Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
The Scammer Force is Strong with Star Wars: The Rise of Skywalker
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
267M Facebook Users’ Phone Numbers Exposed Online
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Lousy IoT Security
DTEN makes smart screens and whiteboards for videoconferencing systems. Forescout found that their security is terrible:
In total, our researchers discovered five vulnerabilities of four different kinds:
- Data exposure: PDF files of shared whiteboards (e.g. meeting notes) and other sensitive files (e.g., OTA — over-the-air updates) were stored in a publicly accessible AWS S3 bucket that also lacked TLS encryption (CVE-2019-16270, CVE-2019-16274).
- Unauthenticated web server: a web server running Android OS on port 8080 discloses all whiteboards stored locally on the device (CVE-2019-16271).
- Arbitrary code execution: unauthenticated root shell access through Android Debug Bridge (ADB) leads to arbitrary code execution and system administration (CVE-2019-16273).
- Access to Factory Settings: provides full administrative access and thus a covert ability to capture Windows host data from Android, including the Zoom meeting content (audio, video, screenshare) (CVE-2019-16272).
These aren’t subtle vulnerabilities. These are stupid design decisions made by engineers who had no idea how to create a secure system. And this, in a nutshell, is the problem with the Internet of Things.
From a Wired article:
One issue that jumped out at the researchers: The DTEN system stored notes and annotations written through the whiteboard feature in an Amazon Web Services bucket that was exposed on the open internet. This means that customers could have accessed PDFs of each others’ slides, screenshots, and notes just by changing the numbers in the URL they used to view their own. Or anyone could have remotely nabbed the entire trove of customers’ data. Additionally, DTEN hadn’t set up HTTPS web encryption on the customer web server to protect connections from prying eyes. DTEN fixed both of these issues on October 7. A few weeks later, the company also fixed a similar whiteboard PDF access issue that would have allowed anyone on a company’s network to access all of its stored whiteboard data.
[…]
The researchers also discovered two ways that an attacker on the same network as DTEN devices could manipulate the video conferencing units to monitor all video and audio feeds and, in one case, to take full control. DTEN hardware runs Android primarily, but uses Microsoft Windows for Zoom. The researchers found that they can access a development tool known as “Android Debug Bridge,” either wirelessly or through USB ports or ethernet, to take over a unit. The other bug also relates to exposed Android factory settings. The researchers note that attempting to implement both operating systems creates more opportunities for misconfigurations and exposure. DTEN says that it will push patches for both bugs by the end of the year.
Boing Boing article.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Honda Leaks Data of 26K North American Customers
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Senators Introduce Bill to Protect Schools Against Cyber-Threats
US Senators Introduce Bill to Protect Schools Against Cyber-Threats

A bill designed to enhance the cybersecurity of K–12 schools was introduced to the US House of Representatives on Monday.
If passed into law, the K-12 Cybersecurity Act would require the Department of Homeland Security (DHS) to create a list of cybersecurity recommendations and a cybersecurity toolkit for educational institutions to use when making improvements to their cyber-protections.
The bill was introduced by Senators Rick Scott and Gary Peters, who both serve on the Senate Homeland Security Committee.
Peters, who also serves on the Governmental Affairs Committee, said: “Schools across the country are entrusted with safeguarding the personal data of their students and faculty, but lack many of [the] resources and information needed to adequately defend themselves against sophisticated cyber-attacks.”
Support for the bill has been expressed by the National Education Association, the American Federation of Teachers, the National Association of Secondary School Principals, and the Consortium for School Networking.
It would further require the DHS to research and report back on the overall cyber-risks faced by schools.
Scott said: “The safety of our schools is always my top priority, and that includes protecting the information of our students and teachers. I’m proud to sponsor the K–12 Cybersecurity Act of 2019 to further protect our schools, students and educators, and give them the resources they need to stay safe.”
The bill closely mirrors the State and Local Government Cybersecurity Improvement Act, which was introduced to the House in August but has yet to see any action.
According to data collected by Armor, over 1,000 schools in the United States have been affected by ransomware alone in 2019. In Louisiana, Governor John Bel Edwards declared a statewide emergency in July in response to ransomware attacks on three school districts.
It isn’t just malware that poses a risk to American schools. In August 2019, a high school in Spotsylvania County, Virginia, wired $600,000 to a fraudulent football field turf provider after being deceived in an elaborate email phishing scam.
“School districts are a treasure trove for cyber-criminals seeking to pilfer valuable information, such as social security numbers and financial information until a ransom has been paid. From January through November of this year, SonicWall detected almost nine million intrusion attempts, demonstrating the tenacity and dedication of online threats and threat networks,” commented Bill Conner, CEO of cybersecurity firm SonicWall.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Siemens Contractor Jailed for Planting Logic Bombs
Siemens Contractor Jailed for Planting Logic Bombs

A Siemens contractor who sabotaged computer programs so that he would later be re-hired to fix them has been jailed.
David Tinley of Harrison City, Pennsylvania, pleaded guilty in federal court to a charge of intentional damage to a protected computer back in July 2019.
Between 2014 and 2016, the 62-year-old computer programmer inserted malicious pieces of code known as logic bombs into software used at the Monroeville branch of Siemens in Pennsylvania. The logic bombs were designed to unleash code that would cause the software to malfunction after specific circumstances arose.
“The logic bombs ensured that the programs would malfunction after the expiration of a certain date. As a result, Siemens was unaware of the cause of the malfunction and required Tinley to fix these malfunctions,” reads a statement released July 19, 2019, by the United States Attorney’s Office of the western district of Pennsylvania.
Deceived by Tinley’s despicable ruse, Siemens reputedly paid tens of thousands of dollars to the contractor to fix the masterfully orchestrated problems of his own sinister creation. According to a pre-sentence memorandum, Tinley paid Siemens $42,000 in restitution for that work.
For his criminal actions, Tinley faced a maximum prison term of 10 years and a maximum fine of $250,000. On Monday, December 16, United States District Judge William S. Stickman handed the corrupt contractor a six-month federal prison sentence and ordered him to pay a $7,500 fine.
Once his custodial sentence has been served, Tinley will spend a further two years under court-ordered supervision.
According to Law360 (registration required), the computer programs that prosecutors said Tinley had damaged were in fact spreadsheets that Siemens used to manage orders.
Siemens rumbled Tinley’s logic bomb–planting scheme in May 2016, when the contractor, who was out of town and unable to visit the office to carry out a fix in person, was able to provide a password that unlocked the spreadsheets to Siemens staff.
Assistant United States Attorney Shardul S. Desai prosecuted this case on behalf of the government.
United States Attorney Scott W. Brady lauded the Federal Bureau of Investigation for its investigation, which led to the successful prosecution of Tinley.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
LifeLabs Pays to Secure Sensitive Customer Data After Cyber-Attack
LifeLabs Pays to Secure Sensitive Customer Data After Cyber-Attack

A Canadian laboratory testing company has made a payment to secure the sensitive information of millions of customers that was exposed during a cyber-attack.
LifeLabs opted to pay up after criminals gained unauthorized access to the information of 15 million customers. Most of the customers impacted were in British Colombia and Ontario.
In an open letter to customers, president and CEO of LifeLabs Charles Brown said customer information exposed in the incident may have included names, addresses, email addresses, logins, passwords, dates of birth, health card numbers, and lab test results.
The information accessed by the cyber-criminals has not been exposed publicly.
Brown wrote: “I want to emphasize that at this time, our cybersecurity firms have advised that the risk to our customers in connection with this cyber-attack is low and that they have not seen any public disclosure of customer data as part of their investigations, including monitoring of the dark web and other online locations.”
After identifying that a data breach had occurred, the laboratory engaged security experts to isolate and secure the affected systems and determine the scope of the incident.
LifeLabs then took steps to strengthen their system against future attacks and paid an undisclosed amount to retrieve the data that had been accessed.
Brown wrote that the payment had been made “in collaboration with experts familiar with cyber-attacks and negotiations with cyber-criminals.”
The laboratory’s investigation into the incident indicates that the lab-test results of around 85,000 Ontario customers, who underwent tests in 2016 or earlier, may have been impacted in the incident. Similarly, any health and information accessed by cyber-criminals is thought to have dated from 2016 or earlier.
LifeLabs has offered any customers who are concerned about this incident a year’s worth of free security protection that includes dark-web monitoring and identity-theft insurance.
Brown wrote that the attack occurred despite the laboratory’s efforts to increase their cybersecurity in recent years.
“While we’ve been taking steps over the last several years to strengthen our cyber defenses, this has served as a reminder that we need to stay ahead of cybercrime, which has become a pervasive issue around the world in all sectors,” wrote Brown.
Brown gives no indication as to where the attack originated, when it happened, or who perpetrated it.
Government partners were notified of the breach on October 28, and the incident is currently under investigation by law enforcement.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Data Leak Exposes Thousands of US Defense Contractor Staff
Data Leak Exposes Thousands of US Defense Contractor Staff

A digital consultancy has accidentally leaked the personal details of thousands of US defense contractor employees after yet another misconfiguration of cloud infrastructure, it has emerged.
Washington DC-based IMGE accidentally exposed the names, phone numbers, home and email addresses of more than 6000 Boeing staff, according to The Daily Beast.
The trove featured government relations staff and senior executives, including one who apparently worked at the contractor’s advanced prototyping unit on highly sensitive technologies.
“This information was exposed as a result of human error by the website’s vendor,” a Boeing spokesperson told the news site. “Boeing takes cybersecurity and privacy seriously and we require our vendors to protect the data entrusted to them. We are closely monitoring the situation to ensure that the error is resolved quickly.”
The information itself is said to have been harvested by IMGE from a website called Watch US Fly, dedicated to “advancing and protecting American aerospace and manufacturing.”
That site requests that supporters leave their contact details for future campaigns and in order to direct their demands to fund Boeing projects to the right lawmakers, according to the report.
However, it is blocked in the UK so Infosecurity could not confirm these details.
It’s unclear how long the data was left exposed in the Amazon S3 bucket, although the Boeing employees were just a small fraction of the 50,000 individuals whose personal information was reportedly compromised by the snafu.
Chris DeRamus, CTO of DivvyCloud, explained that cloud misconfigurations like this are increasingly common as many users aren’t familiar with cloud security settings and best practices.
“It is especially concerning that the database contained information about 6,000 Boeing employees, many of whom are heavily involved with the US government and military, as the exposed data is more than enough information for cyber-criminals to launch highly targeted attacks against those impacted to gain more confidential government information,” he added.
“Companies who manage large amounts of sensitive data, especially data related to government and military personnel, need to be proactive in ensuring their data is protected with proper security controls. Companies must adopt robust security strategies that are appropriate and effective in the cloud at the same time they adopt cloud services – not weeks, months, or years later.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Over 1000 US Schools Hit by Ransomware in 2019
Over 1000 US Schools Hit by Ransomware in 2019

Over 1000 US schools have now been affected by ransomware so far this year, according to new data from Armor.
The security vendor claimed to have discovered 11 new school districts comprised of 226 schools that have been compromised by the malware since late October.
That brings the total number of affected school districts to 72 for the year, impacting an estimated 1039 schools nationwide.
Chris Hinkley, head of Armor’s threat resistance unit (TRU), said the attackers are deliberately targeting organizations that store sensitive data and run critical services.
“The attackers know that the services these organizations provide are critical to their communities, and they also know that schools and municipalities are typically more vulnerable to security attacks because of their limited budgets and lack of IT staff,” he said.
“This combination can give the threat actors a tremendous advantage over their victims because they know these entities cannot afford to shut down and are often more likely to pay the ransom.”
Fortunately, of the 11 districts caught in the latest round of ransomware attacks, only one is confirmed to have paid the ransom.
Earlier this week Microsoft urged customers not to pay the cyber-criminals.
“We never encourage a ransomware victim to pay any form of ransom demand. Paying a ransom is often expensive, dangerous, and only refuels the attackers’ capacity to continue their operations; bottom line, this equates to a proverbial pat on the back for the attackers,” argued Ola Peters, senior cybersecurity consultant at the firm’s Detection and Response Team (DART).
“The most important thing to note is that paying cyber-criminals to get a ransomware decryption key provides no guarantee that your encrypted data will be restored.”
The bad news for US organizations doesn’t end with school districts. According to Armor, 82 municipalities and 44 healthcare organizations have also been hit with ransomware this year.
The figures from Emisoft are even more stark: 103 municipalities and 759 healthcare providers, as well as 1224 schools may have been impacted by ransomware so far this year.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk