International Arrests Over ‘Criminal’ Crypto Exchange

The owner of China-based cryptocurrency exchange Bitzlato was arrested in Miami on Wednesday, along with five associates in Europe, during an international operation against “darknet” markets.

Anatoly Legkodymov, 40, a Russian living in Shenzhen, China, appeared in handcuffs and leg shackles in a Miami courtroom on money laundering charges, and was denied bail by a judge who deemed him a flight risk.

He was detained for his role in allegedly transmitting a total of $700 million in illicit funds, the US Department of Justice charged, with officials saying that criminals used the exchange as a haven for narcotics trading and selling stolen financial information.

Five other men, mainly of Russian and Ukrainian nationalities, were arrested in Spain, Portugal and Cyprus, as part of a complex police swoop led by French authorities, officials in Paris said.

According to US court documents, Legkodymov is the founder and majority shareholder of Hong Kong-registered Bitzlato, which marketed itself as requiring minimal identification from users.

Bitzlato’s largest partner for transactions was Hydra, an anonymous, illicit online marketplace on the “darknet” that was shut down by US and German authorities last year.

The secret “darknet” includes websites that can be accessed only with specific software or authorizations, ensuring anonymity for users.

As the arrests were announced, authorities dismantled Bitzlato’s digital infrastructure, including its servers in France, and seized cryptocurrency worth $17 million.

Paris prosecutor Laure Beccuau said Bitzlato enabled cryptocurrencies including bitcoin and ethereum to be converted into Russian rubles.

‘Cryptocrime ecosystem’

US Deputy Attorney General Lisa Monaco welcomed “a significant blow to the cryptocrime ecosystem.”

“Overnight, the Department worked with key partners here and abroad to disrupt Bitzlato, the China-based money laundering engine that fueled a high-tech axis of cryptocrime, and to arrest its founder,” she said.

Monaco said that “today’s actions send the clear message: whether you break our laws from China or Europe — or abuse our financial system from a tropical island — you can expect to answer for your crimes.”

When it was closed in April 2022, the Hydra marketplace had around 17 million customer accounts and more than 19,000 vendor accounts, according to German federal police.

Such networks have faced increased pressure from international law enforcement after a boom in usage during the coronavirus pandemic.

“As alleged, Bitzlato sold itself to criminals as a no-questions-asked cryptocurrency exchange, and reaped hundreds of millions of dollars’ worth of deposits as a result,” said Breon Peace, Attorney for the Eastern District of New York.

“The defendant is now paying the price for the malign role that his company played in the cryptocurrency ecosystem.

“Bitzlato allegedly became a haven for criminal proceeds and funds intended for use in criminal activity.”

In May 2019, Legkodymov allegedly told a colleague on Bitzlato’s internal chat system that users were “known to be crooks” deploying others’ identity documents to register accounts.

In the Miami courtroom, Federal Judge Jacqueline Becerra told Legkodymov, dressed in a gray polo shirt and blue shorts, that he faces a possible five-year prison term. Legkodymov will return to court Friday for a hearing on his transfer to New York, where the charges were brought.

US officials are cracking down on the cryptocurrency sector after the uproar caused by the recent bankruptcy of FTX and Alameda Research.

FTX, once the world’s highest profile crypto exchange, collapsed spectacularly in November leaving nine million customers in the lurch and seeing cofounder Sam Bankman-Fried indicted for fraud by US prosecutors.

Related: Canadian Teen Arrested Over Theft of $36 Million in Cryptocurrency

Related: Justice Dept. Announces $3.6B Crypto Seizure, 2 Arrests

view counter

© AFP 2022

Previous Columns by AFP:
Tags:

https://www.securityweek.com/international-arrests-over-criminal-crypto-exchange




Gli attacchi informatici si confermano il rischio maggiore per le aziende a livello mondiale (specie per le tlc). Il report

Per il secondo anno consecutivo, i Rischi informatici derivanti da attacchi informatici e l’Interruzione di attività rappresentano i principali timori delle aziende (entrambi con il 34% delle risposte).

Lo rivela la nuova indagine di Allianz Global Corporate & Specialty (AGCS), il sondaggio annuale sui principali rischi percepiti dalle aziende a livello globale secondo gli oltre 2.700 intervistati, provenienti da 94 paesi, tra cui amministratori delegati, risk manager, broker ed esperti assicurativi.

Secondo il report, la frequenza degli attacchi ransomware rimarrà elevata anche nel 2023, e il costo medio di una violazione dei dati è ai massimi storici con 4,35 milioni di dollari (come previsto dal Cost of Data Breach report di IBM) che si prevede supererà i 5 milioni di dollari nel 2023. Il conflitto in Ucraina e le più ampie tensioni geopolitiche stanno aumentando il rischio di un attacco informatico su larga scala da parte di soggetti supportati dagli Stati. A ciò si aggiunge una crescente carenza di professionisti di cyber security, che genera problemi quando si tratta di migliorare la sicurezza.

Per le aziende di molti Paesi, il 2023 sarà probabilmente un altro anno problematico per l’Interruzione di attività (BI), perché molti modelli di business sono sensibili agli shock e ai cambiamenti improvvisi, che a loro volta incidono sui profitti e sui ricavi. Gli attacchi informatici sono la causa di BI che le aziende temono di più (45% delle risposte, al secondo posto la crisi energetica (35%), seguita dalle catastrofi naturali (31%).

Paura per gli attacchi informatici: l’Italia come il resto del mondo

A livello globale i rischi informatici rimangono in testa alla classifica dei rischi per le aziende di tutto il mondo tra cui Canada, Francia, Giappone, India e Regno Unito. È questo il rischio che preoccupa maggiormente le piccole e medie  imprese (con un fatturato annuo inferiore ai 250 milioni di dollari).

E nel nostro Paese? In Italia i rischi informatici rappresentano i principali timori delle aziende, seguiti da Interruzione di attività e Crisi energetica. Secondo il rapporto, per il secondo anno consecutivo, nel nostro Paese i rischi informatici derivanti da attacchi malware e ransomware, violazione di dati e guasti IT, rappresentano un rischio per il 47% delle aziende italiane.

10 rischi in Italia.jpg

La classifica per settori: telecomunicazioni

Rinnovabili

Energia utilites

Media

Settore Pubblico e sanità

Per approfondire

https://www.key4biz.it/gli-attacchi-informatici-si-confermano-il-rischio-maggiore-per-le-aziende-a-livello-mondiale-specie-per-le-tlc-il-report/431328/




Free Decryptors Released for BianLian, MegaCortex Ransomware

Avast and Bitdefender have released decryptors to help victims of BianLian and MegaCortex ransomware recover their data for free.

Written in Golang, BianLian emerged in August 2022 and has been used in targeted attacks against entertainment, healthcare, media, and manufacturing organizations.

Once it has been executed on a victim’s machine, the malware identifies all available drives to find files and encrypt them.

BianLian targets a total of 1,013 file extensions and features a particular encryption routine: it does not encrypt data at the beginning of a file, nor data at its end.

Known for its fast encryption capabilities, the ransomware appends the “.bianlian” extension to the affected files and drops a ransom note named “Look at this instruction.txt” in each folder on the machine. Once the encryption process has been completed, the malware deletes itself.

Avast warns that its decryption tool only works with files encrypted with a known variant of BianLian and that victims of more recent versions of the ransomware might need to provide a malware binary to be able to recover their data for free.

The BianLian decryptor (direct download) is available on Avast’s website. The cybersecurity firm also provides detailed instructions on how the tool should be used.

The MegaCortex ransomware initially emerged in January 2019, but did not rise to fame until May that year, when it was used in a global attack campaign.

The malware was used by the same cybercriminals who also distributed the Dharma and LockerGoga ransomware, and who are believed to have infected roughly 1,800 victims, mostly companies.

In 2020, MegaCortex was mentioned in a FireEye report as being one of the six ransomware families to use a ‘process kill list’ targeting over 1,000 processes, including industrial software.

In October 2021, Europol and Norwegian Police announced the arrest of 12 individuals believed to have been part of the cybercrime ring.

Earlier this month, Bitdefender announced the availability of a free decryption tool for the MegaCortex victims, built in cooperation with the NoMoreRansom Project, Europol, and Swiss law enforcement. The decryptor is available on Bitdefender’s website (direct download) and the company also provides a step-by-step guide to using the tool.

Related: Free Decryptor Available for LockerGoga Ransomware Victims

Related: Free Decryptors Released for AstraLocker Ransomware

Related: Can Encryption Key Intercepts Solve The Ransomware Epidemic?

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/free-decryptors-released-bianlian-megacortex-ransomware




Cybersecurity e infrastrutture critiche, da oggi entrano in vigore le direttive NIS 2 e CER

Al via da oggi due direttive fondamentali per innalzare le difese informatiche a livello europeo. Stiamo parlando della direttiva sulle misure per un elevato livello comune di cybersicurezza in tutta l’Unione (la cosiddetta Nis 2) e la direttiva sulla resilienza delle entità critiche (direttiva Cer), due direttive pubblicate in Gazzetta Ufficiale lo scorso 27 dicembre 2022.

La NIS 2

La NIS 2 sostituisce le norme sulla sicurezza delle reti e dei sistemi informativi, la prima legislazione a livello europeo sulla sicurezza informatica. “La direttiva Nis 2 garantirà un’Europa più sicura e più forte ampliando in modo significativo i settori e le tipologie di entità critiche che rientrano nel suo campo di applicazione. Tra questi figurano i fornitori di reti e servizi pubblici di comunicazione elettronica, i servizi di centri dati, la gestione delle acque reflue e dei rifiuti, la fabbricazione di prodotti critici, i servizi postali e di corriere e gli enti della pubblica amministrazione, nonché, più in generale, il settore sanitario. Inoltre, rafforzerà i requisiti di gestione del rischio di cybersicurezza che le aziende sono tenute a rispettare, nonché snellirà gli obblighi di segnalazione degli incidenti con disposizioni più precise in materia di segnalazione, contenuto e tempistica”, spiega Bruxelles in una nota.

NIS 2: in dettaglio

Nel dettaglio, con la NIS 2 si istituisce formalmente la rete europea dell’organizzazione di collegamento per le crisi informatiche, Eu–CyClone, che sosterrà la gestione coordinata degli incidenti di sicurezza informatica su larga scala. Mentre ai sensi della vecchia direttiva Nis gli Stati membri erano responsabili di determinare quali entità avrebbero soddisfatto i criteri per qualificarsi come operatori di servizi essenziali, il nuovo testo introduce una regola di limite di dimensione. Ciò significa che rientreranno nel suo campo di applicazione tutte le medie e grandi entità operanti nei settori o che forniscono servizi contemplati dalla direttiva.

La norma include disposizioni aggiuntive per garantire la proporzionalità, un livello più elevato di gestione del rischio e criteri di criticità per la determinazione degli enti coperti. Il testo chiarisce inoltre che la direttiva non si applicherà agli enti che svolgono attività in settori quali la difesa o la sicurezza nazionale, la pubblica sicurezza, le forze dell’ordine e la magistratura. Sono esclusi dal campo di applicazione anche i Parlamenti e le banche centrali. Poiché anche le pubbliche amministrazioni sono spesso oggetto di attacchi informatici, Nis 2 si applicherà agli enti della pubblica amministrazione a livello centrale e regionale (gli Stati membri possono decidere però che si applichi anche a loro).

La nuova Cer sostituisce la direttiva europea sulle infrastrutture critiche del 2008

“Le nuove norme rafforzeranno la resilienza delle infrastrutture critiche a una serie di minacce, tra cui i rischi naturali, gli attacchi terroristici, le minacce interne o il sabotaggio. Saranno coperti 11 settori: energia, trasporti, banche, infrastrutture dei mercati finanziari, sanità, acqua potabile, acque reflue, infrastrutture digitali, pubblica amministrazione, spazio e cibo. Gli Stati membri – si legge – dovranno adottare una strategia nazionale ed effettuare valutazioni periodiche del rischio per identificare le entità considerate critiche o vitali per la società e l’economia”.

I Paesi Ue hanno 21 mesi di tempo per recepire entrambe le direttive nel diritto nazionale. Durante questo periodo, gli Stati membri dovranno adottare e pubblicare le misure necessarie per conformarsi ad esse entro e non oltre il 17 ottobre 2024.

https://www.key4biz.it/cybersecurity-e-infrastrutture-critiche-da-oggi-entrano-in-vigore-le-direttive-nis-2-e-cer/431222/




Website of Canadian Liquor Distributor LCBO Infected With Web Skimmer

Canadian liquor distributor Liquor Control Board of Ontario (LCBO) has announced that a web skimmer injected into its online store was used to steal users’ personal data.

One of the largest liquor sellers in Canada, LCBO retails and distributes alcoholic beverages throughout the Ontario province, operating over 670 stores and employing more than 8,000 people.

Last week, the company abruptly took offline its online store and mobile application, only to later explain that it fell victim to a cyberattack in which a web skimmer was injected into LCBO.com.

“At this time, we can confirm that an unauthorized party embedded malicious code into our website that was designed to obtain customer information during the checkout process,” the retailer said.

According to LCBO, all individuals who provided their personal information on the online store’s check-out pages and made payments between January 5 and 10, 2023, are impacted.

The compromised personal information, the company says, includes names, addresses, email addresses, LCBO.com account passwords, Aeroplan numbers, and credit card information.

“This incident did not affect any orders placed through our mobile app or vintagesshoponline.com,” the company said.

The company did not share information on the number of impacted customers, but said that it disabled customer access to both the online store and mobile app as a precautionary measure, and that it also forced a password reset for all user accounts.

“LCBO.com and our mobile app have been restored and are fully operational. We have also reset all LCBO.com account passwords. Registered customers will be prompted to reset their password on login,” the company said.

Web skimmer attacks, also referred to as Magecart attacks, are typically the result of a misconfiguration or unpatched vulnerabilities that allow threat actors to inject information stealer malware into a website and harvest the information of unsuspecting users.

Magecart attacks have been around for years, with multiple groups operating under the umbrella and hundreds of online stores compromised to date. In 2019, a free service called URLscan.io was made available to help customers and retailers alike check for the presence of web skimmers.

Related: Hundreds of eCommerce Domains Infected With Google Tag Manager-Based Skimmers

Related: Target Open Sources Web Skimmer Detection Tool

Related: Web Skimmer Injected Into Hundreds of Magento-Powered Stores

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/website-canadian-liquor-distributor-lcbo-infected-web-skimmer




CircleCI Hacked via Malware on Employee Laptop

Software development service CircleCI has revealed that a recently disclosed data breach was the result of information stealer malware being deployed on an engineer’s laptop.

The incident was initially disclosed on January 4, when CircleCI urged customers to rotate their secret keys.

In an updated incident report on Friday, the company said that it was initially alerted of suspicious activity on December 29, 2022, and that on December 31 it started rotating all GitHub OAuth tokens on behalf of its customers.

On January 4, 2023, CircleCI learned that malware deployed on an engineer’s laptop on December 16 was used to steal a 2FA-backed SSO session, which allowed the attackers to access the company’s internal systems.

“Our investigation indicates that the malware was able to execute session cookie theft, enabling them to impersonate the targeted employee in a remote location and then escalate access to a subset of our production systems,” the company said.

The compromised employee account was used to generate production access tokens, which allowed the hackers to “access and exfiltrate data from a subset of databases and stores, including customer environment variables, tokens, and keys”.

The attackers, CircleCI said, performed reconnaissance on December 19 and exfiltrated the sensitive information on December 22.

“Though all the data exfiltrated was encrypted at rest, the third party extracted encryption keys from a running process, enabling them to potentially access the encrypted data,” the company said.

To contain the breach, the company shut down all access for the compromised employee account, shut down production access to nearly all employees, rotated all potentially exposed production hosts, revoked all project API tokens, revoked all personal API tokens created prior to January 5, rotated all Bitbucket and GitHub OAuth tokens, and started notifying customers of the incident.

“We have taken many steps since becoming aware of this attack, both to close the attack vector and add additional layers of security,” CircleCI said.

According to the company, both “both the attack vector and the potential of a lingering corrupted host” were eliminated through the rotation of all production hosts.

Due to the sensitive nature of the exfiltrated information, all CircleCI customers should rotate SSH keys, OAuth tokens, project API tokens, and other secrets, and should investigate any suspicious activity observed after December 16.

“Because this incident involved the exfiltration of keys and tokens for third-party systems, there is no way for us to know if your secrets were used for unauthorized access to those third-party systems,” the company said. “At the time of publishing, fewer than 5 customers have informed us of unauthorized access to third-party systems as a result of this incident.”

Cloud monitoring service Datadog, one of the impacted CircleCI customers, announced late last week that it had identified an old RPM GNU Privacy Guard (GPG) private signing key that was compromised in the incident, along with its passphrase.

“As of January 12th, 2023, Datadog has no indication that the key was actually leaked or misused, but we are still taking the following actions out of an abundance of caution,” Datadog said.

Related: LastPass Says Password Vault Data Stolen in Data Breach

Related: Toyota Discloses Data Breach Impacting Source Code, Customer Email Addresses

Related: Microsoft Confirms Data Breach, But Claims Numbers Are Exaggerated

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/circleci-hacked-malware-employee-laptop




Most Cacti Installations Unpatched Against Exploited Vulnerability

Most internet-exposed Cacti installations have not been patched against a critical-severity command injection vulnerability that is being exploited in attacks.

An open-source web-based network monitoring and graphing tool that offers an operational monitoring and fault management framework, Cacti is a front-end application for the data logging utility RRDtool.

In early December 2022, the tool’s maintainers announced patches for CVE-2022-46169, a critical-severity (CVSS score 9.8) command injection flaw that could allow unauthenticated attackers to execute code on the server running Cacti, if a specific data source was used.

The security defect consists of an authentication bypass, where an unauthenticated attacker can access a specific file, and an improper sanitization of an argument during the processing of a specific HTTP query for a polling ‘action’ defined in the database.

Users can define actions for the monitoring of hosts (pollers) and the issue impacts a poller type that executes a script. An attacker able to bypass authentication can supply the specific argument that is passed along to the execution call unsanitized, achieving command injection.

Cacti versions 1.2.23 and 1.3.0, released on December 5, include patches for this vulnerability.

A few days after SonarSource published a technical analysis of CVE-2022-46169 on January 3, The Shadowserver Foundation warned that it had logged the first exploitation attempts targeting the security defect.

“Using Cacti? We started to pick up exploitation attempts for Cacti unauthenticated remote command injection CVE-2022-46169 including subsequent malware download. These started Jan 3rd. Make sure to patch & not expose your Cacti instance to the Internet,” Shadowserver said.

This week, attack surface management firm Censys revealed that, out of 6,400 internet-accessible Cacti hosts that it has identified, only 26 were running a patched version of the tool. Most of these servers are in Brazil, with Indonesia and the US rounding up the top three.

With exploitation of this vulnerability underway, organizations are advised to update Cacti to a patched version as soon as possible.

Related: Google Documents IE Browser Zero-Day Exploited by North Korean Hackers

Related: Fortinet Ships Emergency Patch for Already-Exploited VPN Flaw

Related: Omron PLC Vulnerability Exploited by Sophisticated ICS Malware

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/most-cacti-installations-unpatched-against-exploited-vulnerability




Pro-Russian Group DDoS-ing Governments, Critical Infrastructure in Ukraine, NATO Countries

A Pro-Russian cybercrime group named NoName057(16) is actively launching distributed denial-of-service (DDoS) attacks against organizations in Ukraine and NATO countries.

Also known as NoName05716, 05716nnm or Nnm05716, the threat actor has been supporting Russia’s invasion of Ukraine since March 2022, launching disruptive attacks against government and critical infrastructure organizations.

To date, the group has launched DDoS attacks against government, military, telecommunications, and transportation organizations, as well as media agencies, suppliers, and financial institutions in Ukraine, Czech Republic, Denmark, Estonia, Lithuania, Norway, and Poland.

According to cybersecurity firm SentinelOne, the group focused on Ukrainian news websites at first, but later shifted attention to NATO-associated targets, aiming to silence what it deems to be anti-Russian.

NoName057(16) uses a Telegram channel to claim responsibility for disruptions, justify its actions, make threats, and mock targets. The group, SentinelOne says, “values the recognition their attacks achieve through being referenced online”.

The threat actor was also seen abusing GitHub to host tools advertised on their Telegram channel, including the DDoS tool DDOSIA, a multi-threaded application that has both Python and Golang implementations.

GitHub promptly removed the NoName057(16)-associated accounts and repositories after being informed about the nefarious activity.

Some of the most recent incidents attributed to the group include the targeting of the Polish government in December 2022, attacks on Lithuanian organizations (mainly cargo and shipping firms) in January 2023, and hits on Danish financial institutions.

This week, the group was seen attempting to disrupt the 2023 Czech presidential elections, taking place January 13-14.

“Specific targets include domains for candidates Pavel Fischer, Marek Hilšer, Jaroslav Bašta, General Petr Pavel, and Danuše Nerudová. Additionally, the Ministry of Foreign Affairs of the Czech Republic website was also targeted at the same time,” SentinelOne notes.

Throughout 2022, the group has been observed employing various tools for carrying out attacks, including Bobik-infected systems, which are ensnared in a botnet. According to SentinelOne, however, NoName057(16) “appears to primarily seek participation voluntarily through their DDOSIA tool”.

“NoName057(16) is yet another hacktivist group to emerge following the war in Ukraine. While not technically sophisticated, they can have an impact on service availability– even when generally short lived. What this group represents is an increased interest in volunteer-fueled attacks, while now adding in payments to its most impactful contributors,” SentinelOne concludes.

Related: Russian APT Gamaredon Changes Tactics in Attacks Targeting Ukraine

Related: Ukraine’s Delta Military Intelligence Program Targeted by Hackers

Related: New ‘Prestige’ Ransomware Targets Transportation Industry in Ukraine, Poland

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/pro-russian-group-ddos-ing-governments-critical-infrastructure-ukraine-nato-countries




The Guardian Confirms Personal Information Compromised in Ransomware Attack

British news organization The Guardian has confirmed that personal information was compromised in a ransomware attack in December 2022.

The company fell victim to the attack just days before Christmas, when it instructed staff to work from home, announcing network disruptions that mostly impacted the print newspaper.

Right from the start, the Guardian said it suspected ransomware to have been involved in the incident, and this week the company confirmed that this was indeed the case.

In an email to staff on Wednesday, The Guardian Media Group’s chief executive and the Guardian’s editor-in-chief said that the sophisticated cyberattack was likely the result of phishing.

They also announced that the personal information of UK staff members was compromised in the attack, but said that reader data and the information of US and Australia staff was not impacted.

“We have seen no evidence that any data has been exposed online thus far and we continue to monitor this very closely,” the Guardian representatives said.

While the attack forced the Guardian staff to work from home, online publishing has been unaffected, and production of daily newspapers has continued as well.

“We believe this was a criminal ransomware attack, and not the specific targeting of the Guardian as a media organization,” the Guardian said.

The company continues to work on recovery and estimates that critical systems would be restored in the next two weeks. Staff, however, will continue to work from home until at least early February.

“These attacks have become more frequent and sophisticated in the past three years, against organizations of all sizes, and kinds, in all countries,” the Guardian said.

It’s unclear which ransomware group was behind the attack.

Related: Rail Company Wabtec Says Data Stolen in Ransomware Attack

Related: New Zealand Government Hit by Ransomware Attack on IT Provider

Related: Virginia County Confirms Personal Information Stolen in Ransomware Attack

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/guardian-confirms-personal-information-compromised-ransomware-attack




ACN, accordo con la Camera dei Deputati per il rafforzamento delle difese cyber. Baldoni: “Previsti progetti grazie al PNRR”

La Camera dei Deputati e l’Agenzia per la Cybersicurezza Nazionale (ACN) hanno sottoscritto oggi un protocollo d’intesa in materia di sicurezza informatica. L’accordo, spiega l’Agenzia in una nota nota, permetterà di avviare un qualificato confronto a tutela dell’Istituzione e nell’interesse generale del Paese.

“Siamo molto orgogliosi della collaborazione avviata con la Camera dei deputati e di lavorare al rafforzamento delle capacità cyber di questa grande istituzione, nel rispetto delle prerogative costituzionali”, ha dichiarato Roberto Baldoni, Direttore Generale di ACN. “L’Agenzia per la cybersicurezza nazionale è impegnata, sin dalla sua costituzione, ad essere capo maglia di una rete nazionale di scambio informativo tesa a rafforzare, nell’interesse generale del Paese, la capacità di monitoraggio, prevenzione e risposta agli attacchi informatici verso l’Italia e le sue istituzioni. Per questo ci avvaliamo del supporto di realtà d’eccellenza come il nostro CSIRT Italia. Abbiamo previsto, inoltre, diversi progetti destinati ad innalzare le difese cibernetiche della Camera, individuati in maniera congiunta e che prevedono l’utilizzo di fondi nazionali o del PNRR. L’accordo, in linea con la Strategia nazionale di cybersicurezza 2022-2026, contiene anche iniziative di formazione per creare le necessarie competenze specialistiche e assicurare la diffusione di cultura cyber e dei rischi connessi al digitale”.

Soddisfazione dal Presidente Lorenzo Fontana: “Grazie a questa collaborazione, potenziamo le strategie nella gestione e nel contenimento delle minacce cibernetiche attraverso la realizzazione di sinergie, l’aggiornamento e la formazione del personale”.

La collaborazione si inserisce in un contesto globale in cui la minaccia cyber si è fatta sempre più forte e in cui la collaborazione e il confronto sulle strategie di rafforzamento diventano cruciali anche in considerazione del percorso di trasformazione digitale avviato dalla Camera nello svolgimento della sua funzione istituzionale.

In questo scenario, lo scambio di informazioni per il potenziamento dei servizi di gestione e contenimento delle minacce cibernetiche, la realizzazione di sinergie attraverso la definizione di buone pratiche e l’aggiornamento e la formazione del personale rivestono una straordinaria importanza.

https://www.key4biz.it/acn-accordo-con-la-camera-dei-deputati-per-il-rafforzamento-delle-difese-cyber-baldoni-previsti-progetti-grazie-al-pnrr/430543/