<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Cyber Crime by Abdul Osman</title>
      <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c</link>
      <description></description>
      <language>en-us</language>
      <pubDate>2024-03-02 06:57:49 UTC</pubDate>
      <lastBuildDate>2024-03-06 00:10:35 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>AlphaBay</title>
         <author>abdulkareemosman330</author>
         <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2902704294</link>
         <description><![CDATA[<p>Alpha bay is known as one of the most notorious facilitators of illegal drugs, firearms, stolen data, and counterfeit goods. This eBay of illegal goods was established in 2014 by someone who goes by the alias Alpha02. Like others, this darknet Marketplace operated on the tor browser for buyers and sellers to use anonymously.&nbsp;</p><p>&nbsp;</p><p>Darknet markets primarily use cryptocurrencies as the preferred method of payment due to their pseudonymous and decentralized nature, which provides a level of anonymity to both buyers and sellers. Bitcoin was the most accepted cryptocurrency on darknet markets for many years.&nbsp;</p><p>&nbsp;</p><p>So what exactly was being traded on this site? a wide range of listings, including drugs (such as cocaine, heroin, and prescription medications), hacking tools, stolen financial information, counterfeit currency, weapons, and more. The platform utilized an escrow system, where funds were held by Alpha Bay until buyers confirmed receipt of their orders, providing a layer of security for transactions.&nbsp;<br>&nbsp;</p><p>Alpha Bay attracted a large volume of customers and buyers from around the globe. Its extensive catalogue and user-friendly interface contributed to its popularity among people wanting to break the law.&nbsp;</p><p>&nbsp;</p><p>Alpha bay was shut down in July 2017 by law enforcement agencies in a coordinated international operation involving authorities from the United States of America, Canada, and Thailand. Following the shutdown came the death of the founder of Alpha bay, Alexandre Cazes who was arrested in Thailand, shortly after his arrest, Cazes was found dead in his cell, reportedly by suicide. &nbsp;<br>&nbsp;<br>&nbsp;</p><p>Although the takedown of Alpha bay was a significant blow to the darknet marketplace ecosystem, It led to the migration of users to other darknet markets. &nbsp;<br>&nbsp;</p><p>“cut off one head and two will take its place” 4 years after the shutdown of Alpha bay someone that went by DE Snake claimed that they were a co-founder of Alpha Bay and they were unscathed by the attack on Alpha Bay. They had communicated with blogs via encrypted messages &nbsp; to publicize the comeback of alpha bay. Although they aren't as prominent as they used to be, it goes to show that you can't really stop drug crypto markets.&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p><p>Following the shutdown of Alpha Bay, law enforcement agencies continued their efforts to target other dark web markets and illicit activities online. While Alpha Bay no longer operates, other darknet marketplaces have emerged to fill the void left by its absence, indicating the persistent challenge of combating illegal activities on the dark web.&nbsp;</p>]]></description>
         <enclosure url="https://www.youtube.com/watch?v=FgDcPutIK7k" />
         <pubDate>2024-03-02 10:02:13 UTC</pubDate>
         <guid>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2902704294</guid>
      </item>
      <item>
         <title>Equifax</title>
         <author>abdulkareemosman330</author>
         <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2903247933</link>
         <description><![CDATA[<p>Equifax was a leading credit report agency that fell victim to one of the biggest data breaches in history, which compromised the foundation of trust in data security and privacy. In 2017, cyber criminals capitalized on vulnerabilities within Equifax's systems, compromising the personal information of approximately 1<a rel="noopener noreferrer nofollow" href="https://archive.epic.org/privacy/data-breach/equifax/">47 million individuals in the united states and an unreported sum of individuals in Canada too.</a> This breach emphasized the grave consequences of cybercrime and highlighted the critical need for  fortified cybersecurity measures in the digital age.</p><p><br/></p><p>The attackers of the Equifax gained unauthorized access to an abundance of sensitive data including, names, Social Security numbers, birth dates, addresses, and even drivers license numbers and credit card information.</p><p><br/></p><p>The scale of the Equifax breach was staggering, affecting millions of individuals and exposing them to the risk of identity theft, financial fraud, and other forms of cyber exploitation. The compromised information provided cybercriminals with the means to perform a wide range of fraudulent activities, posing significant risks for affected individuals and organizations too. </p><p><br/></p><p>In the aftermath of the breach, Equifax faced intense public pressure, drawing criticism for its handling of the incident and  flaws in its cybersecurity practices. The company's response, including delays in disclosing the breach and the lack of transparency, tarnished trust in Equifax and the broader credit reporting industry, leading to calls for stronger regulatory oversight and accountability.</p><p><br/></p><p>The Equifax hack served as a wake up call for business and policymakers, highlighting the urgency of prioritizing cybersecurity and data protection measures. It underscored the need for proactive strategies to safeguard sensitive information and neutralize the risks posed by cyber threats. Despite the measures taken in response to the breach, the incident also emphasized the persistent challenges posed by cybercrime and the evolving nature of cyber threats in an increasingly digital world.</p><p><br/></p><p>In the wake of the Equifax breach, efforts to enhance cybersecurity defenses and combat cybercrime have increased. Governments, businesses, and cybersecurity experts continue to work together to strengthen defenses, improve incident response, and raise awareness about the importance of cybersecurity. While the Equifax breach was a historic moment in the fight against cyber threats, it also highlighted the ongoing need for innovation and collaboration  to safeguard against future breaches and protect individuals privacy and security in the digital age.</p>]]></description>
         <enclosure url="" />
         <pubDate>2024-03-03 12:00:08 UTC</pubDate>
         <guid>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2903247933</guid>
      </item>
      <item>
         <title>Podesta phishing incident</title>
         <author>abdulkareemosman330</author>
         <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2904236739</link>
         <description><![CDATA[<p>The Podesta phishing incident during the 2016 U.S. presidential election campaign was a wake-up call for the importance of cybersecurity in political campaigns. John Podesta, head of Hillary Clinton's campaign, got tricked by a fake email asking him to change his password. This kind of deception&nbsp;is called social engineering, where attackers manipulate people into giving away their sensitive information.&nbsp;</p><p>&nbsp;</p><p>Phishing is an attempt to steal one's sensitive information in the form of credit card numbers, usernames, passwords, and bank account information by pretending to be a reputable source such as amazon or Aus post and creating a problem that will make the reader anxious which will make them more likely to accept the phishers “solution”. A phishing attacker takes advantage of the victim's vulnerability and lures them in, Similar to how a fisherman uses bait to catch a fish, hence the name phishing.&nbsp;</p><p>&nbsp;&nbsp;</p><p>The attack on Podesta's email showed how vulnerable political campaigns can be to cyber threats. It highlighted the need for better training to recognize phishing attempts. If Podesta and his team were trained better, they might have spotted the fake email and avoided the breach.&nbsp;</p><p>&nbsp;&nbsp;</p><p>Another lesson from the Podesta incident is the importance of using multi-factor authentication (MFA). MFA adds an extra layer of security by requiring more than just a password to access an account. If Podesta had MFA enabled, even if his password was compromised, the attackers would have found it much harder to get into his account.&nbsp;</p><p>&nbsp;&nbsp;</p><p>The response to the Podesta incident revealed weaknesses in how political campaigns handle cybersecurity. Instead of being proactive and preventing breaches, campaigns often wait until something bad happens before acting. This delayed approach leaves them vulnerable to attacks.&nbsp;</p><p>&nbsp;&nbsp;</p><p>Some critics argue that the response to the Podesta incident was too slow and didn't address the underlying issues. They say that campaigns need to do more to protect themselves from cyber threats, including investing in better security measures and training for staff.&nbsp;</p><p>&nbsp;&nbsp;</p><p>The Podesta incident also raised concerns about foreign interference in elections. U.S. intelligence agencies believe that the attackers were linked to Russia, raising questions about the role of foreign governments in cyber-attacks on political targets.&nbsp;</p><p>&nbsp;&nbsp;</p><p>In summary, the Podesta phishing incident serves as a reminder of the importance of cybersecurity in political campaigns. By learning from this incident and taking steps to improve cybersecurity practices, campaigns can better protect themselves from cyber threats in the future.&nbsp;</p>]]></description>
         <enclosure url="https://www.youtube.com/watch?v=WWAjDuDF5oA" />
         <pubDate>2024-03-04 09:58:46 UTC</pubDate>
         <guid>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2904236739</guid>
      </item>
      <item>
         <title>WannaCry ransomware</title>
         <author>abdulkareemosman330</author>
         <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2906345805</link>
         <description><![CDATA[<p>Ransomware is a type of malicious software designed to encrypt files on a victim's computer. This makes them inaccessible until a ransom is paid. Ransomware is typically spread through phishing emails and untrusted websites. Once infected, users receive a ransom demanding them to pay a sum of money, usually by cryptocurrency, to regain access to their files via a decryption key. Ransomware attacks could possibly lead to data loss, financial loss, and reputational damage. &nbsp;</p><p>&nbsp;</p><p>One of the most famous ransomware attacks in history is the WannaCry ransomware attack. This attack targeted computers running Microsoft windows, exploiting vulnerabilities in the window server message block protocol. The ransomware spread rapidly across networks, infecting hundreds of thousands of computers in over 150 countries within days.&nbsp;</p><p>&nbsp;</p><p>Ransomware attacks like WannaCry have a significant impact not only within the digital realm but also in the physical world,&nbsp;although ransomware is cyber-dependant. While the initial infection and encryption of files occur within digital systems, the consequences extend far beyond the digital space. For example, in the case of WannaCry, disruptions in healthcare impacted patient care and safety.&nbsp;</p><p>&nbsp;</p><p>The WannaCry attack had a profound impact on many institutions such as healthcare, finance, and government. Hospitals and healthcare facilities were particularly affected, with some forced to cancel surgeries and divert patients due to compromised computer systems. Financial institutions also faced operational disruptions, posing risks to financial stability and customer data.&nbsp;</p><p>&nbsp;&nbsp;</p><p>The perpetrators behind the WannaCry ransomware attack have not been definitively identified. However, cybersecurity experts have linked the attack to the North Korean government-sponsored hacking group known as Lazarus Group.&nbsp;</p><p>&nbsp;</p><p>The attack highlighted critical lessons in cybersecurity. First and foremost, it demonstrated the importance of patch management. The attack exploited a known vulnerability for which a security patch had been available months prior. Organizations that had failed to apply the necessary patches left themselves open to such threats. This strengthens the need for timely patching and software updates to reduce the risk of cyberattacks.&nbsp;</p><p>&nbsp;</p><p>Also, the WannaCry attack highlighted the importance of backup and recovery procedures. Many organizations affected by the attack found themselves unable to recover their encrypted data, leading to significant disruptions in business operations. Implementing comprehensive backup and recovery strategies is necessary to ensure that data can be restored in the event of a ransomware attack.&nbsp;</p><p>&nbsp;</p><p>The WannaCry attack also demonstrated the importance of collaboration among nations to respond to cyberthreats. Governments, cybersecurity institutions, and law enforcement agencies collaborated to contain the spread of the ransomware and weaken its impact. This played a vital role in confronting the attack and preventing further harm.&nbsp;</p><p>&nbsp;</p><p>&nbsp;</p><p>In conclusion, the WannaCry ransomware attack was a wake-up call for the cybersecurity community, highlighting the importance of preparedness in facing the evolving threat of cybercrime. Although WannaCry is still active in today's world, we have adapted and provided solutions to mitigate its effects. &nbsp;</p>]]></description>
         <enclosure url="https://www.youtube.com/watch?v=jivRCrm4jSw" />
         <pubDate>2024-03-05 14:19:50 UTC</pubDate>
         <guid>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2906345805</guid>
      </item>
      <item>
         <title>Dyn DDoS </title>
         <author>abdulkareemosman330</author>
         <link>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2907061041</link>
         <description><![CDATA[<p>A distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the functioning of a targeted server, network, or service by overwhelming it with a flood of traffic. The goal of a ddos attack is to render a website or online service unusable to users by flooding it with an excessive amount of traffic from multiple sources, which uses up all of its resources and bandwidth. Ddosing can also occur in smaller scales as I have encountered people on video games who use this technique to ruin the fun.&nbsp;</p><p>&nbsp;</p><p>One of the more notable DDos incident was the attack on Dyn, which is a DNS provider that gives URLS their unique domain name. In October 2016, attackers disrupted access to several well-known websites and services, including twitter, Netflix, PayPal, Spotify, and reddit. &nbsp;</p><p>&nbsp;</p><p>The attackers were successful by utilizing a botnet called Mirai, which compromised devices that had internet with malware, such as webcams, routers, and digital recorders. &nbsp;</p><p>&nbsp;</p><p>The Dyn Ddos attack received a lot of attention due to its disruptive impact. It highlighted the vulnerability of critical internet infrastructure to DDoS attacks and raised awareness about the security risks associated with insecure internet technology devices.&nbsp;</p><p>&nbsp;</p><p>Following the incident, there was a call for organizations to enhance their cybersecurity defences and address vulnerabilities in such devices. It also led to increased collaboration among internet service providers, technology companies, and law enforcement agencies to prevent similar attacks in the future.&nbsp;</p>]]></description>
         <enclosure url="https://padlet.pics/1/proxy?url=https%3A%2F%2Fimgs.search.brave.com%2FAFBGgljYM5NO4_yqcGh6mhnvxzALmh1MPQaZj7kQ528%2Frs%3Afit%3A200%3A200%3A1%2Fg%3Ace%2FaHR0cHM6Ly9pLnl0%2FaW1nLmNvbS92aS9M%2FZXVtdTE3RGhhSS9t%2FYXhyZXNkZWZhdWx0%2FLmpwZw" />
         <pubDate>2024-03-06 00:10:35 UTC</pubDate>
         <guid>https://padlet.com/abdulkareemosman330/i3q28frtm5e3a26c/wish/2907061041</guid>
      </item>
   </channel>
</rss>
