—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Author: admin
Log4J-Related RCE Flaw in H2 Database Earns Critical Rating
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Friday Squid Blogging: Squid Prices Are Rising
The price of squid in Korea is rising due to limited supply.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Norton’s Antivirus Product Now Includes an Ethereum Miner
Norton 360 can now mine Ethereum. It’s opt-in, and the company keeps 15%.
It’s hard to uninstall this option.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Norton 360 Now Comes With a Cryptominer
Norton 360, one of the most popular antivirus products on the market today, has installed a cryptocurrency mining program on its customers’ computers. Norton’s parent firm says the cloud-based service that activates the program and allows customers to profit from the scheme — in which the company keeps 15 percent of any currencies mined — is “opt-in,” meaning users have to agree to enable it. But many Norton users complain the mining program is difficult to remove, and reactions from longtime customers have ranged from unease and disbelief to, “Dude, where’s my crypto?”

Norton 360 is owned by Tempe, Ariz.-based NortonLifeLock Inc. In 2017, the identity theft protection company LifeLock was acquired by Symantec Corp., which was renamed to NortonLifeLock in 2019 (LifeLock is now included in the Norton 360 service).
According to the FAQ posted on its site, “Norton Crypto” will mine Ethereum (ETH) cryptocurrency while the customer’s computer is idle. The FAQ also says Norton Crypto will only run on systems that meet certain hardware and software requirements (such as an NVIDIA graphics card with at least 6 GB of memory).
“Norton creates a secure digital Ethereum wallet for each user,” the FAQ reads. “The key to the wallet is encrypted and stored securely in the cloud. Only you have access to the wallet.”
NortonLifeLock began offering the mining service in July 2021, and early news coverage of the program did not immediately receive widespread attention. That changed on Jan. 4, when Boing Boing co-editor Cory Doctorow tweeted that NortonCrypto would run by default for Norton 360 users.

NortonLifeLock says Norton Crypto is an opt-in feature only and is not enabled without user permission.
“If users have turned on Norton Crypto but no longer wish to use the feature, it can be disabled by temporarily shutting off ‘tamper protection’ (which allows users to modify the Norton installation) and deleting NCrypt.exe from your computer,” NortonLifeLock said in a written statement. However, many users have reported difficulty removing the mining program.
From reading user posts on the Norton Crypto community forum, it seems some longtime Norton customers were horrified at the prospect of their antivirus product installing coin-mining software, regardless of whether the mining service was turned off by default.
“How on Earth could anyone at Norton think that adding crypto mining within a security product would be a good thing?,” reads a Dec. 28 thread titled “Absolutely furious.”
“Norton should be DETECTING and killing off crypto mining hijacking, not installing their own,” the post reads. “The product people need firing. What’s the next ‘bright idea’? Norton Botnet? ‘ And I was just about to re-install Norton 360 too, but this has literally has caused me to no longer trust Norton and their direction.”
It’s an open question whether Norton Crypto users can expect to see much profit from participating in this scheme, at least in the short run. Mining cryptocurrencies basically involves using your computer’s spare resources to help validate financial transactions of other crypto users. Crypto mining causes one’s computer to draw more power, which can increase one’s overall electricity costs.
“Norton is pretty much amplifying energy consumption worldwide, costing their customers more in electricity use than the customer makes on the mining, yet allowing Norton to make a ton of profit,” tweeted security researcher Chris Vickery. “It’s disgusting, gross, and brand-suicide.”
Then there’s the matter of getting paid. Norton Crypto lets users withdraw their earnings to an account at cryptocurrency platform CoinBase, but as Norton Crypto’s FAQ rightly points out, there are coin mining fees as well as transaction costs to transfer Ethereum.
“The coin mining fee is currently 15% of the crypto allocated to the miner,” the FAQ explains. “Transfers of cryptocurrencies may result in transaction fees (also known as “gas” fees) paid to the users of the cryptocurrency blockchain network who process the transaction. In addition, if you choose to exchange crypto for another currency, you may be required to pay fees to an exchange facilitating the transaction. Transaction fees fluctuate due to cryptocurrency market conditions and other factors. These fees are not set by Norton.”
Which might explain why so many Norton Crypto users have taken to the community’s online forum to complain they were having trouble withdrawing their earnings. Those gas fees are the same regardless of the amount of crypto being moved, so the system simply blocks withdrawals if the amount requested can’t cover the transfer fees.
Norton Crypto. Image: Bleeping Computer.
I guess what bothers me most about Norton Crypto is that it will be introducing millions of perhaps less savvy Internet users to the world of cryptocurrency, which comes with its own set of unique security and privacy challenges that require users to “level up” their personal security practices in fairly significant ways.
Several of my elder family members and closest friends are longtime Norton users who renew their subscription year after year (despite my reminding them that it’s way cheaper just to purchase it again each year as a new user). None of them are particularly interested in or experts at securing their computers and digital lives, and the thought of them opening CoinBase accounts and navigating that space is terrifying.
Big Yellow is not the only brand that’s cashing in on investor fervor over cryptocurrencies and hoping to appeal to a broader (or maybe just older) audience: The venerable electronics retailer RadioShack, which relaunched in 2020 as an online-focused brand, now says it plans to chart a future as a cryptocurrency exchange.
“RadioShack’s argument is basically that as a very old brand, it’s primed to sell old CEOs on cryptocurrency,” writes Adi Robertson for The Verge.
“Too many [cryptocurrency companies] focused on speculation and not enough on making the ‘old-school’ customer feel comfortable,” the company’s website states, claiming that the average “decision-making” corporate CEO is 68 years old. “The older generation simply doesn’t trust the new-fangled ideas of the Bitcoin youth.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Covid Test Data Breach at British School
Covid Test Data Breach at British School

A mix-up at a school in Worcestershire, England, caused parents to receive the Covid-19 test results of other people’s children.
The data breach, reported today by the Evesham Journal, occurred at co-educational secondary school and sixth-form college The De Montfort School (TDMS) in Evesham, which is part of the Four Stones Multi Academy Trust.
Students returning to learning after the holiday season underwent asymptomatic testing for the coronavirus at TDMS on Tuesday. In a security incident ascribed to “human error,” some students’ test results were sent to the wrong guardians.
Ninth-grade student Amelia Felton was among the children affected by the data breach. Felton’s mother, Becky, learned of the security breach not through the school, but via the parent of another student.
“I’m not very happy,” Becky Felton told the Evesham Journal. “It was another parent that told me she had received my daughter’s result. This is a serious breach of personal data.”
The head teacher at The De Montfort School, Ruth Allen, confirmed that the data breach had taken place while the test results were being uploaded to the school’s network.
Allen said the incident had involved the personal data of only a small number of students, and that the school’s coronavirus testing process had been successful owing to the cooperation of students and teaching staff.
“In line with government guidance, on Tuesday, January 4, the school facilitated asymptomatic testing for our students following the Christmas break,” said Allen.
“Testing for students was completed quickly and without fuss thanks to our excellent team of testers and the good will of our students, who now have testing down to a fine art. This meant that all students were back in face-to-face lessons on Wednesday.”
She added: “Unfortunately, whilst uploading results, a data breach occurred that affected a small number of students.”
Allen said that the data breach has been investigated according to the regulations laid out in the Four Stones Multi Academy Trust data protection policy and that the security incident was reported to the Information Commissioner’s Office.
The TDMS head added that the data breach was “found to be the result of a human error.”
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Cyber-Attack on Fertility Centers of Illinois
Cyber-Attack on Fertility Centers of Illinois

A company that operates multiple fertility centers across Northern Illinois has suffered a data breach because of a cyber-attack.
Fertility Centers of Illinois (FCI) reported the data breach to the Department of Health and Human Services’ Office for Civil Rights (OCR) as affecting 79,943 current and former patients.
The unidentified attacker had access to some of the patients’ protected health information (PHI) and was also able to access personal data belonging to FCI employees.
Third-party computer forensic specialists were hired by FCI after the company detected suspicious network activity on February 1, 2021.
While cybersecurity measures implemented by FCI ensured that the company’s electronic medical record system could not be accessed, the attacker was able to get into administrative files and folders.
FCI reviewed the contents of the compromised files and by August 27, 2021, determined that they contained a range of patient data including names in combination with one or more of the following types of information: Social Security numbers, passport numbers, financial account information, payment card information, diagnoses, treatment information, medical record numbers, billing/claims information, prescription information, Medicare/Medicaid identification information, health insurance group numbers, health insurance subscriber numbers, patient account numbers, encounter numbers, referring physicians, usernames and passwords with PINs, or account login information.
Employee information potentially compromised in the cyber-attack included names, employer-assigned identification numbers, ill-health/retirement information, occupational health-related information, medical benefits and entitlements information, patkeys/reason for absence, and sickness certificates.
Since the attack occurred, FCI has made improvements to its cybersecurity posture, which include implementing enterprise-class identity verification software and providing extra training to its workforce on cybersecurity practices.
Data breach notifications have been mailed out to all affected individuals. FCI is offering victims complimentary credit monitoring and identity theft protection services for 12 months through Equifax.
News of the FCI attack follows the theft of data from America’s largest fertility clinic operator, US Fertility, in September 2020. In November 2021, a fertility clinic in the United Kingdom also became the victim of cyber-criminals when ransomware was used to attack a medical record scanning company used by Lister Fertility Clinic.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Investigation Launched into RIPTA Data Breach
Investigation Launched into RIPTA Data Breach

A recently reported data breach impacting the Rhode Island Public Transit Authority (RIPTA) is to be investigated by the state’s attorney general.
The protected health information (PHI) of thousands of individuals was involved in the data breach, which occurred when RIPTA was attacked by cyber-criminals last summer.
RIPTA reported the data breach to the Department of Health and Human Services’ Office for Civil Rights (OCR) as affecting 5,015 individuals who are members of the transport authority’s group health plan.
The Providence Journal reports that the number of impacted individuals subsequently rose to 17,378.
Suspicious activity was identified on RIPTA’s computer network on August 5, 2021, and – according to a breach notice posted to the authority’s website – blocked the same day.
Digital forensic evidence of the cybercrime revealed that parts of RIPTA’s network had been accessible to an unknown threat actor since August 3, 2021.
After reviewing what data the threat actor had been able to access, RIPTA determined that files containing the personal information of health plan members were stored in the comprised area of the network and that these files had been exfiltrated in the cyber-attack.
Data stored in the exfiltrated files included health plan members’ names, addresses, dates of birth, Social Security numbers, Medicare ID numbers, qualification information, health plan ID numbers, and claims information.
According to a document sent to state employees by the Department of Administration on Wednesday, some of the PHI exfiltrated in the attack had been “incorrectly shared” with RIPTA by the state’s previous health insurance provider, UnitedHealthcare.
RIPTA senior executive Courtney Marciano said that the PHI of individuals with no connection to RIPTA had been sent to the transport authority in error by UnitedHealthcare. RIPTA has since switched its insurance provider to Horizon BlueCross/Blue Shield of Rhode Island.
Rhode Island attorney general Peter Neronha stated his intention to investigate the data breach to the Providence Journal. Neronha’s probe will determine whether any state laws have been violated, such as the Identity Theft Protection Act of 2015.
It is possible that the OCR may investigate UnitedHealthcare over the seemingly impermissible disclosure of state employees’ PHI to RIPTA.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
UK Police Seize £322m of Cryptocurrency in Past Five Years
UK Police Seize £322m of Cryptocurrency in Past Five Years

UK police have seized cryptocurrency worth £322m over the past five years, according to official figures obtained by the New Scientist publication following a freedom of information (FoI) request.
The funds were taken during multiple criminal investigations over this period, highlighting how cryptocurrencies are increasingly used in illegal activity. This is primarily due to the challenges law enforcement face in seizing digital currencies compared to cash. One of these is that cryptocurrencies are often protected by strong encryption, which is impenetrable without a key. It is also difficult for law enforcement to seize cryptocurrency under existing legislation in the UK, even if there is suspicion it has been gained from criminal activity.
The £322m worth of funds were seized by 12 of the UK’s 48 police forces, although the true figure could be much higher because 15 forces reportedly did not respond to the New Scientist’s request. In addition, the UK’s National Crime Agency, which is exempt from FoI legislation, has not revealed how much cryptocurrency it has seized.
Almost all (99%) of the seized cryptocurrencies were Bitcoin, although small amounts of Ethereum, Dash, Monero and Zcash were also confiscated.
Commenting on the story, Jake Moore, former head of digital forensics at Dorset Police and global cybersecurity advisor at ESET, said: “Police forces have come so far in digital investigations, yet the final step of confiscation is simply too difficult to examine in many situations. The key design of cryptocurrencies is to keep them secure from interception from anyone, whether that be a threat actor or law enforcement, plus they were not intended to have a back door for any reason. This naturally causes a problem for police forces wanting to seize through the original procedures they are all used to with old-fashioned finances. In some cases, criminals may be locked up without giving away access to their funds, only to see huge returns on their release from jail.
“Digital investigations still remain in their infant phase and require far more resources to improve fighting this growing criminality. Cyber-criminals are very aware of the well-documented evasion tactics available but policing is improving at a rate that will slowly catch up in time. Deploying better surveillance techniques on known suspects, increasing intelligence and improving the profiling on those who are thought to be involved all helps build stronger evidence to recover and seize funds. However, the cost of this could potentially outweigh the amount that is recoverable in many cases.”
Last year, Europol revealed it had observed the proliferation of new money laundering techniques involving cyptocurrencies, a trend exacerbated by the COVID-19 pandemic.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains
Man Pleads Guilty to $50m Investment Fraud Scheme
Man Pleads Guilty to $50m Investment Fraud Scheme

A Californian man has admitted his part in a $50m conspiracy to defraud scores of investors via lookalike scam websites.
Allen Giltman, 56, of Irvine, pleaded guilty to one count of conspiracy to commit wire fraud and one count of conspiracy to commit securities fraud.
For eight years up to October 2020, he’s said to have conspired with others to build and run websites to solicit funds from investors. Many were designed to look like legitimate sites run by financial institutions or non-existent but legitimate-seeming companies.
To enhance the sites’ legitimacy, the conspirators would falsely claim their ‘institutions’ were regulated by the Federal Deposit Insurance Corporation (FDIC), the Financial Industry Regulatory Authority (FINRA), the Securities Investor Protection Corporation and the New York Stock Exchange.
They claimed deposits would be protected and used real names and logos of the companies they impersonated.
Lured in by higher-than-average rates of return on their certificates of deposit (CDs), the victims usually found the sites via internet searches, according to the Department of Justice (DoJ).
Giltman typically fielded introductory calls and emails from these victims, impersonating real FINRA broker-dealers using their names and FINRA Central Registration Depository numbers. He then provided would-be investors with application forms and instructions on how to wire funds for CD purchases.
In reality, no investor ever received a CD, and their funds were apparently moved to various international bank accounts in Russia, Georgia, Hong Kong, and Turkey.
Investigators identified around 70 victims of the nationwide scheme and as many as 150 scam sites.
Giltman faces a maximum jail term of 25 years and will be forced to pay $500,000 or twice the gross amount of gain or loss from each offense, whichever is greater. He is also facing a civil complaint filed yesterday by the SEC.
Investment fraud is among the highest-grossing cybercrimes, according to the FBI. It revealed that over $336m was lost to fraudsters in 2020, more than any other crime type bar romance scams and business email compromise.
Over 8700 victims were identified during the reporting period.
—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains