From Dark Reading:
Businesses Not Properly Securing Microsoft Active Directory
"Businesses overlook key security aspects of AD, leaving sensitive data open to external and internal attacks, new study shows.
Microsoft Active Directory (AD) often lulls enterprises into a false sense of security. Many are so confident in the system's security measures they neglect to put the right safeguards in place."
The purpose of this blog is to help small-medium businesses (SMB's) deal effectively with their unique cyber security needs. With over 15 years experience in IT and cyber security I will show SMB's how they can leverage their limited resources to develop effective cyber defenses to the most common threats using information security best practices and no/low cost tools.
LinkedIn: http://www.linkedin.com/in/ecissorsky/
Twitter: @ecissorsky
Thursday, May 11, 2017
10 Free or Low-Cost Security Tools
From Dark Reading:
10 Free or Low-Cost Security Tools
"Security spending is on the rise, but allocating funds remains a challenge. Systems are expensive and skilled talent — if you can find it — comes at a high price.
A new wave of tools, from low-cost to free open source software (FOSS), aim to help with tasks like network scanning and penetration testing. Some of these tools are tailored for specific purposes while others cross several domains."
10 Free or Low-Cost Security Tools
"Security spending is on the rise, but allocating funds remains a challenge. Systems are expensive and skilled talent — if you can find it — comes at a high price.
A new wave of tools, from low-cost to free open source software (FOSS), aim to help with tasks like network scanning and penetration testing. Some of these tools are tailored for specific purposes while others cross several domains."
US-CERT Alert: FTC Announces Resource for Small Business Owners
From US-CERT:
FTC Announces Resource for Small Business Owners
"The Federal Trade Commission (FTC) has released an announcement about its new website devoted to protecting small businesses. This resource aims to help business owners avoid scams, protect their computers and networks, and keep their customers' and employees' data safe."
FTC Announces Resource for Small Business Owners
"The Federal Trade Commission (FTC) has released an announcement about its new website devoted to protecting small businesses. This resource aims to help business owners avoid scams, protect their computers and networks, and keep their customers' and employees' data safe."
US-CERT Alert: Microsoft Releases May 2017 Security Updates
From US-CERT:
Microsoft Releases May 2017 Security Updates
"Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of a system."
Microsoft Releases May 2017 Security Updates
"Microsoft has released updates to address vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of a system."
US-CERT Alert: Cisco Releases Security Update
From US-CERT:
Cisco Releases Security Update
"Cisco has released a security update to address a vulnerability in its WebEx Meetings Server which could allow a remote attacker to obtain sensitive information."
Cisco Releases Security Update
"Cisco has released a security update to address a vulnerability in its WebEx Meetings Server which could allow a remote attacker to obtain sensitive information."
Lawyers demand answers after artist forced to unlock his phone
From Sophos Naked Security:
Lawyers demand answers after artist forced to unlock his phone
"In February, artist Aaron Gach flew home to San Francisco after putting on a gallery installation in Brussels.
The show, titled Center for Tactical Magic, focused on “mass incarceration, government control, and political dissent”."
Lawyers demand answers after artist forced to unlock his phone
"In February, artist Aaron Gach flew home to San Francisco after putting on a gallery installation in Brussels.
The show, titled Center for Tactical Magic, focused on “mass incarceration, government control, and political dissent”."
The Google Play apps that say they don’t collect your data – and then do
From Sophos Naked Security:
The Google Play apps that say they don’t collect your data – and then do
"Adware is typically viewed as a nuisance that does no real harm. But in recent research, SophosLabs has seen adware in Google Play that does more than just deliver ads. This strain can collect the user’s personal information, including email address, and send them to a remote server.
Sophos detects this adware library as Android XavirAd and the information-stealing component as Andr/Infostl-BK."
The Google Play apps that say they don’t collect your data – and then do
"Adware is typically viewed as a nuisance that does no real harm. But in recent research, SophosLabs has seen adware in Google Play that does more than just deliver ads. This strain can collect the user’s personal information, including email address, and send them to a remote server.
Sophos detects this adware library as Android XavirAd and the information-stealing component as Andr/Infostl-BK."
How to hack a Jeep Cherokee – but don’t try this at home, kids
From Sophos Naked Security:
How to hack a Jeep Cherokee – but don’t try this at home, kids
"Charlie Miller and Chris Valasek originally hacked a Jeep Cherokee in 2015, physically controlling it – and a nervous journalist occupying it – on the highway. FCA, the company that makes the Cherokee, recalled 1.4m of them and issued a patch. In response, the pair hacked that one, too, and gained more control, rather than less. Earlier this year, they put all their notes online, which most of us missed until Valasek tweeted it."
How to hack a Jeep Cherokee – but don’t try this at home, kids
"Charlie Miller and Chris Valasek originally hacked a Jeep Cherokee in 2015, physically controlling it – and a nervous journalist occupying it – on the highway. FCA, the company that makes the Cherokee, recalled 1.4m of them and issued a patch. In response, the pair hacked that one, too, and gained more control, rather than less. Earlier this year, they put all their notes online, which most of us missed until Valasek tweeted it."
Unhappy 39th birthday, spam, and many unhappy returns
From Sophos Naked Security:
Unhappy 39th birthday, spam, and many unhappy returns
"In October 2011, email turned 40. Last week it was the turn of its troublesome twin, spam, to make it to within a year of the same hoary milestone.
Inevitably in an industry ageing fast, personal computing’s calendar is filling up with significant anniversaries. So, does spam’s – or email’s – really matter that much?"
Unhappy 39th birthday, spam, and many unhappy returns
"In October 2011, email turned 40. Last week it was the turn of its troublesome twin, spam, to make it to within a year of the same hoary milestone.
Inevitably in an industry ageing fast, personal computing’s calendar is filling up with significant anniversaries. So, does spam’s – or email’s – really matter that much?"
One more way to get busted on the Dark Web
From Sophos Naked Security:
One more way to get busted on the Dark Web
"Tor users suspected of child abuse imagery may have visited an outside file-sharing service simply because Tor’s so slow at routing traffic.
As Motherboard reports, the US Department of Homeland Security (DHS) identified several Tor users suspected of using a dark web site to post links to child abuse imagery that was hosted on a file-sharing service."
One more way to get busted on the Dark Web
"Tor users suspected of child abuse imagery may have visited an outside file-sharing service simply because Tor’s so slow at routing traffic.
As Motherboard reports, the US Department of Homeland Security (DHS) identified several Tor users suspected of using a dark web site to post links to child abuse imagery that was hosted on a file-sharing service."
Tuesday, May 9, 2017
3 Reasons Why TheDarkOverlord Loves Vendor Data Breaches
From PivotPoint Security:
3 Reasons Why TheDarkOverlord Loves Vendor Data Breaches
"As hacker monikers go, TheDarkOverlord (TDO) picked a pretty catchy one. Not much is known about this hacker yet (not even whether it’s an individual or a group, but I’m guessing the latter), but we do know a few things. They know what they’re doing. They’re an enormous thorn in Netflix’s side. And they absolutely, positively love vendor data breaches.
As you may well have heard by now, TDO made headlines recently when they posted most of the new, unreleased episodes of the hit Netflix original “Orange is the New Black” online when Netflix refused to pay a ransom."
3 Reasons Why TheDarkOverlord Loves Vendor Data Breaches
As you may well have heard by now, TDO made headlines recently when they posted most of the new, unreleased episodes of the hit Netflix original “Orange is the New Black” online when Netflix refused to pay a ransom."
MSFTSecurity Virtual Security Summit
Date: Wednesday, May 10th Time: 8:00am-10:15am PT / 11:00am-1:15pm ET
On May 10th, join leading experts as we live stream from the CISO Summit, an invitation-only event for Chief Information Security Officers of large enterprises. For the first time, we’re making this exclusive content available for you to view online.
It’s no surprise that cybersecurity will continue to be a top issue for executives, IT and security professionals in 2017. The threats are wide-ranging and plentiful, but there are best practices and solutions you can adopt to keep your organization safe.
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
A follow up to two (2) previous posts. From Forbes:
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
"Less than a week after the Federal Trade Commission warned app developers to stop using code that listened for inaudible sound to track mobile owners' TV watching habits, the Indian firm that marketed the product tells FORBES it's killing the software. But Silverpush product manager Piyush Bhatt says it's not ending the Unique Audio Beacon service because of that FTC action, or because of the many privacy concerns raised over the last year. It's simply a "business decision"."
Silverpush Quits Creeping World Out, Ceases Tracking TV Habits Via Inaudible 'Beacons'
"Less than a week after the Federal Trade Commission warned app developers to stop using code that listened for inaudible sound to track mobile owners' TV watching habits, the Indian firm that marketed the product tells FORBES it's killing the software. But Silverpush product manager Piyush Bhatt says it's not ending the Unique Audio Beacon service because of that FTC action, or because of the many privacy concerns raised over the last year. It's simply a "business decision"."
Are you encrypting your documents? Here’s what happens when you don’t
From Sophos Naked Security:
Are you encrypting your documents? Here’s what happens when you don’t
"In June 2015, someone connected to Plymouth University accidentally sent a spreadsheet containing the salaries, pensions and allowances of 245 senior staff to the wrong email address.
The error was reported to the UK’s Information Commissioner (ICO), and the file was said to have been deleted by the recipient. Until, that is, the same file turned up last week in the inbox of a local newspaper from an anonymous source."
Are you encrypting your documents? Here’s what happens when you don’t
"In June 2015, someone connected to Plymouth University accidentally sent a spreadsheet containing the salaries, pensions and allowances of 245 senior staff to the wrong email address.
The error was reported to the UK’s Information Commissioner (ICO), and the file was said to have been deleted by the recipient. Until, that is, the same file turned up last week in the inbox of a local newspaper from an anonymous source."
Dating site users spammed with smut after ‘third-party’ data leak
From Sophos Naked Security:
Dating site users spammed with smut after ‘third-party’ data leak
"Users of the Guardian’s Soulmates dating site have been getting spammed with smut after the site leaked their contact information.
The UK-based Guardian newspaper’s publisher, which runs the service, is blaming “human error” and a third-party technology provider for the leak, which has now been fixed. According to the BBC, the site — which charges users up to £32 ($41.50) per month — said that only email addresses and user IDs had been exposed directly. But that information can be used to dig out more from public profiles, said the company, including photos, relationship preferences and physical descriptions."
Dating site users spammed with smut after ‘third-party’ data leak
"Users of the Guardian’s Soulmates dating site have been getting spammed with smut after the site leaked their contact information.
The UK-based Guardian newspaper’s publisher, which runs the service, is blaming “human error” and a third-party technology provider for the leak, which has now been fixed. According to the BBC, the site — which charges users up to £32 ($41.50) per month — said that only email addresses and user IDs had been exposed directly. But that information can be used to dig out more from public profiles, said the company, including photos, relationship preferences and physical descriptions."
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
From The Independent:
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
"Researchers say the technique can even be used to de-anonymise Tor users
An increasing number of Android applications are attempting to track users without their knowledge, according to a new report.
Over recent years, companies have started hiding “beacons”, ultrasonic audio signals inaudible to humans, in their adverts, in order to track devices and learn more about their owners."
Android Apps Secretly Tracking Users By Listening To Inaudible Sound Hidden In Adverts
"Researchers say the technique can even be used to de-anonymise Tor users
An increasing number of Android applications are attempting to track users without their knowledge, according to a new report.
Over recent years, companies have started hiding “beacons”, ultrasonic audio signals inaudible to humans, in their adverts, in order to track devices and learn more about their owners."
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
From The Sun:
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
"Popular apps downloaded by millions of people are always on the look out for clandestine broadcasts which order them to begin snooping on citizens."
SPY PHONE Secret messages hidden in TV adverts can order smartphones to spy on people, researchers warn
"Popular apps downloaded by millions of people are always on the look out for clandestine broadcasts which order them to begin snooping on citizens."
This ‘dark web’ vigilante is zapping tons of child porn
From the NY Post:
This ‘dark web’ vigilante is zapping tons of child porn
"The dark web is now 20 percent lighter — thanks to a “Mr. Robot”-like vigilante hacker who has zapped one-fifth of its content in a crusade against child porn.
“Action had to be taken,” the unnamed hacker told the blog Motherboard.com, adding that he or she is a complete novice."
This ‘dark web’ vigilante is zapping tons of child porn
"The dark web is now 20 percent lighter — thanks to a “Mr. Robot”-like vigilante hacker who has zapped one-fifth of its content in a crusade against child porn.
“Action had to be taken,” the unnamed hacker told the blog Motherboard.com, adding that he or she is a complete novice."
US-CERT Alert: Security Tip (ST05-019) Preventing and Responding to Identity Theft
Privacy Week follow up from US-CERT:
Security Tip (ST05-019) Preventing and Responding to Identity Theft
Is identity theft just a problem for people who submit information online?
You can be a victim of identity theft even if you never use a computer. Malicious people may be able to obtain personal information (such as credit card numbers, phone numbers, account numbers, and addresses) by stealing your wallet, overhearing a phone conversation, rummaging through your trash (a practice known as dumpster diving), or picking up a receipt at a restaurant that has your account number on it. If a thief has enough information, he or she may be able to impersonate you to purchase items, open new accounts, or apply for loans.
Security Tip (ST05-019) Preventing and Responding to Identity Theft
Is identity theft just a problem for people who submit information online?
You can be a victim of identity theft even if you never use a computer. Malicious people may be able to obtain personal information (such as credit card numbers, phone numbers, account numbers, and addresses) by stealing your wallet, overhearing a phone conversation, rummaging through your trash (a practice known as dumpster diving), or picking up a receipt at a restaurant that has your account number on it. If a thief has enough information, he or she may be able to impersonate you to purchase items, open new accounts, or apply for loans.
US-CERT Alert: Security Tip (ST04-014) Avoiding Social Engineering and Phishing Attacks
Privacy Week follow up from US-CERT:
Security Tip (ST04-014) Avoiding Social Engineering and Phishing Attacks
What is a social engineering attack?
In a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.
Security Tip (ST04-014) Avoiding Social Engineering and Phishing Attacks
What is a social engineering attack?
In a social engineering attack, an attacker uses human interaction (social skills) to obtain or compromise information about an organization or its computer systems. An attacker may seem unassuming and respectable, possibly claiming to be a new employee, repair person, or researcher and even offering credentials to support that identity. However, by asking questions, he or she may be able to piece together enough information to infiltrate an organization's network. If an attacker is not able to gather enough information from one source, he or she may contact another source within the same organization and rely on the information from the first source to add to his or her credibility.
Subscribe to:
Posts (Atom)