News

How to Protect Your Social Media Accounts

Social media is part of our social fabric. So much so that nearly 50% of the global population are social media users to some degree or other. With all that sharing, conversing, and information passing between family and friends, social media can be a distinct digital extension of ourselves—making it important to know how you can protect your social media accounts from hacks and attacks.

Beyond the sheer number of people who’re on social media, there’s also the amount of time we spend on it.  People worldwide spend an average of 145 minutes a day on social media. With users in the U.S. spending just over two hours on social media a day and users in the Philippines spending nearly four hours a day, that figure can vary widely. Yet it’s safe to say that a good portion of our day features time scrolling and thumbing through our social media feeds. 

Given how much we enjoy and rely on social media, now’s a fine time to give your social media settings and habits a closer look so that you can get the most out of it with less fuss and worry. Whether you’re using Facebook, Instagram, TikTok, or whatnot, here are several things you can do that can help keep you safe and secure out there: 

1. Set strong, unique passwords

Passwords mark square one in your protection, with strong and unique passwords across all your accounts forming primary line of defense. Yet with all the accounts we have floating around, juggling dozens of strong and unique passwords can feel like a task—thus the temptation to use (and re-use) simpler passwords. Hackers love this because one password can be the key to several accounts. Instead, try a password manager that can create those passwords for you and safely store them as well. Comprehensive security software will include one. 

2. Go private

Social media platforms like Facebook, Instagram, and others give you the option of making your profile and posts visible to friends only. Choosing this setting keeps the broader internet from seeing what you’re doing, saying, and posting, which can help protect your privacy. 

3. Say “no” to strangers bearing friend requests

Be critical of the invitations you receive. Out-and-out strangers could be more than just a stranger, they could be a fake account designed to gather information on users for purposes of cybercrime, or they can be an account designed to spread false information. There are plenty of them too. In fact, in Q3 of 2021 alone, Facebook took action on 1.8 billion fake accounts. Reject such requests. 

4. Think twice before checking in

Nothing says “there’s nobody at home right now” like that post of you on vacation or sharing your location while you’re out on the town. In effect, such posts announce your whereabouts to a broad audience of followers (even a global audience, if you’re not posting privately, as called out above). Consider sharing photos and stories of your adventures once you’ve returned.  

5. The internet is forever

It’s a famous saying for a reason. Whether your profile is set to private or if you are using an app with “disappearing” messages and posts (like Snapchat), what you post can indeed be saved and shared again. It’s as simple as taking a screenshot. If you don’t want it out there, forever or otherwise, simply don’t post it. 

6. Watch out for phishing scams

We’re increasingly accustomed to the warnings about phishing emails, yet phishing attacks happen plenty on social media. The same rules apply. Don’t follow any links you get from strangers by way of instant or direct messengers. And keep your personal information close. Don’t pass out your email, address, or other info as well. Even those so-called “quiz” posts and websites can be ruses designed to steal bits and pieces of personal info that can be used as the basis of an attack. 

7. Also keep an eye out for scams of all kinds

Sadly, social media can also be a place where people pull a fast one. Get-rich-quick schemes, romance cons, and all kinds of imposters can set up shop in ads, posts, and even direct messages—typically designed to separate you from your personal information, money, or both. This is an entire topic to itself, and you can learn plenty more about quizzes and other identity theft scams to avoid on social media 

8. Review your tags

Some platforms such as Facebook allow users to review posts that are tagged with their profile names. Check your account settings and give yourself the highest degree of control over how and where your tags are used by others. This will help keep you aware of where you’re being mentioned by others and in what way. 

9. Protect yourself and your devices

Security software can protect you from clicking on malicious links while on social media while steering you clear of other threats like viruses, ransomware, and phishing attacks. It can look out for you as well, by protecting your privacy and monitoring your email, SSN, bank accounts, credit cards, and other personal information. With identity theft a rather commonplace occurrence today, security software is really a must. 

10. Check your Protection Score and see how safe you are

Now you can point to a number that shows you just how safe you are with our Protection Score. It’s an industry first, and it works by taking stock of your overall security and grading it on a scale of 0 to 1,000. From there, it calls out any weak spots and then walks you through the steps to shore it up with personalized guidance. This way, you’re always in the know about your security, privacy, and personal identity on social media and practically wherever else your travels take you online.

The post How to Protect Your Social Media Accounts appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

McAfee Wins Product of the Year for Best Online Protection

You can feel even more confident that you’ll enjoy life online with us at your side. AV-Comparatives has awarded McAfee as its 2021 Product of the Year.

McAfee makes staying safe simple, and now this endorsement by an independent lab says we protect you best.

Over the course of 2021, AV-Comparatives subjected 17 different online protection products to a series of rigorous tests. Their labs investigated each product’s ability to protect against real-world Internet threats, such as thousands of emerging malicious programs and advanced targeted attacks, along with the ability to provide protection without slowing down the computer.

McAfee topped the field, taking home the award for AV-Comparatives’ Product of the Year thanks to our highest overall scores across the seven different testing periods throughout the year. McAfee further took a Gold Award for the Malware Protection Test, in addition to recognition for its clean, modern, and touch-friendly design and for the way that McAfee Firewall coordinates perfectly with Windows.

“We’re honored by the recognition,” says Chief Technology Officer, Steve Grobman. “The strong reputation that AV-Comparatives carries in the industry cements our place as a leader in online protection.” He goes on to say, “Our work continues. The internet is evolving to be integral to every part of our lives. This creates new opportunities for cyber criminals and drives the evolution of the threat landscape. McAfee is committed to staying one step ahead of these sophisticated threats, ensuring customers can safely utilize the full value of our online world.”

Read the full AV-Comparatives annual report and protect yourself and your family with the year’s top-rated antivirus. Give it a look for yourself with a free 30-day trial of McAfee Total Protection, which includes McAfee’s award-winning anti-malware technology plus identity monitoring, Secure VPN, and safe browsing for an all-in-one online protection.

The post McAfee Wins Product of the Year for Best Online Protection appeared first on McAfee Blogs.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

EHR Vendor Faces Legal Action Over Data Breach

EHR Vendor Faces Legal Action Over Data Breach

A Tennessee-based healthcare technology services company is facing legal action over a cyber-attack that occurred in August 2021.

The class action lawsuit was filed against QRS Healthcare Solutions (QRS, Inc), an electric health record (EHR) vendor and provider of integrated practice management and clinical services, including electronic patient portals.

On August 26 2021, QRS discovered that a cyber-attacker had accessed a QRS dedicated patient portal server on which certain sensitive information was stored.

According to a data security notice published by QRS on its website, the cyber-attack “involved the personal information, including the health information, of some of its clients’ patients.”

The impacted server was taken offline when the attack was discovered, and QRS hired a digital forensics security firm to analyze the incident. 

Investigators determined that an unknown attacker had accessed the server from August 23 2021 to August 26 2021, and may have acquired files containing the protected health information (PHI) of almost 320,000 patients.

“The information may have included, depending on the individual, their name, address, date of birth, Social Security number, patient identification number, portal username and/or medical treatment or diagnosis information,” reads QRS’s notice.

In October, on behalf of its clients, QRS began sending written notifications to individuals whose personal information was accessed in the incident. The healthcare technology services company also offered complimentary identity theft protection services to individuals whose Social Security numbers may have been compromised.

Following the data breach, Kentucky resident Matthew Tincher has filed a class action complaint in the US District Court for the Eastern District of Tennessee against QRS. Tincher, who lives in Frankfurt, alleges that QRS failed to take reasonable action to secure, monitor and maintain the personally identifiable information (PII) and PHI stored on its patient portal.

The suit alleges that the data was stored by QRS in an unencrypted form. It also criticizes QRS for waiting two months before sending out data breach notifications to impacted individuals. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Nova Scotia Seeks to Improve Cyber-Bullying Law

Nova Scotia Seeks to Improve Cyber-Bullying Law

The government of Canadian province Nova Scotia is seeking public feedback on improving anti-cyber-bullying legislation enacted in July 2018.

Nova Scotia was the first Canadian province to enact a detailed law addressing cyber-bullying and the unauthorized sharing of sexually explicit imagery.

The law, known as the Intimate Images and Cyber-protection Act, was created to discourage individuals from bullying others via the internet, over email or through text messages. It further sought to dissuade people from sharing intimate images of individuals without their consent.

Under the Cyber-protection Act, cyber-bullying victims and their families are permitted to participate in dispute resolution programs and can get protection orders issued against alleged offenders to cease their cyber-bullying activities. The law also allows victims and their families to request the deletion of online content, to prohibit further contact, and to seek compensation for their virtual harassment. 

The Cyber-protection Act also established the CyberScan Unit that helps cyber-harassment victims navigate the justice system and comprehend their options. Since its launch four years ago, the CyberScan unit has helped victims in 660 cases.

Built into the law is a mandate for Canada’s justice minister to review its implementation and submit a report on their findings to the Nova Scotia House of Assembly within four years.

“We want to help keep people safe online, so it is important that we review the legislation to ensure that it remains effective,” said justice minister and attorney general Brad Johns.

He added: “The feedback we receive will be valuable in helping us see where we can improve the legislation.”

The consultation phase for the review of the Intimate Images and Cyber-protection Act began on January 6. It was kicked off with the creation of an online survey designed to capture public sentiment surrounding the law. 

This survey is open to Nova Scotians aged 16 or older. Submissions for the survey must be completed by January 28.

In concert with the survey will be a series of virtual focus group sessions run with various stakeholders, including victims and their families, provincial victim-services staff, judges, police, lawyers, scholars and advocates.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Accellion Reaches $8.1m Data Breach Settlement

Accellion Reaches $8.1m Data Breach Settlement

Californian technology company Accellion Inc has reached an $8.1m settlement to resolve a legal claim relating to a data breach in December 2020.

The class action lawsuit was filed on behalf of victims whose personal information was exposed during a cyber-attack on Accellion’s file transfer appliance (FTA).

Accellion had been using the FTA for more than 20 years to securely share files deemed too sensitive or large to be sent over email. Before the cyber-attack occurred, Accellion actively phased out the FTA and encouraged its clients to use a newly developed file transfer solution named Kiteworks. 

Four months before the legacy file transfer solution was due to be retired on April 30 2021, it was attacked by two advanced persistent threat (APT) groups linked to FIN11 and the CLOP ransomware gang.

By exploiting unpatched vulnerabilities in the FTA, the attackers were able to gain access to the files of Accellion’s clients from which they exfiltrated a sizable amount of data.

Sensitive data potentially compromised and stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers and healthcare data.

Many Accellion clients were impacted by the breach, including Shell, The University of California, Stanford University School of Medicine, Bombardier, University of Miami Health, Trillium, Community Health Plan and Kroger.

Accellion identified a zero-day vulnerability in the product in mid-December 2020 and released a patch to address the flaw. By February 2021, four additional vulnerabilities associated with the platform were disclosed and issued CVEs.

The class action lawsuit accused Accellion of failing to implement and maintain appropriate data security practices to protect its clients’ sensitive data and failing to detect vulnerabilities in the security of its FTA. Plaintiffs also alleged that Accellion failed to disclose the inadequacy of its security practices.

According to documents filed in Californian federal court, Accellion accepts no liability for the breach and has denied all of the allegations. The tech company has proposed a settlement that includes $8.1m to cover the claims, notices and administration costs of Accellion FTA users.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Former Inspector General Pleads Guilty to Software Theft

Former Inspector General Pleads Guilty to Software Theft

A former acting inspector general for the US Department of Homeland Security (DHS) has pleaded guilty to charges related to his theft of federal government software and databases.

Charles Edwards, 61, of Sandy Spring, Maryland, worked for the DHS Office of Inspector General (DHS-OIG) from 2008-2013, and before that at the US Postal Service Office of Inspector General (USPS-OIG).

At both organizations, he’s said to have had access to case management software and other systems that contain employees’ highly sensitive personal details.

After leaving the government and setting up his own Maryland-based business, Delta Business Solutions, Edwards apparently stole some of this software and databases containing employee personal information in a bid to develop his own version to sell back to the government.

Edwards pleaded guilty in the US District Court for the District of Columbia to conspiracy to commit theft of government property and theft of government property.

One of his assistants at the DHS, Murali Venkata, 56, of Aldie, Virginia, has pleaded not guilty to charges related to the conspiracy, and his case remains pending.

It’s alleged that Venkata and others helped Edwards in this scheme by reconfiguring his laptop so it could upload the stolen software and databases, providing troubleshooting support and helping him build a test server at his home with the stolen software and data.

Edwards was also said to have retained a team of software developers in India to work on the project.

 In 2014, a bipartisan investigation found that Edwards had “jeopardized the independence of the Office of Inspector General and that he abused agency resources.”

He’s said to have rewritten and delayed critical audits at the request of DHS officials and maintained inappropriate personal relationships with staff.

OIGs are supposed to be independent auditing, inspection and investigative bodies linked to major federal government agencies

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Two Years for Romance Fraudster Who Targeted 670 Women

Two Years for Romance Fraudster Who Targeted 670 Women

A romance scammer who targeted hundreds of women and persuaded some to give him thousands of pounds has been jailed for over two years.

Osagie Aigbonohan, 41, from Lagos, Nigeria, operated under the moniker “Tony Eden” from his flat in Abbey Wood, London.

He’s said to have targeted nearly 700 women, including one who was terminally ill and whom he continued to pursue even after she passed away.

Police who searched his property also found footwear he’d purchased linked to one of his victims.

Another was tricked into paying Aigbonohan £9500 in nine separate transfers after he sold her a line that he had been impoverished by paying for the funerals of several people who’d died in a machinery accident.

The money went into various accounts held under fake identities before being funneled back to Aigbonohan’s own account. At least eight other women are thought to have given him money, totaling an estimated £20,000.

He was sentenced to 28 months at Southwark Crown Court on Friday after pleading guilty to fraud and money laundering charges.

Police arrested Aigbonohan back in July 2021 and found he was living with a false driving license, having overstayed his visa in the UK for two years.

“Romance fraud is a particularly callous offense, involving exploitation of an individual’s emotional needs and caring qualities, to extract money from them. People should be particularly vigilant over the coming month as we head towards Valentine’s Day and more people seek a partner,” warned James Lewis of the Crown Prosecution Service (CPS).

“Aigbonohan demonstrated a cynical disregard for his victims, grooming them with romantic promises before dishonestly persuading them to provide him with financial assistance.”

Action Fraud claimed last week that romance fraudsters conned their victims out of £92m between November 2020 and October 2021. Police warned that the period between Christmas Day and Valentine’s Day is the most dangerous for lonely hearts as scammers are out in force scouring the internet for victims

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Microsoft Warns of Destructive Malware Campaign Targeting Ukraine

Microsoft Warns of Destructive Malware Campaign Targeting Ukraine

Microsoft has detected a major malware wiper campaign targeting government, IT and non-profit organizations across Ukraine.

Dubbed “WhisperGate,” the attacks were first spotted on January 13, at around the same time that over a dozen government websites were forced offline in what was described as a “massive” cyber-attack.

Although Microsoft said it had not noticed any links between the destructive malware campaign, tracked as DEV-0586, and previous known activity groups, it comes at a time of heightened tensions with Russia, which is once again threatening Ukraine with invasion.

The malware, “which is designed to look like ransomware but lacking a ransom recovery mechanism,” has been found on “dozens” of systems, although it may have spread far wider, Microsoft warned.

“The two-stage malware overwrites the Master Boot Record (MBR) on victim systems with a ransom note (Stage 1). The MBR is the part of a hard drive that tells the computer how to load its operating system. The ransom note contains a Bitcoin wallet and Tox ID (a unique account identifier used in the Tox encrypted messaging protocol) that have not been previously observed by the Microsoft Threat Intelligence Center (MSTIC),” the blog post noted.

“The malware executes when the associated device is powered down. Overwriting the MBR is atypical for cybercriminal ransomware. In reality, the ransomware note is a ruse, and that the malware destructs MBR and the contents of the files it targets.”

The second stage malware is hosted on a Discord channel and designed to locate specific file extensions, overwrite the contents, and rename the file with a random four-byte extension.

Microsoft urged affected organizations to search for the relevant IoCs, investigate any anomalous authentication activity and enable multi-factor authentication (MFA) and controlled folder access (CFA) in Microsoft Defender to prevent MBR modification.

Senior manager for tactical defense at F-Secure, Calvin Gan, argued that WhisperGate has echoes of the infamous NotPetya campaign tied to the Russian state.

“With the usage of wiper malware, it is clear that the attackers are not after financial gain but are more motivated to cripple the target operations. Overwriting the MBR would render the machine unbootable, thus making recovery impossible, especially when the malware also overwrites file contents before overwriting the MBR,” he said.

“While the attacker’s true intention of deploying wiper ransomware coupled with file corrupter is not known at the moment, having it targeting government agencies and associated establishments is a sign that they want operations in these organizations ceased immediately. Perhaps the Bitcoin wallet address and communication channel in the ransom note of WhisperGate is a smokescreen to divert the attention of the attacker’s true intention of the attack while making it harder to track them.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

An Examination of the Bug Bounty Marketplace

Here’s a fascinating report: “Bounty Everything: Hackers and the Making of the Global Bug Marketplace.” From a summary:

…researchers Ryan Ellis and Yuan Stevens provide a window into the working lives of hackers who participate in “bug bounty” programs­ — programs that hire hackers to discover and report bugs or other vulnerabilities in their systems. This report illuminates the risks and insecurities for hackers as gig workers, and how bounty programs rely on vulnerable workers to fix their vulnerable systems.

Ellis and Stevens’s research offers a historical overview of bounty programs and an analysis of contemporary bug bounty platforms — ­the new intermediaries that now structure the vast majority of bounty work. The report draws directly from interviews with hackers, who recount that bounty programs seem willing to integrate a diverse workforce in their practices, but only on terms that deny them the job security and access enjoyed by core security workforces. These inequities go far beyond the difference experienced by temporary and permanent employees at companies such as Google and Apple, contend the authors. The global bug bounty workforce is doing piecework — they are paid for each bug, and the conditions under which a bug is paid vary greatly from one company to the next.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains