According to the New York Times, "What gave the Russian hacking, detected more than two years ago, such global reach was its improvised search tool -- antivirus software made by a Russian company, Kaspersky Lab, that is used by 400 million people worldwide, including by officials at some two dozen American government agencies.
I seems I warned of this in 2012 in this post: Kaspersky, ex-KGB, Is Tool of Putin.
Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts
Wednesday, October 11, 2017
Thursday, August 11, 2016
Cyber Criminals Possibly Influencing US Presidential Election
PORTLAND, Ore. - August 11, 2016 - Tripwire today announced the results of a survey of over 220 information security professionals who attended Black Hat USA 2016on July 30-August 4, 2016.
Tripwire's opinion-based survey assessed how cyber security issues were impacting the current U.S. presidential election. When asked if cyber criminals were influencing the outcome of the upcoming election, nearly two-thirds (sixty-three percent) of the respondents said, "yes."
The FBI is currently investigating a high-profile breach of the Democratic National Committee’s computer network after its email content surfaced online. Security experts believe Russia may have orchestrated the hack to influence the outcome of the presidential election. Additionally, AndrĂ©s SepĂșlveda, a political hacker connected with manipulating elections across Latin America, said he was "100 percent sure" the U.S. presidential campaign was being tampered with in a controversial March interview with Bloomberg.
"This is an unprecedented moment in both politics and information security," said Tim Erlin, director of IT security and risk strategy for Tripwire. "A foreign power possibly influencing the U.S. presidential election through electronic means is a game changer for information security professionals. While these survey results aren't surprising, they are very important. We're seeing a significant shift in the role that information security plays on the global stage. While the DNC attack is the most visible, it's not the first incident. We've been building up to this type of event for a number of years."
Additional findings from the survey included:
• Eighty-two percent of the respondents believe state-sponsored attacks on elections should be considered acts of cyber war.
• The 2016 Republican Party platform states that victims of cyber attacks should have "a self defense right" to retaliate. Just over half of the respondents (fifty-five percent) believe this policy would improve national or global cyber security.
• Only ten percent of the respondents consider nation-state attacks to be one of the top two security threats their organizations face.
"In addition to considering nation-state cyber attacks to be an act of war, respondents favor an organization's right to strike back," said Dwayne Melancon, chief technology officer and vice president of research and development for Tripwire. "These two positions have one thing in common: a high margin for error. Attribution of cyber attacks is very difficult. For example, investigations sometimes discover that attacks appearing to come from other countries actually have a command and control base in the U.S., and vice versa. If a cyber attack escalates into war or retribution, you'd better be certain of its origin."
Erlin continued, "While it's clear that the majority of respondents believe state-sponsored attacks are an act of cyber war, there's little consensus on what an appropriate response should be. It's time for the conversation to move beyond true and false to defining an appropriate cyber war response."
Tripwire's opinion-based survey assessed how cyber security issues were impacting the current U.S. presidential election. When asked if cyber criminals were influencing the outcome of the upcoming election, nearly two-thirds (sixty-three percent) of the respondents said, "yes."
The FBI is currently investigating a high-profile breach of the Democratic National Committee’s computer network after its email content surfaced online. Security experts believe Russia may have orchestrated the hack to influence the outcome of the presidential election. Additionally, AndrĂ©s SepĂșlveda, a political hacker connected with manipulating elections across Latin America, said he was "100 percent sure" the U.S. presidential campaign was being tampered with in a controversial March interview with Bloomberg.
"This is an unprecedented moment in both politics and information security," said Tim Erlin, director of IT security and risk strategy for Tripwire. "A foreign power possibly influencing the U.S. presidential election through electronic means is a game changer for information security professionals. While these survey results aren't surprising, they are very important. We're seeing a significant shift in the role that information security plays on the global stage. While the DNC attack is the most visible, it's not the first incident. We've been building up to this type of event for a number of years."
Additional findings from the survey included:
• Eighty-two percent of the respondents believe state-sponsored attacks on elections should be considered acts of cyber war.
• The 2016 Republican Party platform states that victims of cyber attacks should have "a self defense right" to retaliate. Just over half of the respondents (fifty-five percent) believe this policy would improve national or global cyber security.
• Only ten percent of the respondents consider nation-state attacks to be one of the top two security threats their organizations face.
"In addition to considering nation-state cyber attacks to be an act of war, respondents favor an organization's right to strike back," said Dwayne Melancon, chief technology officer and vice president of research and development for Tripwire. "These two positions have one thing in common: a high margin for error. Attribution of cyber attacks is very difficult. For example, investigations sometimes discover that attacks appearing to come from other countries actually have a command and control base in the U.S., and vice versa. If a cyber attack escalates into war or retribution, you'd better be certain of its origin."
Erlin continued, "While it's clear that the majority of respondents believe state-sponsored attacks are an act of cyber war, there's little consensus on what an appropriate response should be. It's time for the conversation to move beyond true and false to defining an appropriate cyber war response."
Wednesday, February 10, 2016
The Institute for Critical Infrastructure Technology (ICIT) Releases the Encyclopedia of the Most Prominent Hacktivists, Nation State, and Mercenary Hackers
The Institute for Critical Infrastructure Technology, a leading cybersecurity think tank, has published its most recent research report entitled Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups. The report is an encyclopedia of bad actors stemming from the nation state, mercenary, and hacktivist arenas and details the characteristics and intricacies of the world’s most prolific threat groups.
Authors James Scott (ICIT Co-Founder and Senior Fellow) and Drew Spaniel (Visiting Scholar) cover threat groups not by use of a particular ranking system, rather by the dominant players categorized by geography, including China, Russia, Iran, and North Korea. Zero days, malware, tool kits, exploit techniques, digital foot prints and targets are covered in-depth. The report covers 40 bad actors including: Blue Termite, the Elderwood Platform, Deep Panda APT 30, APT 2, Tarh Andishan, Ajax, Dark Hotel, Bureau 121, Energetic Bear, Uroburos, Sofacy Group, the “Duke” family, Carbanak, SEA, Animal Farm, Hellsing. and Shrouded.
Friday, December 11, 2015
7 Largest Data Breaches of 2015
10Fold Reveals Seven Largest Data Breaches of 2015
Close to 200 Million Personal Records Breached Around the World
SAN FRANCISCO, CALIF. (Dec. 11, 2015) —10Fold, a full-service B2B technology public relations agency, today announced that more than 193.4 million personal records are vulnerable to identity theft and fraud attributed to the top data breaches of 2015. In its year-in-review, 10Fold analyzed 720 data breaches that occurred throughout the year and highlighted seven of the largest.
"As the research 10Fold has conducted clearly shows, security never sleeps. Each of the top seven data breaches compromised more than 5 million records, indicating that attackers are becoming stealthier, are employing more sophisticated techniques and are going after bigger and more lucrative targets," said Angela Griffo, vice president of the security practice at 10Fold. "What's more, our research indicates that cyber criminals are increasingly going after targets in the medical and healthcare verticals, which store valuable patient data that can't be reissued like a credit card. Looking at the top breaches at year's end allows us to detect patterns while also giving us a glimpse of what we can expect to see in the future."
News reports about the seven largest data breaches, which are listed below, indicated that each of the attacks affected more than five million users. 10Fold selected these data breaches based on independent research and review of third-party resources such as ID Theft Resource Center and Information Is Beautiful.
Largest Insider Breaches of 2015
1. Excellus BlueCross BlueShield: Excellus BlueCross BlueShield announced that it was the victim of a sophisticated attack after hackers gained access to its information technology systems dating as far back as December 2013. This attack followed a series of healthcare hacks that had started at the beginning of the year. The Excellus hack in particular compromised the personal identifiable information of more than 10 million members, making this the third-largest healthcare breach in 2015. The exposed information, which includes names, birth dates, Social Security numbers, member identification numbers, financial account information and claims information, leaves members vulnerable to fraud and identity theft.
2. Premera Blue Cross: One month after the breach at Anthem Blue Cross, Premera Blue Cross released a statement saying it had experienced a cyber attack affecting up to 11 million members. The hack was discovered by the organization on January 29 of this year, although the initial attack dates back to May 2014. Premera's investigation team determined that attackers infiltrated the organization's information technology system, which allowed them to access applicants' and members' personal information, such as names, birth dates, Social Security numbers, member identification numbers and bank account information. Affected customers included employees of Microsoft, Starbucks and Amazon.
3. VTech: VTech was hit by the first data breach to ever directly target children; an unauthorized party accessed customer data through the Learning Lodge app store customer database and Kid Connect servers on November 14. According to the company, the attack affected 6.4 million children and 4.9 million customer (parent) accounts worldwide, exposing personally identifying information such as names, passwords, IP addresses, download history, and children's gender and birth dates.
4. Experian/T-Mobile: Experian North America stated that attackers breached a server in one of its business units that contained personally identifiable information for approximately 15 million T-Mobile customers. The data included names, birth dates, addresses and Social Security numbers or an alternative form of ID, such as drivers' license numbers. The breach occurred, in part, because T-Mobile shared customer information with Experian to process required credit checks for service or device financing. Breaches such as these underscore that when customers share their information with a business, their personal data isn’t always kept private.
5. OPM: The Federal Office of Personnel Management announced that a cyber attack compromised the records of more than 21.5 million citizens, enabling attackers to gain access to highly personal information contained on background investigation applications. Altogether, the attack affected 19.7 million individuals who applied for security clearances, 1.8 million relatives and other government personnel associates, and 3.6 million current and former government employees. What's more, the stolen data also included 5.6 million fingerprint records belonging to the background-check applicants. According to news reports, the breach caused U.S. intelligence and law enforcement officials to be concerned about the theft of data on government forms submitted for security clearances. And with good reason — these applicants share detailed information about themselves, including mental-health history and previous relationships. Hackers that gain access to the identity and fingerprints of employees with existing security clearances can cause serious, and irreparable damage to users' privacy.
6. Ashley Madison: The hacker group identified as The Impact Team claimed to have accessed Ashley Madison’s user database, financial records and other proprietary information, including the personal data of 37 million users. A manifesto written by The Impact Team disclosed that the "full delete" feature on Ashley Madison was a lie — that the company did not scrub the personally identifiable information of customers who opted to have their profile and history deleted, but instead kept their payment information and purchase details, which hold identifiable information. The manifesto also instructed Avid Life Media (ALM), the parent company of Ashley Madison, to permanently delete the forums of Ashley Madison or they would release all customer information. ALM opted to keep the site running and consequently, The Impact Team released the customer records two months later.
7. Anthem: The largest healthcare data breach in history occurred at the beginning of 2015. Anthem announced in February that it was the victim of a data breach that resulted in the theft of approximately 78.8 million highly sensitive patient records. By the end of the month, Anthem disclosed that the breach likely impacted an additional 8.8 to 18.8 million non-patient records that included names, birth dates, Social Security numbers, addresses and employment data. The attack on Anthem was the beginning of a series of healthcare hacks this year, including assaults on Premera Blue Cross, CareFirst BlueCross BlueShield, UCLA Health Systems and Excellus BlueCross BlueShield.
Monday, November 16, 2015
6 CyberHacks That Will Affect Your Life in 2016
6 CyberHacks That Will Affect Your Life in 2016
As we are quickly marching toward the end of another year, Stephen Newman, CTO of Damballa, discusses the new types of cyber attacks that will likely see in 2016. He points out that these new types of attacks will draw everyone's attention to the lack of privacy and security in our interconnected world.
As we are quickly marching toward the end of another year, Stephen Newman, CTO of Damballa, discusses the new types of cyber attacks that will likely see in 2016. He points out that these new types of attacks will draw everyone's attention to the lack of privacy and security in our interconnected world.
Wednesday, May 13, 2015
Hackers Hit Starbucks Mobile Users to Steal Credit Card Credentials
Credit card hackers are targeting Starbucks gift card and mobile payment users and stealing from consumers' credit cards. This new scam is so ingenious, the cyber criminals don't even need to know the account number of the card they are hacking! By taking advantage of the Starbucks auto-reload feature, they can steal hundreds of dollars in a matter of minutes. Because the crime is so simple, it can escalate quickly.
"This hack underscores the need for companies to protect all of the sensitive information they hold on their customers," said Brendan Rizzo, technical director EMEA, HP Security Voltage. "Criminals are always looking for a way to exploit a system in a way that they can then turn into cold hard cash. In this case, there is a further risk in that the app stores and displays personal information about the user such as their name, full address, phone number and email address. Criminals could then use this information or sell it on for use in more targeted larger-scale spear-phishing or identity theft attacks. Beyond the threat to customers' sensitive data, companies need to be concerned with the impact such an event can have on their reputation and, ultimately, on their bottom line. A data-centric approach to security is the key cornerstone needed to allow companies to mitigate the risk and impact of these types of attacks."
"16 Million Starbucks customer who utilize their mobile payment service may have been compromised as part of a organized attack," observed Stephen Coty, chief security evangelist, Alert Logic. "There have been reports of the mobile app being manipulated to hijack funds once the mobile device is reloaded with funds from a credit or gift card. There has been conversations through Twitter about customers seeing fraud taking place with their Starbucks accounts. Starbucks has said that they process approximately $2 billion in mobile payments
"The timing of this attack is very interesting since, just about a week ago, Starbucks had an issue in their stores with their payment system not allowing for the processing of credit cards. Makes you think what exactly happened to the payment system that shut down the service for a day and gave attackers an opportunity to compromise a part of their system."
Gavin Reid, VP of threat intelligence, Lancope, points out that, "Nothing too new here – if you guess the username and password for an account that is backed by you bank bad things can and will follow. This highlights problems with using consumer cards and accounts that are backed up with either a high limit credit card or even worse the current checking account. Ideally vendors would make this form of compromise harder by using multi factor authentication and the banks themselves would issue one-time-use account numbers that contain a fixed amount of cash limiting the loss. This type of small amount theft can be automated reusing already exposed credentials. Consumers can protect themselves by setting hard to guess unique passwords."
Thursday, March 12, 2015
Protecting Healthcare Records from Cyber Attacks Is a Game of Cat and Mouse
Protecting Healthcare Records from Cyber Attacks Is a Game of Cat and Mouse
By Mike Potts, CEO, Lancope
The never-ending battle between healthcare organizations and cyber attackers has always been like a game of cat and mouse. The hacker plays the role of the mouse, constantly trying to sneak past the company’s cat that is guarding information. For years, the cat not only consistently beat the mouse, he would help his fellow cats identify new mice and keep them out of their cupboards too. But as the successful data breaches over the past year demonstrate, including one earlier this year that made headlines after millions of health insurance records were compromised, the mice are now kicking the cats in their tails.
As the healthcare sector continues its collective effort to move to a 100-percent electronic records system, these recent attacks should serve to do two things. First, it should shine a light on why your existing cybersecurity system is likely inadequate – even if it complies with HIPAA’s Security Rule. Second, it should prompt you to immediately call your CSO, CIO and IT administrators into your office to overhaul your security posture and establish new employee education and incident response training programs.
While you may not have thought of this industry as a primary target for attackers, I hope you understand that cyber criminals consider healthcare information just as valuable as credit card numbers and other financial records if not more so given the longer shelf life of social security numbers and other personal information. And furthermore, traditional security solutions alone are incapable of keeping thieves out of your network. Healthcare security needs a more holistic approach that keeps watch both outside and inside your network and can help your security personnel more quickly identify and remediate threats. Here is why:
A Game of Cat and Mouse
Your first question might be, “what happened to the cat that I thought was such an effective guard?” Actually, the question you should be asking first is “what’s happened to the mouse to make him so much better at sneaking past the cat-guarded gate?”
The mouse has become faster, smarter and more agile. His motivations have evolved too, from hacking into systems to gain public notoriety and praise from his fellow mice, to silently and anonymously stealing information for financial gain.
In fact, the cat often does not even realize the mouse has snuck in and has been sitting for weeks, possibly months, stealing whatever it finds valuable.
The solution is not to add more cats that keep their ever-watchful eyes trained outside your network in order to spot outside attackers from trying to get in. That’s still important, the cat hasn’t become obsolete. But now building a better mouse trap requires a more holistic approach that guards both from the outside-in and from the inside-out.
This requires monitoring activity across your entire network in real time, including who is accessing and moving data stored in third-party cloud-based services like Dropbox or Salesforce.com. Simply put, security cannot be a one-time “set it and forget it” process.
In addition to implementing technology tools to enable you to see who is in your network and what, exactly, they are doing, you need to educate and train all of your employees, not just those in the IT department. Practice makes perfect. Just as you run regular fire drills, do the same to ensure your teams know what to do when a security threat is identified outside or inside your network? You want to put out a fire in a trash can long before it becomes a blaze that engulfs the whole building and causes irreparable damage.
A Holistic Approach
There’s no sugar-coating this fact: it’s likely only a matter of time before a breach occurs. You still want to lock your front doors (a.k.a. your perimeter), but don’t put all your eggs in that one basket. You have to balance your cybersecurity technology budget and include tools that provide your security team with the intelligence, visibility and forensic IR capabilities they need to identify when someone picks the lock and shut them down before any significant damage is done.
Also, for more information about just how serious the insider threat has become to healthcare organizations, please review the infographic “The Reality of Insider Threats” at http://www.lancope.com/resources/infographics/reality-insider-threats
Wednesday, December 17, 2014
Crimeware-as-a-Service Banking Malware
SophosLabs researcher James Wyke analyzed the malware family Vawtrak used primarily to steal money from victims’ banking and other financial account. The analysis indicates that the people behind the malware are running the crimeware-as-a-service, targeting specific geographic regions and institutions including Bank of America, Wells Fargo, Capital One, Citigroup, Chase, and Fidelity banks. Banks in Canada include TD Bank, Scotia Bank and Desjardins.
Sophos found Vawtrak was the second most popular malware distributed by web-based exploit kits between September-November 2014 representing 11% of all malware replacing Zbot as the leading banking malware botnet. Vawtrak operators are setting up the botnet to deliver crimeware-as-a-service, rather than following a more traditional kit-selling model that older families such as Zeus or SpyEye once employed.
Friday, December 5, 2014
Varonis Perspective on the Sony Breach
This is an amazing story. It's all about not paying attention in Security 101. In the following unattributed analysis, Varonis adds detail and insight on this breach.
FROM VARONIS:
While we have few details on the Sony Pictures attack itself, this very public breach—or pwning in hacker slang--has shown the extent of the actual exposure—it is massive. The always informative Krebs knows, at this point, as much as the rest of us—possible North Korean connection and perhaps the use of destructive erase-all malware. That’s not to say this incident hasn’t revealed significant insights about our collective data security practices: don’t think the Sony incident doesn’t apply to you!
Krebs provides a link to the sprawling Sony directory hierarchy. This should definitively settle any doubt about the scope of this thing.
There are a few points to make.
Unlike the big-box retailer incidents, this breach is not, for the most part, about personally identifiable information or PII. Certainly, there are employee social security numbers, email addresses, passwords, and health identifiers that are now out there for the world to see. But the Sony breach does not involve millions of consumer records and the subsequent issuing of new credit card numbers along with subscriptions to credit monitoring services.
This incident, though, is centered on sensitive data, perhaps even valuable IP, which was found in the 25 gigabytes of file data scooped up by the hackers. The leaked information should look all too familiar to any worker in a larger organization: readable files and emails, or, as we like to refer to it, unstructured, human-generated data. So we’re talking employee salaries, financial data, internal presentations, company information under NDA, legal memos, the CEO’s private notes, and on and on.
We should add that plain-text user passwords were found in files named, um, passwords. They certainly violated the "prime directive" on credentials.
From a broader perspective, we expect this is just one very public instance of a problem that can be found in enterprises globally. The amount of human-readable formation is growing exponentially. These documents live in file shares, intranets and in email as attachments, where far too many people have far more access than they really need, and usage is rarely monitored or analyzed for abuse.
No one should be casting any stones: we have all been or are Sony.
As we’ve seen in other breaches, the compromise of one employee email account can expose troves of sensitive data. It’s likely the hacker harvested credentials —not necessarily of privileged admins or power users-- through PtH and other techniques. With their group memberships and access rights, combined with a loosely permissioned file system, they had a panoramic view of the Sony data landscape.
How did the situation get to be so dire? Consider these two very common business-as-usual scenarios:
Scenario 1: A folder, containing sensitive data, becomes accessible to large group of people
A folder on your network share is used by your HR department—it might even be someone’s "home drive." At some point, someone makes the folder accessible to a broad group of people (this happens a lot), and it’s forgotten. Usage information about this folder (who is opening, creating, deleting, changing, moving files) isn’t tracked or analyzed (this is the norm).
Over time, sensitive files—say salaries, financial data, etc.—accumulate in these publicly sharable folders. No one really thinks about it, but everyone knows that a certain presentation or spreadsheet is just there so there's no need to formally request the data from the relevant owner. It's a data exposure incident waiting to happen, requiring a hacker to gain access to an average users' credentials—a simple phish mail often will do.
Scenario 2: Company emails become web browser enabled and gets hacked
You’ve enabled web browser access to your email system (try mail.yourcompany.com or owa.yourcompan.com if you're wondering), so anyone can log into their email from anywhere with only their password. Usage information about your email system is not tracked or analyzed (you can’t see who is sending or reading email or reading and marking them as unread, etc. – this is also the norm). The hacker gains the password of the email account—maybe by just guessing it. Now the attacker can log in and read all the executive’s email (including the attachments) without leaving his home – and no one will know. Again, very valuable information—merger talks, new customers—in readable formats.
Another Teachable Moment
As Sony’s hackers gained access to more than just passwords, but movie budgets, salaries, social security numbers, health care information and so much more, the Sony breach provides us with yet another teachable moment. It reminded us all the importance of proper access controls, identification of sensitive data – who has access, who is using it, where it’s overexposed to the everyone group and who it belongs to, as well as implementation of real-time alerts.
Friday, October 31, 2014
Cybersecurity Nightmares
It's Halloween, and it's not just trick-and-treaters that scare us, or TK Keanini. Keanini, Chief Technology Officer at Lancope, has compiled a number of short and horrifying cybersecurity scenarios entitled "Welcome to My Cyber Security Nightmare."
Welcome to My Cybersecurity Nightmare
This past year, we have seen some pretty scary stuff happen in cybersecurity. Being that Halloween is almost here; I thought I would share with you some scenarios that keep me up at night. These are scenarios that we are not ready to battle, and that are well beyond the horrific headlines we read on a daily basis. If you enjoy a good scare, read on.
User Participation in Cyber-Attacks
Most of the resources cybercriminals use to carry out their objectives are acquired through some method that results in compromised computers on the Internet. These resources remain available until the user or organization detects and remediates the incident. But what if the user participated willingly? Instead of bad guys having to compromise hosts, what if they instead cut other people such as corporate insiders in on the profits? Given crypto currency, the TOR network, and a few other factors, this could be a nightmare scenario, as we are not ready for this type of surge in distributed attacks.
The recruitment for this could be something like the ‘work from home’ signs you see around your town. The work could be as easy as downloading and installing a package and could earn the host user as much as $10.00/day. That is $300.00/month for someone to simply leave their computer running and connected. The average citizen is not likely to know what type of activity their computer is involved in on a daily basis.
The end result of this scenario would be a massive number of networked computers available for distributed denial-of-service, cryptographic brute forcing, or remote network sniffing. With the cooperation of the host, the capability list is endless, and because they are making money, the host will be motivated to help the cybercriminals persist. Service providers and law enforcement are not ready for this type of attack. This could lead to botnet armies with size and capabilities we have never seen before.
Expansion of Capability Marketplaces
Another nightmare scenario is for cybercriminals to expand their marketplace networks. Today you look at coordination networks like Uber, Instacart, Care.com, etc. These services are facilitators connecting a consumer who wants something delivered with a network of people who can deliver it.
Now think of applying this pattern to cybercrime. On one end there is a criminal who would like the login credentials of a Global 2000 executive. Via TOR networking, they go to a site where they can place their request, submit their crypto currency, and a skilled global workforce accepts this objective and delivers it within the terms of the agreement. This lowers the coordination cost for cybercrime to near zero and connects the demand with the supply in ways that have never been seen to date.
Because so many people are motivated by money, a service like this could turn citizens into cybercriminals if they believe they cannot get caught and that they can easily make a few bucks on the side.
The last thing I will say about this type of participation and marketplace networks is that they fragment security events into small, seemingly disconnected pieces where one event might not look harmful, but only when seen as a whole can the impact and significance be evaluated.
The Next Level of Cybercrime: Click to Compromise
Consider a SaaS service that helped a person compute their cybercrime – Cybercrime as a Service.
The power of big data analytics and machine learning can compute amazing insight for businesses, and it can do the same for criminals. A criminal could log in to a website and declare their objective, and the service would compute several attack plans that the criminal could choose from. This would work in the same way that a user is presented with multiple routes to reach a destination when getting directions online.
This Cybercrime as a Service would have social networks mapped, personal information on each individual, language analysis that yields a level of trust between individuals, mapping to various accounts (some of which may have been compromised), etc. All of this would be creating a corpus of data that can lead the criminal through a directed graph leading to the objective (exfiltration of a file, ransomware, etc.).
Remember, cybercrime is a business and profitable businesses only get smarter and more effective. These are things that keep me up at night because in our current state, there is nothing that makes these types of attacks hard to execute for cybercriminals, and they could easily turn from nightmare to reality.
Thursday, September 25, 2014
PBS Nova: Rise of the Hackers
Great show last night. Quantum computing will kill security as we know it; but quantum cryptography will trump it and win.
Wednesday, May 28, 2014
New Online Banking Trojan Program Combines Zeus and Carberp Features
How sweet is this? Zberp, the new threat, has a wide range of features, and is sure to provide hours of fun and challeges to security mavens.
Commenting on this, Lancope CTO, TK Keanini, said, "Attackers continue to innovate and are not afraid of borrowing techniques from one another. The trend is definitely to leverage toolkits and libraries from each other, as no one bad guy has to code it all himself anymore.
Another trend is that most of their communication channels are encrypted so this is bad news for packet inspection tools. Even if you capture terabytes of packets, the payloads are encrypted. This is where Netflow and IPFIX flow analysis comes in handy because directionality and other behavioural traffic patterns can identify infections even if the channels are using SSL.
As attackers continue to innovate, it is time that defenders do the same. Get creative, think like the adversary and be creative with your countermeasures. This is exactly what the adversary does not want you to do."
Commenting on this, Lancope CTO, TK Keanini, said, "Attackers continue to innovate and are not afraid of borrowing techniques from one another. The trend is definitely to leverage toolkits and libraries from each other, as no one bad guy has to code it all himself anymore.
Another trend is that most of their communication channels are encrypted so this is bad news for packet inspection tools. Even if you capture terabytes of packets, the payloads are encrypted. This is where Netflow and IPFIX flow analysis comes in handy because directionality and other behavioural traffic patterns can identify infections even if the channels are using SSL.
As attackers continue to innovate, it is time that defenders do the same. Get creative, think like the adversary and be creative with your countermeasures. This is exactly what the adversary does not want you to do."
Friday, January 17, 2014
Target Breach Notification Cautions
According to security firm Sophos, "the number of Target data breach victims is increasing with rumblings of records dating back more than a decade being impacted.
"With the high number of individuals receiving data breach notifications, it's important that you remember security best practices. Beware of clicking on links received in e-mails without first checking the link to ensure it is taking you to the desired site. Hackers frequently use this phishing technique to mislead consumers and direct traffic to malicious sites.
"If you encounter a suspect link, contact the vendor directly by typing in the company address directly in the browser.
"An examination of Target’s breach notifications may confuse some consumers and could easily be mistaken for phishing. James Lyne, global head of security for Sophos includes examples and further detail here.
"There are bound to be many copycat hackers jumping on this trend and telling good from bad content is going to be difficult for consumers."
I don't recall buying anything from Target, ever, but yesterday received an email from target.com with the subject: Important message from Target to our guests. Guests? Does this mean anyone who has ever hit the site, or do guests=customers? The message was signed by Target's CEO and offered one year of free credit monitoring. I didn't click through for the offer.
Tuesday, April 2, 2013
How the Biggest DDOS Attack in History Could Have Been Easily Avoided, or Not
Varonis technical director Rob Sobers explains how organizations have to focus on the basics and gives a top 5 list for defense.
Tuesday, February 12, 2013
TV station hacker warns of zombies in Montana
The Walking Dead? Really? The scary thing about this is "The Great Falls Tribune reports the hoax alert generated at least four calls to police to see if it was true."
Seems like something Orson Welles might do, although he wouldn't have had to hack in because he already had access to the airwaves. I guess people today are just as guiible as people in the 1930s.
Seems like something Orson Welles might do, although he wouldn't have had to hack in because he already had access to the airwaves. I guess people today are just as guiible as people in the 1930s.
Wednesday, August 29, 2012
Hotel Keycard Lock Hacker Questions Firmware Fix
"... guests literally reaching for their deadbolts."
Deadbolts won't help when you're not in the room. I recall a conversation about this at an ASIS conference a few years ago. Then it was more of a privacy issue; for example, the management systems records when the door was opened, and by whom. It's not unlike using EZPass to record who goes where and when, or mobile phone GPS data to track movements. Law enforcement and divorce lawyers have a field day with this.
Because hackers can unlock and start cars, not to mention hijack drones, why should we be surprised they can spoof keycards?
Deadbolts won't help when you're not in the room. I recall a conversation about this at an ASIS conference a few years ago. Then it was more of a privacy issue; for example, the management systems records when the door was opened, and by whom. It's not unlike using EZPass to record who goes where and when, or mobile phone GPS data to track movements. Law enforcement and divorce lawyers have a field day with this.
Because hackers can unlock and start cars, not to mention hijack drones, why should we be surprised they can spoof keycards?
Monday, April 23, 2012
Mac trojan fallout: Apple security glory days gone?
There are cults in IT. UNIX is one; Macs is another. These cultists fervently believe their OS is superior to others, and, by extension, they're superior to everyone else.
When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?
When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?
Tuesday, March 27, 2012
National Security-Related Agencies Have No ITC Supply Chain Risks?
Last week, the GAO said that defense-related departments have a security problem because of software, hardware, and components sourced or manufactured overseas, especially China. The departments in question don't track these items, and maintain that no threat exists, or the cost of monitoring exceeds the cost of the risk. This is disingenuous at best.
Now, today, the GAO reports that suspect counterfeit electronic parts can be found on DOD supply chain Internet purchasing platforms.
I recall Whitfield Diffie addressing a RSA conference state that one of his greatest security fears is components calling home (to China). This type of threat has movie written all over it, but this doesn't make it any less real.
Australia has no such qualms, however. It's blocked Huawei from bidding on gear for its National Broadband Network. It seems that foreign governments, especially in Asia, are much more aware of these threats. At least the US Congress has blocked sale of some US high-tech companies to Chinese enterprises controlled by the PLA.
There are other IT security lessons that Australia can teach us.
Now, today, the GAO reports that suspect counterfeit electronic parts can be found on DOD supply chain Internet purchasing platforms.
I recall Whitfield Diffie addressing a RSA conference state that one of his greatest security fears is components calling home (to China). This type of threat has movie written all over it, but this doesn't make it any less real.
Australia has no such qualms, however. It's blocked Huawei from bidding on gear for its National Broadband Network. It seems that foreign governments, especially in Asia, are much more aware of these threats. At least the US Congress has blocked sale of some US high-tech companies to Chinese enterprises controlled by the PLA.
There are other IT security lessons that Australia can teach us.
Monday, March 26, 2012
Hackers breached 174 million records in 2011. Did it make the Guinness Book of Records?
Verizon's breach report notes that hackers breached 174 million records in 2011. This seems like a lot of record, but is it a world record? I wonder what would happen if the hackers of the world decided to go for a world record? Would competition and one-upmanship drive the numbers ever higher?
Tuesday, February 14, 2012
Mobile payments will boost crime
Well, here's another "dog bites man" story. Is there any technical advance that won't boost crime? Don't all these advances become challenges to those with a criminal bent, or just curious? I'm not at ease with this, even though I use online banking. I'm still not sure how banks allow deposits based on a photo from a smartphone. Seems like that's ripe for abuse, too.
Subscribe to:
Posts (Atom)