A Stream of Endless Zero Days

Do you realize that we’re living in a world of endless zero days?

Information security is an overloaded and bloated market with fear tactics at every turn. Additionally, most software solutions are inadequate, 50% of software cannot recognize an intrusion and less than 30% of software can mitigate an event. There is no surprise that Chief Information Security Officers are in a constant state of distress. What would you personally think if you received an email such as this email below?

Hello. This will grab your attention.
You have used Zoom recently, like most of us during these bad COVID times. And I have very unfortunate news for you.
I’ll give you some background on what happened.

There was a zero day security vulnerability on Zoom app, that allowed me a full time access to your camera and some other metadata on your account.
I found a few interesting targets through random lookups. You were just unlucky to be on the list.
After that, I did some creepy stuff and a few recordings, just for fun and to test a few things.

And as you can imagine in your worst dreams, this happened. I have made a recording, where you work on yourself.

Please dont blame me or yourself for this, I didn’t have any bad intentions. I got very sick, lost my job, about to be evicted and have no money to survive.
All of this because of the stupid virus. I’m sorry. I have no other choice. I do not want you to be the next Jeffrey Toobin.
I’m sure you don’t want to be embarrassed. And I dont want to make this video public so your friends and colleagues can see it.

Let’s make a deal. You pay me $2000 in bitcoin, and nothing of this will happen. What happens next is up to you. I’ll give you 3 days to make the payment.
After you send the money, I will delete the video and forget about you forever. The amount is not negotiable.
Send 0.18 Bitcoin (about 2k at current exchange rate) to my wallet 1KrZBBPYXXRd21BNc6sWYK3qF4x1UnhboY
P.S. Don’t try to report this to police, I use TOR and bitcoin can’t be traced. Do not email me back. If you do something stupid, I will distribute the video.
Good luck! Don’t stress!

I know hg6bc1r4 is one of your password on day of hack..
Lets get directly to the point.

Not one person has paid me to check about you.
You do not know me and you’re probably thinking why you are getting this email?

in fact, i actually placed a malware on the adult vids (adult porn) website and you know what, you visited this site to experience fun (you know what i mean).

When you were viewing videos, your browser started out operating as a RDP having a key logger which provided me with accessibility to your display and web cam.
immediately after that, my malware obtained every one of your contacts from your Messenger, FB, as well as email account.
after that i created a double-screen video. 1st part shows the video you were viewing (you have a nice taste omg), and 2nd part displays the recording of your cam, and its you.

Best solution would be to pay me $2663.
We are going to refer to it as a donation. in this situation, i most certainly will without delay remove your video.

My -BTC -address: 19g7snNAuGedd42uQSKqp4ksq736Bwtmst

[case SeNSiTiVe, copy & paste it]

You could go on your life like this never happened and you will not ever hear back again from me.
You’ll make the payment via Bitcoin (if you do not know this, search ‘how to buy bitcoin’ in Google).

if you are planning on going to the law, surely, this e-mail can not be traced back to me, because it’s hacked too.

I have taken care of my actions. i am not looking to ask you for a lot, i simply want to be paid.

if i do not receive the bitcoin;, i definitely will send out your video recording to all of your contacts including friends and family, co-workers, and so on.

Nevertheless, if i do get paid, i will destroy the recording immediately.
If you need proof, reply with Yeah then i will send out your video recording to your 8 friends.

it’s a nonnegotiable offer and thus please don’t waste mine time & yours by replying to this message.

While it is commonly recognized that there are issues in software, what about design features to ensure security?

We are living in a period of constant ‘noise‘.