—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Twitter Suspends Accounts Used to Snare Security Researchers
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
The Missouri Governor Doesn’t Understand Responsible Disclosure
The Missouri governor wants to prosecute the reporter who discovered a security vulnerability in a state’s website, and then reported it to the state.
The newspaper agreed to hold off publishing any story while the department fixed the problem and protected the private information of teachers around the state.
[…]
According to the Post-Dispatch, one of its reporters discovered the flaw in a web application allowing the public to search teacher certifications and credentials. No private information was publicly visible, but teacher Social Security numbers were contained in HTML source code of the pages.
The state removed the search tool after being notified of the issue by the Post-Dispatch. It was unclear how long the Social Security numbers had been vulnerable.
[…]
Chris Vickery, a California-based data security expert, told The Independent that it appears the department of education was “publishing data that it shouldn’t have been publishing.
“That’s not a crime for the journalists discovering it,” he said. “Putting Social Security numbers within HTML, even if it’s ‘non-display rendering’ HTML, is a stupid thing for the Missouri website to do and is a type of boneheaded mistake that has been around since day one of the Internet. No exploit, hacking or vulnerability is involved here.”
In explaining how he hopes the reporter and news organization will be prosecuted, [Gov.] Parson pointed to a state statute defining the crime of tampering with computer data. Vickery said that statute wouldn’t work in this instance because of a recent decision by the U.S. Supreme Court in the case of Van Buren v. United States.
One hopes that someone will calm the governor down.
Brian Krebs has more.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cyber-attack Response Takes More than Two Working Days
Cyber-attack Response Takes More than Two Working Days

Organizations around the world take on average more than two business days to respond to a cyber-attack, according to new research by American cybersecurity company Deep Instinct.
The finding was published in the company’s second bi-annual Voice of SecOps Report, which was based on a survey of 1,500 senior cybersecurity professionals in 11 countries who work for businesses with more than 1,000 employees and annual revenue north of $500m.
The survey revealed the average global response time to a cyber-assault to be 20.09 hours. Companies within the financial sector were faster to respond, taking on average 16 hours to react.
Larger companies also answered threats faster, clocking up an average response time of 15 hours. Smaller companies were found to be slower at responding, taking an average of 25 hours to make their move.
Other key findings in the report were that only 1% of those surveyed believed that every single one of their endpoints was installed with at least one security agent.
Just over a quarter (26%) cited “complexity” as the main thing impeding their ability to install more endpoint security agents. Others listed as key concerns the time it takes to investigate threats (39%) and a shortage of qualified SecOps staff (35%).
Nearly one-third of survey respondents hold the belief that the biggest challenge regarding deploying endpoint agents is the cloud. Files stored in the cloud were an unchecked vulnerability for 80% of respondents, while 68% were worried that their colleagues would accidentally upload malicious files.
The attack vector those surveyed were most concerned about was hidden persistence. This cyber-attack, where threat actors lurk in systems for prolonged periods without detection, was the biggest fear of 40% of respondents.
“The survey findings shed light on the multiple challenges that security teams face on a daily basis and provide insights into the serious needs that the industry needs to address,” said Guy Caspi, CEO of Deep Instinct.
“This research exposes gaps in organizations’ security posture, including a lack of full coverage on the endpoint, exposure in cloud storage, and malicious file uploads by internal sources into production systems.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Researchers Condemn Apple’s Proposed Phone-Scanning Features
Researchers Condemn Apple’s Proposed Phone-Scanning Features

Apple’s plans to implement new phone-scanning features have been heavily criticized by more than a dozen cybersecurity experts.
The tech company announced in August its intention to start scanning iPhone users’ iCloud Photos libraries. Apple presented the move under the pretext that it would locate users’ caches of illicit content, including child sexual abuse material (CSAM).
In September, after its plans to introduce the new technology were widely condemned, Apple said the launch of the phone-scanning feature would be delayed for an unspecified period while it took “additional time” to consult.
In a new 46-page study, cybersecurity experts concluded that Apple’s new monitoring plans were invasive and ineffective, and reliant upon “dangerous technology.”
After analyzing the technology involved in Apple’s plans, the researchers found that it was not effective at identifying images of children being sexually abused. Editing images just slightly was found to be enough to avoid detection.
“It’s allowing scanning of a personal private device without any probable cause for anything illegitimate being done,” said Susan Landau, one of the researchers and a professor of cybersecurity and policy at Tufts University.
“It’s extraordinarily dangerous. It’s dangerous for business, national security, for public safety and for privacy.”
Concerns over the technology’s use as a surveillance tool were raised by the group of researchers. They emphasized: “It should be a national-security priority to resist attempts to spy on and influence law-abiding citizens.”
Group member Ross Anderson, who is a professor of security engineering at the University of Cambridge, warned: “The expansion of the surveillance powers of the state really is passing a red line.”
The cybersecurity researchers said that documents released by the European Union suggest that the governing body is seeking to establish a similar independent program that would scan encrypted devices for content relating to terrorism, organized crime, or the sexual abuse of children.
The group, which began its study before Apple’s initial August announcement, said they were publishing their research now to warn the EU against implementing “dangerous technology.”
Apple’s Craig Federighi said that the company’s planned phone-scanning features had been “widely misunderstood.” The company has not yet commented on the cybersecurity researchers’ report.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Data Stolen from American Osteopath Group
Data Stolen from American Osteopath Group

The personal data of thousands of individuals have been stolen from a non-profit professional membership organization located in Illinois.
Cyber-thieves struck the American Osteopathic Association (AOA) in the summer of 2020, making off with information that included names, Social Security numbers, and financial account details.
The AOA, which is headquartered in Chicago, represents around 151,000 osteopathic physicians and medical students across the United States. The association was tipped off to the attack when suspicious activity was recorded on some of its systems on June 25 last year.
The network was shut down, and computer forensic specialists were brought in to investigate the nature and scope of the security incident. It was determined that attackers had managed to breach systems where personally identifiable information was contained and had exfiltrated data from those systems.
AOA undertook a review to establish what data had been accessed and which individuals had been impacted by the cyber-attack. As a result, it was concluded that the exfiltrated data included names, addresses, dates of birth, Social Security numbers, financial account information, and email addresses/usernames and passwords.
In a breach report submitted on October 13 to the state of Maine’s attorney general’s office, the AOA stated that 27,485 individuals, including 209 Maine residents, had been impacted by the incident.
The AOA has just begun mailing out breach notification letters to affected individuals, offering them a year of free credit monitoring.
A sample of the breach notice states that the total population of impacted individuals was determined by June 1, 2021. The delay in notifying those individuals is attributed in the letter to the coronavirus pandemic.
“Like many businesses, the COVID-19 pandemic presented considerable challenges to AOA’s normal business operations,” states the letter. “As a result, it has taken an extended time for AOA to identify the names and addresses of impacted individuals due to the pandemic’s impact on our staff’s working conditions, and their inability to be on location to identify all potentially impacted parties.”
The AOA said they were unaware of any actual or attempted malicious use of the stolen data in the cyber-attack.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Google Issues Customers 50,000+ Warnings of State-Backed Attacks
Google Issues Customers 50,000+ Warnings of State-Backed Attacks

Google has seen a 33% year-on-year spike in nation state attempts to compromise its customers so far in 2021, the tech giant revealed yesterday.
Security engineer Ajax Bash claimed that in the year-to-date, Google’s Threat Analysis Group (TAG) had sent over 50,000 warnings to customers that their account was the target of government-backed phishing or malware attempts.
The main reason for the increase in attacks was an “unusually large” campaign attributed to the notorious Kremlin-backed actor known as Fancy Bear (APT28).
“We intentionally send these warnings in batches to all users who may be at risk, rather than at the moment we detect the threat itself, so that attackers cannot track our defense strategies,” Bash explained.
“On any given day, TAG is tracking more than 270 targeted or government-backed attacker groups from more than 50 countries. This means that there is typically more than one threat actor behind the warnings.”
The news follows a similar update from Microsoft last week in which the tech giant revealed that Russia accounted for the majority (58%) of alerts it sent customers over the past year. APT29 (Cozy Bear) generated the vast majority (92%) of these notifications.
Microsoft said it had sent around 20,000 alerts relating to nation-state attacks, far fewer than Google’s tally over the past three years.
Google has been sending out these warnings for nearly a decade now and has an Advanced Protection Program for those who believe they may be a significant target, such as journalists and rights activists.
Also, in the blog post, Bash detailed the latest campaign from Iranian state group APT35, which tried last year to disrupt the US election by targeting Presidential campaign staff.
One of its tried-and-tested techniques is to compromise legitimate sites with phishing kits and send email messages to targets with links to those sites. It’s also been observed uploading spyware hidden in normal-seeming VPN software on Google Play.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
US Government Warns of Insider and Ransomware Threat to Water Plants
US Government Warns of Insider and Ransomware Threat to Water Plants

The US authorities have issued an alert warning of ongoing malicious cyber-activity targeting the country’s water and wastewater systems (WWS) sector.
The alert highlighted multiple tactics, techniques and procedures (TTPs) being used by a range of actors in an attempt to compromise IT and OT systems.
These include spear-phishing, exploitation of insecure RDP, targeting of unsupported or outdated operating systems and software, and exploitation of control system devices with vulnerable firmware.
The alert was issued by the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the National Security Agency (NSA).
It refers to multiple incidents over the past two years – mainly ransomware attacks, including a September 2020 attack on a New Jersey-based WWS facility, a March 2021 compromise at a Nevadan plant, and an August 2021 attack on a Californian WWS site.
Also mentioned is a notorious 2019 incident in which a former employee at a Kansas plant was able to access and shut down some of the key processes used to disinfect water with the intention of causing harm.
History repeated itself two years later when an actor gained unauthorized access to the IT network of a facility in Oldsmar, Florida, and tried to change the water supply’s chemical balance. It was subsequently revealed that it had left a critical SCADA system hooked up to a remote access tool, for which the password was never changed. The same credential was also reused across the facility.
However, the agencies were at pains to point out that the alert does not mean the WWS sector is being targeted more than other industries – merely that plant owners should be aware of ongoing cyber-risk to their operations.
“This activity – which includes attempts to compromise system integrity via unauthorized access – threatens the ability of WWS facilities to provide clean, potable water to, and effectively manage the wastewater of, their communities,” it noted.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Missouri Governor Slammed for Vow to Prosecute Researcher
Missouri Governor Slammed for Vow to Prosecute Researcher

Missouri governor Mike Parson has been widely criticized for seeking to prosecute news reporters who disclosed a vulnerability on a state education website.
The St. Louis Post-Dispatch published a story on Wednesday about how its team discovered a web app flaw on the site that leaked teacher information, including 100,000 Social Security numbers (SSNs).
The SSNs were apparently available in the site’s source code, available to anyone who wanted to right-click on the page.
The journalists reported the security snafu to the Missouri state Department of Elementary and Secondary Education (DESE), which fixed the issue before publication of the story.
However, that hasn’t stopped Parson from a bizarre tirade against the ‘hackers’ in a press conference and on Twitter, in which he vowed to prosecute them for “unlawfully” accessing the teacher data.
“This matter is serious. The state is committing to bring to justice anyone who hacked our system and anyone who aided or encouraged them to do so – in accordance with what Missouri law allows and requires,” he said on the social media site.
Through a multi-step process, an individual took the records of at least three educators, decoded the HTML source code, and viewed the SSN of those specific educators.
We notified the Cole County prosecutor and the Highway Patrol’s Digital Forensic Unit will investigate. pic.twitter.com/2hkZNI1wXE
— Governor Mike Parson (@GovParsonMO) October 14, 2021
“Under Missouri law, a person commits the offense of tampering with computer data if he or she knowingly and without authorization accesses, takes, and examines personal information without permission. This data was not freely available and had to be converted and decoded.”
The 66-year-old Republican signed off by stating: “We will not rest until we clearly understand the intentions of this individual and why they were targeting Missouri teachers.”
Parson’s claims that the ‘hackers’ were motivated by malicious intent is undermined by his revelation that they viewed the details of only three educators.
A stream of comments beneath the social media post derides the governor and his team’s lack of cyber-savvy and question their motives for attacking the media.
Jake Williams, CTO at BreachQuest, said organizations should, in general, avoid shooting the messenger where security vulnerabilities are concerned.
“This is certainly not hacking in any sense of the word. It appears that the reporter used a publicly available web application intended to facilitate searching for teacher certifications. When the results were displayed, the reporter simply viewed the source code of the web page and found the social security numbers,” he continued.
“While governor Parson said the reporter ‘decoded the HTML source code’ in reality they simply used the feature built into every web browser since the dawn of the internet. Because HTTP is stateless, many web applications store their status in hidden form fields so they can be passed from the browser back to the server with every request. It seems likely that these hidden form fields included the social security number of the teacher.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
LANtenna hack spies on your data from across the room! (Sort of)
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains