01 November 2022

Aqvox defrauding audiophiles with a cheap switch


MANY corporations/companies exist for the sole purpose of defrauding people of their hard earned dollars, pesos or even rubles.

Under the microscope (almost literally) is a company that trades in Germany under the internet address of aqvox.de.

The business should be shut down and under investigation of fraud.

They claim that their ~800EUR* (modified) Dlink (~22EUR) switch pumps out superior audio quality.

Upon closer inspection this proves to be a scam.

See video:


*At the time of this post 1 Euro = 1.35 Canadian Dollars.

30  CAD = 22.30 EUR, 1075 CAD = 798 EUR

31 October 2022

Delete these five apps now from your Android phone before your bank account is threatened


Unlike malicious apps that are dripping with malware making it harder to get listed in the Google Play Store (but not impossible, unfortunately), malware droppers look and act like your garden-variety apps. But when these apps notify users that an update is ready, what is really being installed is malware running in the background scooping up your banking information and other personal data.

Banking Trojans act like legit apps until you tap on the Update button



In a new blog post, Amsterdam computer support company Threat Fabric warns Android users about a new banking Trojan designed to steal your login info, account number, and other financial information that might help the attackers steal your hard-earned cash. Like the Greek's Trojan Horse, which from all appearances was a gift to the city of Troy only to be filled with Greek soldiers inside, Trojan malware ambushes users by looking like a legitimate app.


Nonetheless, the report mentions that this new banking Trojan is called Sharkbot and one malware dropper purported to be an app to help users calculate their taxes in Italy. With over 10,000 installs, "Codice Fiscale" has an innocent-looking listing in the Play Store. If opened on a device, the app checks the country where the handset's SIM is registered. If it didn't match the code for Italy, no malicious behavior would take place.

If opened on a phone using a SIM registered in Italy, the app would open a fake Play Store page with a bogus listing for "Codice Fiscale." This fake listing also revealed that an update was available for the app, something that all users would probably tap on. And while some browsers might warn the user about the update, the owner of the phone could feel comforted by the fact that the app was installed from the Google Play Store and go ahead with the update.

What was really being loaded on the phone was the aforementioned banking Trojan. And if you think that you've escaped having your personal info from your banking app stolen because you don't live in Italy, you need to think again. Another dropper app, "File Manager Small, Lite," targets banking apps used in other countries such as the U.S., U.K., Austria and Australia, Italy, Germany, Spain, and Poland.

Another banking Trojan, this one called Vultur, has been disseminated by three malware droppers also found in the Play Store: "Recover Audio, Images & Videos," "Zetter Authentication" and "My Finances Tracker." The first app listed has over 100,000 installs. Vultur keeps track of all taps and gestures made by an Android user on his/her phone. Similar to Sharkbot, this ploy uses a fake update to load the malware on a handset.

Uninstall these five apps if they have been installed on your Android phone


To combat these malware droppers, normally we'd suggest checking the comments section for red flags. However, attackers have been known to load up the comments section with fake reviews. And after the initial installation of one of these apps, you might see a fake Google Play Store listing with phony reviews in an attempt to get you to tap the update button. The victim himself is inadvertently causing the malware to load on his own phone.

ThreatFabric says that it always reports malware droppers in an attempt to have them removed from app stores. But just because an app is removed from an app store doesn't mean it has been removed from your phone. So if you have one of these installed on your device, uninstall it immediately:

  • Recover Audio, Images & Videos – 100,000 downloads
  • Codice Fiscale 2022 - 10,000 downloads
  • Zetter Authentication – 10,000 downloads
  • File Manager Small, Lite - 1,000 downloads
  • My Finances Tracker – 1,000 downloads

ThreatFabric adds, "Such way of distribution of Android banking Trojans is very dangerous as victims may stay unsuspecting for a long time and may not alert their bank about suspicious transactions made without them knowledge. Thus it is very important to take actions on the organization side to detect such malicious apps and their payloads as well as suspicious behavior happening on customer’s device."

Source:phonearena.com

29 October 2022

Data breaches so last millennium, what’s next on the agenda?


Data breaches have been going on since the beginning of the internet.

MANY corporations have been hiding their data breach not only from the public but also from their ‘stakeholders’ in attempts to give the false impression that the data held on their computer systems is safe, so that they would not suffer financial loss if stakeholders or customers would find out.

It is only in recent times that the breaches have been documented in the public news media, where the commoners have been made aware of this as a result of new disclosure law in place

In Australia it is mandatory for corporations to disclose a data breach as soon as they are aware of it, despite this many still do no follow the law.

Does the government fine them?

Is this another deliberately set up ‘toothless’ watchdog in order to deceive the taxpayers that something is done for their good?

The next major ‘hacking’ or rather unlawful / unauthorised entry into systems event is coming up that being into IoT (Internet of Things) devices.

The push now is for consumers to have ‘everything’ connected to the internet, obviously for their benefit and not more data collection right?

From toasters, fridges why not kettles or even USB powered coffee mug warmers, or even your shoe laces, the ‘Internet of Things’ is growing exponentially, where those devices are (deliberately?) insecure and therefore a disaster is in the making.

See video:


Could someone override your IoT connected kettle's tempereature shut off sensor and start a fire in your home?


28 October 2022

Australia’s crime: not allowing UN inspectors in on Human Rights abuse


The colony called Australia is a crime scene.

The colonialists in office have been misbehaving since the 1800’s where the imperial government had enough of the ‘rascals and outlaws’ (in office) and installed the Colonial Laws Validity Act in 1865.

That didn’t deter the scoundrels in government where the democratic process of law making was removed in the land of the Queen, ie Queensland unconstitutionally in 1922, with the removal of the ‘upper house’ even though it was against the referendum result.

What did people do about it? Nothing.

Australia or rather the people in this machine we call the ‘Australian Government’ are human rights abusers, where they ‘just’ have to be caught out, that’s all.

So. the UN came knocking on the colony’s doors, where they were forbidden entry to certain premises where human rights abuse was taking place.

That action is a (Commonwealth)  criminal offence.

In front of the world stage, what’s going to be done about it?

Most likely nothing.

That’s life in a (penal) colony.

27 October 2022

Apps contribute to loss of privacy

Corporations want or rather need you to use their apps that connect to their services instead of using a browser on a personal computer or even a smart phone.

Apps give developers/corporations access to you data that a browser, even on a smartphone does not.

This is a contribution to your loss of privacy.

MANY people are deliberately ignorant of the dangers using Apple or Google smart phones which are ‘deliberate by design’ data sieves.

If you value your privacy, we do not recommend using Apple products nor Google Android OEM smartphones.

Data ‘hacks’ or privacy breaches have been going on since day dot of the internet, but it is only in recent years that this information is being proliferated by the mainstream media into the awareness of the commoner, the serfs the dalits.

Speaking of which one of the world’s largest scamming nations is India, but that is a topic for another day.

If you do not participate in ‘purchasing’ (at $0 to you, where your data is the price you really pay) their business plan to support the app is no longer financially viable.

At the end of the day, is ignorance really bliss?

24 October 2022

Medibank hack: what do we know about the data breach, and who is at risk?

It is thought someone gained access to the insurer’s systems using fake or compromised credentials to steal customer data, including medical information

Medibank has said hackers had contacted the company ‘negotiate’ over 200 gigabytes of customer data. Photograph: Bianca de Marchi/AAP

A major cybersecurity incident has occurred at Medibank Private just weeks after one-third of Australians had their information held to ransom in the Optus data breach.

As one of Australia’s biggest health insurance providers, Medibank holds information that includes intimate medical records, making the breach orders of magnitude more serious than the Optus hack.

There was another data breach earlier this week of the online wine retailer Vinomofo, which led to the records of 700,000 users being sold on a Russian-language cybercriminal forum.

In the wake of the Medibank breach, the cybersecurity minister, Clare O’Neil, warned of a new world “under relentless cyber-attack”, while Australia’s security agencies scrambled to manage the fallout.

Here is what we know so far about the data breach.

What happened?

On 13 October, Medibank said it had taken offline the data and policy systems of its budget provider, ahm, and its international student division after a “cyber incident”. The next day the company announced it had restored systems and said it was “still responding” to the incident.

The situation developed on Wednesday when Medibank disclosed to the Australian stock exchange that hackers had contacted the company to “negotiate” over the future of 200 gigabytes of customer data they said had been stolen from company systems.

Although Medibank initially claimed there was “no evidence that customer data has been accessed”, the public learned the scale of the breach on Thursday as the Australian Signals Directorate and the Australian federal police started to investigate.

How did the attack occur?

Medibank is understood to still be investigating but it is thought someone gained access using fake or compromised user credentials.

What do we know about what was taken?

The hacker shared a sample of 100 policies for verification. This information contained names, addresses, dates of birth, Medicare numbers, phone numbers and medical claims data – including information about diagnoses, procedures and the location of medical services.

In a statement the insurer said the hacker also claimed to hold credit card information, but this has not been confirmed. The sample is believed to come from ahm and contain information about international students who were policyholders.

How many people does it affect?

Medibank has about 4 million customers but it is not known at this stage how many were caught in the breach.

Who is at risk?

So far it has been confirmed international students have been affected, since private health insurance is a requirement when they come to study in Australia. This is concerning as many students have moved from countries where their medical information could be used against them.

Anyone who holds a policy with Medibank should be on notice. Nine newspapers reported the hackers have threatened to release the information of the 1,000 most high-profile Australians if their demands are not met.

What does the company say?

Medibank’s chief executive David Koczkar has “unreservedly” apologised for the breach.

“I apologise and understand this latest distressing update will concern our customers,” he said. “We have always said that we will prioritise responding to this matter as transparently as possible.

“Our team has been working around the clock since we first discovered the unusual activity on our systems, and we will not stop doing that now. We will learn from this incident and will share our learnings with others.”

What does the government say?

Speaking to the ABC on Thursday morning, O’Neil warned Australians of more attacks in the future.

“This is the new world that we live in,” she said. “We are going to be under relentless cyber-attack, essentially from here on in. And what it means is that we need to do a lot better as a country to make sure that we are doing everything we can within organisations to protect customer data, and also for citizens to be doing everything that they can.”

O’Neil said the Medibank and Optus breaches amounted to a “huge wake-up call” that showed the need for an overhaul of information and privacy protections.

What can you do if you’re affected?

It is difficult for an individual person to respond to a data breach of this size and scale. Criminals will typically use this information to take out fake loans or use credit card information to make purchases. To manage this risk people can contact Equifax for credit monitoring and replace credit cards.

Other risks can be managed by reviewing security settings on social media platforms, closing old and unused accounts and being careful about what is posted. This prevents criminals from gleaning contextual information.

Source:TheGuardian

20 October 2022

Australia’s internet the joke of the I.T. world year in year out



Australia is allegedly a first world country, but third world countries are having higher internet speeds than the ‘lucky country’ or rather colony.

The British outpost has been loosing its broadband ranking year after year, where the government reported that in December of 2021 Australia’s ranking fell from 54 to 57.

This year in September the ranking fell down to 71, from the same source, that being ookla.

Australia’s a ‘money for mates’ colony, where tenders are falsified in order for the mates of those in control who set up companies that get the tenders.

Substandard contractors are then obtained to carry out the work, in whichever industry is at play, be it building, I.T. etc in the process ripping off taxpayers and customers alike.

The way Australia’s internet is going, pretty soon, Eskimos on the back of yaks will have faster internet speeds

19 October 2022

Australia's medical practitioners' fraud against taxpayers

Australia's so called 'medical professionals' have been rorting the tax payers' purse for quite some time.

What the mainstream media will not tell you is that it's gotten worse over the past few years, since the mass exodus of medical professionals due to so called government 'mandates', where as a result there has been a policy to import low quality 'yes men' as GPs etc to fill in the government created void.


16 October 2022

Woolworths says 2.2m MyDeal customers’ data hacked


In the third major corporate security breach in as many weeks, Woolworths is scrambling to contact 2.2 million customers of its MyDeal online marketplace arm whose data has been accessed by an unauthorised user using “compromised” credentials, the supermarkets giant says.

The hack follows telecoms group Optus in owning up to data breaches affecting millions of consumers. Health insurer Medibank Private also disclosed a data breach but said it had no evidence of any customer data being accessed, although it was still investigating the hack.

Woolworths said it had contacted relevant regulatory authorities and government agencies about the breach. MyDeal customers who are not contacted have not been affected, the company said. Of the 2.2 million estimated to have been affected, 1.2 million have only had their email addresses exposed.

The exposed data also includes names, phone numbers, delivery addresses and some customers’ birthdates. MyDeal does not store payment, drivers’ licence or passport details and Woolworths said no customer account passwords or payment details had been compromised.

The breach took place within the MyDeal CRM (customer relations management software) system and the MyDeal.com.au and MyDeal app had not been breached in the hack. MyDeal operates on a separate platform to Woolworths’ main platform and no Woolworths Group customers or Everyday Rewards scheme records have been compromised either.

Woolworths chief security officer Pieter van der Merwe said the group’s cybersecurity and privacy teams were “fully engaged and working closely with MyDeal to support the response”.

MyDeal chief executive Sean Senvirtne said: “We apologise for the considerable concern that this will cause our affected customers. We have acted quickly to identify and mitigate unauthorised access and have increased monitoring networks.

“We will continue to work with relevant authorities as we investigate the incident and we will keep our customers fully informed of any further updates affecting them.”

Woolworths completed the acquisition of 80 per cent of MyDeal last month for $243 million. The move is a bid to beef up its online offer. In September last year, the supermarkets giant launched its marketplace platform Everyday Market, which offers a range of goods from baby items to electronics.

Woolworths, through its 176 bricks and mortar Big W stores and supermarkets, and MyDeal, through its online marketplace, sell general merchandise including furniture, health and beauty products, homewares and electronics.

In addition to retailing their own products, Woolworths and MyDeal also operate online marketplaces where third parties sell their wares.

Of the recent spate of hacks which have heightened awareness of cybersecurity threats for businesses, the Optus hack has been the most serious with up to 9.8 million customers affected and sensitive information such as passport and drivers’ licence details compromised.

Medibank said on Friday it had restored access to services provided by its cheaper brand ahm and for international students and that it had not discovered any evidence the data of its 3.6 million members had been accessed, although a “forensic investigation will take time”.

Source: afr.com