Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Liverpool Voyeur Used IM-RAT to Video Women at Home
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Google Ditches Patch-Time Bug Disclosure in Favor of 90-Day Policy
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
TikTok Riddled With Security Flaws
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Mozilla Releases Firefox 72: High-Severity Bugs Patched, Fingerpinting Nixed
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
New SHA-1 Attack
There’s a new, practical, collision attack against SHA-1:
In this paper, we report the first practical implementation of this attack, and its impact on real-world security with a PGP/GnuPG impersonation attack. We managed to significantly reduce the complexity of collisions attack against SHA-1: on an Nvidia GTX 970, identical-prefix collisions can now be computed with a complexity of 261.2rather than264.7, and chosen-prefix collisions with a complexity of263.4rather than267.1. When renting cheap GPUs, this translates to a cost of 11k US$ for a collision,and 45k US$ for a chosen-prefix collision, within the means of academic researchers.Our actual attack required two months of computations using 900 Nvidia GTX 1060GPUs (we paid 75k US$ because GPU prices were higher, and we wasted some time preparing the attack).
It has practical applications:
We chose the PGP/GnuPG Web of Trust as demonstration of our chosen-prefix collision attack against SHA-1. The Web of Trust is a trust model used for PGP that relies on users signing each other’s identity certificate, instead of using a central PKI. For compatibility reasons the legacy branch of GnuPG (version 1.4) still uses SHA-1 by default for identity certification.
Using our SHA-1 chosen-prefix collision, we have created two PGP keys with different UserIDs and colliding certificates: key B is a legitimate key for Bob (to be signed by the Web of Trust), but the signature can be transferred to key A which is a forged key with Alice’s ID. The signature will still be valid because of the collision, but Bob controls key A with the name of Alice, and signed by a third party. Therefore, he can impersonate Alice and sign any document in her name.
From a news article:
The new attack is significant. While SHA1 has been slowly phased out over the past five years, it remains far from being fully deprecated. It’s still the default hash function for certifying PGP keys in the legacy 1.4 version branch of GnuPG, the open-source successor to PGP application for encrypting email and files. Those SHA1-generated signatures were accepted by the modern GnuPG branch until recently, and were only rejected after the researchers behind the new collision privately reported their results.
Git, the world’s most widely used system for managing software development among multiple people, still relies on SHA1 to ensure data integrity. And many non-Web applications that rely on HTTPS encryption still accept SHA1 certificates. SHA1 is also still allowed for in-protocol signatures in the Transport Layer Security and Secure Shell protocols.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Utah Company and Its Former CEO Settle with FTC Over Alleged Security Failures
Utah Company and Its Former CEO Settle with FTC Over Alleged Security Failures

The US Federal Trade Commission has reached a settlement with a Utah company and its former CEO over allegations that shoddy security practices led to the personal information of over a million customers’ being illegally accessed in multiple hacks.
InfoTrax Systems, L.C. and its founder and former CEO Mark Rawlins allegedly failed to use reasonable, low-cost, and readily available security protections to safeguard the personal information they maintained on behalf of the company’s business clients.
As a result of the alleged security failures, a hacker infiltrated InfoTrax’s server, along with websites maintained by the company on behalf of clients, more than 20 times from May 2014 until March 2016.
Sensitive personal information accessed by the hacker included consumers’ Social Security numbers, full names, addresses, email addresses, telephone numbers, usernames, passwords, and payment account numbers with expiration data and CVVs, according to the FTC’s complaint. None of the consumer data stored had been encrypted.
It is further alleged that the presence of the intruder inside the company’s system from May 5, 2014, to March 7, 2016, was only discovered because InfoTrax began receiving alerts that one of its servers had reached maximum capacity.
In its complaint, the FTC wrote: “The only reason Respondents received any alerts is because an intruder had created a data archive file that had grown so large that the disk ran out of space. Only then did Respondents begin to take steps to remove the intruder from InfoTrax’s network.”
More hacks occurred on March 14 and 29, 2016, when a threat actor gained access to the company’s network, infecting it with malware that harvested payment card and other billing data.
Under the terms of the settlement, InfoTrax and Rawlins are prohibited from collecting, selling, sharing, or storing personal information unless they implement an information security program that would address the security failures identified in the complaint.
In addition, the company and Rawlins are required to obtain third-party assessments of their company’s information security programs every two years.
Utah State University computer science graduate Rawlins founded MLM services provider InfoTrax Systems in 1998. Clients of the company include doTerra, Xango, and LifeVantage.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Richard Branson Gets Animated Over Online Scams
Richard Branson Gets Animated Over Online Scams

Sir Richard Branson is so hacked off with cyber-criminals ripping off his name and image that he has released an animated guide to spotting online scams.
The video features two extremely pink cartoon renderings of the Virgin founder who work together to highlight a variety of scamming tactics over a soundtrack that conjures the most daring of James Bond’s espionage escapades.
Fake Branson tries to tempt you into investing in get-rich-quick scams or giving your personal information away to a stranger, while genuine Branson tells you that he and his team would never do that.
By the end of the brief video, the fake Branson is revealed to be a robot, whose head then explodes.
All the fraudulent endorsements and scams mentioned in the video are real tactics that have been used against Branson and his business empire. One such tactic is to send direct messages to people who have posted on Virgin’s social media feeds.
Animated Richard points out: “Scammers are contacting people who post on our social feeds. Even if it’s a verified account, know that I never direct message anyone, nor does my team. I never endorse any get-rich-quick schemes—this is a sure-fire way to lose your investment.”
To step up the fight against scammers, Virgin has opened its own reporting portal at virgin.com/online-scams and urges anyone affected to report any cases featuring Richard or Virgin that seem suspicious.
If you spot anything else you suspect is a scam, Virgin recommends reporting it to Action Fraud, the UK’s national fraud and cybercrime center, via reporting.actionfraud.police.uk.
In 2017, Branson nearly fell prey to a fraudster posing as a UK government official who requested financial assistance to pay the ransom of a supposed kidnapping victim.
The billionaire businessman is not alone in being targeted; according to figures released by the British Office of National Statistics in 2018, cases of fraud, including online scams, cost UK consumers £190bn every year.
“Only trust what we post on our official channels,” says animated Branson.
“Help us stop scammers and report anything you think is suspicious. If you think it’s a con, send it on.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Insight Partners Acquires Armis for $1.1bn
Insight Partners Acquires Armis for $1.1bn

In the first major cybersecurity acquisition of 2020, Israeli company Armis has been acquired by private equity firm Insight Partners.
Under the terms of the agreement, Insight will acquire the company for cash at a valuation of $1.1bn, with participation from CapitalG for $100m and rollover from certain existing stockholders.
The deal represents the largest ever acquisition of a private Israeli cybersecurity company and is also the biggest enterprise IoT security software acquisition to date. Closing is expected to occur in February.
Armis was founded in late 2015 with a mission to help enterprises adopt new connected devices without fear of being compromised by cyber threat actors. The company, which is headquartered in Palo Alto, California, counts numerous Fortune 1000 companies among its clients.
Following the acquisition, Armis will continue to operate independently and will be fully managed by its two co-founders—Yevgeny Dibrov, CEO, and Nadir Izrael, CTO—and the executive team. Going forward, the C-suite will have the support of Insight’s business strategy and ScaleUp division, OnsiteSupport.
This heady mix of freedom with an optional shoulder to lean on was a deal-maker for Armis’ Dibrov.
He said: “Insight is one of the most sophisticated software investors in the sector, and it is due to the depth of their domain expertise that they really understand the enterprise IoT device challenge we are looking to solve, and the size of the market opportunity.
“We considered growth rounds and strategic offers, but by partnering with Insight we have the best of both worlds—operational support and independence, both of which were important in our decision to take on a scaleup partner this early in our company journey.”
Insight Partners is a leading global venture capital and private equity firm investing in high-growth technology and software companies with a reputation for driving transformative change in their industries. Founded in 1995, the firm currently has over $20 billion in assets under management and has cumulatively invested in more than 300 companies worldwide.
Teddie Wardi, managing director at Insight, said: “We’ve spoken with their users, who have told us how powerful the Armis platform is at device discovery, classification, and continuous threat assessment. In a world of unmanaged devices, Armis’ technology is a game changer.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Tech Ops Exec Pleads Guilty in $6m Fraud Case
Tech Ops Exec Pleads Guilty in $6m Fraud Case

A senior vice-president at a global internet marketing firm has pleaded guilty to a wire fraud case in which he illegally paid $6m into an IT shell company.
Hicham Kabbaj worked for over four years at affiliate marketing giant Rakuten Marketing, formerly known as Rakuten LinkShare and part of the Japanese multi-national e-commerce firm.
From 2015, he held positions there as director of operations, VP of global technical operations, SVP of technical operations and then SVP of tech ops and engineering, according to his LinkedIn profile.
However, from at least August 2015 until at least May 2019, Kabbaj was defrauding his employer by issuing invoices in the name of a shell company he created, Interactive Systems, for fictitious products and services such as firewalls and servers, according to the Department of Justice.
The resulting payments, amounting to more than $6m in total, were subsequently transferred to his personal accounts.
“Today, Mr Kabbaj pled guilty to a serious felony because he chose to misuse his position of trust as a corporate executive to steal company funds for his own personal gain,” said Internal Revenue Service, Criminal Investigation Division (IRS-CI) special agent in charge, Jonathan Larsen.
“As a result of the dedicated work of IRS-CI special agents, along with our partners at the US Attorney’s Office, Mr Kabbaj will face the consequences of his crime when he is sentenced by a federal judge.”
Kabbaj, 48, of Floral Park, New York, pleaded guilty to one count of wire fraud, which carries a maximum sentence of 20 years behind bars. He has handed over homes in Palm Beach Gardens, Florida, and Hewitt, New Jersey, as “property traceable to the offense,” and will pay over $6m in restitution.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk