Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Potentially Malicious Apps Your Kids May Use
It’s a question I get several times a year from anxious parents, either via a direct message, an email or even in line at the grocery store. It goes something like this: “What’s the one thing you wish you’d done better when monitoring your kids’ technology?”
Both of my kids are now young adults, and together, we survived a handful of digital mishaps. So, I tend to have a few answers ready. I’ll go into one of those answers in this post, and here it is: I’d physically pick up their phone more often and ask questions about the apps I didn’t recognize.
And here’s why.
There are the apps on your child’s phone that are familiar. They are the easy ones. We know what color they are, what their graphic avatars look like — the little ghost on the yellow background, the little bird, the camera on the bright purple and orange background. We may have gone through the app together or even use one or two of the apps ourselves. There’s Snapchat, TikTok, Twitter, YouTube, WhatsApp, Kik, and Instagram, among others. There are the mainstay photo apps (VSCO, Facetune, PicsArt) and games (The Sims, Fortnite, Minecraft). We may not like all the apps, but we’ve likely talked about the risks and feel comfortable with how your kids use them. With general recognition, it’s easy to have a false sense of security about what apps our kids are using.
Then, there are the apps on your child’s phone you know nothing about — and there are plenty. Rather than dismiss your concern because you don’t understand the app or because you may not have the energy to start an argument, next time, think about pausing to take a closer look. If you have concerns, address them sooner rather than later.
Questions to consider when analyzing an app or online community:
- What’s the goal of this app? Why was it created?
- What kind of community does this app attract?
- What is the age requirement?
- Are anonymous accounts allowed?
- What privacy settings does it have?
- Can kids run up charges on this app?
- Does the app require location information to use it?
- What red flags are people talking about (google it)?
- What do the app reviews say? What do non-profit advocacy groups such as Common Sense Media say about this app?
Potentially Risky Apps, Community Forums
Here are just a few of the non-mainstream apps that kids use that may not be on your radar but may need a second look. Note: Every app has the potential to be misused. The apps mentioned here are also used every day for connection, entertainment, and harmless fun. Here are just a few this author has had experience with, and others commonly documented in the media.
Quick Tip: It’s possible a child might bury an app inside a folder or behind other apps on their home screens, making it harder to find. By going into settings in either iOS (Settings > General > iPhone Storage) or Android (Google Play Store > Apps >All), you can usually get a quick view of all the apps that exist on a phone.
- Privacy, Safety Gaps
Almost every app has privacy gaps if settings and monitoring are neglected. However, apps such as Live.Me, Game Pigeon, and Zoomerang (among many others) may have loopholes when it comes to age verification, location tracking, and gaps in personal data security. These gaps can give potential predators access to kids and increases opportunities for cyberbullying.
Safe Family Tip: Sit down with your kids, go through any unfamiliar apps, and use parental controls to monitor all family device activity.
- Secrecy
If a child wants to keep activity or content secret from a parent, they will likely find a way. Some of the apps kids use to hide games, photos, or texts are encryption apps (apps that scramble content to outside sources) such as WhatsApp, Proton VPN, ProtonMail, Telegram, and Signal. Other secrecy apps are called vault apps (apps that can be disguised, hidden, or locked), such as Calculator, Vault, HideItPro, App Locker, and Poof.
Safe Family Tip: If you find one of these apps on your child’s phone, stay calm. Kids want privacy, which is normal. However, if the content you see is risky, remind your child that no content is 100% private, even if it’s in a vault app. In addition, commit to the ongoing dialogue that strengthens trust and together, considers setting safety expectations for devices, which may include parental controls.
-
Geotagging
Some apps, especially dating-type apps, require users to allow geotagging to connect you with people in your area. Yubo, which is an app like Tinder, is one your kids may be using that requires location to use it. Live.Me is another geotagging app.
Safe Family Tip: Go over the reasons location apps (and dating apps) are dangerous with your child. Sharing their location and meeting In Real Life (IRL) has become the norm to many kids. Remind them of the risks of this kind of behavior and together, put new boundaries in place.
- Extremist Ideas
The web is full of sketchy, dark pockets kids can stumble into. They can hear about a community forum or app from a friend and be wowed simply because it’s different and edgy. While there are plenty of harmless conversations taking place on these apps, spaces such as Discord, Reddit, and Twitch have reportedly housed communities’ extreme ideologies that target vulnerable kids.
Safe Family Tip: Be aware of behavior changes. Talk with your kids about the wide range of ideals and agendas promoted online, how to think critically about conversations and content, and most importantly, how to spot these communities.
- Anonymous Profiles
Anonymity online is problematic for a plethora of reasons. Apps such as Yolo, Tumblr, and Tellonym, Omegle, YikYak, Whisper, LMK, MeetMe, are just a few of those apps to look for. Many of these apps are chat apps used to eventually meet up with new friends in real life (IRL). However, when apps allow anonymous accounts, it’s almost impossible to trace inappropriate content, threats, or bullying incidents.
Safe Family Tip: Kids get excited about making friends and having new experiences— so much so, they can ignore potential consequences. Discuss issues that may arise (catfishing, sextortion, scams, bullying) when people hide behind anonymous names and profiles. If needed, give real examples from the news where these apps have been connected to tragic outcomes.
-
Inflammatory Content
Several apps and online communities have been connected to violence, hate content, intolerance, and fanaticism. A few of these sites include 4Chan, 8Chan, AnyChan, Gab, SaidIt.Net, and 8Kun, among many others.
Safe Family Tip: Note any behavior changes in your child. Talk often about digital literacy and being a responsible publisher (and consumer) of media online.
Staying in step with your child’s latest and greatest app affinity isn’t easy, and every parent makes mistakes in how they approach the task. However, kids of all ages (no matter how tech-savvy they are) need boundaries, expectations, and consistent and honest dialogue when it comes to digital habits and staying safe online. If you don’t know where to start (or start over), one first step is to start today and commit to staying aware of the digital risks out there. In addition, make time to have regular, open conversations with your child about their favorite apps — the ones you know about and the ones you may not.
Stay Updated
To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.
The post Potentially Malicious Apps Your Kids May Use appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Using Fake Reviews to Find Dangerous Extensions
Fake, positive reviews have infiltrated nearly every corner of life online these days, confusing consumers while offering an unwelcome advantage to fraudsters and sub-par products everywhere. Happily, identifying and tracking these fake reviewer accounts is often the easiest way to spot scams. Here’s the story of how bogus reviews on a counterfeit Microsoft Authenticator browser extension exposed dozens of other extensions that siphoned personal and financial data.
Comments on the fake Microsoft Authenticator browser extension show the reviews for these applications are either positive or very negative — basically calling it out as a scam. Image: chrome-stats.com.
After hearing from a reader about a phony Microsoft Authenticator extension that appeared on the Google Chrome Store, KrebsOnSecurity began looking at the profile of the account that created it. There were a total of five reviews on the extension before it was removed: Three Google users gave it one star, warning people to stay far away from it; but two of the reviewers awarded it between three and four stars.
“It’s great!,” the Google account Theresa Duncan enthused, improbably. “I’ve only had very occasional issues with it.”
“Very convenient and handing,” assessed Anna Jones, incomprehensibly.
Google’s Chrome Store said the email address tied to the account that published the knockoff Microsoft extension also was responsible for one called “iArtbook Digital Painting.” Before it was removed from the Chrome Store, iArtbook had garnered just 22 users and three reviews. As with the knockoff Microsoft extension, all three reviews were positive, and all were authored by accounts with first and last names, like Megan Vance, Olivia Knox, and Alison Graham.
Google’s Chrome Store doesn’t make it easy to search by reviewer. For that I turned to Hao Nguyen, the developer behind chrome-stats.com, which indexes and makes searchable a broad array of attributes about extensions available from Google.
Looking at the Google accounts that left positive reviews on both the now-defunct Microsoft Authenticator and iArtbook extensions, KrebsOnSecurity noticed that each left positive reviews on a handful of other extensions that have since been removed.
Reviews on the iArtbook extension were all from apparently fake Google accounts that each reviewed two other extensions, one of which was published by the same developer. This same pattern was observed across 45 now-defunct extensions.
Like an ever-expanding venn diagram, a review of the extensions commented on by each new fake reviewer found led to the discovery of even more phony reviewers and extensions. In total, roughly 24 hours worth of digging through chrome-stats.com unearthed more than 100 positive reviews on a network of patently fraudulent extensions.
Those reviews in turn lead to the relatively straightforward identification of:
-39 reviewers who were happy with extensions that spoofed major brands and requested financial data
-45 malicious extensions that collectively had close to 100,000 downloads
-25 developer accounts tied to multiple banned applications
The extensions spoofed a range of consumer brands, including Adobe, Amazon, Facebook, HBO, Microsoft, Roku and Verizon. Scouring the manifests for each of these other extensions in turn revealed that many of the same developers were tied to multiple apps being promoted by the same phony Google accounts.
Some of the fake extensions have only a handful of downloads, but most have hundreds or thousands. A fake Microsoft Teams extension attracted 16,200 downloads in the roughly two months it was available from the Google store. A counterfeit version of CapCut, a professional video editing software suite, claimed nearly 24,000 downloads over a similar time period.
More than 16,000 people downloaded a fake Microsoft Teams browser extension over the roughly two months it was available for download from the Google Chrome store.
Unlike malicious browser extensions that can turn your PC into a botnet or harvest your cookies, none of the extensions examined here request any special permissions from users. Once installed, however, they invariably prompt the user to provide personal and financial data — all the while pretending to be associated with major brand names.
In some cases, the fake reviewers and phony extension developers used in this scheme share names, such as the case with “brook ice,” the Google account that positively reviewed the malicious Adobe and Microsoft Teams extensions. The email address brookice100@gmail.com was used to register the developer account responsible for producing two of the phony extensions examined in this review (PhotoMath and Dollify).
Some of the data that informed this report. The full spreadsheet is available as a link at the end of the story.
As we can see from the spreadsheet snippet above, many of the Google accounts that penned positive reviews on patently bogus extensions left comments on multiple apps on the same day.
Additionally, Google’s account recovery tools indicate many different developer email addresses tied to extensions reviewed here share the same recovery email — suggesting a relatively few number of anonymous users are controlling the entire scheme. When the spreadsheet data shown above is sorted by email address of the extension developer, the grouping of the reviews by date becomes even clearer.
KrebsOnSecurity shared these findings with Google and will update this story in the event they respond. Either way, Google somehow already detected all of these extensions as fraudulent and removed them from its store.
However, there may be a future post here about how long that bad extension identification and removal process has taken over time. Overall, most of these extensions were available for two to three months before being taken down.
As for the “so what?” here? I performed this research mainly because I could, and I thought it was interesting enough to share. Also, I got fascinated with the idea that finding fake applications might be as simple as identifying and following the likely fake reviewers. I’m positive there is more to this network of fraudulent extensions than is documented here.
As this story illustrates, it pays to be judicious about installing extensions. Leaving aside these extensions which are outright fraudulent, so many legitimate extensions get abandoned or sold each year to shady marketers that it’s wise to only trust extensions that are actively maintained (and perhaps have a critical mass of users that would make noise if anything untoward happened with the software).
According to chrome-stats.com, the majority of extensions — more than 100,000 of them — are effectively abandoned by their authors, or haven’t been updated in more than two years. In other words, there a great many developers who are likely to be open to someone else buying up their creation along with their user base.
The information that informed this report is searchable in this Google spreadsheet.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Boss of ATM Skimming Syndicate Arrested in Mexico
Florian “The Shark” Tudor, the alleged ringleader of a prolific ATM skimming gang that siphoned hundreds of millions of dollars from bank accounts of tourists visiting Mexico over the last eight years, was arrested in Mexico City on Thursday in response to an extradition warrant from a Romanian court.
Florian Tudor, at a 2020 press conference in Mexico in which he asserted he was a legitimate businessman and not a mafia boss. Image: OCCRP.
Tudor, a native of Craiova, Romania, moved to Mexico to set up Top Life Servicios, an ATM servicing company which managed a fleet of relatively new ATMs based in Mexico branded as Intacash.
Intacash was the central focus of a three–part investigation KrebsOnSecurity published in September 2015. That series tracked the activities of a crime gang working with Intacash that was bribing and otherwise coercing ATM technicians to install sophisticated Bluetooth-based skimmers inside cash machines throughout popular tourist destinations in and around Mexico’s Yucatan Peninsula — including Cancun, Cozumel, Playa del Carmen and Tulum.
Follow-up reporting last year by the Organized Crime and Corruption Reporting Project (OCCRP) found Tudor and his associates compromised more than 100 ATMs across Mexico using skimmers that were able to remain in place undetected for years. The OCCRP, which dubbed Tudor’s group “The Riviera Maya Gang,” estimates the crime syndicate used cloned card data and stolen PINs to steal more than $1.2 billion from bank accounts of tourists visiting the region.
Last year, a Romanian court ordered Tudor’s capture following his conviction in absentia for attempted murder, blackmail and the creation of an organized crime network that specialized in human trafficking.
Mexican authorities have been examining bank accounts tied to Tudor and his companies, and investigators believe Tudor and his associates paid protection and hush money to various Mexican politicians and officials over the years. In February, the leader of Mexico’s Green Party stepped down after it emerged that he received funds from Tudor’s group.
This is the second time Mexican authorities have detained Tudor. In April 2019, Tudor and his deputy were arrested for illegal firearms possession. That arrest came just months after Tudor allegedly ordered the execution of a former bodyguard who was trying to help U.S. authorities bring down the group’s lucrative skimming operations.
Tudor’s arrest this week inside the premises of the Mexican Attorney General’s Office did not go smoothly, according to Mexican news outlets. El Universal reports that a brawl broke out between Tudor’s lawyers and officials at the Mexican AG’s office, and a video released by the news outlet on Twitter shows Tudor resisting arrest as he is being hauled out of the building hand and foot.
A Mexican judge will decide on Tudor’s extradition to Romania in the coming weeks.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
FBI Issues Fortinet Flash Warning
FBI Issues Fortinet Flash Warning

The United States Federal Bureau of Investigation issued a flash warning Thursday over the exploitation of Fortinet vulnerabilities by advanced persistent threat (APT) groups.
According to the FBI, an APT actor group has “almost certainly” been exploiting a FortiGate appliance since at least May 2021 to access a web server hosting the domain for a US municipal government.
The APT actors may have established new user accounts on domain controllers, servers, workstations, and the active directories to help them carry out malicious activity on the network.
“Some of these accounts appear to have been created to look similar to other existing accounts on the network, so specific account names may vary per organization,” said the FBI. However, the Feds warned organizations to be on the lookout for accounts created with the usernames “elie” or “WADGUtilityAccount.”
Once inside a network, the APT actors can conduct data exfiltration, data encryption, or other malicious activity.
The alert comes just one month after the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned that APT actors had gained access to devices on ports 4443, 8443, and 10443 for Fortinet FortiOS CVE-2018-13379, and enumerated devices for FortiOS CVE-2020- 12812 and FortiOS CVE-2019-5591.
The cyber-criminal activity appears to be focused on exploiting particular vulnerabilities rather than specific sectors, as the APT actors have been observed actively targeting a broad range of victims across multiple industries.
“The fact that we continue to see these legacy vulnerabilities being exploited in spite of these alerts is a cautionary tale that unpatched flaws remain a valuable tool for APT groups and cyber-criminals in general,” commented Satnam Narang, staff research engineer at Tenable.
They added: “Unpatched vulnerabilities, not zero-days, are the biggest threat to most organizations today because it gets attackers to their end goal in the fastest and cheapest way. It is imperative that both public sector and private organizations that use the FortiGate SSL VPN apply these patches immediately to prevent future compromise.”
Narang said that the risk posed by unpatched vulnerabilities was further heightened by the broad shift of the workforce to remote working over the past year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Jails Telemarketing Fraudster
US Jails Telemarketing Fraudster

A scammer who defrauded elderly American computer users by tricking them into believing that their computers had suffered a cyber-attack will be spending the next three years in federal prison.
Himanshu Asri, of Delhi, India, took part in a five-year telemarketing scheme that conned around 2,000 computer users, most of whom were seniors.
The 34-year-old fraudster operated the call center in India that played an integral part in the Tech Fraud deception.
Under the scheme, Asri arranged for fraudulent pop-up advertisements to appear on computer users’ screens. The ads falsely claimed that malware had been detected on the computer and advised the user to call a phone number for assistance to remove it.
Users who called the number for help spoke to operators at Asri’s call center and at other call centers based in India. Those operators had been coached to reiterate the lie that malware had been found on the callers’ computers.
Users were offered fictitious computer protection services that would remove the non-existent malware for an exorbitant price.
Those who fell prey to the scam paid on average $482 for computer protection service or assistance that they didn’t need and didn’t receive. In some cases, victims were defrauded of amounts exceeding $1,000.
A spokesperson for the US Attorney’s Office for the District of Rhode Island said: “From call data obtained for a three-month period, it was estimated that over five years Asri’s scheme led approximately 6,500 people to view Asri’s deceptive pop-up ads and encounter call center operators who made the Tech Fraud pitch. It is estimated that 1,950 of those people fell prey to the Tech Fraud.”
Asri and his co-conspirators tricked their victims into handing over at least $940,995.74. Had all their fraudulent attempts been successful, it’s estimated that the fraudsters’ illegal activity could have defrauded victims out of approximately $3,133,000.
Asri was arrested at the beginning of 2020. On December 3, he pleaded guilty to wire fraud.
On Thursday, the scammer was sentenced in US District Court in Providence to three years in federal prison followed by a period of supervised release.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
SolarWinds Hackers Go Phishing
SolarWinds Hackers Go Phishing

American multinational technology company Microsoft says that the threat group behind the Microsoft and SolarWinds hack has launched a massive new phishing campaign targeting government agencies, NGOs and think tanks.
Last year, an advanced persistent threat (APT) group exploited vulnerabilities in Microsoft and SolarWinds programs to carry out a supply-chain attack that trojanized SolarWinds’ Orion business software updates to distribute malware. Nine US federal agencies and over 100 companies were targeted.
According to Microsoft, Russian-based APT group Nobelium was not only behind that attack but is now running a phishing campaign that has already targeted thousands of email accounts around the world.
“This week we observed cyber-attacks by the threat actor Nobelium targeting government agencies, think tanks, consultants, and non-governmental organizations,” wrote Microsoft’s vice president of customer security and trust, Tom Burt, in a blog post published on Thursday.
“This wave of attacks targeted approximately 3,000 email accounts at more than 150 different organizations.”
Burt said that organizations in at least 24 different countries were impacted, with the majority of victims located in the United States.
At least one in four of the organizations targeted are involved in international development, humanitarian, and human rights work.
“These attacks appear to be a continuation of multiple efforts by Nobelium to target government agencies involved in foreign policy as part of intelligence gathering efforts,” wrote Burt.
Nobelium launched the phishing campaign by gaining access to the Constant Contact account of USAID.
“From there, the actor was able to distribute phishing emails that looked authentic but included a link that, when clicked, inserted a malicious file used to distribute a backdoor we call NativeZone,” wrote Burt.
“This backdoor could enable a wide range of activities from stealing data to infecting other computers on a network.”
Digital Shadows threat researcher Stefano De Blasi said that Nobelium’s alleged malicious activity exemplified how targeted phishing campaigns still constitute a serious threat against institutions of any kind.
He added: “This campaign is the latest testament to this group’s objective of collecting sensitive and highly valuable information from Western organizations operating in the government and external affairs field.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cyber Pros to Take Part in Charity Challenge to Help Fight Online Crime
Cyber Pros to Take Part in Charity Challenge to Help Fight Online Crime

A new charity initiative, which aims to raise money for two organizations that help tackle online child abuse and cybercrime respectively, has been announced by a group of cybersecurity professionals based in the UK and US.
Infostep 2021 will see 25 volunteers from the Infostep Challenge group of cyber pros walk a total of 19,000 miles , equivalent to a mammoth 42,212,000 steps, over the next six months. This will primarily look to raise funds for the Innocent Lives Foundation, which works with law enforcement to identify sexual predators targeting children online and The Cyber Helpline, which offers free, confidential advice and support service for individuals who have fallen victim to cybercrime.
The Infostep volunteers also hope to use some of the money raised to provide resources for people looking to start a career in cybersecurity.
The challenge originated when Tom Quinn, group IT security services manager for National Express, set a personal post-lockdown goal of walking 70,000 steps per week, which he revealed in a post on LinkedIn. Upon seeing the post, an old colleague of his, Amy Stokes-Waters, who is senior account manager for Cognisys, then reached out to try and get involvement from the wider infosec community. She explained: “I think everyone has had a bit of a lethargic few months. The weather is getting warmer, we’re allowed to get out and about a bit more, and if we can raise money while we’re at it, why not? This really is the infosec community at its finest!”
Commenting on the initiative, Innocent Lives Foundation ambassador and CISO of Ramsey Quantitative Systems, Jonathan Younie, said: “Ultimately, the goal of the Innocent Lives Foundation is to make the world safer for kids. Our team of volunteer technology specialists use OSINT (Open Source Intelligence) to identify predators who target children on the Internet, specifically to generate and distribute CSAM (Child Sexual Abuse Material). We work to provide law enforcement with the information they need to bring these predators to justice, so each dollar raised is used to assist law enforcement in unmasking child predators on the internet.”
Nikki Webb, head of marketing for The Cyber Helpline and global channel manager for Custodian 360, outlined: “Our vision is to ensure the UK is a place where cyber-criminals do not win and our mission is to ensure everyone in the UK has immediate access to expert, cybersecurity help when they need it. Infostep 2021 is an amazing initiative and we are so grateful to be chosen as recipients of some of the funds raised.”
Infostep Challenge added that they are welcoming support from any organization which would like to get involved in the endeavor in some capacity, either through funding or resource donation. Additionally, any individuals who would like to join in with their own personal challenge can follow along using the hashtag #infosteps2021.
Further information can be found at https://infostep.uk/ or via Infostep Challenge’s Twitter account @infostep2021.
As well as Stokes-Waters, Quinn, Webb and Younie, the infosecurity professionals who are taking part in the challenge are the following: Dan Conn, senior software engineer for Mimecast; Scott Winchester, owner of Hax_Shax; Sean Atkinson, director of security assurance at Secarma; Regina Bluman, security analyst at Algolia; Sarah Armstrong-Smith, chief security advisor at Microsoft; Tash Norris, head of cyber security at Moonpig; Paul Taylor, cyber consultancy at ITC Secure; Ryan Surry, director at Intaso; Siân Salmons, trainee cyber security consultant at CAPSLOCK; Cytisus E., senior security engineer at Macys; Lisa Forte, partner at Red Goat Cyber Security; Natasha Harley, co-founder at cyberxperts; Rosie Anderson, head of sales at Honeypot Digital; Rob Croxford, network security consultant; Phillip L., head of sector at ITC Secure; Adrian Tayor, transformation consultant at Deloitte UK; Rob Newby, founder at Procordr; Ste Watts, group head of cyber security operations at Aldermore Bank; Lorna Armitage, co-founder at CAPSLOCK; Dan Komenda, trainee cyber security consultant at CAPSLOCK; Laura Wellstead, co-founder of cyberxperts, Alex Martin, senior business development manager at Cognisys, and Peter Jones, owner at CyberBadger.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
NCSC: Act Now to Protect Streaming Accounts
NCSC: Act Now to Protect Streaming Accounts

The National Cyber Security Centre (NCSC) has warned British internet users to protect their streaming accounts ahead of a summer of sport.
The GCHQ offshoot warned that such accounts can hold a trove of valuable personal and financial information for threat actors to harvest and use to make fraudulent payments or launch follow-on phishing, smishing and vishing scams.
“The UEFA Champions League final will kick off a great British summer of sport and those enjoying it online should be able to do so securely. If accounts aren’t secure, it’s really easy for criminals to access them and then proceed to target people with scam texts and emails,” said NCSC director of policy, Nicola Hudson.
“To help stay protected from this, we would urge people to visit cyberaware.gov.uk for advice on securing accounts and devices and the NCSC’s website for dealing with scam emails and texts.”
The NCSC urged internet users to change their passwords to a strong credential in order to mitigate the risk of credential stuffing, and to pay special care to their email log-ins — if these are hijacked, attackers could reset and change their other passwords. On the Cyber Aware site, it’s also recommended to switch on two-factor authentication.
It also asked users to switch on automatic updates for all apps to address the risk of streaming software being exploited by cyber-criminals.
The past year has seen a spike in the use of streaming services as employees and students were forced to stay home under government-mandated lockdowns.
However, that’s also presented an opportunity for threat actors: in less than a week last April Mimecast said it detected the registration of over 700 suspicious domains designed to impersonate the Netflix brand.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Alert Overload Distressing 70% of SecOps Teams
Alert Overload Distressing 70% of SecOps Teams

Nearly three-quarters of security operations (SecOps) leaders say their home lives are being impacted by the stresses of alert overload, according to a new global study from Trend Micro.
The security vendor polled over 2300 cybersecurity decision-makers that run Security Operations Centers (SOCs) or SecOps from within their IT security function, to compile its report, Security Operations on the Back Foot.
It revealed the inadequacy of current tooling to help them prioritize alerts generated from multiple security controls across the organization.
Over half (51%) said their team is being overwhelmed by the volume of alerts and 55% admitted that they aren’t confident in their ability to prioritize and respond to them. On average, respondents said they’re spending over a quarter (27%) of their time dealing with false positives.
This is taking its toll emotionally: 70% claimed they feel so stressed outside of work that they’re unable to switch off or relax, and are irritable with friends and family.
In the SOC or IT security department, many admitted to turning off alerts (43%), walking away from their computer (43%), hoping another team member will step in (50%), or ignoring alerts entirely (40%).
“We’re used to cybersecurity being described in terms of people, process and technology. All too often, though, people are portrayed as a vulnerability rather than an asset, and technical defenses are prioritized over human resilience,” argued cybersecurity researcher Victoria Baines.
“It’s high time we renewed our investment in our human security assets. That means looking after our colleagues and teams, and ensuring they have tools that allow them to focus on what humans do best.”
The figures chime with research from Sumo Logic last year which revealed that 99% of organizations are experiencing high volumes of alerts which cause issues for SecOps teams. A further 83% admitted this leads to alert fatigue for staff.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk