Showing posts with label central England. Show all posts
Showing posts with label central England. Show all posts

Monday, December 18, 2017

Military Personnel Fire At Man Trying To Ram Checkpoint At US Air Base In UK

US military personnel fired shots at a man who tried to force his way into a military base in central England used by the U.S. air force on Monday. The Mildenhall Royal Air Force base in Suffolk, eastern England said security staff locked down the base, used by the United States to refuel U.S. and NATO aircraft in Europe, at about 1300 GMT following reports of a disturbance. The man was subsequently arrested after the incident.


The U.S. Air Force said the incident had been contained and that the suspect had been apprehended. Police said they remained on the base. The U.S. embassy declined immediate comment.


The UK Ministry of Defence said that the incident took place at the entrance of the base after the driver tried to force the car past the gates.


Shots were fired by American service personnel and a man has been detained with cuts and bruises and taken into custody,” Suffolk Police said. “No other people have been injured as a result of the incident.”



The 1,162-acre base, which houses about 3,100 U.S. military and an additional 3,000 family members, is set for closure after the U.S. said it was going to move is operations from the base to Germany. “The base was locked down and emergency personnel are responding to the situation,” RAF Mildenhall said in a statement. “Individuals in the area surrounding the installation are asked to avoid the base at this time.”



A statement for the base said the lockdown had later been lifted.








Saturday, November 11, 2017

Saudi "Deep State" Prince Bandar Among Those Arrested In Purge: Report

According to a new report by Middle East Eye, Prince Bandar bin Sultan - Saudi Arabia"s most famous arms dealer, longtime former ambassador to the US, and recent head of Saudi intelligence - was among those detained as part of Crown Prince Mohammed bin Salman"s (MBS) so-called "corruption purge" that started with the initial arrests of up to a dozen princes and other top officials last weekend.


If confirmed, the arrest and detention of Bandar would constitute the most significant and high profile figure caught up in the purge - even above that of high profile billionaire investor Prince Alwaleed Bin Talal - given Bandar"s closeness to multiple US administrations and involvement in events ranging from Reagan"s Nicaraguan Contra program (including direct involvement in the Iran-Contra scandal), to making the case for the Iraq War as a trusted friend of Bush and Cheney, to directing US-Saudi covert operations overseeing the arming of jihadists in Syria.



Famous photograph of George W. Bush and his close confidant Prince Bandar bin Sultan.


Middle East Eye issued the report based on multiple contacts "inside the royal court" and indicates further that the scale of MBS" aggressive crackdown is much larger than previously reported, and even involves the torture of "senior figures" among those detained:


Some senior figures detained in last Saturday"s purge in Saudi Arabia were beaten and tortured so badly during their arrest or subsequent interrogations that they required hospital treatment, Middle East Eye can reveal.  People inside the royal court also told MEE that the scale of the crackdown, which has brought new arrests each day, is much bigger than Saudi authorities have admitted, with more than 500 people detained and double that number questioned.



And shockingly, those sources say that the longtime Saudi "deep state" power broker and liaison with the West, Prince Bandar, is among the detained:


One of the most famous is Prince Bandar bin Sultan, a former Saudi ambassador to Washington and confidant of former US President George W Bush.  There is no word on his fate, but Saudi authorities said that one of the corruption cases they are looking at is the al-Yamamah arms deal, in which Bandar was involved.



While no doubt Bandar"s very well-known role in Saudi "oil for arms" programs which have come to define Saudi relations with the West over the past decades is a trumped up and "selective" charge (insofar as the highest levels of the state have overseen such shady dealing) the al-Yamamah deal in particular - which goes back to the mid-1980"s - has been an historical embarrassment to both the UK and Saudi governments (BAE Systems was the prime British contractor involved) for the astounding level of fraudulent accounting exposed in UK courts. 


Concerning Prince Bandar"s role in the al-Yamamah deal, Middle East Eye continues


Bandar bought an entire village in the Cotswolds, a picturesque area of central England, and a 2,000-acre sporting estate with part of the proceeds from kickbacks he received in the al-Yamamah arms deal, which netted British manufacturer BAE £43bn ($56.5bn) in contracts for fighter aircraft.


 


As much as $30m (£15m) is alleged to have been paid into Bandar’s dollar account at Riggs Bank in Washington and the affair led to corruption probes in the US and UK, although the case was dropped in the UK in 2006 after an intervention by then-prime minister Tony Blair.



But more likely is that Bandar has been caught up in this week"s MBS dragnet for his closeness to Western heads of state and foreign intelligence services. With MBS" aggressive consolidation of power which could result in ascension to the throne at any moment, and with fate of multiple princes and officials still unknown - not the least of which is now ex-PM of Lebanon Saad Hariri - a shroud of secrecy has resulted in myriad theories concerning what is really happening behind the scenes. 


Likely, Bandar has been detained to ensure a communications blackout with Western intelligence and media until MBS" plans are complete, with the added benefit of ensuring the "anti-corruption" angle to the purges for the consumption of international media. 



Bandar (left) has been close to multiple US administrations
 spanning decades with direct involvement in events ranging from Reagan"s Nicaraguan Contra program (including being named in the Iran-Contra scandal), to making the case for the Iraq War as a trusted friend of Bush and Cheney, to directing Obama-era covert operations to arm jihadists in Syria.


Ironically, Bandar himself once seemed to publicly boast about receiving massive kickbacks in relation to Saudi weapons dealing, which perhaps further made him an easy and high profile target in this week"s crackdown. According to a royal family profile highlighting corruption in the New York Times from early this week


Perhaps the most famous statement on corruption in Saudi Arabia was made by Prince Bandar. In an interview with PBS in 2001, he said: “If you tell me that building this whole country, and spending $350 billion out of $400 billion, that we had misused or got corrupted with $50 billion, I’ll tell you, yes. But I’ll take that anytime.”



And the New York Times summarized the key events of the multi-billion pound weapons deal with the UK as follows:


Weapons contracts have long been a source of wealth. British media reported that Prince Bandar received well over $1 billion in secret payments from BAE Systems, the leading British military contractor, over the course of a decade. The son of founding King Abdulaziz’s personal doctor, Adnan Khashoggi, became a billionaire as an arms dealer and go-between for weapons makers and members of the royal family.



Meanwhile news of Bandar"s possible arrest and detention hasn"t spread very widely in international media reports as of this writing, but it will be interesting to see the response in the West should the news be confirmed. Will Bandar"s friends in Washington and London go to bat for him? Or will Prince Bandar quietly recede into the background of a permanent forced retirement from public life?


Most likely the latter will be the case. Regardless, for friends of the former powerful Saudi intelligence director on either side of the Atlantic and within Saudi Arabia itself, Bandar no doubt knows where all the skeletons are buried, and this alone makes him a worrisome, volatile and unpredictable figure in the midst of a transfer of power.









Tuesday, May 16, 2017

New Variant Of "WannaCry" Virus Emerges Infecting 3,600 Computers Per Hour

Update: according to the latest data from Check Point Software, cited by Reuters, a new variant of the WannaCry ransomware is now infecting on average 3,600 computers per hour.



* * *


Governments and companies around the world began to gain the upper hand against the first wave of the unrivaled global cyberattack this morning.





More than 200,000 computers in at least 150 countries have so far been infected, according to Europol, the European Union’s law enforcement agency. The U.K.’s National Cyber Security Centre said new cases of so-called ransomware are possible “at a significant scale.”



"For now, it does not look like the number of infected computers is increasing," said a Europol spokesman. "We will get a decryption tool eventually, but for the moment, it’s still a live threat and we’re still in disaster recovery mode."



The initial attack was stifled when a security researcher disabled a key mechanism used by the worm to spread, but experts warned the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn’t or didn’t download a security patch released in March that Microsoft had labeled “critical.”





“I will confess that I was unaware registering the domain would stop the malware until after I registered it, so initially it was accidental,” wrote the researcher, who uses the Twitter name @MalwareTechBlog.



“So long as the domain isn’t revoked, this particular strain will no longer cause harm, but patch your systems ASAP as they will try again.”



But the world is still digging out...





Europol executive director Rob Wainwright told Britain"s ITV television on Sunday that the attack had been "unprecedented". "We"ve never seen anything like this," he said.



In China, "hundreds of thousands" of computers were affected, including petrol stations, cash machines and universities, according to Qihoo 360, one of China"s largest providers of antivirus software. The malware affected computers at “several” unspecified Chinese government departments, the country’s Cyberspace Administration said on its WeChat blog Monday. Since that initial attack, agencies and companies from the police to banks and communications firms have put preventive measures in place, while Qihoo 360 Technology Co., Tencent Holdings Ltd. and other cybersecurity firms have begun making protection tools available, the internet overseer said.



French carmaker Renault said its Douai plant, one of its biggest sites in France employing 5,500 people, would be shut on Monday as systems were upgraded.



At Germany’s national Deutsche Bahn railroad, workers were laboring under "high pressure" Monday to repair remaining glitches with train stations’ electronic departure boards, a spokesman said.



In Japan, Hitachi Ltd. said that some of its computers had been affected.



In South Korea, CJ CGV Co., the country’s largest cinema chain, said advertising servers and displays at film theaters were hit by ransomware. Movie servers weren’t affected and are running as normal, it said in a text message Monday.



Indonesia’s government reported two hospitals in Jakarta were affected.



About 97 percent of U.K. facilities and doctors disabled by the attack were back to normal operation, Home Secretary Amber Rudd said Saturday after a government meeting. At the height of the attack Friday and early Saturday, 48 organizations in the NHS were affected, and hospitals in London, North West England and Central England urged people with non-emergency conditions to stay away as technicians tried to stop the spread of the malicious software.



As Microsoft"s president and chief legal officer, Brad Smith, said in a blog post Sunday:





"An equivalent scenario with conventional weapons would be the US military having some of its Tomahawk missiles stolen," Smith wrote.



"The governments of the world should treat this attack as a wake up call."



And waking up they seem to be...(as Axios notes)





President Trump"s homeland security adviser, Tom Bossert, said that Friday"s global cyberattack is something that "for right now, we"ve got under control" in the U.S., reports AP:



"Bossert tells ABC"s "Good Morning America" that the malware is an "extremely serious threat" that could inspire copycat attacks. But Microsoft"s security patch released in March should protect U.S. networks for those who install it."



"Micrsoft"s top lawyer has criticized U.S. intelligence for "stockpiling" software code that can aid hackers. Cybersecurity experts say the unknown hackers behind the latest attacks used a vulnerability exposed in U.S. government documents leaked online."



"Bossert said "criminals" are responsible, not the U.S. government. Bossert says the U.S. hasn"t ruled out involvement by a foreign government, but that the recent ransom demands suggest a criminal network."



However, new variants of the rapidly replicating malware were discovered Sunday. One did not include the so-called kill switch that allowed researchers to interrupt the malware"s spread Friday by diverting it to a dead end on the internet.


As Bloomberg reports that Matt Suiche, founder of United Arab Emirates-based cyber security firm Comae Technologies warns a new version of the ransomware may have also been spreading over the weekend.


About 50% of machines that would have spread the infection by the second variation of the malware have Russian I.P. addresses, according to Suiche.


Over 40,000 machines appear to have been infected by the second variation of the malware already.



Ryan Kalember, senior vice president at Proofpoint Inc., which helped stop its spread, said the version without a kill switch could spread. It was benign because it contained a flaw that prevented it from taking over computers and demanding ransom to unlock files but other more malicious ones will likely pop up.


"We haven"t fully dodged this bullet at all until we"re patched against the vulnerability itself," Kalember said.

Sunday, May 14, 2017

"Over 200,000 Infected": Europol Fears Computers Simply Won't Start Monday After "Unrivalled" Global Cyberattack

There was a silver lining in what has been dubbed the "world"s biggest ransomware attack" - it struck on Friday mid-afternoon (in Europe), just as businesses were winding down for the weekend, and as a result the full impact of the forced system shutdowns would not be fully felt over the weekend when businesses and infrastructure are generally operating at a subdued pace. However, with the weekend coming to a close, the full extent of the inflicted damage may become apparent in just a few hours.


That was the warning by Europol Executive Director Rob Wainwright who on ITV’s “Peston on Sunday” broadcast, said that additional disruptions are likely as people return to work Monday and turn on their desktop systems, and as a result the "unrivaled" global cyberattack is poised to continue claiming victims.



Speaking to ITV’s, Wainwright added the attack was indiscriminate across the private and public sectors.


At the moment we are in the face of an escalating threat, the numbers are going up, I am worried about how the numbers will continue to grow when people go to work and turn their machines on Monday morning."


“The latest count is over 200,000 victims in at least 150 countries. Many of those will be businesses including large corporations.”


“We’ve seen the rise of ransomware becoming the principal threat, I think, but this is something we haven’t seen before -- the global reach is unprecedented,” Wainwright also said. He also said that organisations across the globe, including investigators from the National Crime Agency (NCA), are now working non-stop to hunt down those responsible for the ransomware.


As we reported on Saturday, the initial attack was halted when a security researcher disabled a key mechanism used by the worm to spread, but experts said the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn’t or didn’t download a security patch released in March that Microsoft had labeled “critical.” Microsoft said in a blog post Saturday that it was taking the “highly unusual“ step of providing the patch for older versions of Windows it was otherwise no longer supporting, including Windows XP and Windows Server 2003.




As the WSJ confirms, the attacks could worsen on Monday morning because of how the virus works.





The virus contains two parts. One is the ransomware, which locks the computer files and displays a message saying that the files will be locked and eventually destroyed unless the user sends payment over the internet to the hacker.



The other part is known as the "spreader." Once the virus makes its way onto one computer--perhaps when a user opens an infected email attachment--the spreader transmits itself to other computers on the network.



The British researcher, who wishes to be identified only as MalwareTech, found a kill switch in the spreader. The spreader was designed to contact a web address to see whether it should further spread itself, but hackers hadn"t bought that web address. So MalwareTech did, and effectively stopped the virus"s spread. It meant that one computer in a network could be infected, but the worm wouldn"t spread to the rest of the network.



Cybersecurity experts expect the latest versions of the worm to have no kill switch for the spreader. So when workers return to the office Monday morning and turn on their computers, they might open an infected email attachment or connect an already-infected laptop to their organization"s non-security-patched network and spread the worm.



There was some good news: having tipped their hand on Friday, and allowing hacking countermeasures to be implemented, about 97% of U.K. facilities and doctors disabled by the attack were back to normal operation, Home Secretary Amber Rudd said Saturday after a government meeting. As reported on Friday, at the height of the attack Friday and early Saturday, 48 organizations in the NHS were affected, and hospitals in London, North West England and Central England urged people with non-emergency conditions to stay away as technicians tried to stop the spread of the malicious software.


“There will be lessons to learn from what appears to be the biggest criminal cyber-attack in history,” Rudd said cited by Bloomberg in response to a letter from Jonathan Ashworth, the shadow secretary of state for health.


Meanwhile, according to Tom Robinson, chief operating officer and co-founder of Elliptic Enterprises Ltd., a ransomware consultant that works with banks and companies, victims have already paid about $30,000 in ransom so far, with the total expected to rise substantially next week, said . Robinson, in an interview by email, said he calculated the total based on payments tracked to Bitcoin addresses specified in the ransom demands. The number, which is likely a conservative estimate, will only embolden the hackers to become even more aggressive in their next attack.





Ransomware is a particularly stubborn problem because victims are often tricked into allowing the malicious software to run on their computers, and the encryption happens too fast for security software to catch it. Some security expects calculate that ransomware may bring in as much as $1 billion a year in revenue for the attackers.



According to Bloomberg, last year an acute-care hospital in Hollywood paid $17,000 in bitcoin to an extortionist who hijacked its computer systems and forced doctors and staff to revert to pen and paper for record-keeping.


On one hand, it is probable that the weekend gave many companies the opportunity to prepare for the next ransomware attack: "While any sized company could be vulnerable, many large organizations with robust security departments would have prioritized the update that Microsoft released in March and wouldn’t be vulnerable to Friday’s attack."


Even so, it does not explain why some of the world"s biggest corporations were so strikingly unprepared for Friday"s events. 





A spokesman for Spain’s Telefonica SA said the hack affected some employees at its headquarters, but the phone company is attacked frequently and the impact of Friday’s incident wasn’t major. FedEx said it was “experiencing interference,” the Associated Press reported.



Renault halted production at some factories to stop the virus from spreading, a spokesman said Saturday, while Nissan’s U.K. car plant in Sunderland, in northeast England, was affected without causing any major impact on business, an official said.



In Germany, Deutsche Bahn faced “technical disruptions” on electronic displays at train stations, but travel was unaffected, the company said in a statement on its website. Newspaper reports showed images of a ransomware message on display screens blocking train information.



Russia’s Interior Ministry, with oversight of the police forces, said about “1,000 computers were infected,” which it described as less than 1 percent of the total, according to its website.



Indonesia’s government reported two hospitals in Jakarta were affected.



Meanwhile, the latest anti-Russia narrative is growing.


"There is a high probability that Russian-language cybercriminals were behind the attack" said Aleks Gostev, chief cybersecurity expert for Kaspersky Labs. “Ransomware is traditionally their topic,” he said. “The geography of attacks that hit post-Soviet Union most also suggests that.” In retrospect, what more convenient confluence of events could there be than having a handy justification for Q2 GDP missing again - just blame it on the computer virus - and accusing Russia of being responsible for the latest global slowdown.