Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Smishing: Why Text-Based Phishing Should Be on Every CISO’s Radar
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Babuk Ransomware Gang Targets Washington D.C. Police
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Second Click Here to Kill Everybody Sale
For a limited time, I am selling signed copies of Click Here to Kill Everybody in hardcover for just $6, plus shipping.
I have 600 copies of the book available. When they’re gone, the sale is over and the price will revert to normal.
Order here.
Please be patient on delivery. It’s a lot of work to sign and mail hundreds of books. I try to do some each day, but sometimes I can’t. And the pandemic can cause mail slowdowns all over the world.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Security Vulnerabilities in Cellebrite
Moxie Marlinspike has an intriguing blog post about Cellebrite, a tool used by police and others to break into smartphones. Moxie got his hands on one of the devices, which seems to be a pair of Windows software packages and a whole lot of connecting cables.
According to Moxie, the software is riddled with vulnerabilities. (The one example he gives is that it uses FFmpeg DLLs from 2012, and have not been patched with the 100+ security updates since then.)
…we found that it’s possible to execute arbitrary code on a Cellebrite machine simply by including a specially formatted but otherwise innocuous file in any app on a device that is subsequently plugged into Cellebrite and scanned. There are virtually no limits on the code that can be executed.
This means that Cellebrite has one — or many — remote code execution bugs, and that a specially designed file on the target phone can infect Cellebrite.
For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in any arbitrary way (inserting or removing text, email, photos, contacts, files, or any other data), with no detectable timestamp changes or checksum failures. This could even be done at random, and would seriously call the data integrity of Cellebrite’s reports into question.
That malicious file could, for example, insert fabricated evidence or subtly alter the evidence it copies from a phone. It could even write that fabricated/altered evidence back to the phone so that from then on, even an uncorrupted version of Cellebrite will find the altered evidence on that phone.
Finally, Moxie suggests that future versions of Signal will include such a file, sometimes:
Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding.
The idea, of course, is that a defendant facing Cellebrite evidence in court can claim that the evidence is tainted.
I have no idea how effective this would be in court. Or whether this runs foul of the Computer Fraud and Abuse Act in the US. (Is it okay to booby-trap your phone?) A colleague from the UK says that this would not be legal to do under the Computer Misuse Act, although it’s hard to blame the phone owner if he doesn’t even know it’s happening.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Digital Estate Planning – What to Do With Your Digital Assets
While we’re enjoying the fruits of digital life—our eBooks, movies, email accounts, social media profiles, eBay stores, photos, online games, and more—there will come a time we should ask ourselves, What happens to all of this good stuff when I die?
Like anything else we own, those things can be passed along through our estates too.
With the explosion of digital media, commerce, and even digital currency too, there’s a very good chance you have thousands of dollars of digital assets in your possession. For example, we can look at research we conducted in 2011 which found that people placed an average value of $37,438 on the digital assets they owned at the time. Now, with the growth of streaming services, digital currency, cloud storage, and more in the past ten years, that figure feels conservative.
Enter the notion of a digital legacy, the way you can catalog and prepare your digital assets for passing through your estate.
Getting started with estate planning for your digital assets
Like so many aspects of digital life nowadays, estate planning law has started to catch up to the realities that attorneys, executors, and heirs face when dealing with an estate and its digital assets. In the U.S., new laws are rolling out that address how digital assets are treated when the owner passes away. For example, they give fiduciaries (like an estate executor, trustee, or an agent under a power of attorney) the right to manage a person’s digital assets if they already have the right to manage a person’s tangible assets. Such laws continue to evolve, and they can vary from state to state here in the U.S.
With that in mind, nothing offered in this article is legal advice, nor should it be construed as such. For legal advice, you can and should turn to your estate attorney for counsel on the best approach for you and the laws in your area. However, consider this article as a sort of checklist that can help you with your estate planning.
My hope is that this article will open your eyes to the digital value you have to pass along, both real and sentimental, and help you prepare your estate accordingly for the ones you care about.
What are digital assets in a will?
The best answer you can get to this question will come from your legal counsel. However, for purposes of discussion, a digital asset is any text or media in digital form that has value and offers the bearer with the right to use it.
To frame it up in everyday terms, let’s look at some real-world examples of digital assets that quickly come to mind. They include but are not limited to:
- Photo libraries
- eBook libraries
- Digital movies
- Digital music
- Digital currency, such as bitcoin
- Air miles
- Hotel points
However, digital assets can readily expand to further include:
- Subscriptions to streaming services and online publications
- Online game accounts—and in-game items associated with them
- Currency stored in online payment platforms
- Online storefronts, such as eBay, Etsy, or business websites
- Website domain names, whether in use or held speculatively for later resale
- Documents kept in cloud storage, like financial documents and ancestry research
And as far as your estate is concerned, you can also consider:
- Online banking and financial accounts
- Email accounts
- Chatrooms and message boards for your interests and hobbies
- Medical and insurance accounts
- Blogs
- Utility accounts
- And any other similar accounts that may help your executor manage your estate
That’s quite the list, and it’s not entirely comprehensive, either.
Start with an inventory of your digital assets
The process of lining up your digital assets begins just like any other aspect of estate planning, by listing all the digital assets and accounts you own. From there, you can see what you have and what you’d like to distribute—and what you can distribute. In fact, when it comes to digital, there are some things you simply can’t pass along. Let’s take a closer look.
What digital assets can you pass along through your will?
Generally speaking, digital assets that you own can be passed along. “Own” is the operative word here. Many digital things we have are in fact licensed to us, which are not transferrable. More on that next, yet examples of things you can likely transfer include:
- Funds kept in an online payment account like PayPal or Venmo.
- Funds due to you via an online store you maintain.
- Cryptocurrency, like bitcoin.
- Digital music that you’ve purchased and own.
Check with your legal counsel to ensure you’re following the letter of the law in your region, and also look into any licensing agreements you may have for items like internet domain names and airline miles that you may hold to determine if they are in fact transferrable.
What digital assets are non-transferrable through your will?
This is an important topic. As mentioned above, some accounts you hold are simply licensed to you and you alone. Thus, they will not transfer. Two of the biggest examples are social media and email accounts. This can have serious repercussions if you do not leave specific instructions as to how those accounts should be handled after your passing.
For example, do you want your social media profiles to remain online as a memorial or do you want them simply to shut down? Note that different social media platforms have different policies for handling the accounts of users who have passed away. For example, Facebook allows for creating memorialized accounts that allow friends and families to continue sharing memories. Policies vary, so check with your social media platforms of choice for specifics.
Likewise, will your executor need access to your email account to handle affairs of the estate? And what about access to online accounts for paying bills and then ultimately closing those accounts? In all, these are points of discussion to have with an experienced estate attorney who knows the law in your region.
Other things to be aware of are that subscriptions to streaming accounts are likely non-transferrable as well. Often, eBooks and digital publications you own are only licensed to you as the sole owner and can’t be transferred. Again, check the agreements associated with items like these and have a talk with your attorney about them to determine what can and can’t be done with them.
Blogs and online communities
Another aspect of your digital legacy is your voice. If you’re a blogger or a participant in an online community, you may wish for a fiduciary or family member to leave a farewell post. Additionally, in the case of a blog, you may want to set up some means for your work to stay online or get archived in some manner. Again, you can work with your attorney to leave specific instructions as to what should be said and then what should be done with the blog or site in question.
Giving your executor access to your digital assets
I have a real-life example of why this is so vital. A friend of mine lost the photos of her and her husband because they were kept in an online storage account to which she had no access. And sadly, the company would not grant her access after his passing. This is often the case with many online accounts and services. Legally speaking, while the deceased may have owned the storage account and the media kept within it, the cloud storage company owns the servers on which that media is stored. The potential difficulty here is that the online service provider may view giving your personal representatives access to your account as a breach of their privacy policy or user agreements.
One way you can avoid heartbreak like this is to discuss giving your executor access to your accounts. This can be provided through a list of accounts, usernames, and passwords that are kept in a sealed letter along with your will, along with instructions that outline your wishes. This is important: a will is public record after you pass away. You won’t want info like usernames and passwords getting out there. Again, you can discuss an option such as this with your attorney.
Protecting your digital assets
One thing you can do today that can protect your digital assets for the long haul is to use comprehensive security protection. Far more than just antivirus, comprehensive security can store precious and important files securely with encryption, arm all your online accounts with strong passwords, and protect your identity as well. Features like these will help you see to it that your digital legacy is secure.
Make a plan
When I’ve brought up the idea of a digital legacy with friends, a light goes on in their head. “Of course, that makes a lot of sense.” It’s easy to take our digital possessions somewhat for granted, perhaps in a way that we simply don’t with our physical possessions. Yet as you can see, there’s a good chance that you indeed have a digital legacy to pass along. By getting organized now, you can see to it that your wishes are followed, and I hope this checklist helps you get started.
Stay Updated
To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.
The post Digital Estate Planning – What to Do With Your Digital Assets appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Security Approach to Cloud-Native Applications
With on-premises infrastructure, securing server workloads and applications involves putting security controls between an organization’s network and the outside world. As organisations migrate workloads (“lift and shift”) to the cloud, the same approach was often used. On the contrary to lift and shift, many enterprise businesses had realized that in order to use the cloud efficiently they need to redesign their apps to become cloud-native. Cloud native is an approach to building and running applications that exploits the advantages of the cloud computing delivery model. Cloud native development incorporates the concepts of DevOps, continuous delivery, microservices, and containers.
”IDC predicts, by 2025, nearly two-thirds of enterprises will be prolific software producers with code deployed daily, over 90% of new apps cloud native, 80% of code externally sourced, and 1.6 times more developers”
Monolithic Apps vs Cloud Native Apps
So, how do you ensure the security of your cloud–native applications?
Successful protection of cloud-native applications will require a combination of multiple security controls working together and managed from one security platform. First, the cloud infrastructure where is the cloud-native application is running (containers, serverless functions and virtual machines) should be assessed for security misconfigurations (security posture ), compliance and for known vulnerabilities. Second, securing the workloads needs a different security approach. Workloads are becoming more granular with shorter life spans as development organizations adopt DevOps-style development patterns. DevOps delivers faster software releases , in some cases, several times per day. The best way to secure these rapidly changing and short-lived cloud-native workloads is to start their protection proactively and build security into every part of the DevOps lifecycle.
Cloud Security Posture Management (CSPM):
The biggest cloud breaches are caused by customer misconfiguration, mismanagement, and mistakes. CSPM is a class of security tools to enable compliance monitoring, DevOps integration, incident response, risk assessment, and risk visualization. It is imperative for security and risk management leaders to enable cloud security posture management processes to proactively identify and address data risks.
Cloud Workload Protection Platforms (CWPP):
CWPP is an agent-based workload security protection technology. CWPP addresses unique requirements of server workload protection in modern hybrid data center architectures including on-premises, physical and virtual machines (VMs), and multiple public cloud infrastructure. This includes support for container-based application architectures.
What is MVISION CNAPP
MVISION CNAPP is the industry’s first platform to bring application and risk context to converge Cloud Security Posture Management (CSPM) for multi public cloud infrastructure, and Cloud Workload Protection (CWPP) to protect hybrid, multi cloud workloads including VMs, containers, and serverless functions. McAfee MVISION CNAPP extends MVISION Cloud’s data protection – both Data Loss Prevention and malware detection – threat prevention, governance and compliance to comprehensively address the needs of this new cloud-native application world thereby improving security capabilities and reducing the Total Cost of Ownership of cloud security.
7 Key elements of MVISION CNAPP:
1. Single Hybrid multi cloud security platform: McAfee MVISION Cloud simplify multi-cloud complexity by using a single, cloud-native enforcement point. It’s a comprehensive cloud security solution that protects and prevents enterprise and customer data, assets and applications from advanced security threats and cyberattacks across multiple cloud infrastructures and environments.
2. Cloud Security Posture Management: McAfee MVISION Cloud provide a continuous monitoring for multi cloud IaaS / PaaS environments to identify gaps between their stated security policy and the actual security posture. At the heart of CSPM is the detection of cloud misconfiguration vulnerabilities that can lead to compliance violations and data breaches.
3. Deep discovery and risk based application:You can’t protect what you can’t see. Discovering all cloud resources and prioritise them based on the risk. MVISION CNAPP uniquely provided deep discovery of all workloads, data, and infrastructure across endpoint, networks, and cloud. If you can quickly understand those risks relative to each other, you can quickly prioritize your remediation reducing overall riskMas quickly as possible.
4. Shift Left posture and vulnerability:By moving security into the CI/CD pipeline and make it easy for developers to incorporate into their normal application development processes and ensuring that applications are secure before they are ever published reduces the chance of introducing new vulnerabilities and minimizing threats to the organization.
5. Zero Trust policy control: McAfee’s CNAPP solution supported by CWPP focus on Zero Trust network and workload policies. This approach not only allows you to gain analytics about who is accessing your environment and how an important component of your SOC strategy but it also ensures that people and services have appropriate permissions to perform necessary tasks.
6. Unified Threat Protection:CWPP unifies threat protection across workloads in the cloud and on-premise. Including OS Hardening, Configuration and Vulnerability Management, Application Control/Allow-Listing and File Integrity control. It also synthesizes workload protections and account permissions into the same motion. Finally, by connecting cloud-native application protection to XDR, you are able to have full visibility, risk management, and remediation across your on-premise and cloud infrastructures.
7. Governance and Compliance:The ideal solution for protecting cloud-native applications includes the ability to manage privileged access and address threat protection for both workloads and sensitive data, regardless of where they reside
Business value:
- One Cloud Security Platform for all your CSPs
- Scan workloads and configurations in development and protect workloads and configurations at runtime.
- Better security by enabling standardization and deeper layered defenses.
- The convergence of CSPM and CWPP
IDC FutureScape: Worldwide IT Industry 2020 Predictions
https://www.idc.com/research/viewtoc.jsp?containerId=US45599219
The post New Security Approach to Cloud-Native Applications appeared first on McAfee Blogs.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Nintendo Sues Bowser
Nintendo Sues Bowser

A lawsuit has been filed by Nintendo of America against the alleged leader of an international video game piracy group.
Canadian national Gary Bowser was arrested in October last year on suspicion of heading a criminal enterprise called Team Xecuter that the United States Department of Justice said created and sold illegal hacking devices.
The circumvention devices enabled users to hack popular video game consoles, including the Nintendo Switch, the Nintendo 3DS, and the Nintendo Entertainment System Classic Edition, so they could be used to play unauthorized, or pirated, copies of authentic gaming titles.
Bowser and his alleged co-conspirator, Frenchman Max Louarn, were each charged with 11 felony counts, including conspiracy to commit wire fraud, wire fraud, conspiracy to circumvent technological measures and to traffic in circumvention devices, trafficking in circumvention devices, and conspiracy to commit money laundering.
Charges were filed by Nintendo of America’s president, Doug Bowser, against Gary Bowser in a western Seattle District Court on Friday, April 16, in what Mario enthusiasts might call a real-life Battle of Bowsers.
In the suit, Gary Bowser is accused of running a “pirate operation” that infringed Nintendo’s copyright by creating and selling hacks.
Nintendo alleges that Bowser “has been a leader in the hacking and piracy community targeting Nintendo’s intellectual property more broadly for many years” and “has trafficked in circumvention devices and helped facilitate infringement of Nintendo video games not only on the Nintendo Switch, but also on earlier consoles, including the Nintendo DS, released in 2004, the Wii, released in 2006, and the Nintendo 3DS, released in 2011.”
In May last year, Nintendo filed two intellectual property complaints in US courts against online stores selling Team Xecuter devices, which the gaming company said violated the anti-circumvention provisions of the Digital Millennium Copyright Act (DMCA).
The first complaint, against a site called UberChips, was settled in October with a $2m payment, though UberChips’ owner denied any wrongdoing. UberChips was ordered by an Ohio court to destroy its stock of circumvention devices and give Nintendo its domain name.
The second lawsuit was filed in Washington against eight different stores that Nintendo said were selling circumvention devices.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cyber-attack on NBA Team
Cyber-attack on NBA Team

An investigation has been launched after cyber-criminals targeted one of the 30 teams in America’s National Basketball Association.
Cybersecurity experts hired by the Houston Rockets are working closely with the Federal Bureau of Investigation to determine the precise nature and extent of the security incident.
Reuters reports that an unknown attacker tried to install ransomware on the basketball franchise’s internal computer systems but was largely unsuccessful.
“The Rockets organization recently detected suspicious activity on certain systems in its internal network. We immediately launched an investigation,” said team spokesperson Tracey Hughes.
Cyber-defenses put in place by the team before the attack were effective in limiting the destruction wrought by the malware.
“Our internal security tools prevented ransomware from being installed except for a few systems that have not impacted our operations,” said the basketball team.
The Rockets said that while the full scope of the attack was yet to be determined, no signs had been detected so far to suggest that threat actors had acquired any sensitive data belonging to the team.
“While this investigation is ongoing, the incident has had no impact to our operations or our ability to take care of our fans, employees, and players,” said the team.
Bloomberg reported that the hacking group Babuk claimed to have exfiltrated 500 gigabytes of data belonging to the Houston Rockets. Babuk alleged that the information it had swiped from the team included financial data, non-disclosure agreements, and contracts.
The gang claimed on its dark web page that it would not return the data to the basketball franchise until a ransom was paid. In a message that was later moved, the gang said that failure to pay would result in the publication of the stolen information.
The team said that if the investigation reveals that any personal data was stolen, then those affected will be notified.
Significant Houston entities to suffer a data breach include the Memorial Hermann Health System and the Texas Children’s Hospital. In 2020, a ransomware attack against the Texas court system left the network temporarily disabled.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk