Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
North Carolina Launches Cybercrime Hotline
North Carolina Launches Cybercrime Hotline

North Carolina has opened a cybercrime hotline after state residents lost millions of dollars to COVID-19-related cyber-scams.
The free NC 2-1-1 phone line, one of the first to be launched in the United States, has been funded by state and federal grants.
Fraudulent schemes claiming victims in the Tarheel State include cell phone cloning, fake COVID-19 test results, fake charities, and scams that seek to exploit people who have lost jobs as a result of the pandemic.
Nichole Dennis, the program director for Cybercrime Support Network, told WCNC Charlotte: “People are falling on hard times, so there’s unemployment scams that are coming around.”
Other scams seek to take advantage of people who have become lonely while living in lockdown. Sharon D’costa, a project manager with NC 2-1-1, said she had observed a rise in the number of romance scams and also in the number of scams involving puppies for sale.
In 2019 alone, more than 8,223 complaints from individuals and small businesses in North Carolina were filed with the FBI Internet Crime Complaint Center, with monetary losses totaling $48,425,764.
State residents have reported more than $4m in fraud losses specific to COVID-19 since March, according to Federal Trade Commission data. This substantial loss makes North Carolina the 8th most targeted state in the nation when it comes to scams that exploit the global health pandemic.
“A lot of people don’t even realize that they’re a victim,” said Dennis.
“They don’t know where to report; there’s not really a clear path of what to do once you’re affected by cybercrime.”
In a bid to make reporting easier, Dennis’s cybercrime team has teamed up with United Way of North Carolina to launch a statewide cybercrime hotline.
“Just dial 2-1-1 and they will speak to our trained call specialists who have access to our resource base of more than 90,000 resources,” said D’costa.
Victims can use it to report all manner of cybercrimes, from bullying and cyber-stalking to romance scams and fraudulent vendors.
In May 2020, the Cybercrime Support Network and Heart of West Michigan United Way in partnership with the Heart of Florida United Way launched a free phone line for residents of 13 northern Michigan counties.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Executive Overconfidence a Security Risk
Executive Overconfidence a Security Risk

Executives are out of touch and overconfident when it comes to their organizations’ web application security practices, according to new research published today by Netsparker.
Netsparker teamed up with Dimensional Research to survey security professionals from 382 organizations worldwide about the maturity and effectiveness of web application security in their organizations. Respondents worked in roles spanning development, DevOps, and C-suite.
The survey found numerous areas where executives believe their organizations are more secure or adhere to best practices at a higher rate than security professionals deeper in the organization. While 75% of executives believe their organization scans all web applications for security vulnerabilities, nearly 50% of security staff said that this wasn’t the case.
Researchers noted that for organizations that intentionally limit scanning to their most important applications, separating the results by role was eye-opening.
“While close to 32% of security staff admit to this practice, for executives this is just over 18%. This suggests that many executives may be in the dark about the criteria for selecting what to scan and when to scan it.”
The results of the survey, published in the report “New Vulnerability Found: Executive Overconfidence,” appear to show that organizations’ existing web application security efforts are insufficient. Researchers found that while over 60% of DevOps respondents said that new security vulnerabilities are being found faster than they can be fixed, only just over 40% of executives are aware of this situation.
Other disparities picked up by the survey relate to internal resistance and friction. While 20% of developers believe that development teams are resistant to incorporating security, close to half of security professionals say they encounter developer resistance.
Furthermore, just under 35% of developers report friction caused by security false positives, compared to over 54% of security staff.
“The survey shows a worrying disconnect between the theory and practice of web application security,” said a spokesperson for Netsparker.
“While most organizations appreciate the importance of web security, many still don’t scan all their applications and an even greater number struggle to deal with vulnerabilities in a timely manner.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Russia Blamed for Cyber-attack on Norwegian Parliament
Russia Blamed for Cyber-attack on Norwegian Parliament

Russia has been accused of carrying out a “significant” cyber-attack on the Norwegian parliament earlier this year.
In August, unauthorized individuals managed to gain access to the email accounts of several elected members of the Storting, Norway’s single-chamber parliament. The cyber-criminals also targeted some accounts belonging to parliament employees.
An unspecified amount of data was stolen in the attack, which impacted some members of Norway’s main opposition party, the Labour Party.
Speaking to the Norwegian press just after the attack took place, the Norwegian parliament’s director, Marianne Andreassen, said: “We don’t know who’s behind it.” However, on Tuesday, Norway’s foreign minister, Ine Eriksen Soereide, laid the blame for the attack squarely at Russia’s door.
“This is a serious event that hit our most important democratic institution,” said Soereide.
“Based on the information available to the government, it is our assessment that Russia stood behind this activity.”
Soereide did not give details of any action that Norway might take against its Arctic neighbor. A Norwegian foreign ministry spokeswoman declined to comment when asked by Reuters whether Russia would be asked to recall its ambassador or any of its diplomats from Norway.
In September 2018, a Russian IT adviser named Mikhail Bochkaryov was arrested at Oslo Airport after exhibiting strange behavior at an IT conference held in Norway’s parliament.
Bochkaryov, an employee of the Russian parliament’s upper chamber, had been attending a seminar organized by the European Centre for Parliamentary Research and Documentation on the Storting’s digitalization process.
Norway’s Police Security Service (PST) said the IT professional had been detained on suspicion of illegal intelligence activities.
Russia’s foreign ministry summoned Norway’s ambassador to protest the arrest and demand the release of Bochkaryov by NATO member Norway. After several weeks in detention, Bochkaryov was released without charge and returned to Moscow.
In 2017, Norway accused APT 29 of carrying out spear-phishing attacks on Norway’s foreign ministry, army, and other institutions. Arne Christian Haugstoyl, an official with PST, said that the group, which has “links to the Russian authorities,” had targeted nine different email accounts.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Hackney Hacked as Council Investigates Attack
Hackney Hacked as Council Investigates Attack

London’s Hackney Council has reported it has “been the target of a serious cyber-attack which is affecting many of our services and IT systems.”
According to a statement from Philip Glanville, mayor of Hackney, council officers have been working closely with the National Cyber Security Centre, external experts and the Ministry of Housing, Communities and Local Government to investigate and understand the impact of the incident.
“This investigation is at an early stage, and limited information is currently available,” he said. “We will continue to provide updates as our investigation progresses. Our focus is on continuing to deliver essential frontline services, especially to our most vulnerable residents, and protecting data, while restoring affected services as soon as possible.”
Jake Moore, cybersecurity specialist at ESET, commented: “This bears all the hallmarks of a ransomware attack, but what we should be worried about is the new direction that threat actors are taking these days, where they not only encrypt the data but they threaten to release it too. Councils which may lack funding, and consequently may not have the strongest network protection, can be an easy target for those looking for vulnerabilities to exploit.
“Unfortunately, there is big money to be made and criminal hackers are quick to adapt and make their crime pay.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Global Firms Seek Zero-Trust as 58% Suffer COVID-Era Breach
Global Firms Seek Zero-Trust as 58% Suffer COVID-Era Breach

Over half of global organizations have suffered a data breach during the COVID-19 crisis, with even more arguing that they need to shift to a zero-trust model to bolster security, according to Forrester.
A new report commissioned by Cloudflare and set to be officially released on Wednesday, Leaders Are Now Committed To Zero Trust, reveals the challenges impacting organizations during the pandemic.
Based on a poll of over 300 global security decision makers at mid and large-sized businesses, it highlights how revenue and planning (64%), customer engagement (53%) and the shift to distributed working (52%) have had the biggest impact so far in 2020.
Despite the majority of respondents claiming to have invested in new devices for work from home (WFH) employees, updated security policies and adopted new security tools for remote workers, over half (58%) still suffered a data breach. A third (33%) were hit by infrastructure outages, with a similar number (29%) struck by ransomware.
Many security bosses admit that VPNs are a major bottleneck, leading to slow connections (46%). Most (54%) say they’ve struggled to maintain these during the shift to WFH. At the same time they’re concerned over staffing shortfalls (80%), apps and data exposed to the public internet (76%) and little management over end user devices (64%).
They admit that legacy network security tools are no longer effective (64%) but have been overwhelmed by rapid migration to the cloud (80%).
The answer for many is a zero-trust approach predicated on the notion of “never trust always verify” and supported by technologies such as multi-factor authentication, network segmentation and endpoint security.
Over three-quarters (76%) of respondents want to move to this model, and even more (81%) say their organization is committed to migrating to this approach in time. However, similar numbers (75%) say they’re struggling to do so due to the complexities of user access at their organization.
The report chimes with a Tanium study from earlier this year which revealed that global firms struggled with the shift to mass remote working due to a lack of visibility into endpoints and challenges around patching.
Although 85% said they felt ready for the shift to remote working, 98% admitted they were caught off guard by security challenges in the first two months, with overwhelmed VPNs (22%) frequently cited as a problem.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Security Experts Warn of Amazon Prime Day Scams
Security Experts Warn of Amazon Prime Day Scams

Security experts are warning of a deluge of phishing activity designed to capitalize on a major Amazon promotional event taking place this week.
Amazon Prime Day is said to be bigger for the e-commerce giant than Black Friday and Cyber Monday combined. That makes it a lucrative target for scammers looking to mimic the Amazon brand in order to trick unwitting shoppers into divulging sensitive personal and financial information.
Fraud prevention company Bolster said it analyzed hundreds of millions of web pages using deep learning, natural language processing and computer vision technology, in order to spot phishing patterns.
“After the spike in March coinciding with the World Health Organization’s COVID-19 pandemic announcement, there was a slight dip then a gradual increase with a sharp spike in August with another 2.5-times increase in September,” it explained.
“The obvious spike is a strong indication that cyber-criminals are gearing up for a profitable Prime Day to take advantage of the unwary.”
These scams could take many forms including: a fake Amazon website featuring new Kindles for $79 requesting confirmation of payment details, a customer support site requiring information to process returns and order cancellations and an ‘Amazon loyalty program’ which offers a free iPhone 11 Pro for answering a few survey questions, and completing payment information.
Bolster urged users to never shop via links in unsolicited emails, to always check the purchasing experience in case it differs from the Amazon norm and to check site details such as blurry images and missing links if they suspect a phishing page.
“The heightened activity around Prime Day and the desire of consumers to not miss out on the deals make it ripe for scams and deception,” warned Neal Dennis, threat intelligence specialist at Cyware.
“Some simple tips for spotting phishing emails include checking the address of the sender, noticing any bad grammar or misspellings and using common sense when considering what the email is asking you for.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US GAO Calls for Greater Cybersecurity for Commercial Airplanes
US GAO Calls for Greater Cybersecurity for Commercial Airplanes

The US Government Accountability Office (GAO) has urged the Federal Aviation Administration to take action to better protect modern commercial airplanes from cyber-risks.
In a post on its website, the GAO wrote: “Modern airplanes are equipped with networks and systems that share data with the pilots, passengers, maintenance crews, other aircraft and air-traffic controllers in ways that were not previously feasible.
“To date, extensive cybersecurity controls have been implemented and there have not been any reports of successful cyber-attacks on an airplane’s avionics systems. However, the increasing connections between airplanes and other systems, combined with the evolving cyber-threat landscape, could lead to increasing risks for future flight safety.”
The agency warned that if avionics systems are not properly protected, they could be at risk to a variety of potential cyber-attacks, with vulnerabilities occurring due to factors such as poor patch management, insecure supply chains and outdated systems.
The GAO has therefore set out a six-piece cybersecurity recommendation guide to executive action.
Commenting on the news, Tim Mackey, principal security strategist at the Synopsys CyRC, said: “Aircraft, like passenger cars, have seen an increase in computerization with software controls becoming an integral component of modern flight systems. As with vehicle systems, aircraft have a long lifespan – meaning that the software used in flight operations, both onboard aircraft and as part of flight activities, will be in use for far longer than that found in consumer situations.”
Properly managing cybersecurity with long lifecycle products requires anticipating future risks when building threat models, he added.
“For example, in recent years the concept of a software supply chain vulnerability has become front of mind as the growth of open source software usage grew. Such attacks can target not only open source software, but the commercial software built using compromised components. Detecting such attacks is challenging in part due to the potential for an attacker to mask their malicious code within a fix for an independent, but legitimate software bug. While the primary goal of such an attack might be financial, were a component compromised in this manner to be used in flight operations, it could offer an opportunity for another malicious group to target an airline or airline operations. This is an example of how attackers define the rules of their attacks and use the opportunities available to them and is also an example of the types of threats highlighted by the GAO.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Ransomware Gangs Outsource Network Access to Drive Success
Ransomware Gangs Outsource Network Access to Drive Success

Ransomware groups are increasingly purchasing network access on underground forums to simplify and accelerate their attacks, Accenture has warned.
The consulting giant’s iDefense threat intelligence business claimed in a new report that the outsourcing trend overlaps that of the relatively recent emergence of ransomware-plus-data-theft.
As developing and maintaining stable network access comes with a high risk of detection and requires significant time and effort, ransomware authors are increasingly seeking third-party help.
“As of September 2020, we actively track more than 25 persistent network access sellers as well as the occasional one-off seller, with more entering the scene on a weekly basis. Network access sellers operate on the same forums as actors associated with the ransomware gangs Maze, Lockbit, Avaddon, Exorcist, NetWalker, Sodinokibi and others,” Accenture wrote.
“We assess with high confidence that this ecosystem will continue to thrive, so long as reputable, invite-only dark web forums provide the platform on which network access sellers and ransomware gangs can securely exchange goods and services.”
Increasingly, such sellers are using zero-day exploits to compromise the networks of individual victim organizations and sell access rather than selling the exploit itself, presumably to drive up profits. One vendor, Frankknox, advertised access to 36 companies for between $2000 and $20,000, according to Accenture.
Another trend is exploitation of VPN infrastructure as more users work from home, although RDP remains the most popular attack vector. Accenture also claimed that an increasing number of network access sellers are advertising breached companies on a single thread by industry, country, access-level, price and other elements, in order to streamline the sales process.
The market for network access was pioneered by “Fxmsp,” an infamous threat actor thought to have made millions over the past few years. Although indicted by the US, he is thought to be currently living in Kazakhstan, which has no extradition treaty with Washington.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
October Patch Tuesday: Microsoft Patches Critical, Wormable RCE Bug
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk