FBI Raids Chinese Payment-Terminal Company

FBI Raids Chinese Payment-Terminal Company

Law enforcement agencies in the United States have searched the Florida premises of a Chinese payment-terminal provider.

A warehouse and offices belonging to multinational Pax Technology were scoured by the Federal Bureau of Investigation, the Department of Homeland Security, and other agencies on Tuesday after concerns were reportedly raised over the company’s security.

The FBI said that the search at the site in Jacksonville had been undertaken “in furtherance of a federal investigation.”

Pax was founded two decades ago and is headquartered in Shenzhen. According to its website, the company has delivered over 57 million terminals to more than 120 countries. In addition to payment terminals, Pax manufactures PIN pads and point-of-sale (POS) hardware and software. 

News of the raid was broken by local Florida news outlet WOKV. When queried about the coordinated law enforcement action, the FBI issued the following statement:

“The FBI Jacksonville Division, in partnership with Homeland Security Investigations, Customs and Border Protection, Department of Commerce, and Naval Criminal Investigative Services, and with the support of the Jacksonville Sheriff’s Office, is executing a court-authorized search at this location in furtherance of a federal investigation. 

“We are not aware of any physical threat to the surrounding community related to this search. The investigation remains active and ongoing and no additional information can be confirmed at this time.”

Pax Technology said that it takes security very seriously and was unaware of any allegations of illegal activity. 

“As always, Pax Technology is actively monitoring its environment for possible threats. We remain committed to providing secure and quality software systems and solutions,” said a company spokesperson.

They added: “Pax Technology is not aware of any illegal conduct by it or its employees and is in the process of engaging counsel to assist in learning more about the events that led to the investigation.”

The company’s British office wrote to its customers in the UK to say that no security issues had occurred. 

In the letter, which was viewed by the BBC, the company said: “No confidential customer information or transaction data was sent from any Pax device sold in the US or UK.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Forrester Predicts Mass Cybersecurity Brain Drain

Forrester Predicts Mass Cybersecurity Brain Drain

Analyst house Forrester has warned of a significant exodus of cybersecurity professionals from the industry due to stress, burnout and limited career progression opportunities.

In its 2022 predictions report for cybersecurity, risk and privacy, the firm said as many as a tenth of professionals could head for the exit.

Some of this may be part of what’s being dubbed the “Great Resignation” — a period of post-pandemic reflection leading many individuals to change career paths.

Forrester also pointed to a Chartered Institute of Information Security study from last year, revealing that 54% of respondents had either left a job due to overwork or burnout or have worked with someone who has.

more recent study from the same organization claimed that over half (51%) of cybersecurity professionals are kept up at night by the stress of the job.

The latest figures from ISC2 out this week actually revealed a drop in the global shortfall of cybersecurity professionals for the second year in a row. However, the group also warned that the size of the workforce is still 65% below what it needs to be, with demand growing everywhere but APAC.

For 2022, Forrester also predicted that 60% of security incidents would result from problems with third parties as supply chains expand to help firms better manage risk and plan contingencies.

To help mitigate these challenges, organizations will increasingly embed cybersecurity policies into third-party contracts, the analyst claimed.

“Before signing new and renewing existing suppliers, organizations will demand policies embedded in their contracts stipulating that the partner assumes the risk of an intruder jumping from the partner’s to the organization’s environment,” it explained.

“Smaller policies reduce exposure for cyber-insurers, while also reducing the policyholder’s risk of working with new and existing suppliers with varying cybersecurity postures. Expect thorough scrutiny of your third-party risk program and supplier tiers if buying these policies.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Misconfigured Database Leaks 880 Million Medical Records

Misconfigured Database Leaks 880 Million Medical Records

Researchers have found an unsecured database leaking over 886 million patient records online, although it’s now confirmed that this was dummy data.

The non-password-protected data trove was found by Jeremiah Fowler and Website Planet and traced to healthcare AI firm Deep 6 AI, which fixed the privacy snafu promptly after it was responsibly disclosed.

Deep 6 AI applies intelligent algorithms to medical data to help find patients for clinical trials within minutes.

The exposed data included the date, document type, physician note, encounter IDs, patient ID, note, UUID, patient type, note ID, date of service, note type and detailed note text.

The notes and physician information were stored in plain text. Patient IDs were encrypted, but it’s unclear how strongly. 

However, a statement from Deep 6 AI sent to Infosecurity clarified that no patients were affected by the exposure.

“In August, a security researcher accessed a test environment that contained dummy data from MIT’s Medical Information Mart of Intensive Care (MIMIC) system, an industry-standard source for de-identified health-related test data. To confirm, no real patient data or records were included in this ephemeral test environment, and it was completely isolated from our production systems,” the statement noted.

“Based on current reporting, we have confirmed that the recent claims reference MIMIC data, and there was no access to real patient records. When the researcher notified us in August, we immediately secured the test environment to ensure there was no further concern.”

According to IBM, healthcare remains way out in front in sectors with the highest average breach costs. They rose by nearly 30% over the past year to top $9.2m per incident.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Suspected Trickbot Malware Developer Faces 60 Years in Jail

Suspected Trickbot Malware Developer Faces 60 Years in Jail

A suspected member of the infamous Trickbot group has been extradited to the US, where he faces decades behind bars if found guilty.

Russian national Vladimir Dunaev, 38, made his first appearance in a federal court on Thursday after being extradited from South Korea to the Northern District of Ohio.

He’s accused of working with others to steal money and sensitive information and infecting millions of computer systems from a range of victim organizations and individuals with Trickbot malware.

Specifically, Dunaev is said to have been a malware developer for the loose coalition of freelance programmers – a role that allegedly involved managing the execution of the malware, developing popular browser modifications and helping to conceal the malware from detection by security software.

Trickbot deployed web injects and keystroke logging to steal online banking credentials, credit card numbers, emails, passwords, dates of birth, social security numbers and addresses from compromised machines, according to the Department of Justice (DoJ).

It said that hijacked bank accounts weren’t only used as a source of funds but also to launder money.

“The Trickbot malware was designed to steal the personal and financial information of millions of people around the world, thereby causing extensive financial harm and inflicting significant damage to critical infrastructure within the United States and abroad,” said acting US attorney Bridget Brennan of the Northern District of Ohio.

“Today’s announcement underscores the great lengths federal law enforcement officials and our international partners will go to hold these alleged cyber-criminals accountable for their actions.”

Although not mentioned in the DoJ release, Trickbot was also used extensively to provide initial access into victim machines — this access was then sold to ransomware actors and others, who used it to deploy Ryuk, Conti and other variants.

According to the court documents, Dunaev and his co-conspirators worked from November 2015 to August 2020.

He’s charged with conspiracy to commit computer fraud and aggravated identity theft; conspiracy to commit wire and bank fraud; conspiracy to commit money laundering; and multiple counts of wire fraud, bank fraud, and aggravated identity theft. If convicted, Dunaev faces a maximum of 60 years behind bars.

His extradition comes several months after 55-year-old Latvian, Alla Witte, was charged with multiple counts for her alleged role in developing the Trickbot malware.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Data Breach at University of Colorado

Data Breach at University of Colorado

An American university is notifying thousands of former and current students that their personal information may have been compromised during a recent data breach.

In a security notice issued October 25, the University of Colorado Boulder (CU Boulder) attributed the breach to an unpatched vulnerability in software provided by a third-party vendor, Atlassian Corporation Plc.

Atlassian is an Australian software company headquartered in Sydney that develops products for software developers, project managers and other software development teams. 

CU Boulder said that the flaw “impacted a program used mostly by the Office of Information Technology (OIT) to share resources, such as support and procedural documents, configuration files and collaborative documents.”

Some files stored in the impacted program contained personally identifiable information (PII) for current and former CU Boulder students. Included in that information were names, student ID numbers, addresses, dates of birth, phone numbers, and genders.

No Social Security numbers or financial information was exposed during the security incident. 

“An analysis by the Office of Information Security revealed some data stored in the program was accessed by an attacker,” said CU Boulder.

Atlassian released a patch for the flaw on August 25. Since the incident, OIT has upgraded the software to the latest version, which is not susceptible to the vulnerability that the attacker exploited.

CU Boulder said that the Office was testing the new version and preparing to implement it when the intrusion occurred.

The university said that most of the roughly 30,000 individuals whose data may have been compromised in the incident are no longer affiliated with CU Boulder as a student or employee. Victims are being notified by the university via email. 

Dan Jones, associate vice chancellor for integrity, safety and compliance at the university, said campus officials did not know who was behind the cyber-attack. 

“Monitoring services will be made available at no cost for individuals whose confidentiality may have been compromised,” said CU Boulder.

The university said that the data breach was not connected to the cyber-attack on CU’s Accellion service earlier this year, which compromised information in 310,000 files, including student data and medical information.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cops Receive Stalkerware Training

Cops Receive Stalkerware Training

Members of the Coalition Against Stalkerware are helping law enforcement agencies to investigate cases involving digital stalking.

The Coalition was created in 2019 by ten founding partners: Avira, Electronic Frontier Foundation (EFF), European Network for the Work with Perpetrators of Domestic Violence (WWP EN), G DATA Cyber Defense, Kaspersky, Malwarebytes, the United States–based National Network to End Domestic Violence (NNEDV), NortonLifeLock, Operation Safe Escape, and WEISSER RING.

Earlier this week, Coalition members NNEDV and Kaspersky joined forces with INTERPOL and Australia’s national umbrella organization for domestic violence services, Wesnet, to arrange two online training sessions addressing issues of digital stalking and domestic violence. 

Kaspersky said that the goal of the online training, which involved more than 210 participants, was “to enhance capacity building within law enforcement agencies, support victims requesting assistance, and hold perpetrators to account.”

According to Kaspersky’s State of Stalkerware 2020 report, 53,870 mobile users worldwide were affected by stalkerware in 2020. The commercially available software invades victims’ privacy by providing personal data such as device location, browser history, text messages, social media chats, photos and more to their stalker. 

Wesnet chief executive officer Karen Bentley said cyber-stalking was among the most common forms of abuse to co-occur with domestic and family violence, and was associated with an increased likelihood of lethal and near-lethal harm.

“Digital stalking is an issue known to the global law enforcement community, but there is a need to enhance capabilities around how to conduct investigations on stalkerware,” said Pei Ling Lee, acting assistant director of cyber strategy and capabilities development at INTERPOL. “The software hides itself, and investigations need to be undertaken carefully for the safety of the victims.”

In the online training sessions, law enforcement officers learned about stalkerware and its installation methods along with different ways to detect it without compromising the safety of a victim. They were also introduced to the free anti-stalkerware scanning app TinyCheck.

Earlier this month, the Coalition Against Stalkerware received the J.D. Falk Award for its work raising awareness, increasing detection, and combating the spread of malware used for stalking and intimate partner abuse.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Google Chrome is Abused to Deliver Malware as ‘Legit’ Win 10 App

Malware delivered via a compromised website on Chrome browsers can bypass User Account Controls to infect systems and steal sensitive data, such as credentials and cryptocurrency.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Friday Squid Blogging: Squid Game Has a Cryptocurrency

In what maybe peak hype, Squid Game has its own cryptocurrency. Not in the fictional show, but in real life.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains