UN General Assembly adopts historic cybercrime convention

The United Nations General Assembly has adopted a landmark treaty to combat cybercrime, marking the culmination of five years of negotiations. The UN Convention against Cybercrime is set to become the first global instrument for global efforts to combat cybercrime and enhance international cooperation and technical assistance.

The UN Office on Drugs and Crime (UNODC), which acted as secretariat throughout the negotiations, celebrated the treaty as a victory for global cooperation.

‘Adopting this landmark convention is a major victory for multilateralism, marking the first international anti-crime treaty in 20 years. It is a crucial step forward in our efforts to address crimes like online child sexual abuse, sophisticated online scams and money laundering,’ said UNODC Executive Director Ghada Waly.

The General Assembly adopted the resolution by consensus, underscoring widespread support. Negotiations included contributions from civil society, academia, and the private sector, ensuring the treaty reflects diverse perspectives. However, many non-state actors raised concerns about the latest draft.

The treaty will open for signature during a formal ceremony in Vietnam in 2025 and will enter into force 90 days after being ratified by at least 40 member states. In addition, UNODC will continue its role as the secretariat for the Ad Hoc Committee, which is tasked with drafting a supplementary protocol to the Convention and supporting the future Conference of States Parties.

For more details about the Convention and negotiations process, please follow the dedicated page.

US healthcare sector faces new data breach

A recent cybersecurity breach involving US healthcare platform ConnectOnCall has compromised sensitive information belonging to more than 910,000 patients. The telehealth service, owned by Phreesia, experienced unauthorised access between February and May 2024, exposing names, phone numbers, medical details, and in some cases, Social Security numbers. Phreesia promptly took action after discovering the breach, enlisting cybersecurity experts and notifying federal authorities.

ConnectOnCall facilitates after-hours communication for healthcare providers, making the data theft particularly alarming due to the permanent and sensitive nature of health records. Cybercriminals may use this information for identity theft, fraudulent insurance claims, and targeted phishing attacks. Phreesia has since taken the service offline, offering identity and credit monitoring to affected patients, while working to implement more robust security measures.

The breach highlights the growing threat posed by cyberattacks on US healthcare platforms, where data is not only invaluable but also irreplaceable. Experts urge vigilance, such as monitoring accounts, using strong passwords, and employing identity theft protection. With incidents like this on the rise, calls are growing for stricter regulations to safeguard patient information and prevent similar breaches in the future.

Digital Robin Hood scam hits crypto thieves

A crafty new scam is ensnaring would-be crypto thieves by baiting them with fake wallet seed phrases. Cybersecurity experts at Kaspersky have revealed how scammers post these phrases in YouTube comments, claiming the wallets hold significant funds. The wallets, however, are traps designed to exploit anyone attempting to steal the assets.

One wallet discovered by Kaspersky analyst Mikhail Sytnik reportedly held $8,000 in USDT on the Tron network. A thief must send Tron (TRX) tokens to move the funds to cover transaction fees. Unbeknownst to them, the wallet is a multi-signature account, meaning the TRX sent for fees is instantly redirected to another wallet controlled by the scammers.

Sytnik described the scammers as “digital Robin Hoods” for targeting other opportunists. He advised people never to try accessing others’ wallets, even if given a seed phrase, and to remain cautious of strangers’ claims about cryptocurrency online.

This isn’t the first time fraudsters have exploited greed in the crypto space. In July, Kaspersky exposed a similar scam on Telegram, where users were tricked into downloading malware disguised as legitimate crypto tools, potentially compromising their devices and funds.

Data security measures must be bolstered by Marriott and Starwood

Marriott International and Starwood Hotels have been ordered to improve data security following multiple breaches impacting over 344 million customers. The Federal Trade Commission (FTC) finalised the order on Friday, citing inadequate security practices. Major breaches occurred in 2015, 2018, and 2020, exposing sensitive customer information, including passport details and payment data.

Hackers gained prolonged access to systems during the breaches, with one lasting four years undetected. The companies must now implement measures such as limiting data retention and providing US customers with a way to request the deletion of personal information tied to their accounts.

The FTC accused the hotel chains of misleading consumers with claims of robust data security while failing to address basic vulnerabilities like weak passwords and outdated software. The Connecticut Attorney General’s office also announced a $52 million settlement with Marriott on the same day.

Under the 20-year order, Marriott and Starwood must maintain compliance records, undergo inspections, and ensure transparency about their data handling practices. The ruling is part of broader efforts to hold businesses accountable for safeguarding customer information.

US launches trade investigation into Chinese semiconductors amidst escalating tensions

The Biden administration has initiated a trade investigation targeting Chinese-made legacy semiconductors, which power everyday goods like cars and telecom equipment. This ‘Section 301’ probe aims to address concerns about China’s state-driven expansion in chip manufacturing, which US officials warn could harm American semiconductor producers. Departing President Joe Biden had already imposed a 50% tariff on Chinese semiconductors, set to take effect 1 January, while tightening export controls on advanced AI and memory chips.

Commerce Secretary Gina Raimondo revealed that Chinese legacy chips account for two-thirds of semiconductors in US products, with many companies unaware of their origin—a finding she called alarming, particularly for the defence industry. US Trade Representative Katherine Tai stated that China’s subsidised chip pricing threatens global competition, enabling rapid capacity growth and undercutting market-oriented producers.

China’s commerce ministry has criticised the probe, calling it protectionist and a potential disruptor to global supply chains. Meanwhile, a public hearing on the issue is scheduled for March, with the probe expected to conclude within a year. The investigation follows the COVID-19 pandemic’s impact on semiconductor supply chains, prompting the US efforts to bolster domestic chip production with $52.7 billion in subsidies.

As the Biden administration transitions to President-elect Donald Trump’s leadership in January, this probe may offer Trump an opportunity to escalate tariffs on Chinese imports, echoing the trade practices he implemented during his prior term. Critics, including the US tech industry, have urged officials to approach the investigation collaboratively to avoid further disruption.

Israeli spyware deal reports denied by US and Israel

Officials from the United States and Israel have refuted claims of approving the sale of Israeli spyware firm Paragon to Florida-based AE Industrial Partners. Reports of the transaction surfaced in Israeli media, suggesting both governments had greenlit the deal, but US and Israeli representatives dismissed these assertions.

The White House clarified that the sale was a private transaction with no formal US approval, while Israel‘s Defence Ministry stated it was still evaluating the deal. Paragon, linked to former Israeli intelligence officers, has faced scrutiny in the US market, including a paused $2 million contract with ICE.

The alleged acquisition has drawn attention due to Paragon’s ties to national security and controversial surveillance software. Both AE and Paragon have not yet commented on the situation.

MCU and Fortinet to enhance cybersecurity education in the Philippines

Manila Central University (MCU) has partnered with Fortinet, a global leader in cybersecurity, through its Academic Partner Program to address the growing talent shortage in the Philippines. That collaboration aims to equip students with essential skills to meet industry demands by integrating Fortinet’s Network Security Expert (NSE) training and certification program into the university’s curriculum, either as coursework or standalone offerings.

Faculty members will receive advanced training, and students will benefit from guest lectures, practical exercises, and hands-on learning in areas like network security, malware analysis, and defence strategies. Additionally, the partnership includes establishing a state-of-the-art Cyber Innovation Lab to provide immersive learning experiences.

The initiative aligns with findings from Fortinet’s ‘Cybersecurity Skills Gap 2024 Global Research Report,’ which revealed that 94% of organisations in the Philippines experienced security breaches in 2023, with 77% partly attributed to a lack of cybersecurity skills. MCU joins nine other institutions, including Mapúa University and Mindanao State University-Sulu, in Fortinet’s nationwide effort to strengthen cybersecurity education.

The partnership also represents a significant step toward bridging the cybersecurity skills gap in the Philippines. By combining Fortinet’s expertise with MCU’s academic foundation, the program offers students industry-recognised certifications and practical knowledge needed to excel as cybersecurity professionals.

Why does it matter?

The initiative addresses immediate challenges highlighted in the report and strengthens the country’s capacity to defend against evolving digital threats, ensuring a robust pipeline of future professionals ready to meet global cybersecurity standards.

US charges Russian-Israeli citizen over Lockbit ransomware

The United States has charged Rostislav Panev, a Russian-Israeli dual citizen, for his alleged role as a developer for the Lockbit ransomware group, which authorities describe as one of the world’s most destructive cybercrime operations. Panev, arrested in Israel in August, awaits extradition.

Lockbit, active since 2019, targeted over 2,500 victims across 120 countries, including critical infrastructure and businesses, extorting $500 million. Recent arrests, guilty pleas, and international law enforcement efforts have significantly disrupted the group’s activities.

Experts say law enforcement actions have tarnished Lockbit’s reputation, reducing its attacks and deterring affiliates. Authorities emphasise the importance of holding cybercriminals accountable.

Sparkle and Fincantieri to strengthen submarine cable security and boost Italy’s digital innovation

Sparkle and Fincantieri have formed a strategic partnership to protect submarine telecommunications cables, which are crucial for global connectivity and national security. The collaboration aims to develop innovative technological solutions for securing subsea infrastructure, ensuring its resilience in the face of emerging threats.

By combining Fincantieri’s expertise in underwater technology and shipbuilding with Sparkle’s vast fibre-optic network, the two companies plan to enhance the operational security of these vital systems. Sparkle, with over 600,000 km of fibre-optic cables across multiple continents, has long prioritised the protection of submarine cables through advanced monitoring and security measures.

That partnership is part of broader strategy of Italy to boost technological development and international competitiveness, focusing on safeguarding critical infrastructures fundamental to digital connectivity and economic growth. The collaboration also strengthens Italy’s leadership in digital innovation, with Fincantieri focusing on submarine infrastructure protection and Sparkle enhancing resilience in partnership with the Italian Navy and Polo Nazionale della dimensione Subacquea.

NETSCOUT enhances DDoS protection with AI/ML-Driven adaptive solutions

NETSCOUT SYSTEMS announced significant updates to its Arbor Edge Defense (AED) and Arbor Enterprise Manager (AEM) products as part of its Adaptive DDoS Protection solution. These enhancements are designed to address the growing threats of AI-enabled DDoS attacks, which have surged in sophistication and frequency.

Application-layer and volumetric attacks have increased by 43% and 30%, respectively, with DDoS-for-hire services making attacks easier to execute. To combat these evolving threats, NETSCOUT leverages AI and machine learning (ML) within its ATLAS Threat Intelligence system, which monitors over 550 Tbps of real-time internet traffic across 500 ISPs and 2,000 enterprise sites worldwide.

The AI/ML-powered solution enables dynamic threat identification and mitigation, creating a scalable, proactive defence mechanism. The updated AED and AEM products automate a closed-loop DDoS attack detection and mitigation process, providing real-time protection by adapting to changing attack vectors and applying mitigation recommendations automatically.

NETSCOUT’s solution also offers comprehensive protection across hybrid IT environments, including on-premise infrastructure, private data centres, and public cloud platforms like AWS and Microsoft Azure, with enhancements such as 200 Gbps mitigation capacity, high-performance decryption, and visibility into non-DDoS threats.

By minimising downtime and safeguarding business-critical services, NETSCOUT’s Adaptive DDoS Protection reduces business risks and protects productivity and reputation. As the threat landscape continues to evolve, organisations can rely on NETSCOUT’s innovative technology to stay ahead of attackers and maintain IT resilience. Industry experts and agencies like the Cybersecurity & Infrastructure Security Agency (CISA) highlight the need for adaptive cybersecurity measures. NETSCOUT’s AI/ML-driven solutions meet these demands by offering robust, future-proof protection for critical IT infrastructure.