Yik Yak Returns

Yik Yak Returns

An app that allows users within a 5-mile radius to communicate anonymously has been relaunched four years after it shut down.

Yik Yak was first launched in 2013 and quickly became the ninth most downloaded social media app in the United States, reaching 1.8 million downloads by September 2014. 

Created by college students Tyler Droll and Brooks Buffington, the app was a hit with America’s teens but became dogged by instances of cyber-bullying and violent threats. 

Schools, including Palisades Charter High School (PCHS) in Los Angeles and Russellville High School in Alabama, were forced to evacuate their students after anonymous bomb threats were posted on the app. 

One parent, speaking after the evacuation of PCHS, told NBC News that the app “gives people freedom to post without fear of retribution.”

In 2014, University of Georgia student Ariel Omar Arias was arrested and charged with two felony counts of terroristic threats after posting a threat to commit violence at a campus building via the app. 

Arias claimed the post, which purportedly read, “If you want to live don’t be at the MLC at 12:15,” was a prank.  

Yik Yak Inc., which is based in Nashville, Tennessee, announced the app’s return on Monday in a tweet. Currently, only iPhone users in the US can download the app. However, the company said it planned to make Yik Yak available to other countries and devices. 

The new incarnation of Yik Yak comes with an extensive list of often vaguely defined Community Guardrails detailing what users are not allowed to share in a yak (a post).

Among the content users are barred from posting is “gossip,” “excessive sarcasm,” and “excessive commentary on an individual’s physical attributes, character, or personal life.”

Children should not be identified “under most circumstances” and “license plate numbers, social security numbers, or personal information that identifies someone” should not be posted “in most cases.”

Users are asked to “immediately downvote and report” yaks that don’t “vibe with the Community Guardrails.”

The app’s makers said their plan is to “rely on our community to help make Yik Yak a constructive venue for free and productive speech.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Indiana Contact Tracing Data Breached

Indiana Contact Tracing Data Breached

Hundreds of thousands of Indiana residents are being notified of a data breach involving responses collected via the Hoosier State’s COVID-19 online contact tracing survey.

A software misconfiguration that left information exposed to the public was discovered by an unnamed vulnerability-hunting company. The company informed state officials of the breach on July 2 after they were able to access and download the data. 

The breach was announced by state health officials on Tuesday. Information that was compromised in the incident included names, addresses, email addresses, gender, race, ethnicity, and dates of birth. 

The Indiana Office of Technology and the Indiana Department of Health (IDOH) said immediate steps were taken to correct the misconfiguration and re-secure the records that had been accessed. 

“We take the security and integrity of our data very seriously,” said Tracy Barnes, chief information officer for the state, in a statement.

“The company that accessed the data is one that intentionally looks for software vulnerabilities, then reaches out to seek business. We have corrected the software configuration and will aggressively follow up to ensure no records were transferred.”

The company that discovered the breach returned the sensitive data on August 4 and signed a certificate of destruction to confirm that the information had been permanently deleted.

State health commissioner Dr. Kris Box said they believe the impact of the data breach will be minimal owing to the nature of the information that was accessed. 

“We believe the risk to Hoosiers whose information was accessed is low. We do not collect Social Security information as a part of our contact tracing program, and no medical information was obtained,” said Dr. Box.

“We will provide appropriate protections for anyone impacted.”

Affected Indiana residents will receive data breach notification letters and will be provided with one year of free credit monitoring. The state is partnering with credit monitoring company Experian to set up a call center that will serve victims of the data breach. 

Nearly 750,000 residents have been impacted by the data breach. The Indiana Office of Technology said it will use scanning techniques to ensure that the compromised information was not passed to any additional parties.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Colonial Pipeline Reportedly Admits Data Breach

Colonial Pipeline Reportedly Admits Data Breach

Colonial Pipeline has reportedly admitted that nearly 6000 individuals may have had their personal information compromised by ransomware attackers when they struck earlier this year.

The fuel pipeline operator, which was crippled by the attack in May, confirmed to CNN Business that it had begun sending out breach notification letters to 5810 victims. Most of those affected are thought to be current and former employees and family members.

The compromised information is thought to include names, contact information, birth dates, Social Security numbers, driver’s license details, military ID numbers, and health insurance information.

Speaking to the news channel, a spokesperson from the critical infrastructure operation thanked employees and the public for their understanding as it continues to work through the incident.

“Though our pipeline system is now fully operational, we have been hard at work with third-party cybersecurity experts determining what, if any, personal information may have been affected as a result of the attack,” they added in a statement.

“Based on this review, we learned that an unauthorized party acquired certain personal information in connection with the attack.”

The May ransomware attack forced one of the biggest fuel pipelines in the US offline for several days, pushing prices up and hardening the Biden administration’s stance on cyber-criminals operating from Eastern Europe.

The DarkSide gang thought to have been responsible for the malware soon appeared to disband due to the extra scrutiny from the US government.

Since the attack, ransomware has the attention of heads of state across the globe and has led to sharp words from Washington, NATO and the G7 directed at Russia, which is thought to turn a blind eye to such attacks operating from within its borders.

Data exfiltration is now a common tactic for ransomware actors looking to increase their chances that victim organizations pay up following an attack. According to Coveware, 81% of raids in Q2 2021 involved the threat to leak stolen data, up 5% from the previous quarter.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

MoD Invites Innovators to Reduce Military’s Cyber-Attack Surface

MoD Invites Innovators to Reduce Military’s Cyber-Attack Surface

The UK’s Ministry of Defence (MoD) is calling on startups to help the military reduce its cyber-attack surface by designing a new generation of more secure hardware and software.

The MoD’s Defence and Security Accelerator (DASA) issued the call-to-arms on Monday, claiming it is prepared to fund proposals up to £300,000 for a nine-month contract.

“The Defence Science and Technical Laboratory (DSTL) on behalf of the MoD is interested in identifying and accelerating next generation hardware and software technologies to ‘design-out’ the vulnerabilities prevalent within current and future computer networks and systems (with a particular focus on operational technologies), thereby dramatically reducing defense exposure to cyber effects,” it explained.

“Intelligently applying these technologies would significantly reduce the opportunity for manipulation of such vulnerabilities on MoD systems and platforms; effectively raising the barrier to entry for adversaries and providing greater confidence and a level of assurance against cyber-enabled attack.”

The MoD wants solutions “applicable across a whole “class” of attack surface” rather than those that might only work against a specific threat. However, it said that proposals could be designed for future systems or retrofitted to existing capabilities.

To secure the initial round of funding, proposals must be within Technical Readiness Level 4 – 7. For further funding, interested parties would need to produce a roadmap describing how they would achieve a technical demonstrator by the end of the financial year 2023.

Cycle 1 of the Reducing the Cyber Attack Surface focus area is open now and will close at midday BST on October 20 2021. Cycle 2 will run from October 20 2021 to January 5 2022.

The news comes just a fortnight after the MoD completed its first bug bounty program to help find and remediate vulnerabilities across the department’s networks and 750,000 devices.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Misconfigured Server Leaks US Terror Watchlist

Misconfigured Server Leaks US Terror Watchlist

A secret watchlist of suspected terrorists maintained by the FBI was exposed online after a configuration error and then not fixed for several weeks after being reported, according to Comparitech.

Head of security research at the firm, Bob Diachenko, said he discovered the Terrorist Screening Center (TSC) list on July 19, when the exposed Elasticsearch server was indexed by search engines Censys and ZoomEye.

The list was left online without a password or any other authentication to secure it. It contained 1.9 million records, including full name, TSC watchlist ID, citizenship, gender, date of birth, passport number and more.

The TSC is a classified list of suspected terrorists, including a smaller “no-fly” list. The information is shared with the Departments of State and Defense and customs officers, TSA staff and international partners.

Although he didn’t check the entire database, Diachenko suggested that it may have contained the whole TSC list.

“The terrorist watchlist is made up of people who are suspected of terrorism but who have not necessarily been charged with any crime. In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families,” he argued.

“It could cause any number of personal and professional problems for innocent people whose names are included in the list. There have been several reports of US authorities recruiting informants in exchange for keeping their names off of the no-fly list. Some past or present informants’ identities could have been leaked.”

The exposed server, which was found on a Bahrain rather than a US IP address, was apparently left online without any security for three weeks after Diachenko informed the Department of Homeland Security (DHS).

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop

A remote attacker could exploit a critical vulnerability to eavesdrop on live audio & video or take control. The bug is in ThroughTek’s Kalay network, used in 83m devices.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains