—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Apple’s NSO Group Lawsuit Amps Up Pressure on Pegasus Spyware-Maker
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Attackers Actively Target Windows Installer Zero-Day
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Apple Sues NSO Group
Piling more on NSO Group’s legal troubles, Apple is suing it:
The complaint provides new information on how NSO Group infected victims’ devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices.
NSO Group’s Pegasus spyware is favored by totalitarian governments around the world, who use it to hack Apple phones and computers.
More news:
Apple’s legal complaint provides new information on NSO Group’s FORCEDENTRY, an exploit for a now-patched vulnerability previously used to break into a victim’s Apple device and install the latest version of NSO Group’s spyware product, Pegasus. The exploit was originally identified by the Citizen Lab, a research group at the University of Toronto.
The spyware was used to attack a small number of Apple users worldwide with dangerous malware and spyware. Apple’s lawsuit seeks to ban NSO Group from further harming individuals by using Apple’s products and services. The lawsuit also seeks redress for NSO Group’s flagrant violations of US federal and state law, arising out of its efforts to target and attack Apple and its users.
NSO Group and its clients devote the immense resources and capabilities of nation-states to conduct highly targeted cyberattacks, allowing them to access the microphone, camera, and other sensitive data on Apple and Android devices. To deliver FORCEDENTRY to Apple devices, attackers created Apple IDs to send malicious data to a victim’s device — allowing NSO Group or its clients to deliver and install Pegasus spyware without a victim’s knowledge. Though misused to deliver FORCEDENTRY, Apple servers were not hacked or compromised in the attacks.
This follows in the footsteps of Facebook, which is also suing NSO Group and demanding a similar prohibition. And while the idea of the intermediary suing the attacker, and not the victim, is somewhat novel, I think it makes a lot of sense. I have a law journal article about to be published with Jon Penney on the Facebook case.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
My email has been hacked! What should I do next?
If you find that your email has been hacked, one of your immediate reactions is wondering what you should next.
The answer: take a deep breath and jump into action. There are five steps can help you prevent or minimize any damage done by a compromised account.
So why do hackers go after email accounts? Fact is, that email account of yours is a treasure trove. There’s a good chance it contains years of correspondence with friends and family, along with yet more email from banks, online retailers, doctors, contractors, business contacts, and more. In all, your email packs a high volume of personal info in one place, which makes your email account a top prize for hackers.
Let’s take a look at how you can take back control of your email account, along with some things you can do to keep it from getting hacked in the first place.
You can’t log into your email account:
This one speaks for itself. You go to check your email and find that your username and password combination has been rejected. You try again, knowing you’re using the right password, and still no luck. There’s a chance that a hacker has gotten a hold of your password, logged in, and then changed the password—thus locking you out and giving them control of your account.
One of your contacts asks, “Did this email really come from you?”
Hackers often compromise email accounts to spread malware on a large scale. By blasting emails to everyone on your hacked contact list, they can reach dozens, even hundreds, of others with a bogus email that may include an attachment that’s infected with malware. And no doubt about it, some of those emails can look a little odd. They don’t sound or read at all like the person they’re trying to impersonate—you—to the extent that some of your contacts may ask if this email really came from you.
On the flip side, this is a good reason to never open attachments you weren’t expecting. Likewise, if you get a somewhat strange email from a friend or business contact, let them know. You may be the first indication they get that their email has been compromised.
Slow and erratic device performance:
A sluggish device could be a sign of malware in general. The thing with malware is that it tends to act like a system and resource hog, which may cause your device to run slowly, to turn off and on again suddenly, or even run hot. In some cases, the malware is logging keystrokes on your computer or taps on your phone to siphon off things like usernames and passwords so that a hacker can take control of the accounts associated with them—such as your email, not to mention your bank accounts. This makes a strong case for antivirus and antimalware protection that’s automatically kept up to date to protect against the latest threats.
What should I do if my email is hacked?
1) Change your passwords:
Change your password for your email account if you can. Make it a strong, unique password—don’t reuse a password from another account. Next, update the passwords for other accounts if you use the same or similar passwords for them. (Hackers count on people using simpler and less unique passwords across their accounts—and on people reusing passwords in general.) A password manager that’s included with comprehensive online protection software can do that work for you.
2) Use your email provider’s recovery service, if needed:
In the case where you’ve been locked out of your account because you think the hacker has changed the password, your email provider should have a webpage dedicated to recovering your account in the event of a lost or stolen password. (For example, Google provides this page for users of Gmail and their other services.) This is a good reason to keep your security questions and alternate contact information current with your provider, as this is the primary way to regain control of your account.
3) Reach out to your email contacts:
As mentioned above, a big part of the hacker’s strategy is to get their hooks into your address book and spread malware to others. As quickly as you can, send a message to all your email contacts and let them know that your email has been compromised. And if you’ve done so, let them know that you’ve reset your password so that your account is secure again. Likewise alert them that they shouldn’t open any emails or attachments from you that were sent during the time your account was compromised.
4) Scan your device for malware and viruses:
Also as mentioned above, there are several ways that a hacker can get a hold of your email account information—one of them by using malware. Give your device a thorough virus scan with comprehensive online protection software to ensure your device is free from malware. Set up a regular scan to run automatically if you haven’t already. That will help keep things clean in the long run.
5) Check your other accounts:
Sometimes one bad hack leads to another. If someone has access to your email and all the messages in it, they may have what they need to conduct further attacks. Take a look at your other accounts across banking, finances, social media, and other services you use and keep an eye out for any unusual activity.
The bigger picture: Keep tabs on your identity
More broadly speaking, your email account is one of the several pieces that make up the big picture of your online identity. Other important pieces include your online banking accounts, online shopping accounts, and so on. No question about it, these are things you want to keep tabs on.
With that, check your credit report for any signs of strange activity. Your credit report is a powerful tool for spotting identity theft. And in many cases, it’s free to do so. In the U.S., the Fair Credit Reporting Act (FCRA) requires the major credit agencies to provide you with a free credit check at least once every 12 months. Canada provides this service, and the UK has options to receive free reports as well, along with several other nations. It’s a great idea to check your credit report, even if you don’t suspect a problem.
Beyond keeping tabs on your identity, you can protect it as well. Online identity protection such as ours can provide around-the-clock monitoring of your email addresses and bank accounts with up to $1M of ID theft insurance in the event your identity gets compromised. Additionally, it can put an identity recovery pro on the case if you need assistance in the wake of an attack or breach. Taking a step like this can help keep your email account safer from attack in the first place—along with many others as well.
The post My email has been hacked! What should I do next? appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
81% of UK Retailers Leaving Customers at Risk of Email Fraud Ahead of #BlackFriday
81% of UK Retailers Leaving Customers at Risk of Email Fraud Ahead of #BlackFriday

More than four-fifths (81%) of UK retailers are putting their customers at risk of email fraud by not implementing the recommended level of domain-based message authentication, reporting and conformance (DMARC) protection.
This is according to a new study by Proofpoint, which warned of a likely surge in fraudulent emails targeting online shoppers ahead of this year’s Black Friday and Cyber Monday.
DMARC is an email authentication, policy and reporting protocol designed to improve and monitor protection of the domain from fraudulent emails. Yet worryingly, ahead of the Black Friday and Christmas shopping periods, Proofpoint said just 19% of UK retailers have adopted the recommended level of DMARC protection (reject), which blocks fraudulent emails from reaching their intended targets.
The research also showed that under half (45%) of UK retailers have implemented the minimum level of DMARC protection, which prevents malicious actors from spoofing their domain. This is significantly lower than the proportion of global retailers (70%) included in the Forbes Global 2000 who have implemented this level of DMARC protection. Additionally, more than a third (36%) of UK retailers have no published DMARC record at all, leaving themselves wide open to impersonation attacks.
Email has become an increasingly important means by which retailers contact customers about offers amid the shift to e-commerce during COVID-19, and fraudsters have heavily exploited this trend.
Adenike Cosgrove, cybersecurity strategist, International, Proofpoint, commented: “Organizations in all sectors should look to deploy authentication protocols, such as DMARC, to shore up their email fraud defenses. Cyber-criminals will always leverage key events to drive targeted attacks using social engineering techniques such as impersonation and will capitalize on a time when guards are down and attentions are focused on grabbing seasonal bargains. Ahead of Black Friday, shoppers must be vigilant in checking the validity of all emails, and retailers must do better to ensure their customers remain safe online.”
Yesterday, Kaspersky released new research, which found online payment fraud surged by 208% between September and October 2021, further highlighting the threats facing online shoppers.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Over a Fifth of UK Cyber Workers Experience Discrimination
Over a Fifth of UK Cyber Workers Experience Discrimination

The UK’s cybersecurity sector appears to be faring pretty well in terms of its diversity, but challenges around inclusion, career progression and discrimination persist, according to a new government report.
The second annual Decrypting Diversity report from the National Cyber Security Centre (NCSC) was compiled from interviews with 945 professionals working in the industry.
The headline figures are encouraging: over a third (36%) of respondents were female, which is a higher proportion than in some studies, and 10% were from the LGB community, which the report claimed is higher than the 2.2% of the population that is LGB according to 2018 ONS data.
A quarter identified as having a disability, more than the 14% of the IT workforce as a whole and the 20% figure for the UK’s working population. The report also claimed that the statistics for ethnic minorities (15%) and trans and non-binary (1%) respondents were in line with those of the national population.
However, there are still clear areas where improvement is necessary. For example, only one in 20 respondents were aged 18-24, just 3% entered via a school leaver or apprenticeship scheme, and 12% via a graduate scheme. The NCSC said increasing these figures needs to be a priority.
More concerning is that over a fifth (22%) of respondents said they’ve experienced discrimination in the past year, up from 16% in 2020. In addition, the number claiming to have experienced a career barrier due to one of their characteristics also surged, from 14% last year to 25%.
The NCSC claimed these figures might have been influenced by this year’s survey asking about a broader set of characteristics.
However, it’s also true that women, those from ethnic minority backgrounds, and those who are lesbian or gay experienced higher-than-average levels of discrimination. Women and ethnic minority respondents were also more likely to have experienced career roadblocks.
Another key stat – the degree to which individuals feel included, accepted and treated equally at work – didn’t move from last year. That means over a fifth (22%) of respondents feel they can’t be themselves at work.
Diversity and inclusion (D&I) is one of the four key pillars of the UK Cyber Security Council, commissioned by the government in 2019.
CEO Simon Hepburn said the council would play its part in helping to drive positive change.
“The sector must succeed at this. It’s vital not just to help the sector fill the tens of thousands of vacancies that exist, but for the sector and the UK to benefit from the wider range of abilities, improved creativity, different thinking and alternative contributions of a truly diverse, inclusive cybersecurity workforce,” he added.
“The council and the NCSC are in lockstep over the D&I objectives for the sector and, to that end, we also welcome and agree with the conclusions of the report.”
The report’s six recommendations include: better use of data to monitor and improve the “talent lifecycle;” learning from D&I best practice; publicizing success stories; and ensuring roles and skills are described consistently and made clear and accessible to all.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Over 4000 UK Retailers Compromised by Magecart Attacks
Over 4000 UK Retailers Compromised by Magecart Attacks

UK government security experts have been forced to notify over 4000 domestic online businesses that their websites were infected with digital skimming code.
GCHQ agency, the National Cyber Security Centre (NCSC), informed 4151 compromised online shops up to the end of September. Most of these were exploited via a known bug in the popular Magento e-commerce software.
The NCSC argued it was particularly important that digital retailers get their house in order ahead of the busy festive shopping period, which begins at the end of this week with the Black Friday weekend.
“We want small and medium-sized online retailers to know how to prevent their sites being exploited by opportunistic cyber-criminals over the peak shopping period. Falling victim to cybercrime could leave you and your customers out of pocket and cause reputational damage,” said NCSC deputy director for economy and society, Sarah Lyons.
“It’s important to keep websites as secure as possible and I would urge all business owners to follow our guidance and make sure their software is up-to-date.”
The compromised sites were found by the NCSC’s highly successful Active Cyber Defence program, which proactively looks to remove malicious sites and tackle scams before they can impact large numbers of consumers.
It resulted in the take-down of 2.3 million cyber-enabled “commodity campaigns” last year, including hundreds of phishing campaigns using NHS branding and scores of malicious apps.
The NCSC’s actions highlight the continued threat from digital skimming groups such as those filed under the umbrella term “Magecart.”
These groups struck global targets frequently in 2019 and 2020, but little activity has been reported this year. In September 2020, for example, around 2000 stores running Magento were attacked in a single weekend, the most extensive recorded campaign of its kind until that moment.
The British Retail Consortium has developed a Cyber Resilience Toolkit for retailers in partnership with the NCSC
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
More Ransomware Attacks Up to September Than Whole of 2020
More Ransomware Attacks Up to September Than Whole of 2020

Most UK business leaders expect cyber-threats to surge next year, with ransomware, business email compromise (BEC), cloud and supply chain attacks all predicted to increase, according to PwC.
The findings come from the consulting giant’s 2022 Global Digital Trust Insights Survey and were distilled from interviews with 257 business and technology executives in the UK.
Although most (63%) respondents said they expect security budgets to increase next year, even more (66%) predicted cyber-threats would rise. Ransomware (61%), BEC (61%), malware via software updates (63%), and cloud compromise (64%) were among the most notable.
Bobbie Ramsden-Knowles, crisis and resilience partner at PwC UK, claimed the firm’s threat intelligence team has tracked more ransomware incidents globally up to September this year than for the whole of 2020.
“Whereas other types of crises may be perceived as ‘black swan’ events that cannot be predicted, ransomware attacks have become so widespread that we have seen a common set of challenges and decisions that all organizations would face,” he added.
“Developing – and aligning – ransomware playbooks for executive crisis teams and operational responders is a no-regrets move. And, testing these through war games and exercises can reduce uncertainty, build confidence in the ability to respond and help prioritize focus on preventative measures.”
Part of the challenge for executives appears to be mitigating cyber risk stemming from the growing complexity of environments. Some 86% of UK respondents cited this as a concern, especially in the context of multi-vendor cloud and other platforms.
Just two-fifths claimed to have formally assessed their cloud (41%) and supply chain (42%) risks.
Of equal concern is that, despite increased spending, few respondents are confident that they can drive a good return on their investments.
“For example, while 37% of UK respondents said they had implemented cloud security at scale, just 18% are fully realizing the benefits of their investment. The remainder either weren’t investing in this area or hadn’t yet implemented it at scale,” explained PwC UK cybersecurity chair Richard Horne.
“To overcome this challenge and build greater confidence in their security investments, organizations must improve their cyber risk modeling and analysis. This ensures increases in cyber budgets are allocated to priority risks and help build long-term resilience.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cisco Flaw Affects Firewalls
Cisco Flaw Affects Firewalls

A newly discovered vulnerability found in two devices made by Cisco could cause remote access to be disrupted.
The flaw – CVE-2021-34704 – was detected by Positive Technologies researcher Nikita Abramov in October in the firewalls of Cisco ASA (Adaptive Security Appliance) and Cisco FTD (Firepower Threat Defense).
If the vulnerability is exploited, the organization’s firewall will be weakened, leaving it more vulnerable to attack, and employees who are working remotely would be blocked from accessing their organization’s internal network.
According to Abramov, an attacker does not require elevated privileges or special access to exploit the flaw. All it takes is the formation of a simple request, in which one of the parts is of a different size than that expected by the device.
Further parsing of the request will trigger a buffer overflow/overrun as the amount of data in the buffer exceeds its storage capacity. The impacted system will then shut down abruptly and restart.
Abramov said: “If hackers disrupt the operation of Cisco ASA and Cisco FTD, a company will be left without a firewall and remote access (VPN). If the attack is successful, remote employees or partners will not be able to access the internal network of the organization, and access from the outside will be restricted. At the same time, firewall failure will reduce the protection of the company.”
Describing the impact such an outcome could have on an organization. Abramov said: “All this can negatively impact company processes, disrupt interactions between departments, and make the company vulnerable to targeted attacks.”
According to Forrester Research, Cisco is an enterprise firewall market leader that has deployed more than 1 million security appliances around the globe.
An assessment of the flaw determined it to be of high severity with a CVSSv3.0 score of 8.6. A fix for the flaw has been created and users are advised to follow the manufacturer’s recommendations outlined in its security advisory and install updates as soon as possible.
Positive Technologies has previously discovered vulnerabilities in Cisco Firepower Device Manager (FDM) On-Box and critical flaws in Cisco ASA, such as CVE-2020-3187, CVE-2020-3259, and CVE-2020-3452.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains