Dark Web

Related: Medibank Confirms Data Breach Impacts 9.7 Million Customers

https://www.securityweek.com/australian-man-sentenced-for-scam-related-to-optus-hack/




Ransomware, il 60% delle aziende prese di mira ha meno di 250 dipendenti. Il report

Nel 2021 e nel 2022 il 60% delle aziende prese di mira dai ransomware ha meno di 250 dipendenti.

Lo rivela il nuovo report Ransomware Intelligence Global Report 2023, una ricerca che fornisce una panoramica completa degli attacchi ransomware registrati dalle organizzazioni mondiali nel 2021 e nel 2022.

Le aeree geografiche

A livello di aree geografiche, il Nord America si conferma al primo posto a livello mondiale per numero di attacchi, sebbene sia anche l’area che ha registrato il maggiore calo tra il 2021 ed il 2022 (-10%). Segue l’Europa con il 26,73% degli attacchi nel 2021 ed il 29,73% nel 2022 e l’Asia con il 9,82% nel 2021 ed il 15,41% nel 2022.

Anche considerando i principali gruppi di ransomware – in particolare Lockbit, BlackCat e Conti – nel 2021 il Nord America è stato preso di mira da 48 gruppi di ransomware, che sono diventati 57 nel 2022; l’Europa da 48 gruppi di ransomware, che sono diventati 51 nel 2022 – con Regno Unito, Germania, Italia, Francia e Spagna che pesano più del 70% di questi attacchi -; mentre l’Asia è stata attaccata da 45 gruppi di ransomware nel 2021, che sono diventati 51 nel 2022. Anche la Russia, infine, ha registrato nel 2022 un incremento pari al 9% negli attacchi ransomware rispetto al 2021.

I beni di consumo il settore più colpito

Per quanto riguarda i settori, il più colpito nel 2021 è stato quello dei Beni di Consumo con il 28,1% degli attacchi, seguito da quello dei Beni industriali con il 25,08% e da quello Health con il 7,4%; per quanto riguarda il 2022, invece, il settore più colpito è stato quello dei Beni Industriali con il 32% degli attacchi, seguito dai Beni di Consumo con il 24,9% e dal settore IT con il 10,6%.

Secondo il report molte piccole e medie imprese sono particolarmente vulnerabili agli attacchi ransomware, non disponendo delle risorse e delle competenze necessarie per proteggersi efficacemente. Questo le rende un obiettivo interessante per gli aggressori, che sanno che queste aziende sono più propense a pagare il riscatto per riottenere l’accesso ai propri dati.

Il settore assicurativo soffre

Tale situazione si ripercuote quindi sul settore assicurativo, con le compagnie costrette ad affrontare difficoltà crescenti relative alla valutazione dei rischi informatici dei loro clienti e alla determinazione del potenziale impatto di un attacco ransomware che deve essere valutato sulla base di una serie di fattori quali il tipo di dati criptati, i sistemi colpiti, la capacità dell’organizzazione di riprendersi dall’attacco, etc. Inoltre, con l’aumento del numero di richieste di risarcimento legate agli attacchi ransomware, le compagnie assicurative sono costrette ad applicare premi sempre più elevati per coprirne il costo.

Tuttavia, anche il settore assicurativo deve, a sua volta, adottare misure proattive per valutare e mitigare il rischio informatico dei propri clienti. Ciò include l’offerta di soluzioni tecniche per la valutazione e la mitigazione proattiva del rischio, con l’obiettivo di aiutare le organizzazioni a identificare, limitare e rispondere a potenziali vulnerabilità e attacchi. Solo abbinando queste soluzioni alle polizze assicurative, il settore assicurativo può fornire un approccio completo alla gestione del rischio informatico, contribuendo a proteggere le organizzazioni dalle conseguenze potenzialmente devastanti di un attacco ransomware.

Per approfondire

https://www.key4biz.it/434337/434337/




Come costruire un solido programma di governance dei dati

Nell’attuale economia digitale, i dati rappresentano la nuova moneta, con un valore che cresce non solo per le organizzazioni, ma anche per i loro clienti e i cybercriminali. La digitalizzazione e la consumerizzazione in corso ricevono anche una maggiore attenzione da parte delle autorità di regolamentazione, che spingono per una più accentuata protezione della privacy. Poiché la salvaguardia dei dati è una preoccupazione per i CISO e i consigli di amministrazione di tutto il mondo, la creazione di un solido programma di governance è ormai una priorità assoluta.

Il mondo è cambiato. Governance e protezione dei dati devono evolversi in modo corrispondente. Nel vecchio mondo, la protezione delle informazioni era semplice, poiché esse risiedevano nei data center controllati solo da noi. In questo nuovo mondo “ovunque e dovunque”, in cui possono trovarsi nei cloud pubblici, nelle applicazioni SaaS, nei database on premise o in qualsiasi altro luogo, la visibilità dei dati stessi crea nuovi problemi.

Affrontare rischi aziendali sempre più estesi

Una forza lavoro sempre più decentralizzata amplifica anche i rischi incentrati sulle persone, rendendo la protezione dei dati molto più difficile. Secondo il report Cost of a Data Breach di IBM Security, nel 2022 il costo medio di una violazione ha raggiunto il massimo storico di 4,35 milioni di dollari. E il lavoro a distanza è in parte responsabile dell’aumento dei costi, secondo lo stesso report che ha rilevato una “forte correlazione” tra il lavoro da remoto e il costo delle violazioni che sono costate in media 1 milione di dollari in più.

Le informazioni di identificazione personale (PII) di clienti e dipendenti sono i due tipi di record più costosi compromessi in una violazione dei dati. Si tratta di informazioni preziose per i cybercriminali, per furti finanziari, frodi e altri crimini informatici, il che significa che le minacce continueranno a prendere di mira questo tipo di dati e che le autorità di regolamentazione continueranno ad aumentare la pressione sulle organizzazioni affinché li proteggano meglio.

Lo stesso regime normativo in continua espansione è un fattore che fa aumentare i costi delle violazioni e la necessità di una migliore governance. Negli Stati Uniti, ad esempio, già 39 Stati hanno preso in considerazione leggi sulla privacy dei consumatori dal 2018 e cinque le hanno promulgate, secondo l’International Association of Privacy Professionals (IAPP).

Un efficace programma di governance dei dati deve riconoscere questo ambiente in continua evoluzione e considerarne le implicazioni, rispondendo a domande fondamentali quali: dove sono archiviati, sono presenti dati protetti o regolamentati, come vengono utilizzati (e chi vi ha accesso) e come vengono protetti?

I passaggi da considerare per la creazione di un programma di data governance

Per molte organizzazioni, la sfida principale è capire dove risiedono tutti i loro dati e come ottenere visibilità sull’intero ecosistema. La conservazione dei dati è un’altra area di dibattito normativo, soprattutto perché ogni regolamentazione presenta requisiti diversi. L’adozione di un approccio graduale e stratificato alla governance dei dati aiuterà ad affrontare queste sfide e a rispondere alle domande principali che stiamo considerando.

Un approccio a più livelli consente di passare dallo sviluppo e dalla definizione del programma di governance dei dati alla sua manutenzione e ottimizzazione. La prima fase di questo approccio, la Discovery, prevede la definizione del controllo iniziale in cui si procede alla qualificazione delle leggi e delle normative applicabili all’organizzazione, alla definizione della strategia di protezione dei dati in base ai loro cicli di vita, all’identificazione degli utenti più a rischio, alla scoperta dell’impronta digitale, alla creazione di un inventario globale e all’indicizzazione dei dati.

Nella seconda fase (Detection), si sviluppano le capacità di controllo acquisendo un contesto per tutte le attività, gli intenti e gli accessi degli utenti; si identificano gli account compromessi e gli utenti vittime di phishing; si classificano i dati sensibili o regolamentati. Inoltre, si adottano misure per tracciare gli incidenti e raccogliere e acquisire dati da tutte le fonti.

Infine, l’ultima fase (Enforcement) riguarda l’aumento delle capacità di controllo esteso, come la rimozione dei dati da luoghi non attendibili, la disponibilità di una piattaforma di scambio con l’esterno sicura e conforme, l’applicazione delle protezioni dei confini dei dati, l’implementazione di una supervisione completa della conformità e così via.

Scomponendo questi aspetti in passaggi più piccoli e concreti, è possibile creare un approccio programmatico che aiuterà a proteggere i dati in base ai rischi più elevati e garantirà un miglior ritorno sugli investimenti. Ma è fondamentale valutare costantemente l’efficacia del programma e ottimizzarlo, perché ogni ambiente è dinamico per natura e le tattiche delle minacce cambiano costantemente.

Attenzione alle minacce che richiedono un intervento umano

Anche se il panorama aziendale cambia rapidamente, le persone restano al centro della protezione dei dati. Secondo il Data Breach Investigations Report di Verizon, l’elemento umano gioca un ruolo nell’82% delle violazioni di dati. Dal phishing, al furto di credenziali, all’errore umano, sono i dipendenti e gli altri insider a rappresentare il rischio più elevato.

I cybercriminali continueranno a trovare modi creativi per rubare e monetizzare i dati. La protezione in un ambiente di minacce incentrato sulle persone richiede controlli di governance dei dati incentrati sulle persone. Creando un solido framework di questo genere per il programma di governance dei dati, sarà possibile prepararsi meglio ad affrontare le prossime sfide e a proteggere la valuta più preziosa di cui si dispone.

A cura di Lucia Milică, Global Resident CISO, Proofpoint

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/articoli/come-costruire-un-solido-programma-di-governance-dei-dati/




20 Million Users Impacted by Data Breach at Instant Checkmate, TruthFinder

PeopleConnect-owned background check services Instant Checkmate and TruthFinder have disclosed data breaches affecting a total of more than 20 million users.

In individual data breach notices published on February 3, the organizations informed users that the incident was discovered after cybercriminals started sharing databases stolen from the two companies on underground forums.

The databases – or ‘lists’, as the two companies call them – contain names, email addresses, phone numbers, encrypted passwords, and password reset tokens that are either expired or inactive.

“We have confirmed that the list was created several years ago and appears to include all customer accounts created between 2011 and 2019. The published list originated inside our company,” the announcements read.

The two organizations note that the leaked information does not include details on user activity or payment data.

While Instant Checkmate and TruthFinder also note that no “readable or usable passwords or other means to compromise user accounts” leaked either, it is not uncommon for cybercriminals to try to crack stolen encrypted passwords.

“As a best practice we would recommend that you not respond to suspicious communications. We will never ask you for your password, social security number or payment information via email or telephone,” the companies say.

Investigations were launched into both incidents, but no evidence of malicious activity has been found as of now on their networks. According to the two announcements, the data breach was the result of the “inadvertent leak or theft” of the impacted database.

While neither Instant Checkmate nor TruthFinder shared information on the number of affected individuals, the data has already been added to Troy Hunt’s breach notification service Have I been pwned.

The leaked databases include the information of more than 11.9 million Instant Checkmate accounts, and the details of over 8.1 million TruthFinder accounts.

Related: 820k Impacted by Data Breach at Zacks Investment Research

Related: 18k Nissan Customers Affected by Data Breach at Third-Party Software Developer

Related: 251k Impacted by Data Breach at Insurance Firm Bay Bridge Administrators

https://www.securityweek.com/20-million-users-impacted-by-data-breach-at-instant-checkmate-truthfinder/




Cyber Insights 2023 | The Coming of Web3

About SecurityWeek Cyber Insights | At the end of 2022, SecurityWeek liaised with more than 300 cybersecurity experts from over 100 different organizations to gain insight into the security issues of today – and how these issues might evolve during 2023 and beyond. The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs.

Cyber Insights | 2023

SecurityWeek Cyber Insights 2023 | The Coming of Web3 – Web3 is a term that has been hijacked for marketing purposes. Since web3 obviously represents the future internet, claiming to be web3 now is a claim to be the future today. Such claims should be viewed with caution – we don’t yet know what web3 will be.

Two of the biggest culprits are the cryptocurrency and NFT investment industries, which both use blockchains. They have claimed to be web3 so vociferously that some pundits believe that web3 is blockchain. This is way too simplistic – these are just applications running on one technology that may become one of the web3 building blocks. 

Before we discuss the evolution of, and issues with, web3 in 2023 and beyond, we’ll first define one specific view of its basics. 

A tentative definition of web3

Web3 will be the next fundamental characterization of the internet. Currently, its characteristics are clouded by confusion because it doesn’t exist. We won’t know what it is, until it is. Nevertheless, we can make some basic predictions because it will evolve from the current web2 and is bound by the rules of evolution. So, we must start with where we are to predict where we are going.

Web1 can be described as the static web. It was designed to deliver static information from information creators to information consumers. We still use web1.

Web2 can be described as the interactive web. It was designed to allow creators and consumers to interact. Three major examples are online banking, ecommerce, and social media. This is what we have now: a combination of web1 and web2.

Web3 can be described as whatever comes next. It will be an attempt to improve on web1 and web2. Most likely it will be an attempt to correct perceived faults or weaknesses in web2 and improve the users’ internet experience. We’ll focus on these characteristics in our projections for web3 focusing on decentralization and the metaverse — but remember that at this stage, it is still just conjecture.

Decentralization
A perceived fault in web2 is that it allows data to be centralized and focused in the hands of a few mega corporations. Big tech, including companies like Facebook, Microsoft, Google, and Apple own most of the world’s available data. More specifically, they own everybody’s personal information.

This is a problem both politically and socially, and is the primary driver for legislation designed to prevent big tech (and medium tech) from misusing and abusing personal data. GDPR, CCPA (and other privacy legislation), and the FTC’s increasing ‘overview’ of the misuse (which it defines as malpractice), can be seen as political attempts at correcting this fault in web2. We can add that the centralization of data is also a primary cause of cybercriminality, providing Aladdin’s Caves of rich pickings for criminals.

A better solution would be for the internet itself to reduce the stranglehold of big tech by becoming decentralized — companies do not need to own data to be able to confirm identity. Isolated attempts at decentralization already exist. Cryptocurrency (technically, at least) is an attempt to decentralize finance. The interplanetary file system (IPFS) is an attempt to decentralize data held in individual files.

One likely component of web3 will be a decentralized internet — and the distributed ledger implemented as blockchains is the most likely route. Big tech will not support this evolution.

Immersive
A move towards a more immersive internet experience is already in progress. The improvement on web2 is that users wish to move beyond interacting with the internet to becoming part of the experience. This development can be seen in the evolution of the gaming industry — from text-based adventure games, to video platform games, to 3D games and now virtual reality gaming.

But it is also apparent in business. Covid-19 created a need for remote conferencing. This was already available via telephone conferences; but the rapid rise of videoconference tools such as Zoom demonstrates users’ wish to feel more involved – or integrated with the experience. The next logical step is for videoconferencing to evolve into virtual reality conferencing using the same tools and techniques developed for virtual reality gaming.

Web2 is already evolving towards an immersive internet, and ‘immersive’ is likely to be another component of web3. The current ultimate view of an immersive experience is the metaverse.

Web3
The evolutionary pressures on the internet seem to be focusing on two characteristics: decentralization and immersiveness. This is how we will describe the next internet. Note that neither characteristic is dependent on the other, but there is synergy in their marriage. Metaverses do not need to be decentralized but can become so using distributed ledger technology (DLT). Metaverse and DLT are likely to be the key components of web3. The evolution will not be completed in 2023 (in fact, it has barely begun), but there will be much progress in that direction.

But note also that there are competing pressures. Big tech recognizes the value of the metaverse concept (Facebook has even changed its name to Meta), but big tech will not want decentralized metaverses where they lose ownership of users’ data.

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

The technology waiting game

The excitement with which 2022 greeted the dream of the metaverse dissipated into disillusionment over the course of the year. The technology simply isn’t ready to deliver on the dream; but that dream remains. 

Massimo Paloni, chief operations and innovations officer at Italian luxury brand Bvlgari, explained both the problems and the promise of the web3 metaverse. When you buy a product, he said, especially a luxury product, you go to the store not just for the product, but also for the experience. The experience is ‘storytelling’ by the vendor — and all storytelling changes with advances in technology. But the way that technology is used must always be aligned with the vendor DNA.

“Our mission is to be sure that the use of new technology – web3, blockchain and metaverse – is aligned with our value proposition. That is the key,” he said. Web2 ecommerce fails for the luxury brands. “Ecommerce is a bidimensional experience. It kills the magic of going to the store. All ecommerce is beautifully crafted — but ultimately all the stores are similar.”

The promise of the metaverse is that it will allow vendors, especially luxury vendors, to maintain their own storytelling in engaging with their customers. Better engagement, which isn’t supported by web2, will lead to higher sales. But the problem is the technology is new and evolving, and developers still don’t know what might be available in three- or four-months’ time – nevermind a few years.

“Content is absolutely king here – the technology will undoubtedly become better and better, but this is not enough in itself,” says Lars Seier Christensen, chairman of Concordium and founder of Saxo Bank. “Users need to achieve real benefits to embrace it – across areas like entertainment, better access to goods and services, valid commercial models and otherwise unachievable experiences.” What we’ve seen so far over the last year or two has failed to deliver this, and quickly became boring and irrelevant.

“2022 wasn’t a good year for the metaverse,” adds Orlando Crowcroft, tech and innovation editor at LinkedIn. “Two of the most prominent metaverse platforms – Decentraland and Sandbox, with valuations of over $1bn each – were revealed to have under 1,000 daily active users. And Meta’s Horizon World was so unpopular that even staff had to be pressured to use it.”

But he added, “Metaverse enthusiasts should take heart. In 2023, we will see the metaverse take off – in the professional world. VR and AR are being used right now to train pilots and surgeons. Expect employers, universities, and training programs to jump into the metaverse in even bigger ways in the new year.”

Crime in the metaverse

Just as the metaverse is a new concept, crime in the metaverse is an unknown quantity. “Virtual cities and online worlds are new attack surfaces to fuel cybercrime,” warns Aamir Lakhani, cybersecurity researcher and practitioner for Fortinet’s FortiGuard Labs. He is concerned that a metaverse will be an open door to new cybercrime in uncharted territories.

“For example, an individual’s avatar is essentially a gateway to PII, making them prime targets for attackers. Because individuals can purchase goods and services in virtual cities, digital wallets, crypto exchanges, NFTs, and any currencies used to transact, offer threat actors yet another emerging attack surface,” he said.

He also worries about biometric hacking. The AR- and VR-driven components of virtual worlds may make it easier for a cybercriminal to steal fingerprint mapping, facial recognition data, or retina scans. Finally, he added, “The applications, protocols, and transactions within these environments are all also possible targets for adversaries.”

Kaarel Kotkas, founder and CEO at Veriff, sees trust in identity as the biggest problem. “If the metaverse is to be successful,” he said, “there needs to be a guarantee that users are who they say they are.”

“If the Metaverse is to live up to even a portion of its hype,” adds Padraic O’Reilly, co-founder and CPO at CyberSaint, “security will have to be baked in from the start. That is, it should be part of the conception. There should be a kind of cyber charter from the largest participants that stresses transparency, and laws for individuals. Cyber is everyone’s responsibility in the future.”

He also believes that regulation will be required over user identity. “To ensure the security of experiences and transactions in the metaverse, zero trust architecture and more legal protections (blockchain is too authority averse) are required. Without a central authority backing the purported ironclad data integrity of the blockchain, it will remain vulnerable.”

It is worth noting, however, that a ‘central authority’ is at least conceptually contrary to the ideal of decentralization.

Patrick Harr, CEO at SlashNext, continues this theme of identity. “Artificial intelligence solutions will be needed to validate the legitimacy of identities and controls,” he says. “This new type of digital interface will present unforeseen security risks when avatars impersonate other people and trick users into giving away personal data.”

Web3 Cybersecurity

But of course, AI will be used for attack as well as defense. Deepfaked avatars supported by AI chatbots will be used. “We can expect to see more of these holographic-type phishing attacks and fraud scams as the metaverse develops,” he continued. “In turn, folks will have to fight AI with stronger AI because we can no longer rely solely on the naked eye or human intuition to solve these complex security problems.”

Ultimately, security in the metaverse and web3 in general is both a threat and an opportunity. Traditionally, security is largely reactive – we fix things after they have been exploited. But “With web3 we have the opportunity to change the game in terms of security,” suggests Rodrigo Jorge, CISO at Vtex, “and construct something that has security by design, and is planned from user experience to the system architecture and infrastructure.” 

He believes security professionals and companies have the opportunity to adopt security in this early stage so that when web3 becomes popular, it will be safe. 

The progress of decentralization via blockchain

“Web3 reflects an architectural shift decentralizing management of platforms. As platforms decentralize, the organizations that manage them will have to find ways to federate replacement controls for those they had centrally deployed,” says Archie Agarwal, founder and CEO at ThreatModeler. “When organizations design such tectonic shifts in their architecture (like the aggressive decentralization of web3), it’s incumbent on them to model the threats and adjust their security controls that such a shift will expose.”

Value from cryptocurrency technology

While cryptocurrency (as opposed to cryptocurrency technology) is peripheral to a discussion on web3, it cannot be dismissed entirely. Bitcoin demonstrated the security available in the blockchain implementation of the distributed ledger. But it is blockchain rather than cryptocurrency that is important to the development of web3.

Merav Ozair, a fintech professor at Rutgers Business School, commented on Nasdaq (December 20, 2022), “There is no doubt that the benefits of blockchain technology and web3 are immense. Jamie Dimon, CEO of JPMorgan, who has bashed bitcoin, has always been one of the great supporters of blockchain technology. JPMorgan is one of the leading companies in web3 and has made significant investments in blockchain technology, web3 and the metaverse since 2015.”

She also notes that the value of decentralization (in this case, cryptocurrency) has been demonstrated during the Ukraine/Russia conflict. The Ukrainian government has asked for donations in cryptocurrency, which has been adopted as a primary currency in the country. 

“These instances underscore the promise of blockchain when Bitcoin, the first blockchain, was launched in January 2009, that a decentralized, peer-to-peer system, accessed by everyone, with no need for intermediaries, can empower everyday people: a system that is for the people, by the people,” she explained. This is the primary advantage of decentralization.

A security weakness in the unfolding web3 will come from its ‘newness’. “Looking forward, attackers are again adjusting their tactics to target individuals in the new web3 world,” comments Hank Schless, director of global campaigns at Lookout. “Since web3 is still a new concept for most people, attackers can rely on the unfamiliar environment to increase the likelihood of success. This is a common tactic, as targeted individuals may not know exactly what red flags to look for in the same way they do with a suspicious social media message.”

Christian Seifert, research at Forta, takes this further. “The current state of the De-Fi market [currently the primary implementation of decentralized blockchain], especially with mounting losses due to hacks and rug pulls, has reduced some of the trust that investors previously had in this industry,” he said.

Security issues 

“I believe the problem will continue to persist unless better security measures are implemented across the board. In this regard, we need an overhaul of the security strategies prevalent today to provide better end user privacy (via the use of, say, wallets) and improved protocol safety.”

In particular, he recommends “routine audits, offering bug bounties, maximizing monitoring and incident response – potentially via the use of future-ready technologies such as artificial intelligence and machine learning – and offering clients cyber insurance.”

Financial institutions 

Since the blockchain was originally developed for use in the finance sector, it should be no surprise that the finance industry is one of the more interested sectors. “There is a major trend of blockchain adoption in large financial institutions,” says Nick Landers, director of research at NetSPI, specifically citing Broadridge, Citi and BNY Mellon. 

“The primary focus,” he continued, “is custodial offerings of digital assets, and private chains to maintain and execute trading contracts. Despite what popular culture would indicate, the business use cases for blockchain technology will likely deviate starkly from popularized tokens and NFTs.” Instead, he believes, industries will prioritize private chains to accelerate business logic, digital asset ownership on behalf of customers, and institutional investment in proof-of-stake chains.

By the end of next year, he expects that every major financial institution will have announced adoption of blockchain technology, if it hasn’t already. “While Ethereum, EVM, and Solidity-based smart contracts have received a huge portion of the security research, nuanced technologies like Hyperledger Fabric have received much less. In addition, the supported features in these business-focused private chain technologies differ significantly from their public counterparts.” 

It is worth noting that private blockchains are not decentralized blockchains – which begs the question, are they really web3?

Either way, this ultimately means more attack surface, more potential configuration mistakes, and more required training for development teams. “If you thought that blockchain is ‘secure by default’,” added Landers, “think again. Just like cloud platform adoption, we’ll see the promises of ‘secure by default’ fall away as unique attack paths and vulnerabilities are discovered in the nuances of this technology.”

Blockchain and social media

Dissatisfaction with big tech’s control of social media has led to the exploration of alternative decentralized approaches. Mastodon, as an alternative to Twitter, is one example. It is decentralized but based on federation rather than blockchain. “Instant global communication is too important to belong to one company,” explains the Mastodon website. “Each Mastodon server is a completely independent entity, able to interoperate with others to form one global social network.”

But a blockchain – more specifically a multichain – social media alternative may appear in 2023. On December 20, 2022, Beepo officially closed the beta version of its decentralized app, and expects to launch in early 2023.

At the beginning of December 2022, Concordium announced an agreement with Beepo to incorporate its native token, CCD, as a means of payment on the platform. “Beepo, a blockchain-based platform powered by E2EE and an AI/ML algorithm with a focus on privacy and security,” explained Concordium, “is protected by end-to-end encryption technology and autonomous moderation, ensuring a totally secure environment for user interactions.”

The Beepo App offers a DApp (decentralized app) browser, tools for independent contractors, features for content creators, and a multichain blockchain infrastructure that lets users engage with various tokens and multiple networks. It is a response to growing user concern over the controlling and often abusive concentration of personal data within web2 big tech firms.

Web3 progress in 2023 

The blockchain part of web3 (disregarding the question of whether private blockchains can even be considered part of web3) will probably develop faster than the metaverse during 2023. William Tyson, associate analyst in the thematic intelligence team at GlobalData, foresees a metaverse winter in 2023. He believes the immaturity of enabling technologies like virtual reality (VR) and artificial intelligence (AI), as well as cooling consumer interest, will prevent the metaverse from being adopted widely in the next year.

He adds, “The absence of a single vision for the metaverse means that its future is malleable and uncertain. Its extraordinary long-term potential is widely recognized, which is why big tech is continuing to funnel billions into its creation— despite the absence of short-term return on investment. The concept will experience a cold period, but this provides an opportunity for underlying technologies to develop.”

Meanwhile, the blockchain part of the equation will pick up steam in 2023. “We don’t have a defining trend for web3 in 2023, but that what we do have instead is an undercurrent of heads-down building and experimentation being done both by developers as well as traditional brands, setting the stage for a really exciting 2024,” says Dan Abelon, partner at Two Sigma Ventures. 

“On the developer side, one area to watch is messaging: enabling decentralized services to communicate directly with end users,” he adds. “On the brand side, I’m excited to see more experiments like those by Reddit and Instagram in recent weeks, that will help bring web3 into the mainstream.”

The metaverse and blockchains are not interdependent – each can exist without the other. However, a decentralized metaverse will require blockchains. Consider a metaverse shopping mall. Like the physical mall, it will comprise multiple businesses operating effectively in one place. In the physical world, shoppers walk from one shop into another. In a web2 shopping mall, they would need a different URL and to log on and present identity credentials to each store.

In a decentralized metaverse, with identity held in a trusted blockchain, identity verification could simply be the presentation of an NFT-like token. This would confirm the user’s identity without requiring personal details to be given to every business in the metaverse – allowing the user to travel freely between the organizations of the mall metaverse.

Within each ‘shop’, three-dimensional images of goods can be investigated. Shopping baskets could be maintained by the collection of NFTs associated with the goods, and could be instantly purchased via a cryptocurrency or NFT from the user’s wallet.

The security issues are primarily fraud via user impersonation, although the user identity is protected by blockchain. One thing that is certain, however, is that as this new cyber world evolves, criminals will be looking for new ways to attack it.

Web3 will happen. What it will look like is not yet known. Blockchain technology is expanding beyond just cryptocurrency, and the use of non-investment NFTs is growing. 

The attraction of a metaverse is undeniable – but we’re going through a phase of disillusionment right now. This is perhaps typified in the disappointment of Meta’s legless cartoon avatar torsos in its Horizon Worlds metaverse.

But we should remember that all of this is new technology with kinks. The AR and VR headsets are still developing; the software development is still new. The potential for the metaverse is too great to ignore. Its synergy with decentralization makes it especially attractive.

It won’t materialize for many years – but development of web3 will continue through 2023 and beyond. The immersive metaverse rather than blockchain will be the defining technology.

Related: Securing the Metaverse and Web3

Related: Hackers Steal Over $600M in Major Crypto Heist

Related: Protecting Cryptocurrencies and NFTs – What’s Old is New

Related: How Blockchain Will Solve Some of IoT’s Biggest Security Problems

https://www.securityweek.com/cyber-insights-2023-the-coming-of-web3/




European Police Arrest 42 After Cracking Covert App

European police arrested 42 suspects and seized guns, drugs and millions in cash, after cracking another encrypted online messaging service used by criminals, Dutch law enforcement said Friday.

Police launched raids on 79 premises in Belgium, Germany and the Netherlands following an investigation that started back in September 2020 and led to the shutting down of the covert Exclu Messenger service.

Exclu is just the latest encrypted online chat service to be unlocked by law enforcement. In 2021 investigators broke into Sky ECC — another “secure” app used by criminal gangs.

After police and prosecutors got into the Exclu secret communications system, they were able to read the messages passed between criminals for five months before the raids, said Dutch police.

“Those arrested include users of the app, as well as its owners and controllers,” their statement added.

Police in France, Italy and Sweden, as well as Europol and Eurojust, its justice agency twin, also took part in the investigation.

The police raids uncovered at least two drugs labs, one cocaine-processing facility, several kilogrammes of drugs, four million euros ($4.3 million) in cash, luxury goods and guns, Dutch police said.

Used by around 3,000 people, including around 750 Dutch speakers, Exclu was installed on smartphones with a licence to operate costing 800 euros for six months.

“Exclu made it possible to exchange messages, photos, notes, voice memos, chat conversations and videos with other users,” Dutch police said.

The online service “was praised by the owners and manager for its high level of security”, police added.

The earlier Sky ECC probe gave investigators a vast trove of messages sent between secretive drug smuggling gangs.

Breaking that encrypted system allowed police to intercept drug shipments and make a large number of arrests.

Related:Hundreds Arrested in ‘Staggering’ FBI Encrypted Phone Sting

Related: 150 People Arrested in US-Europe Darknet Drug Probe

https://www.securityweek.com/european-police-arrest-42-after-cracking-covert-app/




Florida Hospital Cancels Procedures, Diverts Patients Following Cyberattack

Tallahassee Memorial HealthCare (TMH) has canceled procedures and is diverting some patients following a cyberattack that forced it to take some IT systems offline.

Founded in 1948, the not-for-profit community healthcare system provides acute and other types of healthcare services to a 21-county area in North Florida, South Georgia and South Alabama.

On February 3, TMH announced that, late Thursday night, it fell victim to a cyberattack that forced it to disconnect some of its IT systems and start operating under downtime protocols.

On February 5, the healthcare services provider announced that the situation had not been remedied, with all non-emergency surgical and outpatient procedures initially scheduled for February 6 being canceled and rescheduled.

TMH announced that it implemented incident response protocols immediately after discovering the incident, and that backup and downtime protocols it has in place allow it to continue to provide care to its patients.

“We are still operating under downtime procedures, which means we are using paper documentation. We apologize for any delays this may create. We practice for situations like this, and we are prepared to provide safe, high-quality care to our patients during computer system downtimes,” the healthcare provider said on Sunday.

TMH also said that an investigation into the incident was ongoing, without providing details on the type of cyberattack it experienced or on whether any personal or health information was compromised during the attack.

However, the fact that the organization was forced to disconnect some of its IT systems to contain the incident suggests that ransomware might have been involved.

SecurityWeek has emailed TMH for additional information on the incident and will update this article as soon as a reply arrives.

Related: Ransomware Hit 200 US Gov, Education and Healthcare Organizations in 2022

Related: Data Breach at Louisiana Healthcare Provider Impacts 270,000 Patients

Related: Healthcare Organizations Warned of Royal Ransomware Attacks

https://www.securityweek.com/florida-hospital-cancels-procedures-diverts-patients-following-cyberattack/