Thursday, June 4, 2015

What Data Breaches Now Cost And Why

From Dark Reading:


What Data Breaches Now Cost And Why


New Ponemon report says the cost of a data breach has increased by 23% and healthcare and education breaches are the most pricey.


The actual cost of a data breach is all about industry sector and location, location, location. Healthcare and education sectors incur the highest breach costs of all industries, and Germany and the US cost victim organizations more than anywhere else in the world. Such incidents in Brazil and India cost the least, according to the new Ponemon Group 2015 Cost of a Data Breach Study: Global Analysis.

IoT Devices Hosted On Vulnerable Clouds In 'Bad Neighborhoods'

From Dark Reading:


IoT Devices Hosted On Vulnerable Clouds In 'Bad Neighborhoods'


OpenDNS report finds that organizations may be more susceptible to Internet of Things devices than they realize.
Internet of Things devices do create new opportunities for attackers to remotely exploit organizations that are too casual about securing their corporate network from unfamiliar Fitbits, according to new research released today by OpenDNS.

Twin brothers accused of leading phishing gang busted by Russian police

From Sophos Naked Security:


Twin brothers accused of leading phishing gang busted by Russian police


In the history of cybercrime, some of the worst offenders, the biggest breaches, and the baddest malware have come from Russia.


Some recent examples of major hacks carried out by Russian cybergangs include the compromise of the White House email system and the emails of President Obama; the breach of the IRS and thousands of US taxpayers' accounts; and the amassing of more than a billion username and password combinations that spurred fears of the "biggest hack in history."

Skype can no longer be crashed with these eight characters

From Sophos Naked Security:


Skype can no longer be crashed with these eight characters


Such an innocent - and 7/8ths worth of ubiquitous! - set of characters, that "http://:" (minus the quotes).


Not for Skype, though, as it turns out. They're more like Kryptonite to the internet chat app.


As of Wednesday, Skype had reportedly fixed this simple-to-exploit bug.

Microsoft Windows 10: Three Security Features To Know About

From Dark Reading:


Microsoft Windows 10: Three Security Features To Know About


Microsoft's next-generation operating system Windows 10 will be available as a free upgrade to Windows 7 and 8.1 users on July 29. But Windows Enterprise version customers will have to wait until later this year.
Application-vetting and biometric authentication headline the new main security features in Microsoft's new Windows 10 operating system, which the company today said will begin shipping for free on July 29 to users of Windows 7 and 8.

Facebook Requires SHA-2 as of Oct. 1

From ThreatPost:


Facebook Requires SHA-2 as of Oct. 1


Facebook has put developers on notice that as of Oct. 1, apps that do not support SHA-2 will no longer connect to its network.


With Tuesday’s announcement, the tech giant has fallen in line alongside Google, Mozilla and Microsoft in deprecating the SHA-1 and older hash algorithms.

Privacy Proponents Rally In Favor of Tracking Protection in Firefox

From ThreatPost:


Privacy Proponents Rally In Favor of Tracking Protection in Firefox


Privacy advocates are calling on Mozilla to better deploy Tracking Protection, a technology that offers more stringent privacy and speeds up page loads by blocking requests to tracking domains, in its Firefox browser.


The functionality has existed in the browser for months but the idea of making it a more prominent feature began to pick up steam a week and a half ago at Web 2.0, a one day workshop held in conjunction with the IEEE’s Symposium on Security and Privacy, in San Jose, Calif. A paper written by Monica Chew, a former Mozilla software engineer, and Georgios Kontaxis, a computer science student at Columbia University who previously interned at Mozilla, won best paper at the conference, and support for the initiative has slowly bubbled up since then.

2015-06-04 Link of the Day: OWASP ZAP

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.


OWASP ZAP




Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

How to raise users' expectations about security and privacy?

From Help Net Security:


How to raise users' expectations about security and privacy?


Users do not seem to care much about privacy and security.

When buying a new smartphone, for example, they rarely ask about security updates and how long the device will be supported. When downloading a new app, most of them don't even glance at the permissions it asks.

They effectively don't ask for security and privacy, and those two things consequently slip down the tech developers' and creators' list of things that are important when creating new things.

How to turn on two-factor authentication on over 100 popular online services

From Help Net Security:


How to turn on two-factor authentication on over 100 popular online services


TeleSign launched Turn It On, a new campaign featuring a guide to two-factor authentication and providing step-by-step instructions for turning on 2FA for over a 100 popular social networking, banking, cloud computing and other online services that offer the 2FA option.

“The number one tip most experts give for increasing account security and stopping the fallout from data breaches is to turn on two-factor authentication,” said Steve Jillings, CEO of TeleSign. “Yet our research shows that the majority of consumers (61 percent) do not know what two-factor authentication is, even though it’s available on almost every account, free to the consumer and just waiting to be turned on.”

Wednesday, June 3, 2015

This Simple Message Can Crash Skype Badly and Forces Re-Installation

From The Hacker News:


This Simple Message Can Crash Skype Badly and Forces Re-Installation


Just last week iPhone and iPad users were dealing with an iOS text bug that caused the app to crash and iPhones to reboot, now a similar bug has been found that takes out Skype — the popular video chat and messaging service.


Yes, Microsoft-owned Skype VoIP client is also affected by a bug that crashes almost every single version of the Skype client on both desktops and mobile phones with a single message containing just eight characters.

2015-06-03 Link of the Day: SANS Windows Forensic Analysis & Incident Response Poster

From the SANS Institute:


SANS Windows Forensic Analysis & Incident Response Poster
 



Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Online warzone: Cybercrime and terrorism are threatening Europe, and some countries aren't ready.

From Politico:


Online warzone: Cybercrime and terrorism are threatening Europe, and some countries aren't ready.


The Internet is the new underworld front line. Police, judges, lawyers and prosecutors must be trained to combat cybercrime, argued speakers Thursday on a European Commission cybersecurity panel.


Cyberterrorism has become one of the most high-profile threats to the economy and governments. Last week, reports surfaced of an attack on computers in the German parliament by an unknown perpetrator, and in April the Islamic State claimed responsibility for taking French television station TV5Monde offline.

Security startup finds stolen data on the 'Dark Web'

From CSO Online:


Security startup finds stolen data on the 'Dark Web'


Finding stolen data on the Internet is often the first sign of a breach, and a Baltimore-based startup says it has developed a way to find that data faster and more securely.


The company is called Terbium Labs, named after a malleable, silver-gray element. CEO Danny Rogers and CTO Michael Moore say they're taking a large scale, computational approach to finding pilfered data.

Researchers: Hola Fixes Incomplete

From ThreatPost:


Researchers: Hola Fixes Incomplete


Hola, a popular, free, peer-to-peer service that enables anonymous surfing and access to blocked online resources, said today it has patched vulnerabilities discovered last week that expose its millions of users to possible code execution, remote monitoring and other threats to privacy and security.


The researchers who last week disclosed vulnerabilities in the Hola Unblocker Windows client, Firefox and Chrome extensions, and the Hola Android app, however today said that the flaws are still present and that all Hola did was break a vulnerability checker proof-of-concept tool developed by the researchers.

Slew of Vulnerabilities Found in D-Link Storage Devices

From ThreatPost:


Slew of Vulnerabilities Found in D-Link Storage Devices


Researchers have identified dozens of vulnerabilities in several D-Link products, some of which allow attackers to bypass authentication requirements or upload arbitrary files to target devices.


The vulnerabilities lie in a variety of D-Link network storage devices and the company has produced updated firmware to address some of the problems. Researchers at Search-Lab discovered the vulnerabilities and said that there are a number of different D-Link devices open to the authentication bypass, as well as command injection and arbitrary file upload.

U.S. and Japan to Cooperate on Cybersecurity, Information Sharing

From ThreatPost:


U.S. and Japan to Cooperate on Cybersecurity, Information Sharing


The United States and Japan have agreed to cooperate more closely on cybersecurity and information sharing initiatives as a way to help both countries defend against future threats and attacks.


The new initiative will include a variety of components, most notably cooperation during serious incidents, cooperation between the two countries’ cybersecurity and defense units, and information sharing programs. Both countries face threats from a variety of sources, to both private and government networks. The U.S. Department of Defense and Ministry of Defense in Japan said in a statement that the countries will build on an existing foundation of cooperation on information security.

Attacker Decrypts Computers Infected with Locker Ransomware

From ThreatPost:


Attacker Decrypts Computers Infected with Locker Ransomware


Update: Computers infected by the Locker crypto-ransomware were today decrypted as promised by the malware’s author, who last week posted the decryption keys to an upload site and apologized for releasing the malware.


Lawrence Abrams of Bleeping Computer said the infected computers were decrypted for free. A post to Bleeping Computer said that the author’s decryption command only works on computers that are still infected. Any machines that have removed the malware can use a tool posted to the site over the weekend to decrypt their files.

Microsoft to Support SSH in Windows

From ThreatPost:


Microsoft to Support SSH in Windows


After several false starts, Microsoft finally is planning to support SSH in Windows and the company’s engineers also will contribute to the OpenSSH project.


While SSH has been a popular tool for remote login and command execution on many Unix and linux systems for years, Windows has not supported SSH by default, for a variety of reasons. Microsoft has had its own solutions on this front, but SSH has become the default standard for secure remote operations over the years. Customers have been asking Microsoft to add default support for the protocol, and the company now has decided to make the move.

Firmware Bug in OSX Could Allow Installation of Low-Level Rootkits

From ThreatPost:


Firmware Bug in OSX Could Allow Installation of Low-Level Rootkits


There is a vulnerability buried deep in the firmware of many Apple laptops that could allow an attacker to overwrite the machine’s BIOS and install a rootkit, gaining complete control of the Mac.


The vulnerability lies in the UEFI system on some older MacBooks, and researcher Pedro Vilaca discovered that after a MacBook is put to sleep and then brought back up, the machine’s low-level firmware is left unlocked.

IoT devices entering enterprises, opening company networks to attacks

From Help Net Security:


IoT devices entering enterprises, opening company networks to attacks


OpenDNS released The 2015 Internet of Things in the Enterprise Report, a worldwide data-driven security assessment of Internet of Things (IoT) devices and infrastructure found in businesses.

Using anonymized data from the billions of Internet requests routed through OpenDNS’s global network daily, the report details the scale to which IoT devices are present in enterprise environments and uncovers specific security risks associated with those devices. Key findings indicate IoT devices are prevalent in highly regulated industries, and infrastructure supporting those devices are vulnerable to well-known and patchable security flaws.



I find this particularly disturbing:


Though traditionally thought of as local storage devices, Western Digital cloud-enabled hard drives are now some of the most prevalent IoT endpoints observed. Having been ushered into highly-regulated enterprise environments, these devices are actively transferring data to insecure cloud servers.

Weak SSH keys opened many GitHub repositories to compromise

From Help Net Security:


Weak SSH keys opened many GitHub repositories to compromise


Github repositories of many entities, projects, and even one government could have been compromised and used to deliver malicious code due to the owners' use of easily crackable SSH keys.

"A little known feature of GitHub is the ability to look at the public SSH keys that other users have set to be authorised on their account," software developer Ben Cartwright-Cox
explains in a recent blog post detailing this finding.

Android M will give app users a lot better control over their data privacy

From Sophos Naked Security:


Android M will give app users a lot better control over their data privacy


Google unveiled the developer preview of the next version of Android at its annual I/O developer conference last week, and there's a big difference from previous versions in how it will handle user data.


Instead of forcing users to accept a long list of app permissions up front when they install an app, Android "M" devices will ask for permission to use certain features only when it needs them - what Google calls "runtime permissions."

Ex-NBA All Star Chris Gatling accused of being ID theft kingpin

From Sophos Naked Security:


Ex-NBA All Star Chris Gatling accused of being ID theft kingpin


Former NBA All-Star Chris Gatling was arrested in Scottsdale, Arizona on Saturday and charged with being the kingpin in a credit card and identity theft scam.


TMZ reports that one of the former basketball athlete's alleged victims was a woman he met on a dating site.

Educating Kids on Cyber Safety

From SANS Securing the Human Project Ouch! newsletter:


Educating Kids on Cyber Safety


The number of ways children today can go online and interact with others is staggering. New social media services pop up like weeds and there are an ever-increasing number of apps and games that connect online. In addition, many schools are migrating to services such as Google Drive and require work to be completed and submitted online. Kids are literally growing up "connected." While this has many benefits, these opportunities also come with risks. In this newsletter, we explore three areas of risk for kids and what you can do to help them stay safe.

Tuesday, June 2, 2015

Employee credentials of half of European top 500 firms exposed online

From Help Net Security:


Employee credentials of half of European top 500 firms exposed online


Cyber attacks and data breaches very often start with phishing or spear-phishing. Access to good credentials is key - whether it's for straight emailing or direct access to target email systems, etc.

Web intelligence firm Recorded Future has recently scoured the Web’s underbelly, including paste sites and forums, for exposed corporate credentials (emails and passwords), and found that 49 percent of Europes's largest companies have had credentials belonging to their employees exposed online.

Malvertising infected millions of users in 2015

From Help Net Security:


Malvertising infected millions of users in 2015


New research from Malwarebytes has found that malvertising is one of the primary infection vectors used to reach millions of consumers this year.

The analysis looked at the
three large scale zero-day attacks affecting Flash Player, and the results have been presented at Infosecurity Europe 2015.

1 in 4 UK PCs infected

From Help Net Security:


1 in 4 UK PCs infected


PandaLabs published its Quarterly Report for Q1, analyzing the IT security events and incidents from January through March 2015.

The multinational security vendor detected over 225,000 new malware strains per day in the first quarter of the year, with peaks reaching 500,000. This record-breaking figure represents a 40 percent increase over Q1 2014, and is well above the average for the entire year, which stood at approximately 205,000 new malware samples per day.

Future attacks: Hiding exploit code in images

From Help Net Security:


Future attacks: Hiding exploit code in images


Successfully hiding messages in images has already been done, but is it possible to deliver an exploit in one - and run it?

Saumil Shah, founder and CEO of Net-Square, has demonstrated at
Hack in the Box Amsterdam 2015 that it's possible, and has posited that such attacks are more than likely to crop up in the near future, as he can't be the only one who thought about this, tried it and succeeded.

Drone detection: What works and what doesn't

From Help Net Security:


Drone detection: What works and what doesn't


Another drone was discovered flying in restricted air space around the White House two weeks ago. The Secret Service found the pilot simply because they happened to see him.

In other words, there is no indication that the Secret Service would have found the pilot if he had not been in plain view. This person didn’t have bad intentions, but one day someone will. A little drone-detection education is in order:

Why you shouldn't worry about privacy and security on your phone

From Sophos Naked Security:




Why you shouldn't worry about privacy and security on your phone


Do you worry about privacy and security on your mobile phone?


Don't!


After all, worrying won't help...but making informed decisions will.


When it comes to mobile phone privacy and security, you need to ask yourself:
  • Q1. Which security settings are suitable for me?
  • Q2. How do I configure them?
  • Q3. How do I check that my settings are correct?





Google's new 'My Account' lets you tweak privacy and security settings

From Sophos Naked Security:


Google's new 'My Account' lets you tweak privacy and security settings


Google knows a lot about you.


I know, I know: DUH.


When Google's not tracking what sites users visit online so it can target-market them, its snoopy Street View cars are driving around and sniffing unsecured wireless networks and their passwords, usernames, and private email.

Facebook moves to encrypt the emails it sends users

Kudos to Facebook.  Encryption is a good thing.


From Sophos Naked Security:


Facebook moves to encrypt the emails it sends users


Facebook announced that it's introducing an experimental new feature that lets users add OpenPGP public encryption keys to their profiles so that Facebook can encrypt the email notifications it sends them.
From the post:
Whilst Facebook seeks to secure connections to your email provider with TLS, the stored content of those messages may be accessible as plaintext (with attachments) to anyone who accesses your email provider or email account.
To enhance the privacy of this email content, today we are gradually rolling out an experimental new feature that enables people to add OpenPGP public keys to their profile; these keys can be used to "end-to-end" encrypt notification emails sent from Facebook to your preferred email accounts.

Windows 10 will be available July 29, Microsoft confirms

Windows 10 is "eagerly anticipated" by whom, Apple, RedHat, Unbuntu?  Windows 8.x was about the best thing that ever happened to those companies/OS'.


From Fox News:


Windows 10 will be available July 29, Microsoft confirms


Microsoft’s eagerly-anticipated Windows 10 operating system will be available July 29, the software giant announced Monday.


Terry Myerson, executive vice president of Microsoft’s operating systems group confirmed the availability date in a blog post Monday. “Through the feedback and testing of over four million Windows Insiders, we’ve made great progress on Windows 10 and we’re nearly ready to deliver this free upgrade to all of our Windows customers,” he wrote.

Supreme Court throws out conviction for Facebook threats

I find this rather disturbing.


From Fox News:


Supreme Court throws out conviction for Facebook threats


The Supreme Court on Monday threw out the conviction of a Pennsylvania man convicted of making threats on Facebook, but dodged the free speech issues that had made the case intriguing to First Amendment advocates. 


Chief Justice John Roberts, writing for seven justices, said it was not enough for prosecutors to show that the comments of Anthony Elonis would make a reasonable person feel threatened. 


But the court did not specify to lower courts exactly what the standard of proof should be.

Your Email Typos Reveal More About You Than You Realize

From AOL Jobs:


Your Email Typos Reveal More About You Than You Realize


Like mortality, typos are part of the human condition. Someday we'll all die, and someday we'll all send an email with scrambled letters.

We are born alone, we die alone, and we misplace the occasional vowel alone.

But according to Andrew Brodsky, a doctoral candidate at Harvard Business School, those unintentional errors may be expressing more than we think.

FBI flying surveillance aircraft over US cities, planes traced to fake companies

From Fox News:


FBI flying surveillance aircraft over US cities, planes traced to fake companies


The FBI is operating a small air force with scores of low-flying planes across the country carrying video and, at times, cellphone surveillance technology -- all hidden behind fictitious companies that are fronts for the government, The Associated Press has learned. 


The planes' surveillance equipment is generally used without a judge's approval, and the FBI said the flights are used for specific, ongoing investigations. In a recent 30-day period, the agency flew above more than 30 cities in 11 states across the country, an AP review found.

Monday, June 1, 2015

Heartland's New Breach

From Data Breach Today:

Heartland's New Breach

A new breach reported by Heartland Payment Systems, the same company that in 2008 suffered a payments hack that exposed 130 million U.S. credit and debit cards, hasn't received much attention. But this latest breach could potentially be far more damaging individually to the undisclosed number of consumers affected, one fraud expert tells me.

2015-06-01 Link of the Day: eBook: Cybersecurity for Dummies

Brought to you by Help Net Security:
 
 
 

Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Millions of users installed malicious Minecraft apps from Google Play

From Help Net Security:

Millions of users installed malicious Minecraft apps from Google Play

Since August 2014, Minecraft lovers who like to play the popular game on their Android phones have been targeted with apps that are purportedly cheats for the game, but are ultimately aimed at tricking them into believing their device has been infected.

According to ESET researcher Lukas Stefanko, over 30 such apps have "sprouted" on Google Play since that first one, and have been installed by over 600,000 users.

Which malware lures work best?

From Help Net Security:

Which malware lures work best?

More often than not, malware peddlers' main goal is to deliver their malicious wares to the maximum number of users possible. Choosing the right lure is crucial to achieving that goal.

Two researchers from University of Cambridge and Southern Methodist University have examined real world data from some worms that spread over the social graph of Instant Messenger users, and have confirmed what most of us considered to be true: simple lures are more than enough, and people are more likely to fall for lures in their native language.

Scany: Network scanner for iOS

From Help Net Security:

Scany: Network scanner for iOS

Over the past five years I tested quite a few iOS applications that could be used for providing quick snaps of the local network. Most of them were free applications and very often lacking either functionality or having notable bugs in the network scanning process and/or the user interface. Recently I got a review copy of Scany, a networking tool for iOS devices and it quickly became my go to app for this type of work.

Phishing study finds major brands heavily targeted, niche sites also at risk

From Sophos Naked Security:

Phishing study finds major brands heavily targeted, niche sites also at risk

Phishing experts at the Anti-Phishing Working Group (APWG) have released their latest global survey, revealing the latest trends observed in the second half of 2014.

Russian billboard advertising contraband hides when it recognises cops

From Sophos Naked Security:

Russian billboard advertising contraband hides when it recognises cops

Moscow's Don Giulio Salumeria promises "small islands of warm and sunny Italy," offering authentic Italian prosciutto, ricotta, mozzarella and tiramisu for sale in the cold lands of Russia.

Fat lot of good any of it will do Muscovites, given that Russia has banned food imports from the European Union and the US.

Thousands of sites block and redirect Congress to Patriot Act protest page

From Sophos Naked Security:

Thousands of sites block and redirect Congress to Patriot Act protest page

As of Sunday night, 14,827 websites and counting were blocking IP addresses associated with the US Congress, redirecting visitors away from their sites and toward a page protesting mass surveillance.

Silk Road founder Ross Ulbricht gets life without parole

Cybercrime. Doesn't. Pay.

From Sophos Naked Security:

Silk Road founder Ross Ulbricht gets life without parole

Ross Ulbricht, founder of hidden online marketplace Silk Road, has been sentenced to life in prison without the possibility of parole.

Ulbricht was convicted in February of seven separate charges, but two were dropped by prosecutors shortly before sentencing.

The final judgement on the remaining five charges resulted in jail time for each, with sentences of 5, 15 and 20 years plus two life terms to be served concurrently.

"Marauders Map" - Is your location being tracked through Facebook Messenger?

From Sophos Naked Security:

"Marauders Map" - Is your location being tracked through Facebook Messenger?

A Chrome browser extension developed by a Harvard College computer science student allows people to pinpoint and track the location of Facebook Messenger users.

The extension - called Marauders Map after the magical chart from the Harry Potter books that reveals the location of every person within Hogwarts School - works by scooping up the location data of Facebook Messenger users and plotting it on a map.

Security is an Industry of Priorities

From Security Week:

Security is an Industry of Priorities

For many reasons you’ve heard and read about, security is a very difficult space. Prioritizing is an unenviable job many security professionals must do every day – do you go live with a product on time, or do you hold it to fix that security bug which could cause a catastrophic failure? The answer is nuanced, as we all know well, and while I think we all would love it if we never had to answer that question, it’s a reality. Sure, security should have been built into the thing well before release was even within sight – but you know, time, money, priorities …

Protecting the Protectors: Putting Network and Security Admins First

From Security Week:

Protecting the Protectors: Putting Network and Security Admins First

Network and system administrators are critical to the success of virtually every modern organization. Their job is inherently to both avert and fix problems across a seemingly endless number of users, devices, applications and systems. From a security perspective, all of these assets have potential vulnerabilities that need to be managed, and admins must also keep pace with a constantly evolving spectrum of threats. Staying on top of all of these challenges at the same time typically requires black-belt time management skills just to keep one’s head above water. With all of this focus on taking care of others, it is easy for admins to forget to take care of themselves.

Bitdefender Unveils Hypervisor-Based Memory Introspection Technology

From Security Week:

Bitdefender Unveils Hypervisor-Based Memory Introspection Technology

Romania-based security solutions provider Bitdefender announced on Wednesday a new technology designed to help virtualization vendors and datacenter administrators detect and block sophisticated threats.

Bitdefender Hypervisor-based Memory Introspection provides organizations insight into virtualized endpoints through hypervisor-level inspection.