Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Maze Ransomware Adopts Ragnar Locker Virtual-Machine Approach
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Security Takeaways from the Great Work-from-Home Experiment
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
SecOps Teams Wrestle with Manual Processes, HR Gaps
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Friday Squid Blogging: Nano-Sized SQUIDS
SQUID news:
Physicists have developed a small, compact superconducting quantum interference device (SQUID) that can detect magnetic fields. The team l focused on the instrument’s core, which contains two parallel layers of graphene.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Matt Blaze on OTP Radio Stations
Matt Blaze discusses an interesting mystery about a Cuban one-time-pad radio station, and a random number generator error that probably helped arrest a pair of Russian spies in the US.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Nihilistic Password Security Questions
Posted three years ago, but definitely appropriate for the times.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Indicts Two Over Cyber-Intrusion Campaign
US Indicts Two Over Cyber-Intrusion Campaign

The US has indicted two Iranians in connection with the theft of hundreds of terabytes of sensitive data from computers in America, Europe, and the Middle East.
Hooman Heidarian, aged 30, and Mehdi Farhadi, 34, were allegedly involved in a slew of coordinated hacks perpetrated to make money or for political reasons.
Data stolen in the attacks and later allegedly sold on the black market by the defendants included confidential communications pertaining to national security, foreign policy intelligence, non-military nuclear information, aerospace data, human rights activist information, victim financial information and personally identifiable information, and intellectual property, including unpublished scientific research.
The defendants are further accused of politically motivated hacking on behalf of Iran to steal information relating to dissidents, human rights activists, and opposition leaders.
Heidarian, otherwise known as Neo, and Farhadi, also known as Mehdi Mahdavi and Mohammad Mehdi Farhadi Ramin, are both from Hamedan, believed to be one of Iran’s oldest cities.
According to the ten-count indictment, since at least 2013, the defendants have been responsible for a coordinated campaign of cyber-intrusions into computer systems around the world.
Among the campaign’s victims are several American and foreign universities, a think tank in Washington, DC, a defense contractor, an aerospace company, a foreign policy organization, non-governmental organizations (NGOs), non-profits, and governments and other entities they identified as rivals or adversaries to Iran.
In addition to the alleged theft of highly sensitive data, the defendants are further accused of vandalizing websites. Using the pseudonym “Sejeal,” the defendants allegedly posted messages appearing to signal the demise of Iran’s internal opposition, foreign adversaries, and countries marked out as rivals to Iran, including Israel and Saudi Arabia.
Tools and tactics allegedly used by the defendants to gain and maintain unauthorized access to victim networks included vulnerability scanning tools, session hijacking, SQL injection, malicious programs installations, and keyloggers.
The pair are further accused of developing a botnet tool, which facilitated the spread of malware, denial of service attacks, and spamming to victim networks.
Each defendant is charged with conspiracy to commit fraud and related activity in connection with computers and access devices; unauthorized access to protected computers; unauthorized damage to protected computers; conspiracy to commit wire fraud; access device fraud; and aggravated identity theft.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Fatality After Hospital Hacked
Fatality After Hospital Hacked

A woman in need of urgent medical treatment has died after a hospital under cyber-attack was unable to admit her.
Attackers struck the Düsseldorf University Clinic (DUC) last Thursday, causing IT systems at the major hospital to fail. Because of the attack, a woman seeking emergency treatment at the hospital on Friday night died after she had to be transported to a hospital in another city for treatment.
Treatment of the deceased woman was delayed by an hour as she had to travel an additional 20 miles to a hospital in Wuppertal.
The DUC said that computer forensic experts investigating the incident determined that threat actors had managed to exploit a vulnerability in “widely used commercial add-on software.” The software that contained the weakness was not named by the hospital.
Following the attack, systems at the DUC gradually crashed, preventing the hospital from being able to access data. As a result, operations were postponed, and emergency patients were redirected to alternative healthcare providers.
Hospital staff said that they believe data temporarily placed off limits as a result of the cyber-assault has not been irretrievably lost. A week on from the attack, the DUC’s IT systems are slowly being restarted.
In what may have been a deadly mistake by the attackers, it seems the real target of this cyber-crime may have been Heinrich Heine University, with which the DUC is affiliated.
News agency DPA reported that 30 servers at the hospital were encrypted last week and an extortion note was left on one of the servers, according to a report from North Rhine-Westphalia state’s justice minister.
The note was addressed to the Heinrich Heine University and not the DUC. It asked for the university to make contact but did not mention a specific ransom demand.
Düsseldorf police used the contact details given in the note to reach out to the attackers, informing them that their attack had impacted a hospital. The attackers subsequently provided a digital decryption key and made no attempt to extort money.
Communication with the attackers has since broken down. An investigation has been launched that could see the perpetrators charged with negligent manslaughter.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Stalkerware Banned from Google Play Store
Stalkerware Banned from Google Play Store

Google has told app developers to remove from its Play Store stalkerware capable of operating behind the scenes without the user’s consent.
The tech giant yesterday issued an update to its Developer Program Policy requiring all apps that track users and send their data to another device to include an “adequate notice or consent” and show a “persistent notification” that the actions of the user are being tracked.
While an exception was made for apps used by parents to track their children, Google said that stalkerware was not to be used to track an adult without their consent.
The update states: “Only policy compliant apps exclusively designed and marketed for parental (including family) monitoring or enterprise management may distribute on the Play Store with tracking and reporting features, provided they fully comply with the requirements described below.”
App developers were told that they can no longer present their product as an aid to spying or a secret surveillance solution. Nor can they hide or cloak tracking behavior in an attempt to mislead users about an app’s true functionality.
App developers have until October 1 to comply with the directives.
Google has also said that, starting October 21, it will remove any apps “that engage in coordinated activity to mislead users.”
Christoph Hebeisen, director of security intelligence research at Lookout, a California provider of mobile phishing solutions, welcomed Google’s new approach to the stalkerware permitted in its app store.
“The use of mobile technology for surveillance in abusive relationships is a disturbing trend. Google’s move to curb such apps on Play is a step in the right direction,” said Hebeisen.
Lookout already considers any app that doesn’t make it clear tracking is taking place to be malicious. Users receive alerts when surveillance-ware that is independent of the stated purpose of the app is deployed.
Hebeisen said: “We consider such apps malicious if the app doesn’t show a persistent notification, hides its icon, masquerades as something other than its true functionality or hides a part of its functionality. We apply this logic no matter if the app has been loaded from an official app store or sideloaded onto the device.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk