News

Connecticut Nerds Report CSAM

Connecticut Nerds Report CSAM

A suspected cyber-criminal has been placed under arrest in Connecticut following a tip-off from workers at a computer repair store.

Technicians at Guildford-based company Nerds To Go called the cops after allegedly detecting illegal images and videos on a computer belonging to 67-year-old Anthony Bruno of East Haven, Connecticut.

Bruno had brought his device into the locally owned and operated computer repair and IT support company in June 2021, because he had been unable to turn it on.

According to an affidavit written about the case by Officer Cassandra Lall, the technicians tested the device and transferred the files stored on it onto a separate hard drive. They then reinstalled the computer’s Windows operating system and moved the files back onto Bruno’s device.

In keeping with the Nerds To Go protocol, one of the technicians opened a few of the moved files to ensure that they had been transferred back onto the customer’s device without being corrupted. 

In the affidavit, Lall wrote that “once the computer was powered back on, he [the technician] observed a file on the ‘Desktop’ that was titled ‘Funtimes Folder Copy’ that contained a video or MP4 file. The file had a thumbnail of what looked like a male penis.”

Lall stated that the technician “then observed a second thumbnail of what looked like a small child, possibly 11 years old, and that he believed the file was labeled ‘11 YO’.”

The technician and his manager watched the video for a few seconds and then called police. A search of Bruno’s device and the hard drive used by Nerds To Go technicians in the repair of Bruno’s device was undertaken by law enforcement officers.

It is alleged that 730 unique images and videos depicting child sexual abuse were recovered during the search.

Guildford police arrested Bruno on December 21 and charged him with first-degree possession of child pornography. According to judicial records, Bruno was arraigned and released on a $20,000 surety bond. 

Bruno has not yet entered a plea regarding the charge. He is due to go before the court on February 3, 2022.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Thieves Raid Grass Valley

Cyber-Thieves Raid Grass Valley

A cyber-attack on a city in California has resulted in the exfiltration of personal and financial data belonging to vendors, city employees, and their spouses.

A data security incident notice published by the City of Grass Valley states that an unknown attacker was able to access some of the city’s IT systems for four months last year.

The city said that the attacker exploited the unauthorized access they enjoyed between April 13 and July 1, 2021, to steal data belonging to an unspecified number of individuals.

Victims affected by the data breach include Grass Valley employees, former employees, spouses, dependents, and individual vendors hired by the city. Other victims include individuals whose information may have been provided to the Grass Valley Police Department, as well as individuals whose information was provided to the Grass Valley Community Development Department in loan application documents.

The statement does not reveal the date upon which the presence of the threat actor was detected by Grass Valley but claims that the city “immediately took steps to secure our network, contacted law enforcement, and began an investigation with the assistance of a cybersecurity firm.”

A review of which files had been accessed by the threat actor and what data had been compromised was concluded on December 1. Information exposed during the attack was found to include Social Security numbers, driver’s license numbers, vendor names, and limited medical or health insurance information.

For individuals whose information may have been provided to the Grass Valley Police Department, the impacted data included name and one or more of the following: Social Security number, driver’s license number, financial account information, payment card information, limited medical or health insurance information, passport number, and username and password credentials to an online account.

Those who had applied for a community development loan may have had names and Social Security numbers, driver’s license numbers, financial account numbers, and payment card numbers compromised.

Grass Valley started notifying victims of the data breach on January 7, 2022. 

The city said: “To help prevent something like this from happening again, we continue to review our systems and are taking steps to enhance our existing security protocols.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Over Half of SMEs Have Experienced a Cybersecurity Breach

Over Half of SMEs Have Experienced a Cybersecurity Breach

Over half (51%) of SME businesses and self-employed workers in the UK have experienced a cybersecurity breach, according to a new study by insurance firm Markel Direct.

The findings were taken from a survey of 1000 SME firms and self-employed individuals in the UK, underlining fears that these organizations are at particularly high risk of cyber-attacks due to lack of resources and cybersecurity expertise. This issue has been exacerbated by the digital shift during COVID-19.

The most common attack methods faced by these organizations were malware/virus related (24%), data breaches (16%) and phishing attacks (15%). More than two-thirds (68%) of respondents said the cost of breaches they experienced was up to £5000.

The study also analyzed the extent of cybersecurity measures that are in place for SMEs and the self-employed. Nearly nine in 10 (88%) respondents said they had at least one form of cybersecurity, such as antivirus software, firewalls or multifactor authentication, and 70% said they were fairly confident or extremely confident in their cybersecurity arrangements.

Of these organizations and individuals, 53% had antivirus/malware software in place, and 48% had invested in firewalls and secure networks. In addition, nearly a third (31%) revealed they conducted risk assessments and internal/external audits on a monthly basis.

Worryingly, 11% of respondents said they would not spend any money on cybersecurity measures, viewing them as “unnecessary costs.”

Rob Rees, director of direct and partnerships from Markel Direct, commented: “Cyber-attacks on the largest corporations are often headline news, especially in consideration of some of the major breaches that have happened over the last few years to well-known businesses and local authorities. However, SMEs and the self-employed are also at risk, and the consequences can be devastating to smaller businesses that may not be able to recover from the financial impact of a cyber-breach or losing the trust of their customers.

“Cyber-criminals often target the self-employed and SMEs, as they lack the resources that large businesses have to invest in cybersecurity. SMEs and the self-employed who become targets of a cyber-attack can end up facing financial and operational consequences, of which some may never recover from.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Issues Warning Over Commercial Spyware

US Issues Warning Over Commercial Spyware

US government security experts have issued new guidance for possible targets of commercial spyware on protecting themselves from unwarranted surveillance.

“Some governments are using commercial surveillance software to target dissidents, journalists & others around the globe who they perceive as critics,” warned the US National Counterintelligence and Security Center (NCSC) in a Twitter post.

“Commercial surveillance tools are also being used in ways that pose a serious counterintelligence and security risk to US personnel and systems.”

The notice explained that the spyware is being deployed to target mobile and other internet-connected devices using Wi-Fi and cellular data connections.

“In some cases, malign actors can infect a targeted device with no action from the device owner. In others, they can use an infected link to gain access to a device,” it said.

Issued jointly by the NCSC and State Department, the guidance document warned that spyware could monitor phone calls, device locations and virtually any content on a device, including text messages, files, chats, messaging app content, contacts and browsing history.

Among the advice for potential targets was to update software regularly, never click on links in unsolicited messages, encrypt and password-protect devices and regularly restart devices to help remove malware implants.

The note also urged individuals to only use trusted VPNs, disable geolocation features and cover the camera.

The guidance comes just weeks after it was revealed that nine State Department staffers had their iPhones remotely hacked by spyware from controversial surveillance firm NSO Group.

The notorious Pegasus malware was used to snoop on the employees, who were either based in Uganda or working on projects concerning the African country.

The Biden administration is cracking down on the activities of commercial spyware providers.

In November, the Treasury put NSO Group on its Entity List – an export blocklist that will make it harder for the firm to get hold of American components or work with US partners.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

FlexBooker Reveals Major Customer Data Breach

FlexBooker Reveals Major Customer Data Breach

An online booking software provider has released details of a cloud breach over the festive period, resulting in the theft of millions of customers’ personal details.

FlexBooker offers appointment scheduling software for organizations in healthcare, finance and other sectors to accept bookings on their website.

However, late last week, breach notification site HaveIBeenPwned revealed that 3.7 million customer accounts had been compromised in December. It noted that most (69%) of the info was already in its database, presumably due to previous breaches and details reshared across multiple sites.

FlexBooker released a notice soon after, admitting that its cloud systems were targeted.

“On December 23, 2021, starting at 4:05 PM EST our account on Amazon’s AWS servers was compromised, resulting in our temporary inability to service customer accounts, and preventing customers from accessing their data,” it said.

“As part of the incident, our system data storage was also accessed and downloaded. In response to the outage, we worked closely with Amazon to restore a backup, and were able to restore operations within 12 hours.”

It’s unclear how the attackers were able to compromise the FlexBooker account and whether human error such as cloud misconfiguration had anything to do with it.

According to FlexBooker, the stolen information included customers’ full names, email addresses and phone numbers. It claimed that no payment card details were compromised, although according to HaveIBeenPwned, “partial credit card data” was taken.

Customer passwords were encrypted, and the encryption key was not accessed or downloaded, FlexBooker added.

It urged victims of the breach to review accounts for any suspicious activity, obtain a credit report, and consider placing a fraud alert on the report, as well as seeking a credit freeze.

Only 3% of breach victims place a credit freeze on their accounts despite it being a far more effective fraud mitigation strategy than credit monitoring.

It prevents lenders from obtaining a credit report about an individual, meaning they can’t open any new lines of credit, nor can fraudsters use stolen identity information.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Finalsite: All School Sites Now Restored After Ransomware Attack

Finalsite: All School Sites Now Restored After Ransomware Attack

A school IT supplier hit by ransomware last week has claimed that all of its customers’ websites have now been restored, although many will still be suffering some kind of disruption.

Finalsite claims to serve over 8000 schools worldwide, offering content management, communications, mobile and enrolment software.

After discovering ransomware on some systems on January 4, it was claimed that thousands of schools were affected – not only by the downing of websites but also critical messaging services designed to notify communities about weather-related closures or changing COVID-19 protocols.

In an update on Sunday, the firm claimed that it had restored front-end access to 99.9% of customer websites and that all sites now had admin access.

However, there were several caveats.

“We are still working to restore some assets from File Manager and Media Manager, which may affect the display of pages that rely on items like photos or videos loaded from these locations,” Finalsite noted.

“We have identified a segment of data integrations that require the restoration of mapping files, which we will restore and provide an update upon completion.”

It also explained that its legacy bulk email notification tool, eNotify, was still experiencing problems, although its replacement, the Messages module, is back up and running.

There’s still no word from the company as to whether it was forced to engage with its extorters to accelerate the process of restoration and recovery or if any sensitive data may have been taken. The majority of ransomware attacks now feature a data exfiltration and “double extortion” element, according to experts.

The nature of the provider hit by this attack could hint at a growing trend for ransomware in 2022, as threat actors target upstream supply chain firms more frequently to cause maximum damage and increase their chances of a big pay-out

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains