Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Mozilla mandates 2FA security for Firefox developers
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Epilepsy Foundation Bombarded with Seizure-Triggering Twitter Posts
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Rooster Teeth Attack Showcases New Magecart Approach
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Alexa, Google Home Eavesdropping Hack Not Yet Fixed
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Iranian Attacks on Industrial Control Systems
New details:
At the CyberwarCon conference in Arlington, Virginia, on Thursday, Microsoft security researcher Ned Moran plans to present new findings from the company’s threat intelligence group that show a shift in the activity of the Iranian hacker group APT33, also known by the names Holmium, Refined Kitten, or Elfin. Microsoft has watched the group carry out so-called password-spraying attacks over the past year that try just a few common passwords across user accounts at tens of thousands of organizations. That’s generally considered a crude and indiscriminate form of hacking. But over the last two months, Microsoft says APT33 has significantly narrowed its password spraying to around 2,000 organizations per month, while increasing the number of accounts targeted at each of those organizations almost tenfold on average.
[…]
The hackers’ motivation — and which industrial control systems they’ve actually breached — remains unclear. Moran speculates that the group is seeking to gain a foothold to carry out cyberattacks with physically disruptive effects. “They’re going after these producers and manufacturers of control systems, but I don’t think they’re the end targets,” says Moran. “They’re trying to find the downstream customer, to find out how they work and who uses them. They’re looking to inflict some pain on someone’s critical infrastructure that makes use of these control systems.”
It’s unclear whether the attackers are causing any actual damage, or just gaining access for some future use.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Nuclear Bot Author Arrested in Sextortion Case
Last summer, a wave of sextortion emails began flooding inboxes around the world. The spammers behind this scheme claimed they’d hacked your computer and recorded videos of you watching porn, and promised to release the embarrassing footage to all your contacts unless a bitcoin demand was paid. Now, French authorities say they’ve charged two men they believe are responsible for masterminding this scam. One of them is a 21-year-old hacker interviewed by KrebsOnSecurity in 2017 who openly admitted to authoring a banking trojan called “Nuclear Bot.”

On Dec. 15, the French news daily Le Parisien published a report stating that French authorities had arrested and charged two men in the sextortion scheme. The story doesn’t name either individual, but rather refers to one of the accused only by the pseudonym “Antoine I.,” noting that his first had been changed (presumably to protect his identity because he hasn’t yet been convicted of a crime).
“According to sources close to the investigation, Antoine I. surrendered to the French authorities at the beginning of the month, after being hunted down all over Europe,” the story notes. “The young Frenchman, who lived between Ukraine, Poland and the Baltic countries, was indicted on 6 December for ‘extortion by organized gang, fraudulent access to a data processing system and money laundering.’ He was placed in pre-trial detention.”
According to Le Parisien, Antoine I. admitted to being the inventor of the initial 2018 sextortion scam, which was subsequently imitated by countless other ne’er-do-wells. The story says the two men deployed malware to compromise at least 2,000 computers that were used to blast out the sextortion emails.
While that story is light on details about the identities of the accused, an earlier version of it published Dec. 14 includes more helpful clues. The Dec. 14 piece said Antoine I. had been interviewed by KrebsOnSecurity in April 2017, where he boasted about having created Nuclear Bot, a malware strain designed to steal banking credentials from victims.
My April 2017 exposé featured an interview with Augustin Inzirillo, a young man who came across as deeply conflicted about his chosen career path. That path became traceable after he released the computer code for Nuclear Bot on GitHub. Inzirillo outed himself by defending the sophistication of his malware after it was ridiculed by both security researchers and denizens of the cybercrime underground, where copies of the code wound up for sale. From that story:
“It was a big mistake, because now I know people will reuse my code to steal money from other people,” Inzirillo told KrebsOnSecurity in an online chat.
Inzirillo released the code on GitHub with a short note explaining his motivations, and included a contact email address at a domain (inzirillo.com) set up long ago by his father, Daniel Inzirillo.
KrebsOnSecurity also reached out to Daniel, and heard back from him roughly an hour before Augustin replied to requests for an interview. Inzirillo the elder said his son used the family domain name in his source code release as part of a misguided attempt to impress him.
“He didn’t do it for money,” said Daniel Inzirillo, whose CV shows he has built an impressive career in computer programming and working for various financial institutions. “He did it to spite all the cyber shitheads. The idea was that they wouldn’t be able to sell his software anymore because it was now free for grabs.”
If Augustin Inzirillo ever did truly desire to change his ways, it wasn’t clear from his apparent actions last summer: The Le Parisien story says the sextortion scams netted the Frenchman and his co-conspirator at least a million Euros.
In August 2018, KrebsOnSecurity was contacted by a researcher working with French authorities on the investigation who said he suspected the young man was bragging on Twitter that he used a custom version of Nuclear Bot dubbed “TinyNuke” to steal funds from customers of French and Polish banks.

The source said this individual used the now-defunct Twitter account @tiny_gang1 to taunt French authorities, while showing off a fan of 100-Euro notes allegedly gained from his illicit activities (see image above). It seemed to the source that Inzirillo wanted to get caught, because at one point @tiny_gang1 even privately shared a copy of Inzirillo’s French passport to prove his identity and accomplishments to the researcher.
“He modified the Tinynuke’s config several times, and we saw numerous modifications in the malware code too,” the source said. “We tried to compare his samples with the leaked code available on GitHub and we noticed that the guy actually was using a more advanced version with features that don’t exist in the publicly available repositories. As an example, custom samples have video recording functionality, socks proxy and other features. So the guy clearly improved the source code and recompiled a new version for every new campaign.”
The source said the person behind the @tiny_gang Twitter account attacked French targets with custom versions of TinyNuke in one to three campaigns per week earlier this year, harvesting French bank accounts and laundering the stolen funds via a money mule network based mostly in the United Kingdom.
“If the guy behind this campaign is the malware author, it could easily explain the modifications happening with the malware, and his French is pretty good,” the researcher told KrebsOnSecurity. “He’s really provocative and I think he wants to be arrested in France because it could be a good way to become famous and maybe prove that his malware works (to resell it after?).”
The source said the TinyNuke author threatened him with physical harm after the researcher insulted his intelligence while trying to goad him into disclosing more details about his cybercrime activities.
“The guy has a serious ego problem,” the researcher said. “He likes when we talk about him and he hates when we mock him. He got really angry as time went by and started personally threatening me. In the last [TinyNuke malware configuration file] targeting Poland we found a long message dedicated to me with clear physical threats.”
All of the above is consistent with the findings detailed in the Le Parisien report, which quoted French investigators saying Antoine I. in October 2019 used a now-deleted Twitter account to taunt the authorities into looking for him. In one such post, he included a picture of himself holding a beer, saying: “On the train to Naples. You should send me a registered letter instead of threatening guys informally.”
The Le Parisien story also said Antoine I. threatened a researcher working with French authorities on the investigation (the researcher is referred to pseudonymously as “Marc”).
“I make a lot more money than you, I am younger, more intelligent,” Antoine I. reportedly wrote in July 2018 to Marc. “If you do not stop playing with me, I will put a bullet in your head. ”
French authorities say the defendant managed his extortion operations while traveling throughout Ukraine and other parts of Eastern Europe. But at some point he decided to return home to France, despite knowing investigators there were hunting him. According to Le Parisien, he told the French authorities he wanted to cooperate in the investigation and that he no longer wished to live like a fugitive.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Orbitz and Expedia Agree to Data Breach Settlement with Pennsylvania
Orbitz and Expedia Agree to Data Breach Settlement with Pennsylvania

The office of Pennsylvania attorney general Josh Shapiro has reached a settlement with travel websites Orbitz and Expedia following an investigation into a 2018 data breach.
The cybersecurity incident, disclosed by Orbitz in March 2018, may have exposed the personal data of 20,755 Pennsylvanian customers.
An investigation into the breach, carried out by Shapiro’s office and led by Deputy Attorney General Timothy Murphy, found that a threat actor had used malware to target up to 880,000 payment cards around the world by compromising Orbitz’s online travel booking portal.
Orbitz was notified by a business partner in 2017 that the travel rewards redemption portal hosted by the Orbitz Legacy Platform may have been a possible common point of purchase in connection with fraudulent payment card transactions.
The Assurance of Voluntary Compliance, filed in Philadelphia County, alleges Orbitz violated Pennsylvania’s Unfair Trade Practices and Consumer Protection Law by making misrepresentations in its customer-facing privacy policy about the safeguarding of customers’ personal information.
It further alleges that Orbitz failed to fully implement Expedia’s company policies related to data security and neglected to have in place multiple Payment Card Industry Data Security Standards at the time of the breach.
Under the terms of the settlement, Expedia and Orbitz will pay $110,000, which includes an $80,000 civil penalty. Expedia acquired Orbitz and its assets in September 2015.
Josh Shapiro said: “Just like that, someone broke into Orbitz’s IT system and vacationed in what was supposed to be a safe place for travelers. The breach showed the company’s promise to keep customer information secure was more like a leaky boat.
“We work every day to protect Pennsylvania consumers and to seek justice when any company misrepresents itself.”
Expedia and Orbitz have agreed to strengthen their security practices going forward by implementing a comprehensive information security program on the Orbitz website, conducting an annual comprehensive risk assessment, and developing a plan and program for designing, implementing, and operating safeguards.
The companies have also agreed to perform regular security monitoring, logging, and testing; improve access control and account management tools; reorganize and segment its network; and comply with Payment Card Industry Data Security Standards.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Instagram Mounts Challenge Against Free Speech
Instagram Mounts Challenge Against Free Speech

Instagram has launched an artificial intelligence warning system that challenges the free speech of its users.
Starting today, the social networking app will notify people when their captions on a photo or video “may be considered offensive” and give them “a chance to pause and reconsider their words before posting.”
A user who attempts to post a comment deemed to be objectionable will receive a prompt that reads “This caption looks similar to others that have been reported.” The user will then be given three options: to edit the caption, to learn more about why their comment has prompted this response, or to share it anyway.
The new warnings feature is being presented as a strategy to reduce online bullying; however, the warnings are the smallest of steps away from directly impeding users’ free speech.
Rollout of the warnings feature has currently only been undertaken in “select countries”; however, Instagram plans to exert control over what users are allowed to post globally in the coming months.
In a statement released today, Instagram wrote: “As part of our long-term commitment to lead the fight against online bullying, we’ve developed and tested AI that can recognize different forms of bullying on Instagram. Earlier this year, we launched a feature that notifies people when their comments may be considered offensive before they’re posted.
“Results have been promising, and we’ve found that these types of nudges can encourage people to reconsider their words when given a chance.”
Instagram has not stated who it is that decides whether content is potentially offensive or by what standards such comments are measured. No mention is given either of the potential dangers of silencing users’ voices and driving the disaffected underground.
Instagram wrote: “Today, when someone writes a caption for a feed post and our AI detects the caption as potentially offensive, they will receive a prompt informing them that their caption is similar to those reported for bullying. They will have the opportunity to edit their caption before it’s posted.
“In addition to limiting the reach of bullying, this warning helps educate people on what we don’t allow on Instagram, and when an account may be at risk of breaking our rules.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Apax Funds to Acquire Coalfire
Apax Funds to Acquire Coalfire

Funds advised by global private equity advisors Apax Partners are to acquire cybersecurity assessment and consulting services provider Coalfire.
The long-established cybersecurity firm, which has 730 employees operating from 11 locations in the United States and the United Kingdom, is being purchased from The Carlyle Group and The Chertoff Group for an undisclosed sum.
According to a statement released on Friday, the deal is expected to close in early 2020, subject to regulatory approval.
Coalfire was founded in 2001 with the mission to help organizations avert threats, close gaps, and effectively manage cyber-risk. Today, the company has more than 1,800 government and commercial clients and extensive cloud security experience, working with seven of the top ten SaaS providers.
In the US, Coalfire is one of several third-party assessment organizations chosen by the government to evaluate and certify cloud computing products and services for use by federal agencies as part of the government-wide Federal Risk and Authorization Management Program (FedRAMP).
Rohan Haldea, partner at Apax Partners, said: “Coalfire is an established and highly respected cybersecurity advisory and assessment services firm that is well-positioned for further growth due to cybersecurity trends and the vision of its strong management team. The Apax Funds’ investment will assist the company in particular by increasing Coalfire’s investment in technology; continuing to invest in thought leadership, especially with respect to securing cloud environments; and deepening capabilities across assurance standards while scaling its penetration testing and cyber-risk services business.”
William Blair and Latham & Watkins respectively served as financial and legal advisers to Coalfire in the transaction. Kirkland & Ellis LLP acted as Apax Funds’ legal counsel.
Carlyle made an investment in Coalfire in 2015 through its $1.1bn US Equity Opportunity Fund I. At the end of 2016, Coalfire acquired Viennese cybersecurity leader Veris Group.
Tom McAndrew, Coalfire CEO, said: “We are thrilled with our new partnership with Apax, which will help drive our growth plans while continuing our commitment to our customers, people, and core values. The leadership, support, and investment provided by Carlyle, Chertoff, and Baird Capital have been instrumental in our success over the last four years, and we are excited to begin this new chapter.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk