Tuesday, April 27, 2010
Report Shows Weaknesses in Anti-Virus Engines
According to Google's Niels Provos, "We found that if you have anti-virus protection installed on your computer but the [malware detection] signatures for it are out-of-date by just a couple of days, this can drastically reduce the detection rates. It turns out that the closer you get to now, the commercial anti-virus programs were doing a much worse job at detecting pages that were hosting fake anti-virus payloads."
As to the danger, Krebs writes: "Fake anti-virus attacks use misleading pop-ups and videos to scare users into thinking their computers are infected and offer a free download to scan for malware. The bogus scanning programs then claim to find oodles of infected files, and victims who fall for the ruse often are compelled to register the fake anti-virus software for a fee in order to make the incessant malware warnings disappear. Worse still, fake anti-virus programs frequently are bundled with other malware. What’s more, victims end up handing their credit or debit card information over to the people most likely to defraud them."
Read the story and link to the Google report at KrebsOnSecurity.com ...
For what to do if you become a scareware victim, read Brian Krebs tutorial here ...
Monday, April 26, 2010
Money Mules: The Final Link in Getting Your Money to the Cyberthief Who Stole It
Read the story at KrebsOnSecurity.com ...
Friday, April 23, 2010
Cybercriminals Learn to Hide Their Malware From Search Engines
Read the whole story at KrebsOnSecurity.com ...
Analysis of 43 Online Bank Thefts Illustrates Diversity of Victims
Read the story at KrebsOnSecurity.com ...
Thursday, April 22, 2010
White House Moves to Focus Cybersecurity Strategy on Protection, Not Auditing
"Agencies have spent too much time, money and energy on generating paperwork that they end up filing away in these secure cabinets and they don't end up protecting systems," said Vivek Kundra, the government's chief information officer, in an interview published in Federal Times.
Kundra and Howard Schmidt, White House Cybersecurity Coordinator, said that the new policy points toward continuous monitoring and patching of federal systems, and also toward the deployment of cybersecurity systems that better position the government against constantly evolving threats.
Read the entire story and download the OMB Memo at Information Week ...
Symantec 2009 Global Internet Security Threat Report
Download the Executive Summary from Symantec ...
Download the entire Report ...
Fire Alarm Company Burned by e-Banking Fraud
Read the story at KrebsOnSecurity.com ...
Cybercriminals Take Advantage of McAfee Snafu
Read more at KrebsOnSecurity.com ...
Wednesday, April 21, 2010
Social Engineering Case Study: Google Hackers Duped Their Victims
Read the entire story at the Washington Post ...
McAfee Antivirus Software Locks Up PCs
Read the whole story at KrebsOnSecurity.com ...
Tuesday, April 20, 2010
Health Care Survey: Slow Hospital Compliance with New Regulations Causing Increased Data Breaches & Medical Identity Theft
- Compliance continues to lag as nearly 85% of hospitals are NOT in compliance with the HITECH Act
- Breaches are up over 120% from last year's survey
- 41% of hospitals now have 10 or MORE data breaches annually
- Potential patient ID fraud and misuse going un‐investigated as 34% of hospitals keep inadequate records
- 48% of hospitals do not check to make sure vendors and business associates are in compliance with the HITECH act.
As medical consumers, should we be worried. You betcha!
Download the report (PDF).
Thanks to Hal Amens for this story.
China-Google Controversy Illustrates Cloud Security Risk
“As the story makes clear, businesses considering cloud services like those offered by Google, Amazon and others must ‘look before they leap’,” warns Internet security expert Stan Stahl, Ph.D., Citadel Information Group, Inc. “While it’s probably obvious to look at the security provided by the cloud provider, less obvious is that the business needs to also look at that part of security that will still be its responsibility, the part of security that the cloud service provider isn’t providing,” says Dr. Stahl, as the go-to security authority. “Security can never be a matter of looking at ‘this’ or ‘that.’ Security must always be about looking at ‘this’ and ‘that’,” he adds.
Read Terry's blog ...
Rent-a-Fraudster: A Fascinating Look at the Cybercrime Underworld
Read the story at KrebsOnSecurity.com ...
GAO report says IRS Blase' about Cybersecurity
Read the story at Information Week ...
Mozilla Disables Insecure Java Plugin in Firefox
Read more at KrebsOnSecurity.com ...
Monday, April 19, 2010
A Security Flaw in Palm Pre Demonstrates Need for Caution
Read more at V3.co.uk ...
California Senate Passes Strengthened Data Breach Disclosure Law
To read the story on Information Security ...
Changing Culture Improves Organization's Data Privacy and Information Security Program
Download the Poneman Report ...
Download our paper "Beyond Awareness Training: It's Time to Change the Culture" from our web site ...
Visitors to Web Sites Hosted by Network Solutions Again at Risk
Read the story at KrebsOnSecurity.com ...
Friday, April 16, 2010
$500 Buys Entry-Level Cybercrime Exploit Pack
Read the story at KrebsOnSecurity.com ...
Thursday, April 15, 2010
Java Patch Targets Latest Attacks
Read more at KrebsOnSecurity.com ...
Download Java Update ...
Thursday, April 8, 2010
U.K. Approves Crackdown on Internet Pirates
Read more at The New York Times ...
Wednesday, April 7, 2010
In cyberwar, who's in charge?
Read more at Business Week ...
ISP Privacy Proposal Draws Fire
Read more at KrebsOnSecurity.com ...
Cybersecurity Coordinator Howard Schmidt: Private Sector Key to Stopping Google-style Attacks
Read more at Network World ...
Tuesday, April 6, 2010
Computer Crooks Steal $100,000 from Ill. Town
Read the full story at KrebsOnSecurity.com ...
Researchers begin work on 'sophisticated' security for healthcare IT
Read the story at Healthcare IT News ...
Thanks to Hal Amens for this story.
e-Banking Guidance for Banks & Businesses
- Authentication (including token based/one-time password generators) is only one layer of control. Out of band (also being called 3rd factor) verification such as call backs, fax, etc… is still highly recommended.
- Businesses and banks should require dual controls.
- Establish and monitor exposure limits. You may want to consider 2 limits – lower limits for authentication only, higher limit with out-of-band verification.
- Set up alerts to your customers so they know when a transaction has been initiated.
- Have a relatively low limit (less than 9K) for daily reporting.
- Monitor for “money mule” activity, typified by the presence of one or more of the following:
- New accounts that are opened by a customer with a small deposit, followed shortly by one or more large deposits by ACH credit or wire transfer.
- An existing account with a sudden increase in the number and dollar amounts of deposits by ACH credit or wire transfer.
- A new or existing account holder that withdraws a large amount of cash shortly after a large deposits (often 5%-10% less then the deposit).
- Examiners will be looking at this hard at your next exam: They will be looking for a combination of controls; authentication, verification, limits, risk management and monitoring.
- Educate your customers but do not rely on customer controls.
- Recommend to customer that they set up a single use computer specifically for online banking and nothing else.
- Don’t let marketing “over promise” and “under deliver”. For example, “Business banking on-line, anywhere, anytime at the touch of the key” encourages customers to not worry about security (i.e. connecting onto unsecured wireless networks).
- Have an Incident Response plan specifically for situations of this type.
- The FBI is interested. There are currently more than 250 ongoing investigations. If your bank/customer experiences an ACH attack, contact the Cyber Supervisor at the local FBI office. They have been given guidance in how to respond and report.
Read more at KrebsOnSecurity.com ...
Security Updates for Foxit, QuickTime/iTunes
Read more at KrebsOnSecurity.com ...
Monday, April 5, 2010
Cyber Security Survey Finds Businesses' Most Valuable Data at Risk
Read more at eSecurity Planet ...
Cybercriminals Find Way to Test Malware Before Launching an Attack
Read more at KrebsOnSecurity.com ...
Friday, April 2, 2010
Java Patch Plugs 27 Security Holes
Read more at KrebsOnSecurity.com ...
Thursday, April 1, 2010
Cybercrime Gangs Fight Each Other Over Desktops
Read more at KrebsOnSecurity.com ...
Washington State Law Requires PCI Compliance; Allows Banks to Recover Data Breach Costs
Read more at eSecurity Planet ...
Wednesday, March 31, 2010
Spam Site Registrations Flee China for Russia
Read more at KrebsOnSecurity.com ...
More C-Level Involvement Needed in Cybersecurity, says ANSI
Read more at Business Week ...
Separating April Fools’ From Fraud on the Web
Read more at the New York Times ...
Tuesday, March 30, 2010
Online Thieves Take $205,000 Bite Out of Missouri Dental Practice
Read more at KrebsOnSecurity.com ...
Technology Coalition Seeks Stronger Privacy Laws
Read more at the New York Times ...
FBI: Business Can Help Fight Cybercrime by Reporting Breaches to Law Enforcement
Read the story at DarkReading ...
Thanks to Michael Zweiback for this.
Apple Fixes More Than 90 Security Vulnerabilities in Mac OS X
Read more at KrebsOnSecurity.com ...
E-Mails of Activists, Academics and Journalists Hacked in China
Read more at the New York Times ...
Monday, March 29, 2010
Microsoft Releases Emergency IE Fix
Read more at KrebsOnSecurity.com ...
Facebook Proposes Changes in Privacy Policy to Share User Data with Other Sites
Read more at the Washington Post ...
Friday, March 26, 2010
New Inexpensive "Sniffer" Captures Keystrokes From Wireless Devices
Read more at The Register ...
Thursday, March 25, 2010
Would You Have Spotted this ATM Fraud?
Read more at KrebsOnSecurity.com ...
Cybercrime Law Update from Washington
Read more at KrebsOnSecurity.com ...
Wednesday, March 24, 2010
Cybercriminals Make $$$$$ Peddling Rogue Anti-Virus Products
Read more at KrebsOnSecurity.com ...
Tuesday, March 23, 2010
Riskiest Online Cities: The Emperor Has No Clothes
As novelist G.K. Chesterton once wrote “It’s not that they don’t know the answer. It’s that they don’t know the question.”
The report measured the online risk of a city by looking several pieces of data, including:
- Cybercrimes data from Symantec Security Response, including number of malicious attack, number of potential malware infection, number of spam zombies, number of bot infected computer, and level of Internet access
- Expenditures on computer hardware and software
- Wireless hotspots
- Broadband connectivity
- Internet usage
- Online purchases
The report leaves much to be desired for at least three reasons.
First, the data collected may not meaningfully relate to online risk. Expenditures on computer hardware and software may mean little or nothing since one large supercomputer can cost the same as zillions of PCs and actually lower risk.
Second, missing from this list are things that would serve to mitigate risk such as:
- Number of information systems security professionals in the City
- Average number of information security professionals per 1,000 computers and per company
- Percentage of computers who connect to hotspots using a VPN
- Percentage of companies ISO27001 certified
- Numbers of CISSPs, CISMs, etc
- Percentage of businesses / homes with professionally managed firewalls
My third objection may be the most fundamental of all. Just exactly what is "online risk" supposed to mean when applied to a city as opposed to an organization or individual. My online risk goes up or down as the total number of bot infected or spam zombie computers in the world goes up or down. My online risk is pretty much the same whether there are more bot infected or spam zombie computers in Seattle or Los Angeles; it’s the total number that matter, not where they happen to be located.
My risk is my risk: It depends on my specific online habits and the specific security measures I take, not whether I'm more likely to be attacked from down the street or halfway around the country [or even the world].
If a city’s online risk is to measure the likelihood of my being attacked by virtue of being online in that city — analogous to what physical risk measures when we say that one city is safer than another — than the factors Norton used in the survey are, I contend, simply the wrong factors.
As you see, my objections are less related to security than to the nature of the survey itself.
Nice try Norton. But you need to go back to the drawing board, if there's even a drawing board here.
Monday, March 22, 2010
More Online Bank Theft Victims
Read more from KrebsOnSecurity.com ...
Sunday, March 21, 2010
Banking laws leave business customers vulnerable to Internet fraud
Read more ...
Saturday, March 20, 2010
How Privacy Vanishes Online
Read more ...
Paper in China Sets Off Alarms in U.S.
Read more ...
In Bid to Sway Sales, Cameras Track Shoppers
Read more ...
Bad BitDefender Antivirus Update Hobbles Windows PCs
Read more ...
Friday, March 19, 2010
Google patches Chrome days before hacking contest
Mozilla confirms critical Firefox bug
Naming and Shaming ‘Bad’ ISPs
Read more ...
Wednesday, March 17, 2010
After weeklong fight, rogue ISP Troyak struggles for life
Read more ...
Measure would force White House, private sector to collaborate in cyber-crisis
Read more ...
Closing Down ISPs that Allow Malicious Activity
Read more ...
Revised Cybersecurity Bill Introduced in Senate
Read more ...
FCC Broadband Plan Calls For Enhanced Cyber Defenses
Google Attacks Highlight Growing Problem of Cyber Security Threats
Read more ...
Texan accused of disabling 100 cars over Internet
Read more ...
Researchers Map Multi-Network Cybercrime Infrastructure
Read more ...
Tuesday, March 16, 2010
The Snitch in Your Pocket
Read more ...
Thanks to Richard Greenberg for this.
MSE Users: Check for Updates, Piracy
Read more ...
eBanking Victim? Take a Number.
Read more ...
Monday, March 15, 2010
Stopgap IE Fix, Safari Update Available
Read more ...
Sunday, March 14, 2010
Identity theft may be prelude to more serious crime
Read more ...
Saturday, March 13, 2010
FBI: Online Fraud Costs Skyrocketed in 2009
Read more ...
Friday, March 12, 2010
Apple plugs 16 holes in Safari as Pwn2Own looms
Thursday, March 11, 2010
ZeuS botnet code keeps getting better… for criminals
Read more ...
Thanks to Brad Maryman for this.
Massachusetts Data Security Rules to Have National Impact
Read more ...
Thanks to Bennet Kelley of ILC for this.
Zeus botnet temporarily disrupted, but back in full force
Read more ...
Crooks Crank Up Volume of E-Banking Attacks
Read more ...
Dozens of ZeuS Botnets Knocked Offline
Read more ...
Wednesday, March 10, 2010
Law Firms slow to awaken to cybersecurity threat
National Law Journal: Hackers delve for client secrets, litigation plans, negotiation strategies and details of pending transactions.
An oddly worded e-mail was the first sign of something amiss at Los Angeles firm Gipson Hoffman & Pancione. It didn't read like the messages the firm's attorneys usually sent each other — didn't pass the "smell test." ... His suspicions raised, the recipient, associate Gregory Fayer, picked up the phone and discovered that the colleague who supposedly sent the e-mail knew nothing of it. Other attorneys at the firm also received the bogus e-mail, which was eventually traced to China — where Gipson Hoffman is litigating a $2.2 billion copyright infringement suit against the government. Fayer was well aware that cyberattackers often use fake e-mail messages to break into computer networks.
Thanks to Dave Roberts and Leba Finklestein for this.
Security gaps exploited in grade scandal remain, may be difficult to close
Read more ...
Tuesday, March 9, 2010
Verisign: Security Solutions Overwhelming to Consumers
Source: eSecurity Planet
Monoprice.com Shuttered After Fraud Complaints
Read more ...
Microsoft Patch Tuesday: Two Bug Fixes, IE Warning
Microsoft released two patches for eight security holes in its March "Patch Tuesday" drop, but also issued an advisory about a recently discovered flaw in Internet Explorer. ... The bugs fixed by the two patches are rated "important," the second highest ranking on Microsoft's four-tier severity rating scale. ... One bug that Microsoft did not fix this time around is a zero-day flaw in the way older versions of Windows handles help files and scripting -- Microsoft sent out a Security Advisory regarding the hole last week. ... According to Microsoft, the zero-day help file hole affects Windows 2000 Service Pack 4 (SP4), Windows XP SP2 and SP3, as well as 64-bit versions of XP Professional SP2, and Windows Server 2003. More recent releases of Windows, including Vista, Windows Server 2008, and Windows 7, are not at risk, Microsoft said.
Source: eSecurity Planet
Cyber Crooks Leave Traditional Bank Robbers in the Dust
Read more ...
LifeLock Will Pay $12 Million to Settle Charges by the FTC and 35 States That Identity Theft Prevention and Data Security Claims Were False
Read more ...
Energizer DUO: Trojan yourself for only $19.99
Read more ...
Source: CyberCrime & Doing Time
Monday, March 8, 2010
Victim Asks Capital One, ‘Who’s in Your Wallet?’
Read more ...
Fiserv to Banks: Stay on Outdated Adobe Reader
Read more ...
Friday, March 5, 2010
New Massachusetts Data Privacy Law
Read more ...
FBI to Private Sector: Cybersecurity Joint Effort
Read more ...
Source: eSecurityPlanet.com
Yep, There’s a Patch for That
Read more ...
Regulators Revisit E-Banking Security Guidelines
KrebsOnSecurity: Prodded by incessant reports of small- to mid-sized business losing millions of dollars at the hands of organized cyber criminals, federal regulators may soon outline more stringent steps that commercial banks need to take to protect business customers from online banking fraud and educate users about the risks of banking online. ... At issue are the guidelines jointly issued in 2005 by five federal banking regulators under the umbrella of the Federal Financial Institutions Examination Council (FFIEC). The guidance was meant to prod banks to implement so-called “multifactor authentication” — essentially, to require customers to provide something else in addition to a user name and password when logging into their bank accounts online, such as the output from a security token.
Thursday, March 4, 2010
Homeland Security Chief Details Cyber Threats
Read more ...
Source: eSecurityPlanet.com
Criminal investigation opened in grade-changing scandal at Churchill High
Read more ...
New BlackEnergy Trojan Targeting Russian, Ukrainian Banks
Read more ...
SECURITY ALERT: Citadel has begun seeing attacks in the US using the new BlackEnergy Trojan.
Thanks to Brad Maryman for this.
Wednesday, March 3, 2010
RSA panel: No easy solution for Zeus Trojan, banking malware
Read more ...
Source: SearchFinancialSecurity.com
Thanks to Brad Maryman for this.
Tuesday, March 2, 2010
White House: Comprehensive National Cybersecurity Initiative
- To establish a front line of defense against today’s immediate threats by creating or enhancing shared situational awareness of network vulnerabilities, threats, and events within the Federal Government—and ultimately with state, local, and tribal governments and private sector partners—and the ability to act quickly to reduce our current vulnerabilities and prevent intrusions.
- To defend against the full spectrum of threats by enhancing U.S. counterintelligence capabilities and increasing the security of the supply chain for key information technologies.
- To strengthen the future cybersecurity environment by expanding cyber education; coordinating and redirecting research and development efforts across the Federal Government; and working to define and develop strategies to deter hostile or malicious activity in cyberspace.
Download the CNCI Overview with a link to the CNCI ...
Information on U.S. website for medical data thefts is bare-bones
Read more ...
Monday, March 1, 2010
Wyndham computers hacked into again for credit card names, numbers
Read more ...