
latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

kmov.com(KMOV) -- Wednesday night, TRICARE, the health care program for millions of military members, retirees, and their families announced a data breach that affects an estimated 4.9 million people.
Read TRICARE's statement here: www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf
Science Applications International Corporation reported that one of its employees was driving backup computer tapes from one federal office to another in San Antonio, Texas. At one point, the car was broken into and the backup tapes were stolen. SAIC says it won't disclose how many tapes were taken, but says only "some" were encrypted.
The tapes that were lost included names, Social Security numbers, addresses, and medical treatment information of patients who were treated at San Antonio military treatment facilities (or patients who have had lab work processes there) from 1992 until September 7, 2011.
TRICARE and SAIC say they are working to identify all the beneficiaries whose information may have been lost and notify the affected people. TRICARE says that the risk of harm to patients is low because the thief would have to have access to specific hardware and software and know how to pull the data from the tapes.
Jarrett Kolthoff, who runs a cyber security firm called SpearTip, LLC, says people should be concerned.
"It doesn't take a rocket scientist to grab that information and than use that data in a nefarious manner," said Kolthoff.
"If it was unencrypted, my concern would be the leverage that somebody could use against individuals."
wiredThe document, marked “Law Enforcement Use Only” and dated August 2010, illustrates there are some significant differences in how long carriers retain your data.
Verizon, for example, keeps a list of everyone you’ve exchanged text messages with for the past year, according to the document. But T-Mobile stores the same data up to five years. It’s 18 months for Sprint, and seven years for AT&T.
That makes Verizon appear to have the most privacy-friendly policy. Except that Verizon is alone in retaining the actual contents of text messages. It allegedly stores the messages for five days, while T-Mobile, AT&T, and Sprint don’t store them at all.
darkreading.comIn June, security firm FireEye detected evidence of such a connection when it found instances of a remote-access Trojan whose code seemed to have been reused to infect machines with fake antivirus software. In another incident, cybercriminals sold access to compromised military and government computers, allowing would-be cyberspies to get direct access to their targets, says Darien Kindlund, senior staff scientist at FireEye.
The two examples are part of a building body of evidence that suggests attackers representing what the military and security industry refer to as the advanced persistent threat (APT) are not shying away from using criminals' resources to help them in their missions.
"If military and government hosts are being sold on the black market, who are the most likely buyers -- spammers?' No, they could buy something cheaper on a different network. But for APT?'Yes, it meets their mission objectives," Kindlund says.
Espionage Research Institute (“ERI”) Conference – This year’s keynote speaker was Jarrett Kolthoff, a former U.S. Counterintelligence Agent, now CEO of cyber counterespionage firm SpearTip. Kolthoff provided valuable insights into recent and emerging domestic and foreign cyber espionage threats. Kolthoff was recognized with a plaque presented by ERI President, former CIA officer, Glenn Whidden.
SpearTip’s Kolthoff described a number of “incidents” he has dealt with for his Fortune 100 and other national and international clients to emphasize the increasing prevalence of internet-based surveillance techniques, cyber espionage, malware, APT (Advanced Persistent Threats) that requires his team to learn and adapt constantly to the ever-changing playing field.Whidden created ERI in an effort to bring together Technical Surveillance Countermeasures (“TSCM”) specialists, security practitioners, businessmen and corporate security executives to share information about hostile global espionage targeting business and industry.
Additionally, Kolthoff sees more and more corporate espionage by departing employees electronically transferring large amounts of competitively sensitive company data. The ease with which such data can be copied and transported requires far higher levels of vigilance by company executives. According to Kolthoff, it is not a matter of “if” data theft will occur, but what the company is prepared to do in mitigation of such losses “when” a company discovers that it has already been breached.
Kolthoff notes that threats exist for enterprises of all types and sizes, from governmental to non-profits to low tech service providers, in addition to obvious targets such as technology driven multinationals. No matter the organization, corporate espionage and cyber warfare are not simply on the doorstep – they are already a dramatic reality.

It took nearly three years, but Seattle police detectives say they've unraveled a theft ring that operated both in cyberspace and through old-fashioned burglaries with a technological twist — breaking into a company with the sole purpose of installing malicious software to enable future thefts.
Federal prosecutors have indicted three men — Joshua Allen Witt, 34; Brad Eugene Lowe, 36; and John Earl Griffin, 36 — on charges of conspiracy and eight other counts including accessing a protected computer to further fraud, access device fraud and aggravated identity theft.
The 20-page indictment lays out a scheme that U.S. Attorney Jenny Durkan on Wednesday said was "both sophisticated and rudimentary," and combined high technology with broken glass and jimmied locks.
The trio is accused of targeting at least 53 companies, with losses expected to mount into the hundreds of thousands of dollars.
"In some cases, the victims were both burgled and cyber-burgled," Durkan said at a news conference.
The indictment accused the men of "wardriving" — cruising in a vehicle outfitted with a powerful Wi-Fi receiver to detect business wireless networks. They then would hack into the company's network from outside, cracking the security code and accessing company computers and information.
crn.com.auBAE Systems Australia's cyber security head has warned against four mindsets preventing security specialists from effectively dealing with cyber threats.
According to the defence contractor's Tim Scully, an overemphasis on all-encompassing defensive measures or on compliance with standards or regulations could be counterproductive.
Scully, who was also the chief executive officer of BAE subsidiary Stratsec, chaired a work group on Cyber Threat and Fortress Mentality at the second national cyber warfare conference in Canberra this week.
Fortress mindset
He described the "fortress mindset" as the traditional approach to security, where specialists aimed to keep all threats outside of their networks.
Defensive measures in a "fortress" approach focused on systems and infrastructure rather than focusing on protecting the organisation's most valuable information.
That approach was as naïve as thinking that everything inside the network was secure, he said.
“If your network is connected to the Internet, and you have something of value to a threat actor, you are likely already compromised," he said.
More...
wiredTwo researchers who set up doppelganger domains to mimic legitimate domains belonging to Fortune 500 companies say they managed to vacuum up 20 gigabytes of misaddressed e-mail over six months.
The intercepted correspondence included employee usernames and passwords, sensitive security information about the configuration of corporate network architecture that would be useful to hackers, affidavits and other documents related to litigation in which the companies were embroiled, and trade secrets, such as contracts for business transactions.
“Twenty gigs of data is a lot of data in six months of really doing nothing,” said researcher Peter Kim from the Godai Group. “And nobody knows this is happening.”
Doppelganger domains are ones that are spelled almost identically to legitimate domains, but differ slightly, such as a missing period separating a subdomain name from a primary domain name – as in the case of seibm.com as opposed to the real se.ibm.com domain that IBM uses for its division in Sweden.
Kim and colleague Garrett Gee, who released a paper this week (.pdf) discussing their research, found that 30 percent, or 151, of Fortune 500 companies were potentially vulnerable to having e-mail intercepted by such schemes, including top companies in consumer products, technology, banking, internet communication, media, aerospace, defense, and computer security.
More...
foxnews.comAMSTERDAM – A company that sells certificates guaranteeing the security of websites, GlobalSign, said Tuesday it is temporarily halting the issuance of new certificates over concerns it may have been targeted by hackers.
GlobalSign, the Belgian subsidiary of Japan's GMO Internet Inc., is one of the oldest such companies globally, and large, but much smaller than industry giants VeriSign and GoDaddy.
It said in a statement it does not know whether it has actually been hacked, but is taking threats by an anonymous hacker seriously in the wake of an attack on a smaller Dutch firm, DigiNotar, that came to light last week.
The DigiNotar attack is believed to have allowed the Iranian government to spy on thousands of Iranian citizens' communications with Google email during the month of August.
Fallout from the Dutch hack continued Tuesday as the Dutch government, which used DigiNotar to authenticate many of its sites, continued to seek replacements.
Meanwhile the Netherlands' national prosecutors said they were investigating DigiNotar, a subsidiary of Chicago-based Vasco Inc., for possible criminal negligence.
The company did not return phone calls seeking comment.
More...
cnn.com London (CNN) -- U.S. government agencies, the United Nations, defense contractors and Olympic bodies have all been targeted by a single intruder in an "unprecedented" campaign of cyberspying, says a new report by a computer-security firm. The operation, which targeted agencies and groups in 14 countries, bears the hallmarks of state-sponsored espionage, according to the report by security company McAfee. Other cybersecurity experts downplayed the report's findings, however.
McAfee said the attacks, which it calls Operation Shady RAT, have allowed hackers potentially to gain access to military and industrial secrets from 72 targets, most of them in the United States, over a five-year period.
McAfee did not name all the targets but said the sheer scope of victims, including 14 U.S. government bodies; the governments of Canada, India, South Korea and Taiwan; defense contractors; the International Olympic Committee; and even a cybersecurity company, indicates no one is safe.
Dmitri Alperovitch, McAfee's vice president of threat research, said attacks on political nonprofit groups indicated a "state actor" could be behind the operation. He declined to name a specific country, but media reports have pointed a finger at China.
When contacted by CNN, an official at the Chinese embassy said that the allegations were unwarranted, irresponsible and an attempt to vilify China. The official added that China, too, has been a victim of hacking and that the country wants to work with other countries to end the problem.
More...