Showing posts with label Data Breaches. Show all posts
Showing posts with label Data Breaches. Show all posts

March 19, 2017

G's Reading List for March 19, 2017

Virtual machine escape fetches $105,000 at Pwn2Own hacking contest [updated]
by Dan Goodin @ Arstechnica.com

Using 3 different exploits in Microsoft Edge browser, Windows 10, and then VMWare contestants were able to escape a virtual machine to compromise the host the VM was running on. Impressive.
Linkhttps://arstechnica.com/security/2017/03/hack-that-escapes-vm-by-exploiting-edge-browser-fetches-105000-at-pwn2own/
_____________________________________________

Malwarebytes teams up with Cybersecurity Factory
by Malwarebytes Labs
Malwarebytes is proud to support Cybersecurity Factory, a 10-week summer program for early-stage cybersecurity companies. This program runs in collaboration with Highland Capital Partners provides teams with a $35,000 convertible note investment, office space, and dedicated security mentorship from industry leaders at leading companies throughout the United States...
Linkhttps://blog.malwarebytes.com/malwarebytes-news/2017/02/malwarebytes-teams-up-with-cybersecurity-factory/
_____________________________________________

WikiLeaks to Share CIA Hacking Data with Tech Companies
by Marissa Lang, San Francisco Chronicle
WikiLeaks will release the code showing how the CIA managed to break into phones, work around encrypted messaging apps and avoid detection by software designed to defend against cyberattacks.
_____________________________________________

Google Points to Another POS Vendor Breach
by Brian Krebs @ Krebs on Security

Another good thing about Google's site warnings.


June 27, 2015

Interesting analysis' of US OPM data breach

If you are interested in the recent US Office of Personnel Management (OPM) data breach you'll want to check out the following articles and blog posts.  For those not familiar with this breach, see here.

Richard Bejtlich has a great blog post regarding what Einstein and Continuous Diagnostic Monitoring (CDM) does and does not.  He talks about a debate going on in the Federal govt. about CDM and the misconception they have about it.  Statements are being tossed around that CDM searches for nefarious actors once they are already in networks.  Richard rightly points out that CDM does not do this but rather it is a vulnerability management program which searches for known cyber flaws.  Read more about this here:
http://taosecurity.blogspot.com/2015/06/continuous-diagnostic-monitoring-does.html (link)

Richard has a follow up post to the CDM debate where he talks about the House of Representatives' OPM breach hearings.  One of the witnesses testimony incorrectly talks about CDM providing real-time anomalous behavior detection.  Read more here:
http://taosecurity.blogspot.com/search/label/cdm (link)

Arstechnica article Why the "biggest government hack ever" got past the feds:
http://arstechnica.com/security/2015/06/why-the-biggest-government-hack-ever-got-past-opm-dhs-and-nsa/ (link)

April 3, 2011

Major breach exposed customers of major brands

There's been a data breach (article 1, article 2) at one of the largest marketing services companies around and your email might have been exposed. The breach occurred at a company called Epsilon which handles email communications for many big brands such as Capital One, Citi, Disney, etc. Their website boasts over 2,500 clients including 7 Fortune 10 companies.

At this time the list includes about 15 companies but it's been growing, so even if you've not done business with one of the companies listed below, one that you have done business with might have been exposed.

Criminals are using the emails to send malicious software (in the form of PDFs or other documents) and/or links to websites that lead to malicious software and/or phishing scams. Be alert. Here's the list of companies confirmed to have been exposed at this time (some have links to notifications):

UPDATE 06-APR-2011 (LIST UPDATED):
1800-Flowers
Abe Books
AbeBooks
Air Miles CA
Ameriprise Financial
Barclays Bank
Beachbody
Bebe Stores Inc.
Benefit Cosmetics
BestBuy
Brookstone
Capital One
Charter Communications (Charter.com)
Citibank
City Market
Dillons
Disney
HSN (Home Shopping Network)
Eddie Bauer
Eurosport/Soccer.com
Food 4 Less
Fred Meyer
Fry's
Hilton Worldwide
JP Morgan Chase
Kroger
Jay C
King Soopers
Kroger
LL Bean Visa Card
Lacoste
Marriott International
Marriott Rewards
McKinsey & Company
Moneygram
New York & Company
QFC
Ralphs
Red Roof Inns Inc.
Ritz-Carlton
TiVo
Robert Half
Smith Brands
TD Ameritrade
TIAA-CREF
Target
The College Board
The Home Shopping Network
TiVo
US Bank
Verizon
Walgreens
World Financial Network National Bank

April 2, 2011

NSA to investigate NASDAQ hack


Several sources are reporting that the National Security Agency (NSA) is looking into the breach of the company that runs NASDAQ experienced back in October of 2010.

Bloomberg News interviewed former head of U.S. counterintelligence in the Bush and Obama administrations, Joel Brenner, who stated “By bringing in the NSA, that means they think they’re either dealing with a state-sponsored attack, or it’s an extraordinarily capable criminal organization.”

It's being reported that other U.S. Federal Govt agencies (FBI, Secret Service) are assisting as well.




Kim Zetter (@KimZetter) over at Wired Magazine has a good article on this topic:
http://www.wired.com/threatlevel/2011/03/nsa-investigates-nasdaq-hack/

March 19, 2009

Basic Measures Would Prevent Most Breaches?

We just finished our March meeting of the Northeast Ohio Information Security Forum and there's one talk in particular that got me thinking about basic security measures. The talk was called "The Top 10 Breaches of 2008" by Tom Eston who is a lead security assessment professional working at a Fortune 500 company. I along with many others in the audience were amazed at the lack of basic security measures in many of the incidents reviewed that if implemented could have prevent some of them.

During the talk there was a fair amount on discussion and comments from the audience. We were pretty harsh and quick to judge the security, or lack thereof, practices of the organizations who suffered the breach. While these folks may deserve the criticism one thing that we all probably didn't think hard about is the fact that they are just like many of us in that they are overworked having too much security work that needs done and not enough time or money to complete it.

That said, the common cause of these breaches appears to be the lack of focus and execution of some basic security measures. We all need to heed the lessons from these breaches and DO THE BASICS:
  • Egress Filtering Rules. Keep that data from escaping your network.
  • Practice the "need to know" principle in access control. Why do they have access to that data when they don't need it for their job?
  • Monitoring of Access. Who's watching the logs showing when someone used their access?
  • Monitoring Outbound Activity Initiated by Servers. Why is that server FTPing out to an IP on the Internet when it normally doesn't?
  • Tighter Access Control on Servers
  • PCI Certified != You're Secure
  • Encrypt the Backup Tapes. Okay, this might be a little more than basic but c'mon - most backup software can do this.
Tom's talk was very good and I recommend you check out the presentation (download from here PDF) as well as his blog http://www.spylogic.net