Marylander Found Guilty of Skiptracing

Marylander Found Guilty of Skiptracing

A man from Maryland has been convicted of selling place of employment information (POE) illegally obtained from workforce agencies in multiple states.

Guy Cuomo of Frederick was found guilty on Monday of being a member of a fraud and identity theft scheme that profited from a practice known as ‘skiptracing.’

Under the process, information is gathered on a debtor’s last known place of employment and sold to debt collectors. 

Cuomo, 54, worked for and managed companies owned by 42-year-old Jason “J.R.” Trowbridge in Frederick, Maryland, including Paymerica Corporation.

Posing as debtors, Cuomo and five co-conspirators at Paymerica systemically created unemployment insurance accounts in multiple state workforce agencies’ computer systems using the social security numbers and other personally identifying data belonging to their unknowing victims. 

After confirming the employers that the debtors had worked for, Paymerica sold this information to debt collectors for approximately $90 per debtor. 

Paymerica made nearly $1m selling the stolen POE information for as many as 12,000 people from 40 states over approximately three years. 

Evidence presented at trial showed that attempts had been made to unlawfully obtain the POE for up to 200,000 debtors from all 50 states.

“Guy Cuomo and his co-conspirators ran a boiler room for identity theft,” said United States attorney Carla Freedman, “They used personal identifying information to trick state workforce agencies into disclosing the last known places of employment for thousands of victims.”  

Cuomo, Trowbridge, and the other conspirators tried to cover up their illegal activity by using Virtual Private Networks to mask the Internet Protocol addresses used to access and fill out the unemployment insurance applications in the debtors’ names.  

Cuomo was charged in June 2019. Following a five-day trial, a jury convicted Cuomo on Monday of computer fraud, misuse of a social security number, aggravated identity theft and additional related conspiracy charges. Cuomo could receive a maximum prison term of 22 years when he is sentenced on March 16, 2022.

For his part in the conspiracy, Trowbridge agreed to a sentence of 39 months, which is pending approval by the court. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Introduces New Cybersecurity Legislation for IoT Devices

UK Introduces New Cybersecurity Legislation for IoT Devices

The UK government has today introduced new legislation to Parliament that aims to better protect consumers’ IoT devices from hackers.

The Product Security and Telecommunications Infrastructure (PSTI) Bill places new cybersecurity standards on manufacturers, importers and distributors of internet-connectable devices, such as phones, tablets, smart TVs and fitness trackers. The legislation will also apply to products that can connect to multiple other devices but not directly to the internet, like smart light bulbs and smart thermostats.

These requirements include banning universal default passwords, forcing firms to be transparent about actions they are taking to fix security flaws in their products and creating a better public reporting system for any vulnerabilities discovered. In addition, these companies will have a duty to investigate compliance failures, produce statements of compliance and maintain appropriate records of this.

Failure to comply could result in heavy fines issued by a new regulator – up to £10m of 4% of their global turnover, as well as up to £20,000 a day in the case of an ongoing contravention. The regulator will also be given the power to require firms to comply with the security requirements, recall their products or stop selling or supplying them altogether. The legislation is further bolstered by the fact ministers will be able to mandate further security requirements as new threats emerge.

The legislation comes amid the surging use of IoT devices, with an average of nine in every UK household. Unsurprisingly, these devices have become increasingly targeted by cyber-criminals in recent years. For example, earlier this year, Which? published an investigation demonstrating that smart homes could face more than 12,000 cyber-attacks in a single week.

Minister for Media, Data and Digital Infrastructure, Julia Lopez, commented: “Everyday hackers attempt to break into people’s smart devices. Most of us assume if a product is for sale, it’s safe and secure. Yet many are not, putting too many of us at risk of fraud and theft.

“Our Bill will put a firewall around everyday tech from phones and thermostats to dishwashers, baby monitors and doorbells, and see huge fines for those who fall foul of tough new security standards.”

Dr Ian Levy, NCSC technical director, stated: “I am delighted by the introduction of this bill which will ensure the security of connected consumer devices and hold device manufacturers to account for upholding basic cybersecurity.

“The requirements this bill introduces – which were developed jointly by DCMS and the NCSC with industry consultation – mark the start of the journey to ensure that connected devices on the market meet a security standard that’s recognized as good practice.”

Commenting on the new legislation, Gerhard Zehethofer, vice President, IoT & manufacturing at ForgeRock, said: “This is a positive step from the UK government. IoT has been talked about for years as a truly transformative technology, but adoption has been slower than expected. In 2012, it was predicted there would be a trillion connected devices globally by 2020, now the predictions are for just 36 billion.

“Overcoming the real security concerns surrounding IoT will be critical to unlocking growth, and IoT-specific regulations such as this one have a major role to play. Common-sense fixes like the banning of default passwords and incentivizing manufacturers to keep on top of security updates and vulnerabilities will help protect consumers and their data, building the trust that the IoT market needs to achieve its full potential.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CISA Issues Holiday Ransomware Message

CISA Issues Holiday Ransomware Message

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are warning Americans not to take a break from cybersecurity this holiday season.

In a joint alert issued Monday, the agencies urged the public and private sector organizations to “remain vigilant and take appropriate precautions to reduce their risk to ransomware and other cyberattacks” ahead of Thanksgiving.

The warning was not triggered by receiving any specific threat intelligence but was born instead from knowing what has come to pass. 

“This advisory is based on observations on the timing of high impact ransomware attacks that have occurred previously rather than a reaction to specific threat reporting,” said the agencies. 

“Specifically, malicious cyber actors have often taken advantage of holidays and weekends to disrupt critical networks and systems belonging to organizations, businesses, and critical infrastructure.” 

The agencies said that data gathered in 2021 showed cyber actors launching “serious and impactful ransomware attacks during holidays and weekends, including Independence Day and Mother’s Day weekends”.

A paper chain of recommended mitigations accompanied the call for caution. First, entities were advised to select and identify the IT security employees to provide weekend and holiday cover in the event of a ransomware attack. 

Other advice included:

  • Implementing multi-factor authentication for remote access and administrative accounts.
  • Mandating strong passwords.
  • Training employees not to click on suspicious links.

Attack techniques the agencies specifically warned against included phishing scams in which threat actors pose as charities and fraudulent sites spoofing genuine businesses to target holiday shoppers. 

“The FBI is dedicated to combatting cyber-crimes targeting the American public and our private sector partners. Cyber-criminals have historically viewed holidays as attractive times to strike,” said FBI Cyber assistant director Bryan Vorndran. 

“We will continue to provide cyber threat information and share best safeguard practices. We urge network defenders to prepare and remain alert over the upcoming holiday weekend and report any suspicious activity to www.ic3.gov.”

CISA Director Jen Easterly said: “While we are not currently aware of a specific threat, we know that threat actors don’t take holidays.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Most US Healthcare Apps Susceptible to Cyber-Attack

Most US Healthcare Apps Susceptible to Cyber-Attack

Vulnerabilities exist in most of the web applications used by leading healthcare providers in the United States, according to new research by cyber assessment company Outpost24.

In its new 2021 Web Application Security for Pharma and Healthcare report, the company shared the finding that 90% of the web applications used by the US healthcare operators are susceptible to cyber-attacks.

The report assessed the internet-exposed applications of the top 20 largest pharma and healthcare organizations in the European Union and in the US to identify common attack vectors and exploitable flaws. 

Researchers found that 85% of the top 20 pharma and healthcare applications had an external attack surface score of 30 or above out of 58.24. Outpost24 classified such a score as ‘critically exposed,’ indicating a “high susceptibility for security and vulnerability exposure.”

Healthcare organizations in the United States were found to be more at risk than their European counterparts. While US organizations had an average risk exposure score of 40.5, the score for healthcare organizations in the EU was 32.79.

A quarter of the web applications run by healthcare organizations in the US presented a cybersecurity risk. Out of a total 6069 web applications run over 2197 domains, 3% were considered as “suspect” by researchers and a further 23.74% were found to be running on vulnerable components.

Although EU healthcare organizations run almost four times as many web applications as those in the US, the percentage of apps deemed to be risky was lower in the EU than in the US.  

Of the 20,394 web applications run by EU healthcare organizations over 9216 domains, 3.3% were considered to be suspect and 18.3% were running on vulnerable components.

The researchers found that the top three attack vectors identified across healthcare organizations in the EU and the US to be Degree of Distribution, Page Creation Method and Active Content.

Outpost24 security researcher Nicolas Renard said: “It’s paramount the healthcare organizations carry out the necessary due diligence to continuously evaluate their internet exposed security perimeter given the highly sensitive information stored.”

He urged organizations to “take a proactive stance to identify and mitigate potential security issues before critical care can be impacted.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Malicious JavaScript Loader is a Multi-RAT Dispenser

Malicious JavaScript Loader is a Multi-RAT Dispenser

Researchers are warning of a new JavaScript loader being used to distribute eight Remote Access Trojans (RATs) in information-stealing campaigns.

A team at HP Wolf named the tool “RATDispenser,” and warned that it currently has a detection rate of only 11%.

“As with most attacks involving JavaScript malware, RATDispenser is used to gain an initial foothold on a system before launching secondary malware that establishes control over the compromised device,” explained HP malware analyst, Patrick Schläpfer.

“Interestingly, our investigation found that RATDispenser is predominantly being used as a dropper in 94% of samples analyzed, meaning the malware doesn’t communicate over the network to deliver a malicious payload.”

RATDispenser arrives as a malicious attachment in a phishing email. If the user double clicks, it will run, at which time the obfuscated JavaScript decodes itself and writes a VBScript file to a temporary folder using cmd.exe.

This VBScript file then downloads the malware payload and, if successful, will subsequently delete itself.

The eight malware families include: keylogger and info-stealer Formbook; Java RAT STRRAT, which has remote access, credential stealing and keylogging features; downloader GuLoader; and an open source Java RAT known as Ratty.

According to Schläpfer, the most interesting payload is Panda Stealer.

“First seen in April 2021, this is a new malware family that targets cryptocurrency wallets,” he explained. “The Panda Stealer sample we analyzed were all fileless variants that download additional payloads from a text storage site, paste.ee.”

Panda Stealer and Formbook are always downloaded rather than dropped, but they’re in the minority in terms of the payloads associated with RATDispenser.

“The variety in malware families, many of which can be purchased or downloaded freely from underground marketplaces, and the preference of malware operators to drop their payloads, suggest that the authors of RATDispenser may be operating under a malware-as-a-service business model,” said Schläpfer.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Multiple Bugs Enable Eavesdropping on 37% of Android Phones

Multiple Bugs Enable Eavesdropping on 37% of Android Phones

Security researchers have revealed new vulnerabilities in a popular Android chip which could have allowed threat actors to snoop on the audio of nearly two-fifths (37%) of the world’s smartphones.

CVE-2021-0661, CVE-2021-0662 and CVE-2021-0663 were fixed by Taiwanese microchip company MediaTek in its October bulletin after responsible disclosure by Check Point Research. A fourth issue, CVE-2021-0673, was fixed in October and will be published in the December bulletin.

The Check Point team said it reverse engineered one of the key components on the chip, the audio digital signal processor (DSP), which is deployed to reduce CPU usage and improve media performance.

The bugs in question could be exploited if the user downloads a malicious app.

That app would theoretically then leverage the MediaTek API to attack a library with permissions to talk to the audio driver. As the app has system privileges it would then be able to send crafted messages to the driver to execute code into the firmware of the audio DSP, said Check Point.

This would enable remote attackers to eavesdrop on audio conversations.

MediaTek’s chip is the main processor for “nearly every notable Android device,” including several Chinese manufacturers including Xiaomi, Oppo, Realme and Vivo, according to Check Point.

“Left unpatched, a hacker potentially could have exploited the vulnerabilities to listen in on conversations of Android users. Furthermore, the security flaws could have been misused by the device manufacturers themselves to create a massive eavesdrop campaign,” warned Check Point security researcher, Slava Makkaveev.

“Although we do not see any specific evidence of such misuse, we moved quickly to disclose our findings to MediaTek and Xiaomi.”

Tiger Hsu, product security officer at MediaTek, urged all users to update their handsets when patches become available, but was at pains to point out there’s no evidence the bugs are currently being exploited.

“Device security is a critical component and priority of all MediaTek platforms,” he added. “Regarding the audio DSP vulnerability disclosed by Check Point, we worked diligently to validate the issue and make appropriate mitigations available to all OEMs.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Standing Up to Cyber-Bullies Earns Man Award Nomination

Standing Up to Cyber-Bullies Earns Man Award Nomination

A British man who surmounted the detraction of his cyber-bullies and launched a campaign to raise awareness of cyber-bullying has been nominated for a national award.

Chris Holden, of Winsford, Cheshire, has been shortlisted for ‘Campaigner of the Year’ – one of 11 titles up for grabs in the annual awards run by national disability charity, Sense.

Holden, who is 37 years old and autistic, was so profoundly impacted by the actions of cyber-bullies that he attempted to end his life. But, after connecting with the mental health group Rainbow After The Storm, he learned the coping skills he needed to bounce back from his cyberbullying experience confidently. 

Holden, who is now the group’s anti-bullying ambassador, has been working hard to help other victims of cyber-bullying.

“It’s amazing that I have been shortlisted for this amazing prize,” said Holden. 

“As a young man with autism, who nearly lost my life due to bullying online, I now spend my time talking openly about my experiences of cyberbullying and hoping that I can make a change for others in that situation.”

Holden came to the attention of Sense after launching a nationwide campaign to raise awareness of cyber-bullying and its impact. 

Sense is a national disability charity that supports people living with complex disabilities, including those who are deaf-blind, to communicate and experience the world.

Sense chief executive, Richard Kramer, said: “No one should ever have to experience any bullying, but Chris has turned this experience into something positive that will help others.  

“We’re delighted to shortlist Chris as our’ Campaigner of the Year’ and wish him the greatest success in his work.”

The Sense Awards recognize the outstanding achievements of people with complex disabilities and the staff, carers, family members, volunteers and fundraisers who support them. 

The charity said that this year’s Sense Awards are the perfect opportunity to celebrate how people with complex disabilities have overcome the obstacles caused by the pandemic and thank the people who have supported them. 

The winners of the Sense Awards 2021 will be announced in an online ceremony on Thursday.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Apple Sues “State-Sponsored” Spyware Firm NSO Group

Apple Sues “State-Sponsored” Spyware Firm NSO Group

Apple has become the latest tech giant to sue Israeli spyware developer NSO Group, in a bid to hold it accountable for targeted attacks which compromised users’ devices.

The Cupertino-based firm said it was taking legal action “to prevent further abuse and harm” to users of its products and would be seeking a permanent injunction banning NSO Group from using its products and services.

Apple said that NSO Group used the ForcedEntry exploit for a now-patched iOS bug to install its Pegasus spyware on the devices of targeted journalists, activists, dissidents, academics and government officials.

“NSO Group and its clients devote the immense resources and capabilities of nation states to conduct highly targeted cyber-attacks, allowing them to access the microphone, camera, and other sensitive data on Apple and Android devices,” Apple claimed.

“To deliver ForcedEntry to Apple devices, attackers created Apple IDs to send malicious data to a victim’s device – allowing NSO Group or its clients to deliver and install Pegasus spyware without a victim’s knowledge. Though misused to deliver ForcedEntry, Apple servers were not hacked or compromised in the attacks.”

Interestingly, the Apple notice lays the blame for such attacks squarely at the feet of NSO Group itself and describes it as a “state-sponsored” actor.

The Herzliya-headquartered firm would, on the other hand, describe itself as a private enterprise which only sells software and services to government clients for legitimate law enforcement and intelligence purposes.

Apple follows Facebook in taking NSO Group to court. It started legal proceedings in 2019 after it emerged that malware developed by the Israeli firm was used to target over 1000 WhatsApp users. Facebook said that “attackers used servers and internet-hosting services that were previously associated with NSO.”

Apple’s legal action comes just weeks after NSO Group was added to a US export blacklist designed to prevent it from buying and using components from American companies.

In a brief statement, NSO Group said it was “dismayed” by that decision.

“We look forward to presenting the full information regarding how we have the world’s most rigorous compliance and human rights programs that are based the American values we deeply share, which already resulted in multiple terminations of contacts with government agencies that misused our products,” it claimed.

Apple said it will donate $10m and any damages it may win from the case to cyber-surveillance researchers like those at Citizen Lab and Amnesty Tech.

“The steps we’re taking today will send a clear message: in a free society, it is unacceptable to weaponize powerful state-sponsored spyware against those who seek to make the world a better place,” said Ivan Krstić, head of Apple security engineering and architecture.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

9.3M+ Androids Running ‘Malicious’ Games from Huawei AppGallery

A new trojan called Android.Cynos.7.origin, designed to collect Android users’ device data and phone numbers, was found in 190 games installed on over 9M Android devices.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains