Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Data from 500M LinkedIn Users Posted for Sale Online
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Jurassic Squid and Prey
A 180-million-year-old Vampire squid ancestor was fossilized along with its prey.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Backdoor Added — But Found — in PHP
Unknown hackers attempted to add a backdoor to the PHP source code. It was two malicious commits, with the subject “fix typo” and the names of known PHP developers and maintainers. They were discovered and removed before being pushed out to any users. But since 79% of the Internet’s websites use PHP, it’s scary.
Developers have moved PHP to GitHub, which has better authentication. Hopefully it will be enough — PHP is a juicy target.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
College Track Coach Accused of Cyberstalking
College Track Coach Accused of Cyberstalking

Police in Chicago have arrested a former track and field coach for allegedly soliciting sexually explicit images from female athletes under false pretenses.
Chicago resident Steve Waithe was arrested on April 7 and charged with one count of wire fraud and one count of cyberstalking.
Waithe attended Loch Raven High School, where he was the Maryland State Champion in the triple jump. From 2014–15, the 28-year-old competed on Penn State’s track and field team.
Coaching positions at Illinois Institute of Technology and the University of Tennessee followed, and in October 2018, Waithe began working with athletes at Northeastern University. However, Waithe was fired in February 2019 following an investigation into “inappropriate conduct toward female student-athletes.”
According to the Department of Justice, “it is alleged that during that time, Waithe frequently requested to use female athletes’ cellphones under the pretense of filming their form at practice and at meets. At times, he was observed ‘scrolling through’ the phones.”
In September 2019, Waithe accepted a new coaching position at Concordia University Chicago, which lasted fewer than four months, according to the Associated Press.
It is alleged that in February 2020, Waithe began using social media to contact female Northeastern University track and field athletes. After telling the women that he had discovered compromising photos of them online, Waithe allegedly offered to help remove the images from the internet.
Victims were allegedly tricked into sending Waithe nude or semi-nude photos so he could perform “reverse image searches.”
To disguise his identity online, Waithe allegedly used various pseudonyms, including variations of the phrase “Privacy Protector,” “Katie Janovich,” and “Anon.”
Waithe is further accused of posing as a female researcher to email female athletes and ask them for photographs of themselves nude or in swimwear for the purposes of “athlete research” or “body development study.”
According to court documents, investigators have identified more than 10 victims of the fake research scheme and found over 300 related nude and semi-nude images of victims in Waithe’s email accounts.
It is further alleged that from at least June 21, 2020, to October 3, 2020, Waithe used social media to cyberstalk at least one female Northeastern student-athlete and hacked into her Snapchat account.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Stimulus Stimulates Unemployment Scams
Stimulus Stimulates Unemployment Scams

The number of suspicious unemployment-related emails targeting Americans rose by 50% after the third round of stimulus checks was announced in late February, according to new data from Tessian’s threat intelligence team.
News of the phishing surge comes after the United States Department of Justice warned that fraudsters are creating websites mimicking unemployment benefit websites, including state workforce agency (SWA) websites, “for the purpose of unlawfully capturing consumers’ personal information.”
Threat researchers found that during the week of February 24, when the third stimulus package was announced, the number of suspicious unemployment- and Covid-19-related emails was 50% higher than the previous week.
During this same week, the number of shady unemployment and Covid-19 emails was 40% higher than the weekly average for these types of threats detected since the start of 2021. In particular, the number of unemployment-themed emails alone increased by 16% above the weekly average.
In the week commencing March 8, when Covid-19 stimulus checks started being received, researchers noted that the number of suspicious unemployment- and Covid-related emails was 51% higher than the weekly average.
Tessian CEO Tim Sadler said that cyber-criminals exploit the fact that many people turn to the internet for support and to seek new employment opportunities after losing their job.
“To identify their targets, bad actors will often turn to LinkedIn and social media posts,” said Sadler.
“A recent report from Tessian found that 93% of people share job updates online, and while it’s common for people to let their networks know that they’ve been laid off and are looking for jobs, they are also unknowingly giving cybercriminals the information they need to craft these types of social engineering attacks.”
In March, the unemployment rate in the United States stood at 6%, 2.5 percentage points higher than its pre-pandemic level in February 2020. At 9.7 million, the number of unemployed persons is four million higher than in February 2020.
Unemployment scams are an effective way for cyber-criminals to make money. Bloomberg reported that the US Unemployment System has lost at least $63 billion in improper payments since last year, according to estimates by a watchdog for the US Department of Labor.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Americans Avoid Sites After Forgetting Passwords
Americans Avoid Sites After Forgetting Passwords

Nearly two-thirds of Americans avoid using websites or accounts for which they have forgotten their password, according to new research published today by LastPass.
The password manager and Vault app maker commissioned OnePoll to survey 2,005 Americans about their password habits.
According to LastPass, the results show that the “long-standing trend of poor password behavior persists despite increasing risks online.”
Almost two-thirds (64%) of survey respondents admitted that they would avoid visiting certain websites or accounts where they’ve forgotten their password.
Over half (57%) said that if their phone was lost, broken, or stolen, they’d be locked out of most of their accounts.
The survey identified that the majority of Americans have suffered from password-related anxiety, with 65% of respondents reporting that they have experienced a moment of panic when they realized their computer or mobile device didn’t have a password stored for a website that they wanted to log into.
Managing multiple passwords proved to be a challenge for many Americans, with seven in ten saying that they have too many different passwords to remember. To make password management easier on their memories, Americans use the same password across a range of accounts.
The average survey respondent said that they use the same password for six different accounts, including personal and work-related accounts. Most (68%) reported trying to create passwords that were different from one another but ending up with multiple passwords that were actually very similar.
“While using the same password across many different accounts may seem like the simplest option to avoid the dreaded process of forgetting and resetting your password, by leveraging unique passphrases across different accounts, you will better protect your digital presence,” said a LastPass spokesperson.
The survey revealed that respondents were happy to share streaming services (along with their passwords). Nearly 80% stated that they use six different streaming services, but only 43% pay for three of those services themselves.
Over three-quarters of those surveyed (77%) said that it would be beneficial to have a secure way to give a trusted loved one access to their passwords, especially in case of emergency.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Online Fraud in the UK Up 179% in the Last Decade
Online Fraud in the UK Up 179% in the Last Decade

Internet and e-commerce fraud in the UK rose by 179% during the period from 2010 to 2020, according to an analysis by Uswitch.com.
In 2020 alone £376.5m was lost to internet and e-commerce fraud in the UK, which was more heavily impacted by this type of crime than any other country in Europe. Across the previous decade, more than one in nine (12%) of Brits have been affected by this kind of fraud, with a value of £8908 lost per 1000 inhabitants.
According to the research, internet fraud losses increased significantly from 2010, reaching a peak in 2018 of £394.2m. This dipped in 2019 to £359.3m, but went up again in 2020 to £376.5m.
It was also calculated that people in the UK are now more likely to fall victim to fraud or cybercrime than many other offences; for example, they are 20-times more likely to be a victim of fraud than robbery.
Additionally, Uswitch.com highlighted survey data showing that more than half (51%) of UK residents have suffered financial loss as a result of fraud, while 45% have had their personal information stolen online.
Of all the various forms of fraud, impersonation scams had the highest financial impact in the UK in 2020, with £96.6m lost from impersonation of police or bank staff and £53.7m to other types of impersonation scams.
Encouragingly, over half (56%) of the value lost to impersonation scams last year was reimbursed. However, other types of fraud had a much lower reimbursement rate: for purchase scams it was just 29%.
Nick Baker, broadband expert at Uswitch.com, commented: “Fraudsters are becoming ever more sophisticated in their methods, creating scams for all types of products and services, such as loans, dating, holidays and business opportunities.
“Sadly, people of all ages can fall victim to fraud. Not only do online scams target vulnerable individuals, but they also go after major corporations, smaller businesses and the public sector.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Armed Conflict Draws Closer as State-Backed Cyber-Attacks Intensify
Armed Conflict Draws Closer as State-Backed Cyber-Attacks Intensify

The world is coming perilously close to nation states retaliating against cyber-attacks with conventional weapons, according to a new HP report.
The study, Nation States, Cyberconflict and the Web of Profit, was compiled by University of Surrey senior lecturer in criminology, Mike McGuire, from publicly available reports into state-sponsored attacks and interviews with scores of experts.
It claimed there has been a 100% increase in “significant” state-backed attacks between 2017-20, and an average of over 10 publicly attributed attacks per month in 2020 alone.
Although the largest number (50%) featured surveillance tools, a worrying 14% were focused on damage or destruction, while more than 40% had a physical and digital component.
Most (64%) of the experts McGuire consulted during his research claimed the escalation in tensions last year were “worrying” or “very worrying.”
Factors such as increased weaponization and the readiness of governments to define network attacks as “acts of war” are moving the world into a “dangerous stage” — closer to what the report dubs “advanced cyber-conflict” than at any time since the digital age began.
This phase is defined by nations engaging in repeated digital attacks, an increased focus on physical assets and “potential use of conventional weapons” to strike back after cyber-attacks, the report noted.
The research also revealed how the lines between nation state and cybercrime attacks are increasingly blurring.
It claimed that 10-15% of dark web vendor sales now go to “atypical” purchasers including state actors looking to stockpile zero-day exploits. In addition, half (50%) of nation state attacks now feature low-grade tools bought from the cybercrime underground, while just 20% involve custom malware and exploits built in-house.
What’s more, a majority (58%) of experts consulted for the report claimed it’s becoming more common for governments to recruit cyber-criminals to carry out attacks, and even more (65%) said some nation states launch attacks to generate revenue.
McGuire argued that cybercrime economies are shaping the character of nation state threats.
“There is also a ‘second generation’ of cyber-weaponry in development that draws upon enhanced capabilities in computing power, AI and cyber/physical integrations. One such example is ‘Boomerang’ malware, which is ‘captured’ malware that can be turned inward to operate against its owners,” he explained.
“Nation states are also developing weaponized chatbots to deliver more persuasive phishing messages, react to new events and send messages via social media sites. In the future, we can also expect to see the use of deep fakes on the digital battlefield, drone swarms capable of disrupting communications or engaging in surveillance, and quantum computing devices with the ability to break almost any encrypted system.”
While most experts (70%) argued that an international treaty is needed to prevent further escalation in cyber-conflict, the majority said this would take years to achieve, and a third (30%) claimed it would never happen.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
ACC Launches Data Security Program for Law Firms
ACC Launches Data Security Program for Law Firms

The legal industry’s first comprehensive data security evaluation and accreditation program has been launched today.
The Data Steward Program (DSP), which has been developed by the Association of Corporate Counsel (ACC), will enable quick assessments and comparisons of law firms’ data security standards by prospective clients.
The ACC said the program has been introduced in light of growing concerns from both law firms and their clients regarding the safety of the highly sensitive data being held.
Designed by working groups of law firms and in-house counsel, the DSP has established a standardized framework for assessing, scoring, benchmarking, validating and accrediting a law firm’s posture toward client data security. This information can be shared easily and securely with the current or potential clients of a law firm via an online platform.
The controls have been leveraged from existing data security frameworks such as NIST, but have been customized to meet the specific needs of law firms.
Law companies that sign up to the DSP have two evaluation tiers to choose from. Tier 1, named the DSP Core Assessment, allows companies of all sizes to have their information security capabilities assessed, while the steps they take to protect confidential data will be displayed on the online platform. Under Tier 2, law firms are offered confidential, independent validation of their self-assessment, and if the threshold requirements are met, will gain the award of an ‘ACC DSP Accreditation.’
Jim Merklinger, president of the ACC Credentialing Institute, commented: “The ACC Data Steward Program is a clear win-win for law firms and their clients. Currently, law firms must spend considerable time and money completing individual data security evaluations for their clients. The ACC Data Steward Program provides both standardized, easily comparable evaluation, and, if desired, accreditation of law firms’ security practices – all at a fraction of the time and cost. While the DSP is thorough – assessing 160 controls – early users have indicated that a well-prepared law firm can complete the entire process in a few hours. Review by in-house counsel is equally straightforward. ACC is confident that this new program will prove to be a valuable tool for our members and law firms alike.”
ACC added that a set of charter law firms have already signed up to the program and are currently completing their first Data Steward assessment.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk