Showing posts with label CIO. Show all posts
Showing posts with label CIO. Show all posts

Wednesday, July 7, 2021

Do Smart Contracts Make You Feel Dumb?

 

Stablecoins May Not Be Very Stable.

What is a Coin? What is a Token?

By Dominic Alvieri, @AlvieriD
July 7th, 2021 


The Crypto Craze
The Crypto Craze.



The proposed STABLE Act will require stablecoin issuers to have a banking charter and report holdings.


The STABLE Act may be coming soon. Additional reporting and disclosure of assets securitizing stablecoins is a move in the right direction for security sake.

You probably have heard Bitcoin is an investment or a store of value .
You may have also heard most ransomware is paid in Bitcoins.

Do you know the difference between a coin and a token?
Do you know about different blockchains?
Do you know what fungible means?


What or who is backing your stablecoins?



Bitcoin, Ethereum, Ripple and stablecoins are not all created equal. Bitcoin is a digital currency to invest, hold or purchase in exchange for goods or services much the way a dollar in the local store would. Your one dollar or Bitcoin is fungible or able to replace or is interchangeable or equal to the next one. What or who is behind and backing your stablecoin?



Do you know the difference between Bitcoin and Ethereum.
Do you know the difference between BTC and ETH?


What is a coin and what is a token?

Do you know the difference between a coin and a token? A coin is referred to as a cryptocurrency and can be held as an investment or used  like Bitcoin in exchange for an item, good or service.

A token is issued as a smart contract on the Ethereum blockchain and there are three main types of tokens. A token may currently be a utility, commodity or security based token. In brief a utility token generally is used between a site for a use. A commodity based token is backed by a certain asset or commodity such as gold. A security token implies ownership in that company or decentralized unit. 

Cryptocurrency and tokens have different values. Ethereum has gas to defend infinite loops.
Keccak that. Is that still used? What is that?

Obtain full details before investing in any cryptocurrency, token or other investment in general.

Smart contracts make you feel dumb?


ERC-20 and ERC-721 basics.

In short smart contracts use blockchain technologies and software to execute the exchange of an asset or property between a buyer and a seller written directly into the code of the contract on the Ethereum framework are called ERC 20s. Rather than running a separate blockchain, ERC 20 is the main technological standard and set of rules that apply to issuing smart contracts via the Ethereum blockchain. There are six basic rules and are in place for uniformity among contracts. Several digital currencies including Augur and Maker use the ERC 20 standard.

An ERC 721 is a non-fungible token. There is more to.


The wild world of cryptocurrencies.
There are many different stablecoin issuers.


A word of caution.


A word of caution going forward. Government central banks will be issuing Central Bank Digital Currencies, or CBDCs. A stablecoin is not a CBDC.

 A CBDC is not backed by any Bitcoin, Ethereum or any other digital cryptocurrency. 
It will be issued by a government.

Tether backed stablecoin assets have been questioned before.


 A stablecoin is not backed by either a CBDC, BTC, ETH, etc. Check with your actual investment prospecuts or white paper.  With Tether and other stablecoins you are trusting in a company to maintain its peg rate and assets securitizing the underlying stablecoin. 

The STABLE Act will require stablecoin issuers to acquire a banking charter or license and file reports showing detailed investment holdings backing stablecoin investments.  



Buyer beware security is on you too.
Buyer beware, the security is on you as well.


The crypto craze continues.


Be careful with valuations and security. Do use cold storage and secure 2FA for your accounts. 
The main difference between 2FA and MFA is more factors. 2FA implying two factors and MFA more than two. The more the merrier with security.

Separating MFA between devices will give you an added layer of security. If one of your security factors gets bypassed, your phone ported for example, you will still be able to maintain that second layer of defense to restrict access to that account. 

Having your tokenized security app, email second factor or even SMS alert on another private secure line is a great added layer of security. Secure your accounts with tokenized 2FA at a minimum. 



Fungible or non fungible cyber show?
Blockchain, cryptocurrency, stablecoin or token, Each are different



There are different types of blockchains, public, private and permissioned. 
There are different types of cryptocurrencies.
There are different types of stablecoins.
There are different types of tokens.

Know the difference between Bitcoin, Ethereum and Libra before you invest. Be careful with misinformation when it comes to crypto and investing in general.

 Get verified information.


The Cybersecurity Show By Dominic Alvieri
The Cyber Show by Dominic Alvieri, @AlvieriD

The Cybersecurity Show by Dominic Alvieri
The Cyber Show on Google Blogger and YouTube
    @AlvieriD

Friday, February 12, 2021

New edX Course Links to the Chinese Chief Information Office

 Redirected Link is Now Direct Link

 By Dominic Alvieri

Twitter @AlvieriD


January 23rd, 2021


Redirected link on edX is now a direct link.
Redirected link on edX.

The second largest online educational platform edX created by Harvard and MIT has been breached. Or has it?

A new Rochester Institute of Technology online advanced cybersecurity course on edX was redirected last week to the Chinese Government Chief Information Office in Wanchai, Hong Kong China.

Now the US InfoSec portion links directly to InfoSec China


Redirected edX link to China.
Redirected link last week.

The link above leads to the Chinese Government Chief Information Office in Wanchai, Hong Kong.


Link leads to Chinese Government Information Office.
Link leads to Chinese Government Chief Information Office.


Well how did that get there?

Rochester Institute of Technology and the Chinese professor were unavailable for comment. The redirected link in week one now have direct links to the Chinese government Chief Information Office.

The US InfoSec link now leads directly to the Chinese Chief Information Officer. That is not a typo.

It is still unclear if that is the destined source for the course information. After weeks of question still no answers to why they are still there.


US InfoSec page leads to InfoSec China


Unknown joint educational operation?



Redirected page is now direct.
Redirected page is now directly linked.


US Institutions of higher learning have been probed during the pandemic and warned by the FBI for collaborating with communist groups. The persistent picture painting and data collection by the communist government is under investigation and will update the information is confirmed.

I highly doubt this is the intended educational path for US Cybersecurity masters students but things may have changed in a year, besides the Presidency. 

Update pending with comments due some time in February, 2021.



The Cyber Show


Dominic Alvieri
Twitter @AlvieriD
The Cyber Show
The CyberSecurity Show on
Google Blogger and Medium.

Wednesday, December 9, 2020

Is This The End Of Facebook?

 The FTC and States File Antitrust Lawsuits Against Facebook.


What Will Facebook Lite Look Like?


By Dominic Alvieri, @AlvieriD

December 9th, 2020.


The FTC and states filed a major suit against Facebook today.
Official law suits to split Facebook have been filed.

What will Facebook Lite be in the future?

What will Facebook be in the Future? Without Instagram? Facebook without what now?
Facebook Lite? The next MySpace?

Is this the end of Facebook as we know it?


The FTC and 48 states filed antitrust lawsuits against Facebook today in official calls to split up the social media giant. Google has long been a target as well.

The pieces may be worth more apart now with historically high IPO valuations. Prices continue to rise with the flood of new issues like DoorDash today. Probably not on the thoughts of Facebook executives today but may be on their evening to do list.

Facebook may not have a choice in the near future.


Facebook / Instagram / WhatsApp
Calls to split up Facebook are now official.


This may turn out to be a historic day in retrospect.


With the calls to break up Facebook now official the company may not have a choice but to sell off units to appease the litigators. Facebook and Google have long been the targets of cybersecurity attacks and litigation. The stakes are all on the table now.

At what point is a company to large to continue to grow without harming competition?

Will splitting up Facebook change anything?

With associations in place, competition fierce and alliances made, will splitting Facebook up help or hinder competition? How big is too big?

That is a difficult question to answer and usually is settled in a court of law.



What will Facebook be in the future?
What will Facebook be in the future?



Is this the end of Facebook? Probably not. Is this the end of Facebook as we know it today?


That remains to be answered more likely now in a court of law. Time always tells.
Facebook is now officially on the clock as the net has been cast.


Once the net is cast there is usually a price to be paid. Once again, time will tell. 

Stay tuned.



The Cyber Show by Dominic Alvieri, @AlvieriD
Dominic Alvieri, @AlvieriD





The Cyber Show 
The CyberSecurity Show on Google Blogger and YouTube
by Dominic Alvieri, @AlvieriD

Analyst, Researcher and Tracker.

Saturday, December 5, 2020

How to Slow a Social Engineer

Hacking Bitcoins by Night...


     The Port of it All. 


By Dominic Alvieri, @AlvieriD
December 4th, 2020.

The Cyber Show Do You Know Bitcoin Jack?
Do you know Bitcoin Jack or jack about Bitcoin? 

Porting a number is easier than you think.

The test was simple. Would a representative transfer the account?


The phone rings, "hello thank you for calling (Enter Firm Name Here) how may I help you?
Reporter, hacker, er, social engineer at this stage, " Yes this is (Enter Target Name Here) I have a problem with my phone and I need you to fix it right away.

This is not a step by step how-to but rather an important alert for all and specifically to service related security teams. A live security test. Your friend can be in attendance twenty feet away and silent as the account is transferred to a new phone in the possession of another right in front of him. 

Did you have your MFA on the same device?


 Once transferred many of the apps and accounts, if not all are in control. 



Please use 2FA tokenized preferred. Use any 2FA and MFA securely. Ideally you should separate your MFA from the main device if at all possible. If your device is ported you can still maintain your second factor security on some accounts as long as the 2FA or MFA wasn't on the same device that was just ported.

The engineer could have a baby crying in the background like in this instance. There is generally background noise. Always a sense of urgency, an impulsive need for you the agent to rectify a wrong. 

The simple ploy of a baby crying in the background can create an extra sense of urgency to rush the representative into giving away access to your account. The firm in question did not use any voice recognition technology to verify the identity on the other end of the line nor did it have any satisfactory second forms of authentication or security.



Find out how secure your accounts are.
Use a secure 2FA app and find out what other security measures are available from your account and app providers.

Simple security questions can be cracked.


In many cases , all you would need to access an account are the basics along with horrible security low marks of the last four of an account ID and a simple security question like your mothers maiden name. Plebian forms of security.  Very twentieth century if you will with the advent of biometrics, tokenization and other technologies to authenticate and secure accounts and access points.


Citibank, PayPal and others are implementing voice recognition and other technologies to authenticate and validate the identity of an account. Many firms do not at this time.




The SIM Port of it all.
Porting a number is easier than you think.


The phone is broken...


A phone account breach is the most intimate type of theft. All of your life in bits and bytes there for the taking. Every account, every moment. Now even a regular phish can expose extra hidden losses of not only digital photos and memories but any address, account or even email account linked to any digital assets may be at risk.

If your accounts and apps, let alone digital wallets do not use any added security features such as 2FA, backup keywords, tokenization of any type or any cold storage options, you can lose all of your Bitcoins tonight once I gain access to your accounts and port your number. Many of your assets.

You didn't have your MFA on the same device did you?


A security eye opener for the ill informed. Separate your 2FA and MFA on another device whenever possible.


Cold store and secure digital assets.
Cold store and secure digital assets.


What can you do?


Start with securing your accounts. Use tokenized 2FA over SMS. Try not to have your 2FA app or MFA on the same device. You can lose both with a porting. Use end to end encryption to communicate. Back up data. Use cold storage and secure apps and services from trusted sources. Biometrics, tokenization and new technologies are available.

Have private lines and back up emails for security. Layered defense is best. 

Is there a firewall on that line in the sand?


Digital currencies are coming. Many are already here. Central Banks around the world will be issuing their own versions of a Central Bank Digital Currency (CBDC) in the near future. JD.Com is the first to accept the Chinese digital currency today. The race is on. Many countries are in the process.

A CBDC will be different from the stablecoin of today. What will back the stablecoin?

A protocol is filing for a banking license?


Decentralized finance is sounding centralized when a protocol wants to file for a banking license.

The line in the sand is clear. There is no firewall. You have to defend that line. 

 



One call can lose it all.
One call can lose it all.


One call can lose it all.

Porting or transferring of ones number and account is often done off hours in the middle of the night. In many instances the account is socially engineered, stolen and transferred overnight while you are unaware and unable to reject the unwanted intrusion.

Needless to say advanced planning must be involved in targeted campaigns and targeted defense. 


Keeping your accounts securely online or offline is the difference between a secure hot and cold account. That can be the difference between red or black ink. Bread crumbs now can lead to the whole loaf if exposed.


Biometrics, MFA, secure tokenization, cold storage...



There are many different types of cryptocurrencies.
Be careful with your cryptocurrencies.


Don't just put it on the Blockchain.


If you ever hear someone say just put it on the blockchain they don't know what they are talking about. There are several types of blockchains. There are several types of cryptocurrencies. Proof of work, proof of stake, algorithms, consensus, byzantine fault tolerances, smart contracts, wrapped Bitcoin and hacked Bitcoin.
 

Databases are available online for sale. Your data. My data, It is foolish to think that it is not already in the hands of a cyber criminal right now. Secure your accounts and use backups. 



The Cyber Show on Blockchain Technology
Hyper ledgers, digital currencies, smart contracts, wrapped coins...


Call your service provider and add an extra layer of defense. In may instances your phone or financial account representative would be glad to assist you. 
 
Everything is hackable. Be skilled in defense.

Take security precautions. 



The Cyber Show by Dominic Alvieri
The Cyber Show on Google Blogger and YouTube.



Dominic Alvieri, @AlvieriD

The Cyber Show on Google Blogger, YouTube
The CyberSecurity Show. 

Thursday, November 12, 2020

Black Lives Matter campaign at Amazon.

 Amazon Corporate Hiring Policy


Black Lives do Matter, All Lives Do, with or without a felony.

By Dominic Alvieri, @AlvieriD



The Cyber Show blog on Amazon.
Black Lives Matter campaigns have been everywhere this year.
What exactly does that mean?



Amazon ran a great Black Lives Matter campaign earlier in the year. Or so we thought.
Upon further investigation it turns out that only certain lives matter, not all when it comes to corporate hiring policies.

Amazon is not alone.

How can a campaign matter if it excludes a huge portion of the population?

The largest incarcerated population in the World also has the largest felon population outside of prison seeking gainful employment. Amazon is always touting jobs but will never hire a felon.



The Cyber Show blog on Blogger, by Google.
The Cyber Show blog on Blogger, by Google.


The campaign began showing the true colors with the announcement of the Bezos Academy for underserved children. Amazon will never hire anyone who has made a mistake in the past. All lives matter but only to a point with certain companies.

What about their children?

Can the child of a felon attend the Bezos Academy Amazon?

What about working for Amazon? That is a no. Corporate policy, sorry.

Please buy from us, we support black lives. What?



CNN Report of Bezos Academy.
CNN Report of the new Bezos Academy.


With the largest incarcerated population in the World, The United States also has the largest population of released felons back into society. Amazon is constantly touting jobs and new warehouses, but the truth is they will not hire a Black, White or any color felon. Sorry, doesn't matter how long ago the crime was or even what happened. Amazon does not care what or when it was.

But you can still buy from us!

We have a policy.

Does having a policy make it right?

Amazon logo.
Amazon has a strict corporate policy.


There is a new Bezos Academy preschool, tuition free for underserved communities.
Can all black children attend, even if their mother or father has a felony record?

As of press time, Amazon has not returned a request for comment.

Corporate hiring policy is very clear...
Amazon will never hire a person with a felony record. Period.



United States of America.
Where can the largest incarcerated population work?


The jobs ordeal is continuing with politicians and wall street pushing below living wage jobs and Amazon will not even hire you. So where can they work?

The frame here is that 25 years ago you could have made a mistake and you paid your debts.
Or so you thought.

What ever happened to paying your debt to society? Amazon carries that debt forever.
Many companies and people do. 

What illegal thing have you done now? Prior felon.
What illegal things have you done in 25 years? 

Now people can do horrible things for 25 years and we elect them president.

The last three lines should make the point clear. 

Dominic Alvieri, @AlvieriD






Dominic Alvieri, @AlvieriD
Analyst, Researcher and Tracker.

Friday, November 6, 2020

SEO For Better Please, Not Worst.

 

 Susquehanna University maintains disturbing meme   Suckabanana University                 on search engines.

  By Dominic Alvieri @AlvieriD


Prestigious Susquehanna University is well above this low meme.
                           Prestigious Susquehanna University is above this meme and bad jokes.

Nestled in heart of the Susquehanna Valley in central Pennsylvania is prestigious Susquehanna University. A diamond in the valley.

Malicious memes and jokes have hidden risks finally being realized by more than just the cybersecurity industry. CNN, The New York Times and The Washington Post have been covering the events as they unfold with social media weaponization which comes through many avenues and dark alleys of the internet.

The university is well above this modern technical association of a bad joke that is now weaponized online. It readily shows up available to associate with and link via search engines to the universities website itself and separate searches of other keywords to Kappa Delta Sorority. 

As of press time no one from the university has returned multiple requests for comments.
 
 Is it just a joke? A meme? < ?>SEO_SU</?> 


The CyberSecurity Show on Blogger.
The CyberSecurity Show on Blogger


For years it has been maintained that is a joke and just a meme. Memes and jokes with undertones like this are in poor taste at the very minimum standard of decency. With modern connectivity to the internet available with nearly every device overall internet usage and abuses have been soaring during the pandemic of 2020. COVID-19, viral attacks, ransomware and social abuses online are all reaching epic proportions as we wait for final election results.

So have the dangers. 
A malicious meme or bad joke now online can reach the most innocent and at risk.

You have to break the frames and differentiate between what was shown and pushed to you and what it actually is. 

Is it a video of Alice in Milan or a manipulated image created by Bob of Alice in Minsk?
It was actually made by Trudy in Moscow and emailed to Bob in Manhattan.

That impulse reaction will engrain a lasting memory node, if you will. You will remember Alice in Milan even though it was made by Trudy in Moscow and emailed to Bob in New York City.


The CyberSecurity Show on Blogger.
The CyberSecurity Show on Blogger


You will remember the context of what was intended and it may not be the reality of the situation.

It can influence the unknowing either politically or socially and abuse and entangle you. 
It has to be addressed right now in every way, shape and form.

We are literally disconnecting from reality.

Hashtags and keywords are basically how Google, Microsoft and every search engine lets people find you, your business or your university. It does not just appear. Google and Microsoft did not place this on your site for you on their own accord without technical direction and consent. It is a created association made by you, your business, your university or the person(s) or business that is in charge of your website(s).

That goes for fraternities and sororities as well.


Fraternities and sororities need to adjust SEO.
                                         SEO for fraternities and sororities needs to improve.

What is SEO anyway?

SEO stands for Search Engine Optimization. <a>SEO_101</a>


Google and Microsoft can help you remove them if anyone is ever unsure of how to do so.

The hashtag below is displayed on GramHum which is an Instagram viewing page that displays dubious content with the following examples. The hashtags and keywords have many bad examples.

One of many found that purport this kind of activity. Is this suitable for a child? Is it suitable period? 

Susquehanna University is not involved with any of the websites, pages, hashtags or links other than the current SEO linkage to its website and domain (TLD).

This is an example of what those keywords and hashtags represent and link to.


Instagram viewing page.
Instagram viewer with few posts but dangerous content.


Notice the same post in the snapshot above and below. 
Was this created only for a political trolling campaign? 



Edited for disturbing content.
Edited for disturbing content.



If a post or tweet is added and viewed by millions to disinform or misinform and then deleted, does it count? Yes it does. You distributed non verified malicious content.

My research has shown that several sites are being maintained for years with only a few posts being counted every year. One GramHum landing page only shows 24 posts dating back since the pages inception. A tactic used during the election. Distribute it and then delete it.
 I didn't know or it was only a joke or meme is the excuse.

GranHum dotcom is registered with PorkBun LLC, a registrar of domain names that has had hundreds of reported coronavirus scam websites that it has registered this year. #CyberSecurity

This viewing page group has been placing and deleting content on various sites and show only a minimal amount of posts.


Google search snapshot.
                                 SEO is search engine optimization. Is this optimization acceptable?

The suckabanana keywords and hashtags lead to dangerous areas of the internet with undertones and deviance that many dare not fathom, let alone witness in any form.


Do you know the Banana Fungus? It is real, and bananas may not survive.



                                       Banana fungus is real. So are disturbing banana memes.



The keywords and hashtags have many hidden dark places on the internet that the university does not know about and is not related to, responsible for or associated to in any way, shape or form other than the keyword and hashtag placement for search engines. It is just the first layer of search engine optimization that someone is in control over and will rectify the situation. 

 Google will gladly be able to assist. You can probably Google it.



                                                                 Search results on Bing


The Federal Bureau of Investigation has been investigating the dark underworld of keyword and hashtag associations and leads for many years. Many lead to the dark web. Then the links and layers get deeper. The are becoming more topical and dangerously mainstream today.



Official FBI tweet.
     This is an official tweet regarding the current social media threat to children during the pandemic.


Children are our future and we need to protect them. The "suck a banana' franchise of tags and associations are being hashtagged with kid themed tags including "hard for kids" and others.

The combination of what appears to be a benign "hard for kids" hashtag that may imply a difficult math or science problem, is tagged along with deviant hashtags.

Gamers and gaming sites are another lure.  
Banana rooms and hidden areas that are clicked on may place your child in harms way with no knowledge if not monitored and aware of the dangers. 

Many memes and online distribution channels have become dangerous social weapons.

The Washington Post published an article of political memes Friday, November 6th, 2020. 
Notice the "who made this" comment. Who made it indeed. 

The internet has become weaponized, not just social media.


Dangerous memes and accounts are spreading a different kind of virus that has infected everyone who has seen any of the malicious memes, videos, posts and tweets. 


Courtesy of The Washington Post .

Several photos have shown up on both political and sexually themed sites.


Lurking with bad intent below in nefarious parts of the internet.



Disgraceful memes.
All three above are suckabana hashtag memes cropped for content.

The three links above are all associated with the suckabana franchise of keywords and tags that only gets worse if you follow the links and leads. Several variations of the hashtags and keywords exist and have multiplied at an alarming rate in 2020. 

The Pandemonium in the Pandemic.

 
Hidden banana rooms and different searches yield other nefarious lures.

Weaponizing social media is not only dangerous but it is destroying the very foundations of our democracy and lives and striking many down to the core. 
 
We all can do better. We all have to. All of US.

<p>
Veuillez ne pas sucer une banane sur votre site Web SEO. French.

Por favor, no chupes un platano en tu sito web SEO Spanish.

Molim vas, nemojte sisati bananu na svojoj web stranici SEO. Croatian.

Bitte saugen Sie keine banane auf lhrer Website SEO.. German.

Please don't suck a banana in your website SEO.
</p>

Dominic Alvieri, Analyst, researcher and tracker.


Dominic Alvieri, @AlvieriD
Analyst, Researcher and Tracker.
The Cybersecurity Show on Blogger

















Thursday, October 22, 2020

How To Spot a Troll

 Be on the lookout for Trolls.

Watch out for Trolls


With the political season in full swing and a sprint towards the end with the final debate tonight, be on the lookout for political trolls. Trolling will still be active in many different forms after the election. 

Common troll actions online or off are similar in malicious nature and one sided. Do you really think a person who will knock you over for a cab be a pleasant person online? Someone cut you off on the road and give you the finger? Very thoughtful and caring and no doubt similar in their online persona.

How about someone following you walking all the way home filming all the way to your home address and network? That actually happened to me and in the last 50 yards I turned around and let the expletives fly.  Common little items you may notice in a person can be hidden and multiplied online.

You can be trolled online and not even know it.

Many social sites let you peruse account activity without becoming a member, albeit with restricted messaging privileges. Someone can be trolling you right now as you read this.


Is this a political only account?
Is this a political action account?

Several accounts have been set up online on multiple platforms as political only accounts, meaning they only conduct self serving politics. Building followers some real and some fake along the way.
Can this action figure above be a real person or a person hiding with an ulterior motive?

Pattern analysis can define the account better than the person hiding behind the account. Patterns will reveal hashtag creations and associations that the person thinks they are masking with layers of malicious similarity. Lets get this person 10,000 followers, or attempts to attract others and link more fake accounts to show a social power and strength. 

Account layering is now becoming common practice as many bad actors attempt to gain leverage to sway and disinform. 

The new online version of the old game is now called whack a troll. They are seemingly everywhere. 

Join our cause...please.


Old account becomes active for the election
This account became active just in time for the election.


Russia and Iran have interfered to date with this current election process, as per the FBI. 
Many more attempts are likely before and during the election. This election has been the most challenging to date and no doubt foreshadows more difficulties in upcoming elections. 

Old accounts that are now becoming active are another give away. Sole purpose accounts with fake groups and followers have been proliferating online for years. Some repackaged, others retooled but all share the common traits of sole purpose posting, tweeting and blogging to attain a political goal. 

Can there be hidden financial agendas as well?

What about other hidden agendas?


New FBI warning for all.
New FBI warning.



New dangerous versions of trolls have been appearing online with different dangerous motives. One deceptive troll tactic is to fake a common friendship or association. So and so from xyz group gave me your name. Trolls come with many hidden agendas and dangerous forms. 

The FBI has recently confirmed an alarming social trend in other dangerous trolling incidents.

The time is now to be informed abut the dangers and the many different varieties of trolls online. The troll can be after your ID, finances or family. You have every right to protect yourself. You also have the right to know who and what you are protecting yourself from. The person or entity behind the actual account attempting to cause harm.

Be careful and informed of the dangers. Monitor, educate and inform. The dangers online and off never take a break and are evolving at a rapid pace. Be proactive and not reactive. 

There are new avenues of danger possible at every click, text, email or post. 

Cybersecurity Awareness Month is October. Stay safe and be cybersecurity aware everyday.


By Dominic Alvieri




@AlvieriD
Analyst, Researcher and Tracker.

Friday, September 25, 2020

Malware Literally Just Killed Someone

 

 Ransomware leads to death.    

   By Dominic Alvieri, @AlvieriD
   September 22nd, 2020.

    Did anyone notice ransomware literally just killed someone?

    

    Ransomware just got upgraded to Murderware.


Ransomware attack disabled hospital systems.



German police are treating the cybersecurity event as a homicide. A lifesaving surgery was cancelled at the last minute in Dusseldorf University Hospital on Wednesday, September 9th due to a ransomware attack on the hospital. The patient was immediately rerouted to the next hospital available about 20 miles away. The patient passed away during the ambulance trip.

The digital footprints are familiar. 


Dusseldorf University Hospital


Reports allege that the attack intended to attack a university (Heinrich Heine University) and redirected to Dusseldorf University Hospital. A woman was arriving for a lifesaving procedure when the ransomware attack took down the hospitals IT systems. 

The vulnerability in question is a Citrix VPN appliance controller. 
Chinese nationals have been employing this attack vector heavily this year. So have others.

Different motive? Different bad actor(s)? Same verdict. 

Death brings about change. Change is needed in the war on cyber crime. Ransomware is an evil business that is surging. Cyber criminals have been long overdue in facing the punishment for the true cost of their crimes. 


Ransomware leads to death in Dusseldorf, Germany on 9/9/2020


The vulnerability exploited was the  Citrix CVE 2019-19781 which is known and patches have been available. 
Dusseldorf University Hospital was not patched.

Chinese nationals have employed similar payload and encryption schemes used in this attack. 
Dusseldorf University Hospital was not the intended target. 

It is one of the first ransomware cases to be investigated as a homicide. Cyber criminals have been quietly holding systems, corporations and people in a digital stranglehold.  
Hopefully this will be the turning point. The trigger event.

Public awareness during the Covid-19 crisis must parlay into cybersecurity awareness. 
I am not convinced this will be the last death caused by ransomware, or software in general. 


Dominic Alvieri, Analyst, researcher and Tracker.






Analyst, Researcher and Tracker. @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...