Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Novel Online Shopping Malware Hides in Social-Media Buttons
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
VMware Rolls a Fix for Formerly Critical Zero-Day Bug
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Vancouver Metro Disrupted by Egregor Ransomware
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Bigfin Squid Found in Australian Waters
A bigfin squid has been found — and filmed — in Australian waters for the first time.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
The 2020 Workshop on Economics and Information Security (WEIS)
The workshop on Economics and Information Security is always an interesting conference. This year, it will be online. Here’s the program. Registration is free.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Enigma Machine Recovered from the Baltic Sea
Neat story:
German divers searching the Baltic Sea for discarded fishing nets have stumbled upon a rare Enigma cipher machine used by the Nazi military during World War Two which they believe was thrown overboard from a scuttled submarine.
Thinking they had discovered a typewriter entangled in a net on the seabed of Gelting Bay, underwater archaeologist Florian Huber quickly realised the historical significance of the find.
EDITED TO ADD: Slashdot thread.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
IRS to Make ID Protection PIN Open to All
The U.S. Internal Revenue Service (IRS) said this week that beginning in 2021 it will allow all taxpayers to apply for an identity protection personal identification number (IP PIN), a single-use code designed to block identity thieves from falsely claiming a tax refund in your name. Currently, IP PINs are issued only to those who fill out an ID theft affidavit, or to taxpayers who’ve experienced tax refund fraud in previous years.

Tax refund fraud is a perennial problem involving the use of identity information and often stolen or misdirected W-2 forms to electronically file an unauthorized tax return for the purposes of claiming a refund in the name of a taxpayer.
Victims usually first learn of the crime after having their returns rejected because scammers beat them to it. Even those who are not required to file a return can be victims of refund fraud, as can those who are not actually due a refund from the IRS.
Many of the reasons why refund fraud remains a problem have to do with timing, and some of them are described in more detail here. But the short answer is the IRS is under tremendous pressure to issue refunds quickly and to minimize “false positives” (flagging legitimate claims as fraud) — even when it may not yet have all of the information needed to accurately distinguish phony filings from legitimate ones.
One way the IRS has sought to stem the flow of bogus tax refund applications is to issue the IP PIN, which is a six-digit number assigned to eligible taxpayers to help prevent the use of their Social Security number on a fraudulent income tax return. Each PIN is good only for the tax year for which it was issued.
But up until now, the IRS has restricted who can apply for an IP PIN, although it has over the past few years issued them proactively to some taxpayers as part of a multi-state experiment to determine if doing so more widely might reduce the overall incidence of refund fraud.
The IRS says it will make its Get IP PIN tool available to all taxpayers in mid-January. Until then, if you haven’t already done so you should plant your flag at the IRS by stepping through the agency’s “secure access authentication” process.
Creating an account requires supplying a great deal of personal data; the information that will be requested is listed here.
The signup process requires one to validate ownership of a mobile phone number in one’s name, and it will reject any voice-over-IP-based numbers such as those tied to Skype or Google Voice. If the process fails at this point, the site should offer to send an activation code via postal mail to your address on file.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Universities Attacked by Phishing Campaign
Universities Attacked by Phishing Campaign

Universities and colleges around the world are being targeted by a new phishing campaign, according to fresh research published by RiskIQ.
Among the educational establishments to be hit by the Shadow Academy campaign are Louisiana State University (LSU) in the United States and Oxford, Brighton, and Wolverhampton Universities in the United Kingdom.
RiskIQ researchers got wind of Shadow Academy threat actors’ malicious activity at the beginning of July 2020, when it showed up on their internet intelligence graph.
By tracking the campaign from July to October 2020, researchers uncovered 20 unique targets in Australia, Afghanistan, the UK, and the USA.
According to researchers, the tactics, techniques, and procedures (TTPs) used across the campaign’s attack were “similar” to those deployed by the Mabna Institute, an Iranian company that, according to the FBI, was created for illegally gaining access “to non-Iranian scientific resources through computer intrusions.”
Researchers found that 63% of the universities were targeted with general access or student portal attacks, 37% were targeted with library-themed attacks, and 11% of the universities were hit with attacks themed around financial aid.
LSU, which suffered a student portal domain shadowing attack, was the first target identified by RiskIQ crawl data.
“Domain shadowing intercepts account traffic flowing to existing, registered, and otherwise trustworthy web domains,” wrote researchers.
“First, threat actors steal domain account credentials. They then register unauthorized subdomains to point traffic to malicious servers or, in this case, create phishing pages.”
Researchers discovered that Shadow Academy had hosted similar malicious infrastructure to orchestrate attacks against three other universities.
“RiskIQ’s internet intelligence graph helped unearth a new batch of compromised domains by keying in on the URL structure and date range of registration,” noted researchers.
“Subdomains created from these domains spanned multiple campaign themes, which focused primarily on credential harvesting and financial theft.”
The credential-harvesting URLs detected by researchers were mainly focused on services like Amazon, Instagram, and online banking.
Researchers believe the timing of the campaign’s launch was chosen to coincide with the July release of timelines for on-campus operations by many college campuses.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Bank Employee Sells Personal Data of 200k Clients
Bank Employee Sells Personal Data of 200k Clients

South Africa–based financial services group Absa has stated that one of its employees sold the personal information of 200,000 clients to third parties.
The group confirmed on Wednesday that the illegal activity had occurred and that 2% of Absa’s retail customer base had been impacted.
The employee allegedly responsible for it was a credit analyst who had access to the group’s risk-modeling processes.
Data exposed as a result of the security incident included clients’ ID numbers, addresses, contact details, and descriptions of vehicles that they had purchased on finance.
Financial details including PIN codes and passwords were not compromised by the data theft.
In an interview with ENCA, Absa group chief security officer Sandro Bucchianeri said that the employee believed to be behind the data theft was someone whom “we trusted” and who “had access to the information as part of their day job.”
The analyst, who Bucchianeri said is now facing “broad criminal charges,” has been suspended while the matter is investigated further.
Bucchianeri added that the parties who allegedly purchased the data from the analyst may use it to “try to commit fraud on these accounts.”
The data breach was discovered on October 27; however, Absa waited a month before revealing that client information had been compromised. Bucchianeri said that the delay was a deliberate move to ensure that “court processes” were not jeopardized.
After discovering that a breach had occurred, Absa obtained court orders for search and seizure operations to be carried out at “various premises.”
The bank told Business Insider South Africa that all devices containing the stolen customer data had been found and wiped clean of the information.
The incident at Absa follows the August theft of personal details belonging to 24 million South Africans and nearly 800,000 businesses from Experian in what was one of South Africa’s largest ever data breaches. Information swiped in the breach included names, ID numbers, telephone numbers, addresses, and email addresses.
Customers of Absa, Capitec, Standard Bank, Nedbank, and First National Bank were affected by the incident.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk