Capricorn I.T.

Capricorn I.T. Complete IT services providing on-site support within 100km/1hr of Kerang at no extra cost.

News reports about a dual US/Estonian citizen who was extradited to Chicago for alleged crimes that include participatin...
09/07/2026

News reports about a dual US/Estonian citizen who was extradited to Chicago for alleged crimes that include participating in a cybercrime syndicate are fixating on the fact that he was unmasked despite his use of a VPN.

A lot of users seem to have a limited understanding of what public VPN services can do and their limitations. In this short form article we will delve into the Achilles' heel for this individual, Microsoft Windows telemetry.

The article continues in the comments.

★ 2143: Final entry. Some good news for MVNO customers who were without credit and couldn't recharge their accounts - th...
07/07/2026

★ 2143: Final entry. Some good news for MVNO customers who were without credit and couldn't recharge their accounts - the APIs behind the functionality are now working meaning that those using Boost, ALDI, Belong, etc will have that functionality back. We also have a little bit of post incident discussion that seems to indicate that a loss of synchronization with Telstra's stratum 1 NTP (and more accurate pps) servers which are core to AAA and also general functioning of a LTE/5GNR network. Yes, there are supposed to be alternate clock sources (most sourcing data from GNSS), but that's their story as at this late hour. We likely won't know the true extent of what went wrong and why for some time, but multiple failures would have been needed as core infrastructure is designed to fail over and be redundant. There have been some persistent reports of LTE-M and other embedded devices eg public transit kiosks and ATM machines still having issues but this matter for the wider public should be firmly sitting in the "resolved" basket by the time you read this post.

★ 1232: In what can only be described as a terrible day for the telco, prepaid customers of Telstra and its in-house MVNO Boost have been unable to recharge their accounts. Worse still, data leakage has taken place with reports from users of 2FA text messages being sent to phone numbers entirely unrelated to their account. When contacted for comment, an individual at Customer Care called Janine confirmed that recharges/topups/rollovers were unable to be processed and there was no ETR for the fault at this stage.

★ 0810: Towers are beginning to open back up and normal service shouldn't be far away for outliers - it may pay to restart your phone or toggle airplane mode on and off to force a reconnection if you still have "No Service/SOS Only" on your screen.

★ 0800: many are reporting service is returning but it is still piecemeal with some areas remaining affected. Expect full resolution within the hour. The official Telstra outages checker at telstra.com.au/outages simply returns "something went wrong" when a postcode is supplied. Major news networks have taken this up including the ABC.

★ 0745: Emergency Management Minister Kristy McBain was quoted as saying "The Australian Government has been advised by Telstra that there is an outage affecting a large number of mobile calls and connections [..] We are also aware the issue is also affecting Victoria's V/Line regional train services. [..] We understand Telstra is working on resolving the issue, and arrangements are being made for affected rail passengers". While McBain stated "Australian phones are also required to fall back to other networks for 000 access" in rural areas there may be marginal coverage by other providers, leaving some in areas not serviced by Optus or Vodafone (which is a significant area especially in northern Vic when outside 20km of townships) with no emergency service access.

★ 0600: Mass outage affecting Telstra Mobile customers with many unable to authenticate and seeing "SOS Only" or "No Signal" (depending on if another carrier network is nearby for emergency calls to fail over to). This includes Boost and other MVNOs like ALDI etc.

19/02/2026

New chrome 0day that mitre has coined CVE-2026-2441 - Google has released a patch. This is being actively exploited so don't delay.

𝗖𝗩𝗘-𝟮𝟬𝟮𝟱-𝟭𝟱𝟱𝟱𝟲 𝗡𝗼𝘁𝗲𝗽𝗮𝗱++ 𝗖𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲If you thought a simple text editor was too simple a program to be an attack surface,...
06/02/2026

𝗖𝗩𝗘-𝟮𝟬𝟮𝟱-𝟭𝟱𝟱𝟱𝟲 𝗡𝗼𝘁𝗲𝗽𝗮𝗱++ 𝗖𝗼𝗺𝗽𝗿𝗼𝗺𝗶𝘀𝗲

If you thought a simple text editor was too simple a program to be an attack surface, best think again.

Notepad++ is a text editor that pretty much every Windows based power user has on their machine. The automatic update mechanism of the software has been revealed to be compromised, so please check your systems, refer to the CVE and the project website for updated packages.

MITRE reports on the CVE page that this is still under analysis. If your organization needs a security audit, pe*******on system or other advice, let us know!

Wishing our clients a very Merry Christmas, and hope that everyone has a great day no matter what you are doing today.
25/12/2025

Wishing our clients a very Merry Christmas, and hope that everyone has a great day no matter what you are doing today.

A paper entitled "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" b...
13/12/2025

A paper entitled "Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers" by Gegenhuber et al detailed how read receipts in messaging apps, even supposedly "secure" ones like Whatsapp and Signal, could be used to silently obtain information on the device state by tracking the round trip time. As a crude example, someone on LTE would have a higher round trip time than a person at home on fixed broadband.

The obvious fix is to delay read receipts by an arbitrary time with a minimum delay that exceeds that of the slowest likely connection and then add a random component to that, making the data less useful to bad actors but still achieving the original purpose. There's no need for the read notification to be sent immediately. Introducing a random delay between 200-400ms would render this far less useful. More importantly, no ability for a corrupt message to be sent that doesn't appear but does get acknowledged should exist, and there should be a rate limit.

Our advice is to disable read and delivered reporting in your messaging apps as unfortunately this has yet to be rectified by any of the players in the secure messaging space, and now proof of concept code has been released making this an attack that can and will be used. Those interested in reading more are encouraged to check the github page for gommzystudio/device-activity-tracker

You always need to make sure you use primary sources when at all possible. Some of the rumors circulating around are dow...
21/11/2025

You always need to make sure you use primary sources when at all possible. Some of the rumors circulating around are downright nutty, and I can't even post a few of them as they're sheer bonkers.

❌ No, this was not an attack on Cloudflare infrastructure.
❌ Nation state actors, and other fanciful stories did not play a part.

The true answer is far less interesting, but code got pushed into production that updated a table with bad data periodically which likely gave rise to the initial queries as to whether this was some kind of automated attack.

For those who wish to know all of the information, straight from Matthew Prince himself, the CEO and co-founder of Cloudflare (take the praise during earnings reports etc, but this guy at least is present when things don't go their way) you can read his post (which is very complete, but an after action report will no doubt also be created so lessons can be learned) at the Cloudflare blog at https://blog.cloudflare.com/18-november-2025-outage/

Do I still trust cloudflare? Absolutely. Their record speaks for itself, and this is merely a blip on an otherwise excellent company.

If you experienced intermittent connectivity to a large array of websites this evening, you're not alone. Cloudflare, pr...
18/11/2025

If you experienced intermittent connectivity to a large array of websites this evening, you're not alone. Cloudflare, probably one of the largest CDN around experienced an intermittent issue routing traffic from the public facing addresses, and the proxied hosts. Multiple theories went around from denial of service (unlikely given that Cloudflare is in the business of protecting against DDoS), to DNS/BGP and the usual offenders. The cloudflare blog, which is open to the public will include an after action report when things normalize.

Cloudflare reported at 1120 AEDT (UTC+11) that the issue was resolved and services were recovering, albeit warning that end users may see "higher-than-normal error rates".

Having had some experience with the company and the techs behind it, they run a very tight ship and I've got zero doubt that they pulled in all hands to get this sorted. Unlike some recent outages this was dealt with promptly and communication with both news media and users was excellent. An excellent lesson in how to manage a crisis.

The Cloudflare name and logo are property of Cloudflare, a US based company providing DDoS protection and CDN services.

Address

Kerang, VIC

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 10am - 6pm
Friday 9am - 5pm

Telephone

+611300451337

Alerts

Be the first to know and let us send you an email when Capricorn I.T. posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Capricorn I.T.:

Shortcuts

Share