Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # The Security Skeptic Online personna of Dave Piscitello ## Sitemaps - [XML Sitemap](https://www.securityskeptic.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Domain Name Email Verification is Contact Validation, not Authentication](https://www.securityskeptic.com/domain-name-email-verification-is-contact-validation-not-authentication/) - To comply with ICANN and European Union NIS2 requirements, gTLD domain registrars must verify registrant email addresses. This "owner email verification" process was a topic of considerable discussion prior to and during the recent ICANN meeting. ICANN is caught in a “failing to see the forest for the trees” situation: neither the findings nor the - [cURL needs your help](https://www.securityskeptic.com/curl-needs-your-help/) - If you have ever done investigations, traffic analysis, or any form of content assessment, you've no doubt used cURL Daniel Stenberg wrote recently about the challenges the cURL team face with limited budget and increasing vulnerability reporting due to LLM use. I read about this crisis and immediately donated at https://opencollective.com/curl/donate Please consider donating. #curl - [Making Waves in the Phisher’s Safest Harbor: Exposing the Dark Side of Subdomain Registries](https://www.securityskeptic.com/making-waves-in-the-phishers-safest-harbor-exposing-the-dark-side-of-subdomain-registries/) - Phishers always look for the effective ways to distribute phish email, lure victimsto scam web sites, and shield their online scams from discovery and takedown.Phishers make considerable efforts to maintain these shields, and have repeatedlyadjusted their attack methods in response to each improvement in antiphishingmeasures. Domain names have played an increasingly important role in phishingattacks - [Top 10 Phishing Scams and How to Avoid Them](https://www.securityskeptic.com/top-10-phishing-scams-and-how-to-avoid-them/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [The Evolution of Malware: What You Need to Know](https://www.securityskeptic.com/the-evolution-of-malware-what-you-need-to-know/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [Exploring the Dark Side of DNS Attacks](https://www.securityskeptic.com/exploring-the-dark-side-of-dns-attacks/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [Spam Emails: Identifying and Combating Threats](https://www.securityskeptic.com/spam-emails-identifying-and-combating-threats/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [Why Enterprise Security Can't Be Ignored](https://www.securityskeptic.com/why-enterprise-security-cant-be-ignored/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [The Hidden Costs of Cybercrime Resource Abuse](https://www.securityskeptic.com/the-hidden-costs-of-cybercrime-resource-abuse/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [Practical Internet Security Tips for Everyday Users](https://www.securityskeptic.com/practical-internet-security-tips-for-everyday-users/) - This paragraph serves as an introduction to your blog post. Begin by discussing the primary theme or topic that you plan to cover, ensuring it captures the reader’s interest from the very first sentence. Share a brief overview that highlights why this topic is important and how it can provide value. Use this space to - [Understanding Cybercriminal Tactics](https://www.securityskeptic.com/understanding-cybercriminal-tactics-to-stay-protected/) - Posts in this category examine various tactics that cybercriminals employ when perpetrating crimes. The articles listed here preserve URLs from prior hosting. Common Visual Deceptions in Phishing URLs (07/29/2025 09:50:17 AM) ## Pages - [Home](https://www.securityskeptic.com/) - The Security Skeptic Security Skeptic is an online personna of Dave Piscitello. Here, I share thoughts about Internet security, domain names (DNS), Internet numbers, routing, firewalls, endpoint and network security. I also share findings from phishing, malware, and spam research I conduct at the Cybercrime Information Center. If I live long enough, I may even - [Blog](https://www.securityskeptic.com/blog/) - #firewalls #routing #identity #management #cybersecurity #hybridwarfare#networking #logging #intrusiondetection Understanding Cybercrime Delivery Services Phishing (06/30/2025 09:44:54 AM) #socialengineering #phishing #malware #spam #hacking #botnets #cybercrime Internet Names (DNS) and Addressing Exploiting Well known TLD Strings in Domain Names (07/29/2025 09:50:17 AM) .TOP Promises to Reduce Abuse (06/06/2025 01:26:09 PM) Challenges When Measuring Criminal Abuse of ccTLD Registrars(05/06/2025 - [Remembering The Nefarious ANY](https://www.securityskeptic.com/remembering-the-nefarious-any/) - 4 May 2026 A firewall colleague and mentor, Fred Avolio, offered the most appropriate and succinct advice he was asked when during a training session, “How do you identify the exceptions?” DENY ALL… and wait for a call. Fred’s proposition was that, once a firewall admin has configured the DENY ALL outbound (egress) traffic, they’d - [Blog (2005-2009)](https://www.securityskeptic.com/blog-2005-2009/) - [Ethical Hacking could be so much more than an oxymoron](https://www.securityskeptic.com/ethical-hacking-could-be-so-much-more-than-an-oxymoron/) - 11/29/2009 12:13:28 PM Hacking generally and correctly describes the (noble) art and practice of writing software. The Jargon File defines hacking as, "engaging the act of programming enthusiastically (even obsessively)", and a hacker as, "one who enjoys programming, and is particularly good at it." For our purposes, we'll use the more accurate term cracker, "one who breaks security - [Take Stock of Endpoint and Admission Control Now](https://www.securityskeptic.com/take-stock-of-endpoint-and-admission-control-now/) - 11/29/2009 12:36:33 PM Viruses, worms, and spyware are an Internet pandemic and a major source of concern for IT organizations large and small. The financial losses that can be attributed to these kinds of attacks are considerable, especially in organizations where a Microsoft monoculture exposes both client computing devices and mission-critical servers to common attacks. - [Endpoint security and admission control: necessary but not sufficient](https://www.securityskeptic.com/endpoint-security-and-admission-control-necessary-but-not-sufficient/) - 11/29/2009 01:38:33 PM My partner Lisa Phifer and I have been evangelizing endpoint security for some time, as have many other security practitioners and companies. All you had to do to realize endpoint security would become a priority to large enterprises five years ago was listen to your clients and customers. In our case, we - [Powerline Ethernet: When WiFi won't and CAT-5 Can't](https://www.securityskeptic.com/powerline-ethernet-when-wifi-wont-and-cat-5-cant/) - 11/29/2009 06:58:49 PM Many organizations conduct a site survey prior to deploying Wireless LANs in a facility, and often discover the most appropriate access point placement is a location where they cannot provide power. Since WLAN access points must typically connect to a wired network using CAT-5, an obvious technology solution for such circumstances is - [Legislation Won't Stop the Spyware Juggernaut](https://www.securityskeptic.com/legislation-wont-stop-the-spyware-juggernaut/) - 11/29/2009 07:05:50 PM Spyware has reached such epidemic proportions that legislators in the US Congress as well as state legislatures are responding to public outrage by drafting bills to prohibit its distribution, stem abusive practices and protect Internet user privacy. Unfortunately, pending and recently enacted antispyware legislation are considerably flawed and could actually cause more - [Care and Handling of Credit and Personal Information](https://www.securityskeptic.com/care-and-handling-of-credit-and-personal-information/) - 11/30/2009 08:48:49 AM Despite the real and present dangers identity theft, Phishing and email scam attacks pose, we cannot afford to overlook measures we can take to protect our identities and credit from attacks in the real (physical) world. Financial institutions, law enforcement agencies and attorneys recommend a number of ways you can protect against - [What's The Difference Between Spyware And Viruses?](https://www.securityskeptic.com/whats-the-difference-between-spyware-and-viruses/) - 11/30/2009 10:14:10 AM The average Internet user has difficulty distinguishing viruses from spyware. The differences are indeed subtle. Both are malicious software (malware): uninvited, intrusive, and potentially destructive. Both have the capacity to capture and destroy information, ruin performance, and disrupt business. Viruses and spyware programs are delivered via web visits and downloads, as well - [Is security freeware more or less than you pay for?](https://www.securityskeptic.com/is-security-freeware-more-or-less-than-you-pay-for/) - 11/30/2009 12:32:05 PM Begin a search of "security freeware" and you'll find everything from scanners, LAN analyzers, network mapping and network forensic tools to firewalls, vulnerability assessment software, IDS, and log analysis tools. The price is right and everyone needs more security. What's the catch? Is the Software Truly Secure and Free? I download, install, - [Redirection and Synthesized DNS responses do more harm than good](https://www.securityskeptic.com/redirection-and-synthesized-dns-responses-do-more-harm-than-good/) - 12/01/2009 10:23:13 AM This is a revision to an article originally published in January 2008. Many PC and Internet users are familiar with the concept of a wildcard symbol. From a DOS command window, type "dir *.exe" and MS-DOS will display all the files of type "executable" in the current directory. MAC OS X users can - [Web Application Code is Part of Your Security Perimeter](https://www.securityskeptic.com/web-application-code-is-part-of-your-security-perimeter/) - 12/01/2009 11:20:58 AM This is a revision to an article published January 2008 At first glance, this statement must clearly be an oxymoron (think jumbo shrimp), and you might question the sanity of the folks at The Open Web Application Security Project (OWASP), who composed it. Web applications run on servers protected by Internet firewalls, - [How To Protect Yourself Against Domain Name Hijackers](https://www.securityskeptic.com/how-to-protect-yourself-against-domain-name-hijackers/) - 12/03/2009 02:57:47 PM Domain name hijacking broadly refers to acts where a registered domain name is misused or stolen from the rightful name holder. A domain hijacking is a security risk many organizations overlook when they develop security policy and business continuity plans. Name holders can take measures to protect their domain names against theft - [The Re-emergence of SSL VPNs](https://www.securityskeptic.com/the-re-emergence-of-ssl-vpns/) - 12/03/2009 03:09:32 PM For years, organizations have sought to secure private communication over the Internet using Virtual Private Networks based on IP Security (IPsec VPNs). The process has proven more time- and resource-consuming than expected, but at this point, many organizations, large and small, have succeeded in connecting together their office and campus networks, and - [Antispyware and AV software ought to be the sameware](https://www.securityskeptic.com/antispyware-and-av-software-ought-to-be-the-sameware/) - 12/03/2009 03:15:57 PM Every network client must have antivirus software. We've been told so for years, and the message is finally sinking in. Network admission and integrity control are poised to enforce it today in enterrprise networks and hopefully soon for public Internet access as well. Concern over spyware is increasing so rapidly that I - [Spyware is a Nightmare](https://www.securityskeptic.com/spyware-is-a-nightmare/) - 12/03/2009 03:28:21 PM You think viruses, worms, blended threats and spam are bad? Spyware is worse... Spyware is software - a program file, a browser helper object, or a dynamic link library, for example - installed on your computer, without your knowledge or permission. Sometimes called adware, nastyware, crapware, scumware, and worse, it's all aggravating, - [Understanding VOIP Security](https://www.securityskeptic.com/understanding-voip-security/) - 12/04/2009 09:23:21 AM This authoritative and practical book offers a current and comprehensive understanding of VoIP (Voice over IP) security. Learn how to design and implement secure VoIP networks and services, and how to integrate VoIP securely in existing data networks. Discover how emerging SIP and media security standards will affect future VoIP deployment and - [IDS and DDOS Protection - Better Days Ahead](https://www.securityskeptic.com/ids-and-ddos-protection-better-days-ahead/) - 12/04/2009 09:50:06 AM To date, deployment of Intrusion Detection Systems (IDS) has been a tumultuous and often unrewarding experience for network administrators. Difficult to configure, even for advanced security technicians, and overly susceptible to positive and negative false alarms, ID systems are shut or dummied down. The irony here is obvious: today’s ID system itself - [Defensive Social Networking](https://www.securityskeptic.com/defensive-social-networking/) - 12/08/2009 05:19:43 PM In June 2009, I finally created a Facebook account, but not for any of the conventional reasons folks join social networks. At the time, I worried about the threat of impersonation and possibility of reputational harm. After six months of Facebooking, I'd recommend that many professionals should join a social network even - [Phlavors of Phishing](https://www.securityskeptic.com/phlavors-of-phishing/) - 12/14/2009 05:06:42 PM I still recall my first visit to a Baskin Robbins Ice Cream Parlor. Some of you no doubt recall your own anticipation: imagine choosing from 31 flavors of ice cream! Fifty years later, I feel angst and trepidation rather than anticipation when I open my e-mailbox and confront the imposing numbers of - [Blog 2010 - 2014](https://www.securityskeptic.com/blog-2010-2014/) - 12/22/2014 10:48:19 AM - [Blog (2015-2019)](https://www.securityskeptic.com/blog-2015-2019/) - [Managing the Technology Hype Cycle](https://www.securityskeptic.com/managing-the-technology-hype-cycle/) - 12/15/2009 11:38:09 AM Product life cycle management can be loosely defined as the activities a vendor engages in to develop, launch, market, mature (or evolve) a product. Many products enjoy long product life cycles. Other products reach a point at which they can no longer adapt or evolve, and vendors end the life of a - [The Cyber Doomsday Machine](https://www.securityskeptic.com/the-cyber-doomsday-machine/) - 01/14/2010 03:18:15 PM Trekkies will recall an episode in the original Star Trek series called The Doomsday Machine. The episode describes an encounter with, and ultimate destruction of, a machine that smashes planets which it consumes to fuel its journey from galaxy to galaxy. I watched Star Trek faithfully as a teen. This episode intrigues - [e-crime facts, figures, frustrations, and fixes](https://www.securityskeptic.com/e-crime-facts-figures-frustrations-and-fixes/) - 01/15/2010 10:16:37 AM The US DOJ successfully closed its case against the father-son team of Jude LaCour by handing down guilty verdicts on fifty-two counts of money laundering and drug-trafficking offenses involving the sale of controlled substances over the Internet. Previously, son Jeffery pleaded guilty to drug-trafficking offenses. Also found guilty or pleading out were - [Phishing: a low-paid, low-skills enterprise?](https://www.securityskeptic.com/phishing-a-low-paid-low-skills-enterprise/) - 01/15/2010 10:31:19 AM Cormac Herley and Dinei Florencio published a mildly controversial paper entitled A Profitless Endeavor: Phishing As Tragedy Of The Commons. In the article abstract, the authors say "Phishing is a classic example of tragedy of the commons, where there is open access to a resource that has limited ability to regenerate. Since - [DNS Cache Poisoning](https://www.securityskeptic.com/dns-cache-poisoning/) - 01/17/2010 05:07:58 PM Originally posted 26 Apr 2003 A cache is a local store of information (or munitions). Security researchers and practitioners have demonstrated that the trust relationship on which DNS relies is weak, and an attacker can inject false information into the local cache of a DNS resolver that's caching DNS response messages. By - [How Many Legs Does Your Security Stool Have?](https://www.securityskeptic.com/how-many-legs-does-your-security-stool-have/) - 01/17/2010 07:37:17 PM This is the transcript of a May 2007 podcast I produced for TechTarget. Security begins with the letter "A" Authentication and authorization are the two most fundamental and commonly employed attributes of security. They sound alike, and their definitions are often confused, so let me begin by offering mine: Authentication is the - [ISIT: A Template to Document Your DNS Investigations](https://www.securityskeptic.com/isit-a-template-to-document-your-dns-investigations/) - 12/05/2014 08:52:04 AM Anuj Soni has a fine post at the SANS Digital Forensics and Incident Response blog entitled How to Track Your Malware Analysis Findings. In the post, Anuj asserts that a truly successful malware analysis requires "both a well-crafted process and detailed documentation of the journey through that process". This is a spot on observation - [Preparing for the (Inevitable?) DDoS Attack](https://www.securityskeptic.com/preparing-for-the-inevitable-ddos-attack/) - 07/08/2013 01:06:50 PM The current landscape of means, motives, and opportunities to execute distributed denial of service (DDoS) attacks makes any organization a more likely target than you might imagine. Open-source attack tools are easy to find. Acquiring the capacity to execute a DDoS attack is almost a trivial concern for state-sponsored actors or criminals, who can lease - [Security versus privacy: there is no balance, and that's intentional](https://www.securityskeptic.com/security-versus-privacy-there-is-no-balance-and-thats-intentional/) - 07/19/2013 08:43:19 AM David Lacey has written a thoughtful post at Computer Weekly entitled Security versus privacy - a difficult and uncomfortable balance. I have not bothered to comment to any great extent about the NSA activies and Snowden because, as Lacey so aptly points out, they've "revealed nothing surprising to the security professional, generated - [10 Tips for Better Administrative Client Hygiene](https://www.securityskeptic.com/10-tips-for-better-administrative-client-hygiene/) - 07/22/2013 08:00:12 AM Whether your data or applications are in a cloud, a remotely accessed datacenter, or your local network, an infected or rooted administrative workstation is a nightmare scenario for any organization, government, or critical (e.g., SCADA) infrastructure. Malware accidentally downloaded visiting websites, email attachments, or removable media that contain malicious executables, and file - [Metadata or Content: NSA is not the only data collector you should fear](https://www.securityskeptic.com/metadata-or-content-nsa-is-not-the-only-data-collector-you-should-fear/) - 08/07/2013 03:37:33 PM The PRISM and other surveillance projects have raised public awareness of the extent to which NSA in the US and similar agencies worldwide conduct surveillance or collect metadata associated with individuals? communications. While security agency or law enforcement activities capture international attention, we ought to be equally wary of data collectors other - [The Silence of the ATM LANs](https://www.securityskeptic.com/the-silence-of-the-atm-lans/) - 08/30/2013 04:58:00 PM A former colleague during the dotcom era mentioned that this was one of his all time favorite articles from the Pre-Millenial LAN Wars era. The What Wars? Exactly. Obviously, Ethernet has come even further than I discuss here, and I expect to see it go further in my lifetime. I hope those - [Emergence of DDoS as a Service (DDoSAAS)](https://www.securityskeptic.com/emergence-of-ddos-as-a-service-ddosaas/) - 09/03/2013 10:33:52 AM As if the current frequency of DDoS attacks is not enough, we’re now confronted with an emergence of “legitimized” attacks: DDoS-as-a-service (DDoSAAS). Service? Respected security blogger Brian Krebs exposed the advent of DDoS legitimization and interviews players in this questionable industry in May 2013. What Brian learned is that these services are really straightforward: A - [The People Side of Prevention](https://www.securityskeptic.com/the-people-side-of-prevention/) - 09/13/2013 07:58:13 AM (Originally 07/20/2004) Originally published 20 July 2004. Finding articles nearly twenty years old, I continue to be surprised that certain issues have changed little. In a September 2002 article, The People Side of Prevention, Joanne Cummings asked me about measuring prevention success, and I reflected that success is a metric that is both - [Considerations when comparing firewalls](https://www.securityskeptic.com/considerations-when-comparing-firewalls/) - 09/13/2013 08:20:44 AM Years ago, I cajoled Paul Robertson to allow me to incorporate his responses and mine from a firewall mailing list thread that asked, "how should I compare two firewalls?" This is a reboot of a 23 June 2004 post. Some of these comparison criteria are less relevant in 2013 than 2004 but - [APWG Global Survey Explores Phishing Trends and Name Use in 1H 2013](https://www.securityskeptic.com/apwg-global-survey-explores-phishing-trends-and-name-use-in-1h-2013/) - Greg Aaron and Rod Rasmussen's biannual Global Phishing Survey for 1H 2013 has some interesting findings. For me, the most striking and worrisome include: Shared Virtual Server compromises accounted for 27% of all phishing attacks. Attackers are targeting and compromising servers that hosts large numbers of domains. The attackers exploit the server configuration to install - [Turn Your Android Device into a Swiss Army Knife for Security](https://www.securityskeptic.com/turn-your-android-device-into-a-swiss-army-knife-for-security/) - 10/21/2013 08:16:10 AM Network analysis tablets — full-suite devices that automate security, networking, and application monitoring — are a welcome addition to the toolkit that network and security engineers use to assess infrastructure health and application performance. All-in-one testers from companies like Fluke and AirMagnet remain the Ferraris of network analysis and troubleshooting. These are - [Is It Time to Eliminate Firewalls?](https://www.securityskeptic.com/is-it-time-to-eliminate-firewalls/) - 10/28/2013 08:30:00 AM Director Lt. General Ronnie Hawkins Jr., USAF, announced in a 26 June 2013 interview that the US Defense Information Systems Agency (DISA) was building a security architecture that would ultimately eliminate firewalls. "In the past, we?ve all been about protecting our networks?firewall here, firewall there, firewall within a service, firewall within an - [Malware, War Without End: The Uncomfortable, Unacknowledged Truth](https://www.securityskeptic.com/malware-war-without-end-the-uncomfortable-unacknowledged-truth/) - 12/02/2013 10:17:32 AM My friend and respected infosec colleague, Gary Warner, tweeted a link to a ComputerWorld column, Malware: war without end. I read the article and decided to explore and comment in more detail. Certain assertions in the article frankly make me cringe; for example, this claim, "there are no types of malware - [Are you Monitoring Your DNS?](https://www.securityskeptic.com/are-you-monitoring-your-dns/) - 12/17/2013 03:31:06 PM Why monitor DNS? The obvious reason is to ensure that your Domain Name System is operating as intended. But there’s more to it than that. Access to almost every Internet application relies on queries to DNS, a global name resolution database to determine an Internet address associated with a domain name or - [Harden your resolvers: protect your recursive DNS for you and for everyone else](https://www.securityskeptic.com/harden-your-resolvers-protect-your-recursive-dns-for-you-and-for-everyone-else/) - 01/06/2014 07:00:00 AM The era of DDoS attacks will no doubt continue in 2014, yet operating recursive resolvers -- the name servers that process or resolve DNS queries on behalf of client devices or applications -- in a secure and reliable manner remains a critical yet commonly neglected administrative practice. What is recursive DNS? It’s - [Manage your DNS Portfolio](https://www.securityskeptic.com/manage-your-dns-portfolio/) - 01/13/2014 09:39:37 AM Some readers may be familiar with recent, noteworthy domain hijacks. Hijacks, however, are only one of several ways your online identity or brands can be misused or abused. If you fail to coordinate and monitor domain registrations, you may provide attackers or opportunists with much simpler means to tarnish or exploit your - [Firewall Best Practices - Egress Traffic Filtering](https://www.securityskeptic.com/firewall-best-practices-egress-traffic-filtering/) - 03/27/2014 08:13:33 AM In Spanish Too many network administrators think only to protect their private network resources from external attacks when assessing security threats. Today's landscape is littered with threats that emanate from malware-infected endpoints. Attackers can use these to collect and forward sensitive information from your network or to attack or spam other networks. Companies - [How to Find Your MAC address: From Android to Windows](https://www.securityskeptic.com/how-to-find-your-mac-address-from-android-to-windows/) - 05/23/2014 09:07:14 AM Whether your computing or mobile device of choice is a phone, tablet, or laptop, it has one or network adapters that you can use to connect to the Internet or other devices. And whether the you're communictaing using wired or wireless Ethernet, Bluetooth, cellular/mobile, or near electrostatic field communication phenomena, it's likely that - [Recognizing and Responding to a Phishing Attack](https://www.securityskeptic.com/recognizing-and-responding-to-a-phishing-attack/) - 05/24/2014 12:25:14 PM Even the best of antispam measures may not be enough to protect you from spoof email messages. By spoof email, I mean a message that appears to be from a party you know - most commonly, an ecommerce site, financial institution, even your IT department - but in fact, is a bogus - [Is cybercrime a threat to our economies?](https://www.securityskeptic.com/is-cybercrime-a-threat-to-our-economies/) - 05/28/2014 11:32:34 AM I was invited to a high (Ministerial) level meeting where The Threat of Cybercrime was the center stage topic. One of the questions put before the participants was Is cybercrime a threat to our economies? I commented that there are two contexts to consider when answering this question: How is your economy directly - [Recognizing and Avoiding Situational Harm from Social Voyeurism](https://www.securityskeptic.com/recognizing-and-avoiding-situational-harm-from-social-voyeurism/) - 07/17/2014 02:58:32 PM Recently, I observed three passengers enjoying a bottle of beer at a kiosk at Brisbane Airport. Shortly, they headed for their departure gate, leaving behind three empty bottles. A pilot occupied the table they vacated. Engrossed with an app on his mobile phone, he seemed oblivious to the beer bottles. From my - [Is it a Phish? Common Deceptions in Phishing URL composition](https://www.securityskeptic.com/is-it-a-phish-common-deceptions-in-phishing-url-composition/) - 08/21/2014 09:20:01 AM Phishers take advantage of common user behavior. Phishers know that people often see what they want to read rather than what is actually displayed in a message or hyperlink. They know that when we read in haste, we may pay less attention to punctuation marks. They know, too, that we are generously - [In 2015, Take Spear Phishing Seriously](https://www.securityskeptic.com/in-2015-take-spear-phishing-seriously/) - 12/22/2014 10:48:19 AM This cyber attack against a steel factory in Germany is frightening The attackers reportedly gained access first to an office network via a targeted or "spear" phish and from this lauch point, to a production network, where they caused compromised systems to fail. These failures reportedly interfered with the normal, "controlled" shutdown - [Monitor DNS Traffic And You Just Might Catch A RAT](https://www.securityskeptic.com/monitor-dns-traffic-and-you-just-might-catch-a-rat/) - 01/24/2015 09:12:33 AM Criminals will exploit any Internet service or protocol when given the opportunity. Here are six signs of suspicious activity to watch for in the DNS. IT admins have the thankless task of having to watchdog devices, hosts, and networks for signs of malicious activity. Host intrusion detection and endpoint protection may be - [Five Ways To Monitor DNS Traffic For Security Threats](https://www.securityskeptic.com/five-ways-to-monitor-dns-traffic-for-security-threats/) - 02/05/2015 08:32:08 AM In Monitor DNS Traffic & You Just Might Catch A RAT, I described how inspecting DNS traffic between client devices and your local recursive resolver could reveal the presence of botnets in your networks. Today, I'll share how you can monitor traffic using security systems and name resolvers you may already have deployed. - [A Hacker Personality Quadrant](https://www.securityskeptic.com/a-hacker-personality-quadrant/) - 02/19/2015 10:37:40 AM Science Daily reports that associate professor Kevin Steinmetz of Kansas State University has published a research article in which he attempts to answer the questions: "What is a hacker and what does it mean to hack?" According to Science Daily, Steinmetz, who conducted an ethnographic study to find his answer, "Hacking is a - [Is it spam? This season in IRS tax scams](https://www.securityskeptic.com/is-it-spam-this-season-in-irs-tax-scams/) - 03/09/2015 10:02:06 AM It's tax season in the US. This week's "Is it spam?" features spampaigns that attempt to attract mail recipients into revealing personal information, including Social Security numbers, or electronic filing PINs. These are only a few of the scams that the US Internal Revenue Service (IRS) identifies annually in it's Dirty Dozen - [Can we extend trust-based collaboration beyond handshakes and face-to-face?](https://www.securityskeptic.com/can-we-extend-trust-based-collaboration-beyond-handshakes-and-face-to-face/) - 03/27/2015 09:02:00 AM I had the opportunity to participate in a panel at Suits and Spooks, Washington DC 2015 last month. The panelists shared their perspectives on the perceived post-Snowden "breakdown of trust, and shared how they work on restoring trust from the ground up, one handshake at a time." I struggled when preparing for this - [Is it Spam? A 419 Scam Moves to Skype](https://www.securityskeptic.com/is-it-spam-a-419-scam-moves-to-skype/) - 05/12/2015 09:00:00 AM I recently received a Skype contact invitation from a Benjamin Debrah that seemed to be a 419 scam, also known as an advanced fee fraud. I hadn't seen scams on Skype until now so I decided to probe a bit. I grabbed the image of the alleged Barclay's employee in Ghana and used - [Defense _is_ sexy](https://www.securityskeptic.com/defense-_is_-sexy/) - 06/10/2015 10:54:19 AM Violet Blue begins a post reviewing a recent RAND study: Cyber-defense must change course, or else, with an apt summary of the report: Defense isn't sexy. We mythologize being the hacker, not the hacked. The RAND study depicts network and system defenders as a hapless, hopeless, dispirited, confused lot. Defenders, it seems, have - [Cry havoc! and let slip the iPad investigators of malicious domains!](https://www.securityskeptic.com/cry-havoc-and-let-slip-the-ipad-investigators-of-malicious-domains/) - 07/14/2015 05:28:43 AM For some time, I've used an Android tablet, for the simple reason that Android offered more security and networking utilities. The availability landscape has changed, and I've found iPad apps that meet my mobile needs for five tools I use routinely from a laptop to query domain, IP address, autonomous system, registration - [How to Protect Your Privacy When You Register a gTLD Domain Name](https://www.securityskeptic.com/how-to-protect-your-privacy-when-you-register-a-gtld-domain-name/) - 07/27/2015 08:22:41 AM Recent efforts to introduce or revise policies governing Whois for ICANN generic Top Level Domains have come under intense criticisms of the policy regarding public display of point of contact information associated with a domain name registration (1, 2, 3). In this post I provide some explanation of a domain name registrant’s - [How Much Is Your Personal Data Worth?](https://www.securityskeptic.com/how-much-isyour-personal-data-worth/) - 08/17/2015 09:00:00 AM Today's guest column is from Isa Cox. Isa is an Internet security expert and blogger. She writes about online safety and freedom, tech tips for small business and travel. You may also enjoy her article on e-crime facts and figures. Are you aware of the battles being waged over the fate of your personal - [Dismantling botnets: Dealing with DNS and Whois](https://www.securityskeptic.com/dismantling-botnets-dealing-with-dns-and-whois/) - 08/31/2015 09:03:43 AM Botnet chasers are expert folks from the private or public sector who pore over giga- or terabytes of data – network traffic, malware, DNS, and addressing information – to identify and confirm that a domain name, or perhaps hundreds of domain names, is being abused to support a botnet infrastructure. As is - [Should you participate in industry surveys?](https://www.securityskeptic.com/should-you-participate-in-industry-surveys/) - 10/01/2015 11:58:23 AM Do you receive email invitations to participate in industry surveys, where you're invited to complete an online survey that will report industry trends, the state of industry, industry demographics, or similar findings? Have you completed these for the report or a prize?Have you assessed the risk such participation creates for your organization? - [Gun violence, cybercrime, and alternatives to living in fear](https://www.securityskeptic.com/gun-violence-cybercrime-and-alternatives-to-living-in-fear/) - 12/16/2015 01:05:52 PM A recent New York Times editorial, Fear in the Air, Americans Look Over Their Shoulders begins with “The killings are happening too often. Bunched too close together. At places you would never imagine." The article continues by saying, ... a wide expanse of America’s populace finds itself engulfedin a collective fear, a fear tinged with confusion - [The Still Sad and Deplorable State of Internet Security](https://www.securityskeptic.com/the-still-sad-and-deplorable-state-of-internet-security/) - 01/13/2016 12:31:51 PM I came across an article colleague Stephen Kent and I wrote in 2003. In a subscription magazine, Business Communications Review.. The Sad and Deplorable State of Internet Security, and was struck once again at how little progress we've made on issues we were lamenting over a decade ago. The issues that most concerned - [Identifying Cybercriminals: Is An IP Address Sufficient?](https://www.securityskeptic.com/identifying-cybercriminals-is-an-ip-address-sufficient/) - 02/11/2016 03:08:57 AM When asked “I’ve found the IP address of a criminal, where do I find information about the criminal associated with this address?" I use the following explanation to help investigators so that they appreciate context and relationships between Internet identifiers – domain names, IP addresses, or Autonomous System Numbers (ASNs) – and - [Threats, Vulnerabilities and Exploits – oh my!](https://www.securityskeptic.com/threats-vulnerabilities-and-exploits-oh-my/) - 10/27/2016 09:26:23 AM Some of the most commonly used security terms are misunderstood or used as if they were synonymous. Certain of these security terms are so closely related that it's worth examining these together. Today, we'll look at several related terms – threat, vulnerability, and exploit – and learn how security professionals use these - [IoT Threat Landscape (The Internet of Threats?)](https://www.securityskeptic.com/iot-threat-landscape-the-internet-of-threats/) - 12/02/2016 02:00:00 AM I was invited to speak at the Eastern European DNS Forum/UADOM on 1 December 2016 in a session on the Internet of Things (IoT). I followed A. Baranov's fine presentation about the promises and benefits of IoT with a presentation on IoT characteristics, challenges and threat landscape. I concluded the presentation asking, - [Access Controls, User Permissions and Privileges](https://www.securityskeptic.com/access-controls-user-permissions-and-privileges/) - 06/12/2017 09:03:21 AM In What is Authorization and Access Control, I explained that we use authentication to verify identity – to prove you are whom you claim to be – and also to enable an authorization policy, i.e., to define what your identity is allowed to "see and do". We then implement these authorization policies - [Lending Clarity to Security Risk Definitions](https://www.securityskeptic.com/lending-clarity-to-security-risk-definitions/) - 02/29/2016 09:57:15 AM by Dave Piscitello and Greg Aaron In its Beijing Communiqué of 11 April 2013, the ICANN Government Advisory Committee (GAC) called on ICANN to have new gTLD registry operators find and act upon a variety of abuseive activities occurring within their TLDs. This led to a requirement in the new gTLD contracts: Registry - [Los Ataques Contra El Sistema De Nombres Dominios (Attacks Against the DNS)](https://www.securityskeptic.com/los-ataques-contra-el-sistema-de-nombres-dominios-attacks-against-the-dns/) - 06/27/2016 01:40:16 PM El sistema de nombres de dominio (DNS) es un servicio muy importante a Internet. Todos usamos el DNS para obtener las direcciones de Internet que están asociados con los nombres de dominio de uso fácil. El DNS es una "infraestructura crítica". Los ciber delincuentes y hacktivistas tienen fuertes incentivos para atacar el - [Monitoreo de DNS y Medidas Contra Ataques DNS monitoring and countermeasures](https://www.securityskeptic.com/monitoreo-de-dns-y-medidas-contra-ataques-dns-monitoring-and-countermeasures/) - 06/28/2016 10:56:00 AM Los ataques contra el sistema de nombres de dominio (DNS) se producen con más frecuencia que la mayoría organzations imaginan y ninguna organización es inmune a los ataques. Cada organización debe mirar a "las personas, procesos y tecnología" para proteger sus DNS de los ataques. Las organizaciones también deben considerar cómo la - [IRS Tax Scams Are Year-round Threats](https://www.securityskeptic.com/irs-tax-scams-are-year-round-threats/) - 07/05/2016 09:20:25 AM What once was a seasonal phishing or phone call scam is now a year-round threat. Criminals are not only more aggressive with tax scam email or phone calls than ever, but they’ve contrived scams that claim victims before, during, and after what we traditionally consider tax preparation time in the US. What - [Procedimientos recomendados para firewall: Egreso Filtrado de tráfico](https://www.securityskeptic.com/procedimientos-recomendados-para-firewallegreso-filtrado-de-trafico/) - 07/11/2016 09:00:00 AM en inglés Muchos administradores de red piensan sólo en proteger los recursos privados de ataques externos en la evaluación de amenazas de seguridad. El panorama de hoy está lleno de amenazas que emanan de los equipos dispositivos infectados con malware. Los atacantes pueden utilizar éstos para recoger y transmitir información sensible de su red, - [Now witness the firepower of this fully armed and operational domain name](https://www.securityskeptic.com/now-witness-the-firepower-of-this-fully-armed-and-operational-domain-name/) - 09/07/2016 03:12:57 PM Hyperlinks are prominent in nearly every online activity. We see them on web pages and in email. We embed them in texts, comment fields, or discussion threads. We use them to amplify social media messages or to advertise. One might argue that the most common purpose of hyperlinks today is, in fact, - [Internet Security Isn't a Battle: It's a Health Crisis](https://www.securityskeptic.com/internet-security-isnt-a-battle-its-a-health-crisis/) - 12/21/2016 09:18:30 AM Andra Zaharia invited me to share my thoughts in her recent Heimdal Security blog, Is Internet Security A Losing Battle? Please read the other 30+ experts thoughts at Andra's blog. Here, I've complemented what I shared with Andra with some additional thoughts. To answer Andra's question directly, any battle that you engage on your - [Expired Nameserver Domains](https://www.securityskeptic.com/expired-nameserver-domains/) - 02/03/2017 08:30:00 AM Matthew Bryant's recent post, Respect My Authority – Hijacking Broken Nameservers to Compromise Your Target, describes attacks against authoritativename servers. These are the name servers that host DNS records for your domain name (A, NS, MX, CNAME, TXT...) and thus the definitive or authoritative sources for resolution, i.e., they host the database that applications - [Hack... or attack?](https://www.securityskeptic.com/hack-or-attack/) - 02/20/2017 09:00:00 AM Nearly every day, we see news stories or tweets that reveal another "cyber attack" against a well-known brand, bank or government agency are commonplace today. These are almost always characterized as sophisticated hacking schemes. Some are described as acts of hacktivism. In an effort to characterize certain attacks as the most sophisticated - [What is a Man In The Middle Attack (MITM)](https://www.securityskeptic.com/what-is-a-man-in-the-middle-attack-mitm/) - 04/03/2017 08:45:00 AM An earlier version of this post originally appeared at ICANN blog on 2 October 2015. Many years ago, your local telephone service offered you options. You could subscribe to a private line or you could subscribe to a more economical service that you would share with some of your neighbors. This shared service was - [Authorization and Access Control](https://www.securityskeptic.com/authorization-and-access-control/) - 05/19/2017 09:42:28 AM You are probably familiar with the concept of authentication, the way that security systems challenge you to prove you are the customer, user, or employee whom you claim to be, using a password, token, or other form of credential. You may be less familiar with the concept of authorization, and the related - [Spam: The Security Threat You Easily Forget](https://www.securityskeptic.com/spam-the-security-threat-you-easily-forget/) - 11/06/2017 09:46:42 AM, Revised 11/05/2025 06:49:00 PM In 2016, I spoke at a Cybersecurity conference in Krakow. I was asked during a video interview to identify security threats that I believed were most pressing. Yes, I said: spam. Not DDoS? Not ransomware? Not breach of personal data? Not IoT? Are you daft, Dave? No. My - [Will Email Operators Block Entire TLDs to Prevent Spam?](https://www.securityskeptic.com/will-email-operators-block-entire-tlds-to-prevent-spam/) - 11/15/2017 10:27:58 AM Security administrators use firewalls, web proxies, or antispam gateways to block traffic sources that exhibit suspicious or known attack pattern behaviors. Blocking individual IP addresses has been a staple defensive measure for years. Security system administrators have also blocked entire IP network allocations to mitigate attacks and on rare occasions, they have blocked all - [What is Ransomware?](https://www.securityskeptic.com/what-is-ransomware/) - 02/21/2018 09:00:00 AM Ransomware is a cyberattack (a virus) that is used to extort money. Originally, criminals used ransomware to extract payments from individuals for the recovery of personal information. Today, cyberattackers extort payments from businesses for the recovery of sensitive information. No one is immune to ransomware. Criminals have extorted payments for the recovery - [What is Two-Factor Authentication?](https://www.securityskeptic.com/what-is-two-factor-authentication/) - 06/11/2018 03:37:54 PM This post originally appeared at ICANN blog on 13 July 2015 Today, I'll explain two-factor authentication, how this improves the security of your online accounts or logins, and examples of where you'll find two-factor authentication in use today. Begin at the beginning: What is authentication? Authentication is a security term for demonstrating that you - [The Dark Web: A land of hidden services](https://www.securityskeptic.com/the-dark-web-a-land-of-hidden-services/) - 06/25/2018 02:49:35 PM Originally posed at ICANN Blog, 27 June 2018 According to Internet Live Stats, the World Wide Web passed the one billion website benchmark in 2014 and today is nearly twice that number. The publishers of these near two billion websites compete for search engine relevance and the attention of over four billion Internet users. There is - [Time to clean up the spammiest neighborhoods in the DNS](https://www.securityskeptic.com/time-to-clean-up-the-spammiest-neighborhoods-in-the-dns/) - 08/20/2018 09:31:26 AM Domain Incite reports that Famous Four Media’s portfolio of top-level domains is now under the control of Global Registry Services Ltd. The new company has promised to "abandon its failed penny-domain strategy and crack down on spam". Time will tell whether new ownership cleans up arguably the spammiest neighborhoods in the DNS. Famous Four's - [Post-GDPR WHOIS: A Myriad of Misconceptions, Misinformation and Misdirection](https://www.securityskeptic.com/post-gdpr-whois-a-myriad-of-misconceptions-misinformation-and-misdirection/) - 09/06/2018 09:20:31 AM One of the most memorable lyrics of For What It’s Worth (Buffalo Springfield, 1967) aptly describes the current condition of the post-GDPR debate over domain registration data access: There’s battle lines being drawn… nobody’s right if everybody’s wrong. Cybersecurity and policy pundits are heatedly engaged over the impact of the EU General Data Protection - [Whois studies: it's time to ask the right questions](https://www.securityskeptic.com/whois-studies-its-time-to-ask-the-right-questions/) - 09/12/2018 09:52:34 AM I remain skeptical of all the Whois studies that I’ve reviewed (FTC, SSAC, ICANN), including studies where I was a party to the research. I’ll apologize for failing to contribute to a satisfactory Whois study. I’ll also admit that my understanding of how to study a problem scientifically has greatly expanded over the past - [APWG and M3AAWG Survey: WHOIS Changes Impede Cyber Investigations](https://www.securityskeptic.com/apwg-and-m3aawg-surveywhois-changes-impede-cyber-investigations/) - 10/20/2018 08:03:44 AM The Anti-Phishing Working Group (APWG) and the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) have collaborated to conduct a survey of cyber investigators and anti-abuse service providers to understand how ICANN’s Temporary Specification for gTLD Registration Data has affected their access and usage of domain name registration information and their ability to mitigate - [A critical year for privacy and data protection](https://www.securityskeptic.com/a-critical-year-for-privacy-and-data-protection/) - 01/09/2019 08:24:37 AM Privacy refers to the right to exercise control over how your personal information is collected, used, or disclosed. Data protection refers to measures to protect data from unauthorized access, alteration, or loss. You need both to preserve trust and confidence between consumers and providers of Internet services and content. Privacy rights have - [Conservative abuse reporting throws new TLD program under the bus](https://www.securityskeptic.com/conservative-abuse-reporting-throws-new-tld-program-under-the-bus/) - 02/18/2019 05:18:08 PM ICANN has released a January 2019 domain abuse report generated from the Domain Abuse Activity Reporting system (DAAR). DAAR is a system for studying and reporting on domain name registration and security threat (domain abuse) behavior across top-level domain (TLD) registries and registrars. While at ICANN, I was actively involved with DAAR from inception to - [Google Maps Timeline Review: The Good, the Bad, and the Inevitable Privacy Rift](https://www.securityskeptic.com/google-maps-timeline-reviewthe-good-the-bad-and-the-inevitable-privacy-rift/) - 03/05/2019 08:15:10 AM Google Maps now sends you amonthly email review of your Google Maps Timeline. The email invites you to review your month's travel and daily activities. For those who want an opt-in world, and I have pined for such a world for ages, I checked and it is: you enable the feature when - [Whois Policy Changes Impair Blocklisting Defenses](https://www.securityskeptic.com/whois-policy-changes-impair-blocklisting-defenses/) - 03/08/2019 05:26:12 PM In the aftermath of the adoption of the EU GDPR, ICANN’s policies for access to domain registration data (Whois) have created adverse consequences for investigations into terrorist activities, political influence campaigns and cybercrimes, creating serious threats to public safety. Whois data is employed during preventative and forensic cyber investigations – and ICANN’s - [ICANN prepares for more gTLDs… has enough been done to mitigate threats?](https://www.securityskeptic.com/icann-prepares-for-more-gtlds-has-enough-been-done-to-mitigate-threats/) - 09/13/2019 10:06:16 AM ICANN organization has published a memorandum that describes its Readiness to Support Future Rounds of New gTLDs. The last time I looked, new TLD registrations from the 2012 round constituted around 12 percent of the total gTLD registrations. Despite justifications most commonly cited for expansion - for example, "all the good names are - [Criminal Abuse of Domain Names, Bulk Registration and Contact Data Access](https://www.securityskeptic.com/criminal-abuse-of-domain-names-bulk-registration-and-contact-data-access/) - 10/18/2019 11:47:23 AM My Interisle Consulting Group colleague, Dr. Colin Strutt and I have published a report, Criminal Abuse of Domain Names: Bulk Registration and Contact Information Access. In this report, we study "bulk registration misuse" by criminal actors. Bulk registrations refers to the practice of rapidly acquiring domain names, using these in an attack, - [Microsoft dismantles global spam delivery infrastructure (Necurs)](https://www.securityskeptic.com/microsoft-dismantles-global-spam-delivery-infrastructure-necurs/) - 03/17/2020 09:52:37 AM Microsoft and partners from 35 countries recently took action to dismantle the Necurs spam infrastructure. Microsoft's post calls Necurs a botnet but provides details that illustrate how much more than a botnet Necurs is: The Necurs infrastructure served as a spam delivery platform for spam, cryptomining and DDOS attacks. The spam campaigns - [About](https://www.securityskeptic.com/about/) - Professional History Professional Biography David M. Piscitello has over forty years of experience with data and telecommunications networks and security. As a network architect at Unisys Corporation and Member of Technical Staff for Bell Communications Research, Dave was involved in the design of network and routing protocols, network interfaces, and public switched services (ATM, Frame - [Professional History (of sorts)](https://www.securityskeptic.com/professional-history-of-sorts/) - About Dave I received a Bachelor of Science Degree in Mathematics from Villanova University in 1974, with a strong minor in Philosophy. Disenchanted with real analysis and metric space, I decided to pursue graduate work in philosophy. To pay for graduate school, I accepted a programming position with Burroughs Corporation. I assembly- and micro-coded my - [Issues with Domain Registration Accountability Have a COVID Nexus](https://www.securityskeptic.com/issues-with-domain-registration-accountability-have-a-covid-nexus/) - 03/31/2020 08:28:48 AM My Interisle partners and colleague Greg Aaron have published a detailed study that measures the effectiveness and impact of ICANN's registration data access policies and procedures. This study reveals widespread problems with access to and the reliability of domain name registration data systems (WHOIS). These failures have real-life security implications, which are - [Online Child Predation Rising During COVID Lockdown](https://www.securityskeptic.com/online-child-predation-rising-during-covid-lockdown/) - I attended a Council of Europe cybercrime webinar on the impact of COVID on cybercrime last week. One of the most disturbing criminal activities discussed was the rise in reports of online predation. The National Center for Missing and Exploited Children (NCMEC) has received 4.2 million reports in April. That’s up 2 million from March - [ICANN Policy Further Erodes Whois Access](https://www.securityskeptic.com/icann-policy-further-erodes-whois-access/) - 06/22/2020 09:08:09 AM In anticipation of the EU General Data Protection Regulation (GDPR) adoption in May 2018, ICANN adopted a temporary specification for the Whois services that are used to access domain name regristation information ostensibly to comply with the regulation. This "temp spec" created a number of impediments for abuse investigators,and cybercrime first responders. These - [Phishing Landscape 2020](https://www.securityskeptic.com/phishing-landscape-2020/) - 10/13/2020 01:59:13 PM My colleagues Greg Aaron, Dr. Colin Strutt, Lyman Chapin and I have published a new research report, Phishing Landscape 2020: A Study of the Scope and Distribution of Phishing. Our goal in this study was to capture and analyze a large set of information about phishing attacks, to better understand how much phishing - [Interisle Study Reveals Excessive Withholding of Internet WHOIS Data](https://www.securityskeptic.com/interisle-study-reveals-excessive-withholding-of-internet-whois-data/) - 01/25/2021 09:06:56 AM My Interisle colleagues, together with Greg Aaron, have completed an in-depth analysis of the effects of ICANN policy for WHOIS, a public lookup service that has until recently made it possible to identify who registered and controls a domain name. The European Union’s General Data Protection Regulation (GDPR), adopted in May 2018, - [Interisle 2021 Phishing Study Reports a 70% Increase in Phishing](https://www.securityskeptic.com/interisle-2021-phishing-study-reports-a-70-increase-in-phishing/) - 10/04/2021 09:54:51 AM My Interisle colleagues, together with Greg Aaron of Illumintel, have published a study, Phishing Landscape 2021: A study of the scope and distribution of phishing. From 1 May 2020 through 30 April 2021, we collected nearly 1.5 million phishing reports. Our analyses found ~700,000 phishing attacks among the reports collected. Highlights from - [US citizens under attack from US bases of EIP phishing operations](https://www.securityskeptic.com/us-citizens-under-attack-from-us-bases-of-eip-phishing-operations/) - 11/30/2021 09:10:00 AM As part of the US Covid-19 virus tax relief effort (American Rescue Plan Act of 2021, H.R.1319), the US Internal Revenue Service (IRS) issued a series of Economic Impact Payments to millions of eligible citizens. The third payment was authorized in March 2021. Criminals took note of this well-publicized program and put a phishing campaign - [New TLDs are coming #DangerClose](https://www.securityskeptic.com/new-tlds-are-coming-dangerclose/) - 03/01/2022 09:47:25 AM A Domain Name Wire post, Time to pay attention to the next round of new TLDs, begins with an ominous: They’re coming. Eventually. While not as dramatic or enduring as Arnold Schwarzenegger's "I'll be back", the reporter cites policy activity at ICANN as evidence that new TLDs are coming. Eventually. In a September 2019 post, - [A 5-minute stakeholder intervention before the EU HLIG on #DNSabuse](https://www.securityskeptic.com/a-5-minute-stakeholder-intervention-before-the-eu-hlig-on-dnsabuse/) - 03/14/2022 09:22:06 AM I was invited to participate in an 11 March 2022 meeting of the EU High Level Internet Governance expert group to discuss domain name abuse (#DNSabuse). Following a presentation of a Study on Domain Name System (DNS) Abuse commissioned by the European Commission, I gave a 5-minute intervention. This EC study is comprehensive and well worth #DNSabuse - [Interisle 2022 Study: unabated malware growth, continued exploitation of IoT devices](https://www.securityskeptic.com/interisle-2022-study-unabated-malware-growth-continued-exploitation-of-iot-devices/) - My colleagues at Interisle and I have published a study, Malware Landscape 2022: A Study of the Scope and Distribution of Malware. The study, which analyzed 2.5 million records of distinct malware events from May 2021 to April 2022 collected by the Cybercrime Information Center, explains what malware was most prevalent, where malware was served - [Interisle Study: 61% rise in phishing, 257% increase in cryptocurrency phishing in 2022](https://www.securityskeptic.com/interisle-study-61-rise-in-phishing-257-increase-in-cryptocurrency-phishing-in-2022/) - Study shows 61% increase in phishing attacks, 257% increase in attacks targeting cryptocurrency - [Cybecrime on YouTube](https://www.securityskeptic.com/cybecrime-on-youtube/) - A YouTube channel to complement the quarterly reporting and studies of cybercrime we host at the Cybercrime Information Center - [FTC Rule on Impersonation of Government and Businesses](https://www.securityskeptic.com/ftc-rule-on-impersonation-of-government-and-businesses/) - M3AAWG suggests additional regulatory solutions and best practices to complement the goals of this rule. - [Interisle Study: Phishing Attacks Have Tripled Since 2020](https://www.securityskeptic.com/interisle-study-phishing-attackshave-tripled-since-2020/) - phishing securityskeptic_mep0l1 dns abuse - icann - new gTLD - bulk registrations - [Cybercrime Supply Chain 2023](https://www.securityskeptic.com/cybercrime-supply-chain-2023/) - Interisle colleagues and I released a study, Cybercrime Supply Chain 2023: Measurements and Assessments of Cyber Attack Resources - [Phishing in ccTLDs declines as remnants of Freenom registrations disappear](https://www.securityskeptic.com/phishing-in-cctlds-declines-as-remnants-of-freenom-registrations-disappear/) - 01/11/2024 09:51:08 AM My Interisle colleague and I published our quarterly phishing activity at the Cybercrime Information Center today. While phishing attack volume oscillated during 2023 - down during in the February - April 2023 period, up during the May - July 2023 period and down again for the August - October 2023 period - we still - [Cybercrime Supply Chain: Interviews with the Spamhaus Team](https://www.securityskeptic.com/cybercrime-supply-chain-interviews-with-the-spamhaus-team/) - 03/12/2024 01:03:41 PM The Spamhaus team recently interviewed me to learn more about Interisle's recent study, Cybercrime Supply Chain 2023, where we examine the supply chains used by cybercriminals to acquire resources for malware, spam, and phishing attacks. In Trends, policy and cheap TLDs - an interview with Dave Piscitello (Part 1), we dive into some of the - [Impersonation Phishing: Deception That Uses Exact Match Hostnames](https://www.securityskeptic.com/impersonation-phishing-deception-that-uses-exact-match-hostnames/) - 05/03/2024 10:55:12 AM Phishers have long embedded exact matches of brands in domain names that they register for phishing. Company, service, or product names in domains continue to deceive less technically savvy members of society. Phishers are increasingly using exact match strings to compose hostnames at free web sites for phishing. My Interisle colleagues and - [Cybercriminals ThriveD on a Greenfield Supply Chain in 2024](https://www.securityskeptic.com/cybercriminals-thrived-on-a-greenfield-supply-chain-in-2024/) - 11/18/2024 10:03:53 AM My Interisle colleagues and I today published our 2024 Cybercrime Suppy Chain study. We analyzed 16 million cybercrime events to expose a dramatic rise in criminal exploitation of name, address, hosting, and financial supply chains. In our report, we provide actionable insights for those aiming to curb cybercrime. Among the major findings - [What Can be Done to Reduce Phishing Attacks?](https://www.securityskeptic.com/what-can-be-done-to-reduce-phishing-attacks/) - 09/29/2025 09:05:00 AM Phishing in the 2020s: What Can be Done to Reduce Phishing Attacks? In this post my Interisle colleagues look at what users can do to avoid becoming victims of phishing and, importantly, what domain name, subdomain, and hosting providers need to be doing to prevent criminals from using their services for malicious - [The World's Phishiest Neighborhoods](https://www.securityskeptic.com/the-worlds-phishiest-neighborhoods/) - 04/09/2025 01:20:22 PM In this Interisle Insights article, I take a closer look at our Cybercrime Information Center phishing data to better understand what’s hosted at three autonomous systems which have extraordinary numbers of phishing attacks reported in recent quarters. I also review who’s being targeted by these attacks and what corresponding name and address resources are - [Making a case for gTLD domain registration restrictions](https://www.securityskeptic.com/making-a-case-for-gtld-domain-registration-restrictions/) - 04/11/2025 10:37:30 AM Interisle’s 2024 Cybercrime Supply Chain study, Phishing Landscape Study and quarterly public reporting for nearly 5 years consistently found that the new gTLD program has been a greenfield for phishers, spammers and other exploiters of the domain name system. Some TLDs, however, are demonstrating success in mitigating DNS abuse or otherwise have policies that make - [Death by a 1000 Paper Cuts: how foreign actors are bleeding a cyber-crippled US dry](https://www.securityskeptic.com/death-by-a-1000-paper-cuts-how-foreign-actors-are-bleeding-a-cyber-crippled-us-dry/) - 04/28/2025 09:47:25 AM Numerous US federal agencies that contribute to our national cybersecurity defenses have suffered sweeping job and program cuts. The disruptive effects on the FBI, DOJ, FTC, NIST, and CISA go far beyond the administration’s publicly stated domestic objectives. These cutbacks put the US at a disadvantage in its efforts to mitigate cybercrimes, cyber - [Challenges When Measuring Criminal Abuse of ccTLD Registrars](https://www.securityskeptic.com/challenges-when-measuring-criminal-abuse-of-cctld-registrars/) - 05/06/2025 08:43:48 AM My Interisle colleague Colin Strutt analyzes the data from the Cybercrime Information Center, we regularly report on the top-level domains (TLDs), gTLD Registrars, and Hosting Providers. In this article, we share our experiences with the challenges of identifying registrars associated with cybercrime domains registered in ccTLDs. Enjoy Challenges When Measuring Criminal Abuse of ccTLD Registrars. - [Give us four minutes, learn why phishing is the top cyberthreat](https://www.securityskeptic.com/2025-06-give-us-four-minutes-learn-why-phishing-is-the-top-cyberthreat/) - 06/04/2025 09:37:45 AM If you have four minutes and want to understand why phishing remains one of the top cyberthreats globally, watch this video. - [.TOP promises to reduce abuse. Offer a show of good faith](https://www.securityskeptic.com/2025-06-top-promises-to-reduce-abuse-offer-a-show-of-good-faith/) - 06/06/2025 01:26:09 PM A recent Domain Incite post reports that “ICANN said that it has been working with .TOP for months to put in systems aimed at reducing the abuse of .top domains” and that ICANN Compliance “acknowledged that the remedial measures were sufficient to cure the Notice of Breach.” I commented to Domain Incite’s Kevin Murphy - [Delivery Services Phishing](https://www.securityskeptic.com/22025-06-delivery-services-phishing/) - 06/30/2025 09:44:54 AM Postal and delivery services are among the most exploited verticals in phishing scams. Our data show that USPS continues to be the most exploited delivery service, and DHL is a distant second. Canada is happy to not be the 51st US State but no doubt concerned to find its postal service #3 in the Hearts - [Common Visual Deceptions in Phishing URLS](https://www.securityskeptic.com/2025-07-exploiting-well-known-tld-strings-in-domain-names/) - 06/26/2025 09:00:09 AM In a recent Interisle Insights post I explained how phishers choose domain names in such a way as to fool unsuspecting users by making them appear to be valid for the site they think they are reaching. Phishers take advantage of common user behavior. They know that people often see what they want to - [Exploiting well known TLD strings in domain names](https://www.securityskeptic.com/2025-07-exploiting-well-known-tld-strings-in-domain-names-2/) - 07/29/2025 09:50:17 AM In a recent Interisle Insights post I explained how phishers choose domain names in such a way as to fool unsuspecting users by making them appear to be valid for the site they think they are reaching. Phishers have adopted another kind of deception in domain name composition: they include well known TLDs within - [Contact](https://www.securityskeptic.com/contact/) - Your Essential Cybersecurity Resource Find comprehensive contact details here, including office locations, phone lines, and email contacts, so you can effortlessly connect with our team for support or questions. ## Categories - [Uncategorized](https://www.securityskeptic.com/category/uncategorized/) - [Category 1](https://www.securityskeptic.com/category/category-1/) - Use this description to tell users what kind of blog posts they can find in this category. - [Category 2](https://www.securityskeptic.com/category/category-2/) - Use this description to tell users what kind of blog posts they can find in this category. - [Category 3](https://www.securityskeptic.com/category/category-3/) - Use this description to tell users what kind of blog posts they can find in this category. - [Category 4](https://www.securityskeptic.com/category/category-4/) - Use this description to tell users what kind of blog posts they can find in this category. ## Tags - [Featured](https://www.securityskeptic.com/tag/featured/) - Use this description to tell users what kind of blog posts they can find in this tag.