Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Outgoing FCC Chair Issues Final Security Salvo Against China
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cisco DNA Center Bug Opens Enterprises to Remote Attack
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
SonicWall Breach Stems from ‘Probable’ Zero-Days
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Insider Attack on Home Surveillance Systems
No one who reads this blog regularly will be surprised:
A former employee of prominent home security company ADT has admitted that he hacked into the surveillance feeds of dozens of customer homes, doing so primarily to spy on naked women or to leer at unsuspecting couples while they had sex.
[…]
Authorities say that the IT technician “took note of which homes had attractive women, then repeatedly logged into these customers’ accounts in order to view their footage for sexual gratification.” He did this by adding his personal email address to customer accounts, which ultimately hooked him into “real-time access to the video feeds from their homes.”
Slashdot thread.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Cyber-attack Advice for European Hospitals
New Cyber-attack Advice for European Hospitals

The European Data Protection Board has issued new advice to hospitals regarding what action to take in the event of a cyber-attack.
Currently released in draft form, the new set of recommendations urges healthcare providers hit with ransomware to report the attack even if no patient data is accessed or exfiltrated.
The guidelines state: “The internal documentation of a breach is an obligation independent of the risks pertaining to the breach and must be performed in each and every case.”
A series of attack scenarios are described in the recommendations along with appropriate prior measures, risk assessment, mitigation, and obligations.
“The fact that a ransomware attack could have taken place is usually a sign of one or more vulnerabilities in the [data] controller’s system,” state the guidelines.
In example case number three, a hospital suffers a ransomware attack in which data was encrypted but not exfiltrated and backups of the data are available in an electronic form. Such an attack could have a large impact on patients, according to the EDPB.
“The quantity of breached data and the number of affected data subjects are high, because hospitals usually process large quantities of data,” state the guidelines.
“The unavailability of the data has a high impact on a substantial part of the data subjects. Moreover, there is a residual risk of high severity to the confidentiality of the patient data.”
Despite data restoration’s being possible in this circumstance, the EDPB said such an attack still posed a big risk to patient data.
“The type of the breach, nature, sensitivity, and volume of personal data affected in the breach are important,” state the guidelines.
“Even though a backup for the data existed and it could be restored in a few days, a high risk still exists due to the severity of consequences for the data subjects resulting from the lack of availability of the data at the moment of the attack and the following days.”
The guidelines go on to say that patients who experience major delays in care as a result of a ransomware attack should be informed directly of the attack by the data controller.
“It might be a step too far, to require a communication like this,” commented Dirk Schrader, global vice president at New Net Technologies (NNT).
“The formulated requirement to communicate a data breach to patients affected with the delays caused by it, can create another path for extortion by attackers.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Home Security Technician Admits Spying on Customers
Home Security Technician Admits Spying on Customers

A former home security technician has admitted habitually hacking into customers’ home surveillance cameras to spy on people without their consent.
Telesforo Aviles accessed the accounts of around 200 customers more than 9,600 times over a period of four and half years while employed by security company ADT.
The 35-year-old carried out the cyber-intrusions for his own sexual gratification. He made a note of which camera feeds were linked to the homes of women he deemed attractive, then logged into these feeds repeatedly.
Aviles admitted watching numerous videos of naked women and couples engaging in sexual activity inside their homes.
“Mr. Aviles admits that contrary to company policy, he routinely added his personal email address to customers’ ‘ADT Pulse’ accounts, giving himself real-time access to the video feeds from their homes,” said the Department of Justice in a statement. “In some instances, he claimed he needed to add himself temporarily in order to ‘test’ the system; in other instances, he added himself without their knowledge.”
Aviles pleaded guilty yesterday in federal court to charges of computer fraud, according to the US Attorney’s Office for the Northern District of Texas. He now faces a maximum sentence of five years in prison.
ADT officials told the Dallas Morning News that it “deeply regrets” the incidents and that affected customers have been informed of the intrusion on their most private moments.
Brandon Hoffman, chief information security officer at Netenrich, said that Aviles’ criminal activity highlighted the continued growth of privacy concerns among consumers.
“With the rising exposure of privacy intrusions by basic connected devices, such as Alexa and Google, home devices buyers should beware systems like this that have active intrusion capability,” Hoffman told Infosecurity magazine.
“While designed for the intent of security or providing additional services, it’s important to understand the detail of access these systems provide and measure the benefits versus the risk of privacy invasion.
“Additionally, there is a glaring lack of discussion and availability on protective measures against intrusion from these systems that are common or basic enough to be understood and used by non-deeply technical users.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Court Date for Woman Accused in Theft of Pelosi’s Laptop
Court Date for Woman Accused in Theft of Pelosi’s Laptop

A woman from Pennsylvania will appear before a federal court on Monday to face charges in connection with the theft of a laptop belonging to Speaker of the United States House of Representatives Nancy Pelosi.
The computer was stolen from Pelosi’s office earlier this month when a crowd of people who had been attending a political protest forced their way into the US Capitol building and disrupted the certification of then President-elect Joe Biden’s electoral victory.
Harrisburg resident Riley June Williams was arrested by federal authorities on January 18 following a tip to the FBI from the 22-year-old’s former romantic partner. The ex said that Williams appeared in a video of the Capitol invasion and had said that she intended to sell Pelosi’s stolen computer to Russian intelligence.
Williams, who has no prior criminal record, was charged with trespassing, obstruction, theft, violent entry, and conducting herself in a disorderly way on Capitol grounds.
Video from the chaotic scenes at the Capitol that unfurled on January 6 show a woman matching Williams’ description saying “upstairs, upstairs, upstairs” to people who were trespassing in the building.
An affidavit submitted to the court by an FBI agent based in Virginia stated that Williams had been seen on closed-circuit security camera footage entering and exiting the office of the speaker.
The agent said a video showing a man’s gloved hand picking up an HP laptop from a table and captioned with the words “they got the laptop” may have been shot on a cellphone belonging to Williams.
After three nights in jail, Williams was released into the custody of her mother yesterday by Federal Judge Martin Carlson and placed under travel restrictions.
Carlson ordered Williams to appear in federal court in Washington on Monday to continue her case.
“The gravity of these offenses is great,” he told Williams. “It cannot be overstated.”
Lori Ulrich, defending Williams, said the FBI’s tipster was an abusive ex-boyfriend of Williams whose accusations “are overstated.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Defense More Effective Than Offense in Curbing Nation State Threat Actors
Defense More Effective Than Offense in Curbing Nation State Threat Actors

The effectiveness of offensive capabilities in deterring nation state actors was discussed by a panel during the recent ‘RSAC 365 Innovation Showcase: Cyber Deterrence’ webinar.
Chair of the session, Jonathan Luff, co-founder at Cylon, observed that now is the ideal time to be asking if and when offensive strikes should be used following the Russian state-backed SolarWinds attacks at the end of last year, as well as the inauguration of newly-elected President Joe Biden this week. Luff noted: “The new administration has already made clear it intends to make cyber a huge priority.”
Ciaran Martin, former CEO at the National Cyber Security Centre (NCSC) in the UK, began by arguing that while offensive cyber-actions can be useful against certain types of enemies, they will not deter incidents like SolarWinds. He highlighted the UK’s successful cyber-strikes against the Islamic State back in 2018, which hindered its operations and made it harder for it to radicalize people online. However, he does not believe it would have such a positive effect in preventing cyber-attacks emanating from countries such as Russia and China. “If you knock off the six o’clock news in Moscow who’s that going to deter?” he asked.
He added that the nature of the threat China poses to the West is different to that of Russia, with its bid for technological supremacy an “existential” danger. This means there is now a clash between societies with free and open technologies and those that are authoritarian. Martin commented: “You certainly don’t counter that with cyber-attacks or by Trumpian sanctions; you counter it by innovation.”
Sian John, EMEA director, cybersecurity policy at Microsoft, said that the tech giant’s main priority in dealing with the cyber-threats posed is innovating around threat, detection and response capabilities. “We’re definitely on the defense side of that approach,” she added. More broadly, to keep the free and open internet secure, she highlighted the importance of tech companies collaborating more closely “to try and get ahead of the threat.”
The panel agreed that the role of cybersecurity startups will be vital in the development of more innovative defensive solutions going forward. Itxaso del Palacio, partner at investment firm Norton Capital, believes the challenges to organizations posed by the rapid shifts to home working and adoption of the cloud has increased the importance of startups in this space. This has, in turn, already led to more innovative solutions becoming available. “That has accelerated the need to manage and monitor these multi-cloud solutions,” she stated.
Concluding the discussion, the panellists offered reasons for positivity in relation to making the open internet more secure over the coming decade. These include an increased focus by security companies on tackling the evolving ransomware threat and the use of automation to detect dangers quickly. More generally, John said she is “really excited by the move to build privacy and security in by design rather than it being a bolt on.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
ICO Urged to Investigate Secretive Tory Party Consultancy
ICO Urged to Investigate Secretive Tory Party Consultancy

A leading rights group has asked the UK’s data protection regulator to urgently investigate the role of a shadowy political consultancy over claims that helped the Conservative Party to general election victory in 2019.
CT Group is a global lobbying and consulting firm founded by long-time Tory collaborator Lynton Crosby. Its CT Partners Limited business accounted for nearly 40% of the Conservative Party’s £4.5m spend on “Market Research/Canvassing” at the last election, way more than any other business, according to Privacy International.
However, the rights group said it has been consistently stonewalled by the firm after trying to find out exactly what services it offered in the run-up to the general election.
Regulator the Information Commissioner’s Office (ICO) is conducting an ongoing investigation into the use of personal information and data analytics for political purposes. It was sparked by revelations over the work of Cambridge Analytica, which is said to have used data harvested illegally from Facebook users and their friends to target voters in the 2016 US Presidential election.
The hiring of companies like Cambridge Analytica and CT Partners is increasingly common in modern politics, and in itself is perfectly legal.
However, there are growing concerns over how voters’ personal data is used to profile them in political campaigns, especially in opaque online “micro-targeting,” which allows parties to say different things to different people in the hope of securing their vote.
COVID-19 has accelerated the trend for this kind of virtual campaigning, which relies on the processing of vast volumes of personal data on individuals who often have no idea they’re being profiled in this way, noted Privacy International.
The non-profit’s policy director, Lucy Purdon, argued that this “invisible processing” of personal data is at the heart of its concerns about CT Partners, and could have major GDPR compliance implications.
“Most people will have no direct relationship with these companies, and are mostly unaware they are being profiled for political purposes,” she said. “It is vital that the democratic process is not undermined by these secret and opaque methods. Voters deserve better.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk