How to Reduce Exchange Server Downtime in Case of a Disaster?

Exchange downtime can have serious implications on businesses. Thus, it’s important to maintain backups and implement best practices for Exchange servers that can help restore the Exchange server when a disaster strikes with minimal impact and downtime.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

DOJ to Consider Expanding Use of AI Prisoner Monitoring Tech

DOJ to Consider Expanding Use of AI Prisoner Monitoring Tech

A House of Representatives panel has asked for a study to be done on the use of artificial intelligence (AI) to analyze prisoners’ phone calls.

Reuters reports that the United States Department of Justice (DOJ) has been asked to report on the use of AI monitoring as a tool to prevent suicide and violent crime. 

The monitoring systems would be used to analyze and automatically transcribe inmates’ conversations, flagging particular words or phrases. Such technology is already in use in prison facilities in AlabamaNew York, and Georgia.

A House Democratic aide said that the DOJ was being actively encouraged “to engage with stakeholders in the course of examining the feasibility of utilizing such a system.”

Commenting on the prospect of AI’s being used to monitor inmates’ phone calls, Texas resident Heather Bollin, whose fiancé is in prison, told Reuters: “It’s very unsettling. What if I say something wrong on a call? It could be misconstrued by this technology, and then he could be punished.”

Privacy groups have questioned the use of AI call monitoring in prisons. 

“This Congress should be outlawing racist policing tech – it shouldn’t be funding it,” said Albert Fox Cahn, executive director of New York-based advocacy group the Surveillance Technology Oversight Project (STOP).

“People who have been caught up in the criminal justice system are always turned into the subjects of experimentation for new technology systems.”

A Stanford University and Georgetown University study into technology that transcribes voice conversations concluded that such tech has a high error rate when used to analyze words spoken by black people. 

The study’s lead author Allison Koenecke, said: “Speech-to-text technology is not in a place where it can be used to make these kinds of criminal justice decisions.”

Police in Oxford, Alabama, already use Verus voice monitoring technology to listen in on prisoners’ phone conversations. Oxford chief of police Bill Partridge said that the tech had helped to prevent suicides and that inmates had been captured discussing “actually committing the murder.”

He said: “I think if the federal government starts using it, they’re going to prevent a lot of inmate deaths.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

T-Mobile Investigates Possible Data Breach

T-Mobile Investigates Possible Data Breach

T-Mobile has launched an investigation into a claim that the personal data of more than 100 million of its customers had been compromised. 

The claim was first discovered and reported by Vice News. Researchers came across a hacker on an online forum asking for Bitcoin in exchange for Social Security numbers.

Though T-Mobile isn’t mentioned in the forum for sale post, the hacker told Vice that the data was a subset of 100 million records that had been taken from T-Mobile servers. 

The hacker alleged that the company misconfigured a gateway GPRS support node used for testing, exposing it to the internet and allowing the attacker to eventually pivot to the LAN.

It is alleged that the stolen information includes customers’ phone numbers, names, physical addresses, Social Security numbers, and driver licenses.

The hacker said that the rest of the data, which isn’t being offered for sale on the forum, is being sold privately. 

In a statement to Reuters, T-Mobile said: “We are aware of claims made in an underground forum and have been actively investigating their validity. We do not have any additional information to share at this time.”

Sharon Besser, SVP of Guardicore, said that if the data breach does prove to be genuine, it shows how important it is to properly segment internal environments to limit attackers’ ability to access ‘crown jewel’ data. 

“Repeated instances like this highlight the fact that organizations still struggle with reducing the attack surface and limiting lateral movement once a trusted network has been compromised,” she said. 

Jack Chapman, VP of Threat Intelligence at Egress, said the data breach “could be one of the most serious leaks of consumers’ sensitive information we’ve seen so far this year” due to the number of potential victims.

“The data leaked in this breach is reported as being already accessible to cyber-criminals, who could now weaponize it to formulate sophisticated phishing attacks targeting the victims,” said Chapman. “Follow-up attacks may utilize the information accessed through this data breach to trick people into sharing more personal data that can be used for identity and financial fraud.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Delivery Scams Most Prominent Form of Smishing

Delivery Scams Most Prominent Form of Smishing

Texts purporting to be from parcel and delivery companies are the most prevalent form of ‘smishing’ scams, according to new data provided to UK Finance by cybersecurity firm Proofpoint.

The data showed that over two-thirds (67.4%) of all UK texts reported as spam to the NCSC’s 7726 text messaging system, operated by Proofpoint, during the 30 days to mid-July 2021, were supposedly from delivery companies. The next highest category of scam texts was those pretending to be financial institutions and banks (22.6%).

Over the 90 days to mid-July, the proportion of spam texts relating to parcel and package deliveries was lower, at 53.2%, while those purporting to be from financial institutions and banks were 36.8%.

As with other forms of phishing campaigns, smishing attacks have risen substantially during the COVID-19 pandemic, with the crisis providing significant opportunities for scammers to lure consumers into clicking on malicious links and giving away personal data such as credit card details. One of these relates to the rise in online deliveries as a result of social distancing restrictions.

Katy Worobec, managing director of economic crime at UK Finance, commented: “Criminals are experts at impersonating a range of organizations and have capitalized on the pandemic, knowing that many of us will be ordering goods online and awaiting parcel deliveries at home.

“We are urging people to follow the advice of the Take Five to Stop Fraud campaign and to always stop and think whenever you get a text message out of the blue before parting with your information or money. Always avoid clicking on links in a text message in case it’s a scam and forward any suspected scam text messages to 7726, which spells SPAM on your telephone keypad so that the criminals responsible can be brought to justice.”

Sarah Lyons, NCSC deputy director for economy & society, said, “Scammers and cyber-criminals regularly exploit well-known, trusted brands for their own personal gain, and sadly these latest findings bear that out.

“We would encourage people to be vigilant to any suspicious-looking text messages, which should be forwarded to 7726. However, these scam messages can be very hard to spot, so if you think you’ve already responded to a scam, don’t panic. Whether you were contacted by text message, email or phone, there’s lots you can do to limit any harm. Visit www.cyberaware.gov.uk for more information on how to protect your online accounts and devices.”

Last week, consumer group Which? warned consumers to be aware of a new smishing scam impersonating international parcel delivery firm DPD, which requests the user to send a small fee to rearrange delivery of a parcel.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cadbury Campaigns Against Cyber-bullying

Cadbury Campaigns Against Cyber-bullying

The formerly British-owned chocolate maker Cadbury has launched the second phase of a campaign that encourages people to take action when they witness cyber-bullying.

The #HeartTheHate campaign asks internet users to mark social media posts that have attracted online abuse with a purple heart emoji. 

Cadbury, which was bought by American multinational company Mondelēz International in 2003, initially cooked up the campaign in 2019 to show solidarity with abuse victims. 

The campaign was launched after a poll of 89,685 internet users conducted by Cadbury in partnership with Indian media company Inshorts found that 57.6% of respondents has been cyber-bullied, and 46.5% of victims had been harassed online more than once.

Anil Viswanathan, senior director of marketing at Mondelez India, said: “Cyber-bullying is something which affects everyone, especially today’s youngsters. 

“Apart from the direct impact of bullying, the apathy of the silent bystander impacts the victims in a big way. While we were pleased to see the impact created online through #HeartTheHate, which leveraged this insight in 2019, we knew there was a lot of work still left to do.”

Phase two of the ad campaign follows a more recent poll by Inshorts and Cadbury that surveyed 170,000 people. Researchers found that 42% of respondents reported being cyber-bullied, and 55% said that they had not been given any assistance from friends after falling victim to online abuse.

“Through the next phase of the campaign, we hope to further reiterate Purple Heart as an emoticon that helps express solidarity with the bullied,” said Viswanathan. 

“This campaign leverages technology in a smart way to make consumers understand how breaking their silence and standing up for the victims can make a huge difference in their lives.” 

In the campaign, Indian abuse victims are shown in different scenarios being comforted by seeing the purple hearts left by supporters or getting bullied more when bystanders ignore the first round of abuse.

India represents the third biggest market for Cadbury chocolate products after the UK and Australia. Cadbury Dairy Milk has also teamed up with cyber-psychologist Nirali Bhatiato to run training courses at 20 universities around the country about the impact of cyber-bullying.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Half of US Hospitals Shut Down Networks Due to Ransomware

Half of US Hospitals Shut Down Networks Due to Ransomware

Nearly half (48%) of US hospitals have disconnected their networks in the past six months due to ransomware, according to a new study from Philips and CyberMDX.

The Perspectives in Healthcare Security Report is based on interviews with 130 IT and cybersecurity hospital executives and biomedical engineers and technicians.

The findings revealed the outsized impact ransomware continues to have on healthcare organizations (HCOs) after they battled a surge in attacks during the early months of the pandemic.

Respondents who admitted to shutting down networks due to ransomware were a mix of those who did so proactively to avoid a damaging breach and those forced to do so because of severe malware infection.

Medium-sized hospitals appear to have suffered most from the impact of such attacks. Of respondents that experienced a shutdown due to external factors, large facilities suffered an average of 6.2 hours downtime at the cost of $21,500 per hour. In comparison, mid-size hospitals averaged nearly 10 hours at $45,700 per hour.

Skills gaps and low levels of investment in cybersecurity were highlighted as possible contributing factors. Just 11% of respondents said cybersecurity is a “high priority” for spending, while nearly half of all respondent types claimed their medical device and IoT security staffing levels are inadequate.

More concerning still is that many hospitals still appear to be exposed to severe legacy vulnerabilities: 52% of respondents admitted they’re not protected against the BlueKeep bug, rising to 64% for WannaCry and 75% for NotPetya.

CyberMDX CEO, Azi Cohen, claimed the report would help to raise awareness of critical cybersecurity deficiencies among many HCOs.

“With new threat vectors emerging every day, healthcare organizations are facing an unprecedented level of challenges to their security,” he added. “Hospitals have a lot at stake — from revenue loss to reputational damage, and most importantly patient safety.”

One of the first steps towards improving security posture is comprehensive asset discovery and inventory. However, here too many HCOs are currently failing.

Nearly two-thirds (65%) of respondents claimed they rely on manual methods to calculate inventory, with many of those from mid-size hospitals (15%) and large hospitals (13%) admitting they have no way to determine the number of active or inactive devices on their networks.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

“Jigsaw Puzzle” Phishing Attacks Use Morse Code to Hide

“Jigsaw Puzzle” Phishing Attacks Use Morse Code to Hide

Microsoft has revealed a “unique” phishing campaign using novel techniques to stay hidden from conventional email security filters.

The primary motivation of those behind the emails is to steal usernames and passwords, IP addresses and location data that can be used as entry points for later attacks.

Classic social engineering techniques are employed to trick users into opening a .xls HTML file. Opening the attachment takes the victim to a fake Microsoft Office 365 credentials dialog box on top of a blurred Excel document.

However, the real interest lies in how the attackers have tried to obfuscate and evade detection — by dividing the HTML attachment into several segments before encoding them via various mechanisms.

“Some of these code segments are not even present in the attachment itself. Instead, they reside in various open directories and are called by encoded scripts,” said Microsoft.

“In effect, the attachment is comparable to a jigsaw puzzle: on their own, the individual segments of the HMTL file may appear harmless at the code level and may thus slip past conventional security solutions. Only when these segments are put together and properly decoded does the malicious intent show.”

Since Microsoft began tracking the campaign in July 2020, it has observed multiple iterations featuring various encoding mechanisms and techniques, including the hosting of segments on third-party sites and the use of Morse code.

“Morse code is an old and unusual method of encoding that uses dashes and dots to represent characters. This mechanism was observed in the February (‘Organization report/invoice’) and May 2021 (‘Payroll’) waves,” the tech giant explained.

“In the February iteration, links to the JavaScript files were encoded using ASCII then in Morse code. Meanwhile in May, the domain name of the phishing kit URL was encoded in Escape before the entire HTML code was encoded using Morse code.”

Constantly changing, multi-layer obfuscation techniques like these require dynamic threat protection, Microsoft argued.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Europol: Islamic State Propaganda Networks Are Thriving

Europol: Islamic State Propaganda Networks Are Thriving

Official propaganda from the Islamic State (IS) dwindled during 2020 after disruption from Western coalition forces, but informal supporter networks continue to spread its message far and wide, Europol has warned.

The law enforcement agency’s latest Online Jihadist Propaganda report analyzed the key trends of last year, highlighting the persistence of terrorist content across multiple online channels.

“Jihadist terrorist groups dedicate significant efforts to set up effective online communication campaigns. The production and dissemination of propaganda content is integral to these efforts,” explained Europol executive director, Catherine De Bolle.

“Driven by digital innovation, these groups do not refrain from exploiting the latest technologies to broadcast their message to intended audiences.”

IS’s official propaganda capabilities remained muted in 2020 after significant losses of infrastructure and personnel, with video releases becoming increasingly rare, the report claimed.

However, “committed IS supporters and their networks” are stepping in to spread the group’s messages and advance operational activity both online and off, it added.

IS-supporting media outlets have expanded their digital output and offered assistance to these supporters on how to use private online channels to stay hidden.

“IS-aligned media outlets that specialize in cybersecurity, privacy, and encrypted communications remained committed to their mission of providing online security awareness to IS supporters,” Europol explained.

“The Electronic Horizons Foundations even established a virtual ‘weekly meeting’ with its technical support administrators to provide answers on technical and security-related questions. The virtual ‘meeting’ took place on the Element application.”

Campaigns from media outlets have also helped to inspire Supporter-Generated Content (SGC) productions across encrypted platforms like Telegram. These, in turn, help to direct and inspire lone actor attacks in the EU and elsewhere, the report noted.

Efforts are being focused on staging an IS revival in Iraq and Syria, publicizing its military gains in Africa and spreading the message that freeing IS prisoners around the world is a priority.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains