Don’t Let Old Accounts Haunt You: How to Maintain Your Digital Graveyard

What was the first online service that you signed up for? Perhaps it was your middle school email address (“soccerloveR1450@hotmail.com” anyone?) or your very first Tumblr or Myspace account. Whatever it was, it’s likely that you haven’t used these accounts in years — but did you ever actually delete the account?  

Over the past decade, you’ve likely collected various online accounts that you no longer use. But just because you stop using an account doesn’t mean that it doesn’t exist — and your data is likely still floating around on the World Wide Web. These old “zombie” accounts haunt your digital graveyard and are easy pickings for cybercriminals.   

The Haunting of Accounts Past 

Today, most websites and apps either require or strongly encourage their visitors to create user accounts. Almost always, exchanging an email address for an exclusive offer seems a fair tradeoff.  As a result, consumers quickly accumulate accounts, many of which they may not even remember creating.  

According to Digital Guardian, 70% of consumers have more than 10 password-protected online accounts, and 30% have too many to keep track of. These accounts are comprised of free trials, stores that you no longer purchase from, one-time accounts that you create to buy something, gaming platforms, and apps that you only used a few times. While they may have once served a purpose, you no longer need them.   

The problem with zombie accounts is that they contain credentials at risk of exposure. Say that you sign up for a free week trial of a meal kit delivery service. When creating your account, you include information like your email address, password, phone number, delivery address, and credit card information. Once your trial expires, you decide not to sign up for a membership, but your account information remains online. If the meal kit company is involved in a data breach, your personal data could be leaked and exploited by cybercriminals. And if you happen to reuse the same credentials across multiple accounts, a criminal could use credential stuffing techniques (where they use email and password combinations to hack into online profiles) to break into your other accounts.  

How to Gain Control of Your Data  

So, how can you keep protect your online data and prevent a zombie account apocalypse? Follow these cybersecurity best practices to help keep your information secure:  

Track down and close old accounts 

Don’t remember which accounts you made and no longer use? No worries! If you browse with Google Chrome, check under chrome > settings > passwords. This will show all the accounts and passwords you’ve used and saved. Other browsers like Firefox and Safari have similar settings. If you use a password manager, this will also keep a record of your credentials. Once you’ve identified the online accounts you no longer used (or completely forgot you had), close the account for good! This may take some patience, as some websites require multiple steps to close an account. But it will be worth knowing that your information is safer from online exposure.  

Make sure all your passwords are strong and unique 

Having a strong, unique password for each of your online accounts helps protect them from credential stuffing. By using different passwords for your online accounts, you can take comfort in knowing that the majority of your data is secure if one of your accounts is vulnerable.   

Update your credentials when necessary 

If you realize a company you buy from fell victim to a data breach, start investigating. A tool like McAfee Identity Protection Service can help you monitor multiple email addresses that allow you to see if you were impacted by a breach. If your credentials were potentially exposed, update them on the company’s website immediately.  

Use multifactor authentication 

Multifactor authentication is an online safety measure where more than one method of identity verification is needed to access the valuable information that lies within password-protected accounts. This can prevent a criminal from breaking into your online profile by providing an added layer of security.  

Invest in protection 

McAfee Total Protection will help protect your personal information and privacy and provides identity restoration services and invaluable peace of mind. Ninety-two percent of Canadians are concerned about the protection of their privacy and 37% are extremely concerned, reports the Canadian Centre for Cybersecurity. All it takes is a few changes to your online habits and arming yourself with the right tools to feel secure about your online presence.  

The post Don’t Let Old Accounts Haunt You: How to Maintain Your Digital Graveyard appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Patch Tuesday, October 2021 Edition

Microsoft today issued updates to plug more than 70 security holes in its Windows operating systems and other software, including one vulnerability that is already being exploited. This month’s Patch Tuesday also includes security fixes for the newly released Windows 11 operating system. Separately, Apple has released updates for iOS and iPadOS to address a flaw that is being actively attacked.

Firstly, Apple has released iOS 15.0.2 and iPadOS 15.0.2 to fix a zero-day vulnerability (CVE-2021-30883) that is being leveraged in active attacks targeting iPhone and iPad users. Lawrence Abrams of Bleeping Computer writes that the flaw could be used to steal data or install malware, and that soon after Apple patched the bug security researcher Saar Amar published a technical writeup and proof-of-concept exploit derived from reverse engineering Apple’s patch.

Abrams said the list of impacted Apple devices is quite extensive, affecting older and newer models. If you own an iPad or iPhone — or any other Apple device — please make sure it’s up to date with the latest security patches.

Three of the weaknesses Microsoft addressed today tackle vulnerabilities rated “critical,” meaning that malware or miscreants could exploit them to gain complete, remote control over vulnerable systems — with little or no help from targets.

One of the critical bugs concerns Microsoft Word, and two others are remote code execution flaws in Windows Hyper-V, the virtualization component built into Windows. CVE-2021-38672 affects Windows 11 and Windows Server 2022; CVE-2021-40461 impacts both Windows 11 and Windows 10 systems, as well as Server versions.

But as usual, some of the more concerning security weaknesses addressed this month earned Microsoft’s slightly less dire “important” designation, which applies to a vulnerability “whose exploitation could result in compromise of the confidentiality, integrity, or availability of user data, or of the integrity or availability of processing resources.”

The flaw that’s under active assault — CVE-2021-40449 — is an important “elevation of privilege” vulnerability, meaning it can be leveraged in combination with another vulnerability to let attackers run code of their choice as administrator on a vulnerable system.

CVE-2021-36970 is an important spoofing vulnerability in Microsoft’s Windows Print Spooler. The flaw was discovered by the same researchers credited with the discovery of one of two vulnerabilities that became known as PrintNightmare — the widespread exploitation of a critical Print Spooler flaw that forced Microsoft to issue an emergency security update back in July. Microsoft assesses CVE-2021-36970 as “exploitation more likely.”

“While no details have been shared publicly about the flaw, this is definitely one to watch for, as we saw a constant stream of Print Spooler-related vulnerabilities patched over the summer while ransomware groups began incorporating PrintNightmare into their affiliate playbook,” said Satnam Narang, staff research engineer at Tenable. “We strongly encourage organizations to apply these patches as soon as possible.”

CVE-2021-26427 is another important bug in Microsoft Exchange Server, which has been under siege lately from attackers. In March, threat actors pounced on four separate zero-day flaws in Exchange that allowed them to siphon email from and install backdoors at hundreds of thousands of organizations.

This month’s Exchange bug earned a CVSS score of 9.0 (10 is the most dangerous). Kevin Breen of Immersive Labs points out that Microsoft has marked this flaw as less likely to be exploited, probably because an attacker would already need access to your network before using the vulnerability.

“Email servers will always be prime targets, simply due to the amount of data contained in emails and the range of possible ways attackers could use them for malicious purposes. While it’s not right at the top of my list of priorities to patch, it’s certainly one to be wary of.”

Also today, Adobe issued security updates for a range of products, including Adobe Reader and Acrobat, Adobe Commerce, and Adobe Connect.

For a complete rundown of all patches released today and indexed by severity, check out the always-useful Patch Tuesday roundup from the SANS Internet Storm Center, and the Patch Tuesday data put together by Morphus Labs. And it’s not a bad idea to hold off updating for a few days until Microsoft works out any kinks in the updates: AskWoody.com frequently has the lowdown on any patches that are causing problems for Windows users.

On that note, before you update please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates have been known to erase or corrupt files.

So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.

And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.

If you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a decent chance other readers have experienced the same and may chime in here with useful tips.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Couple Arrested Over Sale of Nuclear Secrets

Couple Arrested Over Sale of Nuclear Secrets

A married couple from Maryland has been arrested on suspicion of selling secret information about the design of nuclear-powered warships. 

Jonathan and Diana Toebbe, both of Annapolis, were arrested in Jefferson County, West Virginia, by the FBI and the Naval Criminal Investigative Service on Saturday, October 9. 

It is alleged that 42-year-old Naval nuclear engineer Jonathan Toebbe, with the help of his 45-year-old wife, sold information classified as Restricted Data to an undercover FBI agent who they believed was a representative of a foreign power.

The complaint affidavit alleges that on April 1, 2020, Jonathan Toebbe sent a package to a foreign government containing a sample of Restricted Data along with instructions for establishing a covert relationship to purchase more of it.

Toebbe allegedly corresponded with an undercover agent posing as a representative of that government for months before agreeing to exfiltrate Restricted Data and sell it for thousands of dollars in crypto-currency. 

After receiving a $10,000 advance payment, Toebbe and his wife allegedly arranged to leave an SD card containing the data at a pre-arranged location in West Virginia on June 26.

While his wife allegedly acted as a lookout, Toebbe allegedly performed the dead drop by hiding an encrypted SD card in a peanut butter sandwich and leaving it at a site agreed upon with the agent.

The agent retrieved the card and paid Jonathan Toebbe $20,000 for the encryption key. The card was found to contain Restricted Data related to submarine nuclear reactors. 

On August 28, Jonathan Toebbe allegedly made a second dead drop, this time concealing an SD card in a pack of chewing gum and accepting a payment of $70,000 from the undercover agent. 

The FBI arrested Jonathan and Diana Toebbe on October 9, after he placed a third SD card at a pre-arranged location in West Virginia. 

The Toebbes have been charged in a criminal complaint alleging violations of the Atomic Energy Act. The couple, who have two children, are due to appear before a federal court in Martinsburg, West Virginia, tomorrow.

Following her arrest, Diana Toebbe has been suspended from her job as a humanities teacher at the private Key School in Annapolis.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Hospital Hacker Steals Patients’ Data

Hospital Hacker Steals Patients’ Data

Data belonging to patients of a hospital in New Mexico has been deleted by an unknown cyber-attacker. 

The IT network of San Juan Regional Medical Center in Farmington was breached by an unauthorized individual in September last year. The attack was reported to the United States Department of Health and Human Services’ Office for Civil Rights on June 4 as a network server security incident impacting 68,792 individuals. 

In a statement released on October 7, the hospital said that it had launched an investigation after identifying unauthorized access to its network on September 8, 2020.

The hospital said: “Upon learning of the issue, SJRMC immediately took steps to secure the network and mitigate against any additional harm. After an extensive forensic investigation, we determined that as part of this incident, an unauthorized individual removed information from our network September 7–8, 2020.”

SJRMC undertook a manual review of the files that had been removed in the cyber-attack. The hospital discovered on July 13, 2021, that those files had contained “the personal and protected health information of certain patients.”

The hospital said on October 7 that it is notifying the patients whose data was affected by the incident. Information compromised in the incident includes names, dates of birth, Social Security numbers, driver’s license numbers, passport information, financial account numbers, health insurance information, and medical information (diagnosis, treatment, medical record number, patient account number). 

“This incident does not impact all SJRMC patients, and not all information was impacted for all individuals. SJRMC is now notifying individuals so that they can take steps to protect their information,” said the hospital.

SJRMC has not found any evidence to suggest that the compromised data has been misused. The hospital said that the attack did not involve ransomware. 

“Nevertheless, in addition to providing this website notice, SJRMC is sending notification to all affected patients for whom we have enough information to determine a physical address. We have also set up a dedicated call center,” said the hospital.

Individuals whose Social Security numbers were in the files removed during the cyber-attack are being offered complimentary credit monitoring services.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Imprisons Man Who Exploited Children Via Social Media

US Imprisons Man Who Exploited Children Via Social Media

A sexual predator who used social media apps to victimize minors has been sent to prison in the United States.

Jacob Blanco, of Fresno, California, used several ruses to manipulate children as young as six years old into producing sexually explicit material and then sharing it with him.

Using apps including Musical.ly (now TikTok), Kik and Snapchat, the 29-year-old offender posed as a child modeling agent or pretended to be a minor himself to deceive his victims.

Police became aware of Blanco’s illegal activity in March 2017 after being contacted by the parents of a six-year-old child. The parents alerted authorities after discovering that their child had communicated with another user on Musical.ly and had created sexually explicit images at the request of that user. 

An investigation into the incident led law enforcement to Blanco, and a search warrant was obtained to search his residence and digital devices. That search revealed that Blanco had successfully persuaded and coerced multiple minors to create sexually explicit material.

In May 2020, Blanco pleaded guilty to five counts of sexual exploitation of a minor and receipt and distribution of material involving sexual exploitation of minors. 

“Blanco admitted, as part of his plea agreement, that he communicated with at least 50 minors and asked for and received sexually explicit images from many of them,” said the Department of Justice’s Office of Public Affairs in a statement released October 8. 

On Friday, Blanco was sentenced to 55 years in prison followed by a lifetime of supervised release. 

Acting US Attorney Phillip Talbert for the Eastern District of California said: “The fact that the defendant used social media to sexually exploit the victims serves as a reminder that the internet can be a dangerous place especially for children.”

Blanco’s sentencing comes a month after the National Center on Sexual Exploitation (NCOSE) urged TikTok to do more to protect minors using its platform. 

Lina Nealon, director of corporate and strategic initiatives at NCOSE, said: “Under an account we created as a 13-year-old, we were easily able to find videos promoting OnlyFans, as well as other pornography and prostitution sites, despite the fact that this type of material is against TikTok’s Community Guidelines.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Android Phones Sharing Significant User Data Without Opt-Outs

Android Phones Sharing Significant User Data Without Opt-Outs

Android mobile phones are undertaking significant data sharing without offering opt-outs for users, according to a new report by researchers at Trinity College Dublin and the University of Edinburgh.

The authors said the scale of data transmission taking place is far beyond what is to be expected, raising major privacy concerns.

For the study, the team analyzed six variants of the Android OS to determine the amount of data they are sending to developers and third parties with pre-installed system apps, such as Google, Microsoft, LinkedIn and Facebook. The phones manufacturers included in the study were Samsung, Xiaomi, Huawei, Realme, LineageOS and /e/OS.

All of the developers, with the exception of e/OS, collected a list of all the apps installed on a handset. The researchers noted this information is potentially sensitive, as it can reveal user interests, such as sexual orientation or political views, e.g., a Republican news app.

The Xiaomi handset was revealed to be sending details of all app screens viewed by users to Xiaomi, including when and for how long each app is used. This data appeared to be sent outside Europe to Singapore. The Huawei handset sent tech giant Microsoft details of app usage, including when the user is writing a text or using the search bar.

Four firms – Samsung, Xiaomi, Realme and Google – were shown to collect long-lived device identifiers, such as the hardware serial number and user-resettable advertising identifiers. This data allows a new identifier value to be trivially re-linked back to the same device when a user resets an advertising identifier.

Additionally, the researchers noted that third-party system apps from companies such as Google, Microsoft, LinkedIn and Facebook are pre-installed on most handsets analyzed and silently collected data without opt-out. This even occurs when the phone is minimally configured and the handset is idle.

Interestingly, the privacy-focused e/OS variant of Android was observed to transmit virtually no data.

Prof Doug Leith, chair of computer systems at the School of Computer Science and Statistics, Trinity College Dublin, commented: “I think we have completely missed the massive and ongoing data collection by our phones, for which there is no opt out. We’ve been too focused on web cookies and on badly-behaved apps.  

“I hope our work will act as a wake-up call to the public, politicians and regulators. Meaningful action is urgently needed to give people real control over the data that leaves their phones.”

Dr Paul Patras, associate professor in the School of Informatics, University of Edinburgh, said: “Although we’ve seen protection laws for personal information adopted in several countries in recent years, including by EU member states, Canada and South Korea, user-data collection practices remain widespread. More worryingly, such practices take place “under the hood” on smartphones without users’ knowledge and without an accessible means to disable such functionality. Privacy-conscious Android variants are gaining traction though and our findings should incentivize market-leading vendors to follow suit.”

Commenting on the research, Niamh Muldoon, global data protection officer at OneLogin, warned many phone developers could be facing the prospect of large fines if changes are not made. “This research is really interesting as it highlights the risk and financial business impact of not investing in a robust privacy program, which is something that not all businesses pay attention to.

“The business impact is the financial cost associated with legal fees and potential privacy regulatory fines as a result of not adhering to GDPR compliance requirements. There are also financial implications with employee compensation if found that the privacy of their data was not adhered to both from a business collection purpose and/or if adequate protection controls were not in place leading to the result of their data being breached.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Banking Insider Accused of Role in $1m BEC Scheme

Banking Insider Accused of Role in $1m BEC Scheme

Three men including one former bank employee have been indicted by a federal grand jury for their alleged role in a business email compromise (BEC) conspiracy.

Onyewuchi Ibeh, 21, of Bowie, Maryland, Jason Joyner, 42, of Washington, DC and Mouaaz Elkhebri, 30, of Alexandria, Virginia, were charged with money laundering and aggravated identity theft, according to a superseding indictment late last week.

According to the court documents, they’re said to have targeted firms of all sizes across the globe between January 2018 and March 2020.

After phishing their way into employee accounts, they would allegedly conduct months-long reconnaissance before stepping in at the crucial moment when a supplier invoice was expected by the victim company — substituting their own highly convincing request for payment.

Faked domains mimicking those of the supplier were employed to add legitimacy to their communications with the victim organization.

At least five businesses lost over $1.1m in total over the period, with the co-conspirators laundering the funds through dozens of bank accounts, according to the Department of Justice (DoJ).

Each man is said to have played a particular role in the scheme.

Ibeh apparently managed the money laundering process, directing the others to open accounts which he used to wire money around the world. Joyner allegedly withdrew criminal proceeds in cash and delivered it to the other two. Elkhebri is said to have opened accounts in the name of both co-conspirators and victims, using his position as a bank employee to do so.

Elkhebri worked for Bank of America and TD Bank during the period.

Ibeh and Joyner are charged with conspiracy to commit money laundering and money laundering — and each faces a maximum penalty of 20 years in prison. Elkhebri is charged with conspiracy to commit money laundering, money laundering, false entries in a bank’s books, and aggravated identity theft — charges which carry a maximum of 52 years.

According to Accenture, the cost of cyber-attacks carried out by malicious insiders jumped 15% in 2019 to reach $1.6 million per organization, on average.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Most Insurers Mandate MFA, But Premiums Are Still Soaring

Most Insurers Mandate MFA, But Premiums Are Still Soaring

US cyber-insurers are increasing premiums and lowering coverage limits despite mandating stricter security controls as a pre-requisite for coverage, according to a new report.

The US Cyber Market Outlook from wholesale insurance broker Risk Placement Services warns that providers have been “battered” by higher-than-anticipated recent losses and are now generally charging much more for less coverage.

“Over the past year, we’ve seen the challenges of the COVID-19 pandemic and increasing frequency and severity of ransomware attacks put pressure on the US cyber liability market,” said RPS national cyber practice leader Steve Robinson.

“While this market dynamic developed quickly, within a matter of months, longstanding underwriting issues in this market, as well what had been a growing mismatch between exposures and underwriting, helped to create the current situation and the imbalance between coverage supply and demand.” 

Sectors hit hard over the past year, including education, government, healthcare, construction and manufacturing, have seen premiums increase by 300% or more at renewal time. This is even if corporate policyholders have the right set of security controls in place.

Such controls are becoming increasingly widespread, according to RPS. Multi-factor authentication (MFA) is now described as a “must-have” to even qualify for coverage.

Insurers are finding other ways to reduce their risk of losses, the report claimed.

“Insurance companies are incorporating the same scanning technology used by hackers into their own underwriting process. This allows them to assess an organization’s perimeter security and also develop a metric-based estimate for a potential cyber-attack,” it claimed.

“These scanning tools can be used to identify unused, vulnerable open ports that could provide a bad actor with a network entry point.”

The RPS findings are backed by other research this year. A Government Accountability Office (GAO) study from May claimed that take-up of cyber-specific insurance policies had doubled to around half (47%) in 2020, but that successful attacks had also led to rising premiums and reduced coverage limits for some.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ransomware Intrusion Group FIN12 Ramps-Up in Europe

Ransomware Intrusion Group FIN12 Ramps-Up in Europe

A long-running threat group with a track record of rapid ransomware deployment and healthcare sector victims is ramping up its operations in Europe and APAC, Mandiant has warned.

In a new report detailing the work of FIN12, the threat intelligence firm claimed that the prolific threat group had focused mainly on North American targets since its activities were first recorded in 2018.

Around 85% were from this region, and 20% thus far have been healthcare sector organizations, which many ransomware groups promised to steer clear of during the pandemic.

The bad news for organizations elsewhere in the world is that FIN12 appears to be changing its geographical focus.

“We observed twice as many victim organizations based outside of North America in the first half of 2021 than we observed in 2019 and 2020 combined. Collectively, these organizations have been based in Australia, Colombia, France, Indonesia, Ireland, the Philippines, South Korea, Spain, the United Arab Emirates, and the UK,” explained Mandiant in a blog post.

“This shift could be due to various factors such as FIN12 working with more diverse partners to obtain initial access and increasingly elevated and unwanted attention from the US government.”

The group apparently uses Ryuk ransomware to target organizations with over $300m in revenue, partnering with other actors in the cyber underground for initial access, especially those affiliated with Trickbot and BazarLoader malware.

Through these partnerships and by eschewing double extortion tactics, FIN12 has dramatically cut the time it takes to deploy ransomware to victim networks.

“In the first half of 2021, as compared to 2020, FIN12 significantly improved their TTR, cutting it in half to just 2.5 days,” said Mandiant. 

“These efficiency gains are enabled by their specialization in a single phase of the attack lifecycle, which allows threat actors to develop expertise more quickly.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains