Tuesday, July 12, 2011

Complete DHS Daily Report for July 12, 2011

Daily Report

Top Stories

• Severe thunderstorms hit the Chicago, Illinois area July 11, shutting down train service, canceling hundreds of flights, and knocking out power to more than 600,000 customers, according to the Chicago Sun-Times. (See item 25)

25. July 11, Chicago Sun-Times – (Illinois; Indiana) 615,000 without power, travel delays after storms pelt Chicago area. Severe thunderstorms swept through the Chicago, Illinois area the morning of July 11, pelting commuters rushing to get to work, and leaving more than 615,000 Commonwealth Edison customers without power. The heavy rain, hail and winds downed wires throughout Chicago, and sent trees into streets. As of 9:15 a.m, more than 615,000 ComEd customers were without power after the storms, a spokesman said. The hardest hit region was in the northern suburbs where 280,000 were without power. Flights in and out of O’Hare International Airport were experiencing 45-minute delays. More than 100 flights have been canceled, the department of aviation said. At Midway International Airport, some airlines were experiencing delays averaging 50 minutes for in and inbound flights, with 1 cancellation reported, the department said. Trains were either halted or delayed during the heavy storms, according to the Chicago Transit Authority, and Metra. On Metra, due to weather related high winds, Union Pacific North Line, Northwest Line and West Line trains were stopped the morning of July 11, a Metra spokesman said. Trains were back on the move by about 8:50 a.m. but several trains remained delayed as of 9:40 a.m. On the BNSF Railway line, trains were traveling at a reduced speed due to the winds, the Metra spokesman said. All other lines were operating normally. The CTA was honoring Metra tickets on Union Pacific trains during the delays. The CTA issued a customer alert noting all CTA trains were experiencing major delays due to the severe weather. Downed trees on tracks near the Morris station temporarily stopped Purple Line train service. Yellow Line service was also suspended. Source: http://www.suntimes.com/6455127-417/metra-trains-halted-as-heavy-storm-passes-through-chicago-area.html

• The U.S. State Department said it would seek compensation from the Syrian government after hundreds of its supporters smashed windows and scrawled graffiti at the U.S. Embassy in Damascus July 11, msnbc.com reports. (See item 45 )

45. July 11, msnbc.com, Reuters, and Associated Press – (International) Pro-Assad mob attacks US, French embassies in Syria. Syrian government supporters smashed windows at the U.S. and French embassies in Damascus July 11, raised Syrian flags, and scrawled graffiti calling the U.S. ambassador a "dog" in anger over a visit last week to an opposition stronghold. They tore down U.S. Embassy plaques and tried to break security glass, diplomats said, in an escalation of protests against the visit by the U.S. and French ambassadors to the city of Hama, which has seen demonstrations against the Syrian president. "Four buses full of shabbiha (militia loyal to Assad) came from Tartous. They used a battering ram to try to break into the main door," a resident of Afif, the old district where the U.S. Embassy is located, told Reuters by telephone. "This is a violent escalation by the regime," a Western diplomat in the Syrian capital said. "You do not bring busloads of thugs into central Damascus from the coast without its consent." After the crowd was dispersed, protesters moved to the residence of the U.S. Ambassador and attacked it, causing unspecified damage, officials said. No staff at either location were injured, and no personnel were ever in imminent danger, the officials said. French Embassy security guards fired in the air to hold back supporters of Assad's regime who were also protesting the French ambassador's visit to Hama. Protesters smashed French Embassy windows, shattered the windshield of a diplomatic SUV outside the compound and replaced the French flag with a Syrian one. The French Foreign Ministry said three embassy workers were injured. The Syrian regime called the visits to Hama interference in the country's internal affairs, and accused the ambassadors of undermining Syria's stability. The U.S. State Department July 11 condemned Syria for failing to protect the U.S. embassy. "A television station that is heavily influenced by Syrian authorities encouraged this violent demonstration," a State Department spokesperson said in a statement. "We strongly condemn the Syrian government's refusal to protect our embassy, and demand compensation for damages," the statement said. Source: http://www.msnbc.msn.com/id/43711672/ns/world_news-mideast_n_africa/?GT1=43001

Details

Banking and Finance Sector

20. July 10, Sebring News-Sun – (Florida) More than 120 victims of skimmers reported by HCSO. The Sebring News-Sun reported July 10 suspected credit card skimming activities first reported in Avon Park, Florida, have encompassed 3 counties and more than 120 victims locally, according to a spokeswoman with the Highlands County Sheriff's Office. "The Highlands County Sheriff's Office has taken 80 reports to date and estimated Friday [July 8] morning that over 100 people in Highlands County alone have been victims of credit card fraud during the recent suspected skimming activity," a press release stated. The spokeswoman later confirmed 46 more cases were reported July 8 by an undisclosed credit card company. "In all it is estimated the total claims will exceed $200,000," she said. Source: http://www.newssun.com/071011-eb-county-skimmers

21. July 9, Cincinnati Enquirer – (Ohio; Indiana) 4.5M Ponzi scheme probed. Dunhill Investment Advisers kept an office on the edge of downtown Cincinnati, Ohio, and advertised a stock trading strategy that promised profits even when the markets were down. However, investigators said most of the $4.5 million the firm was entrusted with was never invested, the Cincinnati Enquirer reported July 9. Instead, the money went to pay the salaries of the owners. After an investigation of more than a year, Indiana authorities arrested one of Dunhill’s owners, an Indiana resident, and charged him with 18 felonies, including securities fraud and theft. Another owner faces the same charges, but investigators said he has not surrendered, and they do not know where he is. Source: http://communitypress.cincinnati.com/article/AB/20110710/BIZ01/107080357/-4-5M-Ponzi-scheme-probed?odyssey=nav|head

22. July 8, Chicago Tribune – (Illinois) Defective counterfeit detector caused Bank of America fire in Loop, suit claims. A March fire at a Bank of America branch in the Loop area of Chicago, Illinois, was caused by a defective machine that is used to detect counterfeit money, Bank of America said in a lawsuit. An independent investigation by Bank of America shows the fire March 6 originated in the machine that was located at a teller window, according to the suit filed July 6 in a Chicago federal court. Bank of America is suing the counterfeit detector's manufacturer, Hilton Trading Corp., based in Miami, Florida. The bank said the fire caused about $1 million in damages. Source: http://www.chicagotribune.com/business/breaking/chi-defective-counterfeit-detector-caused-bank-of-america-fire-in-loop-suit-claims-20110708,0,3032199.story

23. July 8, Torrance Daily Breeze – (California) Gardena mortgage broker, former bank employees face charges in loan fraud. A mortgage broker from Gardena, California, and two former bank employees faced charges for their alleged involvement in a scheme in which bogus loan applications were used to con lenders out of about $4 million, prosecutors said July 8. Prosecutors allege the man and the co-conspirators obtained about $4 million from various financial institutions by lying on loan applications used to purchase homes in the names of straw buyers. Source: http://www.dailybreeze.com/news/ci_18441249

For another story see item 55 below in the Information Technology Sector

Information Technology Sector

53. July 11, Softpedia – (International) Microsoft security center search results poisoned with malicious links. Microsoft suspended the search capability on its Safety & Security Center Web site after it was discovered cyber criminals poisoned the results with malicious links. Search result poisoning, technically known as black hat search engine optimization (BHSEO), is a common method used to distribute malware or promote spam sites. The technique involves compromising legitimate Web sites and creating pages under their domain that are filled with popular search keywords. Attackers then use other hacked Web sites to link back to the pages, increasing their search result standing for the targeted terms. However, while the pages appear to have content to search engine crawlers, they are designed to redirect real visitors to malicious Web sites. According to the general manager of security software at GFI, the BHSEO campaign on Microsoft's Safety & Security Center Web site was unique. It appeared cyber criminals managed to create search results to search results. "In other words, blackhat SEOs are seeding illegimate search results within the Microsoft search results," the security expert noted. "There are a number of ways this could be done (for example, using the ability on the site to Twitter a search result)," he explained. The rogue search results on Microsoft's Security Center predominantly led to malicious adult sites which asked users to download special codecs in order to play videos. Source: http://news.softpedia.com/news/Microsoft-Security-Center-Search-Results-Poisoned-with-Malicious-Links-210836.shtml

54. July 11, IDG News Service – (International) Google+ hit with spam bug. The Google+ social networking site malfunctioned the weekend of July 9 and 10, spamming its users with repeated notifications via e-mail. Google+, which is being beta tested with a limited number of users, ran out of disk space July 9, causing the glitch, according to a Google senior vice president of engineering. "Please accept our apologies for the spam we caused this afternoon. For about 80 minutes we ran out of disk space on the service that keeps track of notifications. Hence our system continued to try sending notifications. Over, and over again. Yikes," he wrote in a Google+ post. "We didn't expect to hit these high thresholds so quickly, but we should have. Thank you for helping us during this field trial, and once again, we are very sorry for the spam," he added. Google+ is the company's latest and most high-profile attempt to date to launch a social networking service. Source: http://www.computerworld.com/s/article/9218299/Google_hit_with_spam_bug

55. July 9, Softpedia – (International) Zbot targets Android users. Security researchers identified a Zbot component designed for Android that steals mobile transaction authentication numbers sent by banks via SMS. ZeuS, or Zbot, is one of the most popular banking trojans. Zbot originally targeted desktop systems and stole financial information and online banking credentials that fraudsters exploited. However, more banks began to introduce additional layers of security, such as two-factor authentication systems. Some banks also require each transaction request to be confirmed by inputting an unique code sent to the account owner's mobile phone. These codes are known as mobile transaction authentication numbers (mTAN) and make it harder to steal money from compromised accounts. In order to continue stealing money, ZeuS fraudsters learned to capture these mTANs with the help of a man-in-the-mobile component, and social engineering. In 2010, security researchers began to discover ZeuS-related mobile malware created specifically to steal mTANs from phones running Symbian, Windows Mobile, and BlackBerry. However, a sample targeting Android devices only appeared during the past several weeks. "Actually, it is not a new sample and has been detected under several names (Android.Trojan.SmsSpy.B, Trojan-Spy.AndroidOS.Smser.a, Andr/SMSRep-B), but it is far more scary when propagated by the ZeuS gang," said a Fortinet security researcher. He said the malware poses as a banking activation application, but after it is installed, it intercepts all SMS messages and uploads them to a remote server. Source: http://news.softpedia.com/news/Zbot-Targets-Android-Users-210645.shtml

56. July 8, Computerworld – (International) Microsoft beefs up Outlook-to-Hotmail security. Microsoft July 7 boosted the security of a tool that lets Outlook users send and receive messages through the company's Web-based Hotmail service. The new Outlook Hotmail Connector supports HTTPS, a protocol that encrypts all traffic between the e-mail client and the Windows Live Hotmail service. Microsoft added an all-HTTPS option to Hotmail in November 2010, in part as a reaction to Firesheep, a Firefox add-on released October 2010 that let anyone scan an unsecured Wi-Fi network and hijack others' access to Facebook, Twitter, and a host of other services. The latest update to Outlook Hotmail Connector is a follow-up to Microsoft's 2010 move. "Using a connection with HTTPS helps you be even more confident that your account is safer from hijackers, and that your private information remains private," the Outlook team wrote. The new tool encrypts communication between Outlook and the Windows Live e-mail, calendar, and contacts services. Source: http://www.computerworld.com/s/article/9218266/Microsoft_beefs_up_Outlook_to_Hotmail_security

Communications Sector

See items 54, 55, and 56 above in the Information Technology Sector

No comments: