Attacker Causes Epileptic Seizure over the Internet

This isn’t a first, but I think it will be the first conviction:

The GIF set off a highly unusual court battle that is expected to equip those in similar circumstances with a new tool for battling threatening trolls and cyberbullies. On Monday, the man who sent Eichenwald the moving image, John Rayne Rivello, was set to appear in a Dallas County district court. A last-minute rescheduling delayed the proceeding until Jan. 31, but Rivello is still expected to plead guilty to aggravated assault. And he may be the first of many.

The Epilepsy Foundation announced on Monday it lodged a sweeping slate of criminal complaints against a legion of copycats who targeted people with epilepsy and sent them an onslaught of strobe GIFs — a frightening phenomenon that unfolded in a short period of time during the organization’s marking of National Epilepsy Awareness Month in November.

[…]

Rivello’s supporters — among them, neo-Nazis and white nationalists, including Richard Spencer — have also argued that the issue is about freedom of speech. But in an amicus brief to the criminal case, the First Amendment Clinic at Duke University School of Law argued Rivello’s actions were not constitutionally protected.

“A brawler who tattoos a message onto his knuckles does not throw every punch with the weight of First Amendment protection behind him,” the brief stated. “Conduct like this does not constitute speech, nor should it. A deliberate attempt to cause physical injury to someone does not come close to the expression which the First Amendment is designed to protect.”

Another article.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BlueCross BlueShield Whistleblower Warns of Cybersecurity Vulnerabilities

BlueCross BlueShield Whistleblower Warns of Cybersecurity Vulnerabilities

An internal whistleblower has raised concerns about the cybersecurity of Minnesota’s largest health insurer, BlueCross BlueShield. 

As reported yesterday by the Star Tribune newspaper, the whistleblower expressed concern that BlueCross BlueShield had left its system vulnerable to attack by neglecting to make thousands of important updates to its computer system.

Internal documents show that despite warnings to executives, 200,000 vulnerabilities that were deemed “critical” or “severe” were left to fester on the company’s computer systems. In most cases, software patches to fix the issues were available. 

Documents obtained by the newspaper show that as far back as August 2018, cybersecurity engineer Tom Yardic met with executives to share concerns that important patches hadn’t been installed.

Frustrated with their response, Yardic went on to email his concerns to the company’s CEO and board of trustees on September 16. 

“I am sending this e-mail because I have been unable to impact the situation within the avenues the organization provides,” wrote Yardic. “What has not happened is a serious attempt to remedy the situation.”

In a statement emailed to the Star Tribune, the company’s chief information security officer, Amy Ecklund, said that BlueCross BlueShield is working hard to cut the number of security vulnerabilities down before the end of the year. 

“We certainly understand that our members expect us to protect their most sensitive data, and we want them to know that we are committed every single day to doing just that,” said Ecklund.

BlueCross BlueShield Minnesota insures 2.8 million people. To date, the company has not reported a data beach of its own systems.

The personal data of 11,000 members of Minnesota’s Supervalu Group Health Plan were breached in 2015 after Minnesota BlueCross BlueShield stored their information on vulnerable computers owned by another BlueCross licensee, now known as Anthem Inc.

“Protecting our members’ information is our top priority, and our efforts are ongoing,” Minnesota BlueCross BlueShield officials said via email. “As with all companies holding sensitive information, we remain vigilant in our security systems and testing, but we will always strive to do more.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

LightInTheBox Leaks Over 1TB of Customer Data

LightInTheBox Leaks Over 1TB of Customer Data

A Chinese online retailer with a huge North American fanbase has leaked more than 1 terabyte of customer data. 

The major breach in the security of LightInTheBox was discovered by researchers at vpnmentor on November 20. 

Researchers were able to gain access to a massive database containing 1.3 terabytes of daily logs dating from August 9, 2019, to October 11, 2019, totaling over 1.5 billion records. 

The substantial leak compromised the security of LightInTheBox customers across the globe. Researchers were also able to access data from the vendor’s subsidiary sites, including MiniInTheBox.com.

“Our team was able to access this database because it was completely unsecured and unencrypted,” wrote researchers.

Vpnmentor notified the vendor of the breach on November 24. Although no reply was received, the database breach was closed shortly after LightInTheBox was made aware of its existence. 

LightInTheBox, which was founded in 2007, sells clothing, accessories, gadgets, and various items for the home and garden. Most of the 12 million monthly visitors to the retailer’s website are based in North America and Europe. 

The company does not provide specific details about their data security and storage practices and has not publicized any measures they may take to protect their customers’ data.

Vpnmentor researchers wrote: “The data breach affected customers around the world, with entries from many of their international sites, and in numerous languages.”

Private personal data exposed in the leak included users’ IP addresses, countries of residence, email addresses, and the destination pages and online activity of users on the vendor’s website. 

“This data breach represents a major lapse in LightInTheBox’s data security. While this data leak doesn’t expose critical user data, some basic security measures were not taken,” wrote researchers. 

Researchers warned that a leak of this nature could put customers at risk from crimes far more disturbing than online fraud.

“With a website user’s IP address, we were able to identify their city of residence. If a criminal hacker had access to this, along with the other data exposed, they could trick a victim into revealing their home address, and target them for theft and home robbery,” wrote researchers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Jersey Health Network Pays Up in Ransomware Attack

New Jersey Health Network Pays Up in Ransomware Attack

New Jersey’s largest hospital health network has paid threat actors an undisclosed sum to restore data compromised in a cyber-attack.

Hackensack Meridian Health‘s computer systems were shut down after being infected with ransomware on Monday, December 2. The attack caused major disruptions to services at 17 hospitals, nursing homes, and urgent care centers operated by the network.

Elective surgeries for roughly 100 patients were rescheduled as a result of the ransomware incident. Hackensack Meridian Health employees who were unable to access electronic records had to revert to using a paper-based system to deliver care. 

The ransomware payment, together with the costs associated with recovering from a cyber-attack, were covered by Hackensack Meridian Health’s insurance policy, according to Asbury Park Press.

At first, Hackensack Meridian Health was reluctant to disclose the true nature of the problem, citing only that it was grappling with “externally-driven technical issues.” 

But, on Thursday, December 5, news of the ransomware attack was leaked to NJ Advance Media by a hospital IT professional who chose to remain anonymous.

Bridget Devane, a spokesperson for the union Health Professionals and Allied Employees, or HPAE, confirmed on Friday, December 6, at 5 p.m., that “northern New Jersey hospitals are definitely back online.”

Describing the disruption caused by the incident, Devane said: “There have been delays in orders and lab work, and they are having to double-check paperwork carefully to make sure everything is accurate.”

According to NJ Advance Media, the health network confirmed the ransomware attack and the payment of the ransom in a statement released on Friday, December 13.

The statement read: “Due to developments in the investigation, and on advice of national experts, we could not disclose that this was a ransomware attack until now.

“Our network’s primary clinical systems are operational, and our IT teams continue working diligently to bring all applications back online safely. Based on our investigation to date, we have no indication that any patient or team member information has been subject to unauthorized access or disclosure.”

Hackensack Meridian Health, which is based in Edison, New Jersey, has more than 35,000 employees and generates around $6bn in annual revenue.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet Spammers Send Christmas Phishing Emails

Emotet Spammers Send Christmas Phishing Emails

Spammers behind one of the most prolific botnets of recent years have begun bombarding users with Christmas-themed phishing lures, according to researchers.

Phishing emails sent by the Emotet botnet were spotted by Cofense Labs. With typical subject lines such as “Christmas” or “Christmas Party” they’re trying to gain legitimacy by tapping the current seasonal trend for internal emails of this sort.

One particular phishing email posted to Twitter by the vendor read:

“I have attached the menu for the Christmas Party next week. If you would like bring something, look at the list and let me know. Don’t forget to get your donations in for the money tree. Also, wear your tackiest/ugliest Christmas sweater to the party.”

Malicious Word documents are typically attached to these emails, with names like “Party menu” and “Annual Holiday Lunch.” They require the user to “enable editing” to view, but clicking on this button will execute embedded macros to install the Emotet Trojan.

Once installed, this could provide various groups with he means to attempt ransomware downloads, more spam and phishing emails.

Like TrickBot, Emotet was originally a banking Trojan, but then was re-written to function as a malware loader. Its operators sell access for clients to use it as a malware distribution network.

According to Malwarebytes, Emotet malware was detected and removed over 1.5 million times between January and September 2018. In July 2018, the threat became so serious that the US-CERT was forced to release an alert about Emotet and its capabilities.

The Christmas phishing lures have been seen before: back in 2018 Trend Micro warned of a similar campaign targeting UK users. It urged them at the time to automatically disable macros in their security settings.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Leak Exposes One Million Web Browsing Records

Data Leak Exposes One Million Web Browsing Records

Security researchers have uncovered a massive 890GB database containing over one million highly sensitive web browsing records leaked by a South African IT company.

The Elasticsearch database, which was left online without any password protection, belonged to Conor, which has a range of big-name ISP and telco clients in Africa and South America, according to vpnMentor.

The unencrypted data trove related to a web filtering product the South African firm produced for these clients. Effectively this meant it revealed user activity logs for the previous two months, including website URLs, IP address, index names, and MSISDN codes which identify mobile users on a specific network.

These details include highly sensitive web browsing activity such as attempts to visit pornography sites, social media accounts, online storage including iCloud and messaging apps such as WhatsApp.

“Because the database gave access to a complete record of each user’s activity in a session, our team was able to view every website they visited – or attempted to visit. We could also identify each user,” the vpnMentor team explained.

“For an ICT and software development company not to protect this data is incredibly negligent. Conor’s lapse in data security could create real-world problems for the people exposed.”

If hackers had access to the leaked browsing data, exposed customers could find themselves targeted for blackmail and extortion due to the sensitive nature of the sites they may have visited.

That’s not to mention the reputational impact on Conor itself, among its client base, and the ISPs to whom end users would probably turn their ire in the event of a serious breach.

This is just the latest in a long line of exposed Elasticsearch databases revealed by vpnMentor as part of a major web mapping project designed to improve cloud security.

Erring brands have included cosmetics giant Yves Rocher, Canadian telco Freedom Mobile, and Best Western Hotels.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One in 172 RSA Keys Vulnerable to Attack: Report

One in 172 RSA Keys Vulnerable to Attack: Report

The security of RSA certificates has come under scrutiny after researchers revealed that they were able to break nearly a quarter of a million currently active keys.

Security vendor Keyfactor announced its findings in a paper published at the First IEEE Conference on Trust, Privacy and Security in Intelligent Systems and Applications.

The team first built a database of 75 million active RSA keys, augmented with another 100 million certs available through certificate transparency logs.

RSA keys consist of the product of two large, randomly chosen prime numbers and are typically used to encrypt data in transit. However, if a key shares its prime factors with others, then it is compromised.

Unfortunately, the researchers found over 435,000 certificates with a shared factor, enabling them to “rederive” the private key.

“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor.

“The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

This could have a particularly major impact on the IoT sphere due to the low entropy or lack of randomness in key generation there, the firm said.

“These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm,” argued Keyfactor CTO, Ted Shorter.

Michael Barragry, operations lead and security consultant at Edgescan, explained that the issue discovered by the research team was a fault in implementation rather than a weakness with the underlying mathematics.

“Public key certificates are one of the key pieces of infrastructure that enable various devices and servers to securely identify and trust each other. If a malicious actor can successfully spoof a certificate for a particular device, they can essentially masquerade as that device. Depending on the trust chain that it lies within, multiple further attacks may be possible,” he added.

“Vendors need to be conscious of the potential upstream impact of all design decisions, as in this case it seems like an innocuous shortcut around random number generation has given rise to a much more serious flaw.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk