Transcript
Jim Love (0:02)
The US Government launches cybersecurity safety labels for smart devices North Korean hackers are increasingly targeting macOS, and the US treasury sanctions a Chinese cybersecurity firm for supporting state sponsored hacking. This is Cybersecurity Today. I'm your host Jim Love. The White House has launched the US Cyber Trust Mark, a new cybersecurity safety label for Internet connected consumer devices. Starting later this year, the label will appear on products like security cameras, smart TVs, fitness trackers and connected devices, helping consumers assess whether a device is safe to install at home. Products that meet cybersecurity standards set by the National Institute of Standards and Technology NIST will be eligible for the label. These standards require unique and strong default passwords, regular software updates and incident detection capabilities. The goal is to make smart devices more secure against cyber attacks such as hackers accessing house cameras or unlocking doors remotely. The Cyber Trust mark will include a QR code that consumers can scan to see detailed security information about the product, including password instructions, software update policies and minimum support periods. Products that don't meet security standards won't be eligible for the mark. The program was unveiled in July 2023, with major companies like Amazon, Google, Samsung, LG and Best Buy agreeing to participate. In December 2024, the FCC approved 11 cybersecurity label administrators to manage the program. Retailers like Best Buy and Amazon will highlight CyberTrustmark certified products. Consumer Reports praised the initiative, saying it will help raise security standards across the industry. However, the program is voluntary and it remains to be seen how widely manufacturers will adopt the mark. The US Cyber Trust mark aims to become a cybersecurity equivalent of of the Energy Star labels, encouraging consumers to choose more secure devices while pressuring manufacturers to improve their cybersecurity practices. Security researchers have discovered Spectral blur, a new macOS backdoor that shows similarities to malware previously used by North Korean linked Lazarus Group. The back door appears to connect Blue Norof, a subgroup of Lazarus, also known as TA444. Security expert Greg Lesnewich linked Spectral Blur to candy Corn, also known as Socracket. A malware family attributed to candy corn is an advanced implant capable of monitoring infected systems, avoiding detection and interacting with files. In contrast, spectral blur is less sophisticated but still effective, with capabilities to upload and download files, run commands and delete files based on instructions from its command and control server. Researchers noted that North Korean threat actors have intensified their focus on macOS in recent years. In November 2023, security firm Jamf Threat Labs uncovered another macOS malware strain called obse shells, also attributed to Bluenoroff. Both obse shells and Spectral Blur show connections to the Rust Bucket malware campaign, which has been linked to multiple macOS attacks since early 2023. Experts warn that macOS users should remain vigilant as North Korea's interest in Apple systems continues to grow. The U.S. department of the treasury has sanctioned Integrity Technology Group, a Beijing based cybersecurity firm, for allegedly providing infrastructure to support Flax Typhoon, a Chinese state sponsored hacking group known for targeting US Critical infrastructure. This marks a significant escalation in US Efforts to combat state sponsored cyber threats. The Treasury Department revealed that between 2022 and 2023, Flax Typhoon used Integrity Tech's infrastructure to conduct network exploitation activities against multiple victims, including a California based entity. The group's tactics include exploiting known vulnerabilities and using legitimate remote access tools like VPNs and RDP to maintain persistence in compromised networks. Under Executive Order 13694, the sanctions block all U S Based property and interests of Integrity Tech and prohibit US Persons from engaging in transactions with the company. Acting Under Secretary Bradley T. Smith stated the Treasury Department will not hesitate to hold malicious cyber actors and their enablers accountable. Integrity Tech's designation highlights Flax Typhoon's persistent threat to critical infrastructure, including sectors across North America, Europe, Africa and Asia. A joint cybersecurity advisory issued by the US and allied agencies in September 2024 detailed the group's tactics, emphasizing the need for robust cybersecurity measures to protect against these threats. The sanctions may turn out to be mostly symbolic. Integrity Tech itself stated that the sanctions would not adversely affect its business since it does not operate in the US and has no assets there. But US Firms, including financial institutions that have any dealings with this company, would remain vulnerable to sanctions. It's clear that the sanctions are being set to send a message that the US Is serious about countering state sponsored cyberattacks, with the Treasury Department stressing that the goal is positive change, not punishment. But the message is clear. Entities that enable malicious cyber attacks will face significant consequences. And that's our show for today. Show notes can be found@technewsday.com or CA. Take your pick. You can reach me with comments or tips@editorialechnewsday.ca I'm your host Jim Love. Thanks for listening.
