Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Malformed URL Prefix Phishing Attacks Spike 6,000%
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Credential-Stuffing Attack Targets Regional Internet Registry
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Microsoft: SolarWinds Attackers Downloaded Azure, Exchange Code
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Router Security
This report is six months old, and I don’t know anything about the organization that produced it, but it has some alarming data about router security.
Conclusion: Our analysis showed that Linux is the most used OS running on more than 90% of the devices. However, many routers are powered by very old versions of Linux. Most devices are still powered with a 2.6 Linux kernel, which is no longer maintained for many years. This leads to a high number of critical and high severity CVEs affecting these devices.
Since Linux is the most used OS, exploit mitigation techniques could be enabled very easily. Anyhow, they are used quite rarely by most vendors except the NX feature.
A published private key provides no security at all. Nonetheless, all but one vendor spread several private keys in almost all firmware images.
Mirai used hard-coded login credentials to infect thousands of embedded devices in the last years. However, hard-coded credentials can be found in many of the devices and some of them are well known or at least easy crackable.
However, we can tell for sure that the vendors prioritize security differently. AVM does better job than the other vendors regarding most aspects. ASUS and Netgear do a better job in some aspects than D-Link, Linksys, TP-Link and Zyxel.
Additionally, our evaluation showed that large scale automated security analysis of embedded devices is possible today utilizing just open source software. To sum it up, our analysis shows that there is no router without flaws and there is no vendor who does a perfect job regarding all security aspects. Much more effort is needed to make home routers as secure as current desktop of server systems.
One comment on the report:
One-third ship with Linux kernel version 2.6.36 was released in October 2010. You can walk into a store today and buy a brand new router powered by software that’s almost 10 years out of date! This outdated version of the Linux kernel has 233 known security vulnerabilities registered in the Common Vulnerability and Exposures (CVE) database. The average router contains 26 critically-rated security vulnerabilities, according to the study.
We know the reasons for this. Most routers are designed offshore, by third parties, and then private labeled and sold by the vendors you’ve heard of. Engineering teams come together, design and build the router, and then disperse. There’s often no one around to write patches, and most of the time router firmware isn’t even patchable. The way to update your home router is to throw it away and buy a new one.
And this paper demonstrates that even the new ones aren’t likely to be secure.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Amazing Video of a Black-Eyed Squid Trying to Eat an Owlfish
From the Monterey Bay Aquarium.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Mexican Politician Removed Over Alleged Ties to Romanian ATM Skimmer Gang
The leader of Mexico’s Green Party has been removed from office following allegations that he received money from a Romanian ATM skimmer gang that stole hundreds of millions of dollars from tourists visiting Mexico’s top tourist destinations over the past five years. The scandal is the latest fallout stemming from a three-part investigation into the organized crime group by KrebsOnSecurity in 2015.
One of the Bluetooth-enabled PIN pads pulled from a compromised ATM in Mexico. The two components on the left are legitimate parts of the machine. The fake PIN pad made to be slipped under the legit PIN pad on the machine, is the orange component, top right. The Bluetooth and data storage chips are in the middle.
Jose de la Peña Ruiz de Chávez, who leads the Green Ecologist Party of Mexico (PVEM), was dismissed this month after it was revealed that his were among 79 bank accounts seized as part of an ongoing law enforcement investigation into a Romanian organized crime group that owned and operated an ATM network throughout the country.
In 2015, KrebsOnSecurity traveled to Mexico’s Yucatan Peninsula to follow up on reports about a massive spike in ATM skimming activity that appeared centered around some of the nation’s primary tourist areas.
That three-part series concluded that Intacash, an ATM provider owned and operated by a group of Romanian citizens, had been paying technicians working for other ATM companies to install sophisticated Bluetooth-based skimming devices inside cash machines throughout the Quintana Roo region of Mexico, which includes Cancun, Cozumel, Playa del Carmen and Tulum.
Unlike most skimmers — which can be detected by looking for out-of-place components attached to the exterior of a compromised cash machine — these skimmers were hooked to the internal electronics of ATMs operated by Intacash’s competitors by authorized personnel who’d reportedly been bribed or coerced by the gang.
But because the skimmers were Bluetooth-based — allowing thieves periodically to collect stolen data just by strolling up to a compromised machine with a mobile device — KrebsOnSecurity was able to detect which ATMs had been hacked using nothing more than a cheap smart phone.
In a series of posts on Twitter, De La Peña denied any association with the Romanian organized crime gang, and said he was cooperating with authorities.
But it is likely the scandal will ensnare a number of other important figures in Mexico. According to a report in the Mexican publication Expansion Politica, the official list of bank accounts frozen by the Mexican Ministry of Finance include those tied to the notary Naín Díaz Medina; the owner of the Quequi newspaper, José Alberto Gómez Álvarez; the former Secretary of Public Security of Cancun, José Luis Jonathan Yong; his father José Luis Yong Cruz; and former governors of Quintana Roo.
In May 2020, the Mexican daily Reforma reported that the skimming gang enjoyed legal protection from a top anti-corruption official in the Mexican attorney general’s office.
The following month, my reporting from 2015 emerged as the primary focus of a documentary published by the Organized Crime and Corruption Reporting Project (OCCRP) into Intacash and its erstwhile leader — 44-year-old Florian “The Shark” Tudor. The OCCRP’s series painted a vivid picture of a highly insular, often violent transnational organized crime ring (referred to as the “Riviera Maya Gang“) that controlled at least 10 percent of the $2 billion annual global market for skimmed cards.
It also details how the group laundered their ill-gotten gains, and is alleged to have built a human smuggling ring that helped members of the crime gang cross into the U.S. and ply their skimming trade against ATMs in the United States. Finally, the series highlights how the Riviera Maya gang operated with impunity for several years by exploiting relationships with powerful anti-corruption officials in Mexico.
In 2019, police in Mexico arrested Tudor for illegal weapons possession, and raided his various properties there in connection with an investigation into the 2018 murder of his former bodyguard, Constantin Sorinel Marcu.
According to prosecution documents, Marcu and The Shark spotted my reporting shortly after it was published in 2015, and discussed what to do next on a messaging app:
The Shark: Krebsonsecurity.com See this. See the video and everything. There are two episodes. They made a telenovela.
Marcu: I see. It’s bad.
The Shark: They destroyed us. That’s it. Fuck his mother. Close everything.
The intercepted communications indicate The Shark also wanted revenge on whoever was responsible for leaking information about their operations.
The Shark: Tell them that I am going to kill them.
Marcu: Okay, I can kill them. Any time, any hour.
The Shark: They are checking all the machines. Even at banks. They found over 20.
Marcu: Whaaaat?!? They found? Already??
Since the OCCRP published its investigation, KrebsOnSecurity has received multiple death threats. One was sent from an email address tied to a Romanian programmer and malware author who is active on several cybercrime forums. It read:
“Don’t worry.. you will be killed you and your wife.. all is matter of time amigo :)”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Software Firm Owner Admits Fraud and CSAM Possession
Software Firm Owner Admits Fraud and CSAM Possession

The owner of two companies based in Virginia has pleaded guilty to orchestrating a million-dollar fraud scheme, engaging in unlawful monetary transactions, and receipt of child sexual abuse material (CSAM).
Gordon G. Miller III, of Glen Allen, is the sole owner and operator of software engineering company G3 Systems Inc. and self-described venture capital company G3i Ventures LLC.
According to court documents, the 56-year-old started engaging in multiple fraud schemes starting around 2017 to prevent his businesses from failing and to maintain his lifestyle in the absence of legitimate income.
Among the schemes orchestrated by Miller was one in which he represented himself in an online forum as a high-net-worth individual with multiple advanced degrees. Miller falsely claimed on the forum to be an expert in investing in tech companies and made other misrepresentations.
From at least ten individuals whom he met via the forum, Miller fraudulently obtained around $1m between 2017 and 2018.
Miller lied again about his educational achievements when carrying out another fraudulent scheme to divert a federal subcontract to G3 Systems.
“Once he secured the subcontract, Miller submitted fraudulent timesheets and invoices to obtain more than $300,000 in payments from the prime contractor,” said the US Attorney’s Office for the Eastern District of Virginia.
“Between 2018 and 2019, Miller took checks he received from the contractor to a check-cashing store in Richmond to convert the proceeds of the contract-fraud scheme to cash.”
While investigating Miller’s fraudulent activities, federal agents executed a search warrant on the businessman’s residence. A preliminary examination of electronic devices seized from Miller’s home uncovered the presence of child sexual abuse material.
A further search warrant was obtained specifically targeting such material. While executing that warrant, agents discovered more than 700 sexually explicit videos and photographs of minors. The cache had been obtained by Miller between August 2017 and September 2000.
Miller pleaded guilty to the three charges on February 16 and is due to be sentenced on June 14. For the wire fraud and unlawful monetary transaction offenses, he faces a maximum total penalty of 30 years in prison, respectively. The receipt of child pornography offense could extend Miller’s custodial sentence by a maximum of 20 years.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
California DMV Halts Data Transfers After Vendor Breach
California DMV Halts Data Transfers After Vendor Breach

A recent cyber-attack on a company based in Seattle, Washington, may have compromised the data of millions of drivers residing in California.
The California Department of Motor Vehicles has contracted with Automatic Funds Transfer Services, Inc. (AFTS) since 2019 to cross-reference addresses with the national database as part of a process to ensure the addresses to which vehicle registration renewal notices are mailed are correct.
According to a statement released by the DMV on Wednesday, data belonging to its customers may have been compromised when AFTS was hit with a ransomware attack earlier this month.
“Automatic Funds Transfer Services, Inc. (AFTS) of Seattle was the victim of a ransomware attack in early February that may have compromised information provided to AFTS by the DMV, including the last 20 months of California vehicle registration records that contain names, addresses, license plate numbers and vehicle identification numbers (VIN),” said the DMV.
“AFTS does not have access to DMV customers’ Social Security numbers, birthdates, voter registration, immigration status or driver’s license information, therefore this data was not compromised.”
Since learning of the security incident, the DMV has ceased all data transfers to AFTS and reported the cybercrime to law enforcement, including the Federal Bureau of Investigation.
“Data privacy is a top priority for the DMV. We are investigating this recent data breach of a DMV vendor in order to quickly provide clarity on how it may impact Californians,” said DMV director Steve Gordon.
“We are looking at additional measures to implement to bolster security to protect information held by the DMV and companies that we contract with.”
Officials at the DMV said that no evidence had come to light that California drivers’ data stolen in the attack had been misused.
“While the DMV Investigations branch has no indication at this time that information accessed by the ransomware attack on AFTS has been used by the attackers for any nefarious reason, the DMV urges customers to report any suspect activity to law enforcement,” officials said in a statement seen by ABC News.
“The DMV will continue to monitor the situation and work with the appropriate law enforcement agencies.”
Statistics based on 2019 population estimates suggest that California, with more than 26 million licensed drivers, has more licensed drivers than any other state.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Jails Celebrated Nigerian Entrepreneur for Cyber-Fraud
US Jails Celebrated Nigerian Entrepreneur for Cyber-Fraud

A Nigerian entrepreneur who was nominated for Africa’s most prestigious award for businessmen has been imprisoned in the United States for masterminding a multimillion-dollar cyber-fraud scheme.
Obinwanne Okeke headed a criminal team that used email-based cyber-attacks to steal credentials from hundreds of victims from approximately 2015 to 2019. The data they swiped was used to target companies with fraudulent wire-transfer requests and fake invoices.
British company Unatrac Holding Limited, the export sales office for American Fortune 100 corporation Caterpillar, was among Okeke’s victims.
A Unatrac executive unwittingly revealed their login credentials to Okeke’s criminal organization after falling victim to a phishing email in April 2018.
“Okeke participated in the effort to victimize Unatrac through fraudulent wire transfers totaling nearly $11m, which was transferred overseas,” said the US Attorney’s Office for the Eastern District of Virginia in a statement released February 16.
According to court documents, Okeke engaged in other forms of cyber-fraud, including creating fraudulent web pages and sending phishing emails to capture email credentials. His actions caused financial loss to numerous victims.
“Through subterfuge and impersonation, Obinwanne Okeke engaged in a multi-year global business email and computer hacking scheme that caused a staggering $11 million in losses to his victims,” said Raj Parekh, acting US Attorney for the Eastern District of Virginia.
Thirty-three-year-old Okeke is the founder of Invictus Group, which operates in Nigeria, South Africa, and Zambia and was selected by the African Brand Congress to win the Most Innovative Investment Company of the Year Award 2017.
Nominated for the AABLA Awards in the category of Young African Business Leader (West Africa), Okeke is a regular contributor to the Forbes Africa magazine. He also previously appeared on the magazine’s “30 under 30” list.
On June 18, 2020, Okeke pleaded guilty to a charge of conspiracy to commit wire fraud. He was sentenced to ten years in prison on February 16.
“This sentencing demonstrates the FBI’s commitment to working with our partners at the Department of Justice and our foreign counterparts to locate cyber-criminals across the globe and bring them to the United States to be held accountable,” said Brian Dugan, special agent in charge of the FBI’s Norfolk Field Office.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk