Spot Those Black Friday and Cyber Monday Shopping Scams

You’re not the only one looking forward to the big holiday sales like Black Friday and Cyber Monday. Hackers are too. As people flock to retailers big and small in search of the best deals online, hackers have their shopping scams ready. 

One aspect of cybercrime that deserves a fair share of attention is the human element. Crooks have always played on our feelings, fears, and misplaced senses of trust. It’s no different online, particularly during the holidays. We all know it can be a stressful time and that we sometimes give into the pressure of finding that hard-to-get gift that’s so hot this year. Crooks know it too, and they’ll tailor their attacks accordingly as we get wrapped up in the rush of the season. 

5 ways to spot an online shopping scam 

So while you already know how to spot a great deal, here are ways you and your family can spot online shopping scams so you can keep your finances safer this shopping season: 

1) Email attachments that pretend to be from legitimate retailers and shippers 

A common scam hackers use is introducing malware via email attachments, and during the holiday sale season, they’ll often send malware under the guise of offering emails and shipping notifications. Know that retailers and shipping companies won’t send things like offers, promo codes, and tracking numbers in attachments. They’ll clearly call those things out in the body of an email instead. 

2) Typosquat trickery 

A classic scammer move is to “typosquat” phony email addresses and URLs that look awfully close to legitimate addresses of legitimate companies and retailers. They often appear in phishing emails and instead of leading you to a great deal, these can in fact link you to scam sites that can then lift your login credentials, payment info, or even funds should you try to place an order through them. You can avoid these sites by going to the retailer’s site directly. Be skeptical of any links you receive by email, text, or direct message—it’s best to go to the site yourself by manually typing in the legitimate address yourself and look for the deal there. 

3) Copycat deals and sites 

A related scammer trick that also uses typosquatting tactics is to set up sites that look like they could be run by a trusted retailer or brand but are not. These sits may tout a special offer, a great deal on a hot holiday item, or whatnot, yet such sites are one more way cybercriminals harvest personal and financial information. A common way for these sites to spread is by social media, email, and other messaging platforms. Again a “close to the real thing” URL is a telltale sign of a copycat, so visit retailers directly. Also, comprehensive online protection software can prevent your browser from loading suspicious sites and warn you of suspicious sites in your search results. 

4) Counterfeit shopping apps 

While the best of them can look practically professional and be tough to spot, one way to avoid counterfeit shopping apps is to go to the source. Hit the retailer’s website on your mobile browser and look for a link to the app from their website. Likewise, stick to the legitimate app stores such as Google Play and Apple’s App Store. Both have measures in place to prevent malicious apps from appearing in their stores. Some can sneak through before being detected though, so look for the publisher’s name in the description and ensure it is legitimate. On a fake app, the name may be close to the retailer you’re looking for, but not quite right. Other signs of a fake will include typos, poor grammar, and design that looks a bit off. 

5) The “too good to be true” offer 

At the heart of holiday shopping is scarcity. Special offers for a limited time, popular holiday items that are tough to find, and just the general preciousness of time during the season to get things done, like shopping. Scammers love this time of year. During the holidays, they’ll play on that scarcity and crunch you’re under in their offers and messaging. Enter the “too good to be true” offer, typically set up on phony sites like the ones mentioned above. If the pricing, availability, or delivery time all look too good to be true, it may be a scam designed to harvest your personal info and accounts. Use caution here before you click. If you’re unsure about a product or retailer, read reviews from trusted websites to help see if it’s legitimate. 

Great tips for shopping online any time 

Apart from spotting scams, there are several things you can do to keep yourself safer while shopping this holiday season. In fact, they can keep you safer when you shop year ‘round as well. 

Look for the lock icon 

This is a great one to start with. Secure websites begin their address with “https,” not just “http.” That extra “s” in stands for “secure,” which means that it uses a secure protocol for transmitting sensitive info like passwords, credit card numbers, and the like over the internet. It often appears as a little padlock icon in the address bar of your browser, so double-check for that. If you don’t see that it’s secure, it’s best to avoid making purchases on that website. 

Use a credit card instead of your debit card 

Specific to the U.S., the Fair Credit Billing Act offers the public protection against fraudulent charges on credit cards, where citizens can dispute charges over $50 for goods and services that were never delivered or otherwise billed incorrectly. Note that many credit card companies have their own policies that improve upon the Fair Credit Billing Act as well. However, debit cards aren’t afforded the same protection under the Act. Avoid using those while shopping online and use your credit card instead. 

Consider getting a virtual credit card 

Another alternative is to set up a virtual credit card, which is a proxy for your actual credit card. With each purchase you make, that proxy changes, which then makes it much more difficult for hackers to exploit. You’ll want to research virtual credit cards further, as there are some possible cons that go along with the pros, such as in the case of returns where a retailer will want to use the same proxy to reimburse a purchase. 

Use protection while you shop 

Using a complete suite of online protection software can offer layers of extra protection while you shop, such as web browser protection and a password manager. Browser protection can block malicious and suspicious links that could lead you down the road to malware or a financial scam. A password manager can create strong, unique passwords and store them securely as well, making it far more difficult for hackers to compromise your accounts. Identity theft protection takes your safety a step further by helping you secure your identity online and restore it should any of your personal info be found in the wrong hands. 

Use two-factor authentication on your accounts 

Two-factor authentication is an extra layer of defense on top of your username and password. It adds in the use of a special one-time-use code to access your account, usually sent to you via email or to your phone by text or a phone call. In all, it combines something you know, like your password, with something you have, like your smartphone. Together, that makes it tougher for a crook to hack your account. If any of your accounts support two-factor authentication, the few extra seconds it takes to set up is more than worth the big boost in protection you’ll get. 

Use a VPN if you’re shopping on public Wi-Fi 

Public Wi-Fi in coffee shops and other public locations can expose your private surfing to prying eyes because those networks are open to all. Using a virtual private network (VPN) encrypts your browsing, shopping, and other internet traffic, thus making it secure from attempts at intercepting your data on public Wi-Fi and harvesting information like your passwords and credit card numbers. 

Keep an eye on your identity and credit reports 

With all the passwords and accounts we keep, this is important. Checking your credit will uncover any inconsistencies or outright instances of fraud. From there, you can then take steps to straighten out any errors or bad charges that you find. In the U.S., you can run a free credit report once a year with the major credit reporting agencies 

Shop happy! (Don’t give in to stress and scarcity.) 

So while you’re shopping online this year, take a deep breath before you dive in. Double-check those deals that may look almost too good to be true. Look closely at those links. And absolutely don’t click on those attachments that look like shipping notices or coupon deals. Hackers are counting on you to be in a bit of a hurry this time of year. Taking an extra moment to spot their tricks can go a long way toward keeping you and your finances safe. 

The post Spot Those Black Friday and Cyber Monday Shopping Scams appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Who Will Bend the Knee in RaaS Game of Thrones in 2022?

McAfee Enterprise and FireEye recently released its 2022 Threat Predictions. In this blog, we take a deeper dive into a Game of Thrones power struggle among Ransomware-as-a-Service bad actors in 2022.

Prediction: Self-reliant cybercrime groups will shift the balance of power within the RaaS eco-kingdom. 

For several years, ransomware attacks have dominated the headlines as arguably the most impactful cyber threats. The Ransomware-as-a-Service (RaaS) model at the time opened the cybercrime career path to lesser skilled criminals which eventually led to more breaches and higher criminal profits.

For a long time, RaaS admins and developers were prioritized as the top targets, often neglecting the affiliates since they were perceived as less skilled. This, combined with the lack of disruptions in the RaaS ecosystem, created an atmosphere where those lesser-skilled affiliates could thrive and grow into very competent cybercriminals, eventually with a mind of their own.

In a response to the Colonial Pipeline attack, the popular cybercrime forums have banned ransomware actors from advertising. Now, the RaaS groups no longer have a third-party platform on which to actively recruit, show their seniority, offer escrow, have their binaries tested by moderators, or settle disputes. The lack of visibility has made it harder for RaaS groups to establish or maintain credibility and will make it harder for RaaS developers to maintain their current top tier position in the underground.

These events have undermined their trusted position. Ransomware has generated billions of dollars in recent years and it’s only a matter of time before more individuals who believe they aren’t getting their fair share become unhappy.

The first signs of this happening are already visible as described in our blog on the Groove Gang, a cyber-criminal gang that branched off from classic RaaS to specialize in computer network exploitation (CNE), exfiltrate sensitive data and, if lucrative, partner with a ransomware team to encrypt the organization’s network. McAfee Enterprise ATR believes, with high confidence, that the Groove gang is associated with the Babuk gang, either as a former affiliate or subgroup. These cybercriminals are happy to put aside previous Ransomware-as-a-Service hierarchies to focus on the ill-gotten gains to be made from controlling victim’s networks, rather than the previous approach which prioritized control of the ransomware itself.

Trust in a few things remains important even among cybercriminals underground, such as keeping your word and paying people what they deserve. Cybercriminals aren’t immune from feeling like employees whose contributions aren’t being adequately rewarded. When this happens, these bad actors cause problems within the organization. Ransomware has been generating billions of dollars in recent years and with revenue like that, it was inevitable that some individuals who believe they aren’t getting their fair share become unhappy and let the cybercrime world know it.

Recently, a former Conti affiliate was unhappy with their financial portion and decided to disclose the complete Conti attack playbook and their Cobalt Strike infrastructure online. In the past, McAfee ATR has been approached by individuals affiliated with certain RaaS groups expressing grudges with other RaaS members and admins, claiming they haven’t been paid in time or that their share wasn’t proportionate to the amount of work they put in.

In 2022, expect more self-reliant cybercrime groups to rise and shift the balance of power within the RaaS eco-climate from those who control the ransomware to those who control the victim’s networks.

Less-skilled Operators Won’t Have to Bend the Knee in RaaS Model Power Shift

The Ransomware-as-a-Service eco system has evolved with the use of affiliates, the middlemen and women that work with the developers for a share of the profits. While this structure was honed during the growth of GandCrab, we are witnessing potential chasms in what is becoming a not-so-perfect union.

Historically, the ransomware developers, held the cards, thanks to their ability to selectively determine the affiliates in their operations, even holding “job interviews” to establish technical expertise. Using CTB locker as an example, prominence was placed on affiliates generating sufficient installs via a botnet, exploit kits or stolen credentials. But affiliates recently taking on the role and displaying the ability to penetrate and compromise a complete network using a variety of malicious and non-malicious tools essentially changed the typical affiliate profile towards a highly skilled pen-tester/sysadmin.

The hierarchy of a conventional organized crime group often is described as a pyramid structure. Historically, La Cosa Nostra, drug cartels and outlaw motor gangs were organized in such a fashion. However, due to further professionalization and specialization of the logistics involved with committing crime, groups have evolved into more opportunistic network-based groups that will work together more fluidly, according to their current needs.

While criminals collaborating in the world of cybercrime isn’t new, a RaaS group’s hierarchy has been more rigid compared to other forms of cybercrime, due to the power imbalance between the group’s developers/admins and affiliates. But things are changing. RaaS admins and developers were prioritized as the top targets, but often neglected the affiliates who they perceived to be less-skilled. This, combined with the lack of disruptions in the RaaS ecosystem, created an atmosphere where those lesser-skilled affiliates could thrive and grow into very competent cybercriminals.

As more ransomware players have entered the market, we suspect that the most talented affiliates are now able to auction their services for a bigger part of the profits, and maybe demand a broader say in operations. For example, the introduction of Active Directory enumeration within DarkSide ransomware could be intended to remove the dependency on the technical expertise of affiliates. These shifts signal a potential migration back to the early days of ransomware, with less-skilled operators increasing in demand using the expertise encoded by the ransomware developers.

Will this work? Frankly, it will be challenging to replicate the technical expertise of a skilled penetration tester, and maybe – just maybe – the impact will not be as severe as recent cases.

The post Who Will Bend the Knee in RaaS Game of Thrones in 2022? appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

REvil Ransom Arrest, $6M Seizure, and $10M Reward

The U.S. Department of Justice today announced the arrest of Ukrainian man accused of deploying ransomware on behalf of the REvil ransomware gang, a Russian-speaking cybercriminal collective that has extorted hundreds of millions from victim organizations. The DOJ also said it had seized $6.1 million in cryptocurrency sent to another REvil affiliate, and that the U.S. Department of State is now offering up to $10 million for the name or location any key REvil leaders, and up to $5 million for information on REvil affiliates.

If it sounds unlikely that a normal Internet user could make millions of dollars unmasking the identities of REvil gang members, take heart and consider that the two men indicted as part this law enforcement action do not appear to have done much to separate their cybercriminal identities from their real-life selves.

Exhibit #1: Yaroslav Vasinskyi, the 22-year-old Ukrainian national accused of being REvil Affiliate #22. Vasinskyi was arrested Oct. 8 in Poland, which maintains an extradition treaty with the United States. Prosecutors say Vasinskyi was involved in a number of REvil ransomware attacks, including the July 2021 attack against Kaseya, Miami-based company whose products help system administrators manage large networks remotely.

Yaroslav Vasinksyi’s Vkontakte profile reads “If they tell you nasty things about me, believe every word.”

According to his indictment (PDF), Vasinskyi used a variety of hacker handles, including “Profcomserv” — the nickname behind an online service that floods phone numbers with junk calls for a fee. Prosecutors say Vasinskyi also used the monikers  “Yarik45,” and “Yaroslav2468.”

These last two nicknames correspond to accounts on several top cybercrime forums way back in 2013, where a user named “Yaroslav2468” registered using the email address yarik45@gmail.com.

That email address was used to register an account at Vkontakte (the Russian version of Facebook/Meta) under the profile name of “Yaroslav ‘sell the blood of css’ Vasinskyi.” Vasinskyi’s Vkontakte profile says his current city as of Oct. 3 was Lublin, Poland. Perhaps tauntingly, Vasinskyi’s profile page also lists the FBI’s 1-800 tip line as his contact phone number. He’s now in custody in Poland, awaiting extradition to the United States.

Exhibit #2: Yevgeniy Igorevich Polyanin, the 28-year-old Russian national who is alleged to be REvil Affiliate #23. The DOJ said it seized $6.1 million in funds traceable to alleged ransom payments received by Polyanin, and that the defendant had been involved in REvil ransomware attacks on multiple U.S. victim organizations.

The FBI’s wanted poster for Polyanin.

Polyanin’s indictment (PDF) says he also favored numerous hacker handles, including LK4D4, Damnating, Damn2life, Noolleds, and Antunpitre. Some of these nicknames go back more than a decade on Russian cybercrime forums, many of which have been hacked and relieved of their user databases over the years.

Among those was carder[.]su, and that forum’s database says a user by the name “Damnating” registered with the forum in 2008 using the email address damnating@yandex.ru. Sure enough, there is a Vkontakte profile tied to that email address under the name “Yevgeniy ‘damn’ Polyanin” from Barnaul, a city in the southern Siberian region of Russia.

The apparent lack of any real operational security by either of the accused here is so common that it is hardly remarkable. As exhibited by countless investigations in my Breadcrumbs story series, I have found that if a cybercriminal is active on multiple forums over more than 10 years, it is extremely likely that person has made multiple mistakes that make it relatively easy to connect his forum persona to his real-life identity.

As I explained earlier this year in The Wages of Password Re-use: Your Money or Your Life, it’s possible in many cases to make that connection thanks to two factors. The biggest is password re-use by cybercriminals (yes, crooks are lazy, too). The other is that cybercriminal forums, services, etc. get hacked just about as much as everyone else on the Internet, and when they do their user databases can reveal some very valuable secrets and connections.

In conjunction with today’s REvil action, the U.S. Department of State said it was offering a reward of up to $10 million for information leading to the identification or location of any individual holding a key leadership position in the REvil ransomware group. The department said it was also offering a reward of up to $5 million for information leading to the arrest and/or conviction in any country of any individual conspiring to participate in or attempting to participate in a REvil ransomware incident.

I really like this bounty offer and I hope we see more just like it for other ransomware groups. Because as we can see from the prosecutions of both Polyanin and Vasinskyi a lot of these guys simply aren’t too hard to find. Let the games begin.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Telegram – What Parents Need To Know Now

If you hadn’t heard of Telegram till 2021 then you wouldn’t be alone. This relatively unknown messaging and social media platform has risen from relative anonymity to become one of the biggest players in the ‘secret messaging’ business in less than a year. When What’s App changed its terms of usage in early 2021 and informed users that their data would be shared with their new parent Facebook, many ‘jumped ship’ in search of a less intrusive messaging option. But it was Facebook’s six-hour outage in early October that really made Telegram an enticing option. On that same day, Telegram gained a record 70 million users. 

According to Statista, Telegram is now the 10th most popular social media platform worldwide, coming in ahead of Snapchat, Pinterest, and even Twitter! So, as Telegram’s popularity continues to grow, it’s highly likely that your kids will be soon giving it a try if they haven’t already! So, how does it work? Is it safe? And, should you intervene. Here’s what you need to know… 

About Telegram 

Although many of us first heard about Telegram this year, it has in fact been around since 2013. Founded by Russian brothers Pavel and Nikolai Durov, Telegram was founded as part of their efforts to offer a forum for free speech online after their first social networking site, known as VK, was taken over by the Russian Government 

Widely considered to be a Russian ‘Mark Zuckerberg’, VK made Pavel a billionaire. Pavel claims he was pushed out for refusing to provide VK data to the Russian government and shut down anti-corruption advocates. He has since cut ties with VK and moved to Germany. Telegram was last reported to be located in Dubai. 

How Does It Work? 

All you need is the Telegram app and a mobile phone number to start your Telegram account and yes, it works across both the Apple and Android platforms. Although it was started primarily as a messaging app, it has evolved into a social network that can be used to build groups around common interests. Both public and private groups can be set up as well as channels. It is also possible to search for people located close to you. And if you love stickers then you’ll love Telegram. Many consider it to have the best range of any messaging app! 

Is It Safe? 

Right from the start, Telegram has positioned itself as an app committed to private and secure messaging. However, the fact that end-to-end encryption is not automatically used on messages sent in Telegram means it is not as ‘secure’ as privacy focussed messaging platforms such as Signal which offer end-to-end encryption for all communication.  

It is important to note that Telegram users can choose for their chats to be ‘secret’ which means they will be end-to-end encrypted, meaning that only the sender and receiver can read the message – but you must opt in to have the additional level of privacy. But group chats, one of the app’s most popular features, cannot be end-to-end encrypted. 

How Does Telegram Deal With Controversial Content? 

One of the biggest issues with Telegram is the content shared in the app and the company’s “hands-off” approach to moderation. Telegram’s a truly unique combination of messaging and social media plus its publicly relaxed content moderation strategy means it attracts a certain style of the user who may have been outed from more mainstream online platforms. 

A quick Google will produce multiple examples of how Telegram has been widely used by fringe political groups. Security experts have acknowledged that Telegram is in fact ‘the app of choice’ for terrorist organizations. Neo-nazi groups have reportedly used Telegram as a recruiting platform and the far-right QAnon has reportedly set up a home on Telegram after messaging app Parler was suspended earlier this year. 

Now, of course, this sounds completely horrid and makes Telegram seem very unattractive. But I can assure you that my Telegram user experience has been quite bland. I have been using the app on and off for several months now and I’ve never been exposed to political or fringe content but I also haven’t gone looking for it. For me, it has been yet another way of connecting with people in my life with a couple of great stickers to assist! 

Should My Kids Use It? 

In my opinion, Telegram is an app best suited for a robust adult mind. According to the terms and conditions, Telegram users need to be 16+ to join up however as worldly parents, we all know those age restrictions are not a deterrent for many young people! 

While my experience has been no different from using other messaging apps like WhatsApp, I believe Telegram is not an appropriate app for an under 18 as there are too many risks:  

  • Pornographic and violent sexual content is available on Telegram if you chose to seek it out 
  • The ‘find people nearby’ feature allows users to be targeted with inappropriate material if settings haven’t been adjusted 
  • The ‘group nearby’ feature allows users to view groups without joining. There is a risk these groups may contain violent or harmful material. 
  • The lack of content moderation means users could be exposed to fringe political material which may be traumatic and hard to process. 

Now, of course, it is possible to adjust settings to minimize the risks when using the app. If location services are turned off and profiles are not marked visible, then finding ‘random’ groups and people via location will not be an option. And if the default privacy settings are adjusted so that your child can only be contacted by ‘my contacts’ as opposed to ‘everybody’ then this will minimize the risk of receiving communication from people they don’t know. 

So, if you or your kids are looking for a top-notch end-to-end encrypted messaging app then there are definitely better options around, such as Signal. And let’s not forget about WhatsApp which offers end-to-end encrypted messaging on everything sent in the app. Yes, your information will be shared with Facebook but only if you are messaging a business on the app, according to the company. Messages and calls between parties are still protected by end-to-end encryption. So many choices, so many messages to send! 

Happy messaging! 

Alex x 

The post Telegram – What Parents Need To Know Now appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ohio Schools Get New Cybersecurity Resource

Ohio Schools Get New Cybersecurity Resource

School districts in Ohio have been given a new online resource to help them improve their cybersecurity posture.

The launch of the Ohio Department of Education Cyber Security Resources web page was announced by the Ohio Department of Education’s Cyber Security Steering Committee on November 3.

The new resource was developed through the combined efforts of the Ohio Department of Education’s Cyber Security Steering Committee: the Center for Internet Security, the Department of Homeland Security, Filament Essential Services, Information Technology Centers, the Management Council of the OECN, MS-ISAC, OARnet, Ohio CoSN, Ohio Department of Education, Ohio National Guard, and Ohio school districts.

The DOE said that the new site “is dedicated to supporting school districts and all members of the Ohio Education Computer Network (OECN) with cybersecurity resources.”

Visitors to the site will find information and resources that can be used to develop security programs in five key areas: identify, protect, detect, respond, and recover.

Also available on the new site is the latest information from the Center for Internet Security, including real-time news and advisories. Visitors can also use the resource to access the Center’s security tips about how to understand and mitigate current cyber-threats. 

Elsewhere on the site is a Resource Library page where visitors can access the top ten suggestions to enhance their cybersecurity posture. “Adopt a security framework” is the number one recommendation, followed by “Conduct an assessment of the school district’s security program.”

The number three suggestion is for all personnel to carry out security awareness training at least once a year, with particular attention paid to data protection, incident identification, insider threats, and phishing campaigns. 

Featured on the new website are several downloadable resources that include a critical controls self-assessment and a template for an incident response plan.

“Now, more than ever, cybersecurity is a fundamental priority for Ohio’s school districts and the Information Technology Centers that protect and serve their technology needs,” said Geoff Andrews, chief executive officer of the OECN’s Management Council. 

“We are pleased to be a part of the collaborative effort to bring cybersecurity resources to the forefront.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

DOD Licenses Data Carver

DOD Licenses Data Carver

A digital forensics tool capable of retrieving previously unrecoverable data is now available to license from the United States Department of Defense’s Cyber Crime Center (DC3).

DC3’s Advanced Carver was invented by digital forensics expert Dr. Eoghan Casey to salvage corrupted data files from almost any digital device. The tool can be used to recover digital content, including documents, databases, videos, images, and executable files, from devices such as smartphones, laptops, and cameras.

“DC3 Advanced Carver was created to maximize renderable recovered content by salvaging files and fragments that other tools miss; it eliminates false positive results typically produced by other carving tools,” said Casey. 

“The innovative design enables Advanced Carver to recover files faster by leveraging all available resources of a computer.”

Now, after securing a 20-year utility patent for the tool, DC3 are making the Advanced Carver available to state and local governments and private companies for the first time.

Those wishing to secure a license agreement with the Defense Department to use the DC3 Advanced Carver tool should contact TechLink, a national outreach center at Montana State University in Bozeman, Montana, that acts as the DOD’s national partnership intermediary for technology transfer.

TechLink’s services are provided at no cost, meaning neither private companies nor DOD researchers pay for this intermediary service.

TechLink’s Troy Carter said that the Advanced Carver had already proven to be a “unique and reliable” tool in digital forensic examinations. 

An unidentified digital forensic examiner who used the tool to extract from a digital video recorder a video that had a proprietary wrapper said: “A special software player was required to view the date/timestamps of the video. Examiners were only able to identify 10 videos for the relevant time frame utilizing existing tools. 

“Utilizing Advanced Carver and collaborating with a developer subject matter expert on how date/time stamps were stored in video files; 1,874 video clips of the relevant time frame were recovered.”

Another examiner who used the tool said: “In a case with a single cellphone as evidence, an examiner ran a UFED Physical Analyzer on its most thorough setting and recovered a total of 103,160 pictures. Advanced Carver was able to recover 270,228 photographs.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ransomware Attack on Lab in Florida

Ransomware Attack on Lab in Florida

A ransomware attack on a laboratory based in Florida has exposed the personal health information (PHI) of more than 30,000 patients. 

Nationwide Laboratory Services, which is based in Boca Raton, identified suspicious activity on its network on May 19, 2021. An examination of the activity revealed that attackers had used ransomware to encrypt files across the healthcare provider’s network, making their contents inaccessible. 

The lab hired a third-party cybersecurity firm to investigate the attack and assist with remediation. Digital forensics revealed that cyber-attackers had broken into areas of Nationwide Laboratory Services’ network that contained patients’ PHI.

Lawbreakers behind the ransomware assault encrypted files in which patient data was stored, including names, dates of birth, lab test results, medical record numbers, Medicare numbers, and health insurance information.

notice released by Nationwide Laboratory Services regarding the security incident warned: “A limited number of individuals had Social Security number also impacted.”

The lab said that the cyber-attack had not affected all patients of Nationwide. Is also said that the amount of data exposed in the incident differed from patient to patient.

“Nationwide has no evidence that any information was or will be used for any unintended purpose,” stated the laboratory.

report concerning the breach was submitted by Nationwide to the Department of Health and Human Services’ Office for Civil Rights on October 28. The report indicates the PHI of up to 33,437 individuals may have been exposed.

Patients who were affected by the ransomware attack have been notified and provided with best practices to protect their information. Nationwide urged impacted individuals to remain vigilant for signs of identity theft, and to review their financial account statements on a regular basis for any fraudulent activity.

On top of encrypting an unspecified number of files belonging to Nationwide, the cyber-criminals behind the attack on the laboratory potentially deleted some files from their victim’s network.

The laboratory stated: “On May 19, 2021, Nationwide Laboratory Services detected that a ransomware infection began encrypting files stored on its network. In addition to encrypting files, an unauthorized party may have removed a limited number of files from its system.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

One in Three Workers Monitored by Their Employers

One in Three Workers Monitored by Their Employers

Almost one in three (32%) workers are being monitored at work by their employers, according to a new survey of 2424 UK workers by the union Prospect.. This represents a substantial rise from April 2021, when 24% of employees reported being subjected to monitoring at work, sparking privacy and intrusion concerns.

This rise has partially been driven by a significant uptick in home workers being monitored by cameras over this period, up from 6% in April to 13%.

The survey, conducted by the pollster Opinium, also found that four in five (80%) of workers believe the use of webcams to monitor remote workers should either be banned (52%) or heavily regulated (28%). Additionally, just 8% of respondents thought employees should be able to unilaterally decide when to use cameras to monitor home workers.

Younger workers (18-34) were more likely to be monitored than older counterparts, with almost half (48%) reporting that they are monitored at work. This includes 20% being monitored with cameras.

Current Information Commissioner Office (ICO) guidance states that employers should ensure staff are aware of monitoring at work before it starts and explicitly inform them why this is being done. This applies whether at home or in the office.

Amid the increase in hybrid working during the COVID-19 pandemic, the ICO is currently updating its guidelines in this area. The BBC quoted an ICO spokesman as saying: “People expect that they can keep their personal lives private and that they are also entitled to a degree of privacy in the workplace.

“We are currently working on updating our employment practices guidance to address the changes in data protection law and to reflect the new ways employers use technology and interact with staff.”

Prospect is now asking the government to consider making it illegal for employers to use camera monitoring in people’s homes outside of meetings and calls.

Prospect general secretary Mike Clancy said: “We are used to the idea of employers checking up on workers, but when people are working in their own homes, this assumes a whole new dimension.

“New technology allows employers to have a constant window into their employees’ homes, and the use of the technology is largely unregulated by government.

“We think that we need to upgrade the law to protect the privacy of workers and set reasonable limits on the use of this snooping technology, and the public overwhelmingly agrees with us.”

Commenting on the story, Sridhar Iyengar, MD for Zoho Europe, said: “This new data is alarming and demonstrates how misuse of new technology can allow employers to invade staff privacy through, for example, viewing employees’ web browsing page by page,or even watching them at their home ‘desk’ via their webcam. It is even more concerning that the government does not regulate this technology. The ICO is right to guide bosses to ensure their staff are made aware of any remote monitoring and the reasons why it is being deployed. The practices raised in the research are clear examples of employer misuse of remote monitoring software and a violation of employee privacy.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#SecTorCa: Cyber Expert Wendy Nather Unmasks “Scary Bits” of Infosec in 2021

#SecTorCa: Cyber Expert Wendy Nather Unmasks “Scary Bits” of Infosec in 2021

While Halloween 2021 is a few days past, Wendy Nather, head of advisory CISOs at Cisco, still sees many “dark” things on the infosec landscape.

In a keynote session at the SecTor security conference on November 4, Nather outlined various potential concerns facing IT security professionals now and likely for years into the future. The infosec concerns for Nather have in no small part been accelerated by the pandemic, as employees were predominantly working remotely from home.

“We had a surprise visit to zero trust land,” Nather said. “Now, if you’re still not really sure what zero trust means, it’s okay. But, I’m here to tell you that nobody likes that term.”

Zero trust is a concept that has become increasingly used in recent years. Nather said that when the pandemic first hit hard in early 2020, organizations told employees to use whatever they had at home. That ended up with a lot of organizations running out of VPN licenses.

Wendy Nather speaking at SecTor security conference
Wendy Nather speaking at SecTor security conference

“So we had a lot more BYOD (bring your own device), which is something that zero trust is really good at handling,” Nather said.

Another difficult challenge that has emerged due to the pandemic is making effective use of biometric multi-factor authentication technology, including fingerprint and face recognition technology. In multi-user environments like a hospital, it was no longer considered safe for many users to tap a biometric scanning device with their finger, as there was a fear of contact contamination.

“Who knew that face ID would stop working because everybody was wearing masks,” Nather said. “All these sorts of things we had to figure out and scramble and figure out what factors we could still use that would do the authentication that we needed to build a good zero trust environment.”

The Internet is “Dark and Full of Terrors”

Another source of concern for many IT security professionals is the network itself that Nather remarked is “dark and full of terrors.”

The dark part is that the network increasingly lacks visibility as the volume of encrypted internet traffic continues to increase. She noted that while encrypted traffic can be a good thing for privacy, it also means that IT security professionals can’t see everything all the time, as they once could.

Nather said that organizations couldn’t see security events and details needed to make risk decisions for endpoints, applications and connections without being in line with the communication path.

“What you’re left with is looking at the endpoint and the application more closely. You’re going to have to get more indicators for those two spots because you can’t get them from the middle anymore,” Nather said. “So, is this a problem? Yeah, it is.”

Nather noted that the security industry is starting to work through the issue now with a series of different nascent approaches. One such approach is the continuous access evaluation protocol (CAEP).

“This is something that will help after the session initiation and continuing through the life of the session to decide if something is going on that you need to take action on,” Nather said.

Nather warned that there could be a future when IT security professionals have less visibility than ever before. She added that there would be fewer entities that actually have direct control over the network that organizations are using, and enterprises will have to move security controls into new domains and try different frameworks to compensate.

“I don’t want to frighten you completely; it’s not happening just yet, but brace yourself for this brave new world,” Nather said. “I don’t want to leave you completely scared, so I’m just going to say, you know, it’s going to be okay. It’s okay. This is all right. We can figure this out.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

ONS Reports Huge Spike in Cybercrime and Fraud During COVID-19

ONS Reports Huge Spike in Cybercrime and Fraud During COVID-19

Fraud and computer misuse offenses rose by 43% in the year ending June 2021 compared with the pre-COVID year ending June 2019, according to estimates from the Telephone-operated Crime Survey for England and Wales (TCSEW).

Published by the Office for National Statistics (ONS), the figures further demonstrated the extent to which crime shifted to the digital space during COVID-19 lockdown restrictions in the UK. There was an estimated 14% decline in total crime excluding computer misuse and fraud in 2020/21 compared with 2018/19.

Computer misuse offenses, defined as fraudsters hacking or using computer viruses or malware to disrupt services, obtain information illegally or extort individuals or organizations, increased by 85% in 2020/21 compared with 2018/19, with a total of 1.8 million incidents estimated to have occurred. This was largely driven by a 161% rise in unauthorized access to personal information (including hacking). This included victims’ details being compromised via large-scale data breaches and victims’ email or social media accounts being compromised.

There was also an estimated 32% rise in fraud cases, according to the TCSEW. This appeared to be largely driven by substantial increases in “consumer and retail fraud” and “advance fee fraud.” This indicates that fraudsters have adapted to new behaviors such as the shift to online shopping and banking during the pandemic.

Commenting on the figures, Dr Süleyman Özarslan, co-founder of Picus Security and head of Picus Labs, said: “A 43% increase in fraud and computer misuse cases is an astonishing spike. Cybercrime is not a victimless crime, and if this spike was seen in another criminal activity, it would be headline news.

“While most forms of crime in the UK have decreased since 2020, especially during lockdowns, the same cannot be said for online fraud. If anything, it has ramped up considerably. The survey notes a 32% increase in fraud incidents and cites ‘advance fee fraud’ and ‘retail fraud’ as key drivers.”

Özarslan added: “The survey also notes a 161% increase in ‘unauthorized access to personal information.’ I believe this indicates cybercriminals’ additional focus on personal data as a money-making asset. Cyber-criminals will regularly sell stolen personal information on the dark web; for example, credit card details with an account balance up to £3500 may cost in the region of £175. Stealing personal data has been lucrative business during the pandemic.”

The ONS claimed the TCSEW provides a better indication of computer misuse offenses as it contains crimes that go unreported to the police. However, some experts have criticized its accuracy as it only highlights incidents that are reported by individuals.

Jed Kafetz, head of pentesting at RedScan, commented: “As for the 85% increase in computer misuse and hacking, I think the crime stats are still playing catch up to reality. The 1.8 million estimated computer misuse offenses are likely to be a fraction of the real number when you consider how many details are lost, stolen and sold during big data breaches in a typical year. I’m sure hacking incidents are grossly underreported because people increasingly expect them in day-to-day life.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains