Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Apple iOS 14 Thwarts iMessage Attacks With BlastDoor System
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Including Hackers in NATO Wargames
This essay makes the point that actual computer hackers would be a useful addition to NATO wargames:
The international information security community is filled with smart people who are not in a military structure, many of whom would be excited to pose as independent actors in any upcoming wargames. Including them would increase the reality of the game and the skills of the soldiers building and training on these networks. Hackers and cyberwar experts would demonstrate how industrial control systems such as power supply for refrigeration and temperature monitoring in vaccine production facilities are critical infrastructure; they’re easy targets and should be among NATO’s priorities at the moment.
Diversity of thought leads to better solutions. We in the information security community strongly support the involvement of acknowledged nonmilitary experts in the development and testing of future cyberwar scenarios. We are confident that independent experts, many of whom see sharing their skills as public service, would view participation in these cybergames as a challenge and an honor.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Squids Don’t Like Pile-Driving Noises
New research:
Pile driving occurs during construction of marine platforms, including offshore windfarms, producing intense sounds that can adversely affect marine animals. We quantified how a commercially and economically important squid (Doryteuthis pealeii: Lesueur 1821) responded to pile driving sounds recorded from a windfarm installation within this species’ habitat. Fifteen-minute portions of these sounds were played to 16 individual squid. A subset of animals (n = 11) received a second exposure after a 24-h rest period. Body pattern changes, inking, jetting, and startle responses were observed and nearly all squid exhibited at least one response. These responses occurred primarily during the first 8 impulses and diminished quickly, indicating potential rapid, short-term habituation. Similar response rates were seen 24-h later, suggesting squid re-sensitized to the noise. Increased tolerance of anti-predatory alarm responses may alter squids’ ability to deter and evade predators. Noise exposure may also disrupt normal intraspecific communication and ecologically relevant responses to sound.
Press release.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New iMessage Security Features
Apple has added added security features to mitigate the risk of zero-click iMessage attacks.
Apple did not document the changes but Groß said he fiddled around with the newest iOS 14 and found that Apple shipped a “significant refactoring of iMessage processing” that severely cripples the usual ways exploits are chained together for zero-click attacks.
Groß notes that memory corruption based zero-click exploits typically require exploitation of multiple vulnerabilities to create exploit chains. In most observed attacks, these could include a memory corruption vulnerability, reachable without user interaction and ideally without triggering any user notifications; a way to break ASLR remotely; a way to turn the vulnerability into remote code execution;; and a way to break out of any sandbox, typically by exploiting a separate vulnerability in another operating system component (e.g. a userspace service or the kernel).
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
The Taxman Cometh for ID Theft Victims
The unprecedented volume of unemployment insurance fraud witnessed in 2020 hasn’t abated, although news coverage of the issue has largely been pushed off the front pages by other events. But the ID theft problem is coming to the fore once again: Countless Americans will soon be receiving notices from state regulators saying they owe thousands of dollars in taxes on benefits they never received last year.
One state’s experience offers a window into the potential scope of the problem. Hackers, identity thieves and overseas criminal rings stole over $11 billion in unemployment benefits from California last year, or roughly 10 percent of all such claims the state paid out in 2020, the state’s labor secretary told reporters this week. Another 17 percent of claims — nearly $20 billion more – are suspected fraud.
California’s experience is tracked at a somewhat smaller scale in dozens of other states, where chronically underfunded and technologically outdated unemployment insurance systems were caught flat-footed by an avalanche of fraudulent claims. The scammers typically use stolen identity data to claim benefits, and then have the funds credited to an online account that they control.
States are required to send out 1099-G forms reporting taxable income by Jan. 31, and under federal law unemployment benefits are considered taxable income. Unfortunately, many states have not reconciled their forms with confirmed incidences of fraudulent unemployment insurance claims, meaning many people are being told they owe a great deal more in taxes than they actually do.
In a notice posted Jan. 28, the U.S. Internal Revenue Service urged taxpayers who receive forms 1099-G for unemployment benefits they didn’t actually get because of ID theft to contact their appropriate state agency and request a corrected form.
But the IRS’s advice ignores two rather inconvenient realities. The first is that the same 1099-G forms which states are sending to their citizens also are reported to the IRS — typically at the same time the notices are mailed to residents. The other is that many state agencies are completely overwhelmed right now.
Karl Fava, a certified public accountant in Michigan, told KrebsOnSecurity two of his clients have received 1099-G forms from Michigan regarding thousands of dollars in unemployment payments that they had neither requested nor received.
Fava said Michigan recently stood up a website where victims of unemployment insurance fraud who’ve received incorrect 1099-Gs can report it, but said he’s not confident the state will issue corrected notices before the April 15 tax filing deadline.
“In both cases, the recipients contacted the state but couldn’t get any help,” Fava said. “We’re not getting a lot of traction in resolving this issue. But the fact that they’ve now created a web page where people can input information about receiving these tells you they have to know how prevalent this is.”
Fava said for now he’s advising his clients who are dealing with this problem to acknowledge the amount of fraudulent income on their federal tax returns, but also to subtract an equal amount on the return and note that the income reported by the state was due to fraud.
“That way, things can be consistent with what the IRS already knows,” Fava said. “Not to acknowledge an issue like this on a federal return is just asking for a notice from the IRS.”
The Taxpayer Advocate Service, an independent office of the U.S. Internal Revenue Service (IRS) that champions taxpayer advocacy issues, said it recently became aware that some taxpayers are receiving 1099-Gs that include reported income due to unemployment insurance identity theft. The office said it is hearing about a lot of such issues in Ohio particularly, but that the problem is happening nationally.
Another perennial (albeit not directly related) identity theft scourge involving taxes each year is refund fraud. Tax refund fraud involves the use of identity information and often stolen or misdirected W-2 forms to electronically file an unauthorized tax return for the purposes of claiming a refund in the name of a taxpayer.
Victims usually first learn of the crime after having their returns rejected because scammers beat them to it. Even those who are not required to file a return can be victims of refund fraud, as can those who are not actually due a refund from the IRS.
The best way to avoid tax refund fraud is to file your taxes as early possible. This year, that date is Feb. 12. One way the IRS has sought to stem the flow of bogus tax refund applications is to issue the IP PIN, which is a six-digit number assigned to taxpayers that helps prevent the use of their Social Security number on a fraudulent income tax return. Each PIN is good only for the tax year for which it was issued.
Until recently the IRS restricted who could apply for an IP PIN, but the program has since been opened to all taxpayers. To create one, if you haven’t already done so you will need to plant your flag at the IRS by stepping through the agency’s “secure access authentication” process.
Creating an account requires supplying a great deal of personal data; the information that will be requested is listed here.
The signup process requires one to validate ownership of a mobile phone number in one’s name, and it will reject any voice-over-IP-based numbers such as those tied to Skype or Google Voice. If the process fails at this point, the site should offer to send an activation code via postal mail to your address on file.
Once you have an account at the IRS and are logged in, you can request an IP PIN by visiting this link and following the prompts. The site will then display a six digit PIN that needs to be included on your federal return before it can be accepted. Be sure to print out a copy and save it in a secure place.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Social Media Influencer Charged with Election Interference
Social Media Influencer Charged with Election Interference

An American social media influencer has been charged with running a misinformation campaign that tricked social media users into believing that they could vote by text message in the 2016 US presidential election.
Douglass Mackey, aka Ricky Vaughn, was arrested yesterday morning on charges of conspiring with others ahead of the election to spread misinformation designed to deprive US citizens of their constitutional right to vote.
Mackey, of West Palm Beach, Florida, was charged by criminal complaint in the Eastern District of New York and released on a $50k bond. According to the complaint, the 31-year-old shared fraudulent messages encouraging supporters of one of the presidential candidates to vote via text message or social media, a legally invalid method of voting.
Among the misinformation allegedly shared by Mackey was an image shared on November 1, 2016, on Twitter that showed an African American woman standing in front of an “African Americans for Hillary Clinton” sign. The image included the following text: “Avoid the Line. Vote from Home. Text ‘Hillary’ to 59925[.] Vote for Hillary and be a part of history.”
Fine print at the bottom of the image stated “Must be 18 or older to vote. One vote per person. Must be a legal citizen of the United States. Voting by text not available in Guam, Puerto Rico, Alaska or Hawaii. Paid for by Hillary for President 2016.”
At least 4,900 unique telephone numbers texted the name Hillary or some derivative to the 59925 number.
In 2016, Mackey had approximately 58,000 Twitter followers. A February 2016 analysis by the MIT Media Lab ranked one of Mackey’s Twitter handles @Ricky_Vaughn99 as the 107th most important influencer of the then-upcoming election.
By comparison, NBC News was ranked #114, the Washington Post at #43, Vladimir Putin at #41, the musician Cher at #101, and Beau Biden at #63.
“What Mackey allegedly did to interfere with this process—by soliciting voters to cast their ballots via text—amounted to nothing short of vote theft,” said William Sweeney Jr., assistant director in charge of the FBI’s New York Field Office.
“It is illegal behavior and contributes to the erosion of the public’s trust in our electoral processes.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Return to SMS as Security Feature
Return to SMS as Security Feature

New research by California IT service management company Okta has found an increase in the use of SMS as a security feature during the Covid-19 health crisis.
The finding emerged from the latest “Businesses at Work” report, which analyzed the login activity of Okta’s 9,400 customers to reveal the ways in which companies have improved their security posture in response to the pandemic.
Analysis of the data revealed that although use of SMS as a security feature dropped from 53% two years ago to 49% today, its use grew 116% between February and October 2020.
During the same period, use of MFA factor and authenticator app Okta Verify increased 184%, compared to just 28% over the previous six months.
Researchers noted that companies invested heavily in people-centric security tools last year. The deployment of security-awareness training tools such as KnowBe4 grew 46% since the start of 2020, and 194% in the past two years.
Out of more than 6,500 apps, 1Password was Okta’s tenth fastest growing app in 2020. Usage of the app has increased by 582% in the past two years.
According to the report, the top five most popular people-centric security tools were KnowBe4, MimeCast, Envoy, LastPass, and Proofpoint.
“Visitor management tool Envoy is an interesting case,” noted an Okta spokesperson. “With sharp drops in workers’ physical presence in offices, but growing concerns about managing the number of workers in a space at one time, Envoy—Okta’s eighth fastest growing app last year—grew 32% in the past year.”
A key finding to emerge from the data analysis was that to accommodate a distributed workforce, organizations adopted new security strategies like Zero Trust and modern firewalls.
The most popular network-centric security tools in 2020 were Palo Alto Networks, Cisco AnyConnect, and Netskope.
Use of Palo Alto Networks, which provides enterprise security protection to mobile users, grew 1983% over the past three years. Over the same period, secure endpoint access provider Cisco AnyConnect grew 1130%, with 46% of that growth occurring since the end of February 2020.
Use of Netskope, which provides contextual security and mitigates cloud-enabled threats, grew 74% in the past year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Launches Global Action Against NetWalker
US Launches Global Action Against NetWalker

The United States Department of Justice has launched a global law enforcement action against a cyber-criminal gang that has made millions by selling ransomware-as-a-service (RaaS).
A coordinated international law enforcement action to disrupt NetWalker was announced by the Department yesterday.
NetWalker ransomware has claimed numerous victims, including companies, municipalities, hospitals, law enforcement departments, emergency services, school districts, colleges, and universities. In June last year, the University of California San Francisco admitted paying $1.14m to recover important academic work stored on some of its School of Medicine servers that had been encrypted by NetWalker.
“This action reflects the resolve of the US Attorney’s Office for the Middle District of Florida to target and disrupt sophisticated, international cybercrime schemes,” said US Attorney Maria Chapa Lopez for the Middle District of Florida.
“While these individuals believe they operate anonymously in the digital space, we have the skill and tenacity to identify and prosecute these actors to the full extent of the law and seize their criminal proceeds.”
According to court documents, NetWalker operates a RaaS model featuring “developers” and “affiliates” who split ransom payments made by victims.
While developers are responsible for creating and updating the ransomware and making it available to affiliates, affiliates are tasked with identifying and attacking high-value victims with the malware.
The NetWalker action includes charges against Canadian national Sebastien Vachon-Desjardins of Gatineau, Ottawa, in relation to ransomware attacks that allegedly netted NetWalker at least $27.6m.
The action also includes the January 10 seizure of over $454k in crypto-currency from ransom payments made by victims of three separate NetWalker attacks, and the disablement by Bulgarian authorities of a hidden resource on the dark web that NetWalker used to communicate with their victims. Visitors to the resource will now be greeted with a seizure notice.
“We are striking back against the growing threat of ransomware by not only bringing criminal charges against the responsible actors, but also disrupting criminal online infrastructure and, wherever possible, recovering ransom payments extorted from victims,” said Acting Assistant Attorney General Nicholas McQuaid of the Justice Department’s Criminal Division.
“Ransomware victims should know that coming forward to law enforcement as soon as possible after an attack can lead to significant results like those achieved in today’s multi-faceted operation.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Schneider Partners with Immersive Labs to Launch Virtual Training Platform
Schneider Partners with Immersive Labs to Launch Virtual Training Platform

Schneider Electric has announced the launch of a virtual cyber-academy in collaboration with Immersive Labs. The Schneider Electric Cyber Academy will enable businesses to provide cybersecurity training for employees at all levels as well as have monitoring workplace capabilities.
The academy will be delivered through Immersive Labs’ gamified entry-level skills platform. Companies that sign up will gain access to more than 200 labs and be able to monitor improvements in workforce capability.
This aims to help businesses to proactively identify security weaknesses and prepare to deal with attacks. The academy offers bespoke education programs that cover specific areas that are tailored to individual employees with in-built scoring mechanisms to encourage engagement.
A feature of the platform is its ‘battle-test’ scenarios, which enable teams to practise dealing with realistic cyber-incidents. These include scenarios based on cyber-incidents such as Norsk Hydro, forcing teams to apply their skills to real-world challenges.
The academy has been developed in the context of an evolving threat landscape, with many businesses at higher risk of attacks as a result of the shift to home working during COVID-19. Schneider added that the cyber-academy is constantly updated to take into account changes in the methods used by cyber-criminals.
Insufficient security training for staff has been a long-standing problem, with numerous studies indicating the issue has worsened since the move to remote working since the start of COVID-19.
Victor Lough, cybersecurity and advanced digital services business lead at Schneider Electric, commented: “People are the first and most susceptible line of defense against cyber-attacks. It is therefore more important than ever to ensure your teams are trained to deal with the plethora of threats they face.
“The Schneider Electric Cyber Academy enables training to continue remotely and be time-efficient for all involved. With more employees than ever working from home, ensuring security protocols and training are up-to-date must be a key priority not just now, but for the foreseeable future.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk