Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Call of Duty Cheats Expose Gamers to Malware, Takeover
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
From PowerShell to Payload: An Analysis of Weaponized Malware
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Robinhood Warns Customers of Tax-Season Phishing Scams
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: 500-Million-Year-Old Cephalopod
The oldest known cephalopod — the ancestor of all modern octopuses, squid, cuttlefish and nautiluses — is 500 million years old.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Malware Hidden in Call of Duty Cheating Software
News article:
Most troublingly, Activision says that the “cheat” tool has been advertised multiple times on a popular cheating forum under the title “new COD hack.” (Gamers looking to flout the rules will typically go to such forums to find new ways to do so.) While the report doesn’t mention which forum they were posted on (that certainly would’ve been helpful), it does say that these offerings have popped up a number of times. They have also been seen advertised in YouTube videos, where instructions were provided on how gamers can run the “cheats” on their devices, and the report says that “comments [on the videos] seemingly indicate people had downloaded and attempted to use the tool.”
Part of the reason this attack could work so well is that game cheats typically require a user to disable key security features that would otherwise keep a malicious program out of their system. The hacker is basically getting the victim to do their own work for them.
“It is common practice when configuring a cheat program to run it the with the highest system privileges,” the report notes. “Guides for cheats will typically ask users to disable or uninstall antivirus software and host firewalls, disable kernel code signing, etc.”
Detailed report.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
ACLU Files AI FOIA Request
ACLU Files AI FOIA Request

The American Civil Liberties Union (ACLU) has filed a Freedom of Information Act (FOIA) request to find out how America’s national security and intelligence agencies are using artificial intelligence (AI).
The ACLU said it made the request out of concern that AI was being used in ways that could violate Americans’ civil rights.
The request follows the March 1 release of a 16-chapter report containing recommendations on how AI, machine learning, and associated technologies should be used by the Biden administration.
Prepared by the National Security Commission on Artificial Intelligence (NSCAI), the report warns that the US government “is not prepared to defend the United States in the coming AI era.”
The report urges the federal government, including intelligence agencies, to introduce “ubiquitous AI integration in each stage of the intelligence cycle” by 2025. Recommended uses for AI systems detailed in the report include conducting surveillance, exploiting social media information and biometric data, performing intelligence analysis, countering the spread of disinformation via the internet, and predicting cybersecurity threats.
The ACLU says the report raised concerns that government agencies may introduce technology that encroaches on a number of rights held by US citizens, including the rights to privacy and free expression.
In its FOIA request the ACLU stated: “In June 2020, the Office for the Director of National Intelligence released its Artificial Intelligence Framework for the Intelligence Community. One of the core principles endorsed in that framework is transparency.
“Yet the public knows almost nothing about what kinds of AI systems are being developed or used by the Intelligence Community, what policies constrain the deployment or operation of AI systems in practice, and what risks these systems may pose to equality, due process, privacy, free expression, and public safety.”
The ACLU also voiced concerns that AI could be used to unfairly scrutinize America’s non-white communities.
“Of particular concern is the way AI systems may be biased against people of color and marginalized communities, and may be used to automate, expand, or legitimize discriminatory government conduct,” stated the ACLU.
“In addition, AI systems may be used to guide or expand government activities that have long been used to unfairly scrutinize communities of color, including intrusive surveillance, investigative questioning, detention, and watchlisting.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Forensic Audit of MobiKwik Ordered
Forensic Audit of MobiKwik Ordered

A forensic audit of India’s largest independent mobile payments network has been ordered following an alleged data breach.
Reports that data in the care of MobiKwik had been leaked online began circulating on social media in February. Earlier this week, a website on the Darknet appeared to show that 8.2 TB of data had been exfiltrated from the company.
On March 30, the hacking group Jordandaven claimed to have stolen a MobiKwik database containing 36 million files in which the Know Your Customer (KYC) identity verification data of around 3.5 million people was stored.
Among the allegedly leaked data is 99 million customers’ phone numbers, emails, hashed passwords, addresses, and bank account information, and the details of over 40 million payment cards.
Jordandaven claimed that data belonging to MobiKwik founder Bipin Preet Singh and to the company’s chief executive, Upasana Taku, were contained within the leaked database.
MobiKwik has over 107 million users and more than three million merchants on its network. The company’s alleged hackers claim to have stolen 7.5 TB of KYC data related to those merchants.
To ascertain the legitimacy of the hackers’ claims, the Reserve Bank of India yesterday ordered that a forensic audit of MobiKwik be carried out immediately by a CERT-IN (Indian Computer Emergency Response Team) third-party auditor.
MobiKwik, which is based in Gurugram, has dismissed claims of a data leak as untrue.
On Tuesday, a MobiKwik spokesperson said: “We are subjected to stringent compliance measures under PCI-DSS and ISO certifications which include annual security audits and quarterly penetration tests to ensure the security of our platform.
“As soon this matter was reported, we undertook a thorough investigation with the help of external security experts and did not find any evidence of a data breach.”
MobiKwik stated that it had contacted CERT-IN after the alleged data breach. After reviewing a sample of the allegedly leaked data, the company concluded that the data did not belong to them.
The New Indian Express reports that MobiKwik previously contacted CERT-IN after discovering an unauthorized March 1 attempt to access its user-facing application programming interface associated with a payment link generated through its platform.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
DeepDotWeb Administrator Admits Darknet Conspiracy
DeepDotWeb Administrator Admits Darknet Conspiracy

A website owner who received millions of dollars in kickbacks for connecting internet users to Darknet marketplaces has pleaded guilty in a US court to conspiracy to commit money laundering.
Thirty-seven-year-old Brazil resident Tal Prihar owned and operated DeepDotWeb along with his co-defendant and fellow Israeli national, 34-year-old Michael Phan.
Established in 2013, the site not only provided general information about the Darknet, but also featured links to specific sites where users could buy illegal firearms, malware, stolen financial data, illicit drugs, and other contraband.
Every time a user clicked on one of the links, which cannot be found via regular search engines, Prihar and Phan received a payment. In total, hosting the links illegally earned the pair approximately $8.4m, according to court documents.
“Tal Prihar today acknowledged his leadership role in operating a web site that served as a gateway to numerous dark web marketplaces selling fentanyl, heroin, firearms, hacking tools and other illegal goods,” said Acting US. Attorney Stephen Kaufman for the Western District of Pennsylvania in a statement released March 31.
“Mr. Prihar and his codefendant extracted a fee from each customer routed to these illegal sites, profiting in the millions of dollars.”
These illegal kickback payments were paid into Prihar’s DeepDotWeb Bitcoin wallet. To conceal their nature and source, he transferred the money to bank accounts he controlled in the names of shell companies and to other Bitcoin accounts.
Prihar agreed to forfeit $8,414,173 he received in illegal kickbacks when federal authorities seized DeepDotWeb in April 2019.
On March 31, Prihar pleaded guilty to conspiracy to commit money laundering. When he is sentenced on August 2, Prihar faces a maximum prison term of 20 years.
“For six years, DeepDotWeb was a gateway to facilitate the illegal purchase of items to include dangerous drugs, weapons, and malicious software,” said Acting Special Agent in Charge Carlton Peeples of the FBI’s Pittsburgh Field Office.
“Prihar profited as a byproduct from other people’s dangerous transactions and today’s guilty plea sends a message to other cyber actors across the globe who think the dark web is a safe haven. The FBI works with our local, state, federal and international partners regularly to dismantle illicit websites and go after those responsible for them.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
DHS Secretary Outlines Biden Administration’s Cybersecurity Vision
DHS Secretary Outlines Biden Administration’s Cybersecurity Vision

The five principles underpinning the new US administration’s vision to strengthen the nation’s cyber-resilience were outlined by the Department of Homeland Security (DHS) secretary Alejandro Mayorkas during a RSAC webcast.
Mayorkas began by emphasizing the need for the public and private sector to work closely together to defend against, and respond to, rising cyber-attacks. “The government does not have the capacity to achieve our nation’s cyber-resilience alone – so much of our critical infrastructure is in the private sector’s hands,” he pointed out.
Mayorkas also believes the SolarWinds attacks at the end of last year shows the need for the government to modernize its cybersecurity strategies. He noted: “It wasn’t until one of the world’s best cybersecurity company’s got hacked itself and alerted the government that we found out.”
With this in mind, Mayorkas set out the five principles that will guide the current Biden-Harris’ administration’s cybersecurity vision for the US.
1. Championing a free and secure cyberspace: Mayorkas said it is vital to understand the current geo-political trends, which include a regression in democratic ideals, that are impacting the digital space. “Far too often cybersecurity is used as pretext to infringe on civil liberties and human rights,” he commented. As a result, it is vital the US stands up and champions a free and secure cyberspace both “with words and actions.”
2. A focus on cyber-resilience as well as defense: Bold innovations, widescale investments and a raising of the bar for essential cyber-hygiene are all required to ensure the nation is fully cyber-resilient, according to Mayorkas. He added it is important to acknowledge that “no-one is immune from attacks, including federal government or our most advanced technology companies.” Therefore, having a prepared response to breaches is vital alongside preventative measures. Mayorkas also revealed the federal government is currently working on an executive order, focusing on improving its own cyber-resilience.
3. A risk-based approach, based on data: The government needs a fact-based framework to be fully aware of the risks both at home and abroad, enabling it to identify the biggest dangers and act accordingly. Mayorkas outlined that “a focus on a risk-based approach, determining what risks to prioritize and how to allocate limited resources, is crucial to maximizing the government’s impact.”
4. Shared responsibility: At the heart of the administration’s approach to cybersecurity is the principle of collaboration between the government and private sector. In particular, developing a relationship where information is distributed and shared rapidly to deal with threats. “We must strengthen collaboration between the private sector and government to generate the insights necessary to detect malicious cyber-actors,” stated Mayorkas.
5. Integrating diversity, equity and inclusion: Finally, Mayorkas emphasized the importance of facilitating equal access to professional development opportunities in cybersecurity, both to help fill the cyber-skills shortage and develop better policies. “Developing sound public policy requires diverse perspectives from communities that represent America. It requires the recruitment, development and retention of diverse talent,” explained Mayorkas.
He added that the Biden-Harris administration is determined to action these principles and modernize the US’ approach to cybersecurity during its tenure. “President Biden has made cybersecurity a top priority for his administration,” said Mayorkas.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk