Showing posts with label 3rd Party Security. Show all posts
Showing posts with label 3rd Party Security. Show all posts

Monday, February 27, 2012

Stratfor Documents Obtained in December 2011 Breach - Released

The fallout from the December 2011 breach of Stratfor was not fully felt until today, when the website WikiLeaks released a statement that they would begin to publish "5 million e-mails from the private intelligence company Stratfor, starting with a company "glossary" that features unflattering descriptions of U.S. government agencies." 


Stratfor will not confirm nor deny the authenticity of the documents but they do make mention that the documents can now be easily edited by those who release the information.


Wikileaks has stated that the documents will be released through a network of more than 25 news outlets and activist groups in the coming weeks. The first document out was titled "The Stratfor Glossary of Useful, Baffling and Strange Intelligence Terms," featuring brief and sometimes humorous definitions and blunt assessments of U.S. intelligence and law enforcement.


To read more about Stratfor and Wikileaks click here
To read the full text of what was released click here

Tuesday, February 7, 2012

Man in the Browser Attacks Online Banking Customers

Last week you may remember that Symantec notified pcAnywhere customers of the potential for "Man in the Middle" attacks as a result of their leaked source code. This week a malware testing lab out of Britain,  S21sec, is warning online banking users of "Man in the Browser" or MitB threats. 


The idea behind these two threats, despite the different name, is the same. The user downloads malware accidentally and the application lives in their browser and alters what is seen on the site and where the entered data goes. Some more sophisticated versions will change payment details and amounts to try and cover the malicious activity.


Fortunately, many banks use software that understands a user's patterns and when something out of the norm occurs, the bank will alert the account holder of the activity. 


Read more: UPI.com

Tuesday, January 24, 2012

Unsecured Video Conferencing Systems May be Exposing Your Meetings





"SAN FRANCISCO — One afternoon this month, a hacker took a tour of a dozen conference rooms around the globe via equipment that most every company has in those rooms; videoconferencing equipment.

With the move of a mouse, he steered a camera around each room, occasionally zooming in with such precision that he could discern grooves in the wood and paint flecks on the wall. In one room, he zoomed out through a window, across a parking lot and into shrubbery some 50 yards away where a small animal could be seen burrowing underneath a bush. With such equipment, the hacker could have easily eavesdropped on privileged attorney-client conversations or read trade secrets on a report lying on the conference room table.

In this case, the hacker was HD Moore, a chief security officer at Rapid7, a Boston based company that looks for security holes in computer systems that are used in devices like toaster ovens and Mars landing equipment. His latest find: videoconferencing equipment is often left vulnerable to hackers."
Read the rest of this article here: Flaws in videoconferencing systems put boardrooms at risk

Friday, January 6, 2012

Symantec confirms source code leak in two enterprise security products


Computer world has a great article on Symantec's recent source code leak in India. It was supposedly taken from a government database in India where it is not uncommon for tech companies to have to submit their source code to prove they are not using their software to spy on the government. I think many organizations will take notice of this breach and begin to push back more on the requirements to submit source code.
Computerworld - Symantec late Thursday confirmed that source code used in two of its older enterprise security products was publicly exposed by hackers this week.In a statement, the company said that the compromised code is between four and five years old and does not affect Symantec's consumer-oriented Norton products as had been previously speculated."Our own network was not breached, but rather that of a third party entity," the company said in the statement. "We are still gathering information on the details and are not in a position to provide specifics on the third party involved. Presently, we have no indication that the code disclosure impacts the functionality or security of Symantec's solutions," the statement said.Symantec spokesman Cris Paden identified the two affected products as Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2. Both products are targeted at enterprise customers and are more than five years old, Paden said."We're taking this extremely seriously, but in terms of a threat, a lot has changed since these codes were developed," Paden said. "We distributed 10 million new signatures in 2010 alone. That gives you an idea of how much these products have morphed since then, when you're talking four and five years."Symantec is developing a remediation process for enterprise customers who are still using the affected products, Paden noted. Details of the remediation process will be made available in due course, he added.

Wednesday, June 22, 2011

77% Of Business Experienced Data Loss Last Year

A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.

The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.

Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.

Monday, May 9, 2011

Sony CEO Apologizes for Data Breach

Last week, Sony announced that 24.6 million names, addresses, e-mails, birth dates, phone numbers, potentially credit cards and other private information from Sony Online Entertainment accounts could have been taken from company servers or from an old database.

Last month,  a hacker attack on the PlayStation Network may have caused the stealing of data from 77 million user accounts.

This totals over 100 million accounts that were potentially compromised.  Each potentially affected customer will get $1 million in identity theft insurance. 

Sony CEO, Howard Stringer, apologized for “inconvenience” and “concern” the data breach has caused. The company is working on restoring full and safe service as soon as possible. Stringer has a lot of brand mending to do as this breach is being referred to as one of the largest Internet security break-ins in history

Thursday, May 5, 2011

Epsilon Breach Estimated to Cost $4B


The highly publicized data breach of email service provider Epsilon could cost the organization upwards of four billion dollars. This estimate comes from a report done by cyber risk advisory firm CyberFactors, and is dependent on what is done with the data.
               
According to CSO.com
"That figure [$4 billion] could be reached if criminals get hold of the email addresses and successfully exploit them to gather more personal information and carry out a spear-phishing blitz, according to the report. 'However, until such an event takes place and can be directly linked back to this specific breach, the estimate remains theoretical, but certainly possible given the multitude of sites that use email addresses as user IDs,' the report says."
The report goes on further to estimate that the Costs to Epsilon's customers could be $5.5 million each for notification of their customers about the theft, settlements to those customers, legal defense, compliance adjustments and loss of business.

In contrast to this report CEO of Alliance Data Systems, Epsilon's parent company, Ed Heffernan says he sees no meaningful cost or liability stemming from the incident and that they will not see the customer churn that often follows a breach. 

Although Heffernan believes he will not see significant costs as a result of the breach, the widely known act could hold weighty impacts to Epsilon and even Alliance Data’s brand. If Epsilon is lucky, the company has the potential to escape any non-compliance fines, but this does not mean they will be free of detrimental brand impact. Brand losses are approximately 49% of the cost of a data breach and Heffernan may not be taking this into account when he states that the cost will not be meaningful.

If you were a company who needed third party email services, would you want to do business with a company that had more than a million customer records at risk? Probably not.  A tactical data loss prevention strategy may have saved this company, and those customers affected by the breach the trouble this breach has presented.

Wednesday, April 20, 2011

2011 Verizon Data Breach Investigations Report

Verizon recently released their Data Breach Investigations Report.  The report covers approximately 800 data breach cases from 2010.  The review of breaches covers threat agents and actions, how breaches typically occur, and provides statistics on breached organizations.

Below you will find a summary of organizations who have reported breaches in the past year by size. It may be surprising to find that organizations with 11 to 100 employees have reported 436 breaches.



1 to 10
46
11 to 100
436
101 to 1,000
74
1,001 to 10,000
49
10,001 to 100,000
59
Over 100,000
55
Unknown
40


This may not be surprising to you, but the report concludes that 97 percent of the breaches could have been avoided by using simple controls. Do you have the simple controls in place to protect your organization's data? According to the study, organizations should focus mitigation efforts in the following areas:


Monday, April 4, 2011

Marketing Firm's Customer Data Exposed by Hackers


One of the country's largest e-mail marketing firms, Epsilon, reported that on March 30th, “a subset of Epsilon clients’ customer data [was] exposed by an unauthorized entry into Epsilon’s email system."


Epsilon is a subsidiary of Alliance Data Systems and sends over 40 billion emails annually for their clients. These clients include 7 of the top Fortune 10 companies.

Companies whose clients may have been affected by this breach include:
Brookstone
Capital One Financial Corp.
Citigroup 
J.P. Morgan Chase & Co.
Kroger Co.
Marriott International Inc. 
McKinsey & Co.
New York & Co.
Ritz-Carlton
TiVo Inc.
US Bancorp
Walgreen Co.

The hackers were only able to access names and email addresses, and it is still unknown if the information has been used in any email based attacks aimed at obtaining credit card or social security numbers.

This attack reminds us to be vigilant and skeptical of all unsolicited emails or emails from unknown senders. Keep in mind the following tips next time you check your email:
  1. Under no circumstances should anyone respond to an email from an unknown or known party that asks for sensitive personal data. 
  2. If you receive an email from an unknown sender, delete it and mark it as spam in your email client. If you receive an email asking for personal or financial information from an organization that you are a customer of, notify their customer service office immediately.
  3. Also, do not click on links in email or pop-up messages that may come up after clicking a link in an email that asks for your personal or financial information. 
  4. Always use anti-spyware software and a firewall to protect your computer.
  5. Never open or download attachments from an email from an unknown sender.



Tuesday, November 23, 2010

Security Software Vendor, Omniquad, Exposes Customer Details on the Web

On October 4, 2010, it was brought to the attention of the managing director of Omniquad that a helpdesk call system had posted sensitive information about their customers to the internet.  Omniquad, an anti-spyware company, was quick to place blame on the third-party vendor of the exploited software. A spokesperson from Privacy International expressed the feelings of disappointment that many share, "Security and privacy should be at the core of everything they [Omniquad] do and that includes carrying out security audits of all third-party software and services they offer."

This breach brings to light the fact that relying on the security measures of partners or third-party vendors is not enough. Carefully assessing risks to your organization does not stop at the front door.