Romance Fraudster Who Conned Jenifer Lewis Jailed

Romance Fraudster Who Conned Jenifer Lewis Jailed

A convicted fraudster from Santa Monica, California, who conned the women he dated into investing in his fake businesses has been handed a custodial sentence. 

Antonio Mariot Wilson, also known as Dr. Tony Mariot and Brice Carrington, impersonated a Bible scholar and a Navy SEAL in the execution of his romance scams. Wilson lured his targets using online dating sites, including the networking dating app Bumble Bizz.

Between May 2015 and October 2017, the 57-year-old tricked four women into parting with a total of $387,000. Among Wilson’s victims was the actress Jenifer Lewis, whose credits include the films Beaches and Sister Act.

During Wilson’s sentencing hearing, Lewis appeared via Zoom to give the court a victim impact statement. Lewis met Wilson when he was managing a branch of L.A. Fitness and calling himself Brice Carrington.

She described Wilson as “predatory con artist who, during the past 25 years, destroyed the lives of countless women and men.”

The actress said: “He meticulously researched me on the internet. He used all that information on the web to . . . worm his way into my life with false affections. His lies had no boundaries.”

Lewis said Wilson showed her military medals and what appeared to be official documents confirming his story that he had been a Navy SEAL. It later transpired that Wilson had purchased the medals and paperwork online. 

Wilson tricked Lewis into investing $50k in a fictitious sound design business. 

“I agreed to invest, having softened only after he brought his children to my house,” Lewis said. “He used his children. Even to this day, that fact horrifies me the most.”

Lewis said becoming one of Wilson’s victims had taken an emotional toll on her.

“The $50,000 he stole from me does not compare to his stealing my ability to trust. His treachery caused deep depression, and I was forced back into therapy,” she said.

Wilson pleaded guilty to one federal count of wire fraud last May. On March 9, he was sentenced to 8 years in federal prison and ordered to pay restitution of $272,000. 

Prosecutors said Wilson did not tell his most recent victims that he had already served four years in prison after pleading guilty in 2009 to wire fraud and tax evasion charges. In the previous case, Wilson pretended to be an Oscar-winning sound effects designer to fraudulently obtain nearly $4m from investors.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

American Companies Not Taking Cybersecurity Seriously

American Companies Not Taking Cybersecurity Seriously

More than half of Americans believe that their companies could have done more to increase cybersecurity during the global health pandemic, according to a new survey.

In February, tech company Lynx Software asked 1,000 Americans employed during the pandemic about their employer’s approach to cybersecurity since the outbreak of COVID-19. Of those surveyed, 51% said that their companies have not been taking cybersecurity seriously.

Nearly half (48%) said that they were not aware of their company’s implementing any strict IT security policies since the novel coronavirus took hold. 

Just under two-thirds (60%) said that they had not been prohibited from using certain tools or apps that fell short of high security standards. 

The survey also revealed that companies have been relaxed regarding device use, with 65% of survey respondents saying that their company allows them to use their work computer to access personal services. Three-quarters (76%) said they use a personal device for work at least sometimes.

Asked how to describe their experience of cyber-attacks during the pandemic, nearly 4 in 10 (36%) respondents said that they have been, or that they know someone who has been, impacted by a cybersecurity attack since the start of COVID-19. 

A large majority of respondents (69%) indicated that they are more concerned about cybersecurity risks during COVID-19 than they were before the pandemic, as perimeter-based security is no longer possible. 

Fewer than half (49%) of respondents said that the cybersecurity at the organization had been strengthened since the pandemic began. 

Asked to name their biggest cybersecurity concern, 54% of respondents said that their main worry was that their personal data would be compromised. 

“Organizations of all types need to prioritize finding ways to secure end-points for their employees’ devices, whether they are on laptops, edge servers or anything between, especially in the remote, zero-trust environment we are living in. For IT teams this doesn’t have to mean prohibitive costs or compromising performance,” said Arun Subbarao, vice president of engineering and technology at Lynx Software. 

“At Lynx, we endorse increased security awareness for IT in order to combat risks that have come as a result of people’s increasingly virtual lifestyles since COVID-19.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SolarWinds Unlikely to Be an Isolated Event as Attackers Become More Sophisticated

SolarWinds Unlikely to Be an Isolated Event as Attackers Become More Sophisticated

Cyber-attacks have become increasingly sophisticated in the past year, with the SolarWinds incident unlikely to be an isolated event going forward, according to VMware Security Business Unit’s 2021 Global Cybersecurity Outlook report.

The researchers noted that, in addition to widening the attack surface, the shift to digital following the COVID-19 pandemic has allowed malicious actors the time, capital and opportunity to industrialize, leading to advancements in their operations.

Nearly 40% of the 180 IR, cybersecurity and IT professionals surveyed for the study stated that double-extortion ransomware was the most observed new ransomware technique in 2020. In general, ransomware was a very prominent method employed, with 66% of those polled revealing they had been targeted in this way last year.

There also appears to be a growing number of cyber-villains undertaking counter incident responses (IR), with 63% of respondents saying they saw this occur in 2020. Security tooling disablement (33%) was the most common counter IR technique witnessed, followed by DDoS attacks (26%), security tool bypass (15%) and destruction of logs (11%).

Additionally, the report noted a rise in “island hopping,” in which attackers jump from one network to another along a supply chain, as occurred in the SolarWinds attack. Close to half (44%) of those surveyed observed island hopping taking place in over 25% of all IR engagements, while 13% said it occurred in more than 50% of engagements.

Tom Kellermann, head of cybersecurity strategy, VMware Security Business Unit, commented: “This [SolarWinds] is not an isolated event. With COVID-19 catalyzing digital transformation and a shift to cloud services, these sorts of attacks will only increase in frequency. Organizations have to realize that it’s no longer simply about whether breaches along their supply chains can be leveraged to attack them, but whether they themselves can be used to attack their customers.”

Encouragingly, in response to this more dangerous landscape, organizations appear to be adopting more proactive approaches to security. For instance, 81% said their organization now has a threat hunting program in place.

The respondents’ top security priorities for 2021 included security for trusted third parties/supply chain (24%), remote access security (24%), network and endpoint security (22%), identity and access controls (21%) and hardware/physical device security (9%).

Greg Foss, senior cybersecurity strategist, VMware Security Business Unit, added: “Since 2019, we’ve seen e-crime shift from covert shadow groups into these pseudo-legitimate businesses, replete with customer service channels, clear business sites and increasingly sophisticated attack methods.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

ESET: More Than 10 APT Groups Exploiting Recent Microsoft Exchange Vulnerabilities

ESET: More Than 10 APT Groups Exploiting Recent Microsoft Exchange Vulnerabilities

There are more than 10 different advanced persistent threat (APT) groups exploiting recent Microsoft Exchange vulnerabilities, according to ESET research.

Last week, Microsoft released out-of-band patches to fix multiple zero-day vulnerabilities believed to be being exploited by Chinese state-sponsored group Hafnium. The step was taken to protect customers running on-premises versions of Microsoft Exchange Server.

However, today (March 10), ESET claimed the number of APT groups exploiting the vulnerabilities is believed to be in double-figures, identifying more than 5000 global email servers – belonging to businesses and governments alike – that have been affected by related malicious activity.

“The day after the release of the patches, we started to observe many more threat actors scanning and compromising Exchange servers en masse,” said ESET researcher Matthieu Faou. “Interestingly, all of them are APT groups focused on espionage, except one outlier that seems related to a known coin-mining campaign.

“However, it is inevitable that more and more threat actors, including ransomware operators, will have access to the exploits sooner or later,” he added.

What’s more, the ESET researchers noticed that some APT groups were exploiting the vulnerabilities even before the patches were released, dismissing the possibility that the groups built exploits by reverse engineering Microsoft updates.

The threat groups/behavior clusters identified by ESET are:

  • Tick
  • LuckyMouse
  • Calypso
  • Websiic
  • Winnti Group
  • Tonto Team
  • ShadowPad activity
  • The “Opera” Cobalt Strike
  • IIS backdoors
  • Mikroceen
  • DLTMiner

“It is now clearly beyond prime time to patch all Exchange servers as soon as possible. Even those not directly exposed to the internet should be patched. In case of compromise, admins should remove the webshells, change credentials and investigate for any additional malicious activity. The incident is a very good reminder that complex applications such as Microsoft Exchange or SharePoint should not be open to the internet,” concluded Faou.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NHS Regulator Faces Surge in Email Attacks During Vaccine Rollout

NHS Regulator Faces Surge in Email Attacks During Vaccine Rollout

The UK’s health and social care regulator, the Care Quality Commission (CQC), has faced an average of nearly 20,000 malicious email attacks a month in the past three months, according to official figures.

Obtained via a Freedom of Information (FOI) act request from the Parliament Street think tank, the data revealed that the commission, which regulates NHS services, was targeted by close to 60,000 malicious email attacks from December 2020 to February 2021.

The month in which the highest amount of attacks was recorded was January, at 20,486. This was followed by February, at 18,501 recorded cases, and December, at 17,587 cases.

The most common type of malicious email attack was phishing, making up 94% (52,905) of all recorded attacks in the three months. There were also 2311 malware instances and 1358 spam cases recorded by CQC in this period.

The figures have emerged in the context of the rapid rollout of COVID-19 vaccines across the world, which has been increasingly targeted by cyber-criminals in recent months. Last month, experts highlighted a new COVID-19 vaccine phishing scam in which NHS-branded emails were being used to trick users into handing over their personal and financial details. Additionally, recent data from NHS Digital showed that NHS staffers were hit by 137,476 malicious emails last year.

Commenting on the figures, Chris Ross, SVP sales international, Barracuda Networks, said: “Over the last 12 months, cyber-criminals have increasingly exploited the COVID-19 pandemic by using carefully tailored phishing emails to trick remote employees into handing over confidential data and personal information. Our recent research even revealed a 26% spike in vaccine related phishing activity since October 2020.

“Due to its association with the NHS and the vaccination program, scammers have clearly identified the CQC as a hot target for valuable data and will continue to send malicious email attacks to employees until sensitive information or login credentials are leaked – once compromised, data can then be sold on the black market, or used to hold the organization to ransom.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Threat Analysts Banned from Sharing Intel with Peers

Most Threat Analysts Banned from Sharing Intel with Peers

Most threat intelligence analysts aren’t allowed to share artifacts with their peers in professional networks, hindering the global fight against cyber-attacks, according to Kaspersky.

The Russian anti-malware vendor compiled its latest report, Managing Your IT Security Team, from interviews with over 5200 IT business decision-makers across 31 countries in June 2020.

It revealed that two-thirds (66%) of threat intelligence analysts participate in a professional community, in order to gain access to the most up-to-date and actionable information to help them protect their organization.

This includes subscriptions to vulnerability databases (61%), taking part in professional forums and blogs (45%) and receiving threat intelligence from paid (42%) and free (33%) feeds.

However, employers are usually against these same analysts sharing their own intelligence with external communities. Over half (52%) claimed they do not allow such activity.

That means less than half of analysts (44%) have shared potentially critical insights beyond their own organization. In companies where sharing is allowed, 77% do, highlighting the importance of collaboration in the fight against cyber-threats. Even in organizations where it is prohibited, 8% claimed they still try to share information.

This intelligence would typically include indicators of compromise (IoCs) like hashes or C&C servers, as well as information on tactics and techniques, motivations and common penetration vectors, according to Kaspersky.

“Any piece of information – be it new malware or insights on techniques used – is valuable when protecting against advanced threats,” argued Anatoly Simonenko, group manager, technology solutions product management, at Kaspersky.

“That’s why we constantly make our threat research findings available via our information resources and through our TI services. We encourage security analysts to also give a helping hand to others in the same collaborative way.”

Sharing in this way isn’t just good practice, it could help to relieve the workload on stretched analysts. The report found that 41% of those who had asked for help from internal communities had eventually left the business due to high workload.

However, there’s also a balance to be had: the report warned that sharing intelligence about an attack too early on could give the threat actors an advantage, enabling them to adapt their tactics to evade further detection.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Exposed Password Gave Hackers Access to 150,000 Cameras

Exposed Password Gave Hackers Access to 150,000 Cameras

Hacktivists claim to have successfully targeted a leading manufacturer of surveillance cameras, enabling them to access the live feeds of 150,000 cameras around the world, according to a new report.

The attack seems to have been the work of an international hacker collective which did it to highlight the privacy risks associated with pervasive monitoring, according to Bloomberg.

The camera maker, San Mateo-headquartered startup Verkada, said it had disabled all internal admin accounts to prevent unauthorized access.

“Our internal security team and external security firm are investigating the scale and scope of this issue, and we have notified law enforcement,” it added in a statement sent to the news site.

The incident appears to be legitimate: Bloomberg said it had seen video feeds from inside Tesla factories and hospitals. The group claims to have access to Verkada’s entire video archive for all customers, which include women’s health clinics, psychiatric hospitals, jails and even the offices of Verkada itself.

Some of the cameras, such as those inside prisons, use facial recognition to track individuals, the report claimed.

The incident will be embarrassing for Verkada given the firm makes big play of its security credentials, claiming its system was designed to be “secure from the ground up.”

The hacktivists are said to have accessed the feeds through a pretty familiar route – they reportedly found logins for a privileged account exposed on the internet. This gave them root access to the cameras to execute their own code and, in some cases, obtain broader access to customer networks.

“While the Verkada website bolsters that they have a ‘Secure by Default’ methodology, it is clear that while we create devices with security in mind, what humans create typically has flaws,” argued Ordr CSO, Jeff Horne.

“Since the video system data can contain personally identifiable information (PII), company confidential information and personal health information (PHI), it is important that our security community band together to help Verkada, the impacted organizations and the individuals whose privacy was exploited.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Expands Coverage of Exchange Server Patches

Microsoft Expands Coverage of Exchange Server Patches

Microsoft released fixes for over 80 CVEs in yesterday’s Patch Tuesday update round, including a zero-day bug and several publicly disclosed vulnerabilities.

In a week dominated by the exploitation on a massive scale of four zero-day Exchange Server flaws patched out-of-band by Microsoft last week, there’s yet more to do for sysadmins.

The first is yet another zero-day, this time in Internet Explorer.

CVE-2021-26411 is a memory corruption vulnerability that could allow an attacker to target users with specially crafted content,” explained Ivanti senior director of product management, Chris Goettl.

“An attacker could utilize specially crafted websites or websites that accept user-provided content or advertisements to host content designed to exploit this vulnerability.”

Experts also urged IT teams to patch a publicly disclosed vulnerability (CVE-2021-27077) in Windows Win32k that could allow an attacker to elevate privileges on an affected system. It was first reported by Trend Micro’s Zero Day Initiative back in January.

“This vulnerability is not believed to be exploited in the wild, however, the length of time between initial disclosure and a patch being released should be cause for concern as it may have given malicious threat actors the opportunity to figure out the vulnerability and exploit it,” warned Recorded Future senior security architect, Allan Liska.

“A similar vulnerability, also discovered by the Zero Day Initiative, reported last year, CVE-2020-0792, was not widely exploited.”

Of the six Microsoft DNS bugs patched this month, Liska argued that CVE-2021-26877, CVE-2021-26893, CVE-2021-26894 and CVE-2021-26895 should be prioritized as they are remote code execution flaws which impact Windows Server 2008-2016.

Elsewhere, Microsoft expanded the coverage of patches issued for those widely exploited Exchange Server bugs to include out-of-support cumulative updates (CUs) – including Exchange Server 2019 CU 6, CU 5 and CU 4 and Exchange Server 2016 CU 16, CU 15, and CU14.

“This is an indication of the severity and reach of the attacks targeting the Exchange Server on-prem products,” said Goettl.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk