Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Amazon Sues Instagram, TikTok Influencers Over Knockoff Scam
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Botnet Attackers Turn to Vulnerable IoT Devices
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Underwater Robot Uses Squid-Like Propulsion
This is neat:
By generating powerful streams of water, UCSD’s squid-like robot can swim untethered. The “squidbot” carries its own power source, and has the room to hold more, including a sensor or camera for underwater exploration.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Inrupt’s Solid Announcement
Earlier this year, I announced that I had joined Inrupt, the company commercializing Tim Berners-Lee’s Solid specification:
The idea behind Solid is both simple and extraordinarily powerful. Your data lives in a pod that is controlled by you. Data generated by your things — your computer, your phone, your IoT whatever — is written to your pod. You authorize granular access to that pod to whoever you want for whatever reason you want. Your data is no longer in a bazillion places on the Internet, controlled by you-have-no-idea-who. It’s yours. If you want your insurance company to have access to your fitness data, you grant it through your pod. If you want your friends to have access to your vacation photos, you grant it through your pod. If you want your thermostat to share data with your air conditioner, you give both of them access through your pod.
This week, Inrupt announced the availability of the commercial-grade Enterprise Solid Server, along with a small but impressive list of initial customers of the product and the specification (like the UK National Health Service). This is a significant step forward to realizing Tim’s vision:
The technologies we’re releasing today are a component of a much-needed course correction for the web. It’s exciting to see organizations using Solid to improve the lives of everyday people – through better healthcare, more efficient government services and much more.
These first major deployments of the technology will kick off the network effect necessary to ensure the benefits of Solid will be appreciated on a massive scale. Once users have a Solid Pod, the data there can be extended, linked, and repurposed in valuable new ways. And Solid’s growing community of developers can be rest assured that their apps will benefit from the widespread adoption of reliable Solid Pods, already populated with valuable data that users are empowered to share.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
ICE Operation Arrests 113 Child Predators
ICE Operation Arrests 113 Child Predators

A joint operation by Brazil and the United States has led to the arrest of 113 people suspected of producing child sexual abuse material (CSAM) and sharing it online.
US Immigration and Customs Enforcement (ICE) Homeland Security Investigations (HSI) and the Brazil Ministry of Justice and Public Security (MJSP) Secretariat for Integrated Operation (SEOPI) Cyber Laboratory made the arrests across the US and South America between November 2 and November 6 as part of Operation Protected Childhood’s seventh phase.
OPC VII, which simultaneously targeted the distributors and producers of CSAM throughout the Americas, was conducted across multiple ICE HSI domestic field offices and executed in coordination with the agency’s Cyber Crimes Center (C3) and with law enforcement counterparts in Brazil, Argentina, Paraguay, and Panama.
In the United States, HSI offices in Pennsylvania, North Carolina, Tennessee, California, Colorado, and Florida executed 13 child exploitation–related search warrants and made nine arrests for child exploitation offenses.
HSI Raleigh and the Cary Police Department made an arrest on November 6 after receiving a lead from C3 that the suspect was posting CSAM in chat rooms on the social media app Kik. Forensics uncovered hundreds of indecent images of minors, including some naked photographs of the suspect’s own children.
In Brownsville, Pennsylvania, a search warrant was executed regarding the possession and distribution of CSAM following information supplied by Kik Inc that a suspect had used its site to share indecent images of children.
In Florida’s Panama City, a suspect was arrested by Lynn Haven Police Department following a tip from the National Center for Missing and Exploited Children that CSAM was being distributed via Facebook’s Messenger app.
Information supplied by Twitter and HSI McAllen, Texas, led to the execution of a search warrant for possession and distribution of CSAM in West Hills, California, where a suspect had allegedly used Twitter’s direct messaging to share sexually explicit images of children.
OPC was launched in March 2015 by HSI Brazil in partnership with Brazil’s MJSP Cyber Lab to increase the effectiveness of investigations into online child exploitation. Since 2017, the operation has resulted in 781 arrests, 1,383 executed search warrants, and the rescue of dozens of minor victims.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Ticketmaster Fined £1.25m Over Data Breach
Ticketmaster Fined £1.25m Over Data Breach

A British ticketing company has been financially penalized over a 2018 data breach that exposed the personal information of millions of customers across Europe.
The Information Commissioner’s Office (ICO) has fined Ticketmaster UK Limited £1.25m for failing to keep its customers’ personal data secure.
Ticketmaster issued a data breach notice in June 2018 after a third-party platform provider Inbenta Technologies was infected with malicious software.
The malware, which was detected on a customer support product, exfiltrated customer data and passed it on to an unknown attacker.
Information compromised in the incident included names, addresses, emails, telephone numbers, payment card numbers, expiry dates, CVV numbers, and Ticketmaster login details of as many as 11 million Ticketmaster customers in Europe and the United Kingdom.
An investigation into the incident by the ICO found that Ticketmaster violated the General Data Protection Regulation by failing to put “appropriate security measures in place to prevent a cyber-attack on a chat-bot installed on its online payment page.”
The breach, which began in February 2018, was discovered after Monzo Bank customers reported fraudulent transactions.
“The Commonwealth Bank of Australia, Barclaycard, Mastercard and American Express all reported suggestions of fraud to Ticketmaster,” said the ICO, “but the company failed to identify the problem.”
Investigators found that Ticketmaster only started monitoring the network traffic through its online payment page nine weeks after being alerted to possible fraud.
Investigators found that the breach caused 60,000 payment cards belonging to Barclays Bank customers to be used fraudulently. Another 6,000 cards belonging to Ticketmaster customers were replaced by Monzo Bank over suspected fraudulent use.
“A key point from this case is that the data compromised was not submitted to the chat bot itself, but to pages on which the chat bot was embedded, which hackers were then able to scrape through exploiting the chat bot,” commented Emma Erskine-Fox, associate at UK law firm TLT.
“When assessing the risks of processing personal data using software embedded into websites, organizations should therefore consider not just what data might be submitted to that particular software, but how any vulnerabilities might affect data submitted on other areas of the website.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New Center Supports Rail Cybersecurity
New Center Supports Rail Cybersecurity

An international construction engineering and mobility services company is joining forces with a software business to launch a new center that aims to protect the cybersecurity of the railway industry.
The new partnership between France-based Egis Group and Israeli tech company Cylus was announced today along with their plan to construct a Center for Excellence for advanced, rail-focused cybersecurity services.
Built in line with standards (IEC 62443), the Center will deliver a wide array of advanced security solutions and services to customers worldwide. The aim of this new resource is to support railway companies in all aspects of cybersecurity, from development of strategy and risk identification of cyber-risks through to detection and incident response.
Cylus was founded in 2017 with the mission to help mainline and urban railway companies avoid safety incidents and service disruptions caused by cyber-attacks. Leading the company is a team of former executives in the railway industry and veterans from the Israel Defense Forces’ Elite Technological Unit.
“We are thrilled to establish a partnership with Egis, which has decades of experience in providing mobility services around the globe,” said Amir Levintal, CEO of Cylus.
“This partnership strengthens our capabilities to provide end-to-end support to rail organizations in meeting the specter of cyber threats. Our joint services are designed specifically for the railway industry and will enable our customer to focus on their day-to-day operations, business, and growth, leaving their cyber-defense management to our security experts. We are certain that this partnership will drive the rail industry towards a cyber-safe future.”
Egis, a 75%-owned subsidiary of Caisse des Dépôts, which had a turnover of €1.22bn in 2019, cut its rail-sector teeth on the introduction of France’s first high-speed rail links.
“We are excited to collaborate with Cylus, the leading rail cybersecurity company. Joining forces enables us to provide our customers, unique domain expertise as well as cutting-edge cybersecurity know-how and best practices,” said Olivier Bouvart, executive director rail at Egis.
“We decided to take action and be proactive in supporting our customers by preparing them for the growing risk of cyber threats.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Shutterstock Adds Single Sign-On Integration to its Platform
Shutterstock Adds Single Sign-On Integration to its Platform

Creative content provider Shutterstock has announced the launch of turnkey single sign-on (SSO) integration on its platform to enhance security for its enterprise customers across the globe.
The tech company, which grants customer access to a database of 350+ million high-quality licensed images, videos and music tracks, said the new service can be set up in minutes.
The SSO is designed to eliminate password fatigue and speed up workflows by quickly and safely authenticating users across a number of digital platforms and identity management solutions.
Shutterstock said its SSO is now available to over 250,000 companies worldwide as it collaborates with industry-leading identity solutions providers such as Auth0, Microsoft’s Azure AD, Okta, OneLogin and Ping Identity.
“As teams navigate the challenges of working from home, having secure and centralized access to tools and platforms is essential to productivity,” said Alex Reynolds, Shutterstock vice-president and general manager of platform solutions. “The global rollout of SSO stems from our growing commitment to serve the rigorous and ever-changing needs of enterprise customers around the world.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Data Breach Hits 28 Million Texan Drivers
Data Breach Hits 28 Million Texan Drivers

A breach at an insurance software company has resulted in the compromise of 27.7 million personal and driver’s license details in Texas.
Vertafore claimed in a notification this week that, due to human error, three files were stored in an unsecured third-party service which was subsequently accessed without authorization.
The firm was unable to say exactly when this happened — only that it occurred at some point between March 11 and August 1. Vertafore has told Infosecurity that the customer notice was delayed at law enforcement’s request.
Vertafore said that, upon discovering the breach, it immediately secured the files and engaged the help of an outside consultancy to investigate further, as well as law enforcement. The firm didn’t itself detect the breach but had to be notified by a “trusted third party.”
“The files, which included driver information for licenses issued before February 2019, contained Texas driver license numbers, as well as names, dates of birth, addresses and vehicle registration histories,” it explained.
“They did not contain any Social Security numbers or financial account information. No information misuse has been identified. No customer data or any other data — including partner, vendor or other supplier data — or systems hosted for them were impacted. Additionally, no Vertafore system vulnerabilities were identified.”
Vertafore is offering affected customers free credit monitoring and identity restoration services for a year.
The firm said in its FAQs that “we are not aware of any way this information could be used to commit fraud.” However, there is certainly ample opportunity for cyber-criminals to launch convincing follow-on phishing attacks using the personal and driver’s license details compromised.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk