* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, July 4, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    MAY HER SOUL REST IN PEACE 🙏 Veteran entertainment columnist and talent manager Lolit Solis has passed away. She was 78 years old. https://tinyurl.com/6kumarkx | LatestChika.com – Facebook

    Beloved Entertainment Icon Lolit Solis Passes Away at 78 – A Life Remembered with Love and Respect 🙏

    Neil Young Plays Rare Full-Band ‘Ambulance Blues’ With The Chrome Hearts – Yahoo

    Neil Young Stuns Fans with Rare Full-Band Performance of ‘Ambulance Blues’ Alongside The Chrome Hearts

    BTS Announce Their Big Return and Yes, They Already Have Some Major Plans in the Works – Yahoo

    BTS Announce Their Big Return and Yes, They Already Have Some Major Plans in the Works – Yahoo

    Nantucket Dance Festival opens July 8 – The Inquirer and Mirror

    Nantucket Dance Festival Launches with Thrilling Performances Beginning July 8

    A Secret Society, Ritualistic Killings, and a Century-Old Curse Netflix and YRF Entertainment’s ‘Mandala Murders’ Premieres July 25 – About Netflix

    A Secret Society, Ritualistic Killings, and a Century-Old Curse: Dive into the Chilling World of ‘Mandala Murders’ Premiering July 25

    Susquehanna Raises Penn Entertainment Inc. (PENN) Price Target. – Yahoo Finance

    Susquehanna Raises Price Target for Penn Entertainment Inc. (PENN)

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    LG Innotek CEO Moon Hyuksoo: “Our Next-gen Substrate Technology Will Change the Industry Paradigm” – TechPowerUp

    LG Innotek CEO Moon Hyuksoo: “Our Next-Gen Substrate Technology Will Revolutionize the Industry” Revolutionizing the Future: LG Innotek’s CEO Unveils Game-Changing Next-Gen Substrate Technology

    Inspira Technologies Secures Landmark $22.5M Deal: Major Revenue Breakthrough After FDA Clearance – Stock Titan

    Inspira Technologies Secures Landmark $22.5M Deal: Major Revenue Breakthrough After FDA Clearance – Stock Titan

    Meiwu Technology Company Limited and Shenzhen Zhinuo – GlobeNewswire

    Meiwu Technology Company Limited and Shenzhen Zhinuo – GlobeNewswire

    Owls inspire new revolutionary noise reduction technology – KTEN

    Owls inspire new revolutionary noise reduction technology – KTEN

    New center coming to Mizzou will focus on energy research and technology – Columbia Missourian

    Mizzou Launches Innovative New Center Dedicated to Energy Research and Technology

    Mirrors in space and underwater curtains: can technology buy us enough time to save the Arctic ice caps? – The Guardian

    Can Technology Like Space Mirrors and Underwater Curtains Buy Us Time to Save the Arctic Ice Caps?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    MAY HER SOUL REST IN PEACE 🙏 Veteran entertainment columnist and talent manager Lolit Solis has passed away. She was 78 years old. https://tinyurl.com/6kumarkx | LatestChika.com – Facebook

    Beloved Entertainment Icon Lolit Solis Passes Away at 78 – A Life Remembered with Love and Respect 🙏

    Neil Young Plays Rare Full-Band ‘Ambulance Blues’ With The Chrome Hearts – Yahoo

    Neil Young Stuns Fans with Rare Full-Band Performance of ‘Ambulance Blues’ Alongside The Chrome Hearts

    BTS Announce Their Big Return and Yes, They Already Have Some Major Plans in the Works – Yahoo

    BTS Announce Their Big Return and Yes, They Already Have Some Major Plans in the Works – Yahoo

    Nantucket Dance Festival opens July 8 – The Inquirer and Mirror

    Nantucket Dance Festival Launches with Thrilling Performances Beginning July 8

    A Secret Society, Ritualistic Killings, and a Century-Old Curse Netflix and YRF Entertainment’s ‘Mandala Murders’ Premieres July 25 – About Netflix

    A Secret Society, Ritualistic Killings, and a Century-Old Curse: Dive into the Chilling World of ‘Mandala Murders’ Premiering July 25

    Susquehanna Raises Penn Entertainment Inc. (PENN) Price Target. – Yahoo Finance

    Susquehanna Raises Price Target for Penn Entertainment Inc. (PENN)

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    LG Innotek CEO Moon Hyuksoo: “Our Next-gen Substrate Technology Will Change the Industry Paradigm” – TechPowerUp

    LG Innotek CEO Moon Hyuksoo: “Our Next-Gen Substrate Technology Will Revolutionize the Industry” Revolutionizing the Future: LG Innotek’s CEO Unveils Game-Changing Next-Gen Substrate Technology

    Inspira Technologies Secures Landmark $22.5M Deal: Major Revenue Breakthrough After FDA Clearance – Stock Titan

    Inspira Technologies Secures Landmark $22.5M Deal: Major Revenue Breakthrough After FDA Clearance – Stock Titan

    Meiwu Technology Company Limited and Shenzhen Zhinuo – GlobeNewswire

    Meiwu Technology Company Limited and Shenzhen Zhinuo – GlobeNewswire

    Owls inspire new revolutionary noise reduction technology – KTEN

    Owls inspire new revolutionary noise reduction technology – KTEN

    New center coming to Mizzou will focus on energy research and technology – Columbia Missourian

    Mizzou Launches Innovative New Center Dedicated to Energy Research and Technology

    Mirrors in space and underwater curtains: can technology buy us enough time to save the Arctic ice caps? – The Guardian

    Can Technology Like Space Mirrors and Underwater Curtains Buy Us Time to Save the Arctic Ice Caps?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Business

Ditch SMS-based MFA, urges board investigating Lapsus$ gang’s successful attacks

August 11, 2023
in Business
Ditch SMS-based MFA, urges board investigating Lapsus$ gang’s successful attacks
Share on FacebookShare on Twitter

Many organizations victimized by the Lapsus$ extortion gangs through SIM swapping and tricking employees through social engineering have only themselves to blame for being hacked, suggests a U.S. government report.

The report released Thursday by the Cyber Safety Review Board, a branch of the Department of Homeland Security, had unkind things to say about companies, telecom carriers, and the reliance on easily-bypassed text-based SMS systems for multifactor authentication (MFA).

“Lapsus$ made clear just how easy it was for its members (juveniles, in some instances) to infiltrate well-defended organizations,” the report says in part. “Lapsus$ exploited systemic ecosystem weaknesses to infiltrate and extort organizations, sometimes appearing to do so for nothing more than attention and public notoriety.”

Attacks linked to Lapsus$ and associated groups include:

— accessing one organization’s enterprise tools, including SaaS applications that contained source code and customer data, such as Atlassian, Cloudflare, and Slack;
— stealing source code from a telecommunications provider. This is possibly a reference to an attack on T-Mobile;
— stealing 200 gGB of corporate data from a Kansas-based surgical and rehabilitation center;
— stealing approximately 37 GB of source code for over 250 projects from a technology company, after which Lapsus$ made it available for download in an online torrent posted on its Telegram channel. This appears to be a reference to a Microsoft hack;
— stealing and publishing source code for two flagship games from a gaming company, including related assets from the company’s Confluence and Slack servers;
— and stealing and deleting 50 TB of data, including a COVID-19 database, from a non-U.S. government agency.

“Among its findings,” the agency said in a news release accompanying the report, “the Board saw a collective failure across organizations to account for the risks associated with using text messaging and voice calls for multi-factor authentication.”

In one example cited by the report, in January 2022 the gang gained access to privileged internal tools of an unnamed third-party service provider by compromising the computer of a customer support contractor from one of its business process outsourcers. The real
target of this attack was not the third-party service provider, nor the outsourcer, but the downstream customers of the service provider.

“This is a remarkable example of a creative three-stage supply chain attack used by this
class of threat actors,” the report says.

Although the service provider isn’t named, it is similar to the widely-reported 2022 compromise of a contractor of identity and access manager Okta.

One tactic of the gang: Impersonating police and making fraudulent Emergency Disclosure Requests to wireless carriers to obtain sensitive information about targets.

Some of that information enabled SIM swapping by convincing a carrier — or hacking the account of a carrier’s customer support staff — to switch a target’s mobile phone number to smartphones controlled by the gang. Then it could intercept SMS and voice calls and receive MFA-related messages that control access to online email and bank accounts.

The report describes Lapsus$ as a loosely organized group, which included several juveniles, based mainly in the U.K. and Brazil. It had eight to 10 known members as of April 2022. The previous month, police in England arrested seven individuals in connection with Lapsus$. Two juveniles were charged. In September, U.K. police arrested a 17-year-old on suspicion of hacking. Media reports quoted experts believing the three arrests were related to Lapsus$’s attacks against technology and gaming companies. Then, in October, Brazilian police said they had arrested a Brazilian national suspected of belonging to Lapsus$.

Since then, Lapsus$ activity has disappeared. The report’s authors say they can’t rule out the possibility that other gang members are lying low.

Among the board’s recommendations:

— organizations must “urgently” implement improved access controls and authentication methods, and transition away from voice and SMS-based MFA. It’s a recommendation experts have been making for years. “Those methods are particularly vulnerable,” says the report. Instead, organizations should adopt easy-to-use, secure-by-default, passwordless solutions such as Fast IDentity Online (FIDO)2-compliant, phishing-resistant MFA methods.

To facilitate the transition to passwordless authentication, the board recommends Washington develop a secure authentication roadmap for the U.S.;

— carriers should implement more stringent authentication methods to prevent fraudulent SIM swapping;

— organizations should prioritize resiliency and fast recovery to defend against SIM swapping attacks;

— organizations should plan for disruptive cyber intrusions by requiring their whole business, including outside suppliers, to invest in prevention, detection, response, and recovery capabilities;

— Congress should support the creation of “whole-of-society” programs and mechanisms to prevent juvenile cybercrime.

Lapsus$ was not successful in all its attempted attacks, the report adds. Organizations with mature, defense-in-depth controls were most resilient to these threat actor groups. Organizations that used application or token-based MFA methods or employed robust network intrusion detection systems, including rapid detection of suspicious account activity, were especially resilient.

“Organizations that maintained and followed their established incident response procedures significantly mitigated impacts,” the report noted. “Highly effective organizations employed mechanisms such as out-of-band communications that allowed incident response professionals to co-ordinate response efforts without being monitored by the threat actors.”

“We need better technologies that move us towards a passwordless world, negating the effects of credential theft,” the report concludes. “We need telecommunications providers to design and implement processes and systems that keep attackers from hijacking mobile phone service. We need to double down on zero trust architectures that assume breach. We need organizations to design their security programs to cover not only their own information technology environments, but also those of their vendors that host critical data or maintain direct network access. We need to give law enforcement the means to disrupt all manner of threat actors. And we need to help curious young people use their growing digital skills for positive purposes.”

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : ITBusiness.ca – https://www.itbusiness.ca/news/ditch-sms-based-mfa-urges-board-investigating-lapsus-gangs-successful-attacks/125806

Tags: businessditchSMS-based
Previous Post

Black Hat: Tenable to add AI query module to its Exposure Management platform; DARPA AI Cyber Challenge announced

Next Post

Alberta dental plan administrator paid ransomware gang after attack

Church adds Mass ‘for care of creation’ to missal, pope to celebrate – usccb

Pope Introduces New Mass Dedicated to Caring for Creation

July 4, 2025
How UMich computer science students are navigating a shifting job market – The Michigan Daily

How UMich computer science students are navigating a shifting job market – The Michigan Daily

July 4, 2025
Genoa Central Junior High Student Places in the 2025 Soybean Science Challenge – TXK Today

Genoa Central Junior High Student Excels in 2025 Soybean Science Challenge

July 4, 2025
Maison & Objet, the Paris-based home and lifestyle trade show, announces leadership change – FashionNetwork India

Maison & Objet Reveals Dynamic New Leadership to Transform the Future of Home and Lifestyle

July 4, 2025
World’s biggest climate fund ramps up investment plans – Reuters

World’s Largest Climate Fund Accelerates Ambitious Investment Plans

July 4, 2025
US economy ‘on wobbly footing’: Why Wall Street strategists are cautious about stock market’s recent records – Yahoo Finance

US Economy on Shaky Ground: Why Wall Street Strategists Are Cautious Despite Stock Market Records

July 4, 2025
MAY HER SOUL REST IN PEACE 🙏 Veteran entertainment columnist and talent manager Lolit Solis has passed away. She was 78 years old. https://tinyurl.com/6kumarkx | LatestChika.com – Facebook

Beloved Entertainment Icon Lolit Solis Passes Away at 78 – A Life Remembered with Love and Respect 🙏

July 4, 2025
Supreme Court declines to hear case challenging parental consent for abortion – CNN

Supreme Court declines to hear case challenging parental consent for abortion – CNN

July 4, 2025
LG Innotek CEO Moon Hyuksoo: “Our Next-gen Substrate Technology Will Change the Industry Paradigm” – TechPowerUp

LG Innotek CEO Moon Hyuksoo: “Our Next-Gen Substrate Technology Will Revolutionize the Industry” Revolutionizing the Future: LG Innotek’s CEO Unveils Game-Changing Next-Gen Substrate Technology

July 3, 2025
Diego Luna strikes shaky USMNT to win over Guatemala, and into Gold Cup final – Yahoo Sports

Diego Luna Propels USMNT to Thrilling Win Over Guatemala, Punching Ticket to Gold Cup Final

July 3, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (704)
  • Economy (730)
  • Entertainment (21,618)
  • General (15,700)
  • Health (9,768)
  • Lifestyle (734)
  • News (22,149)
  • People (730)
  • Politics (737)
  • Science (15,947)
  • Sports (21,227)
  • Technology (15,713)
  • World (710)

Recent News

Church adds Mass ‘for care of creation’ to missal, pope to celebrate – usccb

Pope Introduces New Mass Dedicated to Caring for Creation

July 4, 2025
How UMich computer science students are navigating a shifting job market – The Michigan Daily

How UMich computer science students are navigating a shifting job market – The Michigan Daily

July 4, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version