—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Crypto Hack Earned Crooks $600 Million
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
SAP Patches Nine Critical & High-Severity Bugs
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cobolt Strike Vulnerability Affects Botnet Servers
Cobolt Strike is a security tool, used by penetration testers to simulate network attackers. But it’s also used by attackers — from criminals to governments — to automate their own attacks. Researchers have found a vulnerability in the product.
The main components of the security tool are the Cobalt Strike client — also known as a Beacon — and the Cobalt Strike team server, which sends commands to infected computers and receives the data they exfiltrate. An attacker starts by spinning up a machine running Team Server that has been configured to use specific “malleability” customizations, such as how often the client is to report to the server or specific data to periodically send.
Then the attacker installs the client on a targeted machine after exploiting a vulnerability, tricking the user or gaining access by other means. From then on, the client will use those customizations to maintain persistent contact with the machine running the Team Server.
The link connecting the client to the server is called the web server thread, which handles communication between the two machines. Chief among the communications are “tasks” servers send to instruct clients to run a command, get a process list, or do other things. The client then responds with a “reply.”
Researchers at security firm SentinelOne recently found a critical bug in the Team Server that makes it easy to knock the server offline. The bug works by sending a server fake replies that “squeeze every bit of available memory from the C2’s web server thread….”
It’s a pretty serious vulnerability, and there’s already a patch available. But — and this is the interesting part — that patch is available to licensed users, which attackers often aren’t. It’ll be a while before that patch filters down to the pirated copies of the software, and that time window gives defenders an opportunity. They can simulate a Cobolt Strike client, and leverage this vulnerability to reply to servers with messages that cause the server to crash.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Data Centric Zero Trust for Federal Government Cybersecurity
As outlined in Executive Order on Improving the Nation’s Cybersecurity (EO 14028), Section 3: Modernizing Federal Government Cybersecurity, CISA has been tasked with developing a Federal cloud-security strategy to aid agencies in the adoption of a Zero Trust Architecture to meet the EO Requirements. While the government awaits the completion of that effort, I think it’s important to look at the two government reference architectures that have already been published, as they will undoubtedly be considered in the development of CISA’s cloud-security strategy. Both NIST (800-207) and DoD (Version 1.0) have released Zero Trust reference architectures. Both define a Zero Trust telemetry architecture informed by security sensors to dynamically evaluate device and user trust and automatically change access permissions with changes in entity trust. They each accomplish the same goal, even if they take slightly different paths to get there.
Whereas the DoD architecture establishes control planes that each have their own decision point, with data given its own decision point, NIST takes a broader approach to Zero Trust and emphasizes Zero Trust in relation to all resources, not just data. The data control plane within the DoD architecture encompasses data processing resources and applies data-specific context to them. As most networks, applications, storage and services exist to process and store data, it makes sense that access to these resources should be specific to the data contained within them, and not just the access to the resources themselves. Protecting data is central to Zero Trust, and the DoD’s architecture acknowledges this.
Data Centric Enterprise
Today, most Zero Trust efforts seem to focus on defending the applications, networks and services that contain the data but fall short of building data specific protections. And while protecting network, application, and service resources is certainly important and essential to layered protections, improving protection around the data is imperative to successfully adopt Zero Trust architecture. People with alarm systems on their homes still lock up valuables in a safe to guard against failures in controls, or less than trustworthy house guests and hired workers.
The DoD puts data at the center of its reference architecture. User and entity trust is assessed in relation to the data being accessed, and permission levels are dynamically changed specific to individual data resources. If Zero Trust operates under the assumption that networks and applications are already compromised, then the only logical way to successfully implement Zero Trust is to combine network, application, and service access technologies with a comprehensive data protection platform. In a well-designed Zero Trust architecture, a comprehensive data protection platform serves not only to protect data, but also as a means to inform the analytics layer of potentially malicious insiders or compromised user accounts in order to automatically trigger changes in access permissions.
Imagine a very simple scenario where an organization has classified specific types of data and implemented controls to protect the data. Jane is a contractor, who, because of her contract function, was vetted and cleared for access to critical applications and controlled unclassified data. Jane has a government-issued laptop with data protection software, and she has access to government cloud applications like Office 365 that are protected and governed by the agencies’ CASB solution. Unfortunately, Jane has been having well disguised and undisclosed financial troubles, which have put her in a compromised situation. In order to try to get herself out of it, she has agreed to act as an insider. Jane initially attempts to send sensitive data to herself through her Office 365 email, but the attempt is blocked by the CASB. She then attempts to share the records from SharePoint to an untrusted email domain and again is blocked by the CASB and reported to security. Desperate, she tries to move the data to an external hard drive, and yet again she is blocked. At this point, Jane gives up and realizes the data is well protected.
On the backend of this scenario, each one of these attempts is logged as an incident and reported. These incidents now inform a Zero Trust dynamic access control layer, which determines that Jane’s trust level has changed, resulting in an automatic change to her user access policies and a Security Operations alert. This is one very basic example of how a data protection platform can inform and affect user trust.
What Comprises a Comprehensive Data Protection Platform?
Effectively architecting a comprehensive data protection platform requires a multi-vector and integrated approach. The platform should be a combination of control points that leverage a common classification mechanism and a common incident management workflow. Data protection enforcement should facilitate enforcement controls across managed hosts, networks, SaaS, and IaaS resources, and whenever possible restrict sensitive data from being placed into areas where there are no controls.
McAfee enables this today through a Unified DLP approach that combines:
- Host Data Loss Prevention (DLP)
- Network Data Loss Prevention (DLP)
- Cloud Access Security Broker (CASB)
- Hybrid Web Gateway – On-Premises and SaaS
- Incident Management
This comprehensive approach enables data protection policies to follow the data throughout the managed environment, ensuring that enterprise data is protected at rest, in transit, and in use. Within the platform, user trust is evaluated conditionally based on policy at each enforcement point, and any change to a user’s group through the Zero Trust architecture automatically modifies policies within the data protection platform.
What Next?
Data protection has long been a challenge for every enterprise. Successful implementation of data protection technologies requires a programmatic effort that includes data owners to accurately and successfully identify and build protections around sensitive information. If not implemented properly, data protection opens the door to user disruptions that many organizations have very little tolerance for. That’s why so many organizations focus their efforts on improving perimeter and access protections. Adversaries know this, which is why compromising user credentials or the supply chain to gain access remains a highly leveraged entry point for threat actors, because perimeter and access control protections fail to guard against people already inside the network with appropriate access. As enterprises plan for Zero Trust architectures, data protection has to take center stage.
By mandating that agencies quantify the type and sensitivity of their unclassified data, the EO appears to be steering Executive Branch agencies down the path of data centricity. The Executive Order focuses on improving the adoption of encryption best practices around data and implementing multifactor authentication in an effort to protect access to sensitive data from malicious outsiders. It falls short, however, of encouraging broad adoption of data loss prevention architectures to protect against accidental and malicious data leakage.
CISA has an opportunity to prioritize data as an enterprise’s central resource in their upcoming cloud-security strategy, which will drive agency adoption of Zero Trust Architecture. They should take this opportunity to emphasize the importance of designing a comprehensive data protection platform to serve as both a trust identifier and a mechanism of protection.
The post Data Centric Zero Trust for Federal Government Cybersecurity appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
5 Online Gaming Tips to Stay Safe From Hackers
For some, vanquishing aliens, building virtual amusement parks, and online battles royale are an excellent stress reliever. As we all know, over the past year there’s been plenty of stress to relieve and more spare time on our hands in which to revel in our hobbies. There was a 30% jump in online gaming traffic from the first to the second quarter of 2020.
Hackers are taking advantage of highly trafficked online gaming portals to make a profit on the dark web. The next time you log on to your virtual world of choice, consider these recent video game breaches and up your gamer security, which could include an antivirus for gaming.
Recent Game Hacks
Between 2019 and 2020, web attacks on gaming companies rocketed up 340%, according to Akamai. Hackers have targeted several high-profile gaming companies recently with various motives. First, game source code was stolen from Electronic Arts to sell on the dark web. Developers shopping the dark web use stolen source codes to reverse-engineer popular games or copy the code into their own game. Capcom and CD Projekt Red were hit by ransomware attacks only a few months apart from each other, one attack focused on company financial information and the other on source code.
“Titan Fall” and “Apex Legends” have both been hacked to the point where the former is unplayable, according to many gamers. To protest “Titanfall’s” developers’ inaction, gamers took to “Apex Legends,” altering in-game messages. The apparent ease with which hackers can walk into online gaming portals requires that game developers and gamers themselves pay more attention to their security.
Online PC gaming allows players to use real-world money to purchase valuable upgrades to their characters. These characters receive admiration from some fellow players. Others feel greed. Advanced characters can fetch a lot of money on the dark web, so some cybercriminals practice credential stuffing to force their way into player accounts and steal ownership. Credential stuffing is a type of brute force attack where hackers take informed guesses at username and password combinations. A strong password or passphrase is essential to keeping your account and investment safe from a dark web fate.
Why Are Video Games Hacked?
Based on the above recent hacks, it is clear that gaming companies host a trove of valuable information. Gamers trust these platforms with their payment information and with the safety of their gaming characters on which they spend thousands of hours and hundreds of dollars upgrading, making gaming a lucrative target for hackers.
Another way cybercriminals target gamers is through malware disguised as an advantage. Cheat software for online games is common as players strive to be the best out of thousands. Advantage seekers for “Call of Duty: Warzone” were targeted by a malware scam. The malware creators advertised the “cheat software” on YouTube with instructions on how to download it. The video received thousands of views and hundreds of comments, which made it look legitimate.
One of the steps in installing the “cheat software” was that users had to disable antivirus programs and firewalls. Users let the cybercriminals walk right into their device! From there, the device was infected by an aggressive type of fileless malware called a dropper. A dropper doesn’t download a malicious file onto the device; rather, it creates a direct pathway to deliver an additional payload, such as credential-stealing malware.
Gamer Security Tips
Competitive gaming is, well, competitive. So, if you invest a lot of real money into your characters, be especially vigilant and follow these five important tips to protect your online accounts.
-
Do not reveal personal information
It’s common for gamers to use variations of their real names and birthdates in their public-facing usernames. Don’t use your real name or birthdate in your username. Consider using a nickname or a combination of random numbers instead. Along this same vein, don’t reveal personal details about yourself (phone number, birthday, places you visit regularly) on chats or streams. Lurking cybercriminals can gather these personal details to impersonate you.
-
Edit your privacy settings
On some online PC games, you can join campaigns with gamers from all over the world. While the interconnectivity is great, carefully vet who you allow to follow your online profile. If a stranger sends a friend request out of the blue, be on alert. They could have nefarious motives, such as phishing for valuable personal data. It’s best to customize your privacy settings to make your profile invisible to strangers.
-
Don’t pirate games or download cheat software
Developers spend a lot of time creating amazing games, so make sure you purchase games legally and play them as they are intended. Be especially wary of free downloads or pirated versions and cheat software, as they’re likely too good to be true. Instead, go for a challenge and have fun with the game as it’s written.
-
Log in with a VPN
A virtual private network (VPN) scrambles your online data traffic, making it impossible for hackers to access your IP address and spy on your online browsing.
-
Sign up for gaming antivirus software
Gaming antivirus software not only makes your online gaming experience more secure, but it can boost your rig’s performance! McAfee Gamer Security detects threats through the cloud and optimizes resources to minimize frame drops.
Stay Updated
To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our newsletter, listen to our podcast Hackable?, and ‘Like’ us on Facebook.
The post 5 Online Gaming Tips to Stay Safe From Hackers appeared first on McAfee Blogs.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Cybercrime Victims Reluctant to Call Cops
Cybercrime Victims Reluctant to Call Cops

A survey by New Zealand’s Ministry of Justice has found that victims of crime in the Land of the Long White Cloud are least likely to report falling prey to cybercrime and sexual assault.
A New Zealander was most likely to contact the police after being impacted by vehicle crime, according to the latest Ministry of Justice New Zealand Crime and Victim Survey. Researchers found that while car crime had an 89% chance of being reported, only around 7% of cybercrimes and sexual assaults were brought to the attention of the police.
Shame, embarrassment, fear of reprisal, and the threat of further humiliation were cited as reasons why victims of cybercrime and sexual assault were unlikely to report the illegal activity to law enforcement.
About 2% of adults experienced sexual assault in the previous 12 months. Victims were proportionately higher among females aged 15-19 (9%) and people with diverse sexualities aged 15-29 (14%).
The survey revealed that while more people are reporting assaults, around three quarters of all crime in New Zealand goes unreported.
The survey was set up in 2018 to collect information from around 8,000 randomly picked New Zealanders every year about their experience of crime. Participants must be aged 15 years or older.
Since the survey began, the rate of reported crime has stayed the same at 25%. However, the rates of assault, robbery, harassment and threatening behavior reported to the police rose from 25% in 2019 to 30% in 2020.
New Zealand police welcomed the increase in reports from victims of crime.
Assistant Commissioner Bruce O’Brien told the New Zealand Herald: “There’s essentially more trust than ever that we will solve these incidents in a timely and effective manner.”
He added: “If it’s not reported to us then our chances of being able to make a difference are significantly reduced. We can only solve crimes that we know about.”
The survey revealed a significant decline in the number of burglaries in New Zealand from 18 per 100 households in 2018 to 14 per 100 households in 2020, while the country was under lockdown to slow the spread of Covid-19.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Remote Workers Duck Security Rules
Remote Workers Duck Security Rules

More than half of employees who work remotely are deliberately ignoring or working around security policies put in place by their company, according to new research.
The insider threat was unearthed during a recent survey of IT and cybersecurity professionals across industries conducted by identity platform Axiad when putting together its 2021 Remote Workforce Security Report.
Researchers found that 52% of tech leaders reported that their remote employees had found workarounds to their company’s security policies.
“Employees were most resistant to complying with multi-factor authentication, mobile device management, and password managers, making it difficult for organizations to ensure all their employees are fully and securely authenticated to all their applications and devices,” said Axiad founder and co-CEO Bassam Al-Khalidi.
“These gaps in authentication leave the business vulnerable to cyberattacks.”
The report notes that phishing threats (71%) and malware (61%) were the most significant new threat vectors impacting remote work environments. More than half of respondents (56%) cited unpatched vulnerabilities as an issue, while 42% were bugged by malicious websites.
While identity theft was a concern for just 37% of respondents, nearly half (49%) were worried about unauthorized users and privileged access.
With the boom in remote working following the Covid-19 pandemic, companies have been taking steps to secure their employees’ access to corporate resources. Researchers found that organizations purchased more user licenses for existing applications (47%), more hardware (29%), took on new vendors (26%), and invested in extra cloud applications (19%).
Another key finding was that 79% of security professionals use the same level of security controls and data management for every employee when corporate resources are being accessed remotely.
“We believe the dramatic increase in phishing threats, combined with 52% of remote workers undermining their company’s security practices, creates a perfect storm for tech leaders,” said Al-Khalidi.
“It’s concerning that so many employees take shortcuts to get their job done, rather than embrace their personal responsibility to follow the policies of their company.”
Al-Khalidi encouraged companies to find a way for their employees to authenticate quickly, securely, and without causing any friction with the IT team.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
UPMC to Pay $2.65M to Settle Data Breach Case
UPMC to Pay $2.65M to Settle Data Breach Case

Judicial approval has been given to a multi-million-dollar settlement concerning a data breach that happened at the University of Pittsburgh Medical Center (UPMC) seven years ago.
The agreement will see UPMC pay $2.65m to 66,000 employees whose personal data was pilfered by former Federal Emergency Management Agency (FEMA) IT specialist Justin Sean Johnson.
Detroit resident Johnson (aka TheDearthStar and Dearthy Star on the dark web) hacked into the center’s Oracle PeopleSoft database in 2013 and 2014 using the nicknames “TDS” and “DS.”
After gaining access to the Center’s human resources server databases, Johnson stole sensitive PII and W-2 information belonging to UPMC employees that included names, addresses, Social Security numbers, salaries, and bank information.
Johnson later sold this information via forums on the dark web to cyber-criminals, who used it to file false tax returns. The Department of Justice said that hundreds of false 1040 tax returns were filed in 2014 using UPMC employee PII, with the result that hundreds of thousands of dollars of false tax refunds were claimed.
After converting this money into gift cards for online retailer Amazon, the cyber-criminals who had filed the false returns bought goods and shipped them to Venezuela. The scheme caused the IRS to lose $1.7m.
Johnson was arrested in June 2020. In May this year, he pleaded guilty to counts 1 and 39 of a 43-count indictment.
Following the breach, a class-action lawsuit was filed accusing the University of Pittsburgh Medical Center of negligence. The suit alleged that UPMC had failed “to comply with widespread industry standards relating to data security.”
The claim was initially dismissed by the trial court and later by the Superior Court; however, it was then upheld on appeal by the Supreme Court of Pennsylvania. The Court decided in favor of the plaintiffs, stating that an employer has a legal duty to exercise reasonable care in how they store employees’ personally identifiable information.
Earlier this year, UPMC was embroiled in another data breach after a cyber-attack on a third-party vendor exposed the PHI of more than 36,000 patients.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Unauthorized Network Access Selling for Up to Five Figures
Unauthorized Network Access Selling for Up to Five Figures

Researchers have found that the sale and purchase of unauthorized access to compromised enterprise networks are influenced by location and industry.
IntSights, a Rapid7 company, released new research today that highlights the dark world of network access, with findings showing that underground criminals sell access to organizations for up to $10,000.
“Some cyber-criminals specialize in network compromises and sell the access that they have obtained to third parties, rather than exploiting the networks themselves,” explained the researchers. “By the same token, many criminals that exploit compromised networks — particularly ransomware operators — do not compromise those networks themselves but instead buy their access from other attackers.”
The attackers who buy the information are often lacking in the skills needed to get the information themselves, according to the study. This is often also the reason they are sold.
“In September 2020, Russian-speaking username “hardknocklife” auctioned off remote desktop protocol (RDP) access to a U.S. hospital,” added the researchers. “He mentioned as a selling point that this RDP access yielded patient records, in which he reportedly had no interest.
“US patient records from healthcare organizations are a valuable resource for identity thieves and other fraudsters because they contain dates of birth, social security numbers and other personal details that they can use for fraudulent credit applications and other malicious purposes,” they went on to say. “This seller could have mined or monetized that data himself but lacked interest in doing so, perhaps because he could be more productive as an intruder than a fraudster, or because he lacked the fraud or criminal business skills to do so.”
This information started at the low price of $500 in the auction but put his “buy no” price of $5000 (USD).
IntSights analyzed a sample of 46 sales of network access on underground forums between September 2019 and May 2021. The sample included 30 offerings from Russian-language forums (65%) and 16 offerings from English-language forums (35%).
The researchers found that the average price for the 40 sales was approximately $9640 (USD), and the median price was $3000 (USD). IntSights researchers view the average price of $9640 (USD) as a better indicator of the higher end of the typical price range.
“When ranked in ascending order, the list of these 40 prices only met or exceeded the average of $9,640 USD in the top quartile, or among the 10 highest prices of these 40,” stated the team. “This higher end of the price range began at $10,000 USD, with three offerings at exactly that price.”
On the lower end of the scale, nine were just three figures out of the ten lowest prices. The more expensive offerings have five-figure prices.
“An examination of the higher and lower prices sheds light on the factors that influence pricing,” the research stated. “For example, the single lowest price of $240 was for access to a healthcare organization in Colombia.
“Criminals typically prefer victims in wealthier countries with advanced economies, as they are generally more lucrative. Prices for access to healthcare organizations also trend lower due to the perception that they are easier to compromise.”
The research also shows that even though this tactic predates the COVID-19 pandemic, the “resulting increase in the use of remote access tools and services have given attackers more attack surface to exploit.” This has fueled the marked increase in sales to unauthorized access to networks, with some underground criminal forums dedicating specific sections to this offering.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains