Showing posts with label supply chain. Show all posts
Showing posts with label supply chain. Show all posts

Sunday, November 17, 2019

Trend Micro reveals that over a dozen obfuscated APT33 botnets have been used for extreme narrow targeting

The threat group regularly referred to as APT33 is known to target the oil and aviation industries aggressively, Trend Micro revealed. This threat group has been reported on consistently for years, but recent findings show that the group has been using about a dozen live Command and Control (C&C) servers for extremely narrow targeting. 

APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and South Korea, with a particular interest in the aviation and energy sectors.


The group puts up multiple layers of obfuscation to run these C&C servers in extremely targeted malware campaigns against organizations in the Middle East, the U.S., and Asia.

“We believe these botnets, each comprising a small group of up to a dozen infected computers, are used to gain persistence within the networks of select targets,” Trend Micro wrote in a post this week. 

The malware is rather basic, and has limited capabilities that include downloading and running additional malware. Among active infections in 2019 are two separate locations of a private American company that offers services related to national security, victims connecting from a university and a college in the U.S., a victim most likely related to the U.S. military, and several victims in the Middle East and Asia.


APT33 has also been executing more aggressive attacks over the past few years. For example, for at least two years the group used the private website of a high-ranking European politician (a member of the country’s defense committee) to send spear phishing emails to companies that are part of the supply chain of oil products. Targets included a water facility that is used by the U.S. army for the potable water supply of one of its military bases.

These attacks have likely resulted in concrete infections in the oil industry. For example, in the fall of 2018, Trend Micro observed communications between a U.K.-based oil company with computer servers in the U.K. and India and an APT33 C&C server. 


Another European oil company suffered from an APT33 related malware infection on one of their servers in India for at least three weeks in November and December last year. There were several other companies in oil supply chains that had been compromised in the fall of 2018 as well. These compromises indicate a big risk to companies in the oil industry, as APT33 is known to use destructive malware.

Saturday, November 2, 2019

Procurant acquires SureCheck to improve global food supply chain platform

Procurant, a Silicon Valley technology company transforming the global food supply chain, announced a definitive agreement to acquire the SureCheck mobile food safety solutions and monitoring business from ParTech Inc., a wholly owned subsidiary of PAR Technology.

Procurant offers companies in the food industry a cloud-based perishable food procurement system that enables trading partner collaboration, IoT and sensor data collection, mobile messaging and alerts, secure storage of critical documentation and the sharing of food safety data in public or private blockchains including the IBM Food Trust. 


Procurant is transforming the global food supply chain with technology to reduce waste, increase visibility, improve food safety and digitize business from production to consumption. The company was founded by industry veterans with decades of experience delivering solutions to growers, shippers, distributors, retailers and foodservice operators. Procurant is backed by GLP Properties (glprop.com) with US$66 billion of assets under management in real estate and private equity funds around the world.

The platform and its related applications help farmers, producers, shippers, distributors and retailers in their strategic planning as well as their day-to-day supply chain processes.

With the addition of SureCheck’s suite of mobile food safety and task management applications and devices, Procurant now offers customers a uniquely comprehensive, operations-focused end-to-end food supply chain solution. The SureCheck suite is now part of a continuum of solutions that leverage a single, global platform designed for the unique requirements of the food industry.


All Procurant solutions benefit from the strengths of a shared infrastructure that includes scalability at consumer performance levels, from the user interface to business logic to storage; mobile as an integral part of the platform, with a focus on managing by exception; and blockchain options that route data to both public and private distributed ledgers.

“The combination of SureCheck’s leading mobile food safety and task management products with Procurant’s food supply chain platform creates a solution unmatched in this industry,” said Eric Peters, CEO of Procurant. “With food safety and visibility across the supply chain becoming ever more critical, Procurant’s innovative approach will help our customers move beyond simple homegrown systems of the past for better visibility, control and trust from farms to consumers.”

MOL Group strengthens alliance with MobileIron to drive business efficiency and growth for on-demand scalability, security, availability

MobileIron announced that it has extended its long-term relationship with MOL Group (MOL), an integrated, multinational oil and gas company headquartered in Budapest, Hungary. MOL Group will transition from MobileIron Core to MobileIron Cloud to get the benefits of full-service unified endpoint management (UEM) in the cloud.

By moving to MobileIron Cloud, MOL Group will benefit from on-demand scalability and enhanced ROI. MOL Group will be able to instantly scale its UEM deployment as business needs change, eliminate long hardware procurement planning cycles and costs, and get automatic updates and access to new features as soon as they become available. 



MOL Group will also be able to minimize hardware costs by eliminating the need to maintain on-prem hardware, reduce data center hardware footprint to virtually zero, and reallocate IT resources from hardware maintenance to more strategic tasks.

S&T Consulting Hungary Ltd., an authorized MobileIron partner, will continue to deliver MobileIron’s products to MOL Group and integrate them within existing corporate systems.


MOL Group is an integrated, international oil and gas company, headquartered in Budapest, Hungary. It is active in over 40 countries with a dynamic international workforce of 26,000 people and a track record of more than 100 years in the industry. MOL’s exploration and production activities are supported by more than 75 years’ experience in the hydrocarbon field. At the moment, there are production activities in 8 countries and exploration assets in 13 countries. 


MOL Group operates four refineries and two petrochemical plants under integrated supply chain management in Hungary, Slovakia and Croatia, and owns a network of 2,000 service stations across 10 countries in Central & South Eastern Europe.

“Over the past few years, MobileIron’s zero trust platform has dramatically improved our mobile productivity,” said Peter Varga, Group CTO/CISO at MOL Group. “Employees can quickly and securely access the resources they need every day, while IT has improved visibility and control across the mobile fleet. We’re confident that MobileIron’s platform will continue to help us meet our mobile security goals, particularly as we migrate to cloud-based infrastructures and services.”

“It’s been exciting to help MOL Group successfully optimize their workflows on secure mobile devices,” said Simon Biddiscombe, CEO, MobileIron. “We look forward to continuing to help MOL Group meet their mobile security needs and migrate to the cloud, without sacrificing productivity. We’re committed to delivering a secure work experience, and helping our customers drive business efficiency and growth.”

Wednesday, October 30, 2019

New SpyCloud offering, Third Party Insight, helps to measure and mitigate supply chain breach risks

SpyCloud launched Tuesday their new Third Party Insight solution to help companies understand risk and remediate exposures to the potential threat of account takeover emanating from supply chain vendors. Businesses can use this tool to evaluate risks presented by vendors, partners or acquisition targets based on several factors that stem from the threat of account takeovers.

Third Party Insight provides SpyCloud customers with a risk ranking (specific to the threat of account takeover) for each third party they work with, plus specific data on executive credentials, potentially infected employees, and the rate of password reuse across exposed data. 


Companies can share this data with partners for free and work with them to remediate exposures, reducing the risk of a breach due to account takeovers in their supply chain.  

Some of the most infamous data breaches occurred after the compromise of a third-party account. Memorably, Target's systems were reportedly compromised in 2013 after an HVAC vendor's credentials were used to access Target's web services for vendors, eventually leading to the propagation of credit card-stealing malware on point of sale systems.


More recently in March 2019, Citrix, which provides virtual private network services to most of the Fortune 1000, fell victim to a breach that emanated from an account takeover attack. Criminals had access to emails, project files, employee information and more over a six-month period before the breach was detected. 


"Your employees are open doors to your network, your data and your intellectual property, but your third-party relationships extend that attack surface even further," explained David Endler, chief product officer and co-founder of SpyCloud. "Our new Third Party Insight solution gives businesses a way to evaluate supply chain risks and work cooperatively with their vendors to mitigate them, in turn strengthening their overall security posture while building goodwill with key partners and suppliers."


"In addition to helping assess how vendors and partners may increase your attack surface, Third Party Insight can also help you understand exposures you may inherit through mergers and acquisitions," said Ted Ross, CEO and co-founder of SpyCloud. "When news of an acquisition leaks to the press, the parties involved become ideal targets for criminals. We can now proactively improve the security posture of these parties ahead of these events."

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...