info-blog-icon.jpg    Chinese hacker who breached Google gained access to sensitive data, US officials say

http://www.washingtonpost.com/world/national-security/chinese-hackers-who-breached-google-gained-acc...

 

According to current and former government officials, they gained access to a sensitive database with years’ worth of information about U.S. surveillance targets

 

 

info-blog-icon.jpg   Why don’t risk management programs work?

http://www.networkworld.com/news/2013/052013-risk-management-programs-269400.html

 

“Risk management programs don’t work because our profession doesn't, in large part, understand risk” – agree? Disagree?

 

 

info-blog-icon.jpg   Journalists Find Massive Data Security Lapse, Get Threats Instead of Thanks

http://www.slate.com/blogs/future_tense/2013/05/21/scripps_journalists_reportedly_find_data_security...

 

Telecom firms may sue the reporters who uncovered mishandled customer data; sounds like security research to me

 

 

info-blog-icon.jpg   Few utilities complying with voluntary anti-Stuxnet measures

http://thehill.com/blogs/hillicon-valley/technology/301091-few-utilities-complying-with-voluntary-an...

 

“A voluntary approach to cybersecurity might make sense for some sectors, but experience shows that it cannot be relied upon to protect the electric grid.”

 

 

info-blog-icon.jpg   Federal government  hunkers down for massive cyber attack Tuesday

http://www.buzzfeed.com/evanmcsan/federal-government-hunkers-down-for-massive-cyber-attack-tue?utm_s...

 

#OPUSA  could affect agencies across the Federal government

 

 

info-blog-icon.jpg   Research reveals reality of password sniffing over HTTP connections

http://www.scmagazineuk.com/research-reveals-reality-of-password-sniffing-over-http-connections/arti...

 

When you load a login form over HTTP, ‘anything you do after that is a little bit pointless'

 

 

info-blog-icon.jpg   'Aggressive' espionage-for-hire operation behind new Mac spyware

http://www.zdnet.com/aggressive-espionage-for-hire-operation-behind-new-mac-spyware-7000015613/

 

An Indian malware service is building attack software for projects involving secret surveillance

 

 

info-blog-icon.jpg   Opinion: Cyber security, what’s in a word?

http://www.infosecurity-magazine.com/view/32534/comment-cybersecurity-and-reality-whats-in-a-word/

 

Hate the ‘cyber’ pre-fix that’s taking over security news? Here’s why you should get over it

California’s Right to Know law was recently put on hold because of push-back from various technology companies and business lobbies. The law aimed to provide consumers with greater transparency on how online vendors use their data.

 

Listen to Tim Eriln, Lamar Bailey, Andrew Storms and Dwayne Melançon discuss why the Right to Know law and more oTripwire's State of Security blog. 

info-blog-icon.jpg     Chinese hackers resume attacks on US targets

http://www.nytimes.com/2013/05/20/world/asia/chinese-hackers-resume-attacks-on-us-targets.html

 

Unit 61398, the People’s Liberation army  cyber unit featured in  the Mandiant report earlier this year, is now operating at 60 percent to 70 percent of previous levels

 

 

info-blog-icon.jpg     Millions hit by Yahoo Japan hack attack

http://www.bbc.co.uk/news/technology-22594136

 

22 million IDs, but no passwords or other identifying info, may have been stolen

 

 

info-blog-icon.jpg     Large Attacks Hide More Subtle Threats In DDoS Data

http://www.darkreading.com/monitoring/large-attacks-hide-more-subtle-threats-i/240155145

 

According to DDoS mitigation experts the worst denial of service attacks are not the biggest ones, not the ones that knock applications down

 

 

info-blog-icon.jpg     Want To Destroy Any Hope Of Serious Cybersecurity? Give The DOJ Its Desired Backdoor Wiretaps On All Communications

http://www.techdirt.com/articles/20130517/08111723117/want-to-destroy-any-hope-serious-cybersecurity...

 

The Obama administration has been "considering" the latest version of the DOJ's plan to require backdoor wiretapping abilities in any form of digital communication

 

 

info-blog-icon.jpg     Jailed hacker designs device to thwart ATM skimming

http://www.net-security.org/secworld.php?id=14931

 

The device is meant to be installed over the ATM's card slot or incorporated into new ATM models, and requires cards to be inserted into the device longer side first, then the card is rotated and and pushed into the slot – too simple?

 

 

info-blog-icon.jpg     Think your Skype messages get end-to-end encryption? Think again….

http://arstechnica.com/security/2013/05/think-your-skype-messages-get-end-to-end-encryption-think-ag...

 

“Right now is that there's a mismatch between the privacy people expect and what Microsoft is actually delivering…”

 

 

info-blog-icon.jpg     DDos for hire works with the blessing of FBI, operator says

http://arstechnica.com/security/2013/05/ddos-for-hire-service-works-with-blessing-of-fbi-operator-sa...

"Since it is a public service on a public connection to other public servers this is not illegal"

info-blog-icon.jpg     Financial Times Twitter and tech blog accounts hacked

http://online.wsj.com/article/SB10001424127887324767004578488862256223962.html

 

Twitter and two-factor authentication are getting to be a regular item in the media

 

 

info-blog-icon.jpg     Saudi websites under attack following surveillance accusations

http://bits.blogs.nytimes.com/2013/05/17/saudi-web-sites-under-attack-following-surveillance-accusat...

 

#OpSaudi is mostly DDoS with a little SQL injection and Twitter hacking mixed in

 

 

info-blog-icon.jpg     Smartphones become wide avenue for hackers

http://seattletimes.com/html/businesstechnology/2020993553_smartphonehackersxml.html

 

Smartphones are increasingly popular with thieves who see the devices as another way to tap into bank accounts

 

info-blog-icon.jpg     US government wants security research on car-to-car networks

http://www.theregister.co.uk/2013/05/17/usa_car_network_security_research/?utm_source=feedly

 

NHTSA has asked for $US2m to research V2V networks with the aim of developing a preliminary baseline set of threats

 

  

 

info-blog-icon.jpg     House could withhold DHS funds while waiting for chemical security report

http://www.nextgov.com/defense/2013/05/house-could-withhold-dhs-funds-while-waiting-chemical-securit...

 

House appropriators are thinking about withholding $20M in 2013 funds from Homeland Security Department until it delivers a spending plan and progresss report for its chemical security program.

 

 

info-blog-icon.jpg     Mac malware signed with Apple ID infects activists laptop

http://arstechnica.com/security/2013/05/mac-malware-signed-with-apple-id-infects-activists-laptop/

 

Stealthy Mac spyware is programmed to take screenshots and send them to remote servers under the control of the attackers

info-blog-icon.jpg     Opinion: Let’s not sacrifice privacy on the altar of cyber security

http://njtoday.net/2013/05/16/opinion-lets-not-sacrifice-our-privacy-on-the-altar-of-cyber-security/

 

Here, here!

 

 

info-blog-icon.jpg    CISPA cyber security bill backers hope second time’s a charm

http://www.nbcnews.com/technology/cispa-cybersecurity-bill-backers-hope-second-times-charm-1C9948195

 

We might see this bill again by fall

 

 

info-blog-icon.jpg    Utilities rising target of hackers with warning of dire results

http://www.businessweek.com/news/2013-05-16/utilities-rising-target-of-hackers-with-warnings-of-dire...

 

“Cyber attacks on computers that run the nation’s energy grid, nuclear reactors and water-treatment plants are increasing with potentially lethal effects, the Department of Homeland Security’s top investigator said.”

 

 

info-blog-icon.jpg    Researchers develop industrial systems that watch for breaches

http://www.csoonline.com/article/733477/researchers-develop-industrial-systems-that-watch-for-breach...

 

"Each device listens to its neighboring device to see if they're misbehaving,"

 

 

info-blog-icon.jpg    CISO: Chief infosec scapegoat officer

http://www.infosecurity-magazine.com/view/32453/ciso-chief-infosec-scapegoat-officer/

 

CISOs are the first victims of every data breach and it's just going to get worse

 

 

info-blog-icon.jpg    Hotel Lock Hack Still Being Used In Burglaries, Months After Lock Firm's Fix

http://www.forbes.com/sites/andygreenberg/2013/05/15/hotel-lock-hack-still-being-used-in-burglaries-...

 

The latest Onity hack crime wave has been occurring in hotels across Arizona. 

It was recently revealed that QinetiQ North American, a major defense contractor, was the victim amassive, multi-year, cyber espionage operation allegedly originating from China. According to a representative from Verizon’s security division, “There was virtually no place we looked where we didn’t find [intrusion].” How could an important national security contractor suffer such devastating breach?

 

Listen to Tim Eriln, Lamar Bailey, Andrew Storms and Dwayne Melançon discuss QinetiQ’s security issues and more on Tripwire's State of Security blog. 

shelley_boose

Security News May 15

by nCircle Staff a week ago - last edited a week ago

info-blog-icon.jpg    Internet crime costs consumers more than half a billion dollars last year

http://www.darkreading.com/attacks-breaches/internet-crime-cost-consumers-more-than/240154922/

 

Consumers lost an average of $1,800 last year 

 

 

info-blog-icon.jpg    A hacker broke into 420,000 vomputers to bring you this GIF of the entire internet at work

http://www.businessinsider.com/a-hacker-broke-into-420000-computers-to-bring-you-this-stunning-gif-o...

 

An anonymous researcher took control over some 420,000 Internet connected-devices in order to "map the whole Internet in a way nobody had done before."

 

 

info-blog-icon.jpg    Spreading the word about cyber security

http://fcw.com/articles/2013/05/15/cybersecurity-evangelism.aspx

 

"Network building is the most important part of the job; you have to win advocates for moving forward with security controls in our systems”

 

 

info-blog-icon.jpg    Holder backs warrant requirement for most email searches

http://thehill.com/blogs/hillicon-valley/technology/300011-holder-backs-warrant-requirement-for-most...

 

The balance between privacy and government access is “one of the most important conversations…we can have in the 21st century."

 

 

info-blog-icon.jpg   Air gaps won’t protect your operations

http://www.automationworld.com/air-gaps-wont-protect-your-operations

 

“Because people will always find a way to get the data where they need it”

 

 

info-blog-icon.jpg   Critical Linux vulnerability imperils users even after silent fix

http://arstechnica.com/security/2013/05/critical-linux-vulnerability-imperils-users-even-after-silen...

 

This high-severity vulnerability that gives untrusted users with restricted accounts nearly unfettered "root" access over machines

 

info-blog-icon.jpg    Adobe shares cyber security lessons

http://blogs.wsj.com/riskandcompliance/2013/05/14/adobe-shares-cybersecurity-lessons/

 

Allan Paller: “It’s hard to build a good reputation when you’ve been the cause of so much damage”

 

 

info-blog-icon.jpg    On cyber security the nation needs meta leadership

http://www.politico.com/story/2013/05/on-cybersecurity-nation-needs-meta-leadership-91278.html?hp=l8

 

Will information sharing only come as a response to a major attack resulting in “a plan will be assembled quickly and haphazardly after the fact”?

 

info-blog-icon.jpg    Android threats growing in number and complexity, report says

http://www.computerworld.com/s/article/9239188/Android_threats_growing_in_number_and_complexity_repo...

 

FSecure: "While the raw amount of Android malware continues to rise significantly, it is the increased commoditization of those malware that is the more worrying trend,"

 

 

info-blog-icon.jpg    It’s better to call ahead when sending malware, Symantec finds

http://www.computerworld.com/s/article/9239168/It_39_s_better_to_call_ahead_before_sending_malware_S...

 

Symantec describes as a sophisticated social engineering campaign aimed at French-speaking accounting and finance department employees. The victim is called and asked in French if they can process an invoice sent by email

 

 

info-blog-icon.jpg    New York student aims to sell his own personal data on Kickstarter

http://www.slate.com/blogs/future_tense/2013/05/13/federico_zannier_is_selling_his_own_personal_data...

 

Turning the online privacy equation on its head, this student aims to take control of his personal data by selling it himself

 

 

info-blog-icon.jpg    3 Big Mistakes In Incident Response

http://www.darkreading.com/management/3-big-mistakes-in-incident-response/240154817

 

Remember: Overreaction can cause you to miss the key details.

 

 

info-blog-icon.jpg    Windows Malware Techniques Spread to Android

http://securitywatch.pcmag.com/mobile-security/311417-windows-malware-techniques-spread-to-android

 

Over 75% of current Android threats exist to make money for their creators.

 

 

info-blog-icon.jpg     Email: Even The CIA Uses It. Time To Get Serious About Its Legal Protections

http://www.forbes.com/sites/erikamorphy/2013/05/14/email-even-the-cia-uses-it-time-to-get-serious-ab...

 

Everyone is impacted by weak email security… 

info-blog-icon.jpg    Cyberattacks Against U.S. Corporations Are on the Rise

http://www.nytimes.com/2013/05/13/us/cyberattacks-on-rise-against-us-corporations.html

 

Energy companies are targeted, attacks may be coming from the Middle East

 

 

info-blog-icon.jpg   Should companies by required to meet certain cyber security standards?

http://stream.wsj.com/story/latest-headlines/SS-2-63399/SS-2-230630/

 

The debate on national cyber security regulation rages on

 

 

info-blog-icon.jpg   SEC Chairman reviewing company cyber security disclosures

http://www.bloomberg.com/news/2013-05-13/sec-chairman-reviewing-company-cybersecurity-disclosures.ht...

 

U.S. Securities and Exchange Commission Chairman Mary Jo White has asked her staff to review whether publicly traded companies should be prodded to disclose more information about cyberattacks on their computer networks

 

 

info-blog-icon.jpg   Saudi Telco asks researcher Moxie Marlinkspike to help spy on residents

http://www.scmagazine.com/saudi-telco-asks-researcher-moxie-marlinspike-to-help-it-spy-on-residents/...

 

it was seeking Marlinspike's assistance in a government-sponsored surveillance project that was seeking to intercept "mobile application data" belonging to Twitter, WhatsApp, Viber and Line users

 

 

info-blog-icon.jpg   Court Data Breach Could Affect Up To 1 Million In Washington State

http://www.seattlemedium.com/News/article/article.asp?NewsID=115189&sID=4

 

The Washington State Administrative Office of the Courts (AOC) announced  a data breach on its public website. Potentially up to 160,000 social security numbers and 1 million driver license numbers may have been accessed

 

 

info-blog-icon.jpg   Tough times at Homeland Security

http://bits.blogs.nytimes.com/2013/05/13/tough-times-at-homeland-security/

 

You think you have hiring problems, DHS has been grappling with the departures of its top cybersecurity officials

 

 

info-blog-icon.jpg   Five Useless Tips From the NSA’s Quaint, Hopelessly Outdated Guide to Internet Research

http://www.slate.com/blogs/future_tense/2013/05/10/nsa_s_hopelessly_outdated_guide_to_internet_resea...

 

Remember, your password should be “at least 8 characters long.”

Evaluating risk and formulating effective responses are two major components of information security. But what is the best way to communicate risk and response to the rest of your organization?

 

Listen to Tim Erlin and Dwayne Melançon as they discuss security risk communication and more on Tripwire's State of Security blog. 

info-blog-icon.jpg     ATM hackers stole $45M in 21st century bank heist

http://www.foxnews.com/tech/2013/05/09/atm-hackers-stole-45m-in-21st-century-bank-heist-feds-say/

 

Bank robbers cyber security style

 

 

info-blog-icon.jpg     The U.S. military's supply chain risk called 'frightening'

http://www.computerworld.com/s/article/9239030/The_U.S._military_s_supply_chain_risk_called_frighten...

 

The Alliance for American Manufacturing believes the U.S. military is too reliant on foreign-made products.

 

 

info-blog-icon.jpg     US cyber war strategy stokes fears of blow back

http://www.reuters.com/article/2013/05/10/us-usa-cyberweapons-specialreport-idUSBRE9490EL20130510

 

“The US is the biggest buyer in the gray market where hackers and security firms sell tools for breaking into computers

 

 

info-blog-icon.jpg     APIs are doors to web services and they need locks

http://readwrite.com/2013/05/10/apis-are-the-doors-to-web-services-and-they-need-locks

 

APIs can be misused by hackers to spoof services, or even pretend to be entire websites

 

 

info-blog-icon.jpg     How the Syrian Army hacked the Onion’s Twitter account

http://theonion.github.io/blog/2013/05/08/how-the-syrian-electronic-army-hacked-the-onion/

 

Great step by step case study

 

 

info-blog-icon.jpg     Google has aggressive plans for strong authentication

http://threatpost.com/google-has-aggressive-plans-for-strong-authentication/?utm_source=dlvr.it&utm_...

 

In addition to logging in at the OS level,”….one of our goals will be to have a consistent concept of identity between the OS, applications, and websites accessed from the browser on the device.”

 

 

info-blog-icon.jpg     Why Intel’s “How Strong is Your Password?” site can’t be trusted

http://arstechnica.com/security/2013/05/why-intels-how-strong-is-your-password-site-cant-be-trusted/

 

Oh Intel,  why no HTTPS? 

info-blog-icon.jpg     Easing into FISMA and FedRAMP? It’s possible

http://fcw.com/articles/2013/05/08/fedramp-fisma-reform.aspx

 

"It's a huge change from doing a FISMA scorecard last December to implementing real-time scanning and continuous diagnostic monitoring this year"

 

 

info-blog-icon.jpg     'OpUSA' Hacktivist Attacks Fall Short

http://www.darkreading.com/attacks-breaches/opusa-hacktivist-attacks-fall-short/240154389

 

A small bank in Arkansas had its website defaced, but that’s pretty much it.

 

 

info-blog-icon.jpg     Senators propose law to go after foreign cybercriminals

http://news.cnet.com/8301-1009_3-57583379-83/senators-propose-law-to-go-after-foreign-cybercriminals...

 

The “Deter Cyber Theft Act”  would require an annual report listing the countries involved in cyber espionage, and could lead to product or country level embargos

 

 

info-blog-icon.jpg     Government Policy on Email Surveillance in "State of Chaos"

http://www.slate.com/blogs/future_tense/2013/05/08/ecpa_reform_documents_show_government_policy_on_e...

 

The FBI may or may not be able to search your email without a warrant.

 

 

info-blog-icon.jpg     Syrian internet back after 19-hour blackout

http://www.bbc.co.uk/news/world-middle-east-22447247

 

“The Syrian government blamed that incident on "terrorists", but internet experts said it was more likely that the regime had shut down the web.”

 

 

info-blog-icon.jpg     Organizations Underestimate The Dangers of Privileged Accounts: Survey

http://www.securityweek.com/organizations-underestimate-dangers-privileged-accounts-survey

 

53% of enterprises said they take 90 days or longer to change the password on privileged accounts.

 

 

info-blog-icon.jpg     It's Time to Check Your Facebook Privacy Settings

http://securitywatch.pcmag.com/security/311233-it-s-time-to-check-your-facebook-privacy-settings

 

Do your privacy settings need some spring cleaning?

 

 

info-blog-icon.jpg     Lack of Chip and PIN technology leaves US shoppers and diners at risk from hackers

http://nakedsecurity.sophos.com/2013/05/08/lack-of-chip-and-pin-technology-leaves-us-shoppers-and-di...

 

According to Trustwave’s annual security report, 45%  companies breached were in the retail sector.

ehanscom

Security News May 7

by nCircle Staff Contributor 2 weeks ago - last edited 2 weeks ago

original.jpg Sweet Password Security Strategy: Honeywords

 http://www.informationweek.com/security/intrusion-prevention/sweet-password-security-strategy-honeyw...

 

Will Honeywords be a sweet solution or will they create a sticky situation?

 

 

original.jpg Government Takes Precautions Over Expected ‘OpUSA’ Cyber Attack

 http://abcnews.go.com/blogs/headlines/2013/05/government-takes-precautions-over-expected-opusa-cyber...

 

OpUSA were expected to launch DDoS attacks against financial and governmental organizations today.

 

 

original.jpg Convenience Store Chain Hacked, Customer Payment Data At Risk

 http://www.darkreading.com/attacks-breaches/convenience-store-chain-hacked-customer/240154376

 

MAPCO says the attack affects debit and credit-card payments made at its stores between March 19 and 25, April 14 and 15, and April 20 and 21.

 

 

original.jpg Database Security: It's More Than Meets the Eye

 http://www.securityweek.com/database-security-its-more-meets-eye

 

"Letting the cat guard the milk is known to be a bad security practice."

 

 

original.jpg New Motto for Silicon Valley: First Security, Then Innovation

 http://bits.blogs.nytimes.com/2013/05/05/disruptions-new-motto-for-silicon-valley-first-security-the...

 

Should security change come from within? 

ehanscom

Security News May 6

by nCircle Staff Contributor 2 weeks ago

original.jpg Google's Schmidt: The Internet needs a delete button

 http://news.cnet.com/8301-1009_3-57583022-83/googles-schmidt-the-internet-needs-a-delete-button/

 

Mistakes young people make can haunt them forever online.

 

 

original.jpg A primer on Bitcoin risks and threats

 https://www.net-security.org/secworld.php?id=14857

 

Malware has certainly hit the Bitcoin market.

 

 

original.jpg The Onion Apparently Hacked by the Syrian Electronic Army

 http://www.slate.com/blogs/future_tense/2013/05/06/the_onion_hacked_syrian_electronic_army_takes_ove...

 

Either the Onion was hit by hackers or “this is an instant contender for cleverest Onion stunt of all time.”

 

 

original.jpg China's Cyber Espionage Targets US Government: Pentagon

 http://www.securityweek.com/chinas-cyber-espionage-targets-us-government-pentagon

 

“China is using its computer network exploitation (CNE) capability to support intelligence collection against the US diplomatic, economic, and defense industrial base sectors that support US national defense programs.”

 

 

original.jpg 7 Habits For Highly Effective BYOD

 http://www.forbes.com/sites/adriankingsleyhughes/2013/05/06/7-habits-for-highly-effective-byod/

 

As BYOD becomes more popular, what security steps are you taking? 

 

info-blog-icon.jpg     Cyberspies outwit model for Bond’s Q

http://www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html

 

QinetiQ ( a government cyber security contractor) hack may have compromised information vital to national security, such as the deployment and capabilities of the combat helicopter fleet.

 

And the same contractor has been hacked repeatedly

http://gigaom.com/2013/05/02/when-a-defense-contractor-gets-hacked-repeatedly-you-know-cybersecurity...

 

 

 

info-blog-icon.jpg     Cybersecurity needs work, experts say

http://www.upi.com/Science_News/Technology/2013/05/03/Cybersecurity-needs-work-experts-say/UPI-46131...

 

Advocating ‘gradual change’

 

 

info-blog-icon.jpg     The consumer cost of a data breach

http://www.cnbc.com/id/100695689

 

A new analysis of the huge data breach last year in Utah estimates that more than 120,000 cases of fraud will occur as a result of information stolen

 

 

info-blog-icon.jpg     Facebook puts a friendly spin on password security with launch of Trusted Contacts

http://gigaom.com/2013/05/02/facebook-puts-a-friendly-spin-on-password-security-with-launch-of-trust...

 

Facebook has re-vamped its password security measures

 

 

info-blog-icon.jpg     50% of enterprises will mandate BYOD by 2017

http://www.infosecurity-magazine.com/view/32215/50-of-enterprises-will-mandate-byod-by-2017/

 

According to Gartner using personal devices for work functionality is inevitable

 

 

info-blog-icon.jpg     Cloud security certification in the works

http://www.cso.com.au/article/460943/cloud_security_certification_works/

 

ISC(2) and the Cloud Security Alliance are teaming up on a professional cloud security certification

 

shelley_boose

Security News May 2

by nCircle Staff 3 weeks ago - last edited 3 weeks ago

info-blog-icon.jpg  Dam! Sensitive Army database of U.S. dams compromised; Chinese hackers suspected

http://www.washingtontimes.com/news/2013/may/1/sensitive-army-database-us-dams-compromised-chines/

 

Is China preparing a future cyber-attack against the national electrical power grid?

 

 

info-blog-icon.jpg  Why you should take hacked sites’ password assurances with a grain of salt

http://arstechnica.com/security/2013/05/why-you-should-take-hacked-sites-password-assurances-with-a-...

 

Reputation.com suffered a security breach that exposed password and then told users, “It was highly unlikely that these passwords could ever be decrypted.”

 

 

info-blog-icon.jpg  Five Habits Of Highly Successful Malware

http://www.darkreading.com/advanced-threats/five-habits-of-highly-successful-malware/240154057

 

In 2012, more than 40 million Windows systems were infected with malware. How do you protect yourself?

 

 

info-blog-icon.jpg  How to Stay Anonymous Online

http://securitywatch.pcmag.com/security/311007-how-to-stay-anonymous-online

 

Anonymous may be an over statement but there’s a lot you can do to protect your privacy online.

 

 

info-blog-icon.jpg  Websites gradually shedding vulnerabilities, though most still contain a serious one

http://www.scmagazine.com/websites-gradually-shedding-vulnerabilities-though-most-still-contain-a-se...

 

53% of websites still  have cross-site scripting (XSS) errors.

 

 

info-blog-icon.jpg  The 7 elements of a successful security awareness program

http://www.csoonline.com/article/732602/the-7-elements-of-a-successful-security-awareness-program

 

One view of how to do security awareness  - how do you do this?

shelley_boose

Security News May 1

by nCircle Staff 3 weeks ago - last edited 3 weeks ago

info-blog-icon.jpg  Speed traders eyed after Twitter hack attack: regulator

http://www.reuters.com/article/2013/04/30/us-hft-regulation-twitter-idUSBRE93T17H20130430

 

Another unintended consequence of the AP twitter hack

 

 

info-blog-icon.jpg   White House: 'Fundamental concerns' remain over cyber security bill
http://thehill.com/blogs/hillicon-valley/technology/297037-white-house-response-to-petition-opposing...

 

“The United States must update our cybersecurity laws, but we will not sacrifice our values in the process."

 

 

info-blog-icon.jpg  Spyware used by governments poses as Firefox, and Mozilla is angry

http://arstechnica.com/information-technology/2013/05/spyware-used-by-governments-poses-as-firefox-a...

 

Mozilla sent the FinFisher software maker a cease and desist letter.

 

 

info-blog-icon.jpg  Password Reuse Rampant, But Users Value Security, Survey Says

http://www.darkreading.com/end-user/password-reuse-rampant-but-users-value-s/240153940

 

61% of the respondents said they use the same password for multiple accounts, but 47% use multi-factor authentication for their email accounts.

 

 

info-blog-icon.jpg  Apple, Verizon earn poor marks in EFF privacy report

http://news.cnet.com/8301-1009_3-57582292-83/apple-verizon-earn-poor-marks-in-eff-privacy-report/

 

Who did the best? Twitter and Sonic.net

 

 

info-blog-icon.jpg  Use a Software Bug to Win Video Poker? That’s a Federal Hacking Case

http://www.wired.com/threatlevel/2013/05/game-king/

 

“Who would not win as much money as they could on a machine that says, ‘Jackpot’? That’s the whole idea!”

 

 

info-blog-icon.jpg  71 Percent of Applications Use Components With Severe or Critical Security Flaws: Report

 

http://www.securityweek.com/71-percent-applications-use-components-severe-or-critical-security-flaws...

 

About 76% of users say they have no control over what components get used in software development projects.

 

 

info-blog-icon.jpg  Twitter warns of additional hacks, threats

http://news.cnet.com/8301-1009_3-57582102-83/twitter-warns-of-additional-hacks-threats/

 

High-profile news organizations are told to take extra precaution when opening email.

 

 

info-blog-icon.jpg  U.S. Urges Finance Industry to Form Cyber Threat Clearinghouses

http://www.businessweek.com/news/2013-04-29/u-dot-s-dot-urges-finance-industry-to-form-cyber-threat-...

 

“Government alone cannot keep our financial system safe. The responsibility of protecting our financial sector rests also with the sector itself.”

 

 

info-blog-icon.jpg  Online monitoring scheme bad news for security, opponents say

http://www.csoonline.com/article/732538/online-monitoring-scheme-bad-news-for-security-opponents-say

 

Surveillance backdoors could potentially be used for state sponsored attacks.

 

 

info-blog-icon.jpg  Recent Breaches More Likely To Result In Fraud

http://www.darkreading.com/attacks-breaches/recent-breaches-more-likely-to-result-in/240153846

 

A person whose data was stolen in 2012 has a 25% chance of becoming a fraud victim. 

 

info-blog-icon.jpg     Hactivists change tactics from data breaches to disruption

 

http://www.eweek.com/security/hactivistists-change-tactics-from-data-breaches-to-disruption-verizon/

 

 

 

In 2011, hactivists stole almost 50% of the total records analyzed in Verizon’s DBIR, last year is was only 2%

 

 

 

 

 

info-blog-icon.jpg    Living Social hacked, as many as 50 million affected

 

http://news.cnet.com/8301-1009_3-57581718-83/livingsocial-hacked-50-million-affected/

 

 

 

Not much information available on this yet, no credit card data was affected

 

 

 

 

 

info-blog-icon.jpg    Attackers target shared Web hosting servers for mass phishing attacks

 

http://www.computerworld.com/s/article/9238712/Hackers_target_shared_Web_hosting_servers_for_mass_ph...

 

 

 

A cautionary tale: Nearly half of all phishing attacks in the second half of 2012 involved the use of hacked hosting servers

 

 

 

 

 

info-blog-icon.jpg    FSOC Report: US Banking still too vulnerable to hackers

 

http://www.securityweek.com/us-banking-sector-too-vulnerable-hackers-fsoc-report

 

 

 

In reference to the DDoS attacks against banks last year, FSOC said "the knowledge and skill of the attackers appeared to increase over time."

 

 

 

 

 

info-blog-icon.jpg    Google Glass hacked within days of release

 

http://www.ibtimes.co.uk/articles/461827/20130426/google-glass-root-hack-easy-claims-developer.htm

 

 

 

“….gaining root access to Google Glass ‘looks easy’ after discovering a 'debug mode' option on Glass that enables further access to the device's operating system”

 

info-blog-icon.jpg   ACLU: CISPA is dead (for now)

http://www.usnews.com/news/articles/2013/04/25/aclu-cispa-is-dead-for-now

 


The Senate is working on another cyber security bill with more privacy provisions

 

 

info-blog-icon.jpg   Many hacked businesses remain unprepared for the next breach

http://www.darkreading.com/attacks-breaches/many-hacked-businesses-remain-unprepared/240153520?token...

 

Kind of flies in the face of “experience is the best teacher”

 

 

info-blog-icon.jpg   Maker of smart-grid software discloses hack
http://news.cnet.com/8301-1009_3-57521049-83/maker-of-smart-grid-software-discloses-hack/

 

Telvent Canada says someone sneaked past its internal firewall, installing malicious software and stealing files related to control software used to manage the electric grid in various countries

 

 

info-blog-icon.jpg    FBI denied permission to spy on hacker through his webcam
http://arstechnica.com/tech-policy/2013/04/fbi-denied-permission-to-spy-on-hacker-through-his-webcam...

 

The description of what the spyware the Feds wanted to installs sounds eerily similar to the RAT banking Trojan

 

 

info-blog-icon.jpg   Israeli airport security allowed to read tourists email

http://www.securityweek.com/israel-airport-security-allowed-read-tourists-email

 

Security officials at Ben Gurion airport are legally allowed to demand access to tourists' email accounts and deny them entry if they refuse

 

info-blog-icon.jpg    Twitter prepping two factor authentication

http://www.wired.com/threatlevel/2013/04/twitter-authentication/

 

Bet they’re working even harder after yesterday’s AP hack

 

info-blog-icon.jpg   here is no such thing as information security risk

http://www.cio.com/article/732299/There_is_No_Such_Thing_as_Information_Security_Risk

 

Connecting security risk to the business is the heart of the issue

 

 

info-blog-icon.jpg   More malware discovered from drone cyber attacks

http://www.csoonline.com/article/732277/more-malware-discovered-from-drone-cyberattacks

 

A cyber espionage campaign targeted at stealing drone related technology

 

 

info-blog-icon.jpg   Homeland Security Chairman to develop cybersecurity bill

 http://thehill.com/blogs/hillicon-valley/technology/295769-homeland-security-chairman-to-develop-cyb...

 

House Homeland Security Chairman Michael McCaul insists his CISPA amendment was "actually praised by the privacy groups." 

 

 

info-blog-icon.jpg   Should Insiders Really Be Your Biggest Concern?

 http://www.darkreading.com/insider-threat/should-insiders-really-be-your-biggest-c/240153455

 

What are more damaging: internal or external threats? 

info-blog-icon.jpg    AP says it’s Twitter account was hacked

http://www.marketwatch.com/story/ap-says-its-twitter-account-hacked-2013-04-23?link=MW_latest_news

 

The market was temporarily stunned, but Twitter moved very quickly to suspend the account

 

 

info-blog-icon.jpg   Google’s Schmidt: Cyber war is the new normal

http://www.afr.com/p/technology/cyber_war_the_new_normal_google_nrn1vaeNTNhU6NcQpHn5zI

 

Schmidt says we can expect “perpetual, permanent, low-grade cyber war”

 

 

info-blog-icon.jpg   The Verizon Data Breach Report came out  today and got tons of coverage. Here were two of my favorite articles:

 

             The year in hacking by the numbers
             http://bits.blogs.nytimes.com/2013/04/22/the-year-in-hacking-by-the-numbers/
 
             “There are only two kinds of companies. Those that have been hacked and those that don’t know they’ve been hacked”
 
            No one size fits all in Verizon data breach report
            http://www.darkreading.com/attacks-breaches/no-one-size-fits-all-in-data-breaches-ne/240153379
 
            A nice round up of the report including this gem: “…..organizations typically don't discover that they've been breached for months and even years after the fact and nearly 70 percent of them learn from a third party.”

 

 

info-blog-icon.jpg   Why security is in denial about awareness

http://www.csoonline.com/article/732153/why-security-is-in-denial-about-awareness

 

“Why do we allow users and administrators to perform unsafe acts such as selecting passwords like 'Password1'?”

 

 

info-blog-icon.jpg   CISPA blackout fails to match 2012’s SOPA and PIPA protest levels

http://www.techhive.com/article/2036167/cispa-blackout-fails-to-match-2012s-sopa-pipa-protest-levels...

 

“The Internet yawned”

 

 

info-blog-icon.jpg   55% of net users use the same password for most, if not all, websites. When will they learn?

http://nakedsecurity.sophos.com/2013/04/23/users-same-password-most-websites/

 

26% of users said that they pick easy-to-remember passwords such as birthdays or people's names.

 

 

info-blog-icon.jpg   Scan My Eyeball, Already

http://www.darkreading.com/end-user/scan-my-eyeball-already/240153358

 

Are consumers demanding biometrics over passwords? 

info-blog-icon.jpg    US eyes push back on Chinese hacking

http://online.wsj.com/article_email/SB10001424127887324345804578424741315433114-lMyQjAxMTAzMDIwMTEyN...

 

“Options include trade sanctions, diplomatic pressure, indictments of Chinese nationals in U.S. courts and cyber countermeasures—both attack and defense, officials said”

 

 

info-blog-icon.jpg    Oracle bug hunter spots Java 7 Server flaw

http://www.informationweek.com/security/vulnerabilities/oracle-bug-hunter-spots-java-7-server-fl/240...

 

Another security black eye for Java

 

 

info-blog-icon.jpg    Three simple steps to determine your risk tolerance

http://www.csoonline.com/article/731833/three-simple-steps-to-determine-risk-tolerance-

 

Who has the authority to assume risk in your organization?

 

 

info-blog-icon.jpg    CBS News says some of its Twitter accounts were hacked

http://uk.reuters.com/article/2013/04/20/usa-cbsnews-twitter-idUKL2N0D70PB20130420

 

CBS News programs, "60 Minutes" and "48 Hours" Twitter accounts were compromised on Saturday

 

 

info-blog-icon.jpg    Attacks on SCADA, ICS honeypots modified critical operations

http://threatpost.com/attacks-scada-ics-honeypots-modified-critical-operations-031913/

 

“…during a 28-day trial  attackers were determined to access SCADA networks and ICS devices and come armed not only with working knowledge of devices and their default configurations, but with purpose-built malware, and the desire to modify industrial processes if they’re able to successfully access a system”

 

 

info-blog-icon.jpg    Ten tips to security funding for an IT security program

http://www.csoonline.com/article/732053/10-tips-to-secure-funding-for-a-security-program

 

Number 4 is pretty important….

shelley_boose

Security News April 19

by nCircle Staff on ‎04-19-2013 04:04 PM

info-blog-icon.jpg     Brookings Institute’s Alan Friedman on the rhetoric surrounding CISPA

http://www.lawfareblog.com/2013/04/brookings-alan-friedman-on-the-rhetoric-surrounding-cispa/

 

These comments seem to apply to the entire national conversation we’re having around cyber security

 

 

info-blog-icon.jpg    Deconstructing defensible: Too many assets, not enough resources

http://www.infosecisland.com/blogview/23096-Deconstructing-Defensible-Too-Many-Assets-not-Enough-Res...

 

Good blog post from Rafal Los

 

 

info-blog-icon.jpg    What you should know about enabling Microsoft two-factor authentication

http://www.fiercecio.com/techwatch/story/what-you-should-know-enabling-microsofts-two-factor-verific...

 

“Users who know their passwords, but lose access to their secondary security proof, will have to go through a mandatory 30 day wait before regaining access to their account”

 

 

info-blog-icon.jpg    Can we cease check box compliance?

http://www.darkreading.com/compliance/can-we-cease-check-box-compliance/240153220

 

"They have to be advocates with persuasive skills in communicating the current state [of security], a future state and what steps are necessary…”

 

 

 

info-blog-icon.jpg    Assange to Google’s Schmidt: Don’t use email

http://www.csoonline.com/article/732042/assange-to-google-s-schmidt-don-t-use-email

 

Wikileaks published a transcript of conversations between Assange and Eric Schmidt

 

 

 

info-blog-icon.jpg    IT security in a nutshell

http://fishbowl.pastiche.org/2013/04/14/it_security_in_a_nutshell/

 

A little Friday humor

shelley_boose

Security News April 18

by nCircle Staff on ‎04-18-2013 04:04 PM

info-blog-icon.jpg     Cybersecurity: A view from the front

http://www.nytimes.com/2013/04/12/opinion/global/cybersecurity-a-view-from-the-front.html?_r=1&

 

Remember the cyber attacks on Estonia in 2008? They made cyber security a national priority

 

 

info-blog-icon.jpg    Popular Wi-Fi routers easy to hack

http://www.digitaltrends.com/computing/wi-fi-routers-hack/

 

And, according to ISE, there’s not much you can do to protect yourself

 

 

info-blog-icon.jpg    Siri remembers your secrets, but for how long?

http://www.wired.com/wiredenterprise/2013/04/siri-privacy/

 

Evidently, Siri has a very long memory

 

 

info-blog-icon.jpg    Opinion: Cyber intelligence sharing and protection act

http://bdaily.co.uk/opinion/16-04-2013/opinion-cyber-intelligence-sharing-and-protection-act/

 

“Tech companies like CISPA because it grants them the equivalent of a Christmas pony”

 

 

info-blog-icon.jpg    Users prefer new forms of authentication

http://www.inforisktoday.com/consumers-favor-new-forms-authentication-a-5692

 

Interesting data from UK, Germany and US what users think about authentication

 

 

info-blog-icon.jpg    DDoS ‘fire drill’ services urges companies to be prepared

http://www.infosecurity-magazine.com/view/31893/ddos-fire-drill-service-urges-companies-to-be-prepar...

 

Is your business doing regular data breach drills? Do they include DDoS attacks?

 

 

info-blog-icon.jpg    Cyberattacks can't break the Internet

http://money.cnn.com/2013/04/16/technology/security/internet-cyberattacks/index.html

 

Today’s humor: “Cyberattackers depend on the Internet too.”

Read more...

shelley_boose

Security News April 17

by nCircle Staff on ‎04-17-2013 04:23 PM

info-blog-icon.jpg    ACLU files FTC complaint over Android security

http://www.aclu.org/blog/technology-and-liberty/aclu-files-ftc-complaint-over-android-smartphone-sec...

 

Patch management for Android devices comes under FTC scrutiny

 

 

info-blog-icon.jpg    Google boosts IT admin control for Chrome browser

http://www.computerworlduk.com/news/applications/3442457/google-boosts-it-admin-control-for-chrome-b...

 

Includes configurable permissions and a “curated web app store”

 

 

info-blog-icon.jpg    Marathon bombing suspect reportedly identified

http://www.computerworld.com/s/article/9238460/Update_Marathon_bombing_suspect_reportedly_identified

 

Speculation on the technology involved in finding suspects in the Boston Marathon bombing

 

 

info-blog-icon.jpg    Apple keeps patching Java on OS X and Snow Leopard long after proposed drop-dead date

http://www.computerworld.com/s/article/9238453/Apple_keeps_patching_Java_on_OS_X_Snow_Leopard_after_...

 

Safari6 now lets users closely manage Java permissions by selecting which sites can execute the software

 

 

info-blog-icon.jpg    Identity theft goes hyperlocal

http://www.securityweek.com/identity-theft-goes-hyperlocal

 

The interesting thing here is the example of loss threshold for local police cyber crime investigation

 

 

info-blog-icon.jpg    Fueled by super botnets, DDoS attacks grow meaner and ever-more powerful

http://arstechnica.com/security/2013/04/fueled-by-super-botnets-ddos-attacks-grow-meaner-and-ever-mo...

 

In the first quarter, DDoS attacks jumped to 48.25 gigabits per second. 

shelley_boose

Security News - Tax Day

by nCircle Staff on ‎04-16-2013 04:40 PM

info-blog-icon.jpg    With security vote looming, White House threatens veto (again)

http://www.forbes.com/sites/andygreenberg/2013/04/16/with-cispa-vote-looming-the-white-house-threate...

 

Privacy and immunity from prosecution revisions needed

 

 

info-blog-icon.jpg    Microsoft discovers Trojan that erases evidence of its existence

http://www.darkreading.com/security/vulnerabilities/240152960/microsoft-discovers-trojan-that-erases...

 

Part of a trend toward malware with anti-forensics capabilities

 

 

info-blog-icon.jpg    Targeted attacks hitting small business have increases threefold

http://www.net-security.org/secworld.php?id=14762&utm_source=dlvr.it&utm_medium=twitter

 

Symantec: Small businesses under 250 employees now the target of 31% of attacks

 

 

info-blog-icon.jpg    High level execs not always the juiciest target for attackers

http://www.securityweek.com/high-level-execs-not-always-juiciest-target-hackers

 

Sales and R&D are the most targeted groups

 

 

info-blog-icon.jpg    Schnuck’s supermarket struggled to find breach that exposed 2.4M credit cards

http://www.computerworld.com/s/article/9238402/Schnucks_supermarket_chain_struggled_to_find_breach_t...

 

The chain’s credit card processor alerted the supermarket chain to a breach but it took them 14 days to find it and shut it down

 

 

info-blog-icon.jpg    The CISOs guide to advanced attackers: Sizing up the adversary

https://securosis.com/blog/the-cisos-guide-to-advanced-attackers-sizing-up-the-adversary

 

A new series on APTs  from Securosis, worth reading

shelley_boose

Security News April 15

by nCircle Staff on ‎04-15-2013 04:40 PM

info-blog-icon.jpg    Android gets 97% of malware, Apple gets 58% of the enterprise

http://tech.fortune.cnn.com/2013/04/14/apple-enterprise-android-malware/

 

“….is it really a good idea to be issuing malware-friendly Android devices to field workers in utilities, healthcare and communication services?”

 

 

info-blog-icon.jpg    An opportunity for CIOs

http://www.forbes.com/sites/forbesinsights/2013/04/12/an-opportunity-for-the-cio/

 

“CIOs have little direct say on strategy…”

 

 

info-blog-icon.jpg    Evaluating risk in the dark

http://itauditsecurity.wordpress.com/2013/04/15/evaluating-risk-in-the-dark/?utm_source=twitterfeed&...

 

Where should existing audit issues that haven’t been remediated fit in the risk equation?

 

 

info-blog-icon.jpg    Hacktivists as gadflies

http://opinionator.blogs.nytimes.com/2013/04/13/hacktivists-as-gadflies/

 

A great opinion piece about the “obscenely excessive prosecution” of relatively innocuous hacks recently

 

 

info-blog-icon.jpg    How hackers fool your employees

http://www.darkreading.com/security/client-security/240152770/how-hackers-fool-your-employees.html

 

Some (more) advice on security awareness and why it matters

 

 

info-blog-icon.jpg    The unique challenges of controlling Java exploits

http://www.securityweek.com/unique-challenges-controlling-java-exploits

 

“For many enterprises the rewards of Java have considerably diminished over the years, while the risks are growing exponentially”

 

 

info-blog-icon.jpg    FAA debunks Android hijack claim

http://www.theregister.co.uk/2013/04/13/faa_debunks_android_hijack_claim/

 

Evidently, hacking a simulator and hacking an airplane during flight are two different things

 

 

info-blog-icon.jpg    Security Awareness Training Debate: Does it Make a Difference?

http://www.securityweek.com/security-awareness-training-debate-does-it-make-difference

 

"You need to set the right expectation that you are trying to help the company, not frame individuals.”

 

 

info-blog-icon.jpg    Porn sites reject 'growing risk' of malware claim

http://www.bbc.co.uk/news/technology-22153527

 

Spokesmen say the threat (along with several other things) has been "grossly exaggerate[d]."

info-blog-icon.jpg     Ten years after: Where security monitoring still falls short

http://itsecurityjournal.com/ten-years-after-where-security-monitoring-still-falls-short/

 

Blog post: “Yesterday’s security tools aren’t effective for today’s threats”

 

 

info-blog-icon.jpg     The IRS going against email privacy tide

http://www.networkworld.com/news/2013/041213-irs-going-against-privacy-tide-268678.html

 

IRS is taking the position that they don’t need subpoenas for email communications in criminal investigations

 

 

info-blog-icon.jpg     Hackers Could Start Abusing Electric Car Chargers to Cripple the Grid, Researcher Says

http://www.cio.com/article/731634/Hackers_Could_Start_Abusing_Electric_Car_Chargers_to_Cripple_the_G...

 

Hack-in-theBox: Vulnerable charging stations could prevent the charging of electric vehicles in a certain area, or possibly even use the vulnerabilities to cripple parts of the electricity grid

 

 

info-blog-icon.jpg     Kevin Mitnick: Hacking the hamburglar

http://www.forbes.com/sites/singularity/2013/04/11/kevin-mitnick-the-hacking-hamburglar/

 

Pretty funny: Mitnick hacked the frequency of a local McDonalds ordering system and took control of the drive-through ordering system

 

shelley_boose

Security News April 11

by nCircle Staff on ‎04-11-2013 06:32 AM

info-blog-icon.jpg    New cybersecurity bill, privacy threat or crucial band-aid

http://www.csmonitor.com/USA/Politics/2013/0410/New-cybersecurity-bill-Privacy-threat-or-crucial-ban...

 

CISPAs new privacy amendments may not go far enough

 

 

info-blog-icon.jpg    Rockefeller asks SEC to step-up cybersecurity disclosures

http://thehill.com/blogs/hillicon-valley/technology/292919-rockefeller-asks-sec-to-step-up-cybersecu...

 

Rockefeller argues that investors have a right to know about cyber-attacks and security protocols.

 

 

info-blog-icon.jpg    Hackers steal Ubisoft's unreleased Far Cry video game

http://www.bbc.co.uk/news/technology-22095115

 

All PC video game sales have been halted until Ubisoft fixes the issue.

 

 

info-blog-icon.jpg    Adobe updates are no laughing matter, but at least XKCD makes them funny

http://nakedsecurity.sophos.com/2013/04/10/adobe-updates-xkcd/

 

This made me laugh out loud

 

 

info-blog-icon.jpg    How To Successfully Phish Your Own Firm

http://www.darkreading.com/insider-threat/167801100/security/security-management/240152679/how-to-su...

 

“The smarter everyone is the more secure the company will be."

 

 

info-blog-icon.jpg    Taking steps to stop software sabotage

http://www.darkreading.com/application-security/167901123/security/news/240152716/taking-steps-to-st...

 

Tips for a secure software development process

 

 

info-blog-icon.jpg    Hijacking an airplane with an Android phone

http://www.net-security.org/secworld.php?id=14733

 

A German security researcher at Hack in the Box demonstrates the “sorry state of aviation security”

According to a recent MIT study, it's possible to identify anonymous mobile users based on the data their phones send to cell towers. Is privacy and anonymity simple an illusion? Listen to Episode 73 of our Security Slice podcast and hear Tim Eriln and Tim “TK” Keanini discuss why our mindsets clash with our browser settings, if there is a bright side to being traced and when privacy is absolutely necessary.