Interview with the Author of the 2000 Love Bug Virus

No real surprises, but we finally have the story.

The story he went on to tell is strikingly straightforward. De Guzman was poor, and internet access was expensive. He felt that getting online was almost akin to a human right (a view that was ahead of its time). Getting access required a password, so his solution was to steal the passwords from those who’d paid for them. Not that de Guzman regarded this as stealing: He argued that the password holder would get no less access as a result of having their password unknowingly “shared.” (Of course, his logic conveniently ignored the fact that the internet access provider would have to serve two people for the price of one.)

De Guzman came up with a solution: a password-stealing program. In hindsight, perhaps his guilt should have been obvious, because this was almost exactly the scheme he’d mapped out in a thesis proposal that had been rejected by his college the previous year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Amazon Delivery Drivers Hacking Scheduling System

Amazon drivers — all gig workers who don’t work for the company — are hanging cell phones in trees near Amazon delivery stations, fooling the system into thinking that they are closer than they actually are:

The phones in trees seem to serve as master devices that dispatch routes to multiple nearby drivers in on the plot, according to drivers who have observed the process. They believe an unidentified person or entity is acting as an intermediary between Amazon and the drivers and charging drivers to secure more routes, which is against Amazon’s policies.

The perpetrators likely dangle multiple phones in the trees to spread the work around to multiple Amazon Flex accounts and avoid detection by Amazon, said Chetan Sharma, a wireless industry consultant. If all the routes were fed through one device, it would be easy for Amazon to detect, he said.

“They’re gaming the system in a way that makes it harder for Amazon to figure it out,” Sharma said. “They’re just a step ahead of Amazon’s algorithm and its developers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dunkin’ Donuts Parent Settles Cyber-attack Lawsuit

Dunkin’ Donuts Parent Settles Cyber-attack Lawsuit

The parent company of Dunkin’ Donuts has agreed to pay hundreds of thousands of dollars in costs and fines to settle a lawsuit that accused the company of glazing over multiple cyber-attacks. 

The suit was filed against Dunkin’ Brands Group Inc. in state Supreme Court in Manhattan in September last year by the state of New York’s attorney general Letitia James. 

James alleged that Dunkin’ neglected to inform customers of cyber-attacks that took place between 2015 and 2018 that compromised the accounts of thousands of customers. 

Attackers used automated credential stuffing and brute-force attacks to steal money from customer accounts created through Dunkin’s free mobile app or website.

James alleged that Dunkin’ failed to inform customers that attacks had taken place, despite being warned repeatedly about the issue by its app developer. 

During the summer of 2015, Dunkin’s app developer provided the company with a list of 19,715 accounts that had been compromised by attacks over a sample period of just five days, but the donut seller failed to tell customers or upgrade its security, according to the lawsuit.   

When the lawsuit was filed, Dunkin’s chief communications officer Karen Raskopf told Infosecurity Magazine that there was “no basis for these claims” and that the company looked forward “to proving our case in court.”

However, on Tuesday, Dunkin’ Brands Group Inc. agreed to $650,000 in fines and costs to settle the lawsuit, according to Reuters. The company further acquiesced to carrying out an upgrade of its security protocols.

Under the terms of the settlement, Dunkin’ customers will be notified of the cyber-attacks that took place between 2015 and 2018 and will be advised to reset their passwords. 

Dunkin’ has further agreed to give refunds for unauthorized transactions that occurred on their Dunkin’ brand stored-value cards.

Dunkin’ has not confirmed or denied any wrongdoing in relation to the cyber-attacks. The settlement of the suit requires a judge’s approval.

The company, which is based in Canton, Massachusetts, has around 8,000 branches nationally, including 1,000 Dunkin’ locations in New York. 

Announcing the settlement, James punned: “Not only will customers be reimbursed for lost funds, but we are ensuring the company’s dangerous brew of lax security and negligence comes to an end.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Minnesota Suffers Second-Largest Data Breach

Minnesota Suffers Second-Largest Data Breach

Hundreds of thousands of Minnesotans are receiving letters warning them that their data may have been exposed in the second-largest healthcare data breach in state history.

The letters were sent to individuals who had donated to or been a patient of Allina Health hospitals and clinics or Children’s Minnesota, a two-hospital pediatric health system in the Twin Cities.

Breach notifications warned that personal data may have been exposed following a ransomware attack on third-party vendor Blackbaud in May 2020. The South Carolina company is one of the world’s largest providers of education administration, fundraising, and financial management software. 

To date, over 3 million people in the United States have been impacted by the attack on Blackbaud, which has also impacted a number of universities, charities, and organizations in the United Kingdom. 

Attackers gained access to copies of a backup fundraising database stored by the Children’s Minnesota Foundation on Blackbaud’s cloud computing systems. Individuals impacted by the breach have been warned to monitor their medical bills for any instances of fraud. 

In a statement regarding the incident, Children’s Minnesota shared: “Based on our investigation and review of the affected Blackbaud database, the incident involved limited patient information that the Foundation received in connection with its fundraising efforts, including: full names, addresses, phone numbers, age, dates of birth, gender, medical record numbers, dates of treatment, locations of treatment, names of treating clinicians, and health insurance status.”

Allina Health has notified more than 200,000 patients and donors that their data may have been exposed as a result of the attack on Blackbaud.

statement on Allina’s website seeks to reassure customers by rather optimistically telling them: “Blackbaud did pay the cybercriminal’s demand with confirmation that the copy of the data that they removed had been destroyed.”

Patients and donors at Regions Hospital and Gillette Children’s Specialty Healthcare in Minnesota have also received data breach notifications this month as a result of the attack on Blackbaud.

The Blackbaud-related breach of hundreds of thousands of records is the second-largest health data breach ever to have been reported in Minnesota. The largest breach, of 11,500,000 records, was reported in July last year by Optum360, LLC.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Criminals Spoof Texas Government

Cyber-Criminals Spoof Texas Government

Cyber-criminals have tried to receive free goods by posing as the Texas government and emailing out Requests for Quotes (RFQs).

The multi-layered email attack, in which threat actors pretended to be from the Texas Department of State Health Services, was discovered by researchers at Abnormal Security

“If unsuspecting salespersons were to respond to this initial request, attackers could establish a line of communication and eventually follow-through with the requested goods,” noted researchers. 

Using what appears to be a genuine government purchase order, the attackers attempted to obtain products worth hundreds of thousands of dollars without handing over a penny.

Attackers addressed an email to the sales department, expressing intent to purchase 20 laptops and 200 external hard drives. Attached to the email was a fake order form that featured a convincing phone number and billing address. 

“Although this purchase order contains a government billing address, the government entities will not receive payment from the fraudulent vendor,” noted researchers. “The attackers’ goal is to retrieve merchandise, and later profit from the resale of the stolen goods.”

To obfuscate their true location and identification, the attackers leveraged several convincing domains and masked their true location by using a VPN service. 

“The email appears to be sent from a dshs.texas.gov domain, while the reply-to is from finance-nycgov.us,” observed researchers. “Finance-nycgov.usa is a domain that was registered just 2 months ago (07/06/2020) to a resident in Washington State and is an impersonation of nyc.gov. 

“In addition, the received-spf has a sinonordic.com domain, and the IP originates from a VPN service based out of Denver, CO.”

Careful attention had been paid by the attackers to the fine details. The deceptive email included the genuine logo of Texas Health and Human Services, and the request appeared to be sent by John William Hellerstedt, MD, the genuine commissioner of Texas Health. 

Researchers noted: “The phone number provided is not associated with the ‘bill to’ address, although the area code is in Texas and does match the area code for the department of state health services phone number. This is a social engineering tactic aimed to engage recipients into requesting the ship to address, either by email or phone.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Home Office Data Loss Incidents Surge by 120%

UK Home Office Data Loss Incidents Surge by 120%

The UK’s Home Office department reported a 120% rise in data loss incidents during the financial year 2019-20.

Figures from the Home Office’s Annual Report and Accounts 2019-20 that were compiled by the think tank Parliament Street showed that there were 4204 individual incidents in 2019-20 compared to 1895 in 2018-19.

The most common type of data loss in the last financial year was inadequately protected electronic equipment, devices or paper documents from outside secured government premises, with 2404 incidents occurring in 2019-20, representing a 242% increase on the previous year.

This was followed 946 incidents of lost electronic equipment or documents from secured government premises, a rise of 552% from the 145 recorded in 2018-19.

Of the 4204 incidents recorded in 2019-20, 25 were highlighted as particularly severe and the Information Commissioners Office (ICO) had to be notified. Encouragingly, this was a decrease on the 35 severe incidents that took place in the previous year. Unauthorized disclosure was the cause of 11 of the 25 severe incidents in 2019-20, and 26 out of 35 the year before.

Andy Harcup, VP sales, Absolute Software, commented: “It’s vital that key government departments like the Home Office take data security seriously. These figures indicate a myriad of losses of critical devices and data, some of which was so serious it had to reported to the regulator.

“It’s not uncommon for a missing file or laptop to fall into the wrong hands, giving hackers and cyber-criminals access to critical public data. Key to tackling this problem is the implementation of sophisticated and robust end-point security, providing IT professionals within the department with full visibility and control over their device: meaning they can freeze or access a laptop, file or device, even if it lands in the wrong hands.”

Earlier this year, the Home Office was found to have breached the GDPR 100 times in its handling of EU citizens’ data in the space of just five months.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Twitter Boosts Account Security for US Election Hopefuls

Twitter Boosts Account Security for US Election Hopefuls

Twitter has announced new measures designed to improve the security of certain high-profile accounts ahead of the upcoming US elections in November.

The social media firm said that chosen accounts would receive in-app notifications requiring or “strongly recommending” the new measures.

Accounts will be required to use a strong password, with those currently on weak log-ins prompted to change their credentials next time they use the app.

Twitter is also enabling “password reset protection” by default: this reduces the chances of unauthorized password changes by requiring the legitimate account holder to confirm their email address or telephone number before making changes.

Finally, the firm is strongly encouraging selected account holders to switch on two-factor authentication, to provide an extra layer of security against unauthorized log-ins.

Designated accounts will include those of the executive branch and Congress, governors and secretaries of state, US news outlets and political journalists, and “Presidential campaigns, political parties and candidates with Twitter election labels running for US House, US Senate or governor.”

In the future, Twitter claimed it would be rolling out: “more sophisticated detections and alerts” to help it respond more quickly to suspicious activity, increased defenses against malicious account takeover and expedited account recovery support.

The news comes just weeks after multiple high-profile accounts including those of Barack Obama and Presidential candidate Joe Biden were hijacked following a social engineering attack on Twitter staff.

Two teens and a man in his early twenties were subsequently arrested and slapped with charges related to the cryptocurrency scam.

Earlier this month, the Chinese government decried as “abominable” an apparent account hijacking attack on UK ambassador Liu Xiaoming’s account.

Although no group has subsequently claimed responsibility for the incident, the account “liked” comments critical of Beijing and one that appeared to contain pornographic content.

Microsoft claimed recently that state-sponsored hackers from China, Iran and Russia have been probing Trump and Biden campaigns for geopolitically useful information.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US CISA: Agencies Must Patch Zerologon Bug by Monday

US CISA: Agencies Must Patch Zerologon Bug by Monday

The US Department of Homeland Security (DHS) has issued an emergency directive designed to force all civilian government agencies to patch a high-risk Windows vulnerability.

CVE-2020-1472 is a critical elevation of privilege bug which exists when an attacker uses the Netlogon Remote Protocol to establish a vulnerable secure channel connection to a domain controller, according to Microsoft. It affects Windows Server 2008 onwards.

Dubbed “Zerologon,” the flaw was fixed in the August Patch Tuesday, although proof-of-concept exploits started to appear over the past week.

As such, it now poses an “unacceptable risk” to the federal civilian executive branch that requires “immediate and urgent action,” the Cybersecurity and Infrastructure Security Agency (CISA) said on Friday.

“The vulnerability in Microsoft Windows Netlogon Remote Protocol (MS-NRPC), a core authentication component of Active Directory, could allow an unauthenticated attacker with network access to a domain controller to completely compromise all Active Directory identity services,” it explained.

“Applying the update released on August 11 to domain controllers is currently the only mitigation to this vulnerability (aside from removing affected domain controllers from the network).”

The resulting emergency directive 20-04 requires all civilian government agencies to patch all Windows Servers with a domain controller role by 23.59 EDT this evening, or remove them from the network.

ExtraHop CISO, Jeff Costlow, argued that the Zerologon bug is easy for attackers to exploit

“The first PoC’s have shown that unauthenticated attackers are able to obtain full administrator privileges on Active Directory systems,” he added.

“Any organizations without the ability to detect exploit attempts will remain at high risk if they delayed the patch as there is no way to know if they were exposed in between the time of reporting and the system update. We urge organizations to patch immediately and be aware that their system might have already been compromised.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk