Arizona Cops Arrest Fugitive in Police Data Bribery Case

Arizona Cops Arrest Fugitive in Police Data Bribery Case

Police in Arizona have arrested a Tennessee man who went on the run after being indicted over a scheme to profit from confidential records belonging to the Memphis Police Department (MPD).

On Wednesday, US Marshal Tyreece Miller announced the arrest of Roderick Harvey for bribery of a public servant and violation of a computer act over $10,000.

The Tennessee Bureau of Investigation (TBI), working with the US Marshals Two Rivers Violent Fugitive Task Force, tracked Harvey to Phoenix, where he was detained without incident and booked into the Maricopa County Jail.

Miller said: “Despite Harvey’s attempt to evade arrest by traveling over a thousand miles, he was safely apprehended.”

Harvey was one of nine people indicted by a Shelby County Grand Jury on August 6 following a year-long investigation by the TBI that began in June 2020. 

The probe was requested by district attorney general Amy Weirich after former Shelby County assistant district attorney Glenda Adams was fired from her role and investigated after allegedly misusing confidential information.

Harvey’s alleged co-conspirators include Adams, three former employees of MPD, and a personal injury attorney with Wells & Associates. The TBI investigation found that Adam, Harvey, Egypt Berry, Latausha Blair, Renatta Dillard, Marcus Lewis, Aaron Neglia, Martin Nolan, and Mustafa Sajid “were responsible for an elaborate scheme to profit from the use of confidential information in Memphis police reports.”

Case prosecutor Bryant Dunaway said the scheme involved buying information about traffic crashes from government employees before that information became public. 

He said: “It seems to be there’s big business in personal injury attorneys and others to acquire information on crash victims, early, before it’s available to the public. It’s kind of a race to get there.”

Adams, Berry, Lewis, Neglia, Nolan and Sajid are all accused of bribing a public servant. Adams, Berry, Blair, Dillard, Neglia and Nolan are accused of a violation of the computer act over $10,000. Adams, Berry and Nolan are accused of official misconduct. 

Berry and Dillard were in custody by August 6, and all the other defendants except Harvey made arrangements to turn themselves into law enforcement. 

The TBI said the investigation remains ongoing and “more indictments are expected.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Angry Birds Developer Accused of Illegal Data Collection

Angry Birds Developer Accused of Illegal Data Collection

The attorney general of New Mexico has brought a lawsuit against a Finnish game developer over its treatment of children’s data.

In the complaint, Hector Balderas accuses Rovio Entertainment of illegally collecting the data of children under the age of 13 who play the puzzle video game Angry Birds.

Rovio is further accused of sending the children’s data to multiple third-party marketing companies that analyze, repackage, resell and otherwise use the information to sell targeted advertising to those children.

The suit states: “Rovio monetizes children by surreptitiously exfiltrating their personal information while they play the Angry Birds Gaming Apps and then using that personal information for commercial exploitation.” 

Developers of child-directed games are required under the federal Children’s Online Privacy Protection Act (COPPA) to obtain parental consent before collecting any personal information from players. Creators whose games are targeted at a wide age range must still take action to ensure that data belonging to users under the age of 13 is not collected.

“The State’s complaint alleges that Rovio has deliberately attempted to turn a blind eye to its enormous child audience, while simultaneously marketing the Angry Birds games to kids through movies, lunch boxes, kids’ meals, and more,” wrote the New Mexico attorney general’s office in a statement released Wednesday.

New Mexico is seeking an injunction to prohibit Rovio’s data collection practices. The state is also pursuing civil penalties and restitution from the Finnish game developer. 

“Parents must have the power to protect their children and determine who can have access to their child’s personal data, and New Mexican parents are being misled about what information is being collected from their children,” said Balderas. 

“This company must follow the law, and we will always hold companies accountable that risk the safety of children.”

Angry Birds is a simplistic game in which cartoon birds are launched from a giant slingshot to knock down structures erected by green cartoon pigs.

Since the game series was launched in 2009, its 35 spin-off games have been downloaded more than 4.5 billion times collectively, making Angry Birds the most downloaded freemium game series of all time.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Cyber Security Council Opens Membership Application Process

UK Cyber Security Council Opens Membership Application Process

The UK Cyber Security Council has today announced it has opened its membership application process.

The self-regulatory body for the cybersecurity education and skills sector, which launched as an independent entity earlier this year, is now inviting applications from eligible organizations throughout the UK. These are any organizations “with an interest in promoting, supporting and developing the cybersecurity profession.”

Those organizations whose membership applications are accepted will be allowed to nominate representatives to the Council’s committees, focusing on the core activities of professional standards, qualifications and careers, ethics and diversity.

Don MacIntyre, interim CEO for the UK Cyber Security Council, commented: “Professional standards, qualifications and careers, ethics and diversity are the stand-out issues facing the profession and its practitioners. Businesses with an interest in cyber security will never have a better opportunity to influence the direction and development of these and other issues than to join the Council and getting involved.”

The Council added that it would be putting in place engagement mechanisms to gather views from member organizations and use these insights to inform activities and decisions. MacIntyre said: “It is only through building an actively engaged community of members that the Council will be able to speak as the representative voice for the UK’s cyber security profession. With every new membership, our voice becomes clearer, louder and increasingly more difficult to be ignored.”

The UK government commissioned the UK Cyber Security Council in 2018 to promote and steward standards across the industry, and the overarching aim of helping close the UK’s cyber skills gap.

In June, the Council announced its first two initiatives as part of its remit to boost professional standards in the cyber industry. These were to determine the terms of two committees: a Professional Standards & Ethics Committee and a Qualifications & Careers Committee. These committees are tasked with helping ensure a common set of standards are adopted throughout education and training interventions related to cybersecurity. The Council also revealed it would be working on an initial mapping of CyBOK’s Qualifications Framework onto a public-facing Career Pathways Framework.


For more information on how to apply for membership to the Council, visit: https://www.ukcybersecuritycouncil.org.uk/membership/

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

“Sophisticated” Cyber-Attack Compromises Patient Data at Private Health Clinic

“Sophisticated” Cyber-Attack Compromises Patient Data at Private Health Clinic

Personal and clinical data of more than 73,000 patients have been affected by a “sophisticated ransomware cyber-attack” on a private medical clinic in Singapore.

In a press release, Eye & Retina Surgeons revealed the attack took place on 6 August, compromising sensitive data including patients’ names, addresses, ID card numbers, contact details and clinical information. However, no credit card or bank account details were accessed or compromised in the incident.

“Patients are now being progressively informed of this cyber-incident,” the release stated.

The clinic confirmed that the attack impacted servers and several computer terminals at its branch in Camden medical, although none of its other branches were unaffected. Thankfully, none of the eye specialist’s clinical operations were affected, and its IT systems are now securely restored.

The company noted it “maintains segregated networks and active medical records are maintained separately on a cloud-based system and thus were not accessed or compromised.”

The incident was reported to the Personal Data Protection Commission and the Singapore Computer Emergency Response Team (SingCERT), while the Eye & Retina Surgeons’ IT team is working with the Cybersecurity Agency of Singapore (CSA) and the Ministry of Health (MOH) to investigate the causes and perpetrators of the attack.

The clinic said there is no evidence that any compromised data has been published, but it will continue to monitor the situation. It added: “(Eye & Retina Surgeons) regrets this breach and wishes to assure its patients that it takes patient confidentiality very seriously.”

In a separate statement, Singapore’s MOH reassured citizens that the compromised systems are not connected to its own IT network, including the National Electronic Health Record, and “there have been no similar cyberattacks on MOH’s IT systems.”

It added: “Following this incident, MOH will be reminding all its licensed healthcare institutions to remain vigilant, strengthen their cybersecurity posture, and ensure the security and integrity of their IT assets, systems, and patient data. It is only through the disciplined maintenance of a safe and secure data and IT system that healthcare professionals will be able to deliver accurate and appropriate care and uphold patient safety.”

Commenting on the story, Jonathan Knudsen, senior security strategist at the Synopsys Software Integrity Group, said: “Every organization is a software organization, even an eye clinic. All organizations, no matter their size or industry, must include cybersecurity as part of their day-to-day operations. A comprehensive, proactive approach to security reduces risk for the organization and its customers.

“In the case of Eye & Retina Surgeons, segmenting the network between administrative functions and medical data was a smart defensive move and prevented this attack from being much worse. This technique is part of the basic security hygiene that all organizations should practice. Even with the best defenses, things can still go wrong. Incident planning helps the organization be prepared to remediate problems and notify customers and authorities.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Government Names Candidate for New Information Commissioner

Government Names Candidate for New Information Commissioner

The UK government’s preferred candidate to be the next information commissioner will be John Edwards, who currently serves as New Zealand’s current privacy commissioner.

The information commissioner plays an increasingly important role in the UK’s regulatory landscape following the country’s departure from the EU.

The Information Commissioner’s Office (ICO) is an independent body that regulates the GDPR and its UK equivalent, the Data Protection Act 2018, as well as the Freedom of Information Act, the NIS Directive — transposed into UK law as the Network and Information Systems Regulation 2018 — and the Privacy and Electronic Communications Regulations (PECR), which govern nuisance calls and spam.

Edwards was appointed privacy commissioner in 2014 and is currently serving his second five-year term in New Zealand. He brings with him over two decades of regulatory and legal experience.

Edwards will now appear before MPs on the Digital, Culture, Media and Sport Select Committee for pre-appointment scrutiny on September 9.

He will arrive at a key moment for the UK as it seeks to strike multibillion-pound “data adequacy” agreements with the US, Australia and South Korea, and navigate a tricky relationship with the EU.

Although the bloc has adopted a data adequacy decision enabling the free flow of information to and from the continent, it may be challenged in court given concerns that the UK’s intelligence services could snoop on European citizens’ data.

“There is a great opportunity to build on the wonderful work already done and I look forward to the challenge of steering the organisation and the British economy into a position of international leadership in the safe and trusted use of data for the benefit of all,” said Edwards.

Current information commissioner Elizabeth Denham claimed her office had supported innovation while driving public trust in data use during the pandemic.

“Implementing any changes parliament decides on will fall to my successor, who will take on a role that has never been more important or more relevant to people’s lives,” she added.

“John Edwards would bring extraordinary breadth, international leadership and credibility to this role. He will receive the support of a modern, independent ICO that has the courage, resources and expertise to make a positive difference to people’s lives.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Record Summer for UK’s Cyber Skills Courses

Record Summer for UK’s Cyber Skills Courses

Over 1850 teenagers signed up for a government-backed cybersecurity skills initiative this summer, a record number, according to the National Cyber Security Centre (NCSC).

The CyberFirst summer course is run by the GCHQ off-shoot and went online-only last year during the pandemic.

That saw record participation which has been surpassed again in 2021, the NCSC claimed. The number of applications this year was also record-breaking, increasing from 3,909 in 2020 to 4,384.

The course itself is open to 14 to 17-year-olds and covers topics such as digital forensics, ethical hacking and cryptography. Pupils now have the option of attending in person at a location in Warwickshire or completing it online.

This year, 43% of attendees were girls, and nearly half (47%) were pupils from ethnic minority backgrounds. Both groups are under-represented in the industry.

CyberFirst courses are intended to spur and nurture an interest in cybersecurity, which will ultimately help close major skills shortages and gaps in the sector.

According to the government, half (50%) of businesses have a basic skills gap — which means those in charge of cybersecurity don’t have the confidence to perform basic tasks. Meanwhile, the shortage of cyber professionals in the UK is estimated at over 27,000, according to the ISC2.

“It’s fantastic to see so many young people engaging with cyber security and developing the skills that will help them thrive in the industry,” said Chris Ensor, NCSC deputy director for cyber growth.

“Our summer courses provide fun, hands-on opportunities to learn about defending our digital world and we hope they will be inspired to pursue their interests further. The next generation of cyber experts must be diverse as well as skilled, and through CyberFirst we are committed to making the industry a more accessible and inclusive place for all.”

More than 55,000 students have taken part in CyberFirst courses and the Girls Competition since 2016.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Tech Giants Pledge Billions to Biden’s “Whole of Nation” Security Plan

Tech Giants Pledge Billions to Biden’s “Whole of Nation” Security Plan

Some of the world’s biggest tech companies have committed tens of billions of dollars to improving supply chain security, closing industry skills gaps and driving security awareness among the public, according to the White House.

As reported by Infosecurity yesterday, the Biden administration welcomed the CEOs of Microsoft, Apple, Google, IBM and others to a meeting yesterday to discuss the “whole-of-nation” effort needed to address cybersecurity threats.”

The result of that encounter has been a series of commitments from these firms, including $10bn from Google over the next five years to expand zero trust and improve supply chain and open source security. The tech giant will apparently also help 100,000 Americans earn “digital skills certificates.”

IBM said it would train 150,000 people in cyber skills over the coming three years and focus on improving the diversity of the security workforce, while Microsoft has committed $20bn over five years to drive security by design, and $150m for federal, local and state governments.

Apple will establish a new program to improve supply chain security, including among its 9000 US suppliers, with multi-factor authentication (MFA), vulnerability remediation, event logging and incident response all playing a key role.

Amazon is making MFA devices available to all AWS customers and rolling out the security training it offers employees to the general public.

Aside from these commitments, the White House announced the expansion of its Industrial Control Systems Cybersecurity Initiative, from the electricity sector to natural gas pipelines, and said the National Institute of Standards and Technology (NIST) would develop a new framework for supply chain security.

In another potentially significant move, insurer Resilience said it would require policyholders to meet a threshold of cybersecurity best practice as a condition of receiving coverage — something experts have been demanding for some time across the industry.

“I’m especially excited to see that Resilience is requiring minimum cybersecurity standards as a condition of coverage,” argued Jake Williams, co-founder and CTO at BreachQuest. “Many organizations view cyber-insurance as an alternative to implementing security controls rather than as a complement to those controls.”

There were also pledges from several education providers to help improve security awareness among the public and grow America’s cyber workforce. The White House claimed it currently has a skills shortage of nearly 500,000 professionals.

“We applaud Amazon’s commitment to make security awareness training available at no charge and to deliver multi-factor authentication (MFA) to all Amazon Web Services account holders. Such basic defenses should be in place everywhere,” argued Jack Kudale, founder and CEO of Cowbell Cyber.

“The security crisis is acute within the small and mid-size business segment. Incentives to drive change and adoption of fundamental cyber-hygiene practices including cybersecurity and cyber-insurance will change the balance of power between businesses and cyber-criminals.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains