Friday Squid Blogging: Person in Squid Suit Takes Dog for a Walk

No, I don’t understand it, either.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Read my blog posting guidelines here.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

I Am Not Satoshi Nakamoto

This isn’t the first time I’ve received an e-mail like this:

Hey! I’ve done my research and looked at a lot of facts and old forgotten archives. I know that you are Satoshi, I do not want to tell anyone about this. I just wanted to say that you created weapons of mass destruction where niches remained poor and the rich got richer! When bitcoin first appeared, I was small, and alas, my family lost everything on this, you won’t find an apple in the winter garden, people only need strength and money. Sorry for the English, I am from Russia, I can write with errors. You are an amazingly intelligent person, very intelligent, but the road to hell is paved with good intentions. Once I dreamed of a better life for myself and my children, but this will never come …

I like the bit about “old forgotten archives,” by which I assume he’s referring to the sci.crypt Usenet group and the Cypherpunks mailing list. (I posted to the latter a lot, and the former rarely.)

For the record, I am not Satoshi Nakamoto. I suppose I could have invented the bitcoin protocols, but I wouldn’t have done it in secret. I would have drafted a paper, showed it to a lot of smart people, and improved it based on their comments. And then I would have published it under my own name. Maybe I would have realized how dumb the whole idea is. I doubt I would have predicted that it would become so popular and contribute materially to global climate change. In any case, I did nothing of the sort.

Read the paper. It doesn’t even sound like me.

Of course, this will convince no one who doesn’t already believe. Such is the nature of conspiracy theories.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

The Proliferation of Zero-days

The MIT Technology Review is reporting that 2021 is a blockbuster year for zero-day exploits:

One contributing factor in the higher rate of reported zero-days is the rapid global proliferation of hacking tools.

Powerful groups are all pouring heaps of cash into zero-days to use for themselves — and they’re reaping the rewards.

At the top of the food chain are the government-sponsored hackers. China alone is suspected to be responsible for nine zero-days this year, says Jared Semrau, a director of vulnerability and exploitation at the American cybersecurity firm FireEye Mandiant. The US and its allies clearly possess some of the most sophisticated hacking capabilities, and there is rising talk of using those tools more aggressively.

[…]

Few who want zero-days have the capabilities of Beijing and Washington. Most countries seeking powerful exploits don’t have the talent or infrastructure to develop them domestically, and so they purchase them instead.

[…]

It’s easier than ever to buy zero-days from the growing exploit industry. What was once prohibitively expensive and high-end is now more widely accessible.

[…]

And cybercriminals, too, have used zero-day attacks to make money in recent years, finding flaws in software that allow them to run valuable ransomware schemes.

“Financially motivated actors are more sophisticated than ever,” Semrau says. “One-third of the zero-days we’ve tracked recently can be traced directly back to financially motivated actors. So they’re playing a significant role in this increase which I don’t think many people are giving credit for.”

[…]

No one we spoke to believes that the total number of zero-day attacks more than doubled in such a short period of time — just the number that have been caught. That suggests defenders are becoming better at catching hackers in the act.

You can look at the data, such as Google’s zero-day spreadsheet, which tracks nearly a decade of significant hacks that were caught in the wild.

One change the trend may reflect is that there’s more money available for defense, not least from larger bug bounties and rewards put forward by tech companies for the discovery of new zero-day vulnerabilities. But there are also better tools.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

85% of UK’s Top Universities at Risk of Email Fraud

85% of UK’s Top Universities at Risk of Email Fraud

More than four-fifths (85%) of the UK’s top 20 universities are putting their students, staff and suppliers at risk of email fraud, according to a new study by Proofpoint.

The researchers found that just 15% of the universities have implemented the recommended and strictest level of domain-based message authentication, reporting and conformance (DMARC). DMARC is an email validation protocol that verifies that the domain of the sender has not been impersonated.

The findings have come amid surging phishing attacks targeting the education sector since the start of the COVID-19 pandemic. For example, last year, a Barracuda Networks study showed that schools, colleges and universities are being disproportionately targeted by spear-phishing attacks. Experts believe that cyber-criminals increasingly view the industry as a soft target.

Encouragingly, 70% of the universities included in the analysis have published a DMARC record, representing a 100% increase since 2019. Therefore, more than two-thirds of these institutions have recognized the need to implement DMARC protocols.

However, six universities out of the 20 had no DMARC record.

Adenike Cosgrove, a cybersecurity strategist at Proofpoint, commented: “Our research has shown that many UK universities are still exposing people to cyber-criminals on the hunt for personal and financial data by not implementing simple, yet effective email authentication best practices. Email continues to be the vector of choice for cyber-criminals and the education sector remains a key target.

“Organizations in all sectors should deploy authentication protocols, such as DMARC, to shore up their email fraud defenses. Cyber-criminals pay close attention to major trends and will drive targeted attacks using social engineering techniques such as impersonation, and universities are no exception to this. As the university terms begins, students and staff must be vigilant in checking the validity of all emails, especially when levels of uncertainty and anticipation are higher at the beginning of a new term.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Illinois Clarifies Limitations on Data Privacy Claims

Illinois Clarifies Limitations on Data Privacy Claims

A court in Illinois has issued an opinion clarifying how the statute of limitations should be applied to the state’s Biometric Information Privacy Act (BIPA).

In what The National Law Review described as “a highly anticipated ruling,” the Illinois Appellate Court published an opinion that while a one-year deadline would be applied to claims based on unlawful profit or disclosure, claims relating to data retention policy disclosure, informed consent, and safeguarding would have a limitation period of five years. 

The ruling was made by a panel of three judges in the case of Tims v. Black Horse Carriers, Inc. The panel said that the different limitation periods are necessary because each BIPA requirement is “separate and distinct.”

The five-year statute of limitations period applies to all BIPA claims that assert (1) unlawful collection of biometric data without written notice, or (2) issues relating to storing or transmitting it, or (3) claims involving the company’s failure to develop a publicly available retention and destruction schedule.

BIPA claims that allege (1) improper disclosure or (2) improper sale, lease, trade, or profit from biometric data will fall under the one-year limitations period.

“This long-awaited decision provides much-needed clarity for businesses and entities involved in the collection or processing of biometric data that impacts Illinois residents,” said Natalie Prescott, practice group associate at law firm Mintz.

“This clarification by the Illinois Appellate Court provides more certainty with respect to when potential claims can be deemed untimely.”

Commenting on the ruling, Tim Wade, technical director, CTO team at California-based AI cybersecurity company Vectra, emphasized the unique importance of biometric data.

“The loss of biometric data is concerning for the same reasons biometric-based authentication systems are weak – an individual can’t go out and get a new set of fingerprints, a new retinal pattern, or a new face. 

“For this reason, companies that collect and store such information must be held to the highest standards of stewardship, and failure to maintain such stewardship is a non-trivial matter. Any erosion in our legal system’s position with respect to that seriousness is a net-loss for individual privacy.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI and CISA Issue Conti Warning

FBI and CISA Issue Conti Warning

An alert has been issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) over Conti ransomware.

In the warning, which was posted on September 22, the agencies observed the increased use of Conti in more than 400 attacks against organizations in the United States and internationally. 

The alert said that Conti actors often get network access via spearphishing campaigns, stolen or weak Remote Desktop Protocol (RDP) credentials, phone calls, fake software promoted via search engine optimization, common vulnerabilities in external assets, and other malware distribution networks. 

In the execution phase, the actors run a getuid payload, then use a more aggressive payload to lower the risk of triggering antivirus engines. 

Cobalt CIO Andrew Obadiaru ascribed the increase in Conti ransomware attack to “our new remote work ecosystem.”

“To protect yourself from becoming the next victim of a Conti attack, I recommend business leaders deploy the following security safeguards: (1) invest in email filtering and phishing detection capabilities, (2) protect and properly secure your remote desktop platform connectivity, (3) perform regular backup testing, and (4) ensure your backups are offline,” Obadiaru told Infosecurity Magazine.

On the same day on which the alert was issued, security specialist Positive Technologies published a report that found that ransomware attacks have reached “stratospheric” levels, accounting for 69% of all attacks involving malware in the second quarter of 2021. This represents an increase of 30% compared with the same period last year. 

Other key findings in Cybersecurity Threatscape: Q2 2021 are that the percentage of attacks aimed at compromising computers, servers, and network equipment increased from 71% in Q1 this year to 87% in Q2. 

While the volume of attacks on governmental institutions soared from 12% in Q1 to 20% in Q2, there was only a minor rise (0.3%) in overall attacks from Q1 to Q2. 

“This slowdown was to be expected as companies took greater measures to secure the network perimeter and remote access systems during a global pandemic and the growth of a dispersed workforce,” said Positive Technologies. “However, the rise in ransomware attacks in particular – a 45% jump in the month of April alone – should cause grave concern.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Eye-Care Providers Report Data Breaches

US Eye-Care Providers Report Data Breaches

The protected health information of hundreds of thousands of Americans has been exposed in two separate security incidents at eye-care providers in the United States.

Simon Eye Management reported a data breach to the Department of Health and Human Services’ Office for Civil Rights on September 14. An email hacking incident at the Delaware-based eye-care group exposed the data of 144,000 individuals.

According to a notice issued by Simon Eye, suspicious activity “related to certain employee email accounts” was observed on or about June 8. An investigation carried out with the help of third-party computer forensic specialists found that unauthorized access to some employee email accounts had occurred from May 12, 2021, to May 18, 2021.

“Our investigation revealed that the unauthorized third party attempted to engage in wire transfer and invoice manipulation attacks against the company, none of which were successful,” said the eye-care group.

Information impacted by the incident may have included names, medical histories, treatment or diagnosis information, and health insurance information. Simon Eye said that “a smaller number of individuals” may also have had their Social Security numbers, birth dates, and/or financial account information exposed.

The eye-care provider said that it had not discovered any evidence of data misuse linked to the incident. 

On May 12, USV Optical, Inc., a subsidiary of U.S. Vision, Inc., noticed suspicious activity on its network. A forensic investigation confirmed that hackers were able to access certain USV Optical servers and systems for nearly a month.

It was determined that data belonging to 180,000 individuals (employees and patients) may have been accessed and possibly exfiltrated by an unauthorized individual from April 20, 2021, to May 17, 2021. 

Information that could have been compromised included names, eye-care insurance information, and insurance claims information. In a security notice, USV Optical said that for some individuals, addresses, dates of birth, and/or “other individual identifiers” may also have been exposed. 

“We have no evidence of any identity theft or fraud occurring as a result of this incident,” stated USV Optical, adding that they “are reporting this incident to relevant state and federal regulators as required.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains