NY County IT Supervisor Charged with Crypto-Mining

NY County IT Supervisor Charged with Crypto-Mining

An information technology expert employed by a New York county has been arrested on suspicion of mining crypto-currency at work.

Christopher Naples is accused of covertly installing dozens of machines throughout his workplace and using them to mine Bitcoin and other types of crypto-currency as part of a secret illegal money-making scheme. 

Naples, who lives in Mattituck, New York, was hired by Suffolk County back in 2000. His current title is Assistant Manager of Information Technology Operations for the Suffolk County Clerk’s Office.

Authorities said that the clandestine crypto-mining activity allegedly carried out by 42-year-old Naples ran up electricity bills in excess of $6,000 for his unsuspecting employer.

Charges were announced against Naples on Wednesday by Suffolk County district attorney Timothy Sini. Naples has been charged with counts including grand larceny, computer trespass, and public corruption.

Sini said Naples is accused of installing 46 crypto-mining devices in six rooms inside the county center located in Riverhead, New York. Hiding places in which the devices were allegedly concealed included beneath the floorboards of the building, on top of or inside server racks, and inside an electrical wall panel that was not in use.

The scheme had allegedly been going on for months with at least ten of the crypto-mining devices up and running since February 2021. 

Naples was released on his own recognizance after appearing in court on Wednesday. 

“Mining crypto-currency requires an enormous amount of resources, and miners have to navigate how to cover all of those electricity and cooling costs,” said Suffolk County’s Sini in a statement regarding Naples’ arrest. 

“Naples found a way to do it. Unfortunately, it was on the backs of taxpayers. We will not allow County employees, who are already on the public’s payroll, to steal taxpayer money or illegally use government resources for their own personal gain.”

The mining devices increased the temperature in some rooms by 20 degrees. 

Sini said: “Not only do we have thousands of dollars of taxpayer money funding this operation, but it also put the county’s infrastructure at risk.”

Naples faces up to 15 years in prison if convicted of the top count against him.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Global Databases Riddled with an Average of 26 Vulnerabilities

Global Databases Riddled with an Average of 26 Vulnerabilities

Nearly half (46%) of the world’s on-premises databases contain known vulnerabilities — most of which are high or critical severity, according to a new five-year study from Imperva.

The security vendor scanned 27,000 databases globally over five years and discovered that they contained 26 vulnerabilities each on average. Some 56% of these were ranked in the top two severity categories, meaning they could lead to serious compromise if exploited.

Some CVEs have not been addressed for several years, Imperva claimed.

Despite the growing popularity of cloud-based platforms, the news is concerning, as most organizations continue to store their most sensitive data on-premises, according to Elad Erez, chief innovation officer at Imperva.

“While organizations stress publicly how much they invest in security, our extensive research shows that most are failing,” he added.

“Too often, organizations overlook database security because they’re relying on native security offerings or outdated processes. Given that nearly one out of two on-prem databases is vulnerable, it is very likely that the number of reported data breaches will continue to grow, and the significance of these breaches will increase too.”

A standard route to compromising non-publicly accessible databases is via web application vulnerabilities such as SQLi or phishing and malware designed to give attackers a foothold into networks.

Compromising public databases is even more accessible, with attackers able to scan for exposed targets via tools like Shodan, before deploying exploit code, Imperva warned.

“Attackers now have access to a variety of tools that equip them with the ability to take over an entire database, or use a foothold into the database to move laterally throughout a network,” said Erez.

“The explosive growth in data breaches is evidence that organizations are not investing enough time or resources to truly secure their data. The answer is to build a security strategy that puts the protection of data at the center of everything.”

France was by far the worst global offender in terms of percentage of vulnerable databases (84%) and second only to China (74) in terms of the average number of bugs per database (72).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Apple Releases Urgent Patch Following Discovery of Pegasus Spyware

Apple Releases Urgent Patch Following Discovery of Pegasus Spyware

Apple has released an urgent update to patch a critical vulnerability that has been exploited by the notorious Pegasus mobile spyware.

The vulnerability, CVE-2021-30860, was discovered by researchers at University of Toronto’s Citizen Lab when analyzing the iPhone of an anonymous Saudi activist infected with NSO Group’s Pegasus spyware. They found a zero-day zero-click exploit against iMessage, which the team dubbed “FORCEDENTRY.” This exploit infected the device by targeting Apple’s rendering library, and was effective against Apple iOS, MacOS and WatchOS devices.

Citizen Lab made a “high-confidence attribution” to NSO Group for the exploit, which it believes has been in use since at least February 2021. It stated: “Our latest discovery of yet another Apple zero day employed as part of NSO Group’s arsenal further illustrates that companies like NSO Group are facilitating “despotism-as-a-service” for unaccountable government security agencies. Regulation of this growing, highly profitable and harmful marketplace is desperately needed.”

After the lab passed details of their findings to Apple, the tech giant quickly released the patch. Apple customers are now being urged to immediately update their devices with the latest update, with the vulnerability affecting all iPhones with iOS versions prior to 14.8, all Mac computers with operating system versions prior to OSX Big Sur 11.6, Security Update 2021-005 Catalina, and all Apple Watches prior to watchOS 7.6.2.

In a statement, Ivan Krstić, head of Apple security engineering and architecture, said: “Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals.” He also reassured customers that the vulnerability is “not a threat to the overwhelming majority of our users.”

Israeli firm NSO Group has regularly been at the center of numerous controversies surrounding the unethical use of Pegasus by authoritarian governments. Facebook is undertaking legal action against the company for allegedly exploiting a vulnerability in WhatsApp to enable its clients to spy on over 1400 users globally, and the spyware was also found on the mobile phone of murdered Saudi journalist Jamal Khashoggi.

CNN quoted a new NSO Group statement, which didn’t directly address the allegations. It stated: “NSO Group will continue to provide intelligence and law enforcement agencies around the world with life-saving technologies to fight terror and crime.”

Commenting on the story, Sam Curry, chief security officer at Cybereason, said: “Monday’s emergency software updates for a critical vulnerability discovered in iPhones, Apple Watches and Macs, shouldn’t be cause for panic. Yes, this newest Pegasus spyware delivery mechanism is novel, invasive and can easily infect billions of Apple devices, but stay calm and simply get control of your device and download the software updates available from Apple. Do that and move on. Follow Apple’s instructions if you think you are infected and consult your IT department at work, school, etc. Failing that, Apple’s Genius Bar will be able to help. With nearly 2 billion iPhones active around the world, 100 million Apple Watches being used and more than 100 million Macs, security can’t be a luxury for Apple and it’s not, it’s a responsibility they take seriously.”

Jesse Rothstein, CTO and co-founder of ExtraHop, added: “We all carry highly sophisticated personal devices which have profound implications to personal privacy. There are many examples of this such as app data collection — which Apple recently moved to curb with its App Tracking Transparency framework.

“Any sufficiently sophisticated system has security vulnerabilities that can be exploited, and mobile phones are no exception.

“Pegasus is an example of how unknown vulnerabilities can be exploited to access highly sensitive personal information. The NSO group is an example of how governments can essentially outsource or purchase weaponized cyber capabilities. This is no different than arms dealing in my view — it’s just not regulated that way. Companies are always going to have to patch their vulnerabilities, but regulations will help prevent some of these cyber weapons from being misused or falling into the wrong hands.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Texas GOP Website Down After Anonymous Hack

Texas GOP Website Down After Anonymous Hack

The website of the Texas Republican Party appeared to be hacked over the weekend and remained largely offline on Monday.

TexasGOP.org showed several crude messages on Saturday — the 20th anniversary of the September 11 terrorist attacks — ridiculing the state’s Republican Party and attacking Texas’ new ‘Heartbeat Act.’

Individuals affiliated with the Anonymous movement appear to be the perpetrators. Hackers replaced website pages with images of Pokémon, links were added directing users to the YourAnonNews Twitter account and pop artist Rick Astley’s viral meme hit Never Gonna Give You Up was added. 

However, the Texas Republican Party have seemingly regained partial control of the site on Monday. Yet, none of its typical content was accessible, and all URLs redirected users to a splash page, which outlined the attack and requested donations. 

The hack was likely influenced by the state’s controversial new abortion ban, prohibiting the practice after six weeks of the pregnancy and effectively halting abortions in some regions of the state altogether.

“We are committed to taking away all the rights of women so we can live our prosperous, Bible-thumping dream,” the Texas GOP’s mission statement was altered to say by the hackers. 

The hackers included a warning at the bottom of the website: “Disclaimer: Hackers on Steroids are 10 times more effective at romance than 100% of Republicans. Trans demon hackers are coming to get you. Abortion is a choice.”

Hackers also added a link to Planned Parenthood of Texas. 

The state’s new law has seen no lawsuits be filed since coming into effect on September 1. Pro-choice campaigners have been hoping that an emergency plea for relief at the Supreme Court would stop the law going ahead, but the court’s conservative majority declined to do so.

“While the nation paused over the weekend in remembrance of the 20th anniversary of 9/11 the Republican Party of Texas website was hacked,” read the website on Monday. “Pro-abortion activists targeted us because of our strong support for the Heartbeat Act. This attack adds to a growing list of actions by the radical left who tries to silence anyone that disagrees with them.” it added.

“We have been able to secure our website, but make no mistake, threats and attacks like this only strengthen our resolve.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Unpatched Bugs Plague Databases; Your Data Is Probably Not Secure – Podcast

Imperva’s Elad Erez discusses findings that 46 percent of on-prem databases are sitting ducks, unpatched and vulnerable to attack, each with an average of 26 flaws.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains