—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Friday Squid Blogging: Possible Evidence of Squid Paternal Care
Researchers have found possible evidence of paternal care among bigfin reef squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
ProtonMail Now Keeps IP Logs
After being compelled by a Swiss court to monitor IP logs for a particular user, ProtonMail no longer claims that “we do not keep any IP logs.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Before You Download: Steer Clear of Malicious Mobile Apps
Cybercriminals like to get in on a good thing. Case in point, mobile apps. We love using apps and they love making bogus ones—malicious apps designed to harm phones and possibly the person using them.
It’s no wonder that they target smartphones. They’re loaded with personal info and photos, in addition to credentials for banking and payment apps, all of which are valuable to loot or hold for ransom. Add in other powerful smartphone features like cameras, microphones, and GPS, and a compromised phone may allow a hacker to:
- Snoop on your current location and everyday travels.
- Hijack your passwords to social media, shopping, and financial accounts.
- Drain your wallet by racking up app store purchases or tapping into payment apps.
- Read your text messages or steal your photos.
All of that adds up to one thing—a great, big “no thanks!”
So how do these malicious apps work? By posing as legitimate apps, they can end up on your phone and gain broad, powerful permissions to files, photos, and functionality—or sneak in code that allows cybercriminals to gather personal info. As a result, that can lead to all kinds of headaches, ranging from a plague of popup ads to costly identity theft.
Here are a few recent examples of malicious apps in the news:
- Fake ad blocking programs that ironically serve up ads instead.
- Phony VPN apps that charge a subscription and offer no protection in return.
- Utility apps that hijack system privileges and permissions, which expose users to further attacks.
Again, “no thanks!” So, let’s see about steering clear of malicious apps like these.
Six steps to safer mobile app downloads
The good news is that there are ways you can spot these imposters. Major app marketplaces like Google Play and Apple’s App Store do their part to keep their virtual shelves free of malware, as reported by Google and Apple themselves. Still, cybercriminals can find ways around these efforts. (That’s what they do, after all!) So, a little extra precaution on your part will help you stay safer. These six steps can help:
1) Avoid third-party app stores
Unlike Google Play and Apple’s App Store, which have measures in place to review and vet apps to help ensure that they are safe and secure, third-party sites may not have that process in place. In fact, some third-party sites may intentionally host malicious apps as part of a broader scam. Granted, cybercriminals have found ways to work around Google and Apple’s review process, yet the chances of downloading a safe app from them are far greater than anywhere else. Furthermore, both Google and Apple are quick to remove malicious apps once discovered, making their stores that much safer.
2) Review with a critical eye
As with so many attacks, cybercriminals rely on people clicking links or tapping “download” without a second thought. Before you download, take time to do some quick research, which may uncover a few signs that the app is malicious. Check out the developer—have they published several other apps with many downloads and good reviews? A legit app typically has quite a few reviews, whereas malicious apps may have only a handful of (phony) five-star reviews. Lastly, look for typos and poor grammar in both the app description and screenshots. They could be a sign that a hacker slapped the app together and quickly deployed it.
Examples of Google Play and Apple App Store entries that list the name of the developer.
3) Go with a strong recommendation
Even better than combing through user reviews yourself is getting a recommendation from a trusted source, like a well-known publication or from app store editors. In this case, much of the vetting work has been done for you by an established reviewer. A quick online search like “best fitness apps” or “best apps for travelers” should turn up articles from legitimate sites that can suggest good options and describe them in detail before you download.
4) Keep an eye on app permissions
Another way cybercriminals weasel their way into your device is by getting permissions to access things like your location, contacts, and photos—and they’ll use sketchy apps to do it. (Consider the long-running free flashlight app scams mentioned above that requested up to more than 70 different permissions, such as the right to record audio, video, and access contacts.) So, pay close attention to what permissions the app is requesting when you’re installing it. If it’s asking for way more than you bargained for, like a simple game wanting access to your camera or microphone, it may be a scam. Delete the app and find a legitimate one that doesn’t ask for invasive permissions like that.
Previewing app permissions in the App Store and Google Play.
Additionally, you can check to see what permissions an app may request before downloading the app. In Google Play, scroll down the app listing and find “About this app.” From there, click “App permissions,” which will provide you with an informative list. In the iOS App Store, scroll down to “App Privacy” and tap “See Details” for a similar list. If you’re curious about permissions for apps that are already on your phone, iPhone users can learn how to allow or revoke app permissions here, and Android can do the same here.
5) Protect your smartphone with security software
With all that we do on our phones, it’s important to get security software installed on them, just like we do on our computers and laptops. Whether you go with comprehensive security software that protects all of your devices or pick up an app in Google Play or Apple’s iOS App Store, you’ll have malware, web, and device security that’ll help you stay safe on your phone.
6) Update your phone’s operating system
Hand-in-hand with installing security software is keeping your phone’s operating system up to date. Updates can fix vulnerabilities that cybercriminals rely on to pull off their malware-based attacks—it’s another tried and true method of keeping yourself safe and your phone running in tip-top shape.
Stay on guard against mobile malware
Here are a few more things you can do:
- Keep a close eye on your phone. Mobile malware sometimes leaves clues that your phone has been compromised, like making it run hot or perform poorly.
- Keep tabs on your accounts. With any kind of scam or identity theft, it’s likely going to leave a record in your statements or payment and banking apps. If you spot something fishy there, follow up and report it.
- Consider checking your credit report for signs of fraud as part of your overall security measures. It may uncover identity theft-related transactions that you were entirely unaware of, such as someone renting an apartment in your name.
Lastly, you can always ask yourself, “Do I really need this app?” One way to avoid malicious mobile apps is to download fewer apps overall. If you’re unsure if that free game is on the up-and-up or if the offer for that productivity app sounds a little too good, skip it. Look for a better option or pass on the idea altogether. As said earlier, cybercriminals really rely on us clicking and downloading without thinking. Staying on guard against mobile malware will cost you a few moments of your time, which is minimal compared to the potential costs of a hacked phone.
The post Before You Download: Steer Clear of Malicious Mobile Apps appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
KrebsOnSecurity Hit By Huge New IoT Botnet “Meris”
On Thursday evening, KrebsOnSecurity was the subject of a rather massive (and mercifully brief) distributed denial-of-service (DDoS) attack. The assault came from “Meris,” the same new botnet behind record-shattering attacks against Russian search giant Yandex this week and internet infrastructure firm Cloudflare earlier this summer.

Cloudflare recently wrote about its attack, which clocked in at 17.2 million bogus requests-per-second. To put that in perspective, Cloudflare serves over 25 million HTTP requests per second on average.
In its Aug. 19 writeup, Cloudflare neglected to assign a name to the botnet behind the attack. But on Thursday DDoS protection firm Qrator Labs identified the culprit — “Meris” — a new monster that first emerged at the end of June 2021.
Qrator says Meris has launched even bigger attacks since: A titanic and ongoing DDoS that hit Russian Internet search giant Yandex last week is estimated to have been launched by roughly 250,000 malware-infected devices globally, sending 21.8 million bogus requests-per-second.
While last night’s Meris attack on this site was far smaller than the recent Cloudflare DDoS, it was far larger than the Mirai DDoS attack in 2016 that held KrebsOnSecurity offline for nearly four days. The traffic deluge from Thursday’s attack on this site was was more than four times what Mirai threw at this site five years ago. This latest attack involved more than two million requests-per-second. By comparison, the 2016 Mirai DDoS generated approximately 450,000 requests-per-second.
According to Qrator, which is working with Yandex on combating the attack, Meris appears to be made up of Internet routers produced by MikroTik. Qrator says the United States is home to the most number of MikroTik routers that are potentially vulnerable to compromise by Meris — with more than 42 percent of the world’s MikroTik systems connected to the Internet (followed by China — 18.9 percent– and a long tail of one- and two-percent countries).
The darker areas indicate larger concentrations of potentially vulnerable MikroTik routers. Qrator says there are about 328,000 MikroTik devices currently responding to requests from the Internet. Image: Qrator.
It’s not immediately clear which security vulnerabilities led to these estimated 250,000 MikroTik routers getting hacked by Meris.
“The spectrum of RouterOS versions we see across this botnet varies from years old to recent,” the company wrote. “The largest share belongs to the version of firmware previous to the current stable one.”
It’s fitting that Meris would rear its head on the five-year anniversary of the emergence of Mirai, an Internet of Things (IoT) botnet strain that was engineered to out-compete all other IoT botnet strains at the time. Mirai was extremely successful at crowding out this competition, and quickly grew to infect tens of thousands of IoT devices made by dozens of manufacturers.
And then its co-authors decided to leak the Mirai source code, which led to the proliferation of dozens of Mirai variants, many of which continue to operate today.
The biggest contributor to the IoT botnet problem — a plethora of companies white-labeling IoT devices that were never designed with security in mind and are often shipped to the customer in default-insecure states — hasn’t changed much, mainly because these devices tend to be far cheaper than more secure alternatives.
The good news is that over the past five years, large Internet infrastructure companies like Akamai, Cloudflare and Google (which protects this site with its Project Shield initiative) have heavily invested in ramping up their ability to withstand these outsized attacks [full disclosure: Akamai is an advertiser on this site].
More importantly, the Internet community at large has gotten better at putting their heads together to fight DDoS attacks, by disrupting the infrastructure abused by these enormous IoT botnets, said Richard Clayton, director of Cambridge University’s Cybercrime Centre.
“It would be fair to say we’re currently concerned about a couple of botnets which are larger than we have seen for some time,” Clayton said. “But equally, you never know they may peter out. There are a lot of people who spend their time trying to make sure these things are hard to keep stable. So there are people out there defending us all.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Prison for BEC Scheme Money Launderer
Prison for BEC Scheme Money Launderer

An Ontario resident, who admitted laundering tens of millions of dollars stolen by cyber-criminals in various wire and bank fraud schemes, is to spend the next 140 months in a United States federal prison.
Dual Canadian and United States citizen Ghaleb Alaumary, formerly of Mississauga, was sentenced yesterday after pleading guilty to two counts of conspiracy to commit money laundering.
He was further ordered to pay $30m in restitution to his victims and to serve three years of supervised release after completing his custodial sentence.
The 37-year-old was found to have acted as a money launderer in multiple criminal schemes, including business email compromise (BEC) scams and cyber-enabled bank heists perpetrated by North Korean hackers.
The Department of Justice said in a statement: “With respect to the North Korean co-conspirators’ activities, Alaumary organized crews of co-conspirators in the United States and Canada to launder millions of dollars obtained through ATM cash-out operations, including from BankIslami and a bank in India in 2018.”
Alaumary also conspired with others, including Ramon Olorunwa Abbas, also known as Ray Hushpuppi, to launder funds stolen from a Maltese bank by North Korean cyber-criminals in February 2019.
In one of the money-laundering cases, Alaumary recruited and organized individuals to withdraw stolen cash from ATMs. He also provided the bank accounts into which the funds from cyber bank heists and fraud schemes were deposited.
Alaumary then further laundered the stolen money through wire transfers, cash withdrawals, and by exchanging the funds for crypto-currency.
In the second case, Alaumary conspired with others in 2017 to impersonate a construction company and request payment from a university in Canada for a major building project.
“The university, believing it was paying the construction company, wired 11.8 million Canadian dollars (approximately 9.4 million U.S. dollars) to a bank account controlled by Alaumary and his co-conspirators,” said the Department of Justice.
Acting US Attorney David Estes said Alaumary “laundered money for a rogue nation and some of the world’s worst cyber-criminals, and he managed a team of co-conspirators who helped to line the pockets and digital wallets of thieves.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cyber-criminal Targets Dadsnet Founders
Cyber-criminal Targets Dadsnet Founders

A hacker who calls themself “The King” is demanding more than $40,000 to return control of a social media account to its rightful owners.
The access being held to ransom relates to an Instagram account belonging to 33-year-old Al Ferguson and his 43-year-old wife, Jen, who together founded a parenting forum geared toward fathers, Dadsnet.
For more than seven years, the entrepreneurial British couple have shared personal details of their lives with tens of thousands of their followers on Instagram. But the pair recently found themselves locked out of their account.
Jen told the Daily Star that a hacker compromised their account and changed the handle. The attacker sent a message via WhatsApp demanding that she and Al pay £1 per follower to regain control over their account.
The couple, who live in Tunbridge Wells, Kent, have 30,000 followers on their Instagram account, making the ransom demand more than $41,500.
On August 29, via WhatsApp, Jen received a screenshot of the Instagram account that showed that the handle had been switched from @it’sTheFergusons to @PharaBenDarWay30K.
The family photo that had been in place as the profile picture had been swapped to an image of a bloodied face. In place of the couple’s profile description, the attacker had written, “This Instagram account is held to be sold back to its owner.”
Jen and Al tried but failed to regain control of the Instagram account. On Tuesday, 36 hours after the hacker made contact, the account was deleted.
The couple said that some of the 5,000 photos they had shared via the account have now been lost forever. Gone too are the captions capturing the family’s highs and lows, which have included seven miscarriages.
Al said: “We’re devastated. All our emotions and memories from the last seven years were in that account.”
The cybercrime has also had a financial impact on the couple, who used to receive income from the account via adverts and sponsorship.
“It feels like someone has come in and stolen all our diaries,” said Jen. “They’ve taken our jobs too, but the emotional side is much, much worse.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Hackers Steal Data from United Nations
Hackers Steal Data from United Nations

Hackers have broken into the computer network of the United Nations and made off with data, according to researchers at cybersecurity firm Resecurity.
Bloomberg reports that the unidentified cyber-criminals behind the theft appear to have gained access simply by using login credentials stolen from a UN employee.
Entry was gained by logging in to the employee’s Umoja account. Umoja, which means “unity” in Kiswahili, is the enterprise resource planning system implemented by the UN in 2015.
It has been theorized that the username and password used in the cyber-attack were purchased from a website on the dark web.
Gene Yoo, chief executive officer at Resecurity, said: “Organizations like the UN are a high-value target for cyber-espionage activity.
“The actor conducted the intrusion with the goal of compromising large numbers of users within the UN network for further long-term intelligence gathering.”
Researchers found that the UN’s systems were first accessed by hackers on April 5, 2021, and that network intrusions continued to take place until August 7.
No evidence was found to suggest that the attackers had damaged or sabotaged the UN’s computer network. The hackers seem to have been motivated instead by a desire to collect information.
Resecurity said that after reporting the security incident to the UN, it worked with the organization’s security team to determine the scale of the intrusion.
While the UN reportedly believes the attack was a reconnaissance mission by hackers who took nothing but screenshots of the organization’s compromised network, Resecurity researchers say that data was stolen in the incident.
Yoo told Bloomberg that the UN ceased communicating with Resecurity after proof of data theft was provided to the organization.
“This attack had been detected before we were notified by the company cited in the Bloomberg article, and corrective actions to mitigate the impact of the breach had already been planned and were being implemented,” UN spokesman Farhan Haq told the DailyMail.com.
“At that time, we thanked the company for sharing information related to the incident and confirmed the breach to them.”
Haq added that the United Nations is frequently targeted by cyber-attacks, including sustained campaigns.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Security Now a “Thankless Task” For 80% of IT Teams
Security Now a “Thankless Task” For 80% of IT Teams

Securing the new hybrid workplace may require significant changes to culture, policy and technology after new HP research revealed significant pushback from remote workers during the pandemic.
The tech giant surveyed over 1000 IT decision-makers and more than 8400 workers across the globe to compile its latest HP Wolf Security study, Rebellions & Rejections.
It revealed that nearly all (91%) IT leaders had felt pressure to compromise on security during the pandemic, with three-quarters (76%) admitting security took a backseat to business continuity.
As a result, 83% of IT teams believe the increase in home workers has created a “ticking time bomb” for a corporate network breach.
These fears are reflected in the uncompromising attitudes of those workers — particularly the younger cohort.
Almost half (48%) of younger workers (18-24 years old) claimed security tools were a hindrance, and nearly a third (31%) have tried to bypass corporate policies to get work done.
Over half (54%) claimed to be more worried about meeting deadlines than exposing their organization to data breaches. In comparison, two-fifths (39%) were unsure what their security policies say or even if their company has them.
Ian Pratt, global head of security for personal systems at HP Inc, warned that breaches could result from users bypassing internal security controls and policies.
“If security is too cumbersome and weighs people down, then people will find a way around it. Instead, security should fit as much as possible into existing working patterns and flows, with technology that is unobtrusive, secure-by-design and user-intuitive,” he added.
“Ultimately, we need to make it as easy to work securely as it is to work insecurely, and we can do this by building security into systems from the ground up.”
The dynamic is also taking its toll on IT teams. Some 83% said trying to set and enforce corporate security policies is impossible given the lines between personal and professional are so blurred. In comparison, 80% said security was becoming a “thankless task” as no one listens anymore.
HP CISO, Joanna Burkey, argued that employee education and engagement is the first step towards improving security for the hybrid workplace. She added that IT teams should also re-evaluate policies to take account of the new working environment.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Attacker Breakout Time Now Less Than 30 Minutes
Attacker Breakout Time Now Less Than 30 Minutes

The average time it takes threat actors to move from initial access to lateral movement has fallen by 67% over the past year, putting extra pressure on security operations (SecOps) teams, according to CrowdStrike.
The findings come from the security firm’s own investigations with customers across around 248,000 unique global endpoints.
For incidents where this “breakout time” could be derived over the past year, it averaged just 1 hour 32 minutes. However, in over a third (36%) of intrusions, adversaries managed to move laterally to additional hosts in under 30 minutes.
That reportedly makes the job of incident responders more challenging. With lateral movement comes the discovery of data to exfiltrate and new systems to deploy ransomware on.
Zeki Turedi, EMEA CTO, CrowdStrike, told Infosecurity that once lateral movement occurs, incidents become harder and more costly to resolve.
“In simple terms, it is easier to deal with a threat actor when they are on one machine than multiple,” he added.
“For a threat actor to start moving laterally they must have already done some basic reconnaissance of the network, but more importantly have credentials to allow them to start moving across the network. At this point they potentially have the keys to the kingdom (network) and can start moving and causing disruption quickly.”
Threat actors are also becoming more stealthy. In 68% of detections indexed by CrowdStrike, no malware was used at all. This means “living off the land” techniques and legitimate tooling was employed to stay under the radar of traditional security tools.
In total, the vendor detected a 60% increase in attempted intrusions across all verticals and geographic regions between July 2020 and June 2021 versus a year previous.
Not all of this activity is about data collection and ransomware deployment. CrowdStrike recorded a 100% year-on-year increase in crypto-jacking in interactive intrusions.
When it came to targeted intrusions, China-based threat actors were the most prolific by far, accounting for 67% of incidents. Next came unattributed state-backed attackers (20%), then Iran (7%) and North Korean (5%) actors.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
