30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware

The previously unknown SnapMC group exploits unpatched VPNs and webserver apps to breach systems and carry out quick-hit extortion in less time than it takes to order a pizza.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Suing Infrastructure Companies for Copyright Violations

It’s a matter of going after those with deep pockets. From Wired:

Cloudflare was sued in November 2018 by Mon Cheri Bridals and Maggie Sottero Designs, two wedding dress manufacturers and sellers that alleged Cloudflare was guilty of contributory copyright infringement because it didn’t terminate services for websites that infringed on the dressmakers’ copyrighted designs….

[Judge] Chhabria noted that the dressmakers have been harmed “by the proliferation of counterfeit retailers that sell knock-off dresses using the plaintiffs’ copyrighted images” and that they have “gone after the infringers in a range of actions, but to no avail — every time a website is successfully shut down, a new one takes its place.” Chhabria continued, “In an effort to more effectively stamp out infringement, the plaintiffs now go after a service common to many of the infringers: Cloudflare. The plaintiffs claim that Cloudflare contributes to the underlying copyright infringement by providing infringers with caching, content delivery, and security services. Because a reasonable jury could not — at least on this record — conclude that Cloudflare materially contributes to the underlying copyright infringement, the plaintiffs’ motion for summary judgment is denied and Cloudflare’s motion for summary judgment is granted.”

I was an expert witness for Cloudflare in this case, basically explaining to the court how the service works.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Top Signs of Identity Theft

When it comes to identity theft, trust your gut when something doesn’t feel right. Follow up. What you’re seeing could be a sign of identity theft. 

A missing bill or a mysterious charge on your credit card could be the tip of an identity theft iceberg, one that can run deep if left unaddressed. Here, we’ll look at several signs of identity theft that likely need some investigation and the steps you can take to take charge of the situation. 

How does identity theft happen in the first place? 

Unfortunately, it can happen in several ways.  

  • In the physical world, it can happen simply because you lost your wallet or debit card. However, there are also cases where someone gets your information by going through your mail or trash for bills and statements. In other more extreme cases, theft can happen by someone successfully registering a change of address form in your name (although the U.S. Postal Service has security measures in place that make this difficult).  
  • In the digital world, that’s where the avenues of identity theft blow wide open. It could come by way of a data breach, a thief “skimming” credit card information from a point-of-sale terminal, or by a dedicated crook piecing together various bits of personal information that have been gathered from social media, phishing attacks, or malware designed to harvest information. Additionally, thieves may eavesdrop on public Wi-Fi and steal information from people who’re shopping or banking online without the security of a VPN.   

Regardless of how crooks pull it off, identity theft is on the rise. According to the Federal Trade Commission (FTC), identity theft claims jumped up from roughly 650,000 claims in 2019 to nearly 1.4 million in 2020—practically double. Of the reported fraud cases where a dollar loss was reported, the FTC calls out the following top three contact methods for identity theft: 

  • Online ads that direct you to a scammer’s site are designed to steal your information. 
  • Malicious websites and apps also steal information when you use them. 
  • Social media scams lure you into providing personal information, whether through posts or direct messages. 

However, phone calls, texts, and email remain the most preferred contact methods that fraudsters use, even if they are less successful in creating dollar losses than malicious websites, ads, and social media. 

What are some signs of identity theft? 

Identity thieves leave a trail. With your identity in hand, they can charge things to one or more of your existing accounts—and if they have enough information about you, they can even create entirely new accounts in your name. Either way, once an identity thief strikes, you’re probably going to notice that something is wrong. Possible signs include: 

  • You start getting mail for accounts that you never opened.  
  • Statements or bills stop showing up from your legitimate accounts. 
  • You receive authentication messages for accounts you don’t recognize via email, text, or phone.  
  • Debt collectors contact you about an account you have no knowledge of. 
  • Unauthorized transactions, however large or small, show up in your bank or credit card statements. 
  • You apply for credit and get unexpectedly denied. 
  • And in extreme cases, you discover that someone else has filed a tax return in your name. 

As you can see, the signs of possible identity theft can run anywhere from, “Well, that’s strange …” to “OH NO!” However, the good news is that there are several ways to check if someone is using your identity before it becomes a problem – or before it becomes a big problem that gets out of hand.  

Steps to take if you suspect that you’re the victim of identity theft 

The point is that if you suspect fraud, you need to act right away. With identity theft becoming increasingly commonplace, many businesses, banks, and organizations have fraud reporting mechanisms in place that can assist you should you have any concerns. With that in mind, here are some immediate steps you can take: 

1) Notify the companies and institutions involved 

Whether you spot a curious charge on your bank statement or you discover what looks like a fraudulent account when you get your free credit report, let the bank or business involved know you suspect fraud. With a visit to their website, you can track down the appropriate number to call and get the investigation process started.  

2) File a police report 

Some businesses will require you to file a local police report to acquire a case number to complete your claim. Even beyond a business making such a request, filing a report is still a good idea. Identity theft is still theft and reporting it provides an official record of the incident. Should your case of identity theft lead to someone impersonating you or committing a crime in your name, filing a police report right away can help clear your name down the road. Be sure to save any evidence you have, like statements or documents that are associated with the theft. They can help clean up your record as well. 

3) Contact the Federal Trade Commission (FTC) 

The FTC’s identity theft website is a fantastic resource should you find yourself in need. Above and beyond simply reporting the theft, the FTC can provide you with a step-by-step recovery plan—and even walk you through the process if you create an account with them. Additionally, reporting theft to the FTC can prove helpful if debtors come knocking to collect on any bogus charges in your name. You can provide them with a copy of your FTC report and ask them to stop. 

4) Place a fraud alert and consider a credit freeze 

You can place a free one-year fraud alert with one of the major credit bureaus (Experian, TransUnion, Equifax), and they will notify the other two. A fraud alert will make it tougher for thieves to open accounts in your name, as it requires businesses to verify your identity before issuing new credit in your name. 

A credit freeze goes a step further. As the name implies, a freeze prohibits creditors from pulling your credit report, which is needed to approve credit. Such a freeze is in place until you lift it, and it will also apply to legitimate queries as well. Thus, if you intend to get a loan or new credit card while a freeze is in place, you’ll likely need to take extra measures to see that through. Contact each of the major credit bureaus (Experian, TransUnion, Equifax) to put a freeze in place or lift it when you’re ready. 

5) Dispute any discrepancies in your credit reports 

This can run the gamut from closing any false accounts that were set up in your name, removing bogus charges, and correcting information in your credit report such as phony addresses or contact information. With your FTC report, you can dispute these discrepancies and have the business correct the record. Be sure to ask for written confirmation and keep a record of all documents and conversations involved.  

6) Contact the IRS, if needed 

If you receive a notice from the IRS that someone used your identity to file a tax return in your name, follow the information provided by the IRS in the notice. From there, you can file an identity theft affidavit with the IRS. If the notice mentions that you were paid from an employer you don’t know, contact that employer as well and let them know of possible fraud—namely that someone has stolen your identity and that you don’t truly work for them. 

Also, be aware that the IRS has specific guidelines as to how and when they will contact you. As a rule, they will most likely contact you via physical mail delivered by the U.S. Postal Service. (They won’t call or apply harassing pressure tactics—only scammers do that.) Identity-based tax scams are a topic all of their own, and for more on it, you can check out this article on tax scams and how to avoid them. 

7) Continue to monitor your credit report, invoices, and statements 

Another downside of identity theft is that it can mark the start of a long, drawn-out affair. One instance of theft can possibly lead to another, so even what may appear to be an isolated bad charge on your credit card calls for keeping an eye on your identity. Many of the tools you would use up to this point still apply, such as checking up on your credit reports, maintaining fraud alerts as needed, and reviewing your accounts closely. 

Righting the wrongs of identity theft: deep breaths and an even keel 

Realizing that you’ve become a victim of identity theft carries plenty of emotion with it, which is understandable—the thief has stolen a part of you to get at your money, information, and even reputation. Once that initial rush of anger and surprise has passed, it’s time to get clinical and get busy. Think like a detective who’s building – and closing – a case. That’s exactly what you’re doing. Follow the steps, document each one, and build up your case file as you need. Staying cool, organized, and ready with an answer for any questions you’ll face in the process of restoring your identity will help you see things through. 

Once again, this is a good reminder that vigilance is the best defense against identity theft from happening in the first place. While there’s no absolute, sure-fire protection against it, there are several things you can do to lower the odds in your favor. And at the top of the list is keeping consistent tabs on what’s happening across your credit reports and accounts. 

The post Top Signs of Identity Theft appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

5 Ways to Get Kids Focused on Their Online Privacy

Kids engage online far differently than adults. Between group chats, social apps, and keeping up with digital trends, their interests, and attention spans constantly shift, which means online privacy concerns get sidelined.  

That’s why, throughout October—Cybersecurity Awareness Month—we will be doubling up on resources and insights your family needs to be safer and more secure online. Ready to roll? Here are a few ways to move online privacy center stage.   

5 ways to focus kids on privacy 

1. Safeguard the fun. 

Few things will put kids to sleep faster than talking with parents about online stuff like privacy. So, flip the script. Talk about the things they love online—shopping, TikTok, and friend groups. All that fun could come to a screeching halt should a bad actor get a hold of your child’s data. Establishing strong digital habits allows your child to protect what they enjoy including their Venmo account, video games, and midnight chatting. Doing simple things such as maximizing privacy settings on social networks, limiting their social circles to known friends, and refraining from oversharing, can dramatically improve digital privacy.  

2. Relationship = safety. 

We say it often: The best way to keep your kids safe online is a strong relationship. A healthy parent-child connection is at the heart of raising kids that can make good choices online. Connect with your child daily. Talk about what’s important to them. Listen. Ask them to show you their favorite apps. Soon, you’ll discover details about their online life and gain the trust you need to discuss difficult topics down the road.   

Layer up your protection.

Studies show that 88% of all data breaches are due to human error. For that reason, consider putting an extra layer of protection between your family and cyberspace. A few ways to do that:

3. Build your digital offense. 

A good offense is the best way to defend yourself against would-be criminals out to grab and misuse your data. Offensive tactics and habits include using strong passwords, maximizing privacy settings on social networks, using a VPN, and boosting security on the many IoT devices throughout your home 

4. Deep clean your digital house. 

Get in the habit of deep cleaning your technology and bring your kids into the routine. Here’s how: 

  •  Together, remove unused apps from all devices
  •  Add Two-Factor Authentication (2FA) to your account passwords
  •  Update all device software
  • Wipe social profiles (including posts) clean of personal or family information such as full names, school name, birthdate, age, address, phone number, email, or location patterns. Do it together and even throw in a few rewards.  

October: Level up family cybersecurity  

It’s hard to slow down and get serious about online privacy if you’ve never experienced a breach or online theft of some kind. However, chances are, the dark side of online living will impact your family before long. Ready to go deeper? Dig into these cyber security tips for every age and stage. 

The post 5 Ways to Get Kids Focused on Their Online Privacy appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

How Coinbase Phishers Steal One-Time Passwords

A recent phishing campaign targeting Coinbase users shows thieves are getting smarter about phishing one-time passwords (OTPs) needed to complete the login process. It also shows that phishers are attempting to sign up for new Coinbase accounts by the millions as part of an effort to identify email addresses that are already associated with active accounts.

A Google-translated version of the now-defunct Coinbase phishing site, coinbase.com.password-reset[.]com

Coinbase is the world’s second-largest cryptocurrency exchange, with roughly 68 million users from over 100 countries. The now-defunct phishing domain at issue — coinbase.com.password-reset[.]com — was targeting Italian Coinbase users (the site’s default language was Italian). And it was fairly successful, according to Alex Holden, founder of Milwaukee-based cybersecurity firm Hold Security.

Holden’s team managed to peer inside some poorly hidden file directories associated with that phishing site, including its administration page. That panel, pictured in the redacted screenshot below, indicated the phishing attacks netted at least 870 sets of credentials before the site was taken offline.

The Coinbase phishing panel.

Holden said each time a new victim submitted credentials at the Coinbase phishing site, the administrative panel would make a loud “ding” — presumably to alert whoever was at the keyboard on the other end of this phishing scam that they had a live one on the hook.

In each case, the phishers manually would push a button that caused the phishing site to ask visitors for more information, such as the one-time password from their mobile app.

“These guys have real-time capabilities of soliciting any input from the victim they need to get into their Coinbase account,” Holden said.

Pressing the “Send Info” button prompted visitors to supply additional personal information, including their name, date of birth, and street address. Armed with the target’s mobile number, they could also click “Send verification SMS” with a text message prompting them to text back a one-time code.

SIFTING COINBASE FOR ACTIVE USERS

Holden said the phishing group appears to have identified Italian Coinbase users by attempting to sign up new accounts under the email addresses of more than 2.5 million Italians. His team also managed to recover the username and password data that victims submitted to the site, and virtually all of the submitted email addresses ended in “.it”.

But the phishers in this case likely weren’t interested in registering any accounts. Rather, the bad guys understood that any attempts to sign up using an email address tied to an existing Coinbase account would fail. After doing that several million times, the phishers would then take the email addresses that failed new account signups and target them with Coinbase-themed phishing emails.

Holden’s data shows this phishing gang conducted hundreds of thousands of halfhearted account signup attempts daily. For example, on Oct. 10 the scammers checked more than 216,000 email addresses against Coinbase’s systems. The following day, they attempted to register 174,000 new Coinbase accounts.

In an emailed statement shared with KrebsOnSecurity, Coinbase said it takes “extensive security measures to ensure our platform and customer accounts remain as safe as possible.” Here’s the rest of their statement:

“Like all major online platforms, Coinbase sees attempted automated attacks performed on a regular basis. Coinbase is able to automatically neutralize the overwhelming majority of these attacks, using a mixture of in-house machine learning models and partnerships with industry-leading bot detection and abuse prevention vendors. We continuously tune these models to block new techniques as we discover them. Coinbase’s Threat Intelligence and Trust & Safety teams also work to monitor new automated abuse techniques, develop and apply mitigations, and aggressively pursue takedowns against malicious infrastructure. We recognize that attackers (and attack techniques) will continue to evolve, which is why we take a multi-layered approach to combating automated abuse.”

Last month, Coinbase disclosed that malicious hackers stole cryptocurrency from 6,000 customers after using a vulnerability to bypass the company’s SMS multi-factor authentication security feature.

“To conduct the attack, Coinbase says the attackers needed to know the customer’s email address, password, and phone number associated with their Coinbase account and have access to the victim’s email account,” Bleeping Computer’s Lawrence Abrams wrote. “While it is unknown how the threat actors gained access to this information, Coinbase believes it was through phishing campaigns targeting Coinbase customers to steal account credentials, which have become common.”

This phishing scheme is another example of how crooks are coming up with increasingly ingenious methods for circumventing popular multi-factor authentication options, such as one-time passwords. Last month, KrebsOnSecurity highlighted research into several new services based on Telegram-based bots that make it relatively easy for crooks to phish OTPs from targets using automated phone calls and text messages.These OTP phishing services all assume the customer already has the target’s login credentials through some means — such as through a phishing site like the one examined in this story.

Savvy readers here no doubt already know this, but to find the true domain referenced in a link, look to the right of “http(s)://” until you encounter the first slash (/). The domain directly to the left of that first slash is the true destination; anything that precedes the second dot to the left of that first slash is a subdomain and should be ignored for the purposes of determining the true domain name.

In the phishing domain at issue here — coinbase.com.password-reset[.]com — password-reset[.]com is the destination domain, and the “coinbase.com” is just an arbitrary subdomain of password-reset[.]com. However, when viewed in a mobile device, many visitors to such a domain may only see the subdomain portion of the URL in their mobile browser’s address bar.

The best advice to sidestep phishing scams is to avoid clicking on links that arrive unbidden in emails, text messages or other media. Most phishing scams invoke a temporal element that warns of dire consequences should you fail to respond or act quickly. If you’re unsure whether the message is legitimate, take a deep breath and visit the site or service in question manually — ideally, using a browser bookmark so as to avoid potential typosquatting sites.

Also, never provide any information in response to an unsolicited phone call. It doesn’t matter who claims to be calling: If you didn’t initiate the contact, hang up. Don’t put them on hold while you call your bank; the scammers can get around that, too. Just hang up. Then you can call your bank or wherever else you need.

By the way, when was the last time you reviewed your multi-factor settings and options at the various websites entrusted with your most precious personal and financial information? It might be worth paying a visit to 2fa.directory (formerly twofactorauth[.]org) for a checkup.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Nukegate CEO Imprisoned for Fraud

Nukegate CEO Imprisoned for Fraud

The former CEO of failed South Carolina electric and natural gas public utility SCANA Corporation (SCANA) has been sent to federal prison after pleading guilty to conspiracy to commit mail and wire fraud.

Evidence presented to a South Carolina Court showed that 66-year-old Kevin B. Marsh intentionally defrauded rate-payers while overseeing and managing SCANA’s operations. 

Marsh made false and materially misleading statements about the progress of the company’s building projects so that SCANA could obtain and keep rate increases imposed on its rate-paying customers and qualify for up to $2.2bn in tax credits.

One of the projects impacted by the fraud was the erection of two nuclear reactors at the V.C. Summer Nuclear Station in Fairfield County. Construction on the $10bn project began in 2013 but was abandoned in 2017 after delays and errors caused costs to skyrocket.

Court filings showed that Marsh stuck rigidly to stating that the project would be completed in 2020 and would therefore meet the deadline set to receive $1.4bn in federal tax credits. 

Prosecutors detailed how the former CEO and chairman of SCANA’s board of directors lied about the progress of the project repeatedly in calls, press releases, and presentations. 

“Due to this fraud, an $11 billion nuclear ghost town, paid for by SCANA investors and customers, now sits vacant in Jenkinsville, South Carolina,” said Acting US Attorney Rhett DeHart. 

The project’s failure, which became known as “Nukegate,” gutted SCANA and its subsidiary, South Carolina Electric & Gas, which were bought out by Dominion Energy of Virginia in 2019.

In February, Marsh pleaded guilty to conspiracy to commit wire and mail fraud and to obtaining property by false pretenses. He was sentenced on October 7 to two years in prison followed by three years of supervised release and fined $200K. Marsh has already paid $5m in restitution.

Felony guilty pleas have been obtained from SCANA’s former executive vice president Stephen Byrne and from Carl Churchman, former Westinghouse Electric Corporation vice president and the project director of the V.C. Summer Nuclear project. 

Jeffrey Benjamin, former Westinghouse Electric Company senior vice president, has been charged in a sixteen-count felony criminal indictment.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Google Creates Cybersecurity Action Team

Google Creates Cybersecurity Action Team

Google is bringing together a bevy of in-house experts to form a new cybersecurity advisory team.

In a statement released earlier today, Google announced the creation of its new Google Cybersecurity Action Team, which it says will have “the singular mission of supporting the security and digital transformation of governments, critical infrastructure, enterprises, and small businesses.”

In pursuit of this mission, the team will provide services in four key areas: strategic advisory, trust and compliance, security customer and solutions engineering, and threat intelligence and incident response. 

“Customers need a consistent approach to preparing for and defending against cybersecurity threats,” said Phil Venables, vice president and CISO at Google Cloud and founder of the Google Cybersecurity Action Team. 

“Our comprehensive suite of security solutions delivered through our platform and amplified by the Google Cybersecurity Action Team will help protect organizations against adverse cyber events with capabilities that address industry frameworks and standards.”

One of the new team’s jobs will be to advise customers on their security strategies, including educational content and transformation workshops. 

“This function will advise customers on the structure of their digital security transformation and provide program management and professional services support,” said Google.

Another role of the team will be to simplify customers’ “compliance journey” through trust and compliance services that map Google’s global compliance certifications to industry control frameworks.

The team will also be involved with the delivery of threat briefings, preparedness drills, incident support, and rapid response engagements.  

Rosa Smothers, former CIA cyber-threat analyst and technical intelligence officer, now a senior vice president at KnowBe4, told Infosecurity Magazine that the formation of the new Google team would help organizations tackle the rising threat of ransomware. 

“In light of the NSA director Nakasone’s recent remarks that within the next 5 years we’ll see ransomware attacks on a daily basis, this team can serve as a bulwark – a part of any company’s overarching defense in-depth strategy – against threat actors,” said Smothers.

She added: “This is a great opportunity for companies utilizing Google Cloud. The company takes their security seriously.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

RealDefense Acquires STOPzilla

RealDefense Acquires STOPzilla

Antivirus and anti-malware brand STOPzilla has been acquired by California holding company RealDefense

The deal was announced earlier today and marks RealDefense’s fourth acquisition in the security sector. Other brands in the RealDefense portfolio include IOLO, MyCleanID, MyCleanPC, USTechSupport, CyberDefender, VirusFix, and WarrantyStar.

To complete the acquisition of STOPzilla, RealDefense partnered with Corbel Capital Partners, a $500m structured debt firm based in Los Angeles.

STOPzilla was founded by iS3 Corporation in 2001 as a popup blocker. This initial program evolved into anti-malware software, and in the last few years, the company developed antivirus protection and STOPzilla Optimizer. 

The brand is based in Santa Monica, California, and states on its website that it has protected over 9 million users worldwide. 

STOPzilla’s AntiVirus program includes a web filter, scan module, enhanced malware detection engine, and smart file cache to defend against infection. STOPzilla’s AntiMalware works with the AntiVirus program to block, detect, and remove malware.

The brand’s Optimizer program promises to speed up PC performance and reduce system crashes by decluttering and performing advanced, automatic repairs plus system and registry backup. 

“For the last twenty years, it’s been an honor and privilege to provide an award-winning software product to users around the globe,” said Robert Scaduto, president and co-founder of STOPzilla. “STOPzilla customers are in great hands with an impressive RealDefense team.”

Also headquartered in Santa Monica, RealDefense provides device optimization/security software and remote desktop technical support services to customers globally. The company takes an active approach in managing operations at its portfolio companies and provides them with development and marketing support.

“We are excited to offer RealDefense’s suite of products to STOPzilla customers and continue to provide valuable privacy, security and optimization services,” said Gary Guseinov, CEO, RealDefense. “The STOPzilla team has done an amazing job building the company over the past 20 years and we are confident that we can continue to improve on the brand’s success.”

According to BusinessWire, in its most recent four acquisitions, RealDefense has achieved average revenue gains of 25% within the first 30 days.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains