Ghanaian Women Cautioned Against Sharing Nudes

Ghanaian Women Cautioned Against Sharing Nudes

A cybersecurity official in the Ghanaian police force has cautioned women and girls against using digital devices to take and share intimate pictures. 

The assistant commissioner of police, Dr. Gustav Herbert Yankson, who is the director of the Cybercrime Unit at the CID Headquarters of the Ghana Police Service, gave the warning while speaking at an event in Accra that commemorated the 2021 International Day of the Girl Child.

“Do not take nude pictures or videos of yourself and do not share such contents to your partner, not even your husband,” said Yankson. 

“The problem is the phone could be hacked, stolen or get damaged and may need to be taken to the repair shop, and before you know it, your nudity is circulating everywhere.”

Sharing nudes online, including on social media platforms, can result in a fine of between $5,200 and $10,000 for Ghanaians.

Under the country’s Cybersecurity Act 2020, an individual who publishes indecent images of children or adults can be imprisoned for up to 25 years. 

The law also stipulates that an individual convicted of threatening to circulate a victim’s nude photos or videos unless they receive a payment from the victim can be sentenced to between 10 and 25 years in prison. 

In April, Ghanaian actress Akuapem Poloo was sentenced to 90 days in prison for the publication of “obscene material and domestic violence.”

Police arrested Poloo over a picture that she posted to her Instagram feed in June 2020. The image showed Poloo taking a bath with her seven-year-old son.

It was accompanied by the message: “I’m naked in front of you because this is how naked I was giving birth to you, so in case you find me naked lying somewhere don’t pass by me but rather see me as your mom who brought you to life. Happy birthday to you @sonof_poloo.”

In an interview with Onua TV’s Captain Smart, the actress said she did not realize what she had done was a crime and had never heard of anyone being arrested for it. 

“When we were children, we bathed with our mothers. I saw my mother’s nakedness,” said Poloo. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ultimatum for Booter Service Users

Ultimatum for Booter Service Users

Dutch police have written to customers of an on-demand booter service to dissuade them from committing cybercrimes.

Booter services, also known as booters, are on-demand DDoS (Distributed-Denial-of-Service) attack services that can be used to bring down websites and networks by overloading or “stressing” IP addresses with data traffic. 

During an ongoing investigation into www.minesearch.rip, Dutch police discovered the details of 29 individuals who had purchased booter services offered for sale on the website. 

In an attempt to deter the site’s customers from launching DDoS attacks, the police took the civilized action of writing to them, warning them to stop using the service or face prosecution.

In a statement issued October 11, the police wrote: “The letter recipients – from all over the country – are associated with a purchase on the website www.minesearch.rip, where illegal DDoS attacks were sold. 

“The aim of the letter is to inform the recipients about the criminality and consequences and also to offer them alternatives.”

Recipients were told that committing cybercrimes could result in “a conviction, criminal record and the loss of your computer and/or laptop.”

The letter read: “We have registered you in our system and you will now receive a final warning. If new similar facts arise in the future, we will prosecute.”

The letter goes on to encourage the booter buyers to “improve your skills in a legal way,” and lists websites including HackTheBox, which gives hackers the chance to win prizes while building up their cybersecurity skills. 

“Not only can companies lose customers and/or revenue,” said the police, but “a DDoS attack can also have major social, disruptive consequences. Companies also often incur considerable financial damage due to the repair costs.”

Dutch police began investigating www.minesearch.rip last year after receiving a report from a game server hosting platform that was struck by a DDoS attack originating from the site.  

“In addition, dozens of reports were received from other companies and authorities,” stated the police. 

On July 30, 2020, the police searched the homes of two 19-year-old men who are suspected of being involved with the website and seized electronic devices, including computers and cellphones.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

University of Sunderland Hit by Suspected Cyber-Attack

University of Sunderland Hit by Suspected Cyber-Attack

A UK university has suffered a suspected cyber-attack, causing “extensive IT issues.”

The University of Sunderland revealed the incident on its official Twitter account this morning, which stated: “our telephone lines, website and IT systems are still down.” The institution first reported it was experiencing IT problems yesterday (12 October) and has now said it “has all the hallmarks of a cyber-attack.”

A local newspaper, the Sunderland Echo, reported that all online classes had been canceled, and staff members faced difficulties accessing their emails. In addition, the University of Sunderland’s official website remains down.

The university said that it is working with the police to try and resolve the problem and will continue face-to-face teaching as much as possible.

The full statement read: “We intend to continue face to face teaching as far as possible and will continue to update our staff and students, as well as continue working with the police.

“We take the security of our systems extremely seriously and we will resolve this as quickly as we can. We ask that prospective students direct message any inquiries in the meantime and that current students email universitysunderland.enquiries@gmail.com.

“Thank you for your patience.”

The suspected cyber-incident follows a surge of attacks targeting schools, universities and colleges during the COVID-19 crisis. These include damaging attacks on two other universities in the North-East of England last year, Newcastle University and Northumbria University. And in April 2021, the University of Hertfordshire and the University of Portsmouth suffered network outages lasting days after ransomware threat actors struck.

It appears cyber-criminals view this sector as an easier target following digital transformation efforts during the pandemic, including the shift to remote learning. In July, the UK’s National Cyber Security Centre (NCSC) updated its guidance on ransomware following a spate of attacks on the education sector.

Commenting on the story, Danny Lopez, CEO at Glasswall Solutions, said: “Reports of universities being the victim of cyber-attacks have become increasingly common over the last 18-months. It’s concerning considering the extensive damage caused by lost data – for both students and staff – and access to vital educational services. The cyber-attack will inevitably have a significant impact on productivity. In addition, just as the new university term begins, students and staff have lost access to their campus network, which will undoubtedly affect teaching and access to study resources. 

“Educational institutions should adopt a ‘defense-in-depth’ approach to cybersecurity, as advised by the NCSC. This means using multiple layers of defense with several mitigations, which creates more opportunities to detect malware and prevent it from doing widespread harm to the institution.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Password-Stealing Attacks Surge 45% in Six Months

Password-Stealing Attacks Surge 45% in Six Months

Attacks using password-stealing malware have surged by 45% over the past six months, highlighting the continued need for additional log-in security measures, according to Kaspersky.

The Russian AV vendor analyzed incidents of Trojan-PSW – a specialized stealer capable of gathering login and other account information.

It noted 160,000 more targets in September 2021 than April, with the total number reaching nearly half a million. That’s an increase of 45%.

“As statistics show, logins, passwords, payment details and other personal data continue to be an attractive target for cyber-criminals and they remain a popular commodity on the dark market,” explained Kaspersky security expert, Denis Parinov.

“For this reason, we encourage internet users to take extra steps to protect your accounts. For example, by using multi-factor authentication (MFA) methods. Increased scammer activity using password stealers also suggests the need for users to be more careful, not to follow unverified links and to use an updated security solution.”

Most US insurers now mandate MFA as a minimum security standard to qualify for coverage. In fact, last month, it was revealed that the tech CEOs who met President Biden for a recent White House summit claimed MFA could thwart as much as 90% of attacks.

However, it’s not a panacea. One-time passwords generated by text message can be intercepted via SIM swapping and other techniques. For that reason, Microsoft last year urged organizations to move away from MFA methods relying on phone networks and towards authentication apps.

Kaspersky has also seen a sharp rise in overall attempts to compromise users. It noted an increase from 24.8 million attempts in Q3 2020 to 25.5 million in the third quarter of 2021, a rise of almost 30%.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft Patches Multiple Zero-Day Bugs

Microsoft Patches Multiple Zero-Day Bugs

Microsoft fixed 74 new CVEs yesterday, including several zero-day vulnerabilities, one of which is being actively exploited in the wild.

Zero-day bug CVE-2021-40449 is a Win32k elevation of privilege vulnerability in Windows affecting Windows 7 and Server 2008 up to Windows 11 and Server 2022. It has reportedly been exploited by Chinese threat actors known as “IronHusky.”

“Microsoft only rated the vulnerability as “important” by their severity scoring system, which is a good example of why organizations need to focus on vulnerability remediation based on risk,” argued Ivanti senior director of product management, Chris Goettl.

“A risk-based approach to vulnerability management takes into account more real-world indicators such as known exploited, public disclosure, and usage trends by threat actors to better understand what exposures you should be focusing on first.”

Microsoft also fixed three publicly disclosed (zero-day) flaws which have had proof-of-concept code released, giving attackers a head-start in crafting exploits for them.

These are CVE-2021-41338, a security feature bypass vulnerability in Windows AppContainer Firewall; Windows kernel elevation of privilege bug CVE-2021-41335; and Windows DNS remote code execution vulnerability CVE-2021-40469.

There was also an updated fix for CVE-2021-33781, a security feature bypass flaw in Azure AD. This vulnerability was initially resolved in the July Patch Tuesday but has been updated to fix Windows 10 v1607, Server 2016 and Windows 11.

Elsewhere, Adobe updated Acrobat, Reader, Connect, Reader Mobile, Commerce, Campaign Standard and ops-cli.

“The updates for Adobe Connect (APSB21-91) and ops-cli (APSB21-88) include critical CVEs with a CVSS base score of 9.8 out of 10,” explained Goettl.

“Adobe Acrobat and Reader (APSB21-104) resolves the most CVEs out of the line-up. A total of four CVEs, two of which are rated as Critical with CVSS scores of 7.8 were resolved in this update.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Customers On Alert as E-Commerce Player Leaks 1.7+ Billion Records

Customers On Alert as E-Commerce Player Leaks 1.7+ Billion Records

A Brazilian e-commerce firm has unwittingly exposed close to 1.8 billion records, including customers’ and sellers’ personal information, after misconfiguring an Elasticsearch server, according to researchers.

A team at SafetyDetectives led by Anurag Sen made the discovery in June and quickly traced the leak back to Hariexpress — a firm that allows vendors to manage and automate their activity across multiple marketplaces, including Facebook and Amazon.

Although the firm replied to the researchers just four days after they alerted it to the leak in early July, it was subsequently uncontactable. Infosecurity is currently trying to confirm if the issue has been fixed or not.

The server was left unencrypted with no password protection in place. It contained 610GB of data, including customers’ full names, home and delivery addresses, phone numbers and billing details. Also exposed were sellers’ full names, email and business/home addresses, phone numbers and business/tax IDs (CNPJ/CPF).

SafetyDetectives could not confirm the total number of those affected due to the size of the trove and the potential for duplicate email addresses.

“A data breach of this magnitude could easily affect hundreds of thousands, if not millions of Brazilian Hariexpress users and e-commerce shoppers. Hariexpress’ leaked server’s content could also affect its own business,” it claimed.

“We cannot know whether unethical hackers have discovered Hariexpress’ unsecured Elasticsearch server. Users, couriers, consumers, and Hariexpress itself should understand the risks they could face from this data breach.”

These include phishing and social engineering attempts built around legitimate user and business details, tax rebate and returns scams using CPF information, and even theft of items from the homes of customers who ordered high-value goods.

There’s also a potential for digital extortion in cases where customers have bought potentially embarrassing items. The researchers highlighted one anonymous shopper who purchased a “penis pump,” for example.

Brazil’s data protection law, the Lei Geral de Proteção de Dados (LGPD), apparently gives regulators the power to fine companies a maximum of 2% of the previous year’s revenue for serious infractions, up to 50 million Brazilian reals ($10m).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Security Serious Unsung Heroes 2021 Winners Announced

Security Serious Unsung Heroes 2021 Winners Announced

The winners of the sixth annual Security Serious Unsung Heroes Awards were unveiled last night during an entertaining ceremony at St. Bart’s Brewery in London.

The lively event was compered by award-winning screenwriter, author, comedian, actor and worldwide speaker on fraud and identity theft, Bennett Arron. Last year’s ceremony was streamed virtually due to the COVID-19 pandemic.

The awards are designed to recognize the efforts of UK cybersecurity professionals and teams in helping advance the country’s cyber protections and raise awareness of security issues.

Yvonne Eskenzi, lead organiser of Security Serious Week and co-founder of Eskenzi PR, commented: “Cybersecurity and the people within this industry are often not given the recognition and appreciation they deserve.

“By hosting this event, we are shining a light on all the hard work that goes on behind the scenes to protect organizations from the threat of cybercrime. Thanks to our fantastic sponsors, we were able to host an amazing party at no charge to our attendees and acknowledge all the incredible and talented people in this industry!”

The judging panel for the awards was comprised of Brian Higgins from Comparitech, Oliver Pickup, award-winning writer,  Yvonne Eskenzi and Infosecurity Magazine‘s very own editor, Eleanor Dallaway.

The winners across all categories were as follows:

  • Cyber Writer – Andy Gill
  • Best Security Awareness Campaign – Talion RansomAware
  • Data Guardian – Emily Overton
  • Best Educator – Winner: Jackie Riley; Highly Commended: Lorna Armitage and Andrea Cullen, CAPSLOCK
  • Godfather/Godmother of Security –  Colonel John Doody
  • Best Ethical Hacker / Pentester – Dale Pavey and Guy Morley from NCC Group
  • Apprentice/Rising Star – Winner: Jenny Codes; Highly Commended: Daniel Dodds
  • Security Leader/Mentor – Marilise de Villiers
  • Security Avengers – Winner: CyberNews Research Team; Highly Commended:  Sainsbury’s
  • CISO Supremo – Alison Dyer

After being crowned ‘Godfather of Security’, Colonel John Doody said: “I am emotionally overwhelmed and humbled to be selected for this prestigious award. I am in my 63rd year in the profession, including my total commitment to the national cybersecurity posture, and will continue to serve the nation as long as I am able. Cybersecurity is the biggest growth profession in the UK and I am so privileged to be recognized for my dedicated evangelism on the subject.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains