BlackBox (Security) Archiv
4.07K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
Russia Proposes a Legal Plan to Restrict Crypto Circulation

The Russian government has issued a proposal to restrict the circulation and transaction of cryptocurrencies

The Russian territory presents a plethora of opportunities as far as the cryptocurrency industry is concerned.

Arguably, a proper legal environment would potentiate Russia’s crypto capacities to become a hub of virtual assets – there’s enough Russian talent to back the industry up.

However, it appears that Russia has lagged behind when it comes to the establishment of crypto hotspots as the lack of proper legal infrastructure happens to be a glaring challenge in the eyes of digital asset enthusiasts.

In recent news, the Russian Ministry of Finance has proposed a move that will create legislation to restrict the circulation of cryptocurrencies within the economy – a decision that will serve as a yardstick for global crypto regulation.

Russian media intimated that the Russian government intends to prescribe amendments to the existing Digital Financial Assets (DFA) law, which was ratified in July and is set to be implemented from the first month of 2021.

Ideally, the DFA law came about as a result of the Russian government’s need to enable transactions involving digital securities and tokens, including well-established cryptocurrencies like Bitcoin and Ether.

At the time of inception, the DFA law was meant to be coupled with a separate piece of legislation targeting the regulation of crypto circulation.

👀 👉🏼 https://tapeucwutvne7l5o.onion/russia-proposes-a-legal-plan-to-russia-crypto-circulation

👀 👉🏼 https://iz.ru/1056107/tatiana-bochkareva-roza-almakunova/zapretnyi-plod-maining-v-rossii-zablokiruiut-oborot-kriptovaliut

👀 👉🏼 https://www.ledgerinsights.com/russia-restrict-circulation-cryptocurrency/

#russia #plan #restrict #cryptocurrency #circulation
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
A data fail left banks and councils exposed by a quick Google search

Details of more than 50,000 letters sent by banks and local authorities were left online for anyone to see

Private details relating to more than 50,000 letters sent out by banks and local authorities were indexed by Google after a London-based outsourcing firm left its system hopelessly exposed. Details about everything from insolvency to final reminders of unpaid council tax and mortgage holidays were left available for anyone to view since June.

Thousands of names and addresses – and the types of letters they were sent – were left exposed, affecting people in the UK, US and Canada. Virtual Mail Room, the firm responsible for the data breach, worked for clients including Metro Bank, 14 local councils, the publisher Pearson and insolvency specialist Begbies Traynor. The specific content of the letters sent to individuals were not visible.

The privacy breach raises doubts about the due diligence carried out by companies and local authorities using outsourced mailing services to handle sensitive customer data. It also comes at a particularly painful time, with many of the names and addresses contained in the breach belonging to people who have been hit hard financially by the pandemic. Such missteps could fall foul of GDPR, with data controllers and processors potentially facing fines totalling tens of millions of pounds. A spokesperson for the Information Commissioner’s Office, the UK’s data regulator, confirmed it was aware of the incident and was making enquiries.

The details exposed by the breach are hugely personal. Amongst the tranche of exposed personal data were the names and addresses of 6,500 customers of Aldermore Bank. The back-end system left exposed reveals which customers received pre-delinquency and remediation letters. A spokesperson for the bank says it is investigating the issue. Elsewhere, more than 250 Metro Bank customers were identified with their company name and address. A Metro Bank spokesperson says the company has “temporarily suspended sharing data” with Virtual Mail Room as a precautionary measure while its investigation continues.

👀 👉🏼 https://www.wired.co.uk/article/virtual-mail-room-data-breach

#virtual #mail #room #privacy #breach #uk #canada #usa
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Media is too big
VIEW IN TELEGRAM
When DevOps goes wrong - An observation story

In recent years, the DevOps movement has grown massively in popularity.
For some it made life easier, for others there were no changes and for others it has become "worse" since then.
If you belong to the latter group and have ever thought that you are alone in this respect, you are wrong. Obviously, some of these deteriorations are due to the fact that DevOps is implemented "wrong" or inconsistently in the workplace.
This talk will give an overview of real life observations made in DevOps environments.
It might include some of the nice, some of the bad and some of the ugly solutions you might encounter.

📺 👉🏼 https://media.ccc.de/v/froscon2020-2587-when_devops_goes_wrong

#froscon2020 #ccc #devops #video
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
The public don’t trust computer algorithms to make decisions about them, survey finds

The majority of people do not trust computers to make decisions about any aspect of their lives, according to a new survey.

Over half (53%) of UK adults have no faith in any organisation to use algorithms when making judgements about them, in issues ranging from education to welfare decisions, according to the poll for BCS, The Chartered Institute for IT.

The survey was conducted in the wake of the UK exams crisis where an algorithm used to assign grades was scrapped in favour of teachers’ predictions.

Just 7% of respondents trusted algorithms to be used by the education sector - joint lowest with social services and the armed forces. Confidence in the use of algorithms in education also differed dramatically between the age groups - amongst 18-24-year-olds, 16% trusted their use, while it was only 5% of over 55-year-olds.

Trust in social media companies’ algorithms to serve content and direct user experience was similar at 8%. Automated decision making had the highest trust when it came to the NHS (17%), followed by financial services (16%) and intelligence agencies (12%), reflecting areas like medical diagnosis, credit scoring and national security.

Police and ‘Big Tech’ companies (like Apple and Google) were level with 11% of respondents having faith in how algorithms are used to make decisions about them personally.

Older people are less trusting about the general use of algorithms in public life, with 63% of over-55s saying they felt negative about this, compared with 42% of 18-24-year-olds. Attitudes to computerized decisions in the NHS, private health care and local councils differ very strongly by age. 30% of 18-24-year-olds said they trusted the use of algorithms in these sectors, while for those over 55, it was 14%.

Over 2,000 people responded to the survey conducted for BCS, The Chartered Institute for IT by YouGov; all were shown a description of algorithms before answering any questions.

Dr Bill Mitchell, Director of Policy at BCS said: “People don’t trust algorithms to do the right thing by them – but there is little understanding of how deeply they are embedded in our everyday life.

“People get that Netflix and the like use algorithms to offer up film choices, but they might not realise that more and more algorithms decide whether we’ll be offered a job interview, or by our employers to decide whether we’re working hard enough, or even whether we might be a suspicious person needing to be monitored by security services.

👀 👉🏼 https://www.bcs.org/more/about-us/press-office/press-releases/the-public-don-t-trust-computer-algorithms-to-make-decisions-about-them-survey-finds/

#people #dont #trust #computer #algorithm #survey
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Your digital privacy is under attack. Can anything be done to protect it?

A committee from the Council of Europe is concerned with the use of technology for mass surveillance programs.

Intelligence services around the world should be kept in check by an international body with the power to make sure governments don't misuse personal data for surveillance purposes, said the Council of Europe's data protection committee chairs in a joint statement.

Countries should agree at an international level on the extent to which the surveillance carried out by intelligence services can be authorized and under which conditions, recommended the committee. The agreement should come as a legal tool that could be enforced independently by a data protection body that is yet to be created.

The European human rights organization said that calls for better data protection at an international level are especially relevant in times of crisis, when circumstances provide governments with an opportunity to lawfully restrict citizens' privacy rights.

👀 👉🏼 https://www.zdnet.com/article/your-digital-privacy-is-under-attack-can-anything-be-done-to-protect-it

👀 👉🏼 Better protecting individuals in the context ofinternational data flows (PDF):
https://rm.coe.int/statement-schrems-ii-final-002-/16809f79cb

#digital #privacy #attack #data #flows #thinkabout #pdf
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
EU leaders to call for an EU electronic ID by mid-2021

EU leaders will ask the European Commission later this month to develop an EU-wide public electronic identification system (e-ID) to access cross-border digital services, according to the draft summit conclusions seen by
EURACTIV.com

Strengthening Europe’s autonomy and sovereignty in the aftermath of the pandemic will be the main topic of the European Council to be held on 24 and 25 September in Brussels and digital initiatives will feature prominently.

As part of their plans, the 27 Heads of State and Government want to have a robust and functional digital ecosystem across the Union for citizens.

To that end, EU leaders will call for the development of an “EU-wide secure public electronic identification (e-ID) to provide people with control over their online identity and data as well as to enable access to cross-border digital services,” the draft document reads.

They will ask the Commission to put forward a proposal for a ‘European Digital Identification’ initiative by mid-2021, and member states hope that an EU-wide e-ID will be especially for cross-border digital services, a market expected to grow in the digital economy.

There has been some progress on this front over the past years at the technical level to guarantee the interoperability of national e-ID. Thanks to that, since September 2018, EU rules allow citizens to use their national e-ID also to access public services across borders in other member states.

In this context, the Commission has recently sought to update the rules on electronic identification operations in the EU, as part of the eIDAS regulation, in a bid to develop a more harmonized and resilient market for electronic identification systems on the bloc.

On the launch of the Commission’s public consultation on the plans in the summer, Commission Vice-President for Digital Margarethe Vestager said that the revision of the 2018 eIDAS regulation “aims to improve its effectiveness, extend its benefits to the private sector and promote trusted digital identities for all Europeans and create a secure and interoperable European Digital Identity which gives citizens control.”

👀 👉🏼 https://www.euractiv.com/section/digital/news/eu-leaders-to-call-for-an-eu-electronic-id-by-mid-2021/

#eu #eIDAS #electronic #id
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Audio
Health Insurers Are Vacuuming Up Details About You — And It Could Raise Your Rates

To an outsider, the fancy booths at a June health insurance industry gathering in San Diego, Calif., aren't very compelling: a handful of companies pitching "lifestyle" data and salespeople touting jargony phrases like "social determinants of health."

But dig deeper and the implications of what they're selling might give many patients pause: a future in which everything you do — the things you buy, the food you eat, the time you spend watching TV — may help determine how much you pay for health insurance.

🎧 👉🏼 https://www.npr.org/sections/health-shots/2018/07/17/629441555/health-insurers-are-vacuuming-up-details-about-you-and-it-could-raise-your-rates

#insurance #companies #secret #health #insurers #bigdata #BigData #surveillance #thinkabout #podcast
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
The business of cybercrime
Financial Times
The business of cybercrime

Sociologist Jonathan Lusthaus spent seven years talking to cyber criminals. He tells Hannah Kuchler what he discovered about the extent of their involvement with organised crime and what he thinks it would take to persuade them to put their talents to better use.

🎧 👉🏼 #podcast #cybercrime #truecrime

📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Episode 25: Cybercrime's Future: A Telegram One-Act Play
Cybercrime's Future: A Telegram One-Act Play

What does the Future of Cybercrime Look Like? Find out in this solo Brett Johnson episode. Brett interviews a well-respected cybercriminal who owns several Telegram Channels. But there is a catch. The guy refuses to have his voice heard and will only communicate by text. For our listeners and because Brett Johnson is THAT guy? Brett plays the part of the criminal in what promises to be one of the most interesting, educational, entertaining, and enlightening podcast interviews of the year.

🎧 👉🏼 #cybercrime #telegram #truecrime #podcast

📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook to be forced to stop sending EU data to the US

The Irish regulator is expected to stop the social media giant from moving data to the US because of privacy concerns.

Ireland's privacy watchdog has told Facebook that it will soon have to stop transferring its European users' data to the United States because the social media giant's current procedures fall foul of EU law.

Facebook was told in early August that the Irish privacy regulator was reviewing how it moved data to the U.S., according to two people with knowledge of the case who spoke on the condition of anonymity because they were not authorized to speak publicly.

In a statement, Nick Clegg, Facebook's head lobbyist, confirmed Ireland's expected decision, saying that the pending ruling would be felt across the transatlantic economy.

"A lack of safe, secure and legal international data transfers would damage the economy and hamper the growth of data-driven businesses in the EU," Clegg said. "We will continue to transfer data in compliance with the recent CJEU ruling and until we receive further guidance."

Facebook still has an opportunity to put its case to Ireland's Data Protection Commissioner before a final judgment — but the order will likely set a precedent for how billions of euros of data should be handled and moved across the Atlantic.

👀 👉🏼 https://www.politico.eu/article/facebook-privacy-data-us/

👀 👉🏼 https://about.fb.com/news/2020/09/securing-the-long-term-stability-of-cross-border-data-flows/

👀 👉🏼 🇩🇪 https://netzpolitik.org/2020/blauer-brief-aus-dublin-facebook-datentransfers-in-die-usa-vor-dem-aus

#fb #DeleteFacebook #privacy #data #PrivacyShield
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Former NSA chief Keith Alexander has joined Amazon’s board of directors

Alexander was the public face of US surveillance during the Snowden leaks

Keith Alexander is joining Amazon’s board of directors, the company revealed in a Securities and Exchange Commission filing today. (Alexander has also been added to the company board’s official site.) A former director of the National Security Agency and the first commander of the US Cyber Command, Alexander served as the public face of US data collection during the Edward Snowden leaks, but he retired from public service in 2013.

Alexander is a controversial figure for many in the tech community because of his involvement in the widespread surveillance systems revealed by the Snowden leaks. Those systems included PRISM, a broad data collection program that compromised systems at Google, Microsoft, Yahoo, and Facebook — but not Amazon.

Alexander was broadly critical of reporting on the Snowden leaks, even suggesting that reporters should be legally restrained from covering the documents. “I think it’s wrong that that newspaper reporters have all these documents, the 50,000-whatever they have and are selling them and giving them out as if these — you know it just doesn’t make sense,” Alexander in an interview in 2013. “We ought to come up with a way of stopping it. I don’t know how to do that. That’s more of the courts and the policymakers but, from my perspective, it’s wrong to allow this to go on.”

Alexander’s board spot will also give Amazon new expertise in defense contracting, an area of particular focus for the company in recent years. Amazon was a leading candidate for a recent $10 billion cloud computing contract with the Pentagon, but it ultimately lost out to Microsoft. The company is currently engaged in a lawsuit against the federal government in connection with the contract, alleging that President Donald Trump’s personal statements against Amazon CEO Jeff Bezos biased the process against Amazon.

👀 👉🏼 https://twitter.com/Snowden/status/1303829551999602688

👀 👉🏼 https://www.theverge.com/2020/9/9/21429635/amazon-keith-alexander-board-of-directors-nsa-cyber-command

👀 👉🏼 https://www.zdnet.com/article/now-amazon-adds-ex-nsa-chief-keith-alexander-to-its-board

👀 👉🏼 https://w3techs.com/technologies/details/ho-amazon

#Snowden #Bezos #Alexander #amazon #DeleteAmazon #usa #nsa #surveillance #thinkabout #why
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
This media is not supported in your browser
VIEW IN TELEGRAM
SF drone footage during the #BayAreaFires on 9/9/20, set to Blade Runner 2049 music

I
know this video has nothing to do with threats to security / privacy / democracy on the net. Or somehow it does? Clearly something we should think about !!

👀 👉🏼 State of emergency declared:
https://www.gov.ca.gov/2020/08/18/governor-newsom-declares-statewide-emergency-due-to-fires-extreme-weather-conditions-2/

📺 👉🏼 https://www.youtube.com/watch?v=x_m9TUP_t_Y

#BayAreaFires #usa #emergency #thinkabout #video
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Media is too big
VIEW IN TELEGRAM
The Social Dilemma

Why the algorithms of #TikTok are possibly optimized more for screentime and less for suicide removal is explained very clearly in the new Netflix documentary "The Social Dilemma". Director Jeff Orlowski has put all the ethics big shots from Silicon Valley in front of the camera - from Tristan Harris to Shoshanna Zuboff - and lets them once again unravel the business model of surveillance capitalism in a striking way.

📺 👉🏼 The Social Dilemma 👈🏼
#video #documentary #surveillance #capitalism #SocialDilemma #thinkabout #why

📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Ransomware accounted for 41% of all cyber insurance claims in H1 2020

Cyber insurance claims ranged in size from $1,000 to well over $2,000,000 per security incident.

Ransomware incidents have accounted for 41% of cyber insurance claims filed in the first half of 2020, according to a report published today by Coalition, one of the largest providers of cyber insurance services in North America.

The high number of claims comes to confirm previous reports from multiple cyber-security firms that ransomware is one of today's most prevalent and destructive threats.

"In the first half of 2020 alone, we observed a 260% increase in the frequency of ransomware attacks amongst our policyholders, with the average ransom demand increasing 47%," the company added.

👀 👉🏼 https://www.zdnet.com/article/ransomware-accounts-to-41-of-all-cyber-insurance-claims

#ransomware #cyber #ensurance #claims
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Hackers Stole $5.4 Million From Eterbase Cryptocurrency Exchange

Cybercriminals successfully plundered another digital cryptocurrency exchange.

European cryptocurrency exchange #Eterbase this week disclosed a massive breach of its network by an unknown group of hackers who stole cryptocurrencies worth 5.4 million dollars.

Eterbase, which has now entered maintenance mode until the security issue is resolved, described itself as Europe's Premier #Digital #Asset #Exchange.

Based in Bratislava, Slovakia, and launched in 2019, Eterbase is a small cryptocurrency exchange platform that focuses on crypto to SEPA integration (via individual IBAN accounts), multi-asset support, and regulatory compliance.

On Monday night, #malicious threat actors managed to raid six Eterbase's hot wallets for #Bitcoin, #Ethereum, #XRP, #Tezos, #Algorand, and #TRON and transferred the funds into their #wallets managed at six rival #crypto #exchanges, Eterbase reported on its Telegram channel on Tuesday.

👀 👉🏼 https://twitter.com/ETERBASE/status/1303829913015902210

👀 👉🏼 https://thehackernews.com/2020/09/hackers-stole-cryptocurrencies.html

#hackers #hacked #cryptocurrencies
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Facebook pilots Campus, a college student-only section similar to The Facebook of '04

The company is aiming to personalize Facebook's core service for the modern-day college experience.

Facebook announced Wednesday that it's piloting a new college-only section on the platform called Facebook Campus. The space is meant to serve as a hub for students on college campuses, offering ways to find and connect with fellow classmates, and keep up with campus events -- sort of like the original The Facebook that launched as a social network for college students back in 2004.

With this new version, however, the company is aiming to personalize Facebook's core service for the modern-day college experience.

"This year, students across the country are facing new challenges as some campuses shift to partial or full-time remote learning, so it's more important than ever to find a way to stay connected to college life," Charmaine Hung, product manager for Facebook Campus, wrote in a blog post.

👀 👉🏼 https://about.fb.com/news/2020/09/introducing-facebook-campus/

👀 👉🏼 https://www.zdnet.com/article/facebook-pilots-campus-a-college-student-only-section-similar-to-the-facebook-of-04

#fb #DeleteFacebook #campus #students
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Smart contact lens prototype raises eyebrows

This prosthetic iris demonstrates the power and promise of nanotechnology.

Smart contact lenses are a sci-fi trope, but they may also offer hope for sufferers of certain kinds of debilitating eye ailments. That's the goal of new research into a a tunable, low-powered iris embedded in a smart contact lens.

It's a good example of the growing role of nanotechnology in human augmentation and therapeutics. The human iris controls pupil size in response to light, a critical function that allows the retina to take in appropriate sensory information. Too much light and the world is washed out, too little and it's veiled in darkness. A host of eye diseases and deficiencies inhibit the iris from responding appropriately, including aniridia and keratoconus. Light sensitivity, similarly, is a painful debilitation and is often associated with chronic migraine.

Researchers at Imec, an innovation hub based in Belgium, along with partners like CMST, a Ghent University-affiliated research group, the Instituto de Investigación Sanitaria Fundación Jiménez Díaz in Madrid, Spain, and Holst Centre have been developing an low-powered wearable solution. The contact lens's iris aperture is tunable thanks to an integrated liquid crystal display (LCD) that manipulates concentric rings.

👀 👉🏼 https://www.zdnet.com/article/smart-contact-lens-prototype-raises-eyebrows

#smart #contactlens #prototype
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
F5 Big-IP RCE writeup + full exploit

When TEAMARES began research into the vulnerability identified in the F5 TMUI RCE vulnerability advisory released last month, we initially started by reading the advisory and mitigation steps, which contained minimal details but included key pieces of information needed to kick off our research. The advisory states that the vulnerability impacts a variety of capabilities when exploited, including the ability to execute arbitrary Java code, which stood out to us.

👀 👉🏼 https://www.criticalstart.com/f5-big-ip-remote-code-execution-exploit/

👀 👉🏼 https://github.com/Critical-Start/Team-Ares/tree/master/CVE-2020-5902

#f5 #ip #remote #code #execution #exploit #teamares #poc #writeup
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
I am a former (convicted) Darknet vendor, dealing in cocaine and heroin to all 50 states from June of 2016 to early 2017. AMA! - ask me anything

My short bio: I was one of the most popular USA domestic cocaine vendors on the darknet on Alphabay and Dream, beginning in the summer of 2016 into early 2017. I initially started selling pure cocaine, and expanded my menu to Xanax and Heroin a couple of months in. AMAA! My Proof: Proof submitted confidentially to moderators

👀 👉🏼 https://www.reddit.com/r/IAmA/comments/iqlr29/iama_i_am_a_former_convicted_darknet_vendor/

#darknet #vendor #dealer #questions
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag