Computerworld reports that Microsoft has said it will issue an emergency patch for the critical Windows shortcut bug on Monday, Aug. 2.... The company said that it is satisfied with the quality of the "out-of-band" update -- Microsoft's term for a patch that falls outside the usual monthly delivery schedule -- but also acknowledged that it has tracked an upswing in attacks.
As this is an extremely serious bug, users need to make sure that this patch gets installed on their PC.
Friday, July 30, 2010
Thursday, July 29, 2010
Fake Firefox Flash Update is Rogue
PC Magazine is reporting that F-Secure has uncovered the latest in rogue anti-malware: A fake Firefox "Just Updated" page which pushes you to install an update to Flash. Don't fall victim to rogue software. Make sure that you control what get's installed on your computer.
Sunday, July 25, 2010
Digital Forensics Association Research Report: Five Years of Data Breaches
A new report from the Digital Forensics Association confirms the need for organizations to pay careful attention to all aspects of information security.The report "The Leaking Vault - Five Years of Data Breaches" analyzes over 2,800 data loss incidents from publicly accessible sources, with a known disclosure of 271.9 million records. This study—the largest of its kind to date—provides analysis on which breach vectors carry the most risk, and should help provide organizations with more accurate information when combating this problem.
Key findings include:
Key findings include:
- Business, government, educational and medical organizations have been responsible for losing on average over 395,000 people's data per day every day for five years.
- Hacking was responsible for 45% of all exposed records with an average loss of 716,000 records
- Stolen laptops were responsible for 49% of breaches but only 6% of lost records per incident.
- The fastest growing attack vector is social engineering
- Social Security Numbers (SSNs) are the most frequent data element reported.
- The Business sector accounted for 70% of breach incidents
Friday, July 23, 2010
Spyware Targets Industrial Facilities, including SCADA systems
Following up our blog post of last week in which we described new malware attacks on industrial control systems, the Christian Science Monitor writes "cyberspies have launched the first publicly known global attack aimed at infiltrating hard-to-penetrate computer control systems used to manage factory robots, refineries, and the electric power grid."
According to the Monitor, "the spyware had spread for at least a month undetected and has already penetrated thousands of industrial computer systems in Iran, Indonesia, India, Ecuador, the United States, Pakistan, and Taiwan, according to a Microsoft analysis. ... The attack is part of a sophisticated new wave of industrial cyberespionage that can infiltrate corporate systems undetected and capture the "crown jewels" of corporations – proprietary manufacturing techniques that are worth billions, experts say. It's significant, too, because of its potential to infiltrate and commandeer important infrastructure, such as the power grid."
The Monitor goes on to write "No one knows who's behind it. Cybersecurity analysts aren't even sure yet what the spyware's creators intend it to do to those industrial systems. The intent could be to sell corporate proprietary secrets – or to seek an advantage over the US in some future assymetric conflict, such as a cyberwar."
According to the Monitor, "the spyware had spread for at least a month undetected and has already penetrated thousands of industrial computer systems in Iran, Indonesia, India, Ecuador, the United States, Pakistan, and Taiwan, according to a Microsoft analysis. ... The attack is part of a sophisticated new wave of industrial cyberespionage that can infiltrate corporate systems undetected and capture the "crown jewels" of corporations – proprietary manufacturing techniques that are worth billions, experts say. It's significant, too, because of its potential to infiltrate and commandeer important infrastructure, such as the power grid."
The Monitor goes on to write "No one knows who's behind it. Cybersecurity analysts aren't even sure yet what the spyware's creators intend it to do to those industrial systems. The intent could be to sell corporate proprietary secrets – or to seek an advantage over the US in some future assymetric conflict, such as a cyberwar."
Monday, July 19, 2010
CyberSecurity Threat Indicator Raised as Critical Windows Zero-Day Vulnerability Discovered
Computerworld and other sources are reporting a newly-discovered critical bug in all versions of Windows. The bug is so critical that the Internet Storm Center (ISC) has pushed its Infocon threat indicator to "Yellow," a rare move, while Symantec also bumped up the status of its ThreatCon barometer to "Elevated." Users are being warned to expect widespread attacks.
"The proof-of-concept exploit is publicly available, and the issue is not easy to fix until Microsoft issues a patch," said Lenny Zeltser, an ISC security analyst.
Last Friday, Microsoft confirmed that attackers can use a malicious shortcut file, identified by the ".lnk" extension, to automatically execute their malware by getting users to view the contents of a folder containing such a shortcut. Malware can also automatically execute on many systems when a USB drive is plugged into the PC.
All versions of Windows, including the just-released beta of Windows 7 Service Pack 1 (SP1), as well as the recently retired Windows XP SP2 and Windows 2000, contain the bug.
In a related post, we reported that Sieman is warning customers about attacks on its industrial control software that exploit this bug.
"The proof-of-concept exploit is publicly available, and the issue is not easy to fix until Microsoft issues a patch," said Lenny Zeltser, an ISC security analyst.
Last Friday, Microsoft confirmed that attackers can use a malicious shortcut file, identified by the ".lnk" extension, to automatically execute their malware by getting users to view the contents of a folder containing such a shortcut. Malware can also automatically execute on many systems when a USB drive is plugged into the PC.
All versions of Windows, including the just-released beta of Windows 7 Service Pack 1 (SP1), as well as the recently retired Windows XP SP2 and Windows 2000, contain the bug.
In a related post, we reported that Sieman is warning customers about attacks on its industrial control software that exploit this bug.
Friday, July 16, 2010
New Malware Targets Industrial Control Systems, like SCADA
PCWorld reports that Siemens is warning customers of new and highly sophisticated malware targeting the computers used to manage large-scale industrial control systems used by manufacturing and utility companies [SCADA]. The malicious software is designed to infiltrate the systems used to run factories and parts of the critical infrastructure. The zero-day malware targets Siemens management software called Simatic WinCC, using a previously undisclosed Windows bug to break into the system.
Tuesday, July 13, 2010
Microsoft Security Updates ... Support Ends for XP, Service Pack 2
KrebsOn Security.com reports "Microsoft today released software updates to fix at least five security vulnerabilities in computers running its Windows operating system and Office applications.... Four out of five of the flaws fixed in today’s patch batch earned a “critical” rating, Redmond’s most severe. Chief among them is a bug in the Help and Support Center on Windows XP and Server 2003 systems that’s currently being exploited by crooks to break into vulnerable machines."
In related Microsoft security news, today also marks the planned end-of-life deadline for Windows XP Service Pack 2, a bundle of security updates and features that Microsoft first released in 2004.Microsoft will no longer support this product, so if you haven't already done so, it's time to upgrade to at least SP3.
In related Microsoft security news, today also marks the planned end-of-life deadline for Windows XP Service Pack 2, a bundle of security updates and features that Microsoft first released in 2004.Microsoft will no longer support this product, so if you haven't already done so, it's time to upgrade to at least SP3.
Monday, July 5, 2010
Microsoft Warns of Uptick in Attacks on Unpatched Windows Flaw
KrebsOnSecurity reports "Microsoft is warning that hackers have ramped up attacks against an unpatched, critical security hole in computers powered by Windows XP and Server 2003 operating systems. The software giant says it is working on an official patch to fix the flaw, but in the meantime it is urging users to apply an interim workaround to disable the vulnerable component." Microsoft issued a statement last week saying the pace of attacks against Windows users had picked up, and that more than 10,000 distinct computers have reported seeing this attack at least one time.
The following graphic from Krebs' blog shows both the daily number of attacks and the cumulative distinct PCs being attacked. As can be seen, peak attacks occurred during the six days from June 22 until June 27.
IT Departments running Windows XP or Server 2003 need to consider running Microsoft’s stopgap “FixIt” tool to disable the vulnerable Help Center component. Users running Windows XP should consider doing this as well. To do so, click this link, then click the “FixIt” button in the middle of the page under the “enable this fix” heading.
The following graphic from Krebs' blog shows both the daily number of attacks and the cumulative distinct PCs being attacked. As can be seen, peak attacks occurred during the six days from June 22 until June 27.
IT Departments running Windows XP or Server 2003 need to consider running Microsoft’s stopgap “FixIt” tool to disable the vulnerable Help Center component. Users running Windows XP should consider doing this as well. To do so, click this link, then click the “FixIt” button in the middle of the page under the “enable this fix” heading.
Tuesday, June 29, 2010
New CyberSecurity Study says "Most senior execs unaware of impact from cyberattacks." ISSA-LA Committed to Doing Something About It.
According to an article in USA Today, a new Ponemon Institute poll of 591 technology managers shows that 83% indicated their organization has been a recent target of advanced threats while 81% felt that senior execs lacked awareness of the seriousness of advanced threats. Our experience confirms the validity of these statistics. The cybercrime problem is only going to get worse as more and more small and medium size businesses fall victim to online bank fraud.
The biggest challenge we see is helping the men and women who have to dedicate resources (people or money) understand (1) why they need to improve the security of their information systems, (2) the basic steps involved in improving systems security, and (3) the ancillary competitive benefits they can get from improved information systems security management.
It's to meet this challenge that we in the Los Angeles Chapter of the Information Systems Security Association (ISSA-LA) have embarked on an aggressive Community Outreach Program. Our objective is nothing less than to raise information security awareness throughout the Los Angeles community. This is the most important thing we can do to help our community protect itself from the scourge of cybercrime. Having successfully concluded our 2nd Annual Information Security Summit we know the time is right to bring the community together around this problem and we are dedicated to doing so.
The biggest challenge we see is helping the men and women who have to dedicate resources (people or money) understand (1) why they need to improve the security of their information systems, (2) the basic steps involved in improving systems security, and (3) the ancillary competitive benefits they can get from improved information systems security management.
It's to meet this challenge that we in the Los Angeles Chapter of the Information Systems Security Association (ISSA-LA) have embarked on an aggressive Community Outreach Program. Our objective is nothing less than to raise information security awareness throughout the Los Angeles community. This is the most important thing we can do to help our community protect itself from the scourge of cybercrime. Having successfully concluded our 2nd Annual Information Security Summit we know the time is right to bring the community together around this problem and we are dedicated to doing so.
Security Updates for Adobe Acrobat, Reader
KrebsOnSecurity.com reports "Adobe Systems Inc. is urging users to update installations of Adobe Reader and Acrobat to fix a critical flaw that attackers have been exploiting to break into vulnerable systems. ... The update brings Adobe Acrobat and Reader to version 9.3.3 (another update for the older 8.2 line of both products brings the latest version to v. 8.2.3). Patches are available for Windows, Mac, Linux and Solaris versions of these programs. Adobe’s advisory for this update is here, and the Reader update is available from this link — or by opening the program and clicking “Help” and “Check for Updates.” If you download the update from the Adobe Reader homepage, you’ll end up with a bunch of other stuff you probably don’t want."
Users discouraged by the ongoing discovery of critical vulnerabilities in Acrobat Reader may want to consider switching to other free PDF readers may be less of a target for malicious hackers. Examples of other free PDF readers include Foxit Reader, Nitro PDF Reader, and Sumatra.
Users discouraged by the ongoing discovery of critical vulnerabilities in Acrobat Reader may want to consider switching to other free PDF readers may be less of a target for malicious hackers. Examples of other free PDF readers include Foxit Reader, Nitro PDF Reader, and Sumatra.
Monday, June 28, 2010
White House Unveils National Strategy for Online Identity
darkReading reports that "the White House has outlined a national strategy for trusted digital identities that could ultimately eliminate the username-and-password model and lay the groundwork for a nationwide federated identity infrastructure. ...Howard Schmidt, cybersecurity coordinator and special assistant to the president, unveiled the administration's strategy for what he called an identity "ecosystem" for users and organizations to conduct online transactions securely and privately such that identities of all parties are trusted.
"For example, no longer should individuals have to remember an ever-expanding and potentially insecure list of usernames and passwords to login into various online services. Through the strategy we seek to enable a future where individuals can voluntarily choose to obtain a secure, interoperable, and privacy-enhancing credential (e.g., a smart identity card, a digital certificate on their cell phone, etc) from a variety of service providers -- both public and private -- to authenticate themselves online for different types of transactions (e.g., online banking, accessing electronic health records, sending email, etc.)," Schmidt blogged late last week."
"For example, no longer should individuals have to remember an ever-expanding and potentially insecure list of usernames and passwords to login into various online services. Through the strategy we seek to enable a future where individuals can voluntarily choose to obtain a secure, interoperable, and privacy-enhancing credential (e.g., a smart identity card, a digital certificate on their cell phone, etc) from a variety of service providers -- both public and private -- to authenticate themselves online for different types of transactions (e.g., online banking, accessing electronic health records, sending email, etc.)," Schmidt blogged late last week."
Wednesday, June 23, 2010
Computing Now's Gary McGraw interviews Richard Clarke
From Computing Now's Website: Gary McGraw talks with Richard A. Clarke. Clarke is an internationally-recognized expert on security, including homeland security, national security, cyber security, and counterterrorism. Gary and Richard discuss what needs to change in order for the United States to focus more attention on defense against cyber war (as opposed to offense). They also discuss the importance of software security in preventing cyber crime and cyber war, network scanning as a part of Dick’s "Defensive Triad," and balancing cybersecurity against individual liberty.
Watch Cary McGraw's interview with Richard Clarke.
Thanks to John Cosgrove for this story.
Watch Cary McGraw's interview with Richard Clarke.
Thanks to John Cosgrove for this story.
Security Updates for Firefox, Opera Browsers
KrebsOnSecurity reports "Mozilla has shipped a new version of Firefox that corrects a number of vulnerabilities in the browser. ... Firefox version 3.6.4 addresses seven security holes ranging from lesser bugs to critical flaws. Mozilla says this latest version of Firefox also does a better job of handling plugin crashes, so that if a plugin causes problems when the user browses a site, Firefox will simply let the plugin crash instead of tying up the entire browser process. Firefox should auto-update (usually on your next restart of the browser), but you can force an update check by clicking “Help,” and then “Check for Updates” (when I did this, I noticed that in its place was the “Apply Downloaded Update Now,” option, indicating that Firefox had already fetched this upgrade.)"
According to Krebs, "Mozilla also shipped, 3.5.10, an update that fixes at least nine security vulnerabilities in its 3.5.x line of Firefox. The software maker will only continue to support this version of Firefox for another couple of months, so if you’re on the 3.5.x line, you might consider upgrading soon."
Krebs reports that a new version of Opera is also available that fixes at least five security flaws in the software. Opera’s update brings the browser to version 10.54. Opera is urging users to upgrade to the latest version, available here.
According to Krebs, "Mozilla also shipped, 3.5.10, an update that fixes at least nine security vulnerabilities in its 3.5.x line of Firefox. The software maker will only continue to support this version of Firefox for another couple of months, so if you’re on the 3.5.x line, you might consider upgrading soon."
Krebs reports that a new version of Opera is also available that fixes at least five security flaws in the software. Opera’s update brings the browser to version 10.54. Opera is urging users to upgrade to the latest version, available here.
Tuesday, June 22, 2010
Security Risk: Time to Move Off Windows XP SP2
Microsoft will stop supporting users of Windows XP SP2 as of July 13, 2010. This means that the company will no longer provide security patches for SP2. All Windows users should immediately upgrade to SP3 or Windows 7. According to a Computerworld article, Windows XP SP2 is still in use in more than 75% of organizations with 36% of the PCs in every organization run SP2.
Wednesday, June 16, 2010
California Court Knowingly Exposes Confidential Data for 10 Days
The ABA Journal reports that a court in California's Sacramento County made 443 confidential documents available on a public kiosk. The problem wasn't fixed until June 4 even though a probate lawyer had brought the problem to the attention of the court on May 24. According to Presiding Judge Steve White, court technology employees didn’t act immediately because of another apparently more pressing computer problem.
Read the story here.
Read the story here.
Monday, June 14, 2010
Free WiFi at Starbucks — Reminder of Cybersecurity Risk
The New York Times reports that Starbuck's will begin offering free WiFi on July 1. This makes it a good time to remind everyone about the need to be cautious when using public Wi-Fi. While the most common risk is eavesdropping, one cannot overlook the risk of computer compromise. Here are five basic rules anytime you're on a WiFi network whose security cannot be verified:
- No online banking or other eCommerce
- No email containing sensitive information except via an approved encrypted link from PC to Mail Server
- Keep anti-virus or host intrusion prevention software (better) up-to-date
- Make sure software patches are up-to-date
- Use VPN for access to office
Sunday, June 13, 2010
"CyberWar: Sabotaging the System" on CBS 60 Minutes
From 60 Minutes: Could foreign hackers get into the computer systems that run crucial elements of the world's infrastructure, such as the power grids, water works or even a nation's military arsenal, to create havoc? They already have. Steve Kroft reports.
Thursday, June 10, 2010
e-Banking Bandits Target Title and Escrow Companies
KrebsOnSecurity.com reports that in March, computer criminals broke into the network of Redondo Beach, California based Village View Escrow Inc. and sent 26 consecutive wire transfers to 20 individuals around the world who had no legitimate business with the firm.The escrow firm has been the victim of on-line bank theft. Cybercriminals hijacked the firm's online bank account and stole $465,000.
In discussions we've had with law enforcement and bank security personnel, we find that this is a cybercrime trend. Cybercriminals seem to have discovered that title and escrow companies are regular users of the ACH system while their security controls are too often easily bypassed by the advanced hacker tools now in use.
We continue to recommend extreme caution in online banking, including
In discussions we've had with law enforcement and bank security personnel, we find that this is a cybercrime trend. Cybercriminals seem to have discovered that title and escrow companies are regular users of the ACH system while their security controls are too often easily bypassed by the advanced hacker tools now in use.
We continue to recommend extreme caution in online banking, including
- When possible, have separate computer(s) used exclusively for online banking
- Utilize 'out-of-band' confirmation for all online bank transactions
- Keep systems patched and all anti-malware software up-to-date
- Diligently check bank accounts daily
- Limit use of social networking sites
- Be on guard for phishing and other social networking attacks
Adobe Flash Update Plugs 32 Security Holes
KrebsOnSecurity reports Adobe has released a new version of its Flash Player software to fix a critical security flaw that hackers have been exploiting to break into vulnerable systems. The update also corrects at least 31 other security vulnerabilities in the widely used media player software.
According to Krebs "The latest version, v. 10.1, fixes a number of critical flaws in Adobe Flash Player version 10.0.45.2 and earlier. Don’t know what version of Flash you’ve got installed? Visit this page to find out. The new Flash version is available for Windows, Mac and Linux operating systems, and can be downloaded from this link."
Krebs continues "If you use both Internet Explorer and non-IE browsers, you’re going to need to apply this update twice, once by visiting the Flash Player installation page with IE and then again with Firefox, Opera, or whatever other browser you use. "
According to Krebs "The latest version, v. 10.1, fixes a number of critical flaws in Adobe Flash Player version 10.0.45.2 and earlier. Don’t know what version of Flash you’ve got installed? Visit this page to find out. The new Flash version is available for Windows, Mac and Linux operating systems, and can be downloaded from this link."
Krebs continues "If you use both Internet Explorer and non-IE browsers, you’re going to need to apply this update twice, once by visiting the Flash Player installation page with IE and then again with Firefox, Opera, or whatever other browser you use. "
Tuesday, June 8, 2010
Microsoft, Apple Ship Big Security Updates
KrebsOnSecurity.com reports Microsoft today released 10 security updates to fix at least 34 security vulnerabilities in its Windows operating system and software designed to run on top of it.This is the largest patch push so far this year from Microsoft.
Users are reminded to turn "on" Microsoft's "AutoUpdate" to download and install patches when they become available.
Krebs reports in the same post that Apple’s Safari 5.0 update fixes at least four-dozen security vulnerabilities in Safari on Mac OS X and Windows versions. Updates are available for Mac OS X v 10.4.11, Mac OS X v10.5.8, Mac OS X v10.6.2 or later, Windows 7, Vista, and XP. Mac users can grab the update from Software Update or Apple Downloads; Safari users on Windows will need to update using the bundled Apple Software Update utility.
Users are reminded to turn "on" Microsoft's "AutoUpdate" to download and install patches when they become available.
Krebs reports in the same post that Apple’s Safari 5.0 update fixes at least four-dozen security vulnerabilities in Safari on Mac OS X and Windows versions. Updates are available for Mac OS X v 10.4.11, Mac OS X v10.5.8, Mac OS X v10.6.2 or later, Windows 7, Vista, and XP. Mac users can grab the update from Software Update or Apple Downloads; Safari users on Windows will need to update using the bundled Apple Software Update utility.
Saturday, June 5, 2010
Adobe Warns of Critical Zero-Day Flaw in Flash, Acrobat & Reader
KrebsOnSecurity.com reports Adobe Systems Inc. warned late Friday that malicious hackers are exploiting a previously unknown security hole present in current versions of its Adobe Reader, Acrobat and Flash Player software. ... “There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player and Adobe Reader and Acrobat,” the company said in a brief blog post published Friday evening. “This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system.” ... Krebs writes "Adobe said the vulnerability exists in Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and a component (authplay.dll) of Adobe Reader and Acrobat versions 9.x for Windows, Mac and UNIX operating systems."
Like all Zero-Day exploits, these have a higher than acceptable likelihood of getting past anti-malware products. That's why we recommend that management seriously consider using advanced intrusion prevention solutions capable of blocking zero-day attacks.
Like all Zero-Day exploits, these have a higher than acceptable likelihood of getting past anti-malware products. That's why we recommend that management seriously consider using advanced intrusion prevention solutions capable of blocking zero-day attacks.
Friday, May 21, 2010
IBM Distributes Malware-Infected USBs at Conference
Last August we blogged that an IBM study concluded: Trust No One. Well, I guess that even includes IBM. Several sources including SC Magazine are reporting that USB drives given out by IBM at the Australian Computer Emergency Response Team (AusCERT) 2010 conference were infected with malware.
Thanks to David Nardoni for this post.
Thanks to David Nardoni for this post.
Wednesday, May 19, 2010
US regulators form plans to encourage banks to better protect customers from online fraud
SC Magazine is reporting that "a panel with representatives from the FDIC, the Federal Reserve System and other agencies is reacting to the rapid evolution of malicious computer programs designed to drain accounts. Among its plans is to require financial institutions to contact customers through means beside the internet, following European banks actions in placing calls to clients' mobile phones to ensure that they intend to transfer money."
Read the entire story at SC Magazine.
Thanks to Richard Greenberg for this story.
Read the entire story at SC Magazine.
Thanks to Richard Greenberg for this story.
Thursday, May 13, 2010
Are Cars Next for Cybercriminals?
The New York Times reports that in a "paper, which will be presented at a computer security conference next week in Oakland, Calif., computer security specialists at the University of Washington and the University of California, San Diego, report that while modern cars have extensive safety engineering in the design of their computer control systems, little thought has been given to the potential threat of hackers who may want to take over the networks that increasingly control modern cars. ...The researchers asked what could happen if a hacker could gain access to the network of a car, said Tadayoshi Kohno, a University of Washington computer scientist. He said the research teams were able to demonstrate their ability to circumvent a wide variety of systems critical to the safety of drivers and passengers. ...They also demonstrated what they described as “composite attacks” that showed their ability to insert malicious software and then erase any evidence of tampering after a crash. ... The researchers were able to activate dozens of functions and almost all of them while the car was in motion."
Read the NY Times story.
Read the NY Times story.
Tuesday, May 11, 2010
Defense Department Creates New Cyber Command Led by Lt. General Keith Alexander
The Washington Post reports that Lt. General Keith B. Alexander, director of the National Security Agency, has been confirmed to head the new Cyber Command. The new command will have both an offensive and defensive capability, including both the ability to block incoming attacks and of launching attacks against enemy computer networks.
The New York Times reported last month that the Defense Department created Cyber Command in response to hundreds of thousands of attacks every day against the computer networks essential to the Pentagon and military by individual hackers, criminal groups and nations.
The New York Times reported last month that the Defense Department created Cyber Command in response to hundreds of thousands of attacks every day against the computer networks essential to the Pentagon and military by individual hackers, criminal groups and nations.
Friday, April 30, 2010
NSA Reviews Future Cybersecurity Techniques, Technologies and Challenges
Brian Krebs reports on a 605 page National Security Association study from 2004. According to Krebs, the document "reads like a listing of the pros and cons for a huge array of defensive and counterintelligence approaches and technologies that an entity might adopt in defending its networks."
Read more and get the full report at KrebsOnSecurity.com ...
Read more and get the full report at KrebsOnSecurity.com ...
Thursday, April 29, 2010
Facebook's Social Web: Protecting Your Privacy
Facebook's introduction of Open Graph represents a new challenge for consumers. By default, you're now opted in to the company's new social sharing services which stretch way beyond the confines of Facebook.com.If this concerns you -- and it should -- here are some links with advice on setting your privacy settings.
Watch a CNET Tech Minute: Take back your privacy from Facebook ...
Read PC World's advice on protecting your privacy on Facebook ...
Read the NY Times guide on opting out of Facebook's instant personalization ...
Watch a CNET Tech Minute: Take back your privacy from Facebook ...
Read PC World's advice on protecting your privacy on Facebook ...
Read the NY Times guide on opting out of Facebook's instant personalization ...
Rapport: A Potential Tool for Lowering Risk of Online Bank Theft
Several banks are asking their online bank customers to use a security tool called Rapport. The tool, part of which installs on user workstations is designed to block online bank theft attacks from ZeuS and other malicious software. Brian Krebs interviews Mickey Boodaei, CEO of Tusteer, the company making Rapport.
Read Brian's interview at KrebsOnSecurity.com ...
Read Brian's interview at KrebsOnSecurity.com ...
Congressman Asks FTC to Investigate Privacy Risks of Copy Machines
You may not know it but copy machines have computer memories, which means they may store tons of private or otherwise sensitive information. That's why Massachusetts Congressman Edward Markey has asked the Federal Trade Commission to investigate the risk to consumers posed by businesses that don't take steps to erase the memory of their copy machines. Expect a new set of regulations requiring businesses disposing of a copy machine to securely erase its hard drive, just like they are supposed to do for their PCs.
Read the story at the Washington Post ...
Watch the CBS News Report that broke the story: Copy Machines, a Security Risk?
Read the story at the Washington Post ...
Watch the CBS News Report that broke the story: Copy Machines, a Security Risk?
Wednesday, April 28, 2010
Infamous Spam-Sending "Storm Worm" Stages a Comeback
Brian Krebs reports that the Storm Worm has once again surfaced. 18 months ago Storm Worm was responsible for approximately 20% of all spam. According to Krebs, "It remains unclear whether this Storm 2.0 strain will be as successful and prolific as its predecessor. But according to a blog post by security firm CA, the curators of the new Storm worm are very actively using the collection of PCs infected with this malware to once again relay junk e-mail advertising male enhancement pills and adult Web sites."
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Tuesday, April 27, 2010
Report Shows Weaknesses in Anti-Virus Engines
Brian Krebs reports on a research report just released by Google on the increasing difficulty defenses have in countering cybercriminals spreading fake anti-virus programs, commonly known as scareware. Using data provided by Google, purveyors of scareware programs have aggressively stepped up their effort to evade detection by legitimate anti-virus programs, both anti-virus software and Google's own detection efforts.
According to Google's Niels Provos, "We found that if you have anti-virus protection installed on your computer but the [malware detection] signatures for it are out-of-date by just a couple of days, this can drastically reduce the detection rates. It turns out that the closer you get to now, the commercial anti-virus programs were doing a much worse job at detecting pages that were hosting fake anti-virus payloads."
As to the danger, Krebs writes: "Fake anti-virus attacks use misleading pop-ups and videos to scare users into thinking their computers are infected and offer a free download to scan for malware. The bogus scanning programs then claim to find oodles of infected files, and victims who fall for the ruse often are compelled to register the fake anti-virus software for a fee in order to make the incessant malware warnings disappear. Worse still, fake anti-virus programs frequently are bundled with other malware. What’s more, victims end up handing their credit or debit card information over to the people most likely to defraud them."
Read the story and link to the Google report at KrebsOnSecurity.com ...
For what to do if you become a scareware victim, read Brian Krebs tutorial here ...
According to Google's Niels Provos, "We found that if you have anti-virus protection installed on your computer but the [malware detection] signatures for it are out-of-date by just a couple of days, this can drastically reduce the detection rates. It turns out that the closer you get to now, the commercial anti-virus programs were doing a much worse job at detecting pages that were hosting fake anti-virus payloads."
As to the danger, Krebs writes: "Fake anti-virus attacks use misleading pop-ups and videos to scare users into thinking their computers are infected and offer a free download to scan for malware. The bogus scanning programs then claim to find oodles of infected files, and victims who fall for the ruse often are compelled to register the fake anti-virus software for a fee in order to make the incessant malware warnings disappear. Worse still, fake anti-virus programs frequently are bundled with other malware. What’s more, victims end up handing their credit or debit card information over to the people most likely to defraud them."
Read the story and link to the Google report at KrebsOnSecurity.com ...
For what to do if you become a scareware victim, read Brian Krebs tutorial here ...
Monday, April 26, 2010
Money Mules: The Final Link in Getting Your Money to the Cyberthief Who Stole It
One of the ways a cybercriminal steals money from a business is to transfer the money in amounts less than $10,000 to the bank accounts of money mules. These money mules then withdraw the money, keep a percentage for themselves and send the rest to the cybercriminal via a money order or other non-bank method. Brian Krebs provides a fascinating glimpse into how money mules are recruited.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Friday, April 23, 2010
Cybercriminals Learn to Hide Their Malware From Search Engines
By now you may have seen security alerts on web-listings returned in a Google or Yahoo search. It's one of the ways that search engines alert their users that the web site contains malicious software. Now Brian Krebs reports that cybercriminals have learned how to 'stealth' their malware so it becomes invisible to the search engines.
Read the whole story at KrebsOnSecurity.com ...
Read the whole story at KrebsOnSecurity.com ...
Analysis of 43 Online Bank Thefts Illustrates Diversity of Victims
Brian Krebs reports on an analysis of 43 on-line bank thefts showing that the preponderance of reported thefts is from the East Coast and Midwest. As these 43 online bank thefts represent a small fraction of the total, it's impossible to make any generalizations from the data. Nevertheless, the data does show how varied the victims are. The only two things that victims have in common may be (1) that they were vulnerable and (2) they got caught up in the 'net' of some cybercriminal, no different from a tuna getting caught up in the net of a tuna boat.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Thursday, April 22, 2010
White House Moves to Focus Cybersecurity Strategy on Protection, Not Auditing
In a sign that the traditional information security audit was failing to control increasing cyber-risk, the Office of Management and Budget has ordered federal agencies to adopt a real-time approach to cyber threats. In a memo issued Wednesday, Agencies will be expected to constantly collect information on cyber threats and submit it to the Homeland Security Department, which will analyze the data and offer advice on best practices.
"Agencies have spent too much time, money and energy on generating paperwork that they end up filing away in these secure cabinets and they don't end up protecting systems," said Vivek Kundra, the government's chief information officer, in an interview published in Federal Times.
Kundra and Howard Schmidt, White House Cybersecurity Coordinator, said that the new policy points toward continuous monitoring and patching of federal systems, and also toward the deployment of cybersecurity systems that better position the government against constantly evolving threats.
Read the entire story and download the OMB Memo at Information Week ...
"Agencies have spent too much time, money and energy on generating paperwork that they end up filing away in these secure cabinets and they don't end up protecting systems," said Vivek Kundra, the government's chief information officer, in an interview published in Federal Times.
Kundra and Howard Schmidt, White House Cybersecurity Coordinator, said that the new policy points toward continuous monitoring and patching of federal systems, and also toward the deployment of cybersecurity systems that better position the government against constantly evolving threats.
Read the entire story and download the OMB Memo at Information Week ...
Symantec 2009 Global Internet Security Threat Report
Symantec has published their 2009 Global Internet Security Threat Report. According to the report, the top web-based attacks in 2009 were on Internet Explorer and Adobe Acrobat/Reader. The report notes the growth in PDF attacks, from 11% of web-based attacks in 2008 to 49% in 2009. The report covers topics like threat activities, vulnerability trends, phishing and the underground economy.
Download the Executive Summary from Symantec ...
Download the entire Report ...
Download the Executive Summary from Symantec ...
Download the entire Report ...
Fire Alarm Company Burned by e-Banking Fraud
KrebsOnSecurity.com reports that a fire alarm company in Arkansas lost more than $110,000 when cybercriminals stole the firm's online bank credentials and drained its payroll account. The bank has told the company that the bank would not accept responsibility for the loss.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Cybercriminals Take Advantage of McAfee Snafu
Brian Krebs reports about McAfee's bad update (see yesterday's blog post: McAfee Anti-Virus Software Locks up PCs) that searching for information about the update returns pages of results that when visited launch the come-ons that try to frighten visitors into purchasing bogus (if not also malicious) anti-virus products. The pages are also capable of being booby-trapped so that unsuspecting users will download and install malicious software on their PCs. Internet Explorer users are most at risk of booby-traps, as the booby-trapped pages simply would not load if users follow our recommendation to use Firefox with the noscript add-on enabled.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Wednesday, April 21, 2010
Social Engineering Case Study: Google Hackers Duped Their Victims
So how did Google and 30 other large companies get hacked? (See our blog post: Google Attacks Highlight Growing Problem of Cyber Security Threats.) Part of the answer is that the attackers duped everyone from system administrators with access to passwords to executives with access to intellectual property and other information, according to a report in the Washington Post. Social engineering attacks, where the cybercriminals take advantage of gullibility and other human weaknesses to gain illegitimate access to sensitive information, have becoming an increasingly common component of cybercriminal attack.
Read the entire story at the Washington Post ...
Read the entire story at the Washington Post ...
McAfee Antivirus Software Locks Up PCs
Several news sources report that McAfee's anti-virus software is erroneously detecting legitimate Windows system files as malicious, causing reboot loops and serious stability problems for many Windows XP users, according to multiple reports.I've talked to several clients who have experienced the same problem. One Citadel client had to rebuild over 100 affected computers, a complete waste of time for IT staff.
Read the whole story at KrebsOnSecurity.com ...
Read the whole story at KrebsOnSecurity.com ...
Tuesday, April 20, 2010
Health Care Survey: Slow Hospital Compliance with New Regulations Causing Increased Data Breaches & Medical Identity Theft
From the Spring 2010 National Survey of Hospital Compliance Executives conducted by Identity Forces:
As medical consumers, should we be worried. You betcha!
Download the report (PDF).
Thanks to Hal Amens for this story.
- Compliance continues to lag as nearly 85% of hospitals are NOT in compliance with the HITECH Act
- Breaches are up over 120% from last year's survey
- 41% of hospitals now have 10 or MORE data breaches annually
- Potential patient ID fraud and misuse going un‐investigated as 34% of hospitals keep inadequate records
- 48% of hospitals do not check to make sure vendors and business associates are in compliance with the HITECH act.
As medical consumers, should we be worried. You betcha!
Download the report (PDF).
Thanks to Hal Amens for this story.
China-Google Controversy Illustrates Cloud Security Risk
Terry Corbell, The Biz Coach, explores the security implications of the China-Google controversy. Terry was kind enough to quote me about particular Cloud security challenges. Here's what I told Terry:
“As the story makes clear, businesses considering cloud services like those offered by Google, Amazon and others must ‘look before they leap’,” warns Internet security expert Stan Stahl, Ph.D., Citadel Information Group, Inc. “While it’s probably obvious to look at the security provided by the cloud provider, less obvious is that the business needs to also look at that part of security that will still be its responsibility, the part of security that the cloud service provider isn’t providing,” says Dr. Stahl, as the go-to security authority. “Security can never be a matter of looking at ‘this’ or ‘that.’ Security must always be about looking at ‘this’ and ‘that’,” he adds.
Read Terry's blog ...
“As the story makes clear, businesses considering cloud services like those offered by Google, Amazon and others must ‘look before they leap’,” warns Internet security expert Stan Stahl, Ph.D., Citadel Information Group, Inc. “While it’s probably obvious to look at the security provided by the cloud provider, less obvious is that the business needs to also look at that part of security that will still be its responsibility, the part of security that the cloud service provider isn’t providing,” says Dr. Stahl, as the go-to security authority. “Security can never be a matter of looking at ‘this’ or ‘that.’ Security must always be about looking at ‘this’ and ‘that’,” he adds.
Read Terry's blog ...
Rent-a-Fraudster: A Fascinating Look at the Cybercrime Underworld
KrebsOnSecurity.com reports that a call service catering to online bank and identity thieves has been busted by U.S. and international authorities. The takedown provides a fascinating look at a special niche of service providers in the cybercrime underworld. Suppose, for example, you're a cybercriminal with a thick Russian accent, you have all the appropriate information about David Smith that his bank requires to transfer money, and you want to move $250,000 from David Smith's bank account but Smith's bank requires an out-of-band phone call with the bank before they'll release the money. To get your $250,000, you rent an English-speaking fraudster who calls the bank for you! Another rent-a-fraud service provides a password-protected Web site catering to customers with stolen credit cards. Yet a third Web site, appropriately named the "Fraud Shop," manages cybercriminal transactions at legitimate Web sites, even arranging for shipping stolen merchandise to mules.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
GAO report says IRS Blase' about Cybersecurity
There's so much anger at the government that I'm almost embarrassed to post this, but it's an important illustration of just how bloody hard it is to effectively manage information systems security ... and why leadership is so very important. And why, perhaps, some of the anger is well-deserved. The GAO reports that sixty-nine percent of 89 security weaknesses and deficiencies identified by the GAO during a 2008 fiscal year audit remain unresolved and depicts the IRS' attitude toward security as rather blasé.
Read the story at Information Week ...
Read the story at Information Week ...
Mozilla Disables Insecure Java Plugin in Firefox
KrebsOnSecurity.com: Brian Krebs reports that Mozilla has disabled vulnerable versions of the Java Development Toolkit for Firefox that cybercriminals have been using to install malicious software on users desktops. Mozilla is taking this action to protect Firefox users from the vulnerabilities in older versions in Java that we reported in our April 15th blog post: Java Patch Targets Latest Attacks. To make sure Java is disabled from Firefox, go to Tools, Add-ons and click the Plugins icon. If any Java Plugins are listed, select the Toolkit and hit the “Disable” button.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Monday, April 19, 2010
A Security Flaw in Palm Pre Demonstrates Need for Caution
Intrepidus Group announced that they've identified dangerous vulnerabilities in the Palm Pre WebOS. The vulnerabilities illustrate one more reason why we would NEVER use an off-the-shelf mobile device for online banking or anything else really sensitive. Even if the on-line bank app was written without security flaws [which is more than doubtful], flaws in the underlying OS [or Trojan horses embedded in other apps] just make it way too dangerous. Don't be lulled by the fact that Palm has already released an update to WebOS. Remember the mantra: All complex software is flawed and has vulnerabilities.
Read more at V3.co.uk ...
Read more at V3.co.uk ...
California Senate Passes Strengthened Data Breach Disclosure Law
Information Week reports that the California Senate has passed SB-1186, a new data breach disclosure law that would require a breach notification letter to include the type of information exposed, a description of the breach, and steps potential victims can take to mitigate risks.
To read the story on Information Security ...
To read the story on Information Security ...
Changing Culture Improves Organization's Data Privacy and Information Security Program
From a recent report by the renowned Poneman Institute: there is a "strong correlation between an organization’s level of respect for an individual’s personal data and the likelihood that the organization will suffer a data breach. By establishing an environment within an organization that encourages employees to see data as an extension of the customer and not merely something owned by the company, thereby fostering the development of a “culture of caring,” data privacy and information security programs become more effective."
Download the Poneman Report ...
Download our paper "Beyond Awareness Training: It's Time to Change the Culture" from our web site ...
Download the Poneman Report ...
Download our paper "Beyond Awareness Training: It's Time to Change the Culture" from our web site ...
Visitors to Web Sites Hosted by Network Solutions Again at Risk
KrebsOnSecurity.com reports that Network Solutions has again been hacked by cybercriminals. The cybercriminals installed malicious software on web sites hosted by Network Solutions. This put visitors to these sites at risk that cybercriminals could take control of their computers, allowing them to steal online credit and bank account passwords and other sensitive information.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Friday, April 16, 2010
$500 Buys Entry-Level Cybercrime Exploit Pack
The iPack may sound like Steve Jobs' next great product but don't be fooled. It's a new custom exploit pack for sale to cybercriminals at prices starting at $500. Like many other exploit kits, the iPack make it easy for hackers to booby-trap Web sites with code that installs malicious software.Other exploit kits are available to cybercriminals to make it easy to exploit workstation weaknesses such as missing patches.
Read the story at KrebsOnSecurity.com ...
Read the story at KrebsOnSecurity.com ...
Thursday, April 15, 2010
Java Patch Targets Latest Attacks
KrebsOnSecurity.com: Oracle Corp. has shipped Java 6 Update 20, a new version of its Java software that nixes a feature in Java that hackers have been using to foist malicious software.The best advice is to turn off Java in your browser, but if you believe you need it, then make sure to keep it patched.
Read more at KrebsOnSecurity.com ...
Download Java Update ...
Read more at KrebsOnSecurity.com ...
Download Java Update ...
Thursday, April 8, 2010
U.K. Approves Crackdown on Internet Pirates
NewYorkTimes: The British Parliament on Thursday approved plans to crack down on digital media piracy by authorizing the suspension of repeat offenders’ Internet connections.
Read more at The New York Times ...
Read more at The New York Times ...
Wednesday, April 7, 2010
In cyberwar, who's in charge?
This Business Week article continues the public dialogue we need so we can find the common cyber-ground needed to prevail against cyberwar, cyberterrorism and cybercrime.
Read more at Business Week ...
Read more at Business Week ...
ISP Privacy Proposal Draws Fire
Brian Krebs reports that the American Registry for Internet Numbers (ARIN) — one of five regional registries worldwide that is responsible for allocating blocks of Internet addresses – is considering a proposal to ease rules that require ISPs to publish address and phone number information for their business customers. The proposal is drawing strong criticism from information systems security professionals as it will make it harder to fight spam, malware and other forms of cybercriminal activity.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Cybersecurity Coordinator Howard Schmidt: Private Sector Key to Stopping Google-style Attacks
Speaking at CSO Perspectives 2010, White House Cybersecurity Coordinator Howard Schmidt says the information security community is right to be spooked by massive, coordinated attacks that recently targeted Google. But he believes the best defense remains in the hands of the private sector."You guys have been carrying the water," Schmidt told attendees at CSO Perspectives 2010. "The government can do a lot to improve the nation's cyber defenses. But ultimately," he said, "the key to warding off attacks like the one Google experienced remains private-sector vigilance." ... "I see this as a whole range of threats we have to deal with -- everything from script kiddies to organized crime and everything in between," he said. "There are a lot of different actors we need to worry about, and we have to work harder to reduce the number of vulnerabilities out there so we can stop all of them, whoever and wherever they are."
Read more at Network World ...
Read more at Network World ...
Tuesday, April 6, 2010
Computer Crooks Steal $100,000 from Ill. Town
Brian Krebs reports on another online bank theft, this one the small Village of Summit, just outside Chicago. In addition to the village's loss, Krebs also notes that crooks recently stole $100,000 from the New Jersey township of Egg Harbor; $130,000 from a public water utility in Arkansas; $378,000 from a New York town; $160,000 from a Florida public library; $500,000 from a New York middle school district; and $415,000 from a Kentucky county.
Read the full story at KrebsOnSecurity.com ...
Read the full story at KrebsOnSecurity.com ...
Researchers begin work on 'sophisticated' security for healthcare IT
Healthcare IT News reports that the Information Trust Institute (ITI) at the University of Illinois at Urbana-Champaign has received $15 million to lead a multi-university consortium of researchers to create technology that will make electronic health record systems and health data exchange secure enough to gain the confidence of doctors and patients.
Read the story at Healthcare IT News ...
Thanks to Hal Amens for this story.
Read the story at Healthcare IT News ...
Thanks to Hal Amens for this story.
e-Banking Guidance for Banks & Businesses
KrebsOnSecurity.com: One of Krebs' sources was recently at a conference where one of the key speakers was a senior official from the Office of the Comptroller of the Currency, one of the main banking industry regulators. ... According to Krebs' source, the OCC official stressed the following points:
Read more at KrebsOnSecurity.com ...
- Authentication (including token based/one-time password generators) is only one layer of control. Out of band (also being called 3rd factor) verification such as call backs, fax, etc… is still highly recommended.
- Businesses and banks should require dual controls.
- Establish and monitor exposure limits. You may want to consider 2 limits – lower limits for authentication only, higher limit with out-of-band verification.
- Set up alerts to your customers so they know when a transaction has been initiated.
- Have a relatively low limit (less than 9K) for daily reporting.
- Monitor for “money mule” activity, typified by the presence of one or more of the following:
- New accounts that are opened by a customer with a small deposit, followed shortly by one or more large deposits by ACH credit or wire transfer.
- An existing account with a sudden increase in the number and dollar amounts of deposits by ACH credit or wire transfer.
- A new or existing account holder that withdraws a large amount of cash shortly after a large deposits (often 5%-10% less then the deposit).
- Examiners will be looking at this hard at your next exam: They will be looking for a combination of controls; authentication, verification, limits, risk management and monitoring.
- Educate your customers but do not rely on customer controls.
- Recommend to customer that they set up a single use computer specifically for online banking and nothing else.
- Don’t let marketing “over promise” and “under deliver”. For example, “Business banking on-line, anywhere, anytime at the touch of the key” encourages customers to not worry about security (i.e. connecting onto unsecured wireless networks).
- Have an Incident Response plan specifically for situations of this type.
- The FBI is interested. There are currently more than 250 ongoing investigations. If your bank/customer experiences an ACH attack, contact the Cyber Supervisor at the local FBI office. They have been given guidance in how to respond and report.
Read more at KrebsOnSecurity.com ...
Security Updates for Foxit, QuickTime/iTunes
KrebsOnSecurity.com: Foxit Software has issued an update to make it easier for users to spot PDF files that may contain malicious content. Also, Apple has pushed out new versions of QuickTime and iTunes that correct nearly two dozen security problems in those programs.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Monday, April 5, 2010
Cyber Security Survey Finds Businesses' Most Valuable Data at Risk
The survey, conducted by Forrester Consulting, identified two primary types of information needing to be secured: (1) Sales lists, strategies and other secrets conferring competitive advantage and (2) custodial information, like credit card numbers, requiring protection. One of the conclusions of the survey: Investments are overweighed against protection and toward compliance.
Read more at eSecurity Planet ...
Read more at eSecurity Planet ...
Cybercriminals Find Way to Test Malware Before Launching an Attack
How does a cybercriminal make sure that the malware attack he's about to launch won't get blocked by anti-malware products? The cybercriminal can't turn to legitimate malware testing sites since they report malware to the major anti-malware makers. Brian Krebs has uncovered a malware testing site that keeps its mouth shut.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Friday, April 2, 2010
Java Patch Plugs 27 Security Holes
KrebsOnSecurity.com: A new version of Java is available that fixes at least 27 security vulnerabilities in the ubiquitous software. ... To see which version of Java you have installed, visit this link and click the “Do I Have Java?” link under the big red “Free Java Download” button. The newest version that includes these 27 fixes is Java 6 Update 19.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Thursday, April 1, 2010
Cybercrime Gangs Fight Each Other Over Desktops
KrebsOnSecurity.com:It’s common for malware writers to taunt one another with petty insults nested within their respective creations. Competing crime groups also often seek to wrest infected machines from one another. A very public turf war between those responsible for maintaining the Netsky and Bagle worms back in 2005, for example, caused a substantial increase in the volume of threats generated by both gangs. ... The latest rivalry appears to be budding between the authors of the Zeus Trojan — a crime kit used by a large number of cyber thieves — and “SpyEye,” a relatively new kit on the block that is taking every opportunity to jeer at, undercut and otherwise siphon market share from the mighty Zeus. ... Symantec alluded to this in a February blog post that highlighted a key selling point of the SpyEye crimeware kit: If the malware created with SpyEye lands on a computer that is already infected with Zeus, it will hijack and/or remove the Zeus infection.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Washington State Law Requires PCI Compliance; Allows Banks to Recover Data Breach Costs
eSecurity Planet: Washington last week became the third state to pass legislation that will allow banks to recover certain costs and damages from retailers and credit card processors that suffer data breaches after failing to comply with current Payment Card Industry (PCI) standards. ...The law, which goes into effect on July 1 in Washington, follows similar laws passed in the states of Minnesota and Nevada and marks a fundamental change in the way government and private sector industries assign responsibility and accountability for preventing identity theft.
Read more at eSecurity Planet ...
Read more at eSecurity Planet ...
Wednesday, March 31, 2010
Spam Site Registrations Flee China for Russia
KrebsOnSecurity.com: A crackdown by the Chinese government on anonymous domain name registrations has chased spammers from Chinese registrars (.cn) to those that handle the registration of Russian (.ru) Web site names, new spam figures suggest. Yet, those spammy domains may soon migrate to yet another country, as Russia is set to enforce a policy similar to China’s beginning April 1. ... Chinese authorities called the move a crackdown on phishing and pornographic Web sites, but human rights and privacy groups marked it as yet another effort by Chinese leaders to maintain tight control over their corner of the Internet.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
More C-Level Involvement Needed in Cybersecurity, says ANSI
BusinessWeek: Organizations with top executives who aren't involved in cybersecurity decisions face a serious problem -- a major hit to their bottom lines, according to a report released Wednesday. ..."Many organizations see cybersecurity as solely an IT problem," said Karen Hughes, director of homeland security standards programs at the American National Standards Institute (ANSI), one of the major sponsors of the new report. "We are directing a wake-up call to executives nationwide. The message is, this is a very serious issue, and it's costing you a lot of money." ... The report, called "The Financial Management of Cyber Risk," recommends how C-level executives can implement cybersecurity risk management programs at their companies. Part of the goal is to get executives such as chief financial officers directly involved in cybersecurity efforts, said Larry Clinton, president of the Internet Security Alliance (ISA), the other major sponsor of the report.
Read more at Business Week ...
Read more at Business Week ...
Separating April Fools’ From Fraud on the Web
NewYorkTimes: On the Internet, every day is April Fools’ Day. ... Thinking about how people get fooled on April 1 is a good way to prepare for the year-round attempts by swindlers to bamboozle the naïve, the witless and those who just aren’t paying close attention. In other words, all of us. ... The same themes run through the e-mail solicitations of Nigerian princes waiting to share their riches, messages by banks to type in your PIN or frantic pleas from Facebook friends trapped overseas without any money. ... How do you tell the real from the surreal today?
Read more at the New York Times ...
Read more at the New York Times ...
Tuesday, March 30, 2010
Online Thieves Take $205,000 Bite Out of Missouri Dental Practice
KrebsOnSecurity.com: Organized computer criminals yanked more than $200,000 out of the online bank accounts of a Missouri dental practice this month, in yet another attack that exposes the financial risks that small- to mid-sized organizations face when banking online. ... Eric Hudkins, the office manager and husband of one of the dentists at Smile Zone, said the money was taken in 11 different transfers, including three large wires.... Hudkins said he contacted the FBI, and that the agent he spoke with told him the FBI wouldn’t open a case on the theft unless it was over $500,000 in losses. ... Meanwhile, Smile Zone’s bank — Springfield, Mo. -based Great Southern Bank — maintains it is not responsible for the loss, according to Hudkins,
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Technology Coalition Seeks Stronger Privacy Laws
NewYorkTimes: A broad coalition of technology companies, including AT&T, Google and Microsoft, and advocacy groups from across the political spectrum said Tuesday that it would push Congress to strengthen online privacy laws to protect private digital information from government access. ... The group, calling itself the Digital Due Process coalition, said it wanted to ensure that as millions of people moved private documents from their filing cabinets and personal computers to the Web, those documents remained protected from easy access by law enforcement and other government authorities.
Read more at the New York Times ...
Read more at the New York Times ...
FBI: Business Can Help Fight Cybercrime by Reporting Breaches to Law Enforcement
One of the things helping cybercriminals is that organizations that have been hit don't often go to law enforcement. FBI director Robert Mueller acknowledged as much in a recent speech at last month's RSA Conference when he said that disclosing breaches to the FBI is the exception and not the rule today.The problem according to acting deputy assistant director for the FBI's Cyber Division Jeffrey Troy is that it helps the attackers if companies aren't disclosing breaches to the FBI or law enforcement. "We are most concerned with gathering that information and sharing it with everyone else [affected] so we can harden the systems," Troy says. "If you are not telling us you have been penetrated ... that [may be] another attack vector we can't protect everyone else from.
Read the story at DarkReading ...
Thanks to Michael Zweiback for this.
Read the story at DarkReading ...
Thanks to Michael Zweiback for this.
Apple Fixes More Than 90 Security Vulnerabilities in Mac OS X
KrebsOnSecurity.com: Apple released a software update on Monday that includes fixes for a massive number of security vulnerabilities in Mac OS X and associated software. ... The update corrects more than 90 security flaws and weaknesses in a variety of Apple and third-party products included in versions of OS X, such as ClamAV, Firewall, iChat, Mail, PHP and QuickTime. ... Updates are available for Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6 through v10.6.2, Mac OS X Server v10.6 through v10.6.2, through Software Update or via Apple Downloads. You might want to schedule the download when you have some time to be away from the computer: Depending on which version you’re downloading, the size of the update may weigh in at more than 750 megabytes.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
E-Mails of Activists, Academics and Journalists Hacked in China
NewYorkTimes: In what appears to be a coordinated assault, the e-mail accounts of more than a dozen rights activists, academics and journalists who cover China have been compromised by unknown intruders. A Chinese human rights organization also said that hackers disabled its Web site for a fifth straight day. ... The infiltrations, which involved Yahoo e-mail accounts, appeared to be aimed at people who write about China and Taiwan, rendering their accounts inaccessible, according to those who were affected. In the case of this reporter, hackers altered e-mail settings so that all correspondence was surreptitiously forwarded to another e-mail address.
Read more at the New York Times ...
Read more at the New York Times ...
Monday, March 29, 2010
Microsoft Releases Emergency IE Fix
KrebsOnSecurity.com: Microsoft Corp. said today it plans to break from its regularly scheduled monthly software update cycle to issue a patch on Tuesday for a security hole in its Internet Explorer Web browser that hackers have been exploiting lately. ... Tomorrow’s update will correct that flaw, as well as at least nine other security holes in IE that Microsoft had planned to patch on the next official Patch Tuesday(April 13).
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Facebook Proposes Changes in Privacy Policy to Share User Data with Other Sites
WashingtonPost: On Friday afternoon, Facebook announced a set of proposed changes to its privacy policy that could allow the popular social network to share more of its users' data with other sites without first getting their approval. ... The move builds on the Palo Alto, Calif., company's December revision of its privacy rules that made far more user information -- including individual status updates -- public by default. Under the new proposal, Facebook could then provide that data to "pre-approved third party websites and applications" unless a user opted out of that feature.
Read more at the Washington Post ...
Read more at the Washington Post ...
Friday, March 26, 2010
New Inexpensive "Sniffer" Captures Keystrokes From Wireless Devices
TheRegister: Kit attacks Microsoft keyboards (and a whole lot more). ... Security researchers on Friday unveiled an open-source device that captures the traffic of a wide variety of wireless devices, including keyboards, medical devices, and remote controls. ...Keykeriki version 2 captures the entire data stream sent between wireless devices using a popular series of chips made by Norway-based Nordic Semiconductor. That includes the device addresses and the raw payload being sent between them. The open-source package was developed by researchers of Switzerland-based Dreamlab Technologies and includes complete software, firmware, and schematics for building the $100 sniffer.
Read more at The Register ...
Read more at The Register ...
Thursday, March 25, 2010
Would You Have Spotted this ATM Fraud?
KrebsOnSecurity.com: The stories I’ve written on ATM skimmers — devices criminals can attach to bank money machines to steal customer data — remain the most popular at Krebs on Security so far. I think part of the public’s fascination with these fraud devices is rooted in the idea that almost everyone uses ATMs, and that it’s entirely possible to encounter this type of sneaky, relatively sophisticated form of crime right in our own neighborhoods. ... police in Alexandria, Va. — just a couple of miles to the East of where I reside — recently were alerted to a skimmer found on an ATM at a Wachovia Bank there.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Cybercrime Law Update from Washington
KrebsOnSecurity.com: There are several cybersecurity policy issues on Capitol Hill that are worth keeping an eye on. Lawmakers in the Senate have introduced a measure that would call for trade restrictions against countries identified as hacker havens. Another proposal is meeting resistance from academics who worry about the effect of the bill’s mandatory certification programs for cyber security professionals. ... As reported by The Hill newspaper, Senators Orrin Hatch (R-Utah) and Kirsten Gillibrand (D-NY) have introduced The International Cybercrime Reporting and Cooperation Act, a bill that would penalize foreign countries that fail to crack down on cyber criminals operating within their borders. ... one of the world’s largest and oldest educational and scientific computing groups says it is “deeply troubled” by mandatory training provisions included in The Cybersecurity Act, a bill proposed by Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine). The bill is aimed at protecting critical U.S. network infrastructure against cybersecurity threats, but it includes language making it illegal for anyone to offer cybersecurity services to any federal agency or system without being certified and licensed as such under a program to be determined by the Commerce Department.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Wednesday, March 24, 2010
Cybercriminals Make $$$$$ Peddling Rogue Anti-Virus Products
KrebsOnSecurity.com: The presence of rogue anti-virus products, also known as scareware, on a Microsoft Windows computer is often just the most visible symptom of a more serious and insidious system-wide infection. To understand why, it helps to take a peek inside some of the more popular rogue anti-virus distribution networks that are paying people to peddle scareware alongside far more invasive threats. ... Distributors or “affiliates” who sign up with avprofit.com, for example, are given access to an installer program that downloads not only rogue anti-virus but also ZeuS, a stealthy piece of malware that specializes in mining online banking credentials from infected PCs. ZeuS is the very piece of malware directly responsible for helping thieves steal tens of millions of dollars from small to mid-sized businesses over the past year. ... Avprofit says it will pay affiliates roughly $1,000 for every 1,000 times they distribute this installer program, or about $1 per install. Typically, affiliates will embed these installers at porn sites or bundle them with programs seeded on peer-to-peer file-sharing services. The nightmare for the victim starts when he or she responds to the fake anti-virus pop-up warning of supposed threats resident on the victim’s PC, by agreeing to download and run a scanning tool.
Read more at KrebsOnSecurity.com ...
Read more at KrebsOnSecurity.com ...
Tuesday, March 23, 2010
Riskiest Online Cities: The Emperor Has No Clothes
Yesterday's news brought an intriguing headline "The Norton Top 10 Riskiest Online Cities Report Reveals Who's Most Vulnerable to Cybercrime." I read the story, examined the report and sadly concluded that there was much less here than meets the eye.
As novelist G.K. Chesterton once wrote “It’s not that they don’t know the answer. It’s that they don’t know the question.”
The report measured the online risk of a city by looking several pieces of data, including:
The report leaves much to be desired for at least three reasons.
First, the data collected may not meaningfully relate to online risk. Expenditures on computer hardware and software may mean little or nothing since one large supercomputer can cost the same as zillions of PCs and actually lower risk.
Second, missing from this list are things that would serve to mitigate risk such as:
My third objection may be the most fundamental of all. Just exactly what is "online risk" supposed to mean when applied to a city as opposed to an organization or individual. My online risk goes up or down as the total number of bot infected or spam zombie computers in the world goes up or down. My online risk is pretty much the same whether there are more bot infected or spam zombie computers in Seattle or Los Angeles; it’s the total number that matter, not where they happen to be located.
My risk is my risk: It depends on my specific online habits and the specific security measures I take, not whether I'm more likely to be attacked from down the street or halfway around the country [or even the world].
If a city’s online risk is to measure the likelihood of my being attacked by virtue of being online in that city — analogous to what physical risk measures when we say that one city is safer than another — than the factors Norton used in the survey are, I contend, simply the wrong factors.
As you see, my objections are less related to security than to the nature of the survey itself.
Nice try Norton. But you need to go back to the drawing board, if there's even a drawing board here.
As novelist G.K. Chesterton once wrote “It’s not that they don’t know the answer. It’s that they don’t know the question.”
The report measured the online risk of a city by looking several pieces of data, including:
- Cybercrimes data from Symantec Security Response, including number of malicious attack, number of potential malware infection, number of spam zombies, number of bot infected computer, and level of Internet access
- Expenditures on computer hardware and software
- Wireless hotspots
- Broadband connectivity
- Internet usage
- Online purchases
The report leaves much to be desired for at least three reasons.
First, the data collected may not meaningfully relate to online risk. Expenditures on computer hardware and software may mean little or nothing since one large supercomputer can cost the same as zillions of PCs and actually lower risk.
Second, missing from this list are things that would serve to mitigate risk such as:
- Number of information systems security professionals in the City
- Average number of information security professionals per 1,000 computers and per company
- Percentage of computers who connect to hotspots using a VPN
- Percentage of companies ISO27001 certified
- Numbers of CISSPs, CISMs, etc
- Percentage of businesses / homes with professionally managed firewalls
My third objection may be the most fundamental of all. Just exactly what is "online risk" supposed to mean when applied to a city as opposed to an organization or individual. My online risk goes up or down as the total number of bot infected or spam zombie computers in the world goes up or down. My online risk is pretty much the same whether there are more bot infected or spam zombie computers in Seattle or Los Angeles; it’s the total number that matter, not where they happen to be located.
My risk is my risk: It depends on my specific online habits and the specific security measures I take, not whether I'm more likely to be attacked from down the street or halfway around the country [or even the world].
If a city’s online risk is to measure the likelihood of my being attacked by virtue of being online in that city — analogous to what physical risk measures when we say that one city is safer than another — than the factors Norton used in the survey are, I contend, simply the wrong factors.
As you see, my objections are less related to security than to the nature of the survey itself.
Nice try Norton. But you need to go back to the drawing board, if there's even a drawing board here.
Monday, March 22, 2010
More Online Bank Theft Victims
KrebsOnSecurity.com: An Arkansas public water utility and a New Jersey town are the latest victims of an organized cyber crime gang that is stealing tens of millions of dollars from small to mid-sized organizations via online bank theft.
Read more from KrebsOnSecurity.com ...
Read more from KrebsOnSecurity.com ...
Sunday, March 21, 2010
Banking laws leave business customers vulnerable to Internet fraud
Los Angeles Times: If hackers drain a personal account, the bank usually must cover most of the loss. But commercial deposits get no such protection. ... Just ask Fan Bao of Los Angeles. ... Bao, who runs a small import-export business, had $50,000 stolen from his bank account by computer hackers in Croatia. Bank of America has refused to reimburse him, saying the loss was his problem, not the bank's. ... Had the money been stolen out of a personal account, the bank's response would have been dramatically different. Federal law would have required the bank to reimburse Bao. ... But, unbeknown to many, business and personal accounts are governed by completely different rules. Those rules protect individuals from online hacking but can leave small-business owners to twist in the wind. ... Normally that would merely be worrisome. But it's far more frightening now because technology and law enforcement experts believe there is a huge wave growing of sophisticated criminal enterprises that target small-business bank accounts.
Read more ...
Read more ...
Saturday, March 20, 2010
How Privacy Vanishes Online
NewYorkTimes: If a stranger came up to you on the street, would you give him your name, Social Security number and e-mail address?... Probably not. ... Yet people often dole out all kinds of personal information on the Internet that allows such identifying data to be deduced. Services like Facebook, Twitter and Flickr are oceans of personal minutiae — birthday greetings sent and received, school and work gossip, photos of family vacations, and movies watched. ... Computer scientists and policy experts say that such seemingly innocuous bits of self-revelation can increasingly be collected and reassembled by computers to help create a picture of a person’s identity, sometimes down to the Social Security number.
Read more ...
Read more ...
Paper in China Sets Off Alarms in U.S.
New York Times: It came as a surprise this month to Wang Jianwei, a graduate engineering student in Liaoning, China, that he had been described as a potential cyberwarrior before the United States Congress. ... Larry M. Wortzel, a military strategist and China specialist, told the House Foreign Affairs Committee on March 10 that it should be concerned because “Chinese researchers at the Institute of Systems Engineering of Dalian University of Technology published a paper on how to attack a small U.S. power grid sub-network in a way that would cause a cascading failure of the entire U.S.”
Read more ...
Read more ...
In Bid to Sway Sales, Cameras Track Shoppers
New York Times: The curvy mannequin piqued the interest of a couple of lanky teenage boys. Little did they know that as they groped its tight maroon shirt in the clothing store that day, video cameras were rolling. ... At a mall, a father emerged from a store dragging his unruly young son by the scruff of the neck, as if he were the family cat. The man had no idea his parenting skills were being immortalized. ... At an office supply store, a mother decided to get an item from a high shelf by balancing her small child on her shoulders, unaware that she, too, was being recorded.... These scenes may seem like random shopping bloopers, but they are meaningful to stores that are striving to engineer a better experience for the consumer, and ultimately, higher sales for themselves. Such clips, retailers say, can help them find solutions to problems in their stores — by installing seating and activity areas to mollify children, for instance, or by lowering shelves so merchandise is within easy reach. ... Privacy advocates, though, are troubled by the array of video cameras, motion detectors and other sensors monitoring the nation’s shopping aisles.
Read more ...
Read more ...
Bad BitDefender Antivirus Update Hobbles Windows PCs
KrebsOnSecurity: A faulty update is being blamed for incapacitating an untold number of Microsoft Windows systems running anti-virus software from BitDefender. ...BitDefender says the problem occurred Saturday morning with a faulty update for 64-bit Windows systems that caused multiple Windows and BitDefender files to be quarantined. The bad update causes the anti-virus program to flag thousands of legitimate Windows and BitDefender program files as a threat called “”FakeAlert.5″.
Read more ...
Read more ...
Friday, March 19, 2010
Google patches Chrome days before hacking contest
ComputerWorld: Google has patched 11 vulnerabilities in the Windows version of Chrome, including one that earned its finder the first $1,337 check from the company's new bug bounty program. ... The update to Chrome 4.1.249.1036 fixes six flaws rated "high," the second-most-severe ranking in Google's four-step threat system; plugs three "medium" holes; and quashes two "low" bugs.
Mozilla confirms critical Firefox bug
ComputerWorld: Mozilla yesterday confirmed a critical vulnerability in the newest version of Firefox, and said it would plug the hole by the end of the month. ... "The vulnerability was determined to be critical and could result in remote code execution by an attacker," Mozilla acknowledged in a post to its security blog late Thursday. "The vulnerability has been patched by developers and we are currently undergoing quality assurance testing for the fix." ...Firefox 3.6, which Mozilla launched in January, is affected, Mozilla said, adding that it would be patched in version 3.6.2, currently slated to ship on March 30.
Naming and Shaming ‘Bad’ ISPs
KrebsOnSecurity:Roughly two years ago, I began an investigation that sought to chart the baddest places on the Internet, the red light districts of the Web, if you will. What I found in the process was that many security experts, companies and private researchers also were gathering this intelligence, but that few were publishing it. Working with several other researchers, I collected and correlated mounds of data, and published what I could verify in The Washington Post. The subsequent unplugging of malware and spammer-friendly ISPs Atrivo and then McColo in late 2008 showed what can happen when the Internet community collectively highlights centers of badness online. ... Fast-forward to today, and we can see that there are a large number of organizations publishing data on the Internet’s top trouble spots. I polled some of the most vigilant sources of this information for their recent data, and put together a rough chart indicating the Top Ten most prevalent ISPs from each of their vantage points.
Read more ...
Read more ...
Wednesday, March 17, 2010
After weeklong fight, rogue ISP Troyak struggles for life
ComputerWorld: After an international take-down effort, a rogue ISP responsible for controlling large numbers of computers infected with data-stealing code is down for the moment, but it may be reconnecting with the Internet, according to security researchers. ... Troyak, which is believed to be based in eastern Europe, was knocked offline earlier this month after other networks supplying its connectivity to the Internet stopped carrying its traffic due to complaints it was complicit in cybercrime. ... Since then the network has fought a cat-and-mouse game with network providers in 12 countries and international law enforcement, according to Jart Armin, the pseudonymous editor of the Hostexploit.com Web site, which has been involved in the action. ... "Troyak is still fighting hard, as it is the only link to the outside Internet for a few [criminal groups]," he said in an e-mail interview. ... Troyak and another ISP, Group 3, provided connectivity for 90 of 249 servers used to control Zeus, a sophisticated piece of malware that steals financial credentials and other data. Group 3 has also been disconnected. ... At this point, Troyak's reputation is so sullied that it is becoming difficult for it to find other ISPs to carry its traffic on the Internet.
Read more ...
Read more ...
Measure would force White House, private sector to collaborate in cyber-crisis
Washington Post: Key members of Congress are pushing legislation that would require the White House to collaborate with the private sector in any response to a crisis affecting the nation's critical computer networks. ... The Cybersecurity Act, drafted by Senate commerce committee Chairman John D. Rockefeller IV (D-W.Va.) and committee member Olympia J. Snowe (R-Maine), is an attempt to prod the Obama administration and Congress to be more aggressive in crafting a coordinated national strategy for dealing with cyberthreats. It is to be unveiled Wednesday. ... The senators also sponsored the National Cybersecurity Advisor Act, which would create a Senate-confirmed, Cabinet-level position to lead efforts to protect the nation's computer systems, elevating the role of the cyber coordinator's job that President Obama filled late last year. That bill is pending in the Senate.
Read more ...
Read more ...
Closing Down ISPs that Allow Malicious Activity
MIT Technology Review: A study highlights efforts to take down ISPs that allow malicious activity. ... In recent years, cyber gangs have been careful to spread their operations across multiple Internet service providers, a tactic that makes it much harder for law enforcement and security administrators to track organized crime activity. ... But new research shows that gathering data from various places, including anti-malware and anti-spam companies and phishing blacklists, makes it possible to identify dense clusters of ISPs that that appear to be overly tolerant of malicious activity. This pattern was particularly evident in Eastern Europe and the Middle East.
Read more ...
Read more ...
Revised Cybersecurity Bill Introduced in Senate
ComputerWorld: A revised version of a cybersecurity bill first proposed last year was introduced again in the U.S. Senate today, notably without a controversial provision that would have given the President authority to disconnect networks from the Internet during a national emergency. ...The bill, called the Cybersecurity Act, is sponsored by Senators Jay Rockefeller (D-W.Va.) and Olympia Snowe (R-Maine). It seeks to improve national cybersecurity preparedness by fostering a closer collaboration between the government and the private sector companies, which own a vast portion of the country's critical infrastructure. ... The bill contains several provisions designed to encourage the growth of a trained and certified cybersecurity workforce, promote public awareness of cybersecurity issues and to foster and fund research leading to the development of new security technologies.
Read more ...
Read more ...
FCC Broadband Plan Calls For Enhanced Cyber Defenses
ChannelWeb: The National Broadband Plan, presented to Congress by the Federal Communications Commission this week, contains stipulations that could equip U.S. communications networks with stronger defenses against cyber threats and protect users' privacy online. ... Among other things, the plan gives a boost for the development of cyber security infrastructure, proposing the implementation of online privacy measures and calling for continued cooperation between the FCC and the Department of Homeland Security on public safety issues and initiatives.
Google Attacks Highlight Growing Problem of Cyber Security Threats
VoiceOfAmerica: Google’s recent disclosure that it was the target of a highly sophisticated cyber attack has brought renewed attention to the growing problem of cyber security threats. Officials and security experts say that while past cyber attacks focused largely on national secrets and defense technologies, that focus is changing. ... Speaking at a recent congressional hearing on future threats to U.S. national security, FBI Director Robert Mueller said cyber attacks are increasingly taking a wider aim. [Director Mueller’s Testimony to Senate Committee on Intelligence] "As the global economy integrates, many cyber threats now focus on economic or non-government targets as we have seen with the recent cyber attack on Google," he explained. "Targets in the private sector are at least as vulnerable and the damage can be just as great."
Read more ...
Read more ...
Subscribe to:
Posts (Atom)