New York Times: Many months behind schedule, the Department of Defense on Friday issued a new policy that, on the surface, seems likely to expand access to popular social networking sites like YouTube, Facebook and Twitter by troops using military computers. ... The new policy, which can be found here, says that the default policy of the department will be to allow access to social networking sites from the military’s non-classified computer network, known by its acronym, NIPRNET (for Non-classified Internet Protocol Router Network.)
Showing posts with label Social networks. Show all posts
Showing posts with label Social networks. Show all posts
Friday, February 26, 2010
Tuesday, February 2, 2010
Twitter Asks Users To Reset Passwords After Possible Phishing Attack
Washington Post: Twitter is locking many users out of the system this morning, and sending them notices that they need to change their passwords in order to regain access to the service, due to concerns over a possible phishing attack.
Read more ...
Read more ...
Wednesday, January 20, 2010
NY Times: The 3 Facebook Settings Every User Should Check Now
In December, Facebook made a series of bold and controversial changes regarding the nature of its users' privacy on the social networking site. The company once known for protecting privacy to the point of exclusivity (it began its days as a network for college kids only - no one else even had access), now seemingly wants to compete with more open social networks like the microblogging media darling Twitter.
Read more ...
Read more ...
Friday, December 18, 2009
Web Attack on Twitter Demonstrates Deep Internet Risk
What's happening: Users going to Twitter Friday morning arrived instead at a site for the “Iranian Cyber Army.” The online attack was the result of the most basic of security breaches: someone got the password to enter the master directory of Twitter’s Internet addresses (Twitter's master DNS or Domain Name Server) and redirected users to the “Iranian Cyber Army" site instead.
What it means: There are two levels of meaning here. The obvious level is that social network sites continue to demonstrate that they have yet to get system security under adequate management control.
At a deeper level, consider that users were redirected from Twitter to the “Iranian Cyber Army" site. What if it weren't Twitter but your favorite eCommerce site and instead of being sent to the “Iranian Cyber Army" site you were presented with a site that looked identical to the site you thought you were going to—except that it stole your credit card information or installed malware on your computer.
And what if it's not your favorite eCommerce site but your own company's web site. And now every visitor going to your web site is at risk that malware will be installed on their computer.
What to do: Keep computers patched. Run an intrusion detection and prevention program instead of basic anti-virus. To protect your company's web site, make absolutely positively certain that IT staff is securely managing the master passwords to your company's DNS.
**********************************
Web Attack on Twitter Is Third Assault This Year
What it means: There are two levels of meaning here. The obvious level is that social network sites continue to demonstrate that they have yet to get system security under adequate management control.
At a deeper level, consider that users were redirected from Twitter to the “Iranian Cyber Army" site. What if it weren't Twitter but your favorite eCommerce site and instead of being sent to the “Iranian Cyber Army" site you were presented with a site that looked identical to the site you thought you were going to—except that it stole your credit card information or installed malware on your computer.
And what if it's not your favorite eCommerce site but your own company's web site. And now every visitor going to your web site is at risk that malware will be installed on their computer.
What to do: Keep computers patched. Run an intrusion detection and prevention program instead of basic anti-virus. To protect your company's web site, make absolutely positively certain that IT staff is securely managing the master passwords to your company's DNS.
**********************************
Web Attack on Twitter Is Third Assault This Year
Sunday, December 13, 2009
Viruses That Leave Victims Red in the Facebook
What's happening: Malware is spreading through Web sites like Facebook and Twitter. After stealing a Member's screen name and password, these malicious programs are coded to automatically send spam messages to the Member's friends and followers. Unsuspecting friends have been asked for money, have been directed to web-sites where malware is installed on their computers, and have had their user-names and passwords to online bank accounts stolen.
What it means: Social networks continue to be the wild wild west of the internet.
What to do: Stay vigilant. Be suspicious. Report suspected problems. And use a strong hard-to-break password.
**********************************
Viruses That Leave Victims Red in the Facebook
What it means: Social networks continue to be the wild wild west of the internet.
What to do: Stay vigilant. Be suspicious. Report suspected problems. And use a strong hard-to-break password.
**********************************
Viruses That Leave Victims Red in the Facebook
Friday, December 11, 2009
Security Alert: Check your Facebook 'privacy' settings now
What's happening: Facebook has made major changes that may allow complete strangers to see your personal photos and videos, date of birth, family relationships, and other sensitive information.
What it means: Unless you act to control who gets to see your private information, Facebook may let anyone see it, friend or foe alike.
What to Do: Follow the advice of Washington Post's Brian Krebs in the blog link below.
**********************************
Check your Facebook 'privacy' settings now
What it means: Unless you act to control who gets to see your private information, Facebook may let anyone see it, friend or foe alike.
What to Do: Follow the advice of Washington Post's Brian Krebs in the blog link below.
**********************************
Check your Facebook 'privacy' settings now
Tuesday, November 10, 2009
Hundreds of Facebook Groups Hacked
What's happening: A hacker, or group of hackers, has taken over up to 300 different Facebook groups.
What it means: Facebook has again shown that its security controls are inadequate to keeping hackers from misusing their network. Cybercriminals and other miscreants continue to have their way with social network sites. This puts the burden of security on end-users like you and me.
What to do: Don't assume Facebook is protecting your security. They can't. Take responsibility for protecting yourself.
**********************************
Hundreds of Facebook Groups Hacked
What it means: Facebook has again shown that its security controls are inadequate to keeping hackers from misusing their network. Cybercriminals and other miscreants continue to have their way with social network sites. This puts the burden of security on end-users like you and me.
What to do: Don't assume Facebook is protecting your security. They can't. Take responsibility for protecting yourself.
**********************************
Hundreds of Facebook Groups Hacked
Wednesday, October 28, 2009
Facebook users attacked with phony password reset emails
What's happening: Facebook users are receiving emails saying their passwords have been reset and instructing them to open an attachment containing their new passwords.
What it means: Users opening the attachment risk having their computers taken over by cyber-criminals.
What to do: Make sure the IT Department is blocking these messages at the spam filter. Alert staff to disregard these emails, both at work and at home, should they get through spam filters. Consider replacing your anti-malware solution with an intrusion detection and prevention system..
**********************************
Computer World: Massive bot attack spoofs Facebook password messages. 'Bredolab' Trojan rides fake reset messages, reaches at least 735,000 users
A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers.
http://www.computerworld.com/s/article/9140058/Massive_bot_attack_spoofs_Facebook_password_messages?source=CTWNLE_nlt_security_2009-10-29
What it means: Users opening the attachment risk having their computers taken over by cyber-criminals.
What to do: Make sure the IT Department is blocking these messages at the spam filter. Alert staff to disregard these emails, both at work and at home, should they get through spam filters. Consider replacing your anti-malware solution with an intrusion detection and prevention system..
**********************************
Computer World: Massive bot attack spoofs Facebook password messages. 'Bredolab' Trojan rides fake reset messages, reaches at least 735,000 users
A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers.
http://www.computerworld.com/s/article/9140058/Massive_bot_attack_spoofs_Facebook_password_messages?source=CTWNLE_nlt_security_2009-10-29
Thursday, October 1, 2009
Protecting Your Business from Social Networking Attacks
Sally, the accounting manager of Acme Enterprises, a medium-sized business, regularly checked her Facebook account while at work. One day she received an email. The email said that a long-lost friend, Bob, had added her as a friend in Facebook. There was a link in the email for Sally to follow to confirm the friend request. Sally clicked the link. Over the next week, cyber-thieves withdrew nearly $1,000,000 from her employers' bank account.
Welcome to the newest nastiest twist in cybercrime.
You see, the email wasn't from Bob and the link didn't go back to Facebook. Bob's on Facebook just like Sally is. That's how the cyber-thieves found them and discovered that they might know each other. That's also where they learned that Sally worked in the accounting department.
After that it was a simple matter to set the trap by sending Sally a friend request from Bob. "How great," thought Sally, "an email from Bob. Let me just follow this link and we can be friends again."
Link followed. Trojan horse installed. $1,000,000 stolen.
According to Breach Security, the number of web security incidents was up 30 percent in the first half of 2009. And social networking sites like Facebook, MySpace and Twitter were the target of 19% of all attacks, more than any other category. That's a big change from last year's report when government networks were the most often attacked and social networks weren't even on the list.
Making matters worse, many of these attacks succeed by taking advantage of missing patches and using obscure technology like "0-day exploits" that get past traditional antivirus and antispyware defenses.
As if that's not bad enough, businesses shouldn't expect their banks to cover losses. Regulation E of the Federal Deposit Insurance Corporation (FDIC) stipulates consumers are protected by cyber crime involving their banks. The FDIC regulation does not cover businesses, however.
Here are five things you can do to inoculate your business against social network attacks:
Thanks to our friends at Lighthouse Consulting who were kind enough to publish this in their newsletter.
Welcome to the newest nastiest twist in cybercrime.
You see, the email wasn't from Bob and the link didn't go back to Facebook. Bob's on Facebook just like Sally is. That's how the cyber-thieves found them and discovered that they might know each other. That's also where they learned that Sally worked in the accounting department.
After that it was a simple matter to set the trap by sending Sally a friend request from Bob. "How great," thought Sally, "an email from Bob. Let me just follow this link and we can be friends again."
Link followed. Trojan horse installed. $1,000,000 stolen.
According to Breach Security, the number of web security incidents was up 30 percent in the first half of 2009. And social networking sites like Facebook, MySpace and Twitter were the target of 19% of all attacks, more than any other category. That's a big change from last year's report when government networks were the most often attacked and social networks weren't even on the list.
Making matters worse, many of these attacks succeed by taking advantage of missing patches and using obscure technology like "0-day exploits" that get past traditional antivirus and antispyware defenses.
As if that's not bad enough, businesses shouldn't expect their banks to cover losses. Regulation E of the Federal Deposit Insurance Corporation (FDIC) stipulates consumers are protected by cyber crime involving their banks. The FDIC regulation does not cover businesses, however.
Here are five things you can do to inoculate your business against social network attacks:
- Prohibit use of social network sites from the office. These sites can be blocked at the corporate firewall. This can become particularly challenging if employees work remotely as it may not be feasible to block access to social networks from home computers. Making matters worse, Trojan horses are like communicable diseases and Sally's work-at-home computer can be infected from her son's. That's why the next four recommendations are so important.
- In addition to antivirus / antispyware defenses, add advanced defenses like intrusion detection and prevention designed to block internet-based attacks like the link in Sally's email and 0-day exploits.
- Your IT staff can block known internet-based attacks by comparing links against a database of known bad links like www.stopbadware.org/home/reportsearch.
- Keep your systems patched. This means not just Windows patching but all your applications, those you know about - like Office and Adobe Reader - and those you might not even know about - like Flash and Java. This also includes your Macintosh computers as they are every-bit as vulnerability-prone as Windows PCs.
- Finally, don't expect to rely on technology alone. Users are often the weakest link so it's very important to train them to detect the subtle signs of an attack so they can keep from becoming victims. They also need to be given guidance on what information is safe to put on a social networking site. Sally put a big bulls-eye on her back when she wrote that she works in Acme's accounting department.
Thanks to our friends at Lighthouse Consulting who were kind enough to publish this in their newsletter.
Tuesday, September 22, 2009
Cyberthieves using Twitter to sell fake antivirus software
What's happening: Cyberthieves are taking advantage of security weaknesses in Twitter to take sell them fake antivirus software
What it means: The Twitter situation corroborates IBM's recent study of web security in which they wrote: The result is "an unprecedented state of Web insecurity as Web client, server and content threats converge to create an untenable risk landscape," according to the report." See our blog posting http://citadelonsecurity.blogspot.com/2009/08/ibm-online-threat-report-trust-no-one.html.
What to do: Don't fall for online ads "scareware." Keep your systems patched -- not just Windows but Acrobat Reader, JAVA, Flash and all the other software on your PC. Keep Twitter, Facebook and other social sites out of the corporate environment. Consider replacing antvirus / antimalware solutions with intrusion detection / prevention solution.
**********************************
From Computerworld: Scammers auto-generate Twitter accounts to spread scareware.
They use bogus accounts, real tweets, to dupe people into installing fake antivirus software.
http://www.computerworld.com/s/article/9138361/Scammers_auto_generate_Twitter_accounts_to_spread_scareware?source=CTWNLE_nlt_security_2009-09-22
What it means: The Twitter situation corroborates IBM's recent study of web security in which they wrote: The result is "an unprecedented state of Web insecurity as Web client, server and content threats converge to create an untenable risk landscape," according to the report." See our blog posting http://citadelonsecurity.blogspot.com/2009/08/ibm-online-threat-report-trust-no-one.html.
What to do: Don't fall for online ads "scareware." Keep your systems patched -- not just Windows but Acrobat Reader, JAVA, Flash and all the other software on your PC. Keep Twitter, Facebook and other social sites out of the corporate environment. Consider replacing antvirus / antimalware solutions with intrusion detection / prevention solution.
**********************************
From Computerworld: Scammers auto-generate Twitter accounts to spread scareware.
They use bogus accounts, real tweets, to dupe people into installing fake antivirus software.
http://www.computerworld.com/s/article/9138361/Scammers_auto_generate_Twitter_accounts_to_spread_scareware?source=CTWNLE_nlt_security_2009-09-22
Thursday, August 27, 2009
Facebook Moves to Improve Privacy and Transparency
What's happening: Social networking sites have become a veritable goldmine for cybercriminals. Many online thefts from business bank accounts start when an employee innocently clicks on a link in an email from Facebook or another of the social network sites.
What it means: While it's good that Facebook is beginning to tighten up their privacy, this post is a warning to everyone that social engineering sites are breeding grounds for cyber-fraud.
What to do: See our discussion with Terry Corbell about the dangers of social networking sites and what management needs to do about it.
**********************************
New York Times: Facebook announced on Thursday that it planned to change the site to give users more privacy and control over their personal information. http://bits.blogs.nytimes.com/2009/08/27/facebook-moves-to-improve-privacy-and-transparency/?scp=1&sq=facebook%20moves&st=cse
What it means: While it's good that Facebook is beginning to tighten up their privacy, this post is a warning to everyone that social engineering sites are breeding grounds for cyber-fraud.
What to do: See our discussion with Terry Corbell about the dangers of social networking sites and what management needs to do about it.
**********************************
New York Times: Facebook announced on Thursday that it planned to change the site to give users more privacy and control over their personal information. http://bits.blogs.nytimes.com/2009/08/27/facebook-moves-to-improve-privacy-and-transparency/?scp=1&sq=facebook%20moves&st=cse
Wednesday, August 19, 2009
Citadel's Stan Stahl talks about social network dangers with Biz Coach, Terry Corbell
5 Safety Measures to Thwart Mounting Social-Network Attacks: http://www.bizcoachinfo.com/archives/1252
Wednesday, July 22, 2009
Social Networking Sites Must Improve Their Security, Says Security Firm
IT security and data protection firm Sophos has called upon social networking websites such as Twitter and Facebook to do more to protect their millions of users, as new research is published examining the first six months of cybercrime in 2009.http://finance.yahoo.com/news/Web-20-Woe-Sophos-Threat-bw-957043460.html?x=0&.v=1
Subscribe to:
Posts (Atom)