dubbel · @dubbel
130 followers · 291 posts · Server mstdn.io

On the way to the (Anti-Phishing Working Group) conference in Dublin to talk about .

Pretty excited, as this is my first in-person talk ever since the pandemic started. :)

apwg.eu/event/tech2023/

#apwg #tech2023 #rdap

Last updated 1 year ago

beSpacific · @bespacific
271 followers · 436 posts · Server newsie.social

Reported have quintupled. The third quarter of 2022, Anti Phishing Working Group observed 1,270,883 total phishing attacks — is the worst quarter for phishing that APWG has ever observed. The total for August 2022 was 430,141 phishing sites, the highest monthly total ever reported to . helpnetsecurity.com/2022/12/28

#phishing #attacks #apwg #cybercrime #cybersecurity

Last updated 2 years ago

The comments on the FTC proposed rule are posted. As a board member, I signed off on these.

In their comment, APWG concentrated on two issues:

1) WHOIS information is vital to the investigation of impersonation scams. The final rule should recognize the now acute issue of domain name registration data (“WHOIS”). While WHOIS data is critical to investigatory capability as it relates to online impersonation and crime, it unfortunately has been significantly truncated since the misinterpretation and over-implementation of the European Union’s General Data Protection Regulation (GDPR) by domain name registries and registrars. This underlines why a final rule is critically needed.

2) Trusted Notifiers are effective tools in impersonation mitigation. FTC should encourage the use of trusted notifier programs by registries and registrars as an avenue to address maliciously registered domain names, and should further encourage participation in trusted notifier programs by business or governmental entities that frequently are impersonated.

My $.02 Trusted Notifier (TN) programs will be essential to mitigating cybercrime but these cannot be left to to define for many reasons, but most importantly, because ICANN's scope is limited to domain names, and having non-federated, individually scoped programs is a terribad idea.

Proposed rule: regulations.gov/document/FTC-2

APWG Comment: regulations.gov/comment/FTC-20

#apwg #icann #whois #cybercrime #fraud #phishing

Last updated 2 years ago

comments on the FTC's proposed rule Trade Regulation Rule on Impersonation of Government and Businesses is available. I was one of the contributors to the comment.

In the comment, M3AAWG "suggests additional regulatory solutions and best practices to complement the goals of this rule, such as clarifying the scope of the rule to include the use of domain names in impersonation schemes and the use of technologies that enable impersonation" and the important role that Whois plays in investigating impersonation and fraud.

Several reports that my Interisle colleagues and I published are cited in the comment, along with the 2022 DNS Abuse Study Commissioned by the European Commission, which also quotes from our studies. Statistics generated from data collected at our Cybercrime Information Center project, cybercrimeinfocenter.org are cited as well.

The and Coalition for a Secure and Transparent Internet () also submitted comments with similar observations and support for regulation. I'll share those links when I receive them.

can effect change

Proposed Rule: federalregister.gov/documents/
Comment: m3aawg.org/sites/default/files

#m3aawg #phishing #apwg #csti #infosec

Last updated 2 years ago

comments on the FTC's proposed rule Trade Regulation Rule on Impersonation of Government and Businesses is available. I was one of the contributors to the comment.

In the comment, M3AAWG "suggests additional regulatory solutions and best practices to complement the goals of this rule, such as clarifying the scope of the rule to include the use of domain names in impersonation schemes and the use of technologies that enable impersonation" and the important role that Whois plays in investigating impersonation and fraud.

Several reports that my Interisle colleagues and I published are cited in the comment, along with the 2022 DNS Abuse Study Commissioned by the European Commission, which also quotes from our studies. Statistics generated from data collected at our Cybercrime Information Center project, cybercrimeinfocenter.org are cited as well.

The and Coalition for a Secure and Transparent Internet () also submitted comments with similar observations and support for regulation. I'll share those links when I receive them.

can effect change

Proposed Rule: federalregister.gov/documents/
Comment: m3aawg.org/sites/default/files

#m3aawg #phishing #apwg #csti #infosec

Last updated 2 years ago

I'll be giving a virtual presentation on Thursday 1 December at eCrime 2022 titled, The Need for Clarity, Accuracy and Rigor When Reporting Cybercrime Statistics. We'll discuss how the lack of taxonomic conventions affects measurements and comparisons across studies.

apwg.org/event/ecrime2022/

I'll share the presentation on Friday.

#apwg #phishing #malware #spam

Last updated 2 years ago

Proud to announce that tomorrow I'll be presenting my work (coauthored with @securescientist) titled:
THREAT/crawl - a Trainable, Highly Reusable, and Extensible Automated Method and Tool to Crawl Criminal Underground Forums
at the AWPG eCrime 2022 online conference!

📄​ Link to the paper 📄
michelecampobasso.github.io/as

⬇️​ Link to the event ⬇️​
apwg.org/event/ecrime2022/

 

#ecrime #apwg #crawler #cybercrime #underground #monitoring #infosec #security #cybersecurity

Last updated 2 years ago

Proud to announce that tomorrow I'll be presenting my work (coauthored with @securescientist) titled:
THREAT/crawl - a Trainable, Highly Reusable, and Extensible Automated Method and Tool to Crawl Criminal Underground Forums
at the AWPG eCrime 2022 online conference!

⬇️​ Link to the event ⬇️​
apwg.org/event/ecrime2022/

 

#ecrime #apwg #crawler #cybercrime #underground #monitoring #infosec #security #cybersecurity

Last updated 2 years ago

I'll be giving a talk and leading a panel at the eCrime 2022 virtual event on December 1.

Title: The Need for Clarity, Accuracy and Rigor When Reporting Cybercrime Statistics: How DNS and Other Abuse Statistics Can Mislead in the Absence of Conventions for Categorizing Cyber Events

apwg.org/event/ecrime2022/

#apwg #cybercrime #phishing #malware #dns

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online