Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Nim-Based Malware Loader Spreads Via Spear-Phishing Emails
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cyberattackers Exploiting Critical WordPress Plugin Bug
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Breach Exposes Verkada Security Camera Footage at Tesla, Cloudflare
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
More on the Chinese Zero-Day Microsoft Exchange Hack
Nick Weaver has an excellent post on the Microsoft Exchange hack:
The investigative journalist Brian Krebs has produced a handy timeline of events and a few things stand out from the chronology. The attacker was first detected by one group on Jan. 5 and another on Jan. 6, and Microsoft acknowledged the problem immediately. During this time the attacker appeared to be relatively subtle, exploiting particular targets (although we generally lack insight into who was targeted). Microsoft determined on Feb. 18 that it would patch these vulnerabilities on the March 9th “Patch Tuesday” release of fixes.
Somehow, the threat actor either knew that the exploits would soon become worthless or simply guessed that they would. So, in late February, the attacker changed strategy. Instead of simply exploiting targeted Exchange servers, the attackers stepped up their pace considerably by targeting tens of thousands of servers to install the web shell, an exploit that allows attackers to have remote access to a system. Microsoft then released the patch with very little warning on Mar. 2, at which point the attacker simply sought to compromise almost every vulnerable Exchange server on the Internet. The result? Virtually every vulnerable mail server received the web shell as a backdoor for further exploitation, making the patch effectively useless against the Chinese attackers; almost all of the vulnerable systems were exploited before they were patched.
This is a rational strategy for any actor who doesn’t care about consequences. When a zero-day is confidential and undiscovered, the attacker tries to be careful, only using it on attackers of sufficient value. But if the attacker knows or has reason to believe their vulnerabilities may be patched, they will increase the pace of exploits and, once a patch is released, there is no reason to not try to exploit everything possible.
We know that Microsoft shares advance information about updates with some organizations. I have long believed that they give the NSA a few weeks’ notice to do basically what the Chinese did: use the exploit widely, because you don’t have to worry about losing the capability.
Estimates on the number of affected networks continues to rise. At least 30,000 in the US, and 100,000 worldwide. More?
And the vulnerabilities:
The Chinese actors were not using a single vulnerability but actually a sequence of four “zero-day” exploits. The first allowed an unauthorized user to basically tell the server “let me in, I’m the server” by tricking the server into contacting itself. After the unauthorized user gained entry, the hacker could use the second vulnerability, which used a malformed voicemail that, when interpreted by the server, allowed them to execute arbitrary commands. Two further vulnerabilities allow the attacker to write new files, which is a common primitive that attackers use to increase their access: An attacker uses a vulnerability to write a file and then uses the arbitrary command execution vulnerability to execute that file.
Using this access, the attackers could read anybody’s email or indeed take over the mail server completely. Critically, they would almost always do more, introducing a “web shell,” a program that would enable further remote exploitation even if the vulnerabilities are patched.
The details of that web shell matter. If it was sophisticated, it implies that the Chinese hackers were planning on installing it from the beginning of the operation. If it’s kind of slapdash, it implies a last-minute addition when they realized their exploit window was closing.
Now comes the criminal attacks. Any unpatched network is still vulnerable, and we know from history that lots of networks will remain vulnerable for a long time. Expect the ransomware gangs to weaponize this attack within days.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Arkansas Bill Addresses “Unfair” Social Media Censorship
Arkansas Bill Addresses “Unfair” Social Media Censorship

The Natural State is considering a new piece of legislation that would hold social media companies accountable for “unfairly censoring or banning someone.”
The Arkansas Unfair Social Media Censorship Act would make sites like Twitter, YouTube, Instagram, and Facebook liable for damages if they remove content for “dubious or pretextual” reasons that are inconsistent with their own terms of service.
Arkansas attorney general Leslie Rutledge said: “This legislation would allow everyone, no matter the circumstances, to have an equal and fair opportunity to post online. And if a social media giant does not comply, the company can be held accountable.”
Rutledge added that the proposed bill was introduced to “combat cancel culture”—the ostracism of an individual or organization deemed to have acted or spoken in a controversial manner.
“Cancel culture cannot become the norm in Arkansas, especially when our Freedom of Speech in rural America is in jeopardy,” she said.
Currently, websites have the ability to regulate content from users on their platforms under Section 230 of the Communications Decency Act. Under the terms of the proposed legislation, social media companies could face fines if they violate the Arkansas Deceptive Trade Practices Act by censoring, deleting, or labelling speech, including religious or political language, without acting in good faith.
In Arkansas, each violation of the Arkansas Deceptive Trade Practices Act can result in injunctions and civil penalties of up to $10,000.
The Bill would not prevent social media sites from acting in good faith to remove content that is believed to be promoting terrorism or that includes violent or obscene material such as content related to child sexual abuse or human trafficking.
“This bill is a great step forward in holding these organizations accountable and lessening the bias enforced by operators of the systems,” Brandon Hoffman, CISO at Netenrich, told Infosecurity Magazine. “However, it remains unclear who would get to rule in judgment in these cases.”
Pondering how social media companies may respond if the Act passes into law, Hoffman said: “They may simply introduce a notion of banning and content removal that prevents this law from being enacted. If that happens then users will have to decide whether or not to abandon said platform.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Vodafone Calls for New Cybersecurity Policies to Help SMEs
Vodafone Calls for New Cybersecurity Policies to Help SMEs

Telecommunications giant Vodafone is calling for the introduction of new cybersecurity policies to help small businesses in the UK recover from the impact of the global health pandemic.
In a statement released today, the company asked Boris Johnson’s government to protect small and medium-sized businesses by providing more support to the National Cyber Security Centre and making cybersecurity protections more accessible.
Vodafone proposed that the value-added tax (VAT) on cybersecurity products should be reduced to 5% to ensure that small and medium-sized enterprises (SMEs) can purchase adequate cyber-defense.
The company’s plea for a policy change coincides with the release today of a new report, “Protecting our SMEs: Cybersecurity in the new world of work,” that shows almost a quarter of SMEs in the UK, the equivalent of 1.3 million businesses, say a cyber-attack could cause them to cease operating.
A further 16% of SMEs, a figure that equates to nearly a million companies, said a cyber-attack could result in a reduction in the number of employees.
“Access to cybersecurity products could be the assistance that is required to take SMEs to the level they need to mitigate such attacks,” Jake Moore, cybersecurity specialist at ESET, told Infosecurity Magazine.
“However, a lack of awareness and education amongst employees arguably remains the biggest cybersecurity hurdle for SMEs.”
SMEs employ three-fifths of the UK’s workforce and, according to the Federation of Small Businesses, account for 99.9% of the UK’s six million private-sector businesses.
“Small businesses are particularly vulnerable to cyber-attacks, as they don’t have the same IT staff in place as large companies, or the large budgets required to shield them from the ever-increasing number of attacks,” Timur Kovalev, chief technology officer at California cybersecurity company Untangle, told Infosecurity Magazine.
“For example, in Untangle’s 2020 survey of our IT administrators, 38% of SMBs have $1,000 or less allocated to their IT security budget.”
Kovalev added that encouraging small businesses to act, and to step up their cybersecurity technology, was a good thing.
He said, “Not all small businesses are aware of the risks, and those that do know the risks don’t always have enough budget to invest in enough protection.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Breach Clarity Acquired by Sontiq
Breach Clarity Acquired by Sontiq

California fintech provider Breach Clarity has been acquired by an intelligent identity security (IIS) and cyber monitoring company based in Nottingham, Maryland.
News of the acquisition by Sontiq was announced today without reference to the terms of the deal. As a result of the acquisition, Sontiq’s tech-enabled IIS Platform products–IdentityForce, Cyberscout, and EZShield–will have the proprietary capability, BreachIQ.
BreachIQ creates a breach score based on the severity and risks of a publicly reported data breach by analyzing more than 1,300 data points. It is powered by machine learning and an AI-driven algorithm developed by Breach Clarity co-founder and founder of Javelin Strategy & Research Jim Van Dyke.
Van Dyke is a former board member of the US Consumer Financial Protection Bureau (CFPB) and also serves as a board member of the Identity Theft Resource Center.
Following the acquisition, Van Dyke will join Sontiq as senior vice president of digital financial wellness. Breach Clarity co-founder Al Pascual is also joining Sontiq as senior vice president of data breach solutions.
Like Van Dyke, financial crime expert Pascual has links to Javelin Strategy & Research, where he previously was head of fraud and security.
“Consumers’ sensitive personal information is exposed daily, and it is increasingly difficult for them to monitor who has their data and where it’s being leaked,” said Van Dyke. “With the integration of our artificial intelligence algorithm and risk expertise, Sontiq will provide clarity to millions of consumers around their individualized risk profile and the protective action steps likely to have the greatest impact.
“In combination with personalized advice and recovery with Sontiq’s white-glove resolution experts, consumers have never been in better hands. We are excited to work with Sontiq’s team to deliver additional, innovative solutions in the coming months.”
Sontiq was formed in 2019, when EZShield, a portfolio company of The Wicks Group, acquired IdentityForce, an identity theft protection provider for businesses and consumers.
The Breach Clarity deal isn’t the first acquisition Sontiq has made this year. In March 2021, Sontiq acquired Cyberscout, a cyber products and services provider to the insurance industry.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
West Ham Supporters’ Personal Details Leaked on Club Website
West Ham Supporters’ Personal Details Leaked on Club Website

English Premier League football club West Ham United appears to have accidently leaked personal data of supporters on its official website, potentially leaving fans exposed to phishing attacks.
As reported today by Forbes, multiple details of fans including full names, dates of birth, telephone numbers, address and email address were displayed when supporters attempted to log into their accounts on the club’s ticketing website.
The article stated that the official club website showed several error messages earlier today, including an admin message stating “Drupal already installed.” After the author created an account on the site and re-logged in with their credentials, the personal details of another West Ham supporter were displayed. A number of West Ham supporters reported similar experiences on the fans forum site KUMB.
In a statement, the club confirmed that the issue has now been resolved, with a spokesman saying: “We are aware there was a technical issue when signing into online accounts this morning. We worked with our third-party service provider and they have already resolved this issue.”
There is currently no suggestion that credit card or any other payment details have been exposed.
Cybersecurity experts believe it is likely the problem was caused by an internal error.
Javvad Malik, security awareness advocate at KnowBe4, commented: “All organizations of all sizes and in all verticals need to foster a culture of cybersecurity so that all aspects of security and design are taken into account. The leak at West Ham United is likely down to an internal error or misconfiguration, which is an easy enough error to make. Which is why it is important to have in place the proper security controls, particularly where customer data is concerned so that there can be assurance the data is being handled correctly.”
Under GDPR rules, West Ham should be directly contacting any supporters whose information was exposed. In the meantime, fans are advised to be on the lookout for unsolicited communications that contain links or requesting financial details.
Natalie Page, threat intelligence analyst at Talion, said: “The potential ramifications for West Ham United from this incident could be extremely costly. Since the introduction of GDPR, we have seen individual organizations fined as much as £42m, with an astonishing overall amount of £235m issued thus far against 533 organizations. For the West Ham United fans potentially affected by this breach, while the club should contact you directly, if your details have been exposed, be cautious and act as if your personal details have been breached until notified otherwise.
“Be alert to incoming texts, calls and emails utilizing the information shared in this incident from unknown sources demanding further personal information or payment. Also consider the password you utilize for this account, if this has been duplicated on other personal accounts, this should be changed promptly.”
Football clubs have been increasingly targeted by cyber-criminals in recent years. In 2020, the NCSC claimed that one Premier League football club nearly lost a £1m transfer fee to scammers, while Manchester United was hit by a suspected ransomware attack in November last year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Protection and Privacy Pivotal to the UK’s National Data Strategy
Protection and Privacy Pivotal to the UK’s National Data Strategy

The data protection and privacy issues surrounding the UK’s National Data Strategy were discussed by experts during a session at a recent Westminster eForum policy conference.
The strategy was published at the end of last year by the UK government, with the aim of harnessing data collected to boost productivity and innovation, both in the public and private sectors.
However, the panellists emphasized that safeguards around data privacy and protection are essential when implementing this national strategy. Gayle McFarlane, partner, Eversheds Sutherland, said that as a starting point, the objective of the data collection and its appropriateness must be clearly defined and communicated. “We need to think about what the ultimate purpose of it is and how it is going to be used,” she outlined. For example, McFarlane noted that while many would consider it a positive to allow the NHS to gather large amounts of data about people’s activities in order to drive health policies, “if that data is used to say if my smart watch hasn’t collected enough steps today and therefore I’m not entitled to particular treatments, do we still feel the same way?”
McFarlane also emphasized the importance of recognizing that different people will feel very differently about their data being collected and used by organizations. This can lead to unintended consequences, including users refusing to access vital services. “Individuals have a different view as to how comfortable they are about the risk-reward of sharing of data,” she explained, adding that “we need to make sure we bring people along with us.”
Due to such considerations, Laura Lazaro Cabrara, legal officer at Privacy International, believes that data subject rights should be one of the key priorities of the National Data Strategy. This includes ensuring clarity and consent takes place during any changes, and allowing individuals to object to their data being used in a certain way. “It is important that these principles are carefully applied to the data strategy and balanced against the hypothetical benefits from more processing,” commented Lazaro Cabrara.
She highlighted the example of the COVID-19 track and trace system set up in the UK last year, in which data from hundreds of millions of check-ins from people who visited pubs, restaurants and hairdressers had barely been used by test and trace. “This is a clear example of data processing which proved to be unnecessary and ultimately excessive,” said Lazaro Cabrara.
Roxanne Morison, head of digital policy, CBI, outlined data issues related to the UK’s formal departure from the EU, and how these should be a crucial component of the National Data Strategy. “Securing adequacy remains the top priority for firms,” she stated. “It matters to all sectors and underpins business operations from logistics to financial services, and really the free flow of data is at the heart of the success of the UK’s digital economy.”
Morison also expressed her belief that the National Data Strategy offers a great opportunity to set a strategic direction and improve coordination in this area. One key way it can make a difference to businesses is to set more uniform standards domestically regarding data protection, with the current situation often quite confusing. “Awareness of these trade-offs between these different definitions between regulators is so important for firms to stop them being caught in the cross-hairs of these different systems,” she said.
Another important benefit the strategy can have is to “show the art of what’s possible, not just what you can’t do” with data in order to harness its full potential, according to Morison. In particular, this involves improving accessibility of guidance, particularly for SMEs and startups which don’t have large compliance teams.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk