What the Hack? July 2022
www.seconcyber.com
Secon
02
Secon approved as a supplier on the Digital Outcomes and Specialists 6 (DOS6) framework. Secon is proud to announce we have been awarded a place on the Crown Commercial Service’s new Digital Outcomes and Specialists 6 (DOS6) framework. Digital Outcomes and Specialists is a “dynamic style framework with the goal of assisting the public sector to purchase, design, build and deliver digital outcomes using an agile approach” (source: Crown Commercial Service). By using the DOS6 framework, public sector organisations can find specialist suppliers who can create bespoke digital projects and services that benefit the public and drive forward the UK government’s digital strategy. Secon’s DOS6 service listing will be available under Lot 1: Digital Outcomes. Rob Finney, Secon’s Commercial Leader, said, “I’m extremely proud that Secon are now able to work with their public sector clients via DOS6. As a key supplier into local government & NHS trusts, this will ensure that we are able to respond more swiftly to our clients requirements, and offer more procurement routes to them in order to better support assisting with keeping them secure.” The DOS6 framework goes live on 10 August 2022. For more information about our inclusion in DOS6 or how we can help design a bespoke security project for your organisation, please fill out the form on the bottom of this page.
Introducing the ‘What the Hack?’ monthly cyber security quiz. Beginning this month, we’re including a quiz in each edition of ‘What the Hack?’ to help you learn more about Secon, our team, and what we think are some of the most interesting facets of cyber security. Be sure to stay tuned for the answers (and our insights about them) in next month’s issue! 1.
2013 saw the release of the first version of our Managed Detection and Response, but what name did it go by when it launched? a. Galileo
2.
Guest question from Realyn Vasquez (pictured above)
c. Gideon
What’s the most common threat vector for cyber crime in 2022? a. Phishing
3.
b. Godfrey
b. Ransomware
c. Denial of service (DoS)
Featured question from the Secon team: According to our Service Management Team Leader Realyn Vasquez, what are the most common security risks our customers face in their environments? We’ll reveal Realyn’s answer to this question in August’s issue of ‘What the Hack?’
What the Hack? - July 2022
03
On-demand webinar - The value of visibility: Why centralised log monitoring is critical for incident response. Security logs provide enormous value – they can tell you who, what, when, where, and why an attempted (or successful) attack occurred and help identify your organisation’s top cyber risks. Additionally, if your organisation is breached, having all your logs available is critical for incident response so you can understand 1) what happened, 2) what you need to do, and 3) how you can avoid a repeat attack in the future. But how can you gain these insights if your logs are siloed in multiple places? In this webinar, Andrew Gogarty, Secon’s Chief Security Evangelist, breaks down just how valuable security logs are. He uses real-life examples to illustrate how centralised log management could have helped organisations reduce risk and conduct thorough post-breach investigations.
Watch this webinar now to learn: •
Why centralised log monitoring is crucial for detecting intrusions
•
Why logs are critical to support a fast response and recovery during a breach
•
How you can use logs to improve mean-time to detect and respond
•
How Secon can help you bring together and correlate the alerts from siloed security tools
Watch now
Secon
04
NFTs: The new playground for cyber criminals. By Jonas Gabriel Rivera, Incident Response Associate. An NFT is a digital asset that’s used to represent real-world items such as art, music, in-game items, and videos. They’re bought and sold online, and they’re usually encoded with the same underlying software as many other cryptos. Despite the fact that they’ve been around since 2014, NFTs are gaining in popularity as a tool to buy and sell digital art. In 2021, the global market for NFTs was valued at USD $41 billion, nearing the whole value of the global fine art market. With the growing popularity of NFTs, many big-name hackers are now shifting their attention to the space to see how they can exploit it, especially because many communities on the platform are slacking or haven’t invested in robust security. Since these platforms and many of their users are new, there are a plethora of exploits and vulnerabilities that hackers can attack. To ensure that they are at least on level with such hackers, the NFT market (and cyber security industry) has a lot of work to do.
NFTs, blockchain attacks, and shifting tactics It’s a similar story with many of the crypto hacks in the news these days: cyber criminals are exploiting flaws in a blockchain’s design to steal millions of dollars, as in the $80 million theft on decentralised finance projects Rari Capital and Fei Protocol and the huge $625 million heist on Ronin, a cryptocurrency network that supports the play-to-earn NFT game Axie Infinity. Hackers were able to steal this massive amount from Ronin because of its status as a sidechain of Ethereum (a prominent blockchain that supports the cryptocurrency Ether). Sidechains are separate blockchain networks that connect to a parent blockchain. Using a sidechain allows transactions to happen quickly and, in this case, ensures that Axie Infinity doesn’t lose any functionality. Unfortunately, it also introduces a lot of security risks. In this case, hackers attacked the bridge between Ethereum and Ronin, a.k.a. how money is passed between the two blockchains. However, on 25 April, a $3 million hack involving nonfungible coins from the popular Bored Ape Yacht Club world exposed a different type of flaw that isn’t specific to blockchain. Scammers hacked the official Instagram account of the NFT collection and uploaded a link to a phony website where users could connect their crypto wallets for what they thought was an NFT launch.
They had unknowingly made themselves vulnerable to theft. When the actual launch took place, users were once again attacked by scammers who uploaded links to fraudulent websites, robbing them of NFTs worth a total of $6.2 million. These occurrences are representative of a growing trend in which social media is being utilised to escalate and carry out crypto and NFT scams. According to Ronghui Gu, Chief Executive Officer of blockchain security firm Certik, these thefts aren’t just happening on Instagram, they’re also happening on Twitter, Facebook, and the messaging platforms Discord and Telegram. Even more attacks have continued to surface in the last month. At the beginning of July there were reports of OpenSea, the world’s largest NFT marketplace, announced it suffered a data breach and warned its 1.5 million users to keep an eye out for subsequent phishing attacks. On 17 July, Premint NFT, another popular platform, divulged that 314 NFTs were stolen from their platform by threat actors who planted a malicious JavaScript code on the site. From the growing number of attacks on NFT platforms, it’s clear that a lot of work must be done to secure these transactions if the NFT market is going to continue to grow.
Who’s behind these attacks? Cyber criminals who previously focused their efforts on breaching large organisations are now shifting to
What the Hack? - July 2022
05
exploiting NFT platforms. In the case of the Ronin/ Axie Infinity hack, US officials have linked the heist to North Korean state-backed hacking group Lazarus. Lazarus has previously been suspected of the 2014 Sony pictures hack, 2017’s WannaCry ransomware attack, another $100 million heist on the blockchain Harmony in June, and many other prominent ransomware attacks. As a result of the Ronin hack, the US Treasury Department’s Office of Foreign Assets Control (OFAC) announced sanctions against an Ethereum wallet belonging to Lazarus. This also lead to the first ever sanctions against a virtual currency mixer, Blender.io, which was used to launder the money following the hack. Other large cyber criminal gangs are also responsible for the growing number of NFT hacks, and more groups will surely begin to set their sights on these new, lucrative opportunities. On 18 July, Yuga Labs, the company behind Bored Ape Yacht Club, warned of more attacks via social media accounts from ‘a persistent threat group that targets the NFT community.’ What’s clear is that as the NFT market continues to increase in value, these attacks will become increasingly common.
So how can you protect yourself in the NFT space? Although it has its own constantly evolving threat landscape, if you’re interested in the world of NFTs, you can protect yourself by using many of the same cyber security best practices we always recommend. Overall, our top recommendations for NFT security tips are: •
Do not click any links or attachments from unknown senders and verify links and URLs before accessing them.
•
Enable two-factor or multi-factor authentication.
•
Never disclose your wallet’s recovery phrase to a third party.
•
Set up a temporary wallet and only store a suitable amount for trading and/or purchasing cryptocurrencies and NFTs.
•
DYOR (do your own research) on the NFT you’re buying before spending money on it. Always conduct sufficient research before purchasing.
Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707
www.seconcyber.com