—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Attackers Will Flock to Crypto Wallets, Linux in 2022: Podcast
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Common Cloud Misconfigurations Exploited in Minutes, Report
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Teen Accused of Stealing Bitcoin Worth $36.5M
Teen Accused of Stealing Bitcoin Worth $36.5M

The largest theft of Bitcoin from a single individual was allegedly perpetrated by a Canadian teenager.
An unnamed youth was arrested last week on suspicion of stealing crypto-currency worth approximately $36.5m from an unnamed victim who is located in the United States.
It is alleged that the defendant used a SIM swapping attack to gain access to the victim’s cell phone, then used that access to drain the funds contained in the victim’s digital wallet.
In March of 2020, Hamilton Police entered into a joint investigation with the Federal Bureau of Investigation and the United States Secret Service Electronic Crimes Task Force.
“The victim had been targeted by a SIM swap attack, a method of hijacking valuable accounts by manipulating cellular network employees to duplicate phone numbers so threat actors can intercept two-factor authorization requests,” said the Hamilton Police in a statement released November 17.
“As a result of the SIM swap attack, approximately $46 million CAD worth of cryptocurrency was stolen from the victim.”
Hamilton Police added that “this is currently the biggest crypto-currency theft reported from one person.”
Investigators linked the defendant to the crime after the teenager allegedly used some of their criminal proceeds to make a purchase online.
“The joint investigation revealed that some of the stolen crypto-currency was used to purchase an online username that was considered to be rare in the gaming community,” stated Hamilton Police.
“This transaction led investigators to uncover the account holder of the rare username.”
Police would not reveal the age of the alleged thief, nor the valuable username allegedly purchased with the stolen crypto-currency.
The teenager was arrested last Wednesday for the theft of over $5,000 and possession of property or proceeds of property obtained by crime. Hamilton Police made multiple crypto-currency seizures valued at more than $7m CAD (approximately $5.5m).
The matter is now before the Canadian courts. Hamilton Police are asking anyone with information about this crime to contact Hamilton Police Service Detective Constable Kenneth Kirkpatrick or call the charity Crime Stoppers of Hamilton.
“The amount, of course, is very surprising,” said Kirkpatrick in an interview with CBC.
“That’s a large amount of money, and it’s a large amount of money in anybody’s opinion.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
GoDaddy Announces Data Breach
GoDaddy Announces Data Breach

Data belonging to up to 1.2 million WordPress customers has been exposed in a security incident at GoDaddy.
The domain registrar web-hosting company said on Monday that an unauthorized third party had gained access to its systems by exploiting a compromised password. The intrusion began in September but wasn’t detected until last week.
GoDaddy has hired an IT forensics firm to investigate the incident. While that investigation remains ongoing, cybersecurity specialists have determined that the unauthorized third party gained access to email addresses and customer numbers belonging to Managed WordPress customers with active or inactive accounts.
In a November 22 filing regarding the data incident, GoDaddy’s chief information security officer, Demetrius Comes, wrote that “the exposure of email addresses presents risk of phishing attacks.”
GoDaddy said that original WordPress admin passwords that were set at the time of provisioning were exposed.
“If those credentials were still in use, we reset those passwords,” said Comes in the filing.
GoDaddy also reset active WordPress customers’ passwords for the Secure File Transfer Protocol (SFTP) and database, after the usernames and passwords for both were exposed in the security incident.
The details of SSL (Secure Sockets Layer) private keys belonging to an unspecified number of active customers were also exposed to the unauthorized third party. The company is currently in the process of issuing and installing new certificates for those customers.
Once the incident was discovered, the intruder was blocked from the system. The investigation into the incident found that the unauthorized third party had been able to access WordPress customers’ data since September 6.
“On November 17, 2021, we discovered unauthorized third-party access to our Managed WordPress hosting environment,” wrote Comes.
“We identified suspicious activity in our Managed WordPress hosting environment and immediately began an investigation with the help of an IT forensics firm and contacted law enforcement. Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress.”
Comes added that the company intends to learn from the incident and is taking steps to further protect its system.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Online Payment Fraud Surges by 208% Ahead of Black Friday
Online Payment Fraud Surges by 208% Ahead of Black Friday

Online payment fraud surged by 208% between September and October 2021, indicating that scammers are ramping up attacks on online shoppers in the build-up to this year’s Black Friday.
In a new report, cybersecurity vendor Kaspersky discovered 1,935,905 financial phishing attacks disguised as e-payment systems in October 2021. This is more than double the 627,560 attacks detected in the previous month.
Interestingly, the researchers didn’t observe any seasonal trends for other types of phishing related to online shopping in the first 10 months of 2021. The emphasis on e-payment systems is believed to be linked to the introduction of new payment systems in many countries this year following the shift to online shopping during COVID-19.
The team also detected 221,745 spam emails containing the words ‘Black Friday’ from October 27 to November 19, providing further evidence that fraudsters are trying to take advantage of the biggest shopping day of the year.
In total, Kaspersky reported seeing 40 million phishing attacks targeting e-commerce and e-shopping platforms from January to October 2021.
Of the online shopping platforms, Amazon was consistently the most popular phishing lure used by scammers. Next was eBay, followed by Alibaba and Mercado Libre.
Tatyana Shcherbakova, security expert at Kaspersky, commented: “We always witness intensified scamming activity amid the Black Friday season. Perhaps a bit more unexpected is the attention being paid to e-payment systems. This time, we discovered a huge increase of 208% in the number of attacks mimicking the most popular payment systems. Of course, every new payment application is seen by scammers as a new opportunity to potentially exploit users.
“So, in order to protect your data and finances, it will be a safe practice to make sure the online payment page is secure: you’ll know it is if the web page’s URL begins with HTTPS instead of the usual HTTP and an icon of a lock will also typically appear beside the URL.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Hackers Exploit ProxyLogon and ProxyShell Bugs in Phishing Blitz
Hackers Exploit ProxyLogon and ProxyShell Bugs in Phishing Blitz

Security researchers have warned attackers are abusing months-old Microsoft Exchange Server flaws to send convincing malware-laden phishing emails within organizations.
A team at Trend Micro spotted the campaign, which exploits the ProxyLogon and ProxyShell vulnerabilities patched by Microsoft in March and May respectively.
By doing so, attackers are able to compromise a victim organization’s on-premises Exchange server, and then send phishing emails to other inboxes in the same organization — disguised as legitimate replies to existing email threads.
As real account names from the victim’s domain are used, there’s more chance these emails will be opened by the recipients.
“Delivering the malicious spam using this technique to reach all the internal domain users will decrease the possibility of detecting or stopping the attack, as the mail getaways will not be able to filter or quarantine any of these internal emails,” Trend Micro explained.
“The attacker also did not drop or use tools for lateral movement after gaining access to the vulnerable Exchange servers, so that no suspicious network activities will be detected. Additionally, no malware was executed on the Exchange servers that will trigger any alerts before the malicious email is spread across the environment.”
The phishing emails in question use attached Excel and Word files featuring malicious macros. These execute a malicious script and download a DLL loader which connects to a C&C server associated with the Squirrelwaffle loader. The final payload is either Cobalt Strike or the Qbot backdoor, according to the report.
Organizations were urged to patch the ProxyLogon and ProxyShell bugs, and use endpoint detection and response (EDR) solutions to detect any suspicious behavior on their servers.
Trend Micro also trumpeted virtual patching technology, which protects vulnerable systems from known and unknown threats until security teams have a chance to apply official updates.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
SEC Warning as Phishing and Vishing Attacks Mount
SEC Warning as Phishing and Vishing Attacks Mount

The Securities and Exchange Commission (SEC) has warned of a new multi-channel phishing campaign designed to elicit personal and financial information from victims.
An investor alert from the regulator revealed that several people have come forward claiming to have received phone calls or voicemail messages from purported SEC staff.
The scammers apparently raised concerns about suspicious activity on the recipients’ checking or cryptocurrency accounts in a bid to trick them into handing over more sensitive info — a classic phishing tactic.
“These phone calls and voicemail messages are in no way connected to the SEC. If you receive a communication that appears to be from the SEC, do not provide any personal information unless you have verified that you are dealing with the SEC,” the regulator urged.
“The SEC does not seek money from any person or entity as a penalty or disgorgement for alleged wrongdoing outside of its formal enforcement process.”
The SEC extended the warning to any form of unsolicited communication, including emails and letters, claiming it will never ask for payments related to enforcement actions, offer to confirm trades, or seek detailed personal and financial information.
Nor will SEC staff ask for details on shareholdings, account numbers, PINs, passwords, or other information, it clarified.
Scammers appear to be using an expanding array of tactics to increase their chances of success.
“Con artists have used the names of real SEC employees and email messages that falsely appear to be from the SEC to trick victims into sending the fraudsters money. Impersonation of US government agencies and employees (as well as of legitimate financial services entities) is one common feature of advance fee solicitations and other fraudulent schemes,” it continued.
“Even where the fraudsters do not request that funds be sent directly to them, they may use personal information they obtain to steal an individual’s identity or misappropriate their financial assets.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Wind Turbine Giant Offline After Cyber Incident
Wind Turbine Giant Offline After Cyber Incident

The world’s largest manufacturer of wind turbines was forced to shut down IT systems across several locations over the weekend after a cybersecurity incident.
In a brief notice on Saturday, Vestas Wind Systems claimed the attack struck the day before, with IT services in multiple business units affected.
At the time, the Danish firm said that customers, employees and other stakeholders could be affected by the incident, and that it was working with internal and external partners to contain and recover.
An update on Monday morning warned that data had been compromised.
“However, there is no indication that the incident has impacted third party operations, including customer and supply chain operations,” it added.
“Vestas’s manufacturing, construction and service teams have been able to continue operations, although several operational IT systems have been shut down as a precaution. Vestas has already initiated a gradual and controlled reopening of all IT systems.”
Although not confirmed by Vestas, a ransomware attack would appear to be the front-runner in terms of likely cause. The turbine giant reported revenues of nearly €15bn in 2020, making it a potentially lucrative target.
High gas prices across Europe and a relatively poor year for wind production is also ratcheting up the pressure on providers of renewables.
Vestas claimed that its investigation is ongoing as the firm tries to “re-establish the integrity of its systems.”
Ransomware attacks surged by an astonishing 485% year-on-year in 2020, according to one report.
There could be yet more for security teams to worry about on this front as they head into winter, with new research claiming that the Conti group likely drove the restart of Emotet.
This could recreate a formidable and prolific source of high quality initial access for ransomware groups.
“Emotet’s return is not coincidental, it is caused by major shifts in the overall cybercrime domain,” argued AdvIntel.
“The growing monopolization of the ransomware world, which is rapidly conquered by only a few highly-organized criminal corporations, leads to better opportunities for criminal ventures like the Emotet botnet developers.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Black Friday and Cyber Monday – here’s what you REALLY need to do!
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains