Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Ryuk Ransomware Attack Sprung by Frugal Student
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Massive DDoS Attack Disrupts Belgium Parliament
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
The Story of Colossus
Nice video of a talk by Chris Shore on the history of Colossus.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Defending Cybersecurity Can’t Be Done Blindfolded–The EU’s NIS2 Review Can Set This Right
Cybercriminals are currently enjoying a golden age, with the volume and severity of attacks growing constantly, and an ability to commit hostile acts with impunity. The EU, in its overhaul of cybersecurity laws dubbed NIS2, is committed to ensuring that what’s illegal offline should also be illegal online. For that to happen, cybersecurity researchers need to have access to all the tools possible to detect, trace and prevent crime online, including access to the Internet’s yellow pages, also known as the WHOIS search.
Cyberthreat research is both an arts and science discipline. Our experts and software detection analysis in the ATR group sift through an enormous amount of data, from a broad range of sources, to detect the signs of a past, ongoing or future cyberattack. Each source of data that is out of reach is one tool less with which to keep up with cybercriminals. Access to the full set of WHOIS data, or lack thereof, is not going to make or break the future of cyber threat research. But it would give criminals an advantage, which is at odds with the core objective of the EU’s cybersecurity review.
The WHOIS search originally contained all the data of a person registering a website, including the contact details of the person responsible for the website. This information is crucial in the event a legitimate website comes under attack from malicious actors
But by continually scanning the registration data, cyber researchers can also pick up patterns that are indicative of malicious activity, such as preparing a botnet or priming a large number of websites ahead of a denial-of-service (DDOS) attack.
Using WHOIS data is particularly useful in preventing future cyber-incidents. Looking at data that indicates that a website or collection of websites are being rigged for a cyberattack can help stop the attack in its cradle. This data can also help cybersecurity researchers minimise the risk of false positives, where the contact data is consistent with a legitimate user, which will minimise the potential disruption for companies and people that have done nothing wrong but whose websites may have been flagged as suspicious.
This data was put out of reach after the EU’s GDPR law came into force, with the unfortunate and clearly unintended consequence of depriving cybersecurity researchers, law enforcement agencies and others from an important pool of data used to fight and prevent cybercrime.
With the review of the EU’s cybersecurity law, NIS2, we have a chance to set things right, by providing a legal basis to access personal data such as the contact details in the WHOIS, for the purpose of fighting crime online, without undermining the important privacy protections introduced in the GDPR. It is now up to lawmakers to ensure that this provision remains intact, as they consider whether to introduce amendments to the cybersecurity legislation text.
The post Defending Cybersecurity Can’t Be Done Blindfolded–The EU’s NIS2 Review Can Set This Right appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Beware of Social Media Scams
Social media is a great place to connect with friends and family. Unfortunately, it is also a great place for misinformation to run rampant, and it is a virtual treasure chest for cybercriminals to steal personal information. Over 25 million Canadians own a social media account, and more than 80% of the Canadian population is expected to be on social media by 2025.
Check out this roundup of common social media scams so you can network intelligently, spot misinformation, and stop its spread.
1. Misinformation
The classic saying of “Don’t believe everything you see on TV” applies neatly to “Don’t believe everything you read on social media.” There is a resurgence of false news reports circulating on social media surrounding COVID-19 and the vaccine. For example, 5G aiding the spread of the virus and the preventive properties of garlic are just two of the rumors about COVID-19.
Misinformation leads to chaos and is a major threat to public health. Before you reshare a post or article, it is great to take a few minutes to digest the message, determine if it is true, and ask yourself if friends and family would genuinely benefit if they heard the news it carries.
There are a few tell-tale signs of fake news posts. First, they often try to inspire extreme emotions, such as rage and indignation, to prompt people to share immediately. Next, fake news reports are frequently poorly written and vague about where they received their information. Always try to find the primary source for “facts.” In the case of COVID-19 news, all health tips should be sourced from a licensed medical professional.
If you are ever in doubt about the facts, especially when they deal with public health, do not share the post. Instead, leave the reporting to trained medical professionals. Consult the World Health Organization and the Public Health Agency of Canada or direct your network to #ScienceUpFirst for the latest and most accurate reports about COVID-19 and the vaccine.
2. Data Leaks
There was a recent data leak at Facebook, and the contents of about half a billion accounts were posted on a hacking website, including 3.49 million Canadian accounts. Hackers can get a lot of mileage out of just one social media profile because it contains all the greatest hits of information needed to verify an identity.
Most profiles list your real full name, birthday, your relationship status, your hometown, and contact information. Also, hackers can skim a user’s posting history to find even more personal details. Many social media users have posted at one time or another a “get to know you” post, where they list many revealing facts. These posts are a pot of gold to cybercriminals. They are basically lists of possible answers to security questions: Where did you go to primary school? What was the model of your first car? What is the name of your favorite stuffed animal?
Another recent trend that can make you vulnerable in case of a data leak is posting COVID-19 vaccine cards. Social media users are excited to share the big milestone of getting their first shot. What they might not realize is that vaccine cards contain vital personal information that could be used by malicious actors. There are alternative ways to share the happy news. Instead, post a picture of the fun bandage the nurse put on your arm or take a selfie outside of the vaccination center.
It is a shame that what you share on social media can be turned against you by cybercriminals, but that does not mean you have to stop sharing details about your life. Instead of posting personal details online that could be used maliciously in the event of a data leak, think about creating an exclusive email newsletter or secure group chat for your closest friends and family.
3. Contest Scams
There is a major thrill when you think you have won something; however, if you receive a notification on social media that you have won a contest, reserve your excitement until you have confirmed its legitimacy. Be especially wary if you do not remember entering a contest.
Contest scams are a type of social engineering tactic used by cybercriminals. Social engineering relies on people’s tendency to trust others. Cybercriminals often capitalize upon extreme emotions, like fear, urgency, and in this case excitement, to trick unsuspecting people into hastily giving up sensitive information.
Phishing is also common in contest scams. Social media users may receive a message that they have won a giveaway and to click on a link to claim their prize. Luckily, easy-to-spot signs of a phishing message include poor grammar, misspellings, and a sense of urgency. Always approach these types of messages with caution. Instead of clicking on any of the links, hover your cursor over them to see where they redirect. If the redirect site URL is suspicious and contains misspellings, steer clear.
If you ever receive a notification on social media that you have won a prize, remain skeptical until you have verified the authenticity. Locate the organization’s official social media page (which you can likely find on their website), and direct message them for more details.
How to Network Safely
With all of these common scams floating about and waiting to strike, check out these tips to network safely.
1. Consider how much you share
The joy of social media is sharing your everyday life with your friends and family. It is fun to have dozens of people wish you a happy birthday on your profile, but consider removing the year of your birthday. Also, consider removing your phone number, home address, and email address from your profile. If a friend or family member wants to get in touch with you, they can personally direct message you. Cybercriminals can take your contact information and full birthday and use it to steal your identity, so it is best not to post it online.
2. Confirm the truth before sharing
While you may want to share the latest news with your networks, do not share information that you are not sure is true. According to Statistics Canada, only half of Canadians investigated the accuracy of COVID-19 social media posts before they reshared. Do your due diligence and be a part of the solution, not part of the problem.
3. Protect your devices from viruses and malware
Even if you are a diligent and intelligent social media user, there is a chance that you could accidentally click on a phishing link. In case this happens, you should have a backup plan to safeguard your devices and your personal information from viruses and malware. Protect your devices with a comprehensive antivirus program, such as McAfee Total Protection. You can rest assured that if you or a member of your family accidentally opens a malicious link, your devices will be safe.
Stay Updated
To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.
The post Beware of Social Media Scams appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Homecoming Queen Hacker to be Tried as an Adult
Homecoming Queen Hacker to be Tried as an Adult

A teenager from Florida who allegedly hacked into the accounts of Pensacola high school students to cast fraudulent homecoming court votes for herself is facing felony charges.
Tate High School homecoming queen Emily Rose Grover allegedly teamed up with her mother, 50-year-old Laura Rose Carroll, to cast nearly 250 fake votes. Carroll works as an assistant principal at Bellview Elementary School in Escambia County.
Agents with the Florida Department of Law Enforcement (FDLE) arrested Pensacola residents Carroll and Grover on March 15, 2021.
Each defendant was charged with one count each of offenses against users of computers, computer systems, computer networks, and electronic devices (a third-degree felony), unlawful use of a two-way communications device (a third-degree felony), criminal use of personally identifiable information (a third-degree felony), and conspiracy to commit these offenses (a first-degree misdemeanor).
An investigation into the homecoming election was instigated in November 2020 when the Escambia County School District contacted local police to report unauthorized access into hundreds of student accounts.
The investigation found that Carroll and her daughter had accessed 246 student FOCUS accounts. The accounts are part of the FOCUS program, the school district’s student information system, to which Carroll had district-level access.
“In October 2020, hundreds of votes for Tate High School’s Homecoming Court voting were flagged as fraudulent, with 117 votes originating from the same IP address within a short period of time,” said a FDLE spokesperson.
“Agents uncovered evidence of unauthorized access to FOCUS linked to Carroll’s cell phone as well as computers associated with their residence, with a total of 246 votes cast for the Homecoming Court.”
When police interviewed students at Grover’s high school, many of them reported hearing Grover describe how she had used her mother’s FOCUS account to cast homecoming queen votes for herself.
“The investigation also found that beginning August 2019, Carroll’s FOCUS account accessed 372 high school records and 339 of those were of Tate High School students,” said the FLDE.
The county’s State Attorney’s Office has reportedly stated that eighteen-year-old Grover, who was aged 17 at the time of the alleged offense, will be tried as an adult when her case comes to court next week..
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Panda Stealer Targets Crypto Wallets
Panda Stealer Targets Crypto Wallets

A new information stealer is going after cryptocurrency wallets and credentials for applications including NordVPN, Telegram, Discord, and Steam.
Panda Stealer uses spam emails and the same hard-to-detect fileless distribution method deployed by a recent Phobos ransomware campaign discovered by Morphisec.
The attack campaign appears to be primarily targeting users in Australia, Germany, Japan, and the United States.
Panda Stealer was discovered by Trend Micro at the start of April. Threat researchers have identified two infection chains being used by the campaign.
They said: “In one, an .XLSM attachment contains macros that download a loader. Then, the loader downloads and executes the main stealer.
“The other infection chain involves an attached .XLS file containing an Excel formula that utilizes a PowerShell command to access paste.ee, a Pastebin alternative, that accesses a second encrypted PowerShell command.”
Once installed, Panda Stealer can collect details like private keys and records of past transactions from its victim’s various digital currency wallets, including Dash, Bytecoin, Litecoin, and Ethereum.
Other cards up Panda’s sleeve are the ability to take screenshots of the infected computer and the power to exfiltrate data from browsers, like cookies, passwords, and cards.
Researchers linked the campaign to an IP address assigned to a virtual private server rented from Shock Hosting. Shock Hosting said that the server assigned to this address has been suspended.
Panda Stealer was determined to be a variant of Collector Stealer, cracked by Russian threat actor NCP, also known as su1c1de.
“Because the cracked Collector Stealer builder is openly accessible online, cybercriminal groups and script kiddies alike can use it to create their own customized version of the stealer and C&C panel,” noted researchers.
While the two stealers behave similarly, they have different command and control server URLs, build tags, and execution folders.
CTO Michael Gorelik, who heads the threat intelligence team for Morphisec, has seen the number of infostealers shoot up since the Emotet network was disrupted.
When analyzing the different types of attacks Morphisec detected across seven million enterprise endpoints over the last 12 months, Gorelik found that infostealers made up the highest percentage of attempted endpoint attacks (31%).
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Poor Working Relationships Between Security and Networking Teams Preventing Benefits of Digital Transformation
Poor Working Relationships Between Security and Networking Teams Preventing Benefits of Digital Transformation

Organizations’ digital transformation projects are being held back through lack of collaboration between security and networking teams, according to a new study by Netskope.
The survey of IT professionals in the UK, France, and Germany, undertaken by Censuswide on behalf of the cloud security firm, revealed that two key components of IT teams—networking and security—often have a poor working relationship. Despite nearly half (45%) of security and networking teams operating within the same group and reporting to a common boss, 43% of those surveyed stated that “the security and networking teams don’t really work together much.”
An even higher proportion (44%) of IT pros described the relationship between these teams in negative terms—”combative” (13%), “dysfunctional” (10%), “frosty” (10%), or “irrelevant” (10%).
This appears to be having major consequences, with more than half (51%) of participants agreeing that lack of collaboration between specialist teams is preventing their organization from experiencing the benefits of digital transformation. This figure rose to 54% when focusing on the responses of CIOs.
The findings come in the context of a surge in new or accelerated digital transformation projects in the past year brought about by the COVID-19 crisis, which has forced many organizations to change the way they operate. Undertaking such transformations safely requires close collaboration with security teams.
More encouragingly, the network and security professionals surveyed highlighted the same top three priorities for driving their team’s activity in 2021, which are “supporting increased productivity for the organization as a whole,” “increasing visibility and control,” and “expansion of infrastructure to support business growth.” Additionally, the survey found that digital transformation projects are being regularly pursued by both teams, with 85% of all participants either working on such a project or having just completed one.
Andre Stewart, VP and MD EMEA at Netskope, commented: “All big companies have their politics and often different divisions compete for budget or strategic importance at the board level but digital transformation is happening now. A more dispersed workforce using a greater number of apps for greater efficiency is creating exponential data growth and a much broader attack surface for hackers. That means network transformation and security transformation must happen now with digital transformation.
“Given this evident divide between networking and security teams CEOs and/or CIOs must get involved or the progress and competitive advantage that could be reaped from digital transformation will be weak.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cyber-Attack on Belgian Parliament
Cyber-Attack on Belgian Parliament

A coordinated cyber-attack has been carried out against Belgium’s parliament, scientific institutions, police services, and universities.
Internet service provider Belnet, which serves the country’s government agencies, fell victim to what it described as a “large-scale attack” on Tuesday.
At around 11:00am CEST, the company was hit by a distributed denial of service (DDoS) attack that overloaded its servers, preventing the availability of online services. Websites with .be domains were impacted.
As a result of the hack, around 200 Belnet customers lost internet access, either partially or totally. News outlet VRT was among the organizations affected.
“The attack is still in progress and takes place in successive waves,” Belnet said in an update on Wednesday morning.
“Our teams are working hard to mitigate them. We are constantly monitoring our network to counter any new attempts.”
Belnet said that no data had been stolen or exfiltrated during the attack and that no personal information had been compromised.
Some websites, including the official site of the City of Brussels, remain down, while others, including the site for the Brussels Police, are back online.
The attack disrupted the workings of the Belgian parliament, causing several meetings to be postponed. Distance learning at some universities and colleges was impacted by unstable connections.
The Brussels Times reports that local transit company STIB had issues with ticket sales because of the attack.
Belgian member of parliament Wouter De Vriendt observed that the cyber-attack coincided with Uighur concentration camp witness Qelbinur Sidiq appearing in the Chamber to publicly give testimony for the first time about the abuse of Uighur minorities by the People’s Republic of China.
“Conclusions about the cyber-attack are premature. But it is important to identify that sensitive context. Denying that is naïve,” said De Vriendt.
Belnet is working to determine who is behind the massive surge in data flow.
“We cannot expect to know tomorrow who is behind it,” said Belnet director Dirk Haex. “It is a very complex analysis that has to be done.”
Commenting on the attack, Nominet government cybersecurity expert Steve Forbes said: “The DDoS attack against Belgium’s government IT network shows how a relatively rudimentary attack can have a serious impact on a national scale.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk