Americans Stressed Out by Cyber-attack Coverage

Americans Stressed Out by Cyber-attack Coverage

Most Americans and Canadians say that news of ransomware attacks and data breaches causes them to experience stress.

An online survey of 2,500 adults in Canada and the United States found that in relation to cybersecurity, seven in ten respondents (69%) said news of data breaches caused them stress. 

The research, which was conducted in July 2021 by research firm Opinion Matters for cybersecurity company Kaspersky, also found that 64% of respondents said that consuming news coverage of ransomware attacks left them feeling stressed.

“These stress levels were nearly identical between Americans and Canadians,” said Kaspersky in its report Dealing with a New Normal in our Digital Reality. 

“When we asked this question in 2018, three quarters of respondents said news of data breaches caused them stress. This number dropped in 2019 to 68%, however since then, the number has barely changed (69%).”

Experiencing a cybersecurity incident ranked as one of life’s top stressors for many respondents, with 37% saying that having their bank account compromised would be more stressful than losing their employment. 

Increased internet usage linked to the COVID-19 pandemic caused additional stress for 56% of survey respondents. 

Nearly three in five respondents increased their use of online services because of the pandemic, with over a quarter (27%) reporting a significant increase. But while 64% of Millennials went online more because of the pandemic, only 45% of Baby Boomers had spent more time on the internet.

Using the internet more often made nearly half of the men who were surveyed (49%) feel more confident that they could maintain their safety online. This confidence boost was only experienced by 29% of women. 

Fewer than half of respondents (48%) said that they check their accounts for indicators of compromise, and only 26% of respondents said that they educate themselves about online privacy. 

Cybersecurity incidents had been experienced by nearly half (48%) of all respondents within the past two years, compared to 28% in 2019. 

Marina Alekseeva, chief human resources officer at Kaspersky, said: “It is important to gain control of your digital life to have peace of mind in knowing your data is protected.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

France Condemns #Anti2010 Cyber-bullying

France Condemns #Anti2010 Cyber-bullying

Education officials in France have spoken out against a new cyber-bullying trend targeting children who were born in 2010.

The BBC reports that the malicious new #anti2010 campaign has been spreading online via Twitter and through the video-sharing app TikTok. Videos that encourage viewers to form an “anti-2010 police” have been watched millions of times.

Euro News reports that the hashtag #anti2010 had more than 40 million views on TikTok before it was removed.

Parents have reportedly become concerned that the campaign has created a vogue for bullying eleven-year-olds at a particularly vulnerable moment in their lives – starting secondary school.

France’s education minister, Jean-Michel Blanquer, condemned the online bullying as “completely stupid and against our values.”

Reports have allegedly been made that the cyber-bullying has progressed from digital taunts to physical violence.

“In the courtyard, they point the finger at us, shouting 2010! 2010!” a student born in 2010 told the Le Parisien newspaper, adding that fights had emerged out of the verbal abuse.

Blanquer urged families to report any cases of harassment via an emergency hotline. 

“The warm welcome of sixth-grade students – and their successful integration thanks to the goodwill of their peers and adults – is an essential issue in school life at the college,” wrote Blanquer in a letter to school principals in which he implored them to be alert to harassment, threats, and insults. 

The main federation of school parents in France (FCPE) has asked the government to act urgently to create a new child protection policy for social networks, saying it is “unacceptable that children are victims of an appeal to hate.”

While the origins of the #anti2010 trend are shrouded in mist, French newspapers have speculated that the bullying arose from a fashion for players of the video game Fortnite to brand younger players as “Fortkids” and slam them for not adhering to an unwritten code of conduct. 

The bullying is believed to have intensified with the release last month of the song “Pop it Mania” by Pink Lily, which contains the lyric “We are the queens of 2010.” On YouTube, the video has attracted nearly half a million (428K) dislikes.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Set to Sanction Cryptocurrency Firms Involved in Ransomware

US Set to Sanction Cryptocurrency Firms Involved in Ransomware

The US government is reportedly set to announce new measures, including sanctions to deter cryptocurrency businesses from getting involved in laundering and facilitating ransomware payments.

People familiar with the matter told the Wall Street Journal that the Treasury could roll out the new sanctions as early as this week. They’ll reportedly target cryptocurrency exchanges and traders who either knowingly or unwittingly enable cybercrime transactions.

As part of the measures, the government will also issue new guidance explaining the risks involved in facilitating ransomware payments, including significant fines and other penalties.

The move would seem to be in keeping with the direction of travel over the past few months, which has seen the Biden administration prioritize ransomware as a national security threat.

Following the Colonial Pipeline attack in early May, the White House issued an open letter to CEOs to persuade them to take the threat more seriously. Reports have also revealed plans to elevate attacks to the same priority level as terrorism.

Then there was the creation of a DoJ Ransomware and Digital Extortion Task Force, which scored a significant victory by helping to seize more than half of the funds paid to the Colonial Pipeline attackers.

Biden’s executive order on cybersecurity will also help drive improvements designed to mitigate the impact of ransomware across the federal government, including the roll-out of multi-factor authentication (MFA) and zero trust principles. It will also make it easier for organizations across public and private sectors to share information following incidents.

The US has also led efforts at a G7 and NATO level to denounce Russia for harboring cybercrime groups that engage in ransomware. The White House has repeatedly claimed it reserves the right to go after these groups unilaterally if no action is taken to contain them.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Payment API Vulnerabilities Exposed “Millions” of Users

Payment API Vulnerabilities Exposed “Millions” of Users

Millions of consumers may have exposed their personal and payment information after researchers discovered API security vulnerabilities affecting multiple apps.

CloudSEK said that of the 13,000 apps uploaded to its BeVigil “security search engine” for mobile applications, around 250 use the Razorpay API to facilitate financial transactions. Unfortunately, it found that approximately 5% of these exposed their payment integration key ID and key secret.

This is not a flaw in Razorpay, which serves around eight million businesses, but rather how app developers are mishandling their APIs.

“When it comes to payment gateways, an API key is a combination of a key_id and a key_secret that are required to make any API request to the payment service provider. And as part of the integration process, developers accidentally embed the API key in their source code. While developers might be aware of exposing API keys in their mobile apps, they might not be aware of the true impact this has on their entire business ecosystem,” the firm explained.

“CloudSEK has observed that a wide range of companies — both large and small — that cater to millions of users have mobile apps with API keys that are hardcoded in the app packages. These keys could be easily discovered by malicious hackers or competitors who could use them to compromise user data and networks.”

Specific data exposed in this way could include user information like phone numbers and email addresses, transaction IDs and amounts, and order and refund details. In addition, because the same apps are usually integrated with other applications and wallets, even more could be at stake, CloudSEK warned.

Threat actors could use the exposed API information to make bulk purchases and then initiate refunds, sell stolen data on the dark web, and/or use it to launch social engineering attacks such as follow-on phishing attempts, the firm claimed.

All 10 of the leaky APIs have now been deactivated. Still, CloudSEK urged developers to understand the potential impact of such issues early on and set up review processes to prevent them from escalating.

That’s because invalidating a payment integration key will stop an app from working, causing significant user friction and financial loss.

“Given the complexities of regenerating API keys, payment providers should design APIs such that, even if the key has not been invalidated, there are options to minimize the permissions and access controls of a given key,” CloudSEK concluded.

“App developers should be given a mechanism to limit what can be done using a key at a granular level, like AWS does. AWS has put in place identity and access management (IAM) policies that can be used to configure the permissions of every operation on an S3 bucket. This practice should be more widely adopted to minimize what threat actors can do with exposed API keys.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Former IT Exec Pleads Guilty to Insider Trading Conspiracy

Former IT Exec Pleads Guilty to Insider Trading Conspiracy

A former IT executive at a NASDAQ-listed healthcare company is facing more than a quarter of a century behind bars after pleading guilty to insider trading and preparing a false tax return.

Dayakar Mallu, 51, of Orlando, Florida, admitted to conspiring with others to trade in the securities of Mylan, which is now a part of global healthcare firm Viatris.

Between 2017 and 2019, the former vice president of global operations information technology worked with another unnamed executive to secure non-public information in advance of public announcements from the firm.

According to the Department of Justice (DoJ), they used this info to place trades and then cashed out via Indian banks, according to the Department of Justice (DoJ).

Mallu’s insider trading resulted in the former exec realizing net profits and losses avoided of more than $4.2m.

Mallu also admitted sending false information to his tax preparer relating to Opel Systems, a company that he owned and controlled, according to the DoJ.

He falsely told the third party that Opel had paid $1.3m to a contractor. In fact, Mallu directed Opel to transfer those funds to his personal securities brokerage account, according to court documents. Therefore, Mallu’s false statement resulted in the preparation of a false 2015 corporate return for Opel.

Mallu will be sentenced in January 2022 and will face a maximum penalty of 25 years in prison for conspiracy to commit securities fraud, plus three years for the tax offenses.

He’s by no means the first IT executive to find himself on the wrong side of the law. Last November, two eBay executives were indicted on charges of cyber-stalking, witness tampering and falsifying records.

In March last year, Anthony Levandowski, former tech lead at Google’s Waymo division, pleaded guilty to 33 counts of trade secrets theft related to his downloading of IP on self-driving cars before leaving the company.

However, he was subsequently pardoned by outgoing President Donald Trump.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Bring Your APIs Out of the Shadows to Protect Your Business

APIs are immensely more complex to secure. Shadow APIs—those unknown or forgotten API endpoints that escape the attention and protection of IT¬—present a real risk to your business. Learn how to identify shadow APIs and take control of them before attackers do.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Payment API Bungling Exposes Millions of Users’ Payment Data

Misconfigured APIs make any app risky, but when you’re talking about financial apps, you’re talking about handing ne’er-do-wells the power to turn your pockets inside-out.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains