—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Emotet’s Behavior & Spread Are Omens of Ransomware Attacks
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
New German Government is Pro-Encryption and Anti-Backdoors
I hope this is true:
According to Jens Zimmermann, the German coalition negotiations had made it “quite clear” that the incoming government of the Social Democrats (SPD), the Greens and the business-friendly liberal FDP would reject “the weakening of encryption, which is being attempted under the guise of the fight against child abuse” by the coalition partners.
Such regulations, which are already enshrined in the interim solution of the ePrivacy Regulation, for example, “diametrically contradict the character of the coalition agreement” because secure end-to-end encryption is guaranteed there, Zimmermann said.
Introducing backdoors would undermine this goal of the coalition agreement, he added.
I have written about this.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Does Your Child Have an Unhealthy Relationship with Social Media?
Have you noticed that when parents gather, it doesn’t take long before the topic of kids and social media comes up. That’s because concern over screen time is a big deal, especially in this post-pandemic season. Parents want to know: How much is too much screen time? When should we step in? How do we reverse poor habits, and what will the lasting digital fallout of the lockdown be?
Device Dependence
These conversations weigh heavy on parents for a good reason. According to a report from Common Sense Media, teens spend an average of seven hours and 22 minutes on their phones a day. Tweens (ages 8 to 12) spend four hours and 44 minutes daily. This is time outside of schoolwork.
Since the pandemic, another study claims that screen time for teens doubled to 7.7 hours a day—plus 5 to 7 daily hours of online learning, according to a study published in JAMA Pediatrics. In addition, according to the Journal of Affective Disorders Reports, children overall have been spending nearly triple the recommended amount of time on their screens.
The good news is that social media also became a powerful tool for kids during the pandemic. Social channels helped kids connect with peers and combat loneliness and other mental health challenges. Still, the poor habit of device dependence may have come with those benefits.
Revising Screen time
While the debate continues over social media’s impact on kids and the research methodology continues to evolve, we can hold on to one clear truth: Any activity in excess can cause kids harm. When it comes to social media, too much screen time may contribute to sleep deprivation, a lack of healthy, and poor academics. In addition, studies show that mental health can be impacted by exposure to hate speech, sexual content, cyberbullying, and comparing oneself to others both physically and financially.
As parents, we know when our family’s wellbeing is in jeopardy. We see it even if we fail to acknowledge it right away. Our kids might become compelled to check their phones. In fact, they panic when they can’t check their likes and comments every few minutes. We notice the red eyes and moodiness at the breakfast table caused by a late-night Tic Tock marathon. We sense a surge of anxiety in our kids when technology goes from entertaining to distressing.
Thankfully, it’s never too late to help your kids better understand the impact of their actions and revise digital habits.
Establishing new habits
1. Start small and make it fun.
In the bestselling book Atomic Habits, author James Clear says, “The task of breaking a bad habit is like uprooting a powerful oak within us.” He adds, “The task of building a good habit is like cultivating a delicate flower one day at a time.” Lasting change, says clear, needs to be enjoyable, not a punishment. If the goal is shaving a few hours off your child’s screen time, consider connecting time limits to an enjoyable activity such as making a meal together or creating an art space in your home for creative projects.
2. Consider a device curfew.
The data is in: The bright screens (and blue light emitted from devices( can cause permanent sleep cycle and brain/melatonin issues, which can have a cascading effect on physical and mental health. Turning off (or limiting the use of) electronic devices at least 15-30 minutes before going to bed may help prevent any adverse effects of technology and screen use on sleep. Consider investing in filtering software that comes with the time limits the whole family can all agree on. Do your research to ensure your family’s technology functions to empower, educate, and entertain.
3. Encourage mindful media use.
Consider how your child uses their time before suggesting sweeping changes to your child’s screen time. Are they vegetating, or are they consciously engaged? Are they creating and learning? Are they engaging with others or stalking accounts and slipping into “comparison despair?” Are family and school responsibilities suffering? Is there a compulsion to post or thoughtfulness? All kids are different, and all online experiences vary. Encourage your child to take time to consider how they feel and what they think while they are using their technology.
4. Educate your kids—use facts.
One way to negotiate screen limits is to make sure your kids understand the impact of excess media. Balance includes tapping into the benefits of social media while also taking steps to protect the body’s need for physical activity, real-life relationships, goal-setting, creative activities, mindfulness, and self-reflection.
Helping kids manage and constantly revise their social media habits is a 24/7 endeavor from the minute they wake up to the minute they fall asleep. The biggest piece of that “management” plan and is keeping frequent, open, and honest communication a critical part of designing habits that encourage a healthy relationship with both peers and technology.
The post Does Your Child Have an Unhealthy Relationship with Social Media? appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Canada Charges Its “Most Prolific Cybercriminal”
A 31-year-old Canadian man has been arrested and charged with fraud in connection with numerous ransomware attacks against businesses, government agencies and private citizens throughout Canada and the United States. Canadian authorities describe him as “the most prolific cybercriminal we’ve identified in Canada,” but so far they’ve released few other details about the investigation or the defendant. Helpfully, an email address and nickname apparently connected to the accused offer some additional clues.
Matthew Filbert, in 2016.
Matthew Philbert of Ottawa, Ontario was charged with fraud and conspiracy in a joint law enforcement action by Canadian and U.S. authorities dubbed “Project CODA.” The Ontario Provincial Police (OPP) on Tuesday said the investigation began in January 2020 when the U.S. Federal Bureau of Investigation (FBI) contacted them regarding ransomware attacks that were based in Canada.
“During the course of this investigation, OPP investigators determined an individual was responsible for numerous ransomware attacks affecting businesses, government agencies and private individuals throughout Canada as well as cyber-related offenses in the United States,” reads an OPP statement.
“A quantity of evidentiary materials was seized and held for investigation, including desktop and laptop computers, a tablet, several hard drives, cellphones, a Bitcoin seed phrase and a quantity of blank cards with magnetic stripes,” the statement continues.
The U.S. indictment of Philbert (PDF) is unusually sparse, but it does charge him with conspiracy, suggesting the defendant was part of a group. In an interview with KrebsOnSecurity, OPP Detective Inspector Matt Watson declined to say whether other defendants were being sought in connection with the investigation, but said the inquiry is ongoing.
“I will say this, Philbert is the most prolific cybercriminal we’ve identified to date in Canada,” Watson said. “We’ve identified in excess of a thousand of his victims. And a lot of these were small businesses that were just holding on by their fingernails during COVID.”
A DARK CLOUD
There is a now-dormant Myspace account for a Matthew Philbert from Orleans, a suburb of Ottawa, Ontario. The information tied to the Myspace account matches the age and town of the defendant. The Myspace account was registered under the nickname “Darkcloudowner,” and to the email address dark_cl0ud6@hotmail.com.
A search in DomainTools on that email address reveals multiple domains registered to a Matthew Philbert and to the Ottawa phone number 6138999251 [DomainTools is a frequent advertiser on this site]. That same phone number is tied to a Facebook account for a 31-year-old Matthew Philbert from Orleans, who describes himself as a self-employed “broke bitcoin baron.”
Mr. Filbert did not respond to multiple requests for comment.
According to cyber intelligence firm Intel 471, that dark_cl0ud6@hotmail.com address has been used in conjunction with the handle “DCReavers2” to register user accounts on a half-dozen English-language cybercrime forums since 2008, including Hackforums, Blackhatworld, and Ghostmarket.
Perhaps the earliest and most important cybercrime forum DCReavers2 frequented was Darkode, where he was among the first two-dozen members. Darkode was taken down in 2015 as part of an FBI investigation sting operation, but screenshots of the community saved by this author show that DCReavers2 was already well known to the Darkode founders when his membership to the forum was accepted in May 2009.
DCReavers2 was just the 22nd account to register on the Darkode cybercrime forum.
Most of DCReavers’s posts on Darkode appear to have been removed by forum administrators early on (likely at DCReavers’ request), but the handful of posts that survived the purge show that more than a decade ago DCReavers2 was involved in running botnets, or large collections of hacked computers.
“My exploit pack is hosted there with 0 problems,” DCReaver2 says of a shady online provider that another member asked about in May 2010.
Searching the Web on “DCreavers2” brings up a fascinating chat conversation allegedly between DCReavers2 and an individual in Australia who was selling access to an “exploit kit,” commercial crimeware designed to be stitched into hacked or malicious sites and exploit a variety of Web-browser vulnerabilities for the purposes of installing malware of the customer’s choosing.
In that 2009 chat, indexed by the researchers behind the website exposedbotnets.com, DCReavers2 uses the Dark_Cl0ud6 email address and actually shares his real name as Matthew Philbert. DCReavers2 also says his partner uses the nickname “The Rogue,” which corresponds to a former Darkode administrator who was the second user ever registered on the forum (see screenshot above).
In that same conversation, DCReavers2 discusses managing a botnet built on ButterFly Bot. Also known as “Mariposa,” ButterFly was a plug-and-play malware strain that allowed even the most novice of would-be cybercriminals to set up a global operation capable of harvesting data from thousands of infected PCs, and using the enslaved systems for crippling attacks on Web sites. The ButterFly Bot kit sold for prices ranging from $500 to $2,000.
An advertisement for the ButterFly Bot.
The author of ButterFly Bot — Slovenian hacker Matjaz “Iserdo” Skorjanc — was Darkode’s original founder back in 2008. Arrested in 2010, Skorjanc was sentenced to nearly five years in prison for selling and supporting Mariposa, which was used to compromise millions of Microsoft Windows computers.
Upon release from prison, Skorjanc became chief technology officer for NiceHash, a cryptocurrency mining service. In December 2017, $52 million worth of Bitcoin mysteriously disappeared from NiceHash coffers. In October 2019, Skorjanc was arrested in Germany in response to a U.S.-issued international arrest warrant for his extradition.
The indictment (PDF) tied to Skorjanc’s 2019 arrest also names several other alleged founding members of Darkode, including Thomas “Fubar” McCormick, a Massachusetts man who was allegedly one of the last administrators of Darkode. Prosecutors say McCormick also was a reseller of the Mariposa botnet, the ZeuS banking trojan, and a bot malware he allegedly helped create called “Ngrbot.” The U.S. federal prosecution against Skorjanc and McCormick is ongoing.
At the time the FBI dismantled Darkode in 2015, the Justice Department said that out of 800 or so crime forums worldwide, Darkode was the most sophisticated English-language forum, and that it represented “one of the gravest threats to the integrity of data on computers in the United States and around the world.”
Some of Darkode’s core members were either customers or sellers of various “locker” kits, which were basically web-based exploits that would lock the victim’s screen into a webpage spoofing the FBI or Justice Department and warning that victims had been caught accessing child sexual abuse material. Victims who agreed to pay a “fine” of several hundred dollars worth of GreenDot prepaid cards could then be rid of the PC locker program.
A 2012 sales thread on Darkode for Rev Locker.
In many ways, lockers were the precursors to the modern cybercrime scourge we now know as ransomware. The main reason lockers never took off as an existential threat to organizations worldwide was that there is only so much money locker users could reasonably demand via GreenDot cards.
But with the ascendance and broader acceptance of virtual currencies like Bitcoin, suddenly criminal hackers could start demanding millions of dollars from victims. And it stands to reason that a great many Darkode members who were never caught have since transitioned from lockers, exploit kits and GreenDot cards to doing what every other self-respecting cybercrook seems to be involved with these days: Locking entire companies and industries for ransomware payments.
One final observation about the Philbert indictment: It’s good to see the Canadian authorities working closely with the FBI on important cybercrime cases. Indeed, this investigation is remarkable for that fact alone. For years I’ve been wondering aloud why more American cybercriminals don’t just move to Canada, because historically there has been almost no probability that they will ever get caught — let alone prosecuted there. With any luck, this case will be the start of something new.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Brothers Confess to Conning Spanish-speaking Americans
Brothers Confess to Conning Spanish-speaking Americans

Two brothers from Peru have admitted their role in an international call-center scam that defrauded Spanish-speaking immigrants to the United States.
Under the conspiracy, victims were called up and threatened with legal action or deportation if they didn’t buy certain educational products.
The scam was perpetrated from a series of call centers in Peru, including several that were operated and owned or co-owned by 32-year-old Josmell Espinoza Huerta (Josmell Espinoza) and his big brother, Carlos Alberto Espinoza Huerta (Carlos Espinoza), aged 40.
On Monday, the brothers, who are both from Lima, Peru, pleaded guilty to conspiring to commit mail fraud and wire fraud.
Court documents detailed how the Espinoza brothers and their co-conspirators in Peru specifically targeted recent immigrants to the United States from Central America, Mexico, and other Spanish-speaking countries.
From April 2011 until July 2019, the fraudsters contacted victims and deceived them into believing that they were required to buy English-language classes. Victims were told that failure to pay for the products and their delivery costs would cause them to be sued in a fictitious “minor crimes court.”
When making the calls, the Espinoza brothers would variously pretend to be lawyers, court officials, federal agents, and representatives of the fake minor crimes court.
Along with the threat of court proceedings, victims were told that their credit scores would drop and that they could be imprisoned or deported if they didn’t pay their aggressors.
Carlos Espinoza acquired $1.3m from his victims, while Josmell Espinoza caused his victims to lose over $700,000.
All seven defendants indicted in this case have now pleaded guilty. California resident Angel Armando Adrianzen, who worked with call centers in Peru to run the telemarketing scam, was sentenced in May to serve 121 months in prison followed by fifteen years’ supervised release.
Henrry Adrian Milla Campuzano, who owned and operated two call centers in Peru, was sentenced in September to 110 months in prison. Jerson Renteria Gonzales was sentenced to 100 months in prison, and Evelyng Milla Campuzano, Fernan Huerta, and Omar Cuzcano Marroquin and were each sentenced to serve 90 months in prison.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Omicron Scam Targets Universities
Omicron Scam Targets Universities

Dozens of universities are being hit with a coordinated cyber-attack that uses news of the Omicron variant as a lure to steal login credentials.
Evidence of the malicious phishing campaigns was dredged up from the murky depths of the cyber-criminal underworld by researchers at the cybersecurity firm Proofpoint.
The universities targeted are mostly based in North America and include the University of Central Missouri in Warrensburg, Missouri, and Vanderbilt University, a private research university in Nashville, Tennessee.
Researchers found the phishing emails to be typically themed around testing information and the latest in the line of COVID-19 variants to be discovered. One email subject line used by the attackers was “Attention Required – Information Regarding COVID-19 Omicron Variant – November 29.”
“Proofpoint observed COVID-19 themes impacting education institutions throughout the pandemic, but consistent, targeted credential theft campaigns using such lures targeting universities began in October 2021,” noted researchers.
“Following the announcement of the new Omicron variant in late November, the threat actors began leveraging the new variant in credential theft campaigns.”
Inside the phishing emails are attachments or URLs for pages created to harvest credentials for university accounts. While some campaigns feature generic Office 365 login portals, others include landing pages designed to mimic the official login portal of the targeted university.
To make their malicious emails harder to detect, threat actors behind the campaigns sometimes direct victims to a legitimate university communication after harvesting the credentials.
Campaigns that rely on malicious attachments have leveraged legitimate but compromised WordPress websites to host credential-gathering web pages, including hfbcbiblestudy[.]org/demo1/includes/jah/[university]/auth[.]php and traveloaid[.]com/css/js/[university]/auth[.]php.
In some campaigns, threat actors spoofed multi-factor authentication (MFA) providers such as Duo to steal MFA credentials.
“Stealing MFA tokens enables the attacker to bypass the second layer of security designed to keep out threat actors who already know a victim’s username and password,” wrote researchers.
Recipients of the malicious emails may not be able to tell they are being targeted by cyber-criminals simply by looking at the sender’s address.
Researchers wrote: “While many messages are sent via spoofed senders, Proofpoint has observed threat actors leveraging legitimate, compromised university accounts to send COVID-19 themed threats.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Vulnerabilities Found in GOautodial
Vulnerabilities Found in GOautodial

A cybersecurity researcher has discovered multiple vulnerabilities in an open-source call center software suite used around the world.
The Synopsys Cybersecurity Research Center (CyRC) released an advisory today exposing two API vulnerabilities in GOautodial. While multiple providers sell GOautodial as a paid-for cloud service, it is available as a free download.
“The vulnerabilities discovered can be exploited remotely to read system settings without authentication and allow arbitrary code execution by any authenticated user via unrestricted file upload,” wrote researchers in the GOautodial advisory.
Among the vulnerabilities unearthed by Synopsys is the broken authentication flaw CVE-2021-43175, which allows attackers with access to the internal network hosting GOautodial to steal sensitive configuration data, such as default passwords, from the GOautodial server without credentials.
Using this data, a threat actor could connect to other related systems on the network, such as VoIP phones.
Another newly found flaw is CVE-2021-43176, which allows any authenticated user at any level to perform remote code execution.
“This would allow them to gain complete control over the GOautodial application on the server, steal the data from fellow employees and customers, and even rewrite the application to introduce malicious behavior such as stealing passwords or spoofing communications (sending messages or emails that look like they come from someone else),” warned CyRC.
Vulnerable versions of the GOautodial API are those created prior to September 27, 2021, including the latest publicly available ISO installer, GOautodial-4-x86_64-Final-20191010-0150.iso.
Scott Tolley, a researcher from the Synopsys Cybersecurity Research Center, discovered the vulnerabilities using the interactive application security testing (IAST) tool Seeker, which automatically tests for security vulnerabilities during the software development life cycle (SDLC).
Tolley’s initial disclosure of the vulnerabilities to GOautodial took place on September 22. The company responded on October 20, saying that the vulnerabilities had been fixed.
Synopsys validated the fix by November 17, then published its advisory regarding the vulnerabilities earlier today.
Other vulnerabilities discovered by keen bug-hunter Tolley include CVE-2021-33177, CVE-2021-33178, and CVE-2021-33179, which are SQL injection, path traversal, and XSS vulnerabilities in the popular application, service, and network monitoring software Nagios XI.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Just 3% of UK Firms Escaped a Supply Chain Breach in 2021
Just 3% of UK Firms Escaped a Supply Chain Breach in 2021

Some 97% of UK organizations suffered a supply chain breach over the past year, up from 82% in 2020 and the second highest figure globally, according to BlueVoyant.
The security firm polled 1200 C-level executives with responsibility for managing risk in supply chains, across the UK, US, Singapore, Canada, Germany and the Netherlands.
UK firms also experienced a higher-than-average percentage of breaches: 59% suffered between two and five supply chain incidents compared to an overall average of 49%. The average number of breaches in the country grew from 2.64 in 2020 to 3.57 in 2021.
Perhaps unsurprisingly given these figures, only a quarter (27%) of UK respondents said they consider third-party cyber risk a key priority versus a 42% global average.
This is despite the fact that budgets are on the rise: 92% said third-party cyber risk management funds are increasing in 2021, up from 87% in 2020.
The figures are increasingly concerning as supply chains expand, driving up complexity and creating potential visibility and control gaps. The number of companies reporting supply chains with more than 1000 partners rose from 8% in 2020 to 43% in 2021 — meaning the average vendor ecosystem in the UK now contains 3715 third parties, up from 1013 in 2020.
Two-fifths (39%) of British firms said they’ve no way of knowing if a cyber risk emerges in a third-party vendor, up from 34% in 2020.
BlueVoyant UK president, James Tamblin, argued that as firms were forced to find new suppliers during the pandemic, they may have taken their eye off the ball regarding cyber risk management.
“I would have expected firms to be focusing urgently on addressing third-party cyber risk, especially bearing in mind that almost all the UK firms surveyed have experienced a breach via their supply chain. This should be sounding alarm bells and prompting immediate action,” he added.
“With supply chains stretched to the breaking point by the pandemic, many UK firms have had to diversify suppliers to build resilience, which could also be limiting visibility.”
The one area where UK companies fared better than those in other countries related to how frequently they reassess vendors and brief the executive team on the results.
The percentage monitoring weekly rose from just 4% in 2020 to 12% in 2021, while over a third (35%) are assessing monthly, a rise of 6% on last year.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Ransomware Victims Pay $700K in Extra Extortion Fees
Ransomware Victims Pay $700K in Extra Extortion Fees

A staggering 96% of ransomware victims that agree to their extorters’ demands are subsequently forced to pay additional fees amounting to hundreds of thousands of dollars, according to CrowdStrike.
The security vendor’s 2021 CrowdStrike Global Security Attitude Survey was compiled from interviews with 2200 senior IT and cybersecurity decision makers in the US, EMEA and APAC.
It found that two-thirds (66%) of respondents had suffered at least one ransomware attack over the past year, with average payments increasing 63% over the year. They were lowest on average in EMEA ($1.3m), followed by the US ($1.6m), and highest in APAC ($2.4m).
The average demand from ransomware groups was $6m. CrowdStrike claimed the gulf between this figure and what victims end up paying is due to organizations getting better at negotiating and understanding their risk exposure.
However, threat actors are seeking to recoup funds in other ways — most notably in extorting the same victims more than once for the same attack. The report claimed that on average these extra payments cost victims $792,493.
“One of the biggest mistakes that a company that falls victim to a ransomware attack can do, is believe that paying the ransom will make all your problems disappear,” CrowdStrike’s EMEA CTO, Zeki Turedi, told Infosecurity.
“What most organizations are completely unaware of, is that not only paying the ransom will more than likely result in another attack in the future, it leaves them in the situation of still needing to fully recover from a catastrophic event as well as further fuelling the cyber-criminal system.”
Turedi claimed organizations would be better off spending money on improving protective measures.
However, here too the report found widespread failures. On average, respondents estimated it would take 146 hours to detect a cybersecurity incident, up from 117 hours in 2020.
Once detected, it takes organizations a further 11 hours to triage, investigate and understand a security incident and 16 hours to contain and remediate one.
Some 69% of respondents said they suffered an incident because of staff working remotely.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains