Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, March 5, 2012

Is Antivirus Software Still Necessary?

Robert McMillan from Wired recently published an article about the necessity of Antivirus Software in light of the ever changing and more sophisticated threat landscape. Here is an excerpt from the article and if you would like to read the whole thing (you should) click here.


"Dan Guido, the CEO of security startup Trail of Bits also doesn’t use AV. Some security pros use it because they’re in regulated industries, or because they work with customers who require it. “If it weren’t for that,” he says, “almost nobody in the security industry would run it.”

It’s a story we heard again and again at RSA this week. The pros are generally smart enough to avoid the things that will get them hacked — visiting malicious websites or opening documents from untrusted sources. But even if they get fooled, the odds are their antivirus software catching it are pretty low. But many of these pros also believe that antivirus isn’t always that useful to the average business either.

“Ten years ago if you were to ask someone the question, ‘Do you need antivirus?’ the overwhelming response would be, ‘Absolutely, my entire security strategy is based on endpoint antivirus,’” says Paul Carugati, a security architect with Motorola Solutions. “Today … I don’t want to downplay the need for it, but it has certainly lost its effectiveness.”

The problem is that most criminals are smart enough to test their attacks against popular antivirus products. There’s even a free website called Virus Total that lets you see whether any of the most popular malware scanning engines will spot your Trojan program or virus. So when new attacks pop up on the internet, it’s common for them to completely evade antivirus detection."

Wednesday, February 22, 2012

Web Security Company Mykonos Acquired by Juniper Networks

Juniper networks closed the 80 million dollar deal February 13th and has added Mykonos, a provider of website and web application security software, to their Security Business Unit. 
The idea behind the acquisition is that Juniper can use the technology to detect attacks before the attack is in progress. The Mykonos product uses predictive analysis and deception-based software that is able to catch an attack in progress, profile the attack, learn the behavior, and then using that behavior to thwart future attacks.
Citing data from a Verizon report, Juniper says web applications are among the largest unprotected attack surfaces and the frequency of attack is increasing.
Read more about this acquisition on Network World

Wednesday, February 15, 2012

Wall Street Journal: Chinese Hackers Suspected In Long-Term Nortel Breach

In an article in the Wall Street Journal by Siobhan Gorman it is speculated that the over decade long breach of the once massive telecommunications company Nortel  was the result of hackers based on China. The article goes on to detail recent U.S. intelligence reports that Chinese hackers are a threat to world networks and that "both government-affiliated and private-sector [Chinese Hackers]—are the world's most 'active and persistent' perpetrators of industrial spying."


While China has been a hot topic in security news for a while I think the most egregious offense is the negligence on the side of Nortel executives. It was reported in the article that nothing was done from a security standpoint after the breach was discovered other than changing the passwords that were used to gain access to the network.


Publicly traded Nortel did not disclose the breach and did not believe that they had to make investors aware because it was not considered a "material" risk or event. Late last year the SEC released a formal memo stating that cyber attacks can be "material" and that an organization must investigate all cyber attacks to determine if they are in fact "material".


In the meantime, Nortel was also in the process of selling portions of their business as a result of filing for bankruptcy. Even during this process executives did not disclose the breach to potential buyers. According to the article, former CEO of Nortel Mike Zafirovski believes, " People who looked at [the hacking] did not believe it was a real issue. This never came up like, 'We have a real issue and we need to disclose to potential buyers of businesses.' Mr. Zafirovski said he didn't believe the infiltrations could be passed on to acquiring companies. 'That's a real, real stretch'."

The article in the WSJ is a great comprehensive timeline of the Nortel breach and all of the factors at play in this complicated story. While outside hackers are a threat to networks, an even greater threat to world networks is a lack of security education, or in this case negligent organizations. Tell us what you think and be sure to check out the full WSJ article here: Chinese Hackers Suspected in Long-Term Nortel Breach


Friday, February 3, 2012

Anonymous Strikes Again - Texas Police Officer Edition

A hacker affiliated with Anonymous has gained access to the Texas Police Association website and obtained names, addresses and police departments of more than 700 officers across the state. These records were then published along with a link to a news story about a Texas police officer being placed on administrative leave while being investigated for child pornography charges.


This is not the first time the Texas Police Association's website has been hacked, but it is the first time personal data has been revealed. Erwin Ballarta, Executive Director of the Texas Police Association has contacted the FBI.



Thursday, January 26, 2012

Symantec Urges Customers to Disable pcAnywhere

The breach of Symantec source code by an Indian hacking group a few weeks ago was all but brushed off by the security giant. Symantec went on the record saying that the leaked code is, "so old that current out-of-the-box security settings will suffice against any possible threats that might materialise as a result of this incident." 

However, in a posting on their website yesterday and an accompanying technical white paper, Symantec suggests that pcAnywhere customers are at a heightened risk and advises users to "disable the product until Symantec releases a final set of software updates that resolve currently known vulnerability risks." Customers could be at risk for "man in the middle" attacks where an unauthorized person accesses pcAnywhere transactions and intercepts data as it travels from its source to its destination. These attacks are more likely because the blueprints for Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks (Norton Utilities and Norton GoBack) and pcAnywhere were accessed in the breach. The information contained in these blueprints makes it easier to identify and exploit software vulnerabilities. 

Symantec reps say that there are 50,000 people using the standalone version of pcAnywhere along with an unknown number of users who received the product bundled within other security packages.

Wednesday, January 25, 2012

Almost 1/3 of Americans Own an E-Reader or a Tablet

According to new research released by the good people at The Pew Internet Project,  "the share of adults in the United States who own tablet computers nearly doubled from 10% to 19% between mid-December and early January and the same surge in growth also applied to e-book readers, which also jumped from 10% to 19% over the same time period." This brings the total number of Americans who own at least one tablet or e-reader to 29%.

gadget ownership over holidays



This study puts solid numbers on the tablet and e-reader market growth speculations. It is becoming more and more important for organizations to look into how they are going to integrate tablet and, more broadly,  mobile security into their enterprise DLP strategy. 

Two of the largest enterprise DLP vendors,Symantec and Websense, are introducing a DLP plug-in for tablets this year. The concept for tablets is pretty basic and shared for the most part across vendors. It works like an endpoint monitor that views and classifies information as it flows from a tablet to a web or cloud application. If the content is deemed appropriate it is allowed to reach its destination, and if the content is sensitive it will either notify DLP administrators, block the content or a combination of both.

Tuesday, January 24, 2012

Unsecured Video Conferencing Systems May be Exposing Your Meetings





"SAN FRANCISCO — One afternoon this month, a hacker took a tour of a dozen conference rooms around the globe via equipment that most every company has in those rooms; videoconferencing equipment.

With the move of a mouse, he steered a camera around each room, occasionally zooming in with such precision that he could discern grooves in the wood and paint flecks on the wall. In one room, he zoomed out through a window, across a parking lot and into shrubbery some 50 yards away where a small animal could be seen burrowing underneath a bush. With such equipment, the hacker could have easily eavesdropped on privileged attorney-client conversations or read trade secrets on a report lying on the conference room table.

In this case, the hacker was HD Moore, a chief security officer at Rapid7, a Boston based company that looks for security holes in computer systems that are used in devices like toaster ovens and Mars landing equipment. His latest find: videoconferencing equipment is often left vulnerable to hackers."
Read the rest of this article here: Flaws in videoconferencing systems put boardrooms at risk

Wednesday, January 4, 2012

Stratfor Breach

New year, new breach investigation. This time hackers claiming to be a part of the "hacktivist" group Anonymous have breached Austin based research company Strategic Forensics. A spokesperson from Anonymous denies this claim and lays blame on a hacker known as “Sabu,” who is closely associated with the LulzSec group.


Strategic Forensics, commonly known as "Stratfor", lost data for about 4,000 clients including passwords, credit card details, and home addresses. 


The hacker or hackers claim they will use the credit card information to make fraudulent donations to charities. Many experts speculate that they will also make efforts to decrypt the passwords and then use them to try and gain access to other accounts held by Stratfor's considerably high-end clientele. Their clients span many big name organizations including U.S. Military, U.S. State Department, Bank of America, JP Morgan Chase, IBM, and Microsoft employees.


This initial dump of client information is apparently not final blow for Stratfor from Anonymous. The group is planning to release millions of private company emails as well.


For a great article on this breach: Digital Trends -- Stratfor Breach

Monday, November 28, 2011

Cyber Monday Means Loss of Productivity

As Black Friday has come and gone many consumers are excited for Cyber Monday. The only problem? Many Americans who plan to partake in the deals offered online are doing so at work. According to a recent survey done by the staffing firm Adecco,nearly half of American workers (46 percent) plan to make a dent in their holiday shopping during work hours – either through online shopping while at work, shopping on lunch breaks, taking sick days or cutting out a little early periodically. Another similar survey done by Randstad shows that 40% of employees plan to only spend an hour online shopping at work while 1 in 3 plan to spend over 5 hours of their work day shopping online.


The lure of online deals does not only pose a threat to productivity, but it can also expose the corporate network to malware. Malware and spam attacks are often quickly formulated and executed based on current events and popular online happenings. These malicious websites are found as links that are a part of common searches such as "Cyber Monday Deals". 


Since many people will be ordering online the use of online postal tracking will go up as well, because of this hackers will be sending postage and shipping related emails to trick people into downloading malicious attachments. Websense Security Labs cites this type of spam as one of the "Top 5 Malicious Spam Subjects" .


Security Labs has detailed the type of subjects and email contents everyone should be on the lookout for.

  • USPS Invoice copy ID46298 (numbers vary)
  • FedEx: New Agent File Form, trackid: 1V6ZFZ7FEOHUQ (numbers vary)
  • DHL Express Notification for shipment 90176712199 (numbers vary)
The email will look like this:
The moral of the story is to shop at home, be careful, and no matter how good the deal looks, do not suspend judgement to click on a strange looking link. Also remember that shipping companies will never require you to download an email attachment to get information about your packages and if you are still concerned, check their website for accurate and up to date information.


Thursday, November 17, 2011

Sacramento Health System Breached - 4.2 Million Records


Two branches of the Sutter Health network were breached in October of this year after an employee's laptop was stolen. The laptop contained databases with Personally Identifiable Information and Personal Health Information for 4.2 million patients. These records are from dates as far back as 1995 and as recent as this year.  Sutter does say that the employee's laptop was not encrypted even though they are currently in the process of encrypting all laptops across the enterprise. 

Data stored in an unprotected state on a laptop or desktop PC puts organizations at risk of becoming the next data breach headline, like Sutter. Only strong encryption of all data on hard disks counters the threat of losing critical intellectual property, customer and/or competitive information and provides a safe harbor from the high profile public disclosures and costly remediation mandated by privacy laws. To protect mobile data from the risks of loss or theft of a laptop or desktop, enterprises not only need the security provided by strong encryption, but also a standards-based solution to the practical issues that organizations encounter when deploying endpoint data protection.


Sutter Health network of care press release below: 

/PRNewswire/ -- Sutter Physicians Services (SPS) and Sutter Medical Foundation (SMF) — two affiliates within the Sutter Health network of care — announced the theft of a company-issued password-protected unencrypted desktop computer from SMF's administrative offices in Sacramento the weekend of Oct. 15, 2011. Following discovery of the theft, Sutter Health immediately reported it to the Sacramento Police Department. It also began an internal investigation. The computer did not contain patient financial records, social security numbers, patients' health plan identification numbers or medical records. While no medical records themselves were on the computer, some medical information was included for a portion of patients.

Following a thorough internal review, Sutter Health discovered that the stolen computer held a database that included two types of information:
  1. For approximately 3.3 million patients whose health care provider is supported by Sutter Physician Services (SPS), the database included only the following patient demographic information dated from 1995 to January 2011: name, address, date of birth, phone number and email address (if provided), medical record number and the name of the patient's health insurance plan. SPS is an organization that provides billing and managed care services for health care providers with which it contracts, including facilities within the Sutter Health network. Patients who think they may be affected should visit www.sutterhealth.org to see the list of impacted health care providers.
  1. For approximately 943,000 SMF patients, the database contained the above demographic data as well as the following information dated from January 2005 to January 2011: dates of services and a description of medical diagnoses and/or procedures used for business operations. Because the data of SMF patients was broader in scope, Sutter Medical Foundation has begun the process to notify these patients by mail. Patients should receive letters no later than Dec. 5.

Read more: http://www.sacbee.com/2011/11/16/4059251/sutter-health-informs-patients.html#ixzz1dyUMTGrj

Thursday, November 10, 2011

Two-fer Thursday!

It is rare that we see two security and data breach related reports cause a stir on the same day. However, today Forrester and lesser known Risk Based Security Inc. delivered two reports with a similar theme -- data breaches can and will affect you personally as well as your organization.


Forrester reports that in a questionnaire distributed to 2,300 IT executives via LinkedIn 25% responded that their organization has had a data breach in the last year. Even more surprising, 21% declined to answer despite being assured that names and responses are kept confidential. 7% of very honest IT executives reported that they don't know and Forrester believes that many of the remaining who reported no breaches in the last year, were probably breached but just don't know it yet.


The above findings by Forrester make this second report more understandable but no less shocking. According to Risk Based Security Inc. and research done by the Open Security Foundation as of October 2011 there have been over 1 billion records exposed. In the first nine months of 2011 we have seen  176,385,870 records exposed compared to 88,473,589 records for all of 2010.


All of these statistics server to prove a point that organizations still are not taking the necessary measures to protect their data and the data of their customers and clients. When it comes to securing your organization taking a holistic approach is the first step to enforcing better protection. By better understanding business needs and processes your security department can better determine where risks reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.


Links to the above reports
Forrester
Risk Based Security Inc.

Monday, November 7, 2011

Advanced Persistent Threats -- Something to worry about or just another buzzword?

In recent months there has been increased discussion in the media about advanced persistent threats (APTs) and even more discussion about how to define an APT. McAfee defines an APT as a "targeted cyberespionage or cybersabotage attack that is carried out under the sponsorship or direction of a nation-state for something other than a pure financial/criminal reason or political protest." Other definitions are more broad describing an APT as a cybercrime category in which the attacker utilizes the full spectrum of attack vectors to reach and compromise the their target. 


Whatever definition is used often is the definition that best serves the main goal of the article or advertisement, which has lead many IT security professionals to put advanced persistent threats in the "buzzword" category. It seems that despite those non-believers almost two-thirds of enterprise information security managers believe their businesses have been targeted by advanced persistent threats and  72% expect to see such attacks continue in the future. These numbers are according to an Enterprise Strategy Group report on  advanced persistent threats. These managers believe that these attacks are being carried out, in order of likelihood, by hacktivist groups such as Anonymous, organized crime rings, competitors conducting reconnaissance or perpetrating industrial espionage, foreign governments, and terrorists.

Whether or not APT is just another catchy acronym we can see that based on the survey results, organizations are responding in the correct way. 51% of respondents said that senior executives have increased the amount of money allocated to training employees on security strategies, 33% now meet more frequently with their Chief Information Security Officer (CISO) or IT risk team and 18% have created the role of CSO or CISO, or another type of senior security position.  The trend of organizations to staff Risk and Security related positions, as direct report positions to the Board of Directors, continues to demonstrate the importance of integrating technology with business process.  Risk and Security of the organization and its critical technology infrastructure (uptime and productivity) and its confidential and sensitive data (GRC, Brand Loss, IP Loss) should be a fundamental to any best-practices organization.   


With the increasing sophistication of the threat matrix, reliance on under managed technologies (AV, IPS, IDS) is simply not enough.  As we continue to build more efficient and open B2B and B2C models, an organization must take into account the context of the information being accessed starting with the roles of people accessing that information, the sensitivity of the information, and the actual use of the information, and enforcement policies.   This takes coordination, via the CISO, of Executives, HR, Legal,  Technology , and Business Unit leaders.

Monday, August 22, 2011

Hacking Group Anonymous Breaches InfraGard

On August 18th hacking group Anonymous published documents stolen from Richard Garcia, senior vice president of Vanguard Defense Industries. The collection of documents contains internal meeting notes and contracts, schematics, non-disclosure agreements, personal information about other VDI employees, and several dozen 'counter-terrorism' documents classified as 'law enforcement sensitive' and 'for official use only.'


Mr. Garcia is also a director of U.S. defense contractor InfraGard, who was breached by one of Anonymous' affiliate hacking groups LulzSec. In the initial post by Anonymous, they state that Mr. Garcia's account was easily hacked because he had not changed some of his passwords after the InfraGard breach in June.


One of the most sensitive emails that was published contains a response from one of Vanguard's chief executives responding to a U.S. Department of Justice contact regarding the suitability of its ShadowHawk drones for use by U.S Marshals. There are also reports that there are documents that show evidence of a Merrill Lynch wealth management adviser giving private advance notice to Garcia about upcoming S&P US credit rating downgrades. This report has yet to be substantiated.



Wednesday, June 22, 2011

Mansfield, Ohio -- Area Agency on Aging: Breached due to Lost Laptop

On June 3, an employee of the Area Agency of Agency in Mansfield, Ohio had a laptop stolen from their car. This resulted in the exposure of personal data related to 43,000 customers.  The laptop was assigned to a Passport case manager. The personal data was health related in nature and also contained the  personal contact information of 35,000 related clients' personal representatives.  


According to a report in The Morning Journal  the Area Agency on Aging had the following response to the Breach:


“The Area Agency on Aging understands the importance of safeguarding our consumer’s personal information and takes that responsibility very seriously,” said Duana Patton, chief executive officer. “We deeply regret that this incident occurred, and we have already taken steps to ensure our laptops are properly equipped to secure personal information from unauthorized access in the future.” 


Unfortunately many organizations take a reactive approach to encrypting endpoint devices such as laptops and cell phones that may contain sensitive information. 


Oil giant BP, had a similar incident this spring in which an employee lost their laptop during routine business travel. The laptop contained  unencrypted personal data such as names, social security numbers, and dates of birth for over 13,000 people who submitted claims with the company after last years oil spill. 


According to Ponemon's "Cost of a Lost Laptop" report, a lost or stolen, unencrypted laptop, will cost an organization $20,000 more than if an encrypted laptop is lost or stolen. Read the full Ponemon report here: Cost of a Lost Laptop Study - Ponemon

77% Of Business Experienced Data Loss Last Year

A survey of over 2,400 IT security administrators conducted by Check Point and Ponemon reveals 77% of businesses experienced data loss last year. This number does not correlate with the number of reported breaches, but with increasing stringency of compliance regulations, we may begin to see more and more reported breaches.

The study’s research shows organizations are struggling with the growing set of security priorities and limited employee awareness about corporate security policies. Over 55 percent of companies surveyed are using more than seven vendors to perform security tasks. Because of this, organizations struggle with minimizing TCO and maximizing performance.

Approaching security with a holistic view of an organization’s technology is the first step in enforcing better protection. This helps to determine where risks can reside. Security is more than a simple technology solution. Aligning IT security with business needs requires a combination of policies, people and enforcement.

Monday, May 23, 2011

Massachusetts Executive Office of Labor and Workforce Development Breached

Client names, social security numbers, email addresses and residential addresses and bank account detail of users of the Massachusetts Executive Office of Labor and Workforce Development claim system. The 1,200 system users were warned that their personal details may have been accessed by a data-stealing worm named W32.QAKBOT.

Symantec defined the W32.QAKBOT as a worm that is capable of keylogging, collecting cookie data, DNS, operating system, private keys from system certificates and URLs. The virus can spread through a computer network, open a back door on a compromised computer that would allow someone to control the machine and keep itself hidden.

Although the problem has been fixed, Executive Office of Labor and Workforce Development is hoping people continue to use the system. It has been communicated that all possible steps are being taken to avoid future recurrence.

Monday, May 9, 2011

Sony CEO Apologizes for Data Breach

Last week, Sony announced that 24.6 million names, addresses, e-mails, birth dates, phone numbers, potentially credit cards and other private information from Sony Online Entertainment accounts could have been taken from company servers or from an old database.

Last month,  a hacker attack on the PlayStation Network may have caused the stealing of data from 77 million user accounts.

This totals over 100 million accounts that were potentially compromised.  Each potentially affected customer will get $1 million in identity theft insurance. 

Sony CEO, Howard Stringer, apologized for “inconvenience” and “concern” the data breach has caused. The company is working on restoring full and safe service as soon as possible. Stringer has a lot of brand mending to do as this breach is being referred to as one of the largest Internet security break-ins in history

Thursday, May 5, 2011

Epsilon Breach Estimated to Cost $4B


The highly publicized data breach of email service provider Epsilon could cost the organization upwards of four billion dollars. This estimate comes from a report done by cyber risk advisory firm CyberFactors, and is dependent on what is done with the data.
               
According to CSO.com
"That figure [$4 billion] could be reached if criminals get hold of the email addresses and successfully exploit them to gather more personal information and carry out a spear-phishing blitz, according to the report. 'However, until such an event takes place and can be directly linked back to this specific breach, the estimate remains theoretical, but certainly possible given the multitude of sites that use email addresses as user IDs,' the report says."
The report goes on further to estimate that the Costs to Epsilon's customers could be $5.5 million each for notification of their customers about the theft, settlements to those customers, legal defense, compliance adjustments and loss of business.

In contrast to this report CEO of Alliance Data Systems, Epsilon's parent company, Ed Heffernan says he sees no meaningful cost or liability stemming from the incident and that they will not see the customer churn that often follows a breach. 

Although Heffernan believes he will not see significant costs as a result of the breach, the widely known act could hold weighty impacts to Epsilon and even Alliance Data’s brand. If Epsilon is lucky, the company has the potential to escape any non-compliance fines, but this does not mean they will be free of detrimental brand impact. Brand losses are approximately 49% of the cost of a data breach and Heffernan may not be taking this into account when he states that the cost will not be meaningful.

If you were a company who needed third party email services, would you want to do business with a company that had more than a million customer records at risk? Probably not.  A tactical data loss prevention strategy may have saved this company, and those customers affected by the breach the trouble this breach has presented.

Monday, April 4, 2011

Marketing Firm's Customer Data Exposed by Hackers


One of the country's largest e-mail marketing firms, Epsilon, reported that on March 30th, “a subset of Epsilon clients’ customer data [was] exposed by an unauthorized entry into Epsilon’s email system."


Epsilon is a subsidiary of Alliance Data Systems and sends over 40 billion emails annually for their clients. These clients include 7 of the top Fortune 10 companies.

Companies whose clients may have been affected by this breach include:
Brookstone
Capital One Financial Corp.
Citigroup 
J.P. Morgan Chase & Co.
Kroger Co.
Marriott International Inc. 
McKinsey & Co.
New York & Co.
Ritz-Carlton
TiVo Inc.
US Bancorp
Walgreen Co.

The hackers were only able to access names and email addresses, and it is still unknown if the information has been used in any email based attacks aimed at obtaining credit card or social security numbers.

This attack reminds us to be vigilant and skeptical of all unsolicited emails or emails from unknown senders. Keep in mind the following tips next time you check your email:
  1. Under no circumstances should anyone respond to an email from an unknown or known party that asks for sensitive personal data. 
  2. If you receive an email from an unknown sender, delete it and mark it as spam in your email client. If you receive an email asking for personal or financial information from an organization that you are a customer of, notify their customer service office immediately.
  3. Also, do not click on links in email or pop-up messages that may come up after clicking a link in an email that asks for your personal or financial information. 
  4. Always use anti-spyware software and a firewall to protect your computer.
  5. Never open or download attachments from an email from an unknown sender.



Wednesday, March 30, 2011

Lost Laptop Exposes 13,000 Oil Spill Victims

According to a BP spokesman the laptop was lost on March 1 by an employee on routine business travel.


The laptop held unencrypted information including the names, Social Security numbers, addresses, phone numbers, and dates of birth of people who filed claims related to the Deepwater Horizon accident that occurred last spring.


"The lost laptop was immediately reported to law enforcement authorities and BP security, but has not been located despite a thorough search," BP said Tuesday. They added that the device was equipped with a tool that would allow them to disable the system under certain circumstances. No further details on the nature of the circumstances that would be required to be met were given.


Unfortunately lost laptops containing sensitive personal data are lost every day, and even more commonly when traveling. In Ponemon's "Billion Dollar Lost Laptop Study" the institution found that of laptops lost 46% contained confidential data, and only 30% of those laptops were encrypted, as shown below. Encryption is not the only method used to protect confidential data on a laptop, but it is one of the most easily implemented and trusted ways to protect your company's and customer's sensitive data.