12 November 2022

Corporate Australia a 'deceptive' site, really?


The claim is that the website address https://corpau.blogspot.com is deceptive in nature.

The further claim is: 

"because it may trick you into doing something dangerous like installing software or revealing personal information like revealing passwords or credit cards."

That's funny, as there are zero design elements that could carry out these tasks.

There is no facility for a person to enter passwords or credit card details like in an ecommerce site.

There are PLENTY of sites that contain virus ridden software yet they are not flagged! 

Did we piss somebody off ?

Ironically, the claim was made by "Google Safe Browsing".

08 November 2022

Smart Homes another data collection point and hack surface



Briefly: 

The Smart Cities and Smart Homes agenda is for the purpose of data collection of the corporate slaves in order to monitor their moves and later to restrict/tax them.

Another 'side effect' of this is that your internet connected devices (IoT, Internet of Things) will be hacked at some point or another in time.

The best thing you can do for your privacy is to NOT buy into this.

06 November 2022

Real Estate Group Harcourts is Australia’s Latest Company to Suffer a Data Breach


On Wednesday night, it was brought to our attention that Australian real estate company Harcourts was the latest cyber-attack victim, with the data now caught up in the breach believed to include pretty sensitive customer data.

Harcourts confirmed with Gizmodo Australia that its Melbourne City franchisee has been the victim of a “cyber-incident”.

It said that on October 24 the franchisee became aware that its rental property database had been accessed by an unknown third party without authorisation. (Each Harcourts office operates as an independent franchise with its own separate operating and IT systems.)

The rental property database holds personal information relating to landlords, tenants and trades and was used by the franchisee’s service provider, Stafflink, to provide it with administrative support.

Harcourts said that in this particular instance, the rental property database was used by a representative of Stafflink and accessed by an unknown third party.

“We understand the unauthorised access occurred because the representative of Stafflink was using their own device for work purposes rather than a company-issued (and more secure) device,” the company said, adding, “A comprehensive external investigation led by cybersecurity experts is underway but it is not yet concluded.”

According to the email shared in the tweet above, for residential rental providers and tradespeople, their full legal name, email, addresses, phone number, copy of a signature and bank details are “potentially visible” to the attackers. For renters/tenants, full legal name, email, addresses, phone number, copy of a signature AND photo ID is believed compromised.

“We understand people will be deeply concerned and upset about this data breach. I would like to offer our sincere apologies to everyone who has been inconvenienced as a result,” Harcourts Australia CEO Adrian Knowles said of the data breach.

“Dealing with this incident is our top priority. We are working together with the franchisee to ensure that all impacted individuals are advised of the incident.”

Knowles said Harcourts was in the process of establishing complimentary credit monitoring and access to the IDCARE support service for impacted individuals and he also said the organisation has “acted decisively to implement a comprehensive external investigation as well as a review of our systems and processes firm wide”.

Australia’s Privacy Commissioner has also been advised of the breach.

“This investigation is still underway and if our understanding of the impacts changes in any way we will make this clear,” Knowles added.

Interestingly, the SBS last month interviewed Harcourts, when it was discussing the potential impact a data breach could have on the real estate industry. A Harcourts spokesperson said “protections are in place” to secure customer data, adding, “Our data is encrypted by Google, so it’s got the best protection in the world”.

The Harcourts data breach is just the latest in a string of cyber incidents experienced by Australian organisations and just one of the many data breaches of 2022.

This article has been updated since it was first published.

Source:gizmodo.com.au

01 November 2022

Aqvox defrauding audiophiles with a cheap switch


MANY corporations/companies exist for the sole purpose of defrauding people of their hard earned dollars, pesos or even rubles.

Under the microscope (almost literally) is a company that trades in Germany under the internet address of aqvox.de.

The business should be shut down and under investigation of fraud.

They claim that their ~800EUR* (modified) Dlink (~22EUR) switch pumps out superior audio quality.

Upon closer inspection this proves to be a scam.

See video:


*At the time of this post 1 Euro = 1.35 Canadian Dollars.

30  CAD = 22.30 EUR, 1075 CAD = 798 EUR

31 October 2022

Delete these five apps now from your Android phone before your bank account is threatened


Unlike malicious apps that are dripping with malware making it harder to get listed in the Google Play Store (but not impossible, unfortunately), malware droppers look and act like your garden-variety apps. But when these apps notify users that an update is ready, what is really being installed is malware running in the background scooping up your banking information and other personal data.

Banking Trojans act like legit apps until you tap on the Update button



In a new blog post, Amsterdam computer support company Threat Fabric warns Android users about a new banking Trojan designed to steal your login info, account number, and other financial information that might help the attackers steal your hard-earned cash. Like the Greek's Trojan Horse, which from all appearances was a gift to the city of Troy only to be filled with Greek soldiers inside, Trojan malware ambushes users by looking like a legitimate app.


Nonetheless, the report mentions that this new banking Trojan is called Sharkbot and one malware dropper purported to be an app to help users calculate their taxes in Italy. With over 10,000 installs, "Codice Fiscale" has an innocent-looking listing in the Play Store. If opened on a device, the app checks the country where the handset's SIM is registered. If it didn't match the code for Italy, no malicious behavior would take place.

If opened on a phone using a SIM registered in Italy, the app would open a fake Play Store page with a bogus listing for "Codice Fiscale." This fake listing also revealed that an update was available for the app, something that all users would probably tap on. And while some browsers might warn the user about the update, the owner of the phone could feel comforted by the fact that the app was installed from the Google Play Store and go ahead with the update.

What was really being loaded on the phone was the aforementioned banking Trojan. And if you think that you've escaped having your personal info from your banking app stolen because you don't live in Italy, you need to think again. Another dropper app, "File Manager Small, Lite," targets banking apps used in other countries such as the U.S., U.K., Austria and Australia, Italy, Germany, Spain, and Poland.

Another banking Trojan, this one called Vultur, has been disseminated by three malware droppers also found in the Play Store: "Recover Audio, Images & Videos," "Zetter Authentication" and "My Finances Tracker." The first app listed has over 100,000 installs. Vultur keeps track of all taps and gestures made by an Android user on his/her phone. Similar to Sharkbot, this ploy uses a fake update to load the malware on a handset.

Uninstall these five apps if they have been installed on your Android phone


To combat these malware droppers, normally we'd suggest checking the comments section for red flags. However, attackers have been known to load up the comments section with fake reviews. And after the initial installation of one of these apps, you might see a fake Google Play Store listing with phony reviews in an attempt to get you to tap the update button. The victim himself is inadvertently causing the malware to load on his own phone.

ThreatFabric says that it always reports malware droppers in an attempt to have them removed from app stores. But just because an app is removed from an app store doesn't mean it has been removed from your phone. So if you have one of these installed on your device, uninstall it immediately:

  • Recover Audio, Images & Videos – 100,000 downloads
  • Codice Fiscale 2022 - 10,000 downloads
  • Zetter Authentication – 10,000 downloads
  • File Manager Small, Lite - 1,000 downloads
  • My Finances Tracker – 1,000 downloads

ThreatFabric adds, "Such way of distribution of Android banking Trojans is very dangerous as victims may stay unsuspecting for a long time and may not alert their bank about suspicious transactions made without them knowledge. Thus it is very important to take actions on the organization side to detect such malicious apps and their payloads as well as suspicious behavior happening on customer’s device."

Source:phonearena.com

29 October 2022

Data breaches so last millennium, what’s next on the agenda?


Data breaches have been going on since the beginning of the internet.

MANY corporations have been hiding their data breach not only from the public but also from their ‘stakeholders’ in attempts to give the false impression that the data held on their computer systems is safe, so that they would not suffer financial loss if stakeholders or customers would find out.

It is only in recent times that the breaches have been documented in the public news media, where the commoners have been made aware of this as a result of new disclosure law in place

In Australia it is mandatory for corporations to disclose a data breach as soon as they are aware of it, despite this many still do no follow the law.

Does the government fine them?

Is this another deliberately set up ‘toothless’ watchdog in order to deceive the taxpayers that something is done for their good?

The next major ‘hacking’ or rather unlawful / unauthorised entry into systems event is coming up that being into IoT (Internet of Things) devices.

The push now is for consumers to have ‘everything’ connected to the internet, obviously for their benefit and not more data collection right?

From toasters, fridges why not kettles or even USB powered coffee mug warmers, or even your shoe laces, the ‘Internet of Things’ is growing exponentially, where those devices are (deliberately?) insecure and therefore a disaster is in the making.

See video:


Could someone override your IoT connected kettle's tempereature shut off sensor and start a fire in your home?


28 October 2022

Australia’s crime: not allowing UN inspectors in on Human Rights abuse


The colony called Australia is a crime scene.

The colonialists in office have been misbehaving since the 1800’s where the imperial government had enough of the ‘rascals and outlaws’ (in office) and installed the Colonial Laws Validity Act in 1865.

That didn’t deter the scoundrels in government where the democratic process of law making was removed in the land of the Queen, ie Queensland unconstitutionally in 1922, with the removal of the ‘upper house’ even though it was against the referendum result.

What did people do about it? Nothing.

Australia or rather the people in this machine we call the ‘Australian Government’ are human rights abusers, where they ‘just’ have to be caught out, that’s all.

So. the UN came knocking on the colony’s doors, where they were forbidden entry to certain premises where human rights abuse was taking place.

That action is a (Commonwealth)  criminal offence.

In front of the world stage, what’s going to be done about it?

Most likely nothing.

That’s life in a (penal) colony.

27 October 2022

Apps contribute to loss of privacy

Corporations want or rather need you to use their apps that connect to their services instead of using a browser on a personal computer or even a smart phone.

Apps give developers/corporations access to you data that a browser, even on a smartphone does not.

This is a contribution to your loss of privacy.

MANY people are deliberately ignorant of the dangers using Apple or Google smart phones which are ‘deliberate by design’ data sieves.

If you value your privacy, we do not recommend using Apple products nor Google Android OEM smartphones.

Data ‘hacks’ or privacy breaches have been going on since day dot of the internet, but it is only in recent years that this information is being proliferated by the mainstream media into the awareness of the commoner, the serfs the dalits.

Speaking of which one of the world’s largest scamming nations is India, but that is a topic for another day.

If you do not participate in ‘purchasing’ (at $0 to you, where your data is the price you really pay) their business plan to support the app is no longer financially viable.

At the end of the day, is ignorance really bliss?

24 October 2022

Medibank hack: what do we know about the data breach, and who is at risk?

It is thought someone gained access to the insurer’s systems using fake or compromised credentials to steal customer data, including medical information

Medibank has said hackers had contacted the company ‘negotiate’ over 200 gigabytes of customer data. Photograph: Bianca de Marchi/AAP

A major cybersecurity incident has occurred at Medibank Private just weeks after one-third of Australians had their information held to ransom in the Optus data breach.

As one of Australia’s biggest health insurance providers, Medibank holds information that includes intimate medical records, making the breach orders of magnitude more serious than the Optus hack.

There was another data breach earlier this week of the online wine retailer Vinomofo, which led to the records of 700,000 users being sold on a Russian-language cybercriminal forum.

In the wake of the Medibank breach, the cybersecurity minister, Clare O’Neil, warned of a new world “under relentless cyber-attack”, while Australia’s security agencies scrambled to manage the fallout.

Here is what we know so far about the data breach.

What happened?

On 13 October, Medibank said it had taken offline the data and policy systems of its budget provider, ahm, and its international student division after a “cyber incident”. The next day the company announced it had restored systems and said it was “still responding” to the incident.

The situation developed on Wednesday when Medibank disclosed to the Australian stock exchange that hackers had contacted the company to “negotiate” over the future of 200 gigabytes of customer data they said had been stolen from company systems.

Although Medibank initially claimed there was “no evidence that customer data has been accessed”, the public learned the scale of the breach on Thursday as the Australian Signals Directorate and the Australian federal police started to investigate.

How did the attack occur?

Medibank is understood to still be investigating but it is thought someone gained access using fake or compromised user credentials.

What do we know about what was taken?

The hacker shared a sample of 100 policies for verification. This information contained names, addresses, dates of birth, Medicare numbers, phone numbers and medical claims data – including information about diagnoses, procedures and the location of medical services.

In a statement the insurer said the hacker also claimed to hold credit card information, but this has not been confirmed. The sample is believed to come from ahm and contain information about international students who were policyholders.

How many people does it affect?

Medibank has about 4 million customers but it is not known at this stage how many were caught in the breach.

Who is at risk?

So far it has been confirmed international students have been affected, since private health insurance is a requirement when they come to study in Australia. This is concerning as many students have moved from countries where their medical information could be used against them.

Anyone who holds a policy with Medibank should be on notice. Nine newspapers reported the hackers have threatened to release the information of the 1,000 most high-profile Australians if their demands are not met.

What does the company say?

Medibank’s chief executive David Koczkar has “unreservedly” apologised for the breach.

“I apologise and understand this latest distressing update will concern our customers,” he said. “We have always said that we will prioritise responding to this matter as transparently as possible.

“Our team has been working around the clock since we first discovered the unusual activity on our systems, and we will not stop doing that now. We will learn from this incident and will share our learnings with others.”

What does the government say?

Speaking to the ABC on Thursday morning, O’Neil warned Australians of more attacks in the future.

“This is the new world that we live in,” she said. “We are going to be under relentless cyber-attack, essentially from here on in. And what it means is that we need to do a lot better as a country to make sure that we are doing everything we can within organisations to protect customer data, and also for citizens to be doing everything that they can.”

O’Neil said the Medibank and Optus breaches amounted to a “huge wake-up call” that showed the need for an overhaul of information and privacy protections.

What can you do if you’re affected?

It is difficult for an individual person to respond to a data breach of this size and scale. Criminals will typically use this information to take out fake loans or use credit card information to make purchases. To manage this risk people can contact Equifax for credit monitoring and replace credit cards.

Other risks can be managed by reviewing security settings on social media platforms, closing old and unused accounts and being careful about what is posted. This prevents criminals from gleaning contextual information.

Source:TheGuardian