Tuesday, March 30, 2010
Online Thieves Take $205,000 Bite Out of Missouri Dental Practice
Read more at KrebsOnSecurity.com ...
Technology Coalition Seeks Stronger Privacy Laws
Read more at the New York Times ...
FBI: Business Can Help Fight Cybercrime by Reporting Breaches to Law Enforcement
Read the story at DarkReading ...
Thanks to Michael Zweiback for this.
Apple Fixes More Than 90 Security Vulnerabilities in Mac OS X
Read more at KrebsOnSecurity.com ...
E-Mails of Activists, Academics and Journalists Hacked in China
Read more at the New York Times ...
Monday, March 29, 2010
Microsoft Releases Emergency IE Fix
Read more at KrebsOnSecurity.com ...
Facebook Proposes Changes in Privacy Policy to Share User Data with Other Sites
Read more at the Washington Post ...
Friday, March 26, 2010
New Inexpensive "Sniffer" Captures Keystrokes From Wireless Devices
Read more at The Register ...
Thursday, March 25, 2010
Would You Have Spotted this ATM Fraud?
Read more at KrebsOnSecurity.com ...
Cybercrime Law Update from Washington
Read more at KrebsOnSecurity.com ...
Wednesday, March 24, 2010
Cybercriminals Make $$$$$ Peddling Rogue Anti-Virus Products
Read more at KrebsOnSecurity.com ...
Tuesday, March 23, 2010
Riskiest Online Cities: The Emperor Has No Clothes
As novelist G.K. Chesterton once wrote “It’s not that they don’t know the answer. It’s that they don’t know the question.”
The report measured the online risk of a city by looking several pieces of data, including:
- Cybercrimes data from Symantec Security Response, including number of malicious attack, number of potential malware infection, number of spam zombies, number of bot infected computer, and level of Internet access
- Expenditures on computer hardware and software
- Wireless hotspots
- Broadband connectivity
- Internet usage
- Online purchases
The report leaves much to be desired for at least three reasons.
First, the data collected may not meaningfully relate to online risk. Expenditures on computer hardware and software may mean little or nothing since one large supercomputer can cost the same as zillions of PCs and actually lower risk.
Second, missing from this list are things that would serve to mitigate risk such as:
- Number of information systems security professionals in the City
- Average number of information security professionals per 1,000 computers and per company
- Percentage of computers who connect to hotspots using a VPN
- Percentage of companies ISO27001 certified
- Numbers of CISSPs, CISMs, etc
- Percentage of businesses / homes with professionally managed firewalls
My third objection may be the most fundamental of all. Just exactly what is "online risk" supposed to mean when applied to a city as opposed to an organization or individual. My online risk goes up or down as the total number of bot infected or spam zombie computers in the world goes up or down. My online risk is pretty much the same whether there are more bot infected or spam zombie computers in Seattle or Los Angeles; it’s the total number that matter, not where they happen to be located.
My risk is my risk: It depends on my specific online habits and the specific security measures I take, not whether I'm more likely to be attacked from down the street or halfway around the country [or even the world].
If a city’s online risk is to measure the likelihood of my being attacked by virtue of being online in that city — analogous to what physical risk measures when we say that one city is safer than another — than the factors Norton used in the survey are, I contend, simply the wrong factors.
As you see, my objections are less related to security than to the nature of the survey itself.
Nice try Norton. But you need to go back to the drawing board, if there's even a drawing board here.
Monday, March 22, 2010
More Online Bank Theft Victims
Read more from KrebsOnSecurity.com ...
Sunday, March 21, 2010
Banking laws leave business customers vulnerable to Internet fraud
Read more ...
Saturday, March 20, 2010
How Privacy Vanishes Online
Read more ...
Paper in China Sets Off Alarms in U.S.
Read more ...
In Bid to Sway Sales, Cameras Track Shoppers
Read more ...
Bad BitDefender Antivirus Update Hobbles Windows PCs
Read more ...
Friday, March 19, 2010
Google patches Chrome days before hacking contest
Mozilla confirms critical Firefox bug
Naming and Shaming ‘Bad’ ISPs
Read more ...
Wednesday, March 17, 2010
After weeklong fight, rogue ISP Troyak struggles for life
Read more ...
Measure would force White House, private sector to collaborate in cyber-crisis
Read more ...
Closing Down ISPs that Allow Malicious Activity
Read more ...
Revised Cybersecurity Bill Introduced in Senate
Read more ...
FCC Broadband Plan Calls For Enhanced Cyber Defenses
Google Attacks Highlight Growing Problem of Cyber Security Threats
Read more ...
Texan accused of disabling 100 cars over Internet
Read more ...
Researchers Map Multi-Network Cybercrime Infrastructure
Read more ...
Tuesday, March 16, 2010
The Snitch in Your Pocket
Read more ...
Thanks to Richard Greenberg for this.
MSE Users: Check for Updates, Piracy
Read more ...
eBanking Victim? Take a Number.
Read more ...
Monday, March 15, 2010
Stopgap IE Fix, Safari Update Available
Read more ...
Sunday, March 14, 2010
Identity theft may be prelude to more serious crime
Read more ...
Saturday, March 13, 2010
FBI: Online Fraud Costs Skyrocketed in 2009
Read more ...
Friday, March 12, 2010
Apple plugs 16 holes in Safari as Pwn2Own looms
Thursday, March 11, 2010
ZeuS botnet code keeps getting better… for criminals
Read more ...
Thanks to Brad Maryman for this.
Massachusetts Data Security Rules to Have National Impact
Read more ...
Thanks to Bennet Kelley of ILC for this.
Zeus botnet temporarily disrupted, but back in full force
Read more ...
Crooks Crank Up Volume of E-Banking Attacks
Read more ...
Dozens of ZeuS Botnets Knocked Offline
Read more ...
Wednesday, March 10, 2010
Law Firms slow to awaken to cybersecurity threat
National Law Journal: Hackers delve for client secrets, litigation plans, negotiation strategies and details of pending transactions.
An oddly worded e-mail was the first sign of something amiss at Los Angeles firm Gipson Hoffman & Pancione. It didn't read like the messages the firm's attorneys usually sent each other — didn't pass the "smell test." ... His suspicions raised, the recipient, associate Gregory Fayer, picked up the phone and discovered that the colleague who supposedly sent the e-mail knew nothing of it. Other attorneys at the firm also received the bogus e-mail, which was eventually traced to China — where Gipson Hoffman is litigating a $2.2 billion copyright infringement suit against the government. Fayer was well aware that cyberattackers often use fake e-mail messages to break into computer networks.
Thanks to Dave Roberts and Leba Finklestein for this.
Security gaps exploited in grade scandal remain, may be difficult to close
Read more ...
Tuesday, March 9, 2010
Verisign: Security Solutions Overwhelming to Consumers
Source: eSecurity Planet
Monoprice.com Shuttered After Fraud Complaints
Read more ...
Microsoft Patch Tuesday: Two Bug Fixes, IE Warning
Microsoft released two patches for eight security holes in its March "Patch Tuesday" drop, but also issued an advisory about a recently discovered flaw in Internet Explorer. ... The bugs fixed by the two patches are rated "important," the second highest ranking on Microsoft's four-tier severity rating scale. ... One bug that Microsoft did not fix this time around is a zero-day flaw in the way older versions of Windows handles help files and scripting -- Microsoft sent out a Security Advisory regarding the hole last week. ... According to Microsoft, the zero-day help file hole affects Windows 2000 Service Pack 4 (SP4), Windows XP SP2 and SP3, as well as 64-bit versions of XP Professional SP2, and Windows Server 2003. More recent releases of Windows, including Vista, Windows Server 2008, and Windows 7, are not at risk, Microsoft said.
Source: eSecurity Planet
Cyber Crooks Leave Traditional Bank Robbers in the Dust
Read more ...
LifeLock Will Pay $12 Million to Settle Charges by the FTC and 35 States That Identity Theft Prevention and Data Security Claims Were False
Read more ...
Energizer DUO: Trojan yourself for only $19.99
Read more ...
Source: CyberCrime & Doing Time
Monday, March 8, 2010
Victim Asks Capital One, ‘Who’s in Your Wallet?’
Read more ...
Fiserv to Banks: Stay on Outdated Adobe Reader
Read more ...
Friday, March 5, 2010
New Massachusetts Data Privacy Law
Read more ...
FBI to Private Sector: Cybersecurity Joint Effort
Read more ...
Source: eSecurityPlanet.com
Yep, There’s a Patch for That
Read more ...
Regulators Revisit E-Banking Security Guidelines
KrebsOnSecurity: Prodded by incessant reports of small- to mid-sized business losing millions of dollars at the hands of organized cyber criminals, federal regulators may soon outline more stringent steps that commercial banks need to take to protect business customers from online banking fraud and educate users about the risks of banking online. ... At issue are the guidelines jointly issued in 2005 by five federal banking regulators under the umbrella of the Federal Financial Institutions Examination Council (FFIEC). The guidance was meant to prod banks to implement so-called “multifactor authentication” — essentially, to require customers to provide something else in addition to a user name and password when logging into their bank accounts online, such as the output from a security token.
Thursday, March 4, 2010
Homeland Security Chief Details Cyber Threats
Read more ...
Source: eSecurityPlanet.com
Criminal investigation opened in grade-changing scandal at Churchill High
Read more ...
New BlackEnergy Trojan Targeting Russian, Ukrainian Banks
Read more ...
SECURITY ALERT: Citadel has begun seeing attacks in the US using the new BlackEnergy Trojan.
Thanks to Brad Maryman for this.
Wednesday, March 3, 2010
RSA panel: No easy solution for Zeus Trojan, banking malware
Read more ...
Source: SearchFinancialSecurity.com
Thanks to Brad Maryman for this.
Tuesday, March 2, 2010
White House: Comprehensive National Cybersecurity Initiative
- To establish a front line of defense against today’s immediate threats by creating or enhancing shared situational awareness of network vulnerabilities, threats, and events within the Federal Government—and ultimately with state, local, and tribal governments and private sector partners—and the ability to act quickly to reduce our current vulnerabilities and prevent intrusions.
- To defend against the full spectrum of threats by enhancing U.S. counterintelligence capabilities and increasing the security of the supply chain for key information technologies.
- To strengthen the future cybersecurity environment by expanding cyber education; coordinating and redirecting research and development efforts across the Federal Government; and working to define and develop strategies to deter hostile or malicious activity in cyberspace.
Download the CNCI Overview with a link to the CNCI ...
Information on U.S. website for medical data thefts is bare-bones
Read more ...
Monday, March 1, 2010
Wyndham computers hacked into again for credit card names, numbers
Read more ...
Friday, February 26, 2010
Mass. Privacy Law: Are You Compliant?
Read more ...
Military Announces New Social Media Policy
New York Times: Many months behind schedule, the Department of Defense on Friday issued a new policy that, on the surface, seems likely to expand access to popular social networking sites like YouTube, Facebook and Twitter by troops using military computers. ... The new policy, which can be found here, says that the default policy of the department will be to allow access to social networking sites from the military’s non-classified computer network, known by its acronym, NIPRNET (for Non-classified Internet Protocol Router Network.)
Organiser of Darkmarket fraud website jailed
BBC: A man who created a website trading in stolen financial information linked to tens of millions of pounds in losses has been jailed for nearly five years. ... Renukanth Subramaniam, 33, founded Darkmarket, a "Facebook for fraudsters" where criminals could buy and sell credit card details and bank log-ins. ... The site was shut down in 2008 after an FBI agent infiltrated it, leading to more than 60 arrests worldwide.
Thursday, February 25, 2010
Intel admits it is under constant attack from hackers
ComputerWeekly: Intel regularly faces cyber attacks by intellectual property thieves and malicious hackers, the chip maker's latest report to the US Securities and Exchange Commission reveals. ... The company admits that one recent and sophisticated incident occurred in January 2010 and that such attacks are sometimes successful.
Wednesday, February 24, 2010
N.Y. Firm Faces Bankruptcy from $164,000 E-Banking Loss
Read more ...
China's military warns Washington, denies hacking
Washington Post: BEIJING (Reuters) - China's military warned the United States on Thursday to "speak and act cautiously" to avoid reigniting tensions between the two powers, denying the People's Liberation Army played a part in Internet hacking.
Tuesday, February 23, 2010
IT Firm Loses $100,000 to Online Bank Fraud
Read more ...
Intel Was Attacked at the Same Time as Google
New York Times: Intel said that it was a victim of a “sophisticated” cyber-attack that occurred around the same time as the much-publicized attack on Google and other companies. ... Intel, which disclosed the January attack in a regulatory filing on Monday, played down the connection to the attacks on Google. ... But a person familiar with the investigation into the attacks said that Intel was part of the same wave of attacks that affected Google and more than 30 other companies.
Monday, February 22, 2010
Widespread Data Breaches Uncovered by FTC Probe. FTC Warns of Improper Release of Sensitive Consumer Data on P2P File-Sharing Networks.
Read more ...
Symantec 2010 State of Enterprise Security Study Shows Frequent, Effective Attacks on Worldwide Business
Read more ...
U.S. pinpoints code writer behind Google attack: report
Read more ...
Sunday, February 21, 2010
Hacking Inquiry Puts China’s Elite in New Light
The university has alliances with elite American ones like Duke and the University of Michigan. And it is so rich in science and engineering talent that Microsoft and Intel have moved into a research park directly adjacent to the school.
But Jiaotong, whose sprawling campus here has more than 33,000 students, is facing an unpleasant question: is it a base for sophisticated computer hackers?
Read more ...Saturday, February 20, 2010
Schools in China say they weren't behind hacking
Washington Post: SHANGHAI -- Two prominent schools in China dispute allegations that hacking attacks on Google and other firms originated from them, a report said Saturday.... The New York Times reported late Thursday that security investigators traced the hacking to computers at Shanghai Jiaotong University and Lanxiang Vocational School in China.
Thursday, February 18, 2010
CVS Caremark Settles FTC Charges that It Failed to Protect Medical and Financial Privacy of Customers and Employees; CVS Pharmacy Also Pays $2.25 Million Fine to DHS
Read more ...
Microsoft Confirms: Got Bluescreen? Check for Rootkits
Read more ...
Broad New Hacking Attack Detected
Read more ...
Thanks to Jason Stahl for sending this.
Large Worldwide Cyber Attack Is Uncovered
AP: More than 75,000 computer systems at nearly 2,500 companies in the United States and around the world have been hacked in what appears to be one of the largest and most sophisticated attacks by cyber criminals discovered to date, according to a northern Virginia security firm. ... The attack, which began in late 2008 and was discovered last month, targeted proprietary corporate data, e-mails, credit-card transaction data and login credentials at companies in the health and technology industries in 196 countries, according to Herndon, Va.-based NetWitness.
2 China Schools Said to Be Tied to Online Attacks
Read more ...
Wednesday, February 17, 2010
‘Time Bomb’ May Have Destroyed 800 Norfolk City PCs
Read more ...
Security Updates for Adobe Reader, Acrobat
Read more ...
Dozens Of Defense Contractors, Agencies Hacked
The Pentagon's forensics-focused Cyber Crime Center, where Shirley is executive director, found that between August 2007 and August 2009, 71 government agencies, contractors, universities and think tanks with connections to the U.S. military had been penetrated by foreign hackers, in some cases multiple times. In total, Shirley told Forbes, the center performed 116 investigations following spying breaches and found that in all but 14 of those cases the intruders had gained complete administrator-level access to the victim's network.
"There are some significant defense contractors among that number," Shirley says. "We can say that any company that's involved in high-technology research and development is a target for these adversaries."
According to Forbes, "military contractors General Dynamics and Northrop Grumman have both been successfully breached by cyberspies in the last two years, according to sources familiar with the security situations of those companies."
Read more ...
Tuesday, February 16, 2010
Hackers Steal $150,000 from Mich. Insurance Firm
Read more ...
Monday, February 15, 2010
China leads the world in hacked computers, McAfee study says
Read more ...
Friday, February 12, 2010
Rootkit May Be Culprit in Recent Windows Crashes
Read more ...
Thursday, February 11, 2010
Critical Security Update for Adobe Flash Player
Read more ...
China Alarmed by Security Threat From Internet
The researcher clicked on the card to open it. Within minutes, secretly implanted computer code enabled an unnamed foreign intelligence agency to tap into the databases of the institute in the city of Luoyang in central China and spirit away top-secret information on Chinese submarines.
Read more ...
Wednesday, February 10, 2010
How to Protect Yourself from the Internet Crime Wave by Dr. Stan Stahl
Joey provides strategic consulting to entrepreneurs in software, internet, technology and tech/media. Her Blog contains a wealth of information, not just for the entrepreneur but for anyone interested in strategy.
ID Theft: Don't Take It Personally
Forbes Magazine: Identity theft often feels less like a random act of fraud than a personal breach of a victim's secrets. But while consumers feel the sting from having their private data stolen, it's their banks that are increasingly picking up the bill.... That's one finding from an identity theft study released Wednesday by fraud analysis firm Javelin Research. The study, which surveyed around 5,000 Americans last year about their experiences with identity theft, calculated that ID fraud had cost around $54 billion in 2009, a significant jump from the $48 billion it estimated for 2008. That higher cost was driven by a greater number of fraud incidents that affected 11.2 million consumers in 2009, compared with 9.9 million in 2008.
Tuesday, February 9, 2010
New Banking Trojan Discovered Targeting Businesses' Financial Accounts
Read more ...
13 Ways to Protect Your Windows PC
Read more ...
Monday, February 8, 2010
Comerica Phish Foiled 2-Factor Protection; Bank Sued
Read more ...
Saturday, February 6, 2010
Zeus Attack Spoofs NSA, Targets .gov and .mil
Read more ...
Friday, February 5, 2010
Consumer Electronics Company Agrees to Settle Data Security Charges; Breach Compromised Data of Hundreds of Consumers
Read more ...
Wednesday, February 3, 2010
Hackers Try to Steal $150,000 from United Way
Read more ...
Tuesday, February 2, 2010
U.S. 'Severely Threatened' By Cyber Attacks says Dennis C. Blair, Director of National Intelligence
Twitter Asks Users To Reset Passwords After Possible Phishing Attack
Read more ...
Monday, February 1, 2010
A Tale of Two Victims
Read more ...
Hacking for Fun and Profit in China’s Underworld
Read more ...