Facebook Whistleblower to Testify Before Senate

Facebook Whistleblower to Testify Before Senate

A former Facebook employee is to appear before a US Senate subcommittee tomorrow after blowing the whistle on the company’s alleged prioritization of profit above user welfare. 

Frances Haugen, a 37-year-old data scientist from Iowa, revealed yesterday that it was she who leaked internal research carried out by Facebook to the Wall Street Journal. This research formed the basis of an investigative series named The Facebook Files, which the Journal has been reporting for the past three weeks.

Among the claims made by the Journal are that Facebook identified negative effects that its platform was having upon its users but didn’t take any action to fix the problems. 

It is further alleged that while claiming to treat all its users equally, Facebook allowed certain high-profile users to post content including harassment and incitement to violence.

Haugen, who has a degree in computer engineering and a Harvard master’s degree in business, held positions at Google, Yelp, and Pinterest prior to working for Facebook for two years as a product manager on the company’s civic misinformation team. Before quitting her job in May, she copied a trove of internal company memos and documents. 

“I’ve seen a bunch of social networks and it was substantially worse at Facebook than anything I’d seen before,” Haugen told CBS.

Speaking on a 60 Minutes episode that aired Sunday, Haugen said: “The thing I saw at Facebook over and over again was there were conflicts of interest between what was good for the public and what was good for Facebook. And Facebook, over and over again, chose to optimize for its own interests, like making more money.”

She added: “The version of Facebook that exists today is tearing our societies apart and causing ethnic violence around the world.”

Following Haugen’s disclosures, two members of the European Parliament have called for an investigation to be launched into the social media company. 

“We need to regulate the whole system and the business model that favors disinformation and violence over factual content – and enables its rapid dissemination,” said European Parliament lawmaker Alexandra Geese.

On October 5, Haugen will testify before a Senate subcommittee in a hearing on Facebook’s research into Instagram’s effect on the mental health of young people.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Prolific Ransomware Operators Arrested in Joint Law Enforcement Action

Prolific Ransomware Operators Arrested in Joint Law Enforcement Action

A coordinated law enforcement action has led to the arrest of two “prolific ransomware operators” in Ukraine, Europol has revealed.

The strike was undertaken between the French National Gendarmerie, the Ukrainian National Police and the United States Federal Bureau of Investigation (FBI) in conjunction with Europol and INTERPOL on September 28. While neither the individuals nor the gang they allegedly belong to were named, Europol said they were “known for their extortionate ransom demands (between €5m and €70m).”

The group is believed to have targeted numerous “very large industrial groups in Europe and North America” since April 2020. They are also renowned for their ‘double extortion’ tactics, deploying malware and stealing sensitive data from their victims in addition to encrypting their files. They would then demand a large ransom payment under threat of leaking the stolen data on the dark web.

The Ukrainian authorities stated that the suspects were responsible for attacks against over 100 worldwide organizations, causing more than $150 million in damages.

As well as the two arrests, the joint law enforcement action resulted in seven property searches, seizure of $375,000 in cash, seizure of two luxury vehicles worth €217,000 and asset freezing of $1.3m in cryptocurrencies.

Europol helped bring together law enforcement agencies to establish a joint strategy, including creating a virtual command post. The operation involved six investigators from French Gendarmerie, four from the US FBI, a prosecutor from the French Prosecution Office of Paris, two specialists from Europol’s European Cybercrime Centre (EC3) and one INTERPOL officer to work alongside the Ukrainian National Police.

Providing further insights into the tactics used by the ransomware operators, Stefano De Blasi, threat researcher at Digital Shadows, said: “The suspects reportedly compromised their victims via spear-phishing campaigns and by targeting remote working tools such as remote desktop protocol (RDP) and virtual private networks (VPN). This observation highlights how social engineering remains a vital access vector for threat actors, as human curiosity is often exploited to bypass technological defences. Additionally, the use of RDP and VPN to compromise organizations suggests that the suspects have likely gained access to victims by purchasing initial access broker (IAB) listings on cyber-criminal forums and marketplaces.”

He added: “Europol also stated that the operation resulted $1.3m being frozen within the group’s seized crypto wallets. Ukrainian police stated that the suspects had an accomplice who helped the group launder money gained from illicit means. The use of individuals skilled in laundering money has been a significant factor in the development of ransomware groups into an effective criminal business model. Although law enforcement agencies have not named the ransomware gang behind this operation, it is unclear what extent the operation will have on the group in question, or on the wider ransomware ecosystem.

“While solitary operations will not provide a remediation to the ransomware threat overnight, law enforcement operations can have a significant impact to targeted ransomware groups, often resulting in a suspension or disruption of their activity. These raids can achieve their greatest potential when paired with diplomatic efforts, innovative policies and effective public-private partnerships.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ex-Army Technician Gets 12 Years for Role in Fraud Scheme

Ex-Army Technician Gets 12 Years for Role in Fraud Scheme

A former US army contractor has been sentenced to more than 12 years behind bars after pleading guilty to helping defraud thousands of military service members, veterans and their families.

Fredrick Brown, 40, of Las Vegas, was sentenced for one count of conspiracy to commit wire fraud and one count of conspiracy to commit money laundering, following a guilty plea nearly two years ago.

As a civilian medical records technician and administrator at the US army’s 65th Medical Brigade, Yongsan Garrison, he admitted to stealing the personal information of countless military staff, including by taking screenshots of his computer while logged into medical databases.

These details — which included names, social security numbers, military ID numbers, dates of birth and contact information — were then sent to Philippines-based co-defendant Robert Wayne Boling Jr. 

In concert with others, he’s accused of using the info to access Pentagon and Veterans Affairs benefits sites to steal millions of dollars.

The fraud scheme targeted around 3300 victims, including eight general officers and many disabled veterans, who were singled out because of the more considerable service-related benefits they received. In total, these individuals lost around $1.5m due to the plot, it’s claimed.

Brown has also been ordered to pay over $2.3m in restitution and will be placed on supervised release for three years after completing his prison term.

Another co-defendant, Trorice Crawford, 34, of San Diego, was last year sentenced to 46 months in federal prison for his role in the scheme — which was to recruit money mules to help launder the funds.

“The defendant brazenly preyed on and victimized US service members and veterans, many of whom were disabled and elderly,” said US attorney Ashley Hoff for the Western District of Texas.

“As part of our mission, we strive to protect these honorable men and women from fraud and abuse. If fraudsters target our service members and veterans, we will seek to identify them and hold them accountable. This office will continue to zealously investigate and prosecute perpetrators of these schemes.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Coinbase Attackers Bypassed Account Authentication

Coinbase Attackers Bypassed Account Authentication

US cryptocurrency exchange Coinbase is facing a backlash from its users after notifying them that at least 6,000 customers had their funds stolen by hackers.

The “third-party campaign” took place between March and May 20, 2021.

“In order to access your Coinbase account, these third parties first needed prior knowledge of the email address, password, and phone number associated with your Coinbase account, as well as access to your personal email inbox,” the firm explained in a breach notification letter.

“While we are not able to determine conclusively how these third parties gained access to this information, this type of campaign typically involves phishing attacks or other social engineering techniques to trick a victim into unknowingly disclosing login credentials to a bad actor. We have not found any evidence that these third parties obtained this information from Coinbase itself.”

However, while Coinbase does not appear to have been responsible for the initial data leak, which enabled the first stage of the attack, a crucial flaw in its authentication process was to blame for the unauthorized account access.

“Even with the information described above, additional authentication is required in order to access your Coinbase account,” it continued.

“However, in this incident, for customers who use SMS texts for two-factor authentication, the third party took advantage of a flaw in Coinbase’s SMS Account Recovery process in order to receive an SMS two-factor authentication token and gain access to your account.”

Coinbase, the world’s second-largest cryptocurrency exchange with tens of millions of global users, said it would reimburse customers the full value of their losses. The firm has also updated its SMS Account Recovery protocols to ensure authentication can’t be bypassed in a similar way in the future.

However, it warned that, while inside hacked accounts, unauthorized third parties would have access and potentially changed details. These details include full name, email and home address, date of birth, IP address for account activity, transaction history, account holdings and balance.

This isn’t the first time Coinbase has been in the news following a security breach. In 2019 it was forced to halt trading of Ethereum Classic (ETC) after spotting “double spend” attacks totalling more than $1m.

Hacked Coinbase accounts are said to be worth as much as $610 apiece on the cybercrime underground.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK’s National Cyber Force Heads to the Northwest

UK’s National Cyber Force Heads to the Northwest

The government has released more details about a planned National Cyber Force (NCF), confirming that it will be located in the northwest village of Samlesbury.

First mooted in 2018, the new facility will form the hub of the UK’s offensive cyber capabilities, drawing personnel from GCHQ, the Ministry of Defence, MI6 and the Defence Science and Technology Laboratory (DSTL).

“The National Cyber Force will help confront aggressive behavior from malign actors, and demonstrate that Britain is investing in next-generation defense capability to protect our people and help our friends counter cyber-threats. It sends a powerful message to our allies and adversaries alike,” said foreign secretary, Liz Truss.

The move is part of the ruling Conservative Party’s efforts to shift more public sector jobs out of London in an attempt to appeal to its newfound voter base in the north.

Situated between Blackburn and Preston, Samlesbury has little to its name save for a 14th-century country house, a BAE Systems aircraft factory and a brewery.

The government was at pains to point out that any offensive activities it carries out from the new National Cyber Force would be done in a “legal, ethical and proportionate” manner to disrupt hostile states, terrorists and criminals threatening the UK’s national security.

It claimed to be a world leader in such matters, with GCHQ having pioneered techniques to break ISIS propaganda networks.

The hub has been in operation since April 2020 but will reportedly expect more than £5bn in funding before 2030, highlighting the strategic importance with which it is regarded in government.

The announcement follows the opening of a GCHQ facility in Manchester, which the government is positioning as the ‘cyber center’ of the UK. It claimed more than 15% of the city’s population now works in the “digital, creative and technology sector.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Facebook Is Down

Facebook — along with Instagram and WhatsApp — went down globally today. Basically, someone deleted their BGP records, which made their DNS fall apart.

…at approximately 11:39 a.m. ET today (15:39 UTC), someone at Facebook caused an update to be made to the company’s Border Gateway Protocol (BGP) records. BGP is a mechanism by which Internet service providers of the world share information about which providers are responsible for routing Internet traffic to which specific groups of Internet addresses.

In simpler terms, sometime this morning Facebook took away the map telling the world’s computers how to find its various online properties. As a result, when one types Facebook.com into a web browser, the browser has no idea where to find Facebook.com, and so returns an error page.

In addition to stranding billions of users, the Facebook outage also has stranded its employees from communicating with one another using their internal Facebook tools. That’s because Facebook’s email and tools are all managed in house and via the same domains that are now stranded.

What I heard is that none of the employee keycards work, since they have to ping a now-unreachable server. So people can’t get into buildings and offices.

And every third-party site that relies on “log in with Facebook” is stuck as well.

The fix won’t be quick:

As a former network admin who worked on the internet at this level, I anticipate Facebook will be down for hours more. I suspect it will end up being Facebook’s longest and most severe failure to date before it’s fixed.

We all know the security risks of monocultures.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains