—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Exchange, Fortinet Flaws Being Exploited by Iranian APT, CISA Warns
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Phishing Scam Aims to Hijack TikTok ‘Influencer’ Accounts
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Is Microsoft Stealing People’s Bookmarks?
I received email from two people who told me that Microsoft Edge enabled synching without warning or consent, which means that Microsoft sucked up all of their bookmarks. Of course they can turn synching off, but it’s too late.
Has this happened to anyone else, or was this user error of some sort? If this is real, can some reporter write about it?
(Not that “user error” is a good justification. Any system where making a simple mistake means that you’ve forever lost your privacy isn’t a good one. We see this same situation with sharing contact lists with apps on smartphones. Apps will repeatedly ask, and only need you to accidentally click “okay” once.)
EDITED TO ADD: It’s actually worse than I thought. Edge urges users to store passwords, ID numbers, and even passport numbers, all of which get uploaded to Microsoft by default when synch is enabled.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Can Thieves Steal Identities With Only a Name and Address?
Can thieves steal identities with only a name and address?
In short, the answer is “no.” Which is a good thing, as your name and address are in fact part of the public record. Anyone can get a hold of them. However, because they are public information, they are still tools that identity thieves can use.
If you think of your identity as a jigsaw puzzle, your name and address are the first two pieces that they can use to build a bigger picture and ultimately put your identity at risk.
With that, let’s look at some other key pieces of your identity that are associated with your name and address—and what you can do to protect them.
For starters, this information is so general that it is of little value in of itself to an identity thief. Yet a determined identity thief can do a bit of legwork and take a few extra steps to use them as a springboard for other scams. For example, with your name and address a thief could:
Research public databases for further pieces of information about you.
There are volumes of public information that are readily available should someone want to add some more pieces to your identity jigsaw puzzle, such as:
- How long you’ve lived in your current home, what you paid for it, and what it’s valued at today.
- If you’re a registered voter and if you voted in a recent election. (Not how you voted, though!)
- Also, if you’re a veteran or the owner of a cat or dog (through pet licenses).
In the U.S., the availability of such information will vary from state-to-state and different levels of government may have different regulations about what information gets filed—in addition to whether and how those reports are made public. Globally, different nations and regions will collect varying amounts of public information and have their own regulations in place as well. More broadly, though, many of these public databases are now online. Consequently, accessing them is easier than the days when getting a hold of that information required an in-person visit a library or public office.
Send you phishing attacks and scams by physical mail.
Phishing attacks aren’t just for email, texts, and direct messages. In fact, thieves are turning to old tricks via old-fashioned physical mail. That includes sending phony offers or by impersonating officials of government institutions, all designed to trick you into giving up your personally identifiable information (PII).
What might that look like in your mailbox? They can take the form of bogus lottery prizes that request bank information for routing (non-existent) winnings. Another favorite of scammers are bogus tax notifications that demand immediate payment. In all, many can look quite convincing at first blush, yet there are ready ways you can spot them. In fact, many of the tips for avoiding these physical mail phishing attacks are the same for avoiding phishing attacks online, which we outline in detail here.
Redirect your physical mail, essentially committing mail fraud.
Recently, I’ve seen a few news stories like this where thieves reportedly abuse the change-of-address system with the U.S. Postal Service. Thieves will simply forward your mail to an address of their choosing, which can drop sensitive information like bank and credit card statements in their mailbox. From there, they could potentially have new checks sent to them or perhaps an additional credit card—both of which they can use to drain your accounts and run up your bills.
The Postal Service has mechanisms in place to prevent this, however. Among which, the Postal Service will send you a physical piece of mail to confirm the forwarding. So, if you ever receive mail from the Postal Service, open it and give it a close look. If you get such a notice and didn’t order the forwarding, visit your local post office to get things straightened out. Likewise, if it seems like you’re missing bills in the mail, that’s another good reason to follow up with your post office and the business in question to see if there have been any changes made in your mail forwarding.
Protecting your good name (and identity too)
So while your name and address are out there for practically all to see, they’re largely of little value to an identity thief on their own. But as mentioned above, they are key puzzle pieces to your overall identity. With enough of those other pieces in hand, that’s where an identity thief can cause trouble. Other crucial pieces of your identity include:
Your Social Security Number or tax ID number:
Let’s start with the biggest one. This is the master key to your identity, as it is one of the most unique identifiers you have. As I covered in my earlier blog on Social Security fraud, a thief can unlock everything from credit history and credit line to tax refunds and medical care with your Social Security or tax ID number. In extreme cases, they can use it to impersonate you for employment, healthcare, and even in the event of an arrest.
You can protect your Social Security Number by keeping it locked in a safe place (rather than in your wallet) and by providing your number only when absolutely necessary. For more tips on keeping your number safe, drop by that blog on Social Security fraud I mentioned.
Your passport and driver’s license:
Thieves have figured out ways of getting around the fact that IDs like these include a photo. They may be able to modify or emulate these documents “well enough” to pull off certain types of fraud, particularly if the people requesting their bogus documents don’t review them with a critical eye.
Protecting yourself in this case means knowing where these documents are at any time. (With passports, you may want to store those securely like your Social Security or tax ID number.) Also be careful when you share this information, as the identifiers on these documents are highly unique. If you’re uncomfortable with sharing this information, you can ask if other forms of ID might work—or if this information is really needed at all. Also, take a moment to make copies of these documents and store them in a secure place. This can help you provide important info to the proper authorities if they’re lost or stolen.
Your card and account information:
With data breaches large and small making the news (and many more that do not), keeping a sharp eye on your accounts is a major part of identity theft prevention. We talk about this topic quite often, and it’s worth another mention because protecting these means protecting yourself from thieves who’re after direct access to your finances and more.
Secure your digital accounts for banking, credit cards, financials, and shopping by using strong, unique passwords for each of your accounts that you change every 60 days. Sound like a lot of work? Let a password manager do it for you, which you can find in comprehensive online protection software. By changing your strong passwords and keeping them unique can help prevent you from becoming a victim if your account information is part of a breach—by the time a crook attempts to use it, you may have changed it and made it out of date.
Extra steps for extra identity protection
In addition to protecting the core forms of identity mentioned above, a few other good habits go a long way toward keeping your identity secure.
1. Install and use online protection software: By protecting your devices, you protect what’s on them, like your personal information. Comprehensive online protection software can protect your identity in several ways, like create and manage the strong, unique passwords we talked about and provide further services that monitor and protect your identity—in addition to digital shredders that can permanently remove sensitive documents (simply deleting them won’t do that alone.)
2. Shred your stuff: Identity theft where thieves dig through trash or go “dumpster diving” for literal scraps of personal info in bills and statements, has been an issue for some time. You can prevent it by shredding up any paper medical bills, tax documents, and checks once you’re through with them. Paper shredders are inexpensive, and let’s face it, kind of fun too. Also, if you’re traveling, have a trusted someone collect your mail or have the post office put a temporary hold on your mail. Thieves still poach mail from mailboxes too.
3. Go paperless: Getting statements online cuts the paper out of the equation and thus removes another thing that a thief can physically steal and possibly use against you. Whether you use electronic statements through your bank, credit card company, medical provider, or insurance company, use a secure password and a secure connection provided by a VPN. Both will make theft of your personal info far tougher on identity thieves.
4. Use a VPN: A VPN is a Virtual Private Network, a service that protects your data and privacy online. It creates an encrypted tunnel to keep you anonymous, by masking your IP address, while connecting to public Wi-Fi hotspots. This is a great way to shield your information from crooks and snoops while you’re banking, shopping, or handling any kind of sensitive information online.
5. Monitor your accounts: Give your statements a close look each time they come around. While many companies and institutions have fraud detection mechanisms in place, they don’t always catch every instance of fraud. Look out for strange purchases or charges and follow up with your bank or credit card company if you suspect fraud. Even the smallest charge could be a sign that something shady is afoot.
6. Check your credit report: This is a powerful tool for spotting identity theft. And in many cases, it’s free to do so. In the U.S., the Fair Credit Reporting Act (FCRA) requires the major credit agencies to provide you with a free credit check at least once every 12 months. Canada provides this service, and the UK has options to receive free reports as well, along with several other nations. It’s a great idea to check your credit report, even if you don’t suspect a problem.
Your name and address are just two pieces of a larger puzzle
While thieves need more than just your name and address to commit the overwhelming majority of fraud, your name and address are centerpieces of the larger jigsaw puzzle that is your overall identity.
And the interesting thing is your puzzle gets larger and larger as time goes on. With each new account you create and service that you sign into, that’s one more piece added to the puzzle. Thieves love getting their hands on any pieces they can because with enough of them in place they can try and pull a fast one in your name. By looking after each piece and knowing what your larger jigsaw puzzle looks like, you can help keep identity thieves out of your business and your life.
The post Can Thieves Steal Identities With Only a Name and Address? appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Tech CEO Pleads to Wire Fraud in IP Address Scheme
The CEO of a South Carolina technology firm has pleaded guilty to 20 counts of wire fraud in connection with an elaborate network of phony companies set up to obtain more than 735,000 Internet Protocol (IP) addresses from the nonprofit organization that leases the digital real estate to entities in North America.

In 2018, the American Registry for Internet Numbers (ARIN), which oversees IP addresses assigned to entities in the U.S., Canada, and parts of the Caribbean, notified Charleston, S.C. based Micfo LLC that it intended to revoke 735,000 addresses.
ARIN said they wanted the addresses back because the company and its owner — 38-year-old Amir Golestan — had obtained them under false pretenses. A global shortage of IPv4 addresses has massively driven up the price of these resources over the years: At the time of this dispute, a single IP address could fetch between $15 and $25 on the open market.
Micfo responded by suing ARIN to try to stop the IP address seizure. Ultimately, ARIN and Micfo settled the dispute in arbitration, with Micfo returning most of the addresses that it hadn’t already sold.
But the legal tussle caught the attention of South Carolina U.S. Attorney Sherri Lydon, who in May 2019 filed criminal wire fraud charges against Golestan, alleging he’d orchestrated a network of shell companies and fake identities to prevent ARIN from knowing the addresses were all going to the same buyer.
Each of those shell companies involved the production of notarized affidavits in the names of people who didn’t exist. As a result, Lydon was able to charge Golestan with 20 counts of wire fraud — one for each payment made by the phony companies that bought the IP addresses from ARIN.
Amir Golestan, CEO of Micfo.
On Nov. 16, just two days into his trial, Golestan changed his “not guilty” plea, agreeing to plead guilty to all 20 wire fraud charges. KrebsOnSecurity interviewed Golestan about his case at length last year, but he has not responded to requests for comment on his plea change.
By 2013, a number of Micfo’s customers had landed on the radar of Spamhaus, a group that many network operators rely upon to help block junk email. But shortly after Spamhaus began blocking Micfo’s IP address ranges, Micfo shifted gears and began reselling IP addresses mainly to companies marketing “virtual private networking” or VPN services that help customers hide their real IP addresses online.
But in a 2020 interview, Golestan told KrebsOnSecurity that Micfo was at one point responsible for brokering roughly 40 percent of the IP addresses used by the world’s largest VPN providers. Throughout that conversation, Golestan maintained his innocence, even as he explained that the creation of the phony companies was necessary to prevent entities like Spamhaus from interfering with his business going forward.
Stephen Ryan, an attorney representing ARIN, said Golestan changed his plea after the court heard from a former Micfo employee and public notary who described being instructed by Golestan to knowingly certify false documents.
“Her testimony made him appear bullying and unsavory,” Ryan said. “Because it turned out he had also sued her to try to prevent her from disclosing the actions he’d directed.”
Golestan’s rather sparse plea agreement (first reported by The Wall Street Journal) does not specify any sort of leniency he might gain from prosecutors for agreeing to end the trial prematurely. But it’s worth noting that a conviction on a single act of wire fraud can result in fines and up to 20 years in prison.
The courtroom drama comes as ARIN’s counterpart in Africa is embroiled in a similar, albeit much larger dispute over millions of wayward African IP addresses. In July 2021, the African Network Information Centre (AFRINIC) confiscated more than six million IP addresses from Cloud Innovation, a company incorporated in the African offshore entity haven of Seychelles (pronounced, quite aptly — “say shells”).

AFRINIC revoked the addresses — valued at around USD $120 million — after an internal review found that most of them were being used outside of Africa by various entities in China and Hong Kong. Like ARIN, AFRINIC’s policies require those who are leasing IP addresses to demonstrate that the addresses are being used by entities within their geographic region.
But just weeks later, Cloud Innovation convinced a judge in AFRINIC’s home country of Mauritius to freeze $50 million in AFRINIC bank accounts, arguing that AFRINIC had “acted in bad faith and upon frivolous grounds to tarnish the reputation of Cloud Innovation,” and that it was obligated to protect its customers from disruption of service.
That financial freeze has since been partially lifted, but the legal wrangling between AFRINIC and Cloud Innovation continues. The company’s CEO is also suing the CEO and board chair of AFRINIC in an $80 million defamation case.
Ron Guilmette is a security researcher who spent several years tracing how tens of millions of dollars worth of AFRINIC IP addresses were privately sold to address brokers by a former AFRINIC executive. Guilmette said Golestan’s guilty plea is a positive sign for AFRINIC, ARIN and the three other Regional Internet Registries (RIRs).
“It’s good news for the rule of law,” Guilmette said. “It has implications for the AFRINIC case because it reaffirms the authority of all RIRs, including AFRINIC and ARIN.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Emotet is Rebuilding its Botnet
Emotet is Rebuilding its Botnet

Cybersecurity professionals are unsurprised by the apparent return of Emotet malware.
First discovered as a banking trojan in 2014, the malware evolved into a powerful tool deployed by cyber-criminals around the world to illegally access computer systems.
The malware’s creators — APT group TA542 — hired Emotet out to other cyber-criminals, who used it to install malware, such as banking trojans or ransomware, onto victims’ computers.
Emotet’s botnet infrastructure was dismantled in January as part of a coordinated action by authorities in Canada, France, Germany, Lithuania, the Netherlands, the United Kingdom, the United States, and Ukraine.
Europol, which coordinated the global takedown action along with Eurojust, said Emotet was the “world’s most dangerous malware,” and its creators “managed to take email as an attack vector to a next level.”
Now, a team of researchers from Cryptolaemus, G DATA, and AdvIntel have reported observing the TrickBot trojan launching what appears to be a new loader for Emotet.
In a blog post, Luca Ebach said that internal processing had identified a Dynamic Link Library (DLL) that TrickBot tried to download as Emotet.
An initial manual verification gave the researchers “high confidence that the samples indeed seem to be a re-incarnation of the infamous Emotet.” The team is now carrying out in-depth analyses in search of a more definitive result.
“Emotet is back again on the scene and, to be fair, we’re not surprised,” said Stefano De Blasi, cyber-threat intelligence analyst at Digital Shadows.
He added: “The new variant of the infamous malware reportedly follows a similar path of delivering both malicious Office or ZIP files, in addition to other command-and-control (C2) payloads.”
De Blasi predicted that many cyber-criminal groups could return to using Emotet over the next few months.
Erich Kron, security awareness advocate at KnowBe4, commented: “It is no surprise to see malware as successful and widespread as Emotet finding its way back on the cybercrime scene, however, it will take some time to build up to its previous size.”
He predicted: “Unfortunately, we can expect to see these infected devices used to increase the spread of ransomware, which is already out of control.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Ethical Hackers Stymie $27bn of Cybercrime
Ethical Hackers Stymie $27bn of Cybercrime

Ethical hackers have prevented $27bn worth of cybercrime during the COVID-19 pandemic, according to new research by California crowdsourced cybersecurity platform Bugcrowd.
The finding was part of Bugcrowd’s latest annual Inside the Mind of a Hacker report, which was published today. The research is based on the analysis of survey responses and security research conducted on the platform from May 1, 2020, to August 31, 2021, in addition to millions of proprietary data points collected on vulnerabilities from 2,961 security programs.
Nearly three quarters of respondents (74%) said vulnerabilities had increased since the outbreak of COVID-19. Most hackers (80%) found a vulnerability they had not encountered before the pandemic.
Almost half of the hackers (45%) said they believe that lack of scope inhibits the discovery of critical vulnerabilities.
Other key takeaways from the report were that 91% of ethical hackers do not believe that point-in-time testing can secure companies year-round.
Commenting, Tim Wade, technical director of Vectra’s CTO team, said: “Security testers asserting that point-in-time testing cannot secure companies year-round is a reflection of what software delivery professionals have known for years and years – shorter, more agile cycles improve quality.”
Most of the hackers (71%) said that they earn more from the San Francisco–based Bugcrowd now that most companies work remotely.
Casey Ellis, founder and CTO at Bugcrowd, said that for many of the platform’s hackers, earnings are going up and payments are being delivered faster.
“Our report found that 47% of ethical hackers earned more on Bugcrowd than they did in the previous period and the time between sending a report and receiving payment had decreased on the Bugcrowd platform, in some cases less than 30 minutes,” said Ellis.
Ellis added that he was inspired by the ingenuity and entrepreneurial mindset of individuals drawn to ethical hacking.
“Our latest report shows that 79% of ethical hackers taught themselves how to hack using online resources,” said Ellis.
“The report also found that this is the youngest, and most ethnically diverse, generation of ethical hackers in history.”
Ellis described the impact of this new wave of White Hat hackers on thwarting cyber-attacks and advancing the industry as “monumental” and “sure to continue.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
K-12 School Districts Failing at Cloud Security
K-12 School Districts Failing at Cloud Security

American K-12 school districts are vulnerable to cyber-attacks targeting data in cloud applications, according to new research.
A study conducted by the EdWeek Research Center and commissioned by cloud application security and student safety monitoring platform ManagedMethods asked district-level administrators about their cybersecurity strategies.
The online survey was completed between July 14 and September 15, 2021, by 214 administrators who said they had at least a medium level of influence on technology decisions. Respondents included 54 technology officers, 52 district superintendents, and 30 curriculum and instruction directors.
Researchers found that 30% of K-12 school districts do not have a cloud security platform in place to monitor and protect the data stored in cloud applications.
Half of the respondents said either that they did not have a platform in place or that they had no idea if a platform had been implemented in their district.
Nearly a third (31%) did not know if their cybersecurity platform consistently monitors the level of risk of files shared with users outside the district’s domain or monitors for potential violations of government regulations.
When asked if their cybersecurity platform monitors the level of risk of files shared within or uploaded into their domains, or reports who has access, 28% of respondents said they didn’t know.
Describing what data they store in the cloud, many respondents (69%) said they either have their human resources systems there already or plan to move them there.
Most respondents (86%) said they use cloud-based learning management systems (LMS) or plan to move these systems to the cloud.
The research revealed that the median budget district administrators have available for cybersecurity is $20,000 annually, of which 20% will go toward protecting cloud applications in 2022.
“School districts have long led the charge into cloud technology by embracing Google Workspace and Microsoft 365 cloud applications. This new research tells us that some district administrators are unaware of the cybersecurity, safety, and privacy risks that come with using them,” said Charlie Sander, CEO at ManagedMethods.
“Technology leaders need to know their cloud environments may be vulnerable, and that it’s their responsibility to secure them.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Panel Discusses How SMEs Can Stay Secure Amid Digital Shift
Panel Discusses How SMEs Can Stay Secure Amid Digital Shift

The ways SMEs can address cybersecurity challenges brought about by rapid digital transformation during COVID-19 were discussed during a webinar hosted by the FT.
The panel, moderated by Danielle Myles, contributor, fDi, Financial Times Group, offered advice on how SMEs can effectively leverage advances in digital technologies to compete with large businesses. The panelists began by outlining the significant benefits such a transformation can entail for them. Sandrine Kergroach, head of SME and Entrepreneur at OECD, noted that costs in administration, logistics and marketing could be significantly lowered through digitization.
Antony Walker, deputy CEO of techUK, agreed and pointed to the “transformational” potential cloud platforms offer to SMEs, as they have commoditized these types of technologies. This means that “services and products that once were only available to the very largest companies are now available to everybody.” In Walker’s view, the benefits of cloud platforms extend to cybersecurity. “One of the real benefits of cloud-based technologies is that you’re benefitting from industrial grade cybersecurity and resilience that means you can stay up and running,” he stated.
Later in the session, the discussion turned to the challenges for SMEs around increased tech adoption, particularly cybersecurity. Henk Koopmans, chief executive officer of R&D at Huawei UK, said fears about the scale of cyber-threats could even “be a barrier to going digital.” To ensure this is not the case, he believes there needs to be more education about the high-level security established in many technologies they can utilize. For example, “we’re so comfortable now making financial transactions using 4G – the only reason we can do that is that it’s based on standards that are thoroughly tested.”
However, Jane Dickinson, digital skills lead at The Open University, pointed out that the majority of cyber-breaches are a result of human behaviors. This issue has been exacerbated by the expanded attack surface during COVID-19, and there needs to be a far greater emphasis on security culture and awareness training throughout SME workforces as a result. “We need to create cultures where everybody takes responsibility for maintaining their own knowledge and skills in this area,” she commented.
Additionally, cyber-criminals have dramatically increased their targeting of SMEs in the pandemic due to “being less well prepared for attacks,” according to Kergroach. With these businesses having less capacity and ability to attract cybersecurity talent, they rely heavily on digital solution providers to offer that protection. Therefore, she believes IT products need to be more tailored towards the specific needs of SMEs.
Koopmans also highlighted the growth in supply chain attacks in the past year, exemplified by the SolarWinds and Kaseya attacks. As many SMEs are part of the supply chain for large businesses, “not embracing it [means] you’re becoming security-wise the weak link in the chain.” Therefore, “if you’re in the supply chain of these companies, then you have a role to play yourself.”
Walker agreed with Dickinson’s point about the importance of building a strong cybersecurity culture in SMEs. He added that many of these businesses, especially those that sell consumer-focused products, need to consider the impact of the new online harms legislation in the UK. For example, companies might need to ask questions like: “are there risks involved here? What if children access my service?”
The panel ended by discussing the digital skills gap, including in cybersecurity. On a positive note, Walker noted that during the pandemic, there has been “a massive increase in people acquiring digital skills” via online courses. For SMEs to take advantage of this emerging talent, he said they must “build a reputation that they are a place where young people can come and gain skills as a great starting point for their career.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains