• Latest
  • Trending
  • All
Fake government procurement websites, protect Ring surveillance cameras, a production company hacked and more

Fake government procurement websites, protect Ring surveillance cameras, a production company hacked and more

December 16, 2019
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
LATAM Cargo strengthens European cargo links

LATAM Cargo strengthens European cargo links

April 14, 2020
Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

Ford making reusable hospital gowns from airbag materials as efforts against coronavirus expand

April 14, 2020
Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

Don’t Sweat NBC’s Decision to Cut Back on Television Ad Inventory

April 14, 2020
Software firms sharpen focus on AI, big data as IT spending drops

Software firms sharpen focus on AI, big data as IT spending drops

April 14, 2020
Navigating turbulent times in your supply chain (TL:DR version)

Navigating turbulent times in your supply chain (TL:DR version)

April 14, 2020
Last Mile Delivery by Drones Market is Booming Worldwide

Last Mile Delivery by Drones Market is Booming Worldwide

April 14, 2020
AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

AIR CARGO MARKET SIZE, SHARE, DEMAND, TREND, LATEST INNOVATIONS & APPLICATION ANALYSIS AND INDUSTRY GROWTH FORECAST 2027 – Science In Me

April 14, 2020
Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

Wheat procurement in Patiala: 6,500 coupons issued to farmers – cities

April 14, 2020
Pandemic, Plastics And The Continuing Quest For Sustainability

Pandemic, Plastics And The Continuing Quest For Sustainability

April 14, 2020
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us
No Result
View All Result
United States International Supply Chain Commission
United States International Supply Chain Commission
Home Procurement

Fake government procurement websites, protect Ring surveillance cameras, a production company hacked and more

by usiscc
December 16, 2019
in Procurement
0
Fake government procurement websites, protect Ring surveillance cameras, a production company hacked and more
503
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Fake government procurement websites found, protect your Ring surveillance camera, a production company hacked and more

Welcome to Cyber Security Today. It’s Monday December 16th. I’m Howard Solomon, contributing reporter on cyber security for ITWorldCanada.com.

To hear the podcast, click on the arrow below:

Some group is putting a lot of effort into a sophisticated scheme for stealing login passwords and usernames of people who use government departments around the world. The particular targets are the procurement websites where governments issue notices for buying everything from desks to trucks. A security company called Anomali says it has found fake websites of Canada, the U.S., Mexico, South Africa, Sweden and Australia. Two international courier web sites are also being imitated. The scam starts with a company receiving a fake email invitation to bid on a government contract. Usually companies entitled to see offers have already registered with the government, including creating a username and password to let them log in. The email includes a link to what is supposed to be the procurement site, but instead the victim goes to a very convincing looking copy. Then the victim is given a choice of logging with email credentials from providers like Microsoft, Google and Yahoo. There are a variety of reasons why an attacker wants to steal login credentials of a business supplier. The best reason is to log in themselves and infiltrate a government department.

What makes this campaign tricky for businesses is the Internet addresses of the fake sites are also convincing. Anomali says that right now none of the fake sites are active, but that doesn’t mean they won’t be shortly. Companies that do business with governments at all levels have to make sure their purchasing staff follow rules. One is never log into a government site from a link in an email. Instead go directly to the procurement site. Depending on the government, it may also be suspicious if the site asks an employee to log in using email credentials like Microsoft Office or Gmail.

The online store of Rooster Teeth Products, which makes online video shows including Red vs Blue, has been hacked. People who bought things on or around December 2nd may have had their credit card numbers stolen because they were switched to a fake payment page.

I’ve mentioned before that the credit and debit card payment machines on gas station pumps can be hacked. Visa has just issued an alert reminding gas station owners and drivers of the threat. Companies need to make sure their systems are protected. Consumers should only use credit or debit cards with security chips in all payment machines. Or, just pay cash.

There have been a number of recent news stories about Amazon Ring Internet-connected surveillance cameras being hacked. This is especially serious if a user has a video camera inside the house. That allows the hacker to see who’s home. In one case the camera was in a youngster’s bedroom, so the parent could see and talk to their child from another part of the house. Well, the child was spooked when a stranger started talking to her. As I’ve said before, anything connected to the Internet can be a threat if it isn’t secured right. First, that means having a unique, hard to guess password for every device. Home hackers — those going after Internet-connected computers, smart speakers, TVs and surveillance cameras — will first try to break passwords using lists of stolen passwords and commonly used passwords. Like “password.” Second, if the device offers two-factor authentication for extra login security, use it. The Amazon Ring system offers it. When deciding which smart device to buy for your home consider whether it offers two-factor authentication.

Speaking of two-factor authentication, Mozilla, which is behind the Firefox browser, will soon force developers of add-on applications to enable two-factor login authentication for their accounts. Browser add-ons or extensions can help make skimming through the Internet easier. They are useful things like password managers, spell checkers, PDF readers as well as fun additions to games. But for hackers extensions can also be a way into millions of computers if they can compromise an app. Then anyone who downloads the app or updates it is stung. It’s happened already to developers of Chrome extensions. Making developers use two-factor authentication will make it harder for hackers to use this trick to get into your computer.

Finally, are you a WordPress administrator whose site uses the Ultimate Addons for Beaver Builder or Ultimate Addons for Elemenator? If so, make sure you update to the latest versions. They close a serious vulnerability.

That’s it for Cyber Security Today. Links to details about these stories can be found in the text version of each podcast at ITWorldCanada.com. That’s where you’ll also find my news stories aimed at businesses and cyber security professionals. Cyber Security Today can be heard on Mondays, Wednesdays and Fridays. Subscribe on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker. Thanks for listening. I’m Howard Solomon.


Related Download
Cybersecurity Conversations with your Board Sponsor: CanadianCIO


Cybersecurity Conversations with your Board – A Survival Guide

A SURVIVAL GUIDE BY CLAUDIO SILVESTRI, VICE-PRESIDENT AND CIO, NAV CANADA
Download Now

Share201Tweet126
usiscc

usiscc

  • Trending
  • Comments
  • Latest
Escape From Tarkov – How to Rotate Items

Escape From Tarkov – How to Rotate Items

February 5, 2020
Supply chain examination: Planning for vulnerabilities you can’t control

Supply chain examination: Planning for vulnerabilities you can’t control

December 7, 2019
Procurement Project Manager job with Camden London Borough Council

Procurement Project Manager job with Camden London Borough Council

February 17, 2020
Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

Art Battle Wichita Falls III at The Warehouse, 1401 Lamar.

0
Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

Global Industry Analysis, Size, Share, Growth, Trends, and Forecasts 2016–2024 – ZMR News Reports

0
PHOTOS: Ottawa firefighters respond to warehouse fire

PHOTOS: Ottawa firefighters respond to warehouse fire

0
Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

Last Mile Delivery Market Worth Observing Growth | UPS, FedEx, SF Express

April 23, 2024
Top 5 Spend Analysis Software ranked in 2024

Top 5 Spend Analysis Software ranked in 2024

March 1, 2024
How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

How Tesla And BMW Are Leading A Supply Chain Renaissance With Blockchain

January 19, 2024
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • DMCA
  • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT
No Result
View All Result
  • Supply Chain
  • Logistics
  • Warehousing
  • Procurement
  • Shipping
  • More
    • Strategic Sourcing
    • Spend Analysis
    • Inventory
    • Contact Us

Copyright © 2024 United States International Supply Chain Commission (usiscc.org)