Texan Accused of Cyber-Stalking and Murder Dies in Jail

Texan Accused of Cyber-Stalking and Murder Dies in Jail

A Texan who was indicted on capital murder charges after being accused of cyber-stalking real estate agents and threatening to sexually assault their children has died in jail. 

Andy Castillo was “released deceased” from the Lubbock County Detention Center on Friday at 4:33pm. Officials from the Lubbock County Sheriff’s Office haven’t revealed how the 58-year-old former resident of Lubbock met his end, but did say that Castillo was at the University Medical Center when he died. 

Castillo was charged in January 2020 over the cyber-harassment of realtors in the Waco area. He allegedly used apps to mask his identity before sending the realtors sexually explicit images and videos from multiple phones.

Castillo was further accused of downloading photos of realtors’ children from social media and sending these images to the realtors along with graphic descriptions of the ways in which he wanted to sexually assault the minors. 

Authorities believe Castillo may have stalked around 100 realtors in roughly 20 cities and 10 states. Police said that Castillo sent his last perverse and threatening message roughly five minutes before his arrest.

Castillo was charged with one count of cyber-stalking and two counts of criminal solicitation-aggravated sexual assault of a child. However, these charges were dropped in December 2020 when Castillo was indicted for the murder of two women who were roommates in Lubbock County.

Last September, cold case investigators linked DNA samples taken from Castillo when he was arrested in connection with the cyber-stalking to DNA evidence collected from the murder scenes of 21-year-old Cynthia Palacio and 21-year-old Linda Carbajal. 

Palacio was strangled to death in July 2003 and her roommate’s life was cut short nine months later. The bodies of both women were discovered on two different rural roads in Texas. 

“A lot of women have been victimized by this creep,” said McLennan County Sheriff Parnell McNamara.

Speaking after Castillo’s DNA had been found on Palacio’s blouse and necklace and under her fingernails as well as in semen on her thigh, McNamara said: “There’s no question in our mind that he committed this murder.” 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI Warns Food and Agriculture Firms of Ransomware Threat

FBI Warns Food and Agriculture Firms of Ransomware Threat

The FBI has issued a new alert warning companies in the food and agricultural sector that they are increasingly at risk of ransomware as their corporate attack surface expands.

The Private Industry Notification, seen by Infosecurity, noted that the vertical is a critical infrastructure sector which, if impacted by such threats, could negatively impact the food supply chain.

“Ransomware may impact businesses across the sector, from small farms to large producers, processors and manufacturers, and markets and restaurants,” it continued. “Cyber-criminal threat actors exploit network vulnerabilities to exfiltrate data and encrypt systems in a sector that is increasingly reliant on smart technologies, industrial control systems and internet-based automation systems.”

Attacks may target larger organizations, deemed more likely to pay higher ransom demands, and smaller firms perceived as softer targets. For both, the increasing move to IoT may offer a new attack surface to target, the FBI warned.

“According to a private industry report, cyber actors may gradually broaden their attack from just IT and business processes to also include the operational technology (OT) assets, which monitor and control physical processes, impacting industrial production regardless of whether the malware was deployed in IT or OT systems,” it noted.

As with all ransomware victims, those in the food and agricultural sector would suffer lost productivity, theft of proprietary and personal information, and reputational and financial damage, the alert claimed.

The industry has already been a target for attacks, most notably the May 2021 raid on Brazilian meat processing giant JBS USA, which the FBI said drove wholesale prices up 25% after various plants across the country were forced to close.

Other incidents cited in the alert include a US bakery which was forced to close for a week in July, a “US-based international food and agriculture business” that was hit by the OnePercent group in November 2020, demanding a $40m ransom, and the attack on beverage giant Molson Coors in March this year.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Imprisons Dark Web Moderator

US Imprisons Dark Web Moderator

A man from Southern Illinois who moderated a website focused on child sexual abuse material (CSAM) has been sent to federal prison for 12 years and 7 months.

Thirty-seven-year-old Sparta resident Kory R. Schulein was indicted by a federal grand jury in October 2020 on a single count of knowingly receiving CSAM over the internet. 

Prosecutors said the unemployed man from Randolph County spent years downloading, sharing, and storing videos and images of minors being sexually assaulted. 

According to the indictment, in addition to being a moderator on a CSAM-focused website, Schulein was an active user of other dark websites offering similar content.  

Law enforcement first became aware of Schulein in 2018 during an FBI investigation of CSAM on the dark web. A federal search warrant was executed at this home address on October 1, 2019, after agents tracked his IP address.

CSAM was discovered by officers on a laptop computer and two external hard drives belonging to Schulein. The illegal and explicit content was downloaded from 2016 to 2019, according to court documents.

More than 9,000 images and videos of CSAM were stored by Schulein on an encrypted hard drive. 

The National Center for Missing and Exploited Children (NCMEC) confirmed the identities of some of the minors depicted in the more than 2,500 images and 100 videos found in Schulein’s possession.

Schulein was found to have posted 13,733 messages on dark websites that were focused on CSAM. Many of his posts included links to videos and images of children being sexually abused. 

The investigation into Schulein was carried out by FBI-Springfield in collaboration with the United States Marshals

Service. The case against him was brought as part of the nationwide initiative Project Safe Childhood. 

On April 29, 2021, Schulein pleaded guilty to knowingly receiving CSAM over the internet. Earlier today, he was 

sentenced to 151 months, or 12 and a half years, in prison. 

Judge Stephen McGlynn, when sentencing Schulein, noted that some of the images and videos collected by the

offender showed children in bondage and adults raping children, including 5-year-old girls and toddlers

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Gun Owners’ Data Exposed

UK Gun Owners’ Data Exposed

The personal information of more than 100,000 UK-based firearm owners appears to have been leaked online.

The data was reportedly published on the blog of an animal rights activist in the form of a reformatted CSV file. When imported into Google Earth, the file showed individual home addresses where guns were believed to be stored, along with owners’ zip codes, phone numbers, IP addresses and email addresses. 

Blog readers were encouraged to “contact as many [gun owners] as you can in your area and ask them if they are involved in shooting animals.” 

News of the leak follows firearm e-tailer Guntrader’s confirmation in July of a data breach impacting more than 100,000 of its customers. 

Guntrader sells new and used shotguns, rifles, air rifles, air pistols and shooting equipment via its website, Guntrader.co.uk. In an email to site users, the site’s managing director, Alexander Andover, said that a database belonging to the company had been stolen.

Included in the stolen database was the personal information of users who had registered with Guntrader between 2016 and 2021 using the vendor’s own electronic gun register software. 

An investigation into the Guntrader breach and its repercussions has been launched by the UK’s National Crime Agency, which said that it “is aware that information has been published online as a result of a recent data breach which impacted Guntrader.”

The agency said: “We are working closely with the South West Regional Cyber Crime Unit, who are leading the criminal investigation, to support the organization and manage any risk.”

Guntrader said that the stolen data did not include any financial information. The site has advised users to change their passwords. 

The British Association for Shooting and Conservation (BASC) responded to the breach with a statement that read: “Our advice to members would be to check home security and be extra vigilant. Make sure all firearms are appropriately locked away and make sure buildings are kept secure.”

Mark Montaldo, a director and data breach specialist at UK-based CEL Solicitorssaid: “I’ve already spoken to several Guntrader users who are naturally afraid for their safety making this a really serious breach.”

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

WhatsApp Fined €225m for GDPR Violations

WhatsApp Fined €225m for GDPR Violations

WhatsApp has been hit by a €225m fine by Ireland’s Data Protection Commission (DPC) for failing to discharge GDPR transparency obligations.

The DPC made the announcement today following the conclusion of an investigation that began in December 2018. This examined whether the popular messaging app “has discharged its GDPR transparency obligations with regard to the provision of information and the transparency of that information to both users and non-users of its service.”

This includes information provided to data subjects about the processing of information between WhatsApp and other Facebook companies.

The DPC submitted its draft decision to other data protection authorities (DPAs) across the EU under Article 60 of the GDPR in December 2020, receiving objections to its proposed actions by eight DPAs. As no consensus could be found, the dispute resolution process under Article 65 of GDPR was triggered on June 3 2021.

The European Data Protection Board (EDPB) then adopted a binding decision on the case, instructing the DPC to reassess and increase its proposed fine. This decision was based on a number of factors, including the size of Facebook’s global annual turnover, with the EDPB stating that “the proposed fine does not adequately reflect the seriousness and severity of the infringements nor has a dissuasive effect on WhatsApp IE.”

Following its reassessment, the DPC has now imposed a fine of €225m on WhatsApp, in addition to a reprimand and “an order for WhatsApp to bring its processing into compliance by taking a range of specified remedial actions.” In total, WhatsApp must comply with eight actions within three months, one of which is an obligation to remind users of their GDPR rights.

The decision represents the second highest financial penalty recorded for violating GDPR rules, behind the $886m fine issued to Amazon earlier this year for allegedly breaking European Union data protection laws.

Reacting to the decision, legal firm Cordery Compliance stated: “Transparency continues to be a key focus for DPAs across Europe. Organizations need to be clear over how they process data and they need to be honest about their data processing practices. Sometimes the transparency obligations under GDPR can be difficult to meet – especially in cases like this where WhatsApp was also processing data on non-users with whom it did not have a direct relationship. Just because this is hard however it doesn’t mean the obligations can simply be ignored.”

Jonathan Armstrong, partner at Cordery, expects to see more fines of this nature going forward: “This case shows us that data protection regulators in many EU countries are serious about data protection and that many are keen to raise the level of fine. It also shows us that data protection is not just about infosec — transparency is a key theme of a lot of GDPR enforcement at the moment and that’s the central theme of the three highest GDPR fines. But that doesn’t mean we can take the foot off the pedal on security.  There are some big cases around at the moment and this won’t be the last high fine we’ll see.”

Ioannis Fragkoulopoulos, customer security director, Obrela Security Industries, commented: “WhatsApp’s privacy terms and conditions have come under scrutiny frequently in the past and the company has had to defend its terms and conditions many times, with users leaving the platform because of ambiguities and policy changes. This fine shows just how serious the Irish government is around transparency. When consumers sign up to platforms, they need to understand exactly how their data will be used and if it will be shared with third parties. This fine will reinforce the importance of this and act as a warning to other companies to be more transparent.”

In May, a German privacy watchdog ruled that WhatsApp’s privacy policy, which was updated in January 2021 to ask its users to grant WhatsApp additional powers to share their data with its parent company, Facebook, was in breach of European data protection rules.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Researchers Invent Device to Thwart USB Malware

UK Researchers Invent Device to Thwart USB Malware

A team of researchers at a UK university have designed a new device, which they claim will mitigate the risk of malicious USB drives.

The “external scanning device” was designed at Liverpool Hope University and will soon go into production, having been granted a patent by the Indian government.

It has been engineered to overcome a major issue with operating systems — that if not configured correctly, they will trust all USBs regardless of what might be installed on them.

This could allow for the automatic transfer of malware from the thumb drive to the host PC.

However, the new device sits between the PC or laptop and USB stick, scanning the removable media for malware whilst disguising information about the computer so that it’s “nearly impossible” for any malicious code to infect the machine.

“Our invention safeguards the host computing device by providing an additional layer of hardware security, and by hiding the host operating system information. The disguised information effectively confuses the external memory device that is plugged into the computing device,” explained project lead, Shishir Kumar Shandilya.

“The invented device also scans the USB and decides the visibility and accessibility of the files present in USB devices at the host computer, giving either full access, partial access or a full block.”

Effectively, the new scanning device aims to “keep the malicious code busy” with a disguised OS, while it scans and categorizes the thumb drive.

The project is said to stem from a relatively new field known as Nature Inspired Cybersecurity (NICS), which takes ideas from the natural world and applies them to IT, to enhance cyber defense.

Shandilya, who is a visiting research fellow in Hope’s School of Mathematics, Computer Science and Engineering, claimed the team is in discussions with manufacturers about how to turn the full prototype into a commercially viable device.

Although not the threat they once were, USB-borne malware threats doubled in OT environments from 2019-2020, according to Honeywell.

There’s also a chance that the advent of hybrid working may lead to a resurgence in the use of thumb drives.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains