—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Friday Squid Blogging: Bigfin Squid Captured on Video
“Eerie video captures elusive, alien-like squid gliding in the Gulf of Mexico.”
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
New Rowhammer Technique
Rowhammer is an attack technique involving accessing — that’s “hammering” — rows of bits in memory, millions of times per second, with the intent of causing bits in neighboring rows to flip. This is a side-channel attack, and the result can be all sorts of mayhem.
Well, there is a new enhancement:
All previous Rowhammer attacks have hammered rows with uniform patterns, such as single-sided, double-sided, or n-sided. In all three cases, these “aggressor” rows — meaning those that cause bitflips in nearby “victim” rows — are accessed the same number of times.
Research published on Monday presented a new Rowhammer technique. It uses non-uniform patterns that access two or more aggressor rows with different frequencies. The result: all 40 of the randomly selected DIMMs in a test pool experienced bitflips, up from 13 out of 42 chips tested in previous work from the same researchers.
[…]
The non-uniform patterns work against Target Row Refresh. Abbreviated as TRR, the mitigation works differently from vendor to vendor but generally tracks the number of times a row is accessed and recharges neighboring victim rows when there are signs of abuse. The neutering of this defense puts further pressure on chipmakers to mitigate a class of attacks that many people thought more recent types of memory chips were resistant to.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
The ‘Zelle Fraud’ Scam: How it Works, How to Fight Back
One of the more common ways cybercriminals cash out access to bank accounts involves draining the victim’s funds via Zelle, a “peer-to-peer” (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family. Naturally, a great deal of phishing schemes that precede these bank account takeovers begin with a spoofed text message from the target’s bank warning about a suspicious Zelle transfer. What follows is a deep dive into how this increasingly clever Zelle fraud scam typically works, and what victims can do about it.
Last week’s story warned that scammers are blasting out text messages about suspicious bank transfers as a pretext for immediately calling and scamming anyone who responds via text. Here’s what one of those scam messages looks like:

Anyone who responds “yes,” “no” or at all will very soon after receive a phone call from a scammer pretending to be from the financial institution’s fraud department. The caller’s number will be spoofed so that it appears to be coming from the victim’s bank.
To “verify the identity” of the customer, the fraudster asks for their online banking username, and then tells the customer to read back a passcode sent via text or email. In reality, the fraudster initiates a transaction — such as the “forgot password” feature on the financial institution’s site — which is what generates the authentication passcode delivered to the member.
Ken Otsuka is a senior risk consultant at CUNA Mutual Group, an insurance company that provides financial services to credit unions. Otsuka said a phone fraudster typically will say something like, “Before I get into the details, I need to verify that I’m speaking to the right person. What’s your username?”
“In the background, they’re using the username with the forgot password feature, and that’s going to generate one of these two-factor authentication passcodes,” Otsuka said. “Then the fraudster will say, ‘I’m going to send you the password and you’re going to read it back to me over the phone.’”
The fraudster then uses the code to complete the password reset process, and then changes the victim’s online banking password. The fraudster then uses Zelle to transfer the victim’s funds to others.
An important aspect of this scam is that the fraudsters never even need to know or phish the victim’s password. By sharing their username and reading back the one-time code sent to them via email, the victim is allowing the fraudster to reset their online banking password.
Otsuka said in far too many account takeover cases, the victim has never even heard of Zelle, nor did they realize they could move money that way.
“The thing is, many credit unions offer it by default as part of online banking,” Otsuka said. “Members don’t have to request to use Zelle. It’s just there, and with a lot of members targeted in these scams, although they’d legitimately enrolled in online banking, they’d never used Zelle before.” [Curious if your financial institution uses Zelle? Check out their partner list here].
Otsuka said credit unions offering other peer-to-peer banking products have also been targeted, but that fraudsters prefer to target Zelle due to the speed of the payments.
“The fraud losses can escalate quickly due to the sheer number of members that can be targeted on a single day over the course of consecutive days,” Otsuka said.
To combat this scam Zelle introduced out-of-band authentication with transaction details. This involves sending the member a text containing the details of a Zelle transfer – payee and dollar amount – that is initiated by the member. The member must authorize the transfer by replying to the text.
Unfortunately, Otsuka said, the scammers are defeating this layered security control as well.
“The fraudsters follow the same tactics except they may keep the members on the phone after getting their username and 2-step authentication passcode to login to the accounts,” he said. “The fraudster tells the member they will receive a text containing details of a Zelle transfer and the member must authorize the transaction under the guise that it is for reversing the fraudulent debit card transaction(s).”
In this scenario, the fraudster actually enters a Zelle transfer that triggers the following text to the member, which the member is asked to authorize: For example:
“Send $200 Zelle payment to Boris Badenov? Reply YES to send, NO to cancel. ABC Credit Union . STOP to end all messages.”
“My team has consulted with several credit unions that rolled Zelle out or our planning to introduce Zelle,” Otsuka said. “We found that several credit unions were hit with the scam the same month they rolled it out.”
The upshot of all this is that many financial institutions will claim they’re not required to reimburse the customer for financial losses related to these voice phishing schemes. Bob Sullivan, a veteran journalist who writes about fraud and consumer issues, says in many cases banks are giving customers incorrect and self-serving opinions after the thefts.
“Consumers — many who never ever realized they had a Zelle account – then call their banks, expecting they’ll be covered by credit-card-like protections, only to face disappointment and in some cases, financial ruin,” Sullivan wrote in a recent Substack post. “Consumers who suffer unauthorized transactions are entitled to Regulation E protection, and banks are required to refund the stolen money. This isn’t a controversial opinion, and it was recently affirmed by the CFPB here. If you are reading this story and fighting with your bank, start by providing that link to the financial institution.”
“If a criminal initiates a Zelle transfer — even if the criminal manipulates a victim into sharing login credentials — that fraud is covered by Regulation E, and banks should restore the stolen funds,” Sullivan said. “If a consumer initiates the transfer under false pretenses, the case for redress is more weak.”
Sullivan notes that the Consumer Financial Protection Bureau (CFPB) recently announced it was conducting a probe into companies operating payments systems in the United States, with a special focus on platforms that offer fast, person-to-person payments.
“Consumers expect certain assurances when dealing with companies that move their money,” the CFPB said in its Oct. 21 notice. “They expect to be protected from fraud and payments made in error, for their data and privacy to be protected and not shared without their consent, to have responsive customer service, and to be treated equally under relevant law. The orders seek to understand the robustness with which payment platforms prioritize consumer protection under law.”
Anyone interested in letting the CFPB know about a fraud scam that abused a P2P payment platform like Zelle, Cashapp, or Venmo, for example, should send an email describing the incident to BigTechPaymentsInquiry@cfpb.gov. Be sure to include Docket No. CFPB-2021-0017 in the subject line of the message.
In the meantime, remember the mantra: Hang up, Look Up, and Call Back. If you receive a call from someone warning about fraud, hang up. If you believe the call might be legitimate, look up the number of the organization supposedly calling you, and call them back.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
North Korean Cyber-criminal Recycles Tactics and Targets
North Korean Cyber-criminal Recycles Tactics and Targets

A threat actor believed to be associated with the Democratic People’s Republic of Korea (DPRK) has a certain fondness for repetition, according to new research published today.
In the report Triple Threat: North Korea–Aligned TA406 Scams, Spies, and Steals, researchers at Proofpoint shine a light on the nefarious activity of the threat actor TA406, whose campaigns they have been tracking since 2018.
“What’s most notable about this North Korea–aligned threat actor is their penchant for reusing the same tactics and targeting the same individuals over and over again,” said Sherrod DeGrippo, vice president of threat research and detection at Proofpoint.
“They also have used everything from sextortion to legitimate services in the name of financial gain.”
Proofpoint’s research team believe TA406 to be one of several actors responsible for cyber-criminal activity publicly tracked as the Kimsuky, Thallium, and Konni Group.
The researchers also have “high confidence” that TA406 is operating on behalf of the North Korean government.
TA406 has been conducting espionage-motivated campaigns since at least 2012 and financially motivated campaigns since at least 2018.
Until January 2021, TA406 campaigns have remained low in volume. However, with the start of the year, the threat actor ramped up their activity to include almost weekly campaigns targeting foreign policy experts, journalists, and non-governmental organizations (NGOs).
While TA406 has been observed using many different malware families, including KONNI , SANNY, CARROTBAT/CARROTBALL, BabyShark, Amadey and Android Moez, this threat actor isn’t known primarily for campaigns that employ malware.
However, researchers attributed to TA406 two campaigns run in 2021 that tried to distribute malware for the purposes of gathering information.
Despite being a professional cyber-criminal, TA406 was observed to follow a standard working day schedule, sending malicious phishing emails out from 9am to 5pm, with the occasional additional late-night session.
Describing TA406’s targets, researchers wrote: “Generally, TA406 phishing campaigns focus on individuals in North America, Russia, and China, with the actors frequently masquerading as Russian diplomats and academics, representatives of the Ministry of Foreign Affairs of the Russian Federation, human rights officials, or Korean individuals.
“TA406 has also targeted individuals and organizations related to crypto-currency for the purpose of financial gain.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Man Charged with Impersonating Female Minnesota Student Online
Man Charged with Impersonating Female Minnesota Student Online

A man from the People’s Republic of China has been charged in connection with the cyberstalking of a female college student in America.
Acting United States Attorney Charles J. Kovats announced on Wednesday that a federal complaint has been filed against Ki Cheung Yau, a Chinese national living in Los Angeles.
Yau, who is 27 years old, is accused of impersonating, harassing, and cyberstalking a woman who is studying at a college in Minnesota.
According to court documents, Yau’s alleged stalking campaign began back in January 2020 and continued through until the present.
It is alleged that Yau used the victim’s name, photographs, and personally identifying information to create a slew of online accounts. Yau allegedly created these accounts on various websites, including social media sites, online dating platforms, and pornography websites.
As detailed in the complaint, Yau allegedly used these fraudulent accounts to pose as the victim online. It is alleged that while impersonating the victim, Yau communicated with others, seeking out sexual relationships and advertising invitations to engage in violent sexual acts.
According to a statement released Wednesday by the United States Attorney’s Office for the District of Minnesota, several internet users were apparently taken in by the fake online profiles allegedly created and worked by Yau.
The statement said that “on two separate occasions in January 2021, a man went to the victim’s residence and asked for the victim by name, presumably because he believed he was meeting the victim for a sexual encounter.”
It wasn’t until February 2021 that the victim made the terrifying discovery that multiple fake online profiles had been created using her name and her likeness. Sites on which the fraudulent profiles were hosted included Facebook, Instagram, and other sites focused on dating or sex.
“As a result of Yau’s stalking and harassment, the victim has received numerous contacts from men she does not know and has been forced to move to a new residence and change her phone number,” stated the US Attorney’s Office for the District of Minnesota.
Following an investigation by the FBI and St. Paul Police Department, Yau has been charged with one count of cyberstalking.
“Using dating and other explicit sites to threaten, harass, and defame a victim is not new. What is rare is that any enforcement action is ever taken,” John Bambenek, principal threat hunter at Netenrich told Infosecurity Magazine.
He added: “Most victims just end up dealing with the shame, embarrassment, and trauma of dealing with this.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Overworked CISOs are Skipping Family Vacations and Holidays
Overworked CISOs are Skipping Family Vacations and Holidays

Chief information security officers (CISOs) are missing medical appointments and family vacations because their workload is so heavy, according to new research by security company Tessian.
In September, Tessian used third-party survey company Censuswide to ask 300 CISOs in the United Kingdom and United States about their working habits.
Researchers found that a quarter of CISOs had not taken any time off work in the past 12 months and 40% had missed a family vacation due to work. Two out of every five CISOs reported missing out on a national or federal holiday like Thanksgiving because they had to work.
CISOs aren’t just spending more days at work; they are also putting in longer hours. Tessian’s Lost Hours report reveals that CISOs work, on average, 11 more hours than they’re contracted to each week while, one in ten works 20 to 24 hours extra a week.
Working so much is having an impact on CISOs’ health, with only 60% saying that they had enough time to exercise regularly. Nearly half (44%) of the CISOs surveyed said they had missed a doctor’s appointment because they were so busy at work.
Many CISOs (59%) said that they can’t always switch off from work after their working day is over.
Asked how their time is spent, 38% of CISOs said they’re spending too much time in departmental meetings and reporting to the board on cybersecurity, while one-third reported feeling drained by administrative tasks.
Further research, commissioned by Tessian and conducted by Forrester in September, asked 317 security strategy decision makers at organizations in the UK and the US about their working lives.
It revealed that security teams spend up to 600 hours per month investigating and remediating threats caused by human error.
“As security leaders, some of our most exciting stories include pulling all-nighters to defend the organization or investigate a threat. However, we often fail to acknowledge that the need for heroics usually indicate a failure condition and are not sustainable,” said Josh Yavor, Tessian’s CISO.
“Like any job function, CISOs have their limits and need to advocate for themselves and time constraints to avoid burnout.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
#IRISSCON: Understanding the Reality of Cyber Threats to Improve Defenses
#IRISSCON: Understanding the Reality of Cyber Threats to Improve Defenses

Understanding the true nature of cyber-threats is critical in enabling organizations to protect themselves, according to Ciaran Martin, Founding CEO of the National Cyber Security Centre and Professor, University of Oxford.
During a session at IRISSCON 2021, Martin said it is important to be more realistic about the true threat cyber-attacks pose to society. For example, he had recently re-watched the classic movie WarGames, which “set a tone about the catastrophization of cybersecurity in a way that just doesn’t match reality.” In WarGames a hacker could set off a nuclear war, and Martin commented: “nothing remotely like this has ever actually happened” in the 38 years since it was released.
In reality, the vast majority of threats are “small scale,” impacting individual organizations. Martin then set out the three main categories of cyber-threats:
1. Getting Robbed
- Cash theft – this can range from scamming individuals online to large-scale bank heists
- IP theft
- Data theft
2. Getting Weakened
- Espionage – this normally involves nation-states accessing and stealing confidential data about governments and major organizations. A recent example of this is the SolarWinds attack in 2020.
- Political interference – this encompasses a range of tactics, including hacking to ferment political discourse and leaking data about political figures e.g., Hillary Clinton in the 2016 Presidential election.
- Prepositioning – this is where threat actors intrude into key systems, ‘implanting’ themselves on a network. Martin said this often occurs during times of peace, ensuring that should tensions escalate between nation-states, there is the capability to undertake espionage activities or launch attacks.
3. Getting Hurt
- Destructive – this is where cyber-attacks cause physical damage to organizations. This might be reckless and accidental, such as Wannacry in 2017, and deliberate, as seen in the NotPetya attack in 2017.
- Ransomware – Martin noted the reason ransomware has come to the attention of mainstream media is due to the physical damage these types of attacks have caused recently. For example, the recent disruption to food and fuel supplies in the US.
Board members and decision-makers should use this categorization to understand “where in this matrix is your organization? Is it a data-rich organization? Or is there a piece of IT that is strategically significant in the political system?” according to Martin.
Reducing Harm
Martin believes there is currently not enough recognition of the limitations of law enforcement in respect of cybersecurity. “We need to understand that because it limits what we can do.” This is largely because major cybercrime gangs operate from regions like Russia, China and the Subcontinent, where it is almost impossible to get traditional law enforcement mechanisms to work. Martin added: “For the first time in human history, you’re able to cause large-scale harm to a society without ever setting foot in it.”
Given this reality, the focus needs to be on defense, and Martin outlined four areas of priority:
1. Importance of basics – Martin noted that “every major incident, even the most sophisticated ones, at least part of the story, there’s some element of basic vulnerability.” Therefore, the vast majority of incidents would be prevented by basic steps, like patching and enforcing multi-factor authentication.
2. Resilience – this relates to preparation for incidents and the way systems are built. “We don’t want to be in the position where we have to rely on the heroics of people,” commented Martin. He highlighted the Colonial Pipeline ransomware attack as a key example of lack of preparedness. He pointed out the incident emerged as a result of an attack on the enterprise rather than the pipeline itself, which did not have sufficient isolation measures. “This really shouldn’t be happening – we need to design security into the systems,” he added.
3. Conversations with boards – security professionals need to ensure boards understand the reality of harm from cyber-attacks. This includes providing them with technical insights they so often lack to ensure security basics are followed. For example, “educate them about counter-phishing strategies, about how to interpret the ethical phishing stats,” said Martin.
4. Protect the digital environment – Martin stated: “I strongly believe we shouldn’t be talking about cybersecurity in militaristic terms.” Instead, it should be seen as an environment which everyone needs to live in. Therefore, it requires a clean-up, such as taking more steps to take down maliciously-hosted websites. This is especially pertinent with the growth in areas like IoT, AI and quantum. He added: “Look at the technology that’s coming and clean up the digital environment.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
#IRISSCON: Security Industry Should Change the Rhetoric Around Cyber-Threats
#IRISSCON: Security Industry Should Change the Rhetoric Around Cyber-Threats

Governments and security vendors should represent cyber-threats differently, cutting down on hyperbole and overly dramatic language. This was the message from Dr Victoria Baines, visiting research fellow at Oxford University, speaking during IRISCON 2021.
Baines began by discussing her book, Rhetoric of Insecurity, which analyzed the rhetoric and messaging around cybercrime. In this research, she observed that governments, vendors and cyber-criminals frequently use similar approaches when describing cyber-threats to the general public. “What shocked me when I looked at cyber was that criminals, governments and vendors have a tendency to represent cyber-threats in exactly the same way – which is kind of weird when you think about it!”
These revolve around panic-inducing language to gain attention, tapping into emotions like fear and anxiety. Baines gave the example of how the FBI describes cyber-threats, where words like ‘devastating,’ ‘insidious’ and ‘catastrophe’ are used. She noted these words “literally refer to large-scale physical disruption,” which is often misleading.
Additionally, governments, cyber-criminals and vendors tend to make the threat seem immediate, inducing quick actions. For example, cyber-criminals often use phrases like ‘you must click now’ to entice people to click on phishing emails, or a ransomware pop-up screen will say ‘you need to pay us now.’ With vendors, phrases like ‘secure your everything’ are commonly invoked to encourage the purchasing of their product.
Baines also highlighted the kind of imagery that is used in respect of cybercrime. These include faceless hackers, crime scene photos, padlocks and cascading zeros and code. In Baines ‘ view, this serves to make the issue remote from people who see it as too complex to try and understand. This creates the perception that “you are powerless; there is absolutely nothing you can do about it.”
An advertisement from a cybersecurity vendor was then read out to the audience. This advert portrayed cybersecurity professionals as superheroes, protecting the public from the forces of ‘darkness.’ Baines said this is not helpful for security professionals, as it places unrealistic expectations on their shoulders, including by board members. “We know those expectations are unreasonable and are having harmful effects on the people in the industry,” she outlined. This includes potentially contributing to mental health issues like stress and burnout.
Amid the ongoing COVID-19 crisis, Baines also pleaded for the industry to avoid the temptation to exploit this situation to induce fear in the public and sell products. She highlighted a recent report entitled ‘Preparing for the Next Global Crisis – A Cyber Pandemic,’ an unsuitable and inaccurate analogy. “All this does is get people to buy things,” added Baines.
However, she does believe lessons from the pandemic can be used to strengthen cybersecurity throughout society. This revolves around the public health approach of invoking a sense of community and sacrifice; in COVID-19, this was staying at home to protect the elderly and vulnerable. In the cyber realm, this can translate to adopting more secure behaviors to help protect the digital world at large. “Rather than harnessing people’s fear, we can harness people’s sense of civic and community responsibility,” stated Baines.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
China’s APT41 Manages Library of Breached Certificates
China’s APT41 Manages Library of Breached Certificates

A freelance Chinese APT group is actively managing a library of compromised code-signing digital certificates to support cyber-espionage attacks targeting supply chain vendors, according to Venafi.
The security vendor’s latest research report details the work of APT41, an unusual group in that it has previously been observed carrying out attacks for both traditional state-sponsored cyber-espionage and personal financial gain.
Venafi claimed that using the certificates and keys that authenticate pieces of code are a key part of its tactics.
APT41 is reportedly managing a library of these certs and keys – some purchased from underground marketplaces, some obtained from other Chinese attack groups and some stolen by APT41 itself.
This shared resource allows members of the group to select the appropriate certificate for their needs, “dramatically” improving success rates, according to Venafi.
These attacks, conducted in support of China’s long-term economic, military and political goals – are often directed at the digital supply chain, allowing easy compromise of downstream customers.
“Code-signing machine identities allow malicious code to appear authentic and evade security controls. The success of attacks using this model over the past decade has created a blueprint for sophisticated attacks that have been highly successful because they are very difficult to detect,” explained Venafi threat intelligence specialist Yana Blachman.
“Since targeting the Windows software utility CCleaner in 2018 and Asus LiveUpdate in 2019, APT41’s methods continue to improve. Every software provider should be aware of this threat and take steps to protect their software development environments.”
Once the targeted downstream organization is compromised via secondary malware, APT41 then moves laterally across networks, using stolen credentials and reconnaissance tools to steal IP and customer data, the report claimed.
APT41 was responsible for one of the most widespread Chinese cyber campaigns of recent years when it exploited Citrix and Zoho endpoints at scores of global organizations across multiple verticals.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains