News

Army Recruiter Cyber-Stalked by Wannabe Soldier

Army Recruiter Cyber-Stalked by Wannabe Soldier

A man from Virginia has admitted cyber-stalking a United States Army recruiter for two years. 

Braxton Louis Danley, a 26-year-old resident of Luray, began harassing the female victim after failing to pass the army’s entrance exam.

Prosecutors said Danley’s first contact with the victim occurred in February 2018 when he sent her an email asking for information on joining the US Army. 

A month later, Danley met the recruiter in person when he visited her recruiting station in Harrisonburg, Virginia. It was on this occasion that Danley took and failed the entrance exam.

The wannabe soldier was told by the victim and by other army recruiters that he should keep studying and retake the exam at a future date. 

Prosecutors said that after receiving this advice, Danley began repeatedly making calls to the army-issued cellphone belonging to the victim, whose identity was not disclosed in court filings.

During the calls, Danley kept asking the victim when he could retake the exam.

Prosecutors said: “Each time, Danley was asked if he had studied for the test – which he admitted that he had not – and was advised that he would only be permitted to retake the test after he had studied.”

In May 2018, after two months of phone calls, Danley started to send the victim abusive emails and text messages and to express his anger over the phone. In one email he wrote: “I remember every thing you [expletive] done to me so time to settle the score.”

Danley then took to posting abusive and physically threatening messages on social media to the victim and two other army recruiters. 

In response to Danley’s campaign of harassment, the victim took out a restraining order against him. When he violated that order, Danley was sentenced to a year in prison. 

Within a few months of his release in June 2019, Danley started harassing the victim again via Facebook. In August 2020, a grand jury indicted Danley on one count of cyber-stalking and three counts of interstate threats.

On December 20, Danley pleaded guilty to cyber-stalking. He is due to be sentenced on February 1 and faces a maximum sentence of five years in prison.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Texas Convicts BEC Scammer

Texas Convicts BEC Scammer

A Texas resident has been convicted of stealing hundreds of thousands of dollars from a school district in Idaho through a business email compromise (BEC) scam.

Teton School District 401, which serves 1,800 students in seven schools in Teton County, fell victim to the cybercrime three years ago. 

In 2018, the district’s business manager, Carl Church, unknowingly made an electronic payment to a fraudulent bank account accessed through his district email account. 

Church transferred $784,833.71 in the belief that he was paying Headwaters Construction Company, a general contractor based in Victor, Idaho, which had been hired by the district to build new schools. 

In January 2019, after news of the cybercrime became public, Church resigned from his position. Speaking at the time, Teton County Deputy Andrew Sewell emphasized that Church was not suspected of any wrongdoing.

Sewell said the BEC cyber-attack “was a believable scam that he [Church] fell victim to.”

The incident was investigated by the Federal Bureau of Investigation. Over half the stolen funds were eventually recovered, and the state insurance carrier ICRMP paid the remaining balance. 

Houston resident Julius Joachim Ohumole, who moved to the United States from his native Nigeria, was charged over the cybercrime on November 8, 2019, and later taken into custody. 

On December 31, 2019, the US Attorney’s Office for the Southern District of Texas announced that 37-year-old Ohumole had been charged with one count of conspiracy, four counts of bank fraud, and two counts of aggravated identify theft.

Teton Valley News reported Wednesday that Ohumole has now been convicted and is due to be sentenced in February 2022. 

Superintendent Monte Woolstenhulme shared news of the conviction at a meeting of the school board on December 13. Woolstenhulme informed the trustees that he had been notified of the conviction by the US Department of Justice in Texas.

Each count of conspiracy and bank fraud carries a possible sentence of up to 30 years in federal prison and a maximum fine of $1m. The aggravated identify theft charge carries a maximum sentence of up to two years in prison.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Consumers Warned of Surging Delivery Text Scams Ahead of Christmas

Consumers Warned of Surging Delivery Text Scams Ahead of Christmas

Consumers have been warned to stay vigilant of delivery scam texts while online shopping for Christmas and during the Boxing Day sales.

UK Finance cited new data from cybersecurity firm Proofpoint showing that delivery ‘smishing’ scams are surging amid the busiest shopping period of the year. This showed that over half (55.94%) of all reported smishing text messages impersonated parcel and package delivery companies so far in Q4 2021. This compares to just 16.37% of smishing attempts in Q4 2020, more than tripling the proportion year-on-year.

Proofpoint also observed a significant drop-off in other types of smishing scams in Q4 2021 compared to Q4 2020. For example, text scams impersonating financial bodies and banks made up 11.73% of smishing attacks in 2021, compared to 44.57% in 2020.

The data comes from the NCSC’s 7726 text message system, operated by Proofpoint. This system enables customers to report suspicious texts.

Typically, delivery smishing scams start with the fraudster sending a fake text message informing the recipient that the courier has been unable to make a delivery and requesting a fee or additional details to rearrange. The consumer will be given a link to a fraudulent website impersonating the package delivery company, in which they are prompted to provide personal and financial details.

This type of scam has become increasingly prominent following the enormous growth in online shopping during COVID-19. Earlier this year, Proofpoint revealed that over two-thirds (67.4%) of all UK texts were reported as spam to the NCSC’s 7726 text messaging system in the 30 days to mid-July 2021.

A recent investigation by Which? demonstrated a particularly sophisticated smishing scam involving a highly convincing DPD copycat website.

Katy Worobec, managing director of economic crime at UK Finance, commented: “Scrooge-like criminals are using the festive season to try to trick people out of their cash. Whether you’re shopping online or waiting for deliveries over the festive period, it’s important to be on the lookout for scams.

“Don’t let fraudsters steal your Christmas – always follow the advice of the Take Five to Stop Fraud campaign and stop and think before parting with your information or money.”

Commenting, Steve Bradford, senior vice president EMEA at SailPoint, said: “The sharp rise in text message scams – or smishing, which has increased tenfold compared to last year, should be a stark warning to the public. With parcel delivery scam texts expected to spike this Christmas, it’s clear cyber-criminals are using every opportunity available to target victims using new methods.

“This comes as more businesses use SMS to engage with customers, to accommodate the digital-first mindset that now characterizes many consumers. But this also opens the doors to threat actors able to masquerade as popular websites or customer service support.

“Consumers must be extra vigilant and refrain from clicking any links in text messages that they’re unsure about. It’s also crucial they are keeping their data, identities and banking information safe – for example, by not taking pictures of their credit card and financial information, since photos often get stored in the cloud, which risks potential exposure to malicious actors.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Alibaba Suffers Government Crackdown Over Log4j

Alibaba Suffers Government Crackdown Over Log4j

Chinese tech giant Alibaba has reportedly been shunned by China’s top tech regulator for failing to report the infamous Log4j vulnerability quickly enough.

Local media claimed that the firm’s Alibaba Cloud business, which has a large team of security researchers, failed to report the issue to the Ministry of Industry and Information Technology (MIIT).

According to news site Protocol, a Chinese regulation dubbed Provisions on Security Loopholes of Network Products was in force as of September. It mandates vulnerabilities be reported immediately to the manufacturer and within two days to the Chinese authorities.

As a result, Alibaba Cloud has reportedly been suspended from MIIT’s threat information sharing platform for six months.

Alibaba Cloud researcher Chen Zhaojun is credited by Apache with finding the first bug in the popular logging utility, dubbed “Log4Shell.”

It was given a CVSS score of 10.0, with commentators describing it as a “worst-case scenario” because the utility is near-ubiquitous in enterprises, can be hard to find, and the bug is relatively easy to exploit.

Chen reportedly notified Apache on November 24, but MIIT only became aware of it on December 9.

Research from several years ago claimed that China’s National Vulnerability Database (CNNVD) is faster at updating with the latest CVEs than the US equivalent (NVD).

However, the researchers later found that this was down to government manipulation.

On further investigation, they found that the Chinese authorities tried to backdate original publication dates for vulnerabilities to disguise their own work to exploit these bugs in state-backed attacks.

Recorded Future argued that the CNNVD is essentially a “shell” for the government’s fearsome Ministry of State Security (MSS), a prodigious hacker of foreign entities.

“This systemic retroactive alteration of original publication dates by CNNVD is an attempt to hide the evidence of this process, obfuscate which vulnerabilities the MSS may be utilizing, and limit the methods researchers can use to anticipate Chinese APT behavior,” the firm said at the time.

“There is no other logical explanation as to why only the initial publication dates for outlier CVEs would have been altered.”

The latest action against Alibaba could also be viewed as part of a recent Communist Party crackdown on big tech, which has cost investors trillions.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

CISA Releases Free Scanner to Spot Log4j Exposure

CISA Releases Free Scanner to Spot Log4j Exposure

The US government’s top security agency has published a new scanning tool to help organizations find unpatched Log4j instances in their IT environment.

The Cybersecurity and Infrastructure Security Agency (CISA) posted the Log4j Scanner to GitHub yesterday. It claimed it’s a “project derived from other members of the open-source community” and designed to help find vulnerable web services impacted by the two flaws in the popular logging tool.

“This repository provides a scanning solution for the log4j remote code execution vulnerabilities (CVE-2021-44228 & CVE-2021-45046),” CISA said. “The information and code in this repository is provided ‘as is’ and was assembled with the help of the open-source community and updated by CISA through collaboration with the broader cybersecurity community.”

Cybersecurity firm FullHunt was name-checked in the release.

Log4j was patched earlier this month but exploits appeared soon after. The initial CVE-2021-44228 bug, dubbed “Log4Shell” was given a CVSS score of 10.0.

It’s deemed particularly dangerous as Log4j is found in numerous third-party software from iCloud to Minecraft. In some cases, it can be exploited relatively easily to achieve RCE for ransomware, cryptojacking, data theft, and more. All Log4j instances may be difficult to find given the complex Java dependencies operating in many enterprise environments.

As a result, some experts have said the threat could persist for years.

A second denial of service flaw (CVE-2021-45046) was found days later, although it has a lower CVSS score of 7.5.

CISA said the scanning tool would only help security teams “look for a limited set of currently known vulnerabilities in assets owned by their organization.” It warned that there may be “as yet unknown” ways for threat actors to leverage the vulnerabilities and said it is continuing to monitor community chatter to ensure its advice is current.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Up to 120,000 Cops May Have Legal Claim Over 2019 Breach

Up to 120,000 Cops May Have Legal Claim Over 2019 Breach

Lawyers are seeking a “group litigation order” against the Police Federation (PFEW) over a 2019 ransomware breach which they say may have impacted 120,000 officers.

Keller Lenkner UK said it served notice this week to the staff association for police constables, sergeants, inspectors and chief inspectors in England and Wales. It intends to seek the order from the High Court in early 2022.

As reported by Infosecurity at the time, the PFEW’s IT systems were first hit on March 9 2019, and then again ten days later.

It claimed that several databases and systems at its Surrey headquarters had been affected.

“Back-up data has been deleted and has been encrypted and became inaccessible. Email services were disabled and files were inaccessible,” an FAQ statement noted.

Although the attack was halted before it could spread to any regional branches across the country, Keller Lenkner claims that the federation did not have adequate data security processes.

This may have led to personal and financial data theft from members. The law firm is also alleging that the PFEW didn’t inform members until a fortnight after the breach, despite GDPR obligations to the contrary.

Group litigation orders are the UK’s equivalent of a US class action suit. However, unlike class actions, where affected parties are included in the suit unless they opt-out, the UK version requires potential litigants to opt-in proactively.

Therefore, each case will be judged on its own merits, but Keller Lenkner said it is looking into pursuing action around financial loss, distress, and loss of privacy for the breach victims.

It claimed that breached information included names, email addresses, national insurance (NI) numbers, ranks and serving forces of up to 120,000 officers, and names, addresses and email addresses of guests who visited the PFEW’s conference Leatherhead.

Also compromised were names, addresses, NI numbers and bank details of members who requested the federation’s assistance for “any investigation, inquiry or complaint.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Cyber-Attack on Belgium’s Military

Cyber-Attack on Belgium’s Military

Threat actors have exploited a vulnerability in Log4j software to wage a cyber-attack on Belgium’s Defense Ministry.

The attack began on December 16 and was confirmed by Belgium’s Ministry of Defense on Monday. 

Speaking to the AFP in Brussels on Tuesday, Belgian military spokesman Commander Olivier Séverin said that the incident had caused damage to services that were connected to the internet, paralyzing part of the ministry’s activities. 

He added that five days after the attack began, analysis of the incident was still being carried out and the process of restoring disrupted services remained ongoing.

Séverin did not shed any light on who may have been responsible for the cyber-attack. 

A spokesperson for Belgian Defense Minister Ludivine Dedonder said that “the ministry’s teams have been working hard in past days to secure its networks” and that the Belgian government will continue to invest in cybersecurity defenses.

Log4j is a Java-based logging library that tracks system processes. Security teams around the world have been working to secure their systems after multiple vulnerabilities were discovered in Log4j earlier this month.

Mike Saxton, chief technologist at Booz Allen and director of Federal Threat Hunt and Digital Forensics and Incident Response (DFIR) urged organizations to act now to mitigate the Log4j vulnerability. 

“Most immediately, organizations must establish and see through a plan that begins with the following: 1) Implementing sensor blocks; 2) Disabling Log4J; 3) Identifying and patching vulnerable versions; 4) Disabling JNDI lookups; 5) Disabling remote codebases; 6) Performing scan with updated vulnerability management templates; 7) Performing searches and analysis of all security logs for evidence of enumeration or compromise; 8) Consolidating, communicating, and disseminating updated threat intel associated with Log4j; 9) Tracking all remediation and mitigation efforts and tasks; 10) Continuing to apply up-to-date blocking measures; 11) Monitoring LDAP traffic; and 12) Moving vulnerable systems behind additional firewalls,” said Saxton. 

He added: “This list may seem overwhelming, but it should be viewed as a template rather than a checklist that organizations can follow.”

In the long term, Saxton advised organizations to move to a persistent threat hunt model and to work under the assumption that their vulnerable assets will be breached. 

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains