EU’s Green Pass Vaccination ID Private Key Leaked

UPDATE: French & Polish authorities found no sign of cryptographic compromise in the leak of the private key used to sign the vaccine passports and to create fake passes for Mickey Mouse and Adolf Hitler, et al.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

More Russian SVR Supply-Chain Attacks

Microsoft is reporting that the same attacker that was behind the SolarWinds breach — the Russian SVR, which Microsoft is calling Nobelium — is continuing with similar supply-chain attacks:

Nobelium has been attempting to replicate the approach it has used in past attacks by targeting organizations integral to the global IT supply chain. This time, it is attacking a different part of the supply chain: resellers and other technology service providers that customize, deploy and manage cloud services and other technologies on behalf of their customers. We believe Nobelium ultimately hopes to piggyback on any direct access that resellers may have to their customers’ IT systems and more easily impersonate an organization’s trusted technology partner to gain access to their downstream customers. We began observing this latest campaign in May 2021 and have been notifying impacted partners and customers while also developing new technical assistance and guidance for the reseller community. Since May, we have notified more than 140 resellers and technology service providers that have been targeted by Nobelium. We continue to investigate, but to date we believe as many as 14 of these resellers and service providers have been compromised. Fortunately, we have discovered this campaign during its early stages, and we are sharing these developments to help cloud service resellers, technology providers, and their customers take timely steps to help ensure Nobelium is not more successful.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Launches Appeal Against Assange Extradition Decision

US Launches Appeal Against Assange Extradition Decision

The United States government has launched an appeal against a UK court’s decision to refuse to extradite Wikileaks founder Julian Assange.

Australian citizen Assange, who is aged 50, was indicted by the US Department of Justice in 2019 over his alleged involvement in the acquisition and publication of thousands of classified US diplomatic and military documents.

The leaked documents related to the wars between the United States and Afghanistan, and between the United States and Iraq. 

The Trump administration sought Assange’s extradition to the US, where he faces 17 charges under the Espionage Act and one charge under the Computer Fraud and Abuse Act. 

In Westminster Magistrate’s court in January, District Judge Vanessa Baraitser blocked Assange’s extradition on mental health grounds. 

Baraitser made her judgement after hearing from Assange’s lawyer that the Wikileaks founder’s risk of suicide would be “imminent the moment extradition becomes likely.”

In July, Britain’s High Court granted the United States government permission to lodge an appeal against Baraitser’s January ruling. 

Now, the Biden administration has started a legal appeal to get Assange extradited to the United States and is arguing that earlier assessments of Assange’s mental health were wrong.

James Lewis QC, representing the US, told the Lord Chief Justice and Lord Justice Holroyde today that Judge Baraitser had been misled by Assange’s psychiatrist, Professor Michael Kopelman. 

Lewis said that Kopelman concealed Assange’s relationship with his fiancé, Stella Morris, and the existence of their two children – factors that may dissuade Assange from ending his life.

Lewis also said that the US had not been given an opportunity to answer the concerns for Assange’s safety that had been expressed by Baraitser.

Lawyers acting on behalf of the United States gave four binding assurances regarding the treatment of Assange. 

These included assurances that Assange would receive “any clinical and psychological treatment” that prison doctors recommended, and that the US would approve Assange’s application to serve a sentence in his native Australia. 

The United States also gave the insurance that it would not make Assange serve a custodial sentence in the United States Penitentiary, Administrative Maximum Facility (USP Florence ADMAX).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

India’s Supreme Court Orders Pegasus Probe

India’s Supreme Court Orders Pegasus Probe

India’s Supreme Court has ordered an investigation to determine whether Prime Minister Narendra Modi’s administration used spyware to illegally surveil opposition leaders, journalists, activists, tycoons, and judges.

In July, India’s main opposition Congress Party accused Modi of “treason” after the cell phone numbers of several Indian journalists, activists, and an opposition election strategist were included in a data leak of numbers believed to be of interest to clients of the Israel-based NSO Group Ltd., maker of the Pegasus spyware

Lawyer Tushar Mehta, representing the government, said in earlier hearings that any software used by Modi’s administration to “combat terrorism” could not be publicly named for security reasons. Mehta also denied that any illegal espionage had taken place. 

The Supreme Court accepted petitions to launch an independent investigation after the government offered “no specific denial” that it had used Pegasus software to spy on Indian citizens but instead offered to create an in-house committee to investigate the allegations. 

In the Supreme Court order, which was issued earlier today, Chief Justice N.V. Ramana said that the alleged use of Pegasus Software by the Indian government to surveil its citizens “raises an Orwellian concern,” and that the court was compelled to seek the truth in a matter in which citizens’ rights to privacy and free speech may have been violated. 

The order emphasized that while certain actions were permitted by the government on the grounds of national security, this argument was not a “free pass” that allowed any action to be taken.

The probe will be carried out by a panel that will be headed by a former Supreme Court judge and include experts in cybersecurity and criminal investigations. The panel has been given eight weeks to determine whether the government or its agencies acquired the Pegasus spyware and, if so, whether it was used to snoop on Indian citizens by listening to their conversations or accessing their private data. 

The panel has also been tasked with making recommendations on how suspicions of illegal surveillance should be handled and to suggest laws and procedures to better protect citizens’ right to privacy.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

EC-Council Offers Free Cybersecurity Training

EC-Council Offers Free Cybersecurity Training

The International Council of Electronic Commerce Consultants (EC-Council) has launched its first-ever MOOC certification series.

A MOOC, or massive open online course, is a training program that offers free education in an online environment, with no limit placed upon class size.

The EC-Council’s MOOC, which has been named the Essentials Series, is devoted to cybersecurity, and will offer certifications in network defense, ethical hacking, and digital forensics. Students will have access to eCourseware, video lectures, and lab tutorials.

EC-Council’s Academic Division announced the launch of the MOOC today and said that the series was designed to help students prepare to start an entry-level role in the information security and cybersecurity industries.

“The EC-Council Academia Division will now offer the Essentials Series, a free education series offering instructor-led and hybrid learning education courses for students and professionals alike,” said an EC-Council spokesperson.

The Essentials Series was developed by the same developers who created the widely recognized United States Department of Defense (DoD)–approved Certified Network Defender (CND), Certified Ethical Hacker (CEH), and Computer Hacking Forensic Investigator (CHFI) certifications.

Wesley Alvarez, director of academics within EC-Council’s office in Tampa, Florida, said: “The number of cybersecurity education programs and resources in today’s environment can be overwhelming to educators and students. It is hard to sort through what models and approaches are highly effective and align clearly to industry workforce roles and skills. 

“Our new approach with the Essentials Series teaches students self-paced essential cybersecurity topics in a nonthreatening environment that can be used independently or in the classroom.”

Course participants will be offered an option to upgrade their learning experience with cyber range technologies that will include challenges and flag submissions, cyber competitions, and industry certifications. 

“We want students on a career-based education track as they begin high school to learn the basics, but to also gain an understanding of their passion and skills while they are establishing confidence,” said Alvarez.

The EC-Council is headquartered in Albuquerque, New Mexico, and has certified over 237,000 professionals from 145 countries. The Council created the Certified Ethical Hacker (CEH) program, among other cybersecurity certifications.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

HM Treasury Hit by Five Million Malicious Emails in Past Three Years

HM Treasury Hit by Five Million Malicious Emails in Past Three Years

Her Majesty’s Treasury, the UK government department responsible for the nation’s economic policy, has been hit by nearly five million malicious email attacks in the past three years, according to official figures.

The data obtained by the think tank Parliament Street following a Freedom of Information (FoI) request showed that 4,870,389 phishing, malware and spam emails targeting HM Treasury were successfully blocked in this period.

This was comprised of 1,271,207 malicious email attacks from October 2018 to September 2019, 1,918,944 between October 2019 to September 2020, and 1,680 from October 2020 to September 2021.

The news comes as Chancellor Rishi Sunak prepares to deliver the UK government’s annual budget, which is expected to include pledges around cybersecurity, such as funding to reduce the digital skills gap.

The figures highlight the growing determination of cyber-criminals to access and steal confidential government data. Earlier this week, Parliament Street revealed that more than 126 million malicious emails had been fired at House of Commons inboxes this year, a 358% increase on the total figure for 2020.

There was no data on how many threats slipped past email filters over this period.

Commenting on the figures, Chris Ross, SVP International for Barracuda Networks, said: “The ever-present cyber threat facing public sector organizations is not going to disappear any time soon. In fact, recent trends indicate that cyber-attacks are likely to become more sophisticated, and criminals will find new ways to breach systems, disrupt apps and websites, and steal sensitive data.

“This is why it is imperative the organizations defend themselves from all angles, with web application firewalls, to protect cloud infrastructure and network, email inbox defense software, to help defend against the onslaught of phishing attacks targeting employees, and a third party data backup solution, to protect data and organizations against the growing ransomware threat.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

North Korean Lazarus APT Targets Software Supply Chain

North Korean Lazarus APT Targets Software Supply Chain

A notorious North Korean APT group has been observed compromising the software supply chain, in campaigns reminiscent of the attacks on SolarWinds and Kaseya, according to Kaspersky.

Lazarus infected legitimate South Korean security software to deploy a malicious payload to target a think tank in the Asian country, researchers explained. 

Used in the attack was an updated version of its BLINDINGCAN remote access Trojan (RAT) previously covered by the US authorities and a second RAT, dubbed COPPERHEDGE.

A second campaign saw Lazarus first target a Latvian IT asset monitoring solutions provider. Although it’s unclear whether there were any downstream victims, the attack involved using a downloader dubbed “Racket,” which was signed using a stolen certificate. Additionally, multiple vulnerable web servers were reportedly compromised at the firm, and malicious scripts were uploaded to control implants on breached machines.

Kaspersky also noted a renewed interest by Lazarus in the defense industry. In June, it spotted cyber-espionage attacks using the MATA framework, which works across three operating systems — Windows, Linux and macOS.

The attacks involved trojanized versions of apps in heavy use by the victim organizations, Kaspersky said.

“These recent developments highlight two things: Lazarus remains interested in the defense industry and is also looking to expand its capabilities with supply chain attacks,” said Ariel Jungheit, a senior security researcher at Kaspersky.

“When carried out successfully, supply chain attacks can cause devastating results, affecting much more than one organization – something we saw clearly with the SolarWinds attack last year. With threat actors investing in such capabilities, we need to stay vigilant and focus defense efforts on that front.”

A BlueVoyant report from earlier this month claimed that 93% of global organizations had suffered a direct breach via their supply chains over the past year. In fact, the number of breaches of this type surged by 37% from the previous year, it claimed.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ofcom’s Scam Call-Blocking Plan Could Save Consumers Millions

Ofcom’s Scam Call-Blocking Plan Could Save Consumers Millions

A plan by the UK telecoms regulator to block scam calls from abroad could save consumers nearly £10m annually in money lost to phone fraudsters, according to a new study from Comparitech.

Ofcom announced on Monday that the country’s telephone networks had agreed to block calls made from outside the UK but displaying as a domestic number — a common tactic used to add legitimacy to fraudulent calls.

It claimed one network has already introduced the measures, and others are looking at ways of following suit.

Comparitech decided to see what the value of the new strategy would be to consumers targeted by so-called “vishing” and other phone-based scams.

Ofcom last week revealed that 45 million Brits received fraudulent calls and texts over a recent three-month period, which equates to 180 million over the year.

Using Pindrop data, Comparitech calculated that roughly two-thirds (64%) of these are likely to have come from another country.

It then used Action Fraud data from April 2020 to March 2021, which revealed that the average victim of reported incidents loses £296. A Which? study claimed that only 10% of total incidents are actually reported to the UK’s national fraud reporting center.

That means the new Ofcom-led plan could prevent as many as 115 million scam calls per year and save consumers as much as £9.6m.

However, it will only be effective if used alongside other measures as part of a multi-layered approach, argued Comparitech privacy advocate Paul Bischoff.

“This includes these recent regulations from Ofcom, third-party apps that enable call blocking, and initiatives from service providers to combat spam calls,” he explained.

“However, implementing effective network-level call screening would require upgrades to old copper-line infrastructure (something the UK is still heavily reliant on) — and that’s an investment that providers won’t make if they don’t have to.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Digital Extortionists DDoS VoIP Providers

Digital Extortionists DDoS VoIP Providers

A trade body has warned of a major DDoS attack campaign designed to extort money from global Voice over IP (VoIP) providers.

Comms Council UK, which represents over 100 VoIP providers, said “several” of its members and international providers had been hit over the past four weeks as part of a coordinated extortion campaign by professional cyber-criminals.

“As our members supply telecoms services to critical infrastructure organizations including the police, NHS and other public services, attacks on our members are attacks on the foundations of UK infrastructure,” it claimed in a brief statement yesterday.

There were no further technical details about the nature of the DDoS attacks, although a spokesperson told the BBC that the attacks were on an “unprecedented” scale and that the entire global industry was under threat.

“We are liaising closely with the UK government, National Cyber Security Centre (NCSC), Ofcom and international agencies to share information and details about the nature of the attacks in the expectation of halting this criminal activity as quickly as possible,” the statement continued.

“We are confident that, with a joined-up government-led initiative, this damaging criminal activity can be halted.”

ESET cybersecurity specialist, Jake Moore, explained that DDoS could be used in the same way as ransomware, even if the latter appears to have become more popular of late.

“The malicious actors behind this appear to be using their attacks against these firms as an example to threaten other VoIP providers with similar attacks unless they agree to paying a huge ransom. However, paying ransoms provides no guarantee it will stop, and this could even increase the demands,” he continued.

“As more IoT devices come online with weak or no protection, more devices will be exploited and used in huge networks targeting their chosen victims.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains