Tampilkan postingan dengan label cyber ci. Tampilkan semua postingan
Tampilkan postingan dengan label cyber ci. Tampilkan semua postingan

Kamis, 23 Februari 2012

Smartphone security gap exposes location, texts, email, expert says


latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

Dmitri Alperovitch, the former McAfee cyber security researcher who is best known for identifying a widespread China-based cyber espionage operation he dubbed "Shady Rat," has used a previously unknown hole in smartphone browsers to deliver an existing piece of China-based malware that can commandeer the device, record its calls, pinpoint its location and access user texts and emails. He conducted the experiment on a phone running Google's Android operating system, although he says Apple's iPhones are equally vulnerable.
"It's a much more powerful attack vector than just getting into someone's computer," said Alperovich, who just formed a new security company, called Crowdstrike, with former McAfee chief technology officer George Kutz.
Alperovich, who has consulted with the U.S. intelligence community, is scheduled to demonstrate his findings Feb. 29 at the RSA conference in San Francisco, an annual cyber security gathering. The Shady Rat attack he disclosed last year targeted 72 government and corporate entities for as long as five years, siphoning off unknown volumes of confidential material to a server in China.

IT and espionage on Wall Street

economist.com

An overturned conviction creates uncertainty about what constitutes a crime


ASK a programmer at an investment bank where he works, and the answer will often simply be “Wall Street”. Isolated from clients and—it was once thought—assets with proprietary value, technologists bounce from firm to firm, from one high-rise building to another.
To this footloose community, the case of Sergey Aleynikov, a Goldman Sachs programmer, came as a shock. Mr Aleynikov was convicted in December 2010 of stealing code tied to Goldman’s lucrative high-speed proprietary-trading operations for use by a new employer. On February 16th, after he had spent nearly a year in prison, three judges in a federal appeals court unanimously reversed his conviction in a hearing that lasted just a single morning. Their written opinion is now eagerly awaited.
Mr Aleynikov admitted to taking code with him on his way out of Goldman, but argued successfully that this did not constitute a crime, or, to be more specific, a federal crime. He benefited from the help of a thorough lawyer, who adroitly knocked down two key claims. Because the computer trading system was not licensed or offered for sale, claimed Kevin Marino, the defendant’s lawyer, it was not a product to be bought or sold for interstate commerce, a key provision for a federal case. Because computer coding constitutes intangible intellectual property, Mr Marino said, it did not qualify under the goods, wares or merchandise components that are protected under the corporate-espionage act.

Kamis, 03 November 2011

U.S. Calls Out China and Russia for Cyber Espionage Costing Billions

foxnews


Hey, China and Russia, get off of our clouds.
That's the warning from a new U.S. national intelligence director's report to Congress released Thursday that states China and Russia are the biggest perpetrators of economic espionage through the Internet. 
The report, Foreign Spies Stealing U.S. Economic Secrets in Cyberspace, also warns that the efforts to calculate the cost of lost research and development is nearly impossible to calculate but could be costing up to $398 billion. As mobile devices proliferate, it's only going to get easier for spies to steal.


Analysts note that this is the first time the U.S. government report has so openly blamed countries that support cyber attacks and espionage at the national and state level.
"The computer networks of a broad array of U.S. government agencies, private companies,
universities, and other institutions -- all holding large volumes of sensitive economic information -- were targeted by cyber espionage; much of this activity appears to have originated in China," reads the report.
Drawing on data from 13 agencies, including the CIA and FBI, over the past two years, the report concludes that attacks against U.S. government networks and military contracts are on the rise. But one of the most worrying trends is the growing number of attacks on businesses that are smaller than the Fortune 500 companies.
Additionally, the report states that China's intelligence services -- as well as private companies and other entities -- are exploiting Chinese citizens or others with family ties in China who have "insider access to corporate networks to steal trade secrets using removable media devices or e-mail."



More...

Note: Worried about Cyber Espionage? Contact us, we can help. ~JDL

SpearTip Announces Strategic Alliance With ComSec


St. Louis, Missouri (PRWEB) November 03, 2011
SpearTip, LLC CEO Jarrett Kolthoff announced that SpearTip has formed a strategic alliance with ComSec, LLC, of Virginia Beach, VA, which provides professional technical surveillance counter measure (TSCM) services nationwide. ComSec’s expertise includes electronic eavesdropping detection, bug sweeps, counterespionage consulting, counter surveillance, cyber TSCM, and anti-surveillance services for businesses and individuals.
Kolthoff said the alliance continues SpearTip’s geographic growth to the eastern seaboard as well as adding skill sets and technical capabilities to SpearTip’s existing cyber counterespionage arsenal.
ComSec is headed by CEO/President J.D. LeaSure, a countersurveillance practitioner in defense and industrial sectors since 1984. LeaSure has extensive training, knowledge, and experience covering eavesdropping devices, detection methods and other surveillance tactics employed by those seeking to steal information. The SpearTip alliance expands ComSec’s capabilities in cyber counterespionage and computer forensics.
“We believe this combination of talents and expertise will strengthen the unique service SpearTip offers clients,” Kolthoff said. “We are able to offer the broadest range of countersurveillance protection of anyone in the industry.”  

Sabtu, 29 Oktober 2011

Facebook hack attacks strike 600,000 times per day, security firm reports

nydailynews.com

Social media company admits to massive lapse in security

Facebook accounts are hacked 600,000 times daily during users’ log-in, the social networking site conceded this week.
The Internet powerhouse said that it records more than 1 billion log-ons each day, and that .06% of those log-ons are compromised.
The shocking lapse in security was first reported by UK-based computer security firm Sophos.
Facebook could not be reached late Friday, although a note that accompanied the startling statistic said, “At Facebook, we take the privacy and safety of the people who use our site very seriously.
“Using a combination of technological innovations...we’re working 24/7 to ensure everyone’s information is safe and secure.”
The scary scope of the security breach was conceded by Facebook on a hard-to-find graphic accompanying a note dilating on its newest efforts to combat Internet piracy.
The post, authored by “Facebook Security” is entitled, “National Cybersecurity Awareness Month Updates,” and can be found on the site.


Read more...

Over 700 Companies Infiltrated by Cyber-Attack

mobiledia.com

At least 760 companies' networks were compromised by the same breach that affected security firm RSA, elevating concern over data security.



Bedford, Mass.-based RSA, the security division of EMC, provides security, risk and compliance solutions to major corporations and disclosed a data breach in March.
Security analyst Brian Krebs' blog identifies hundreds of business and organizations, including 20 percent of Fortune 500 companies, believed to be affected by the RSA security breach.
Krebs' list includes Abbott Labs, Cisco Systems, eBay, the European Space Agency, Facebook, Google, IBM, Intel, the IRS, Motorola, Research in Motion and Wells Fargo.
His list reveals the RSA attack was greater than previously understood, underscoring the challenges of detecting a breach and identifying the parties behind it, especially when the intrusion goes unnoticed until activated.
Shortly after hackers compromised RSA's network, it became clear the security firm wasn't the only corporation victimized in the attack, as dozens of other multinational companies were infiltrated using many of the same tools.

Minggu, 23 Oktober 2011

FBI: Tech firms face spy risk

democratandchronicle.com


Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.


A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.

And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation. "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."

Chili's Sydor Optics played host as the FBI spent a handful of hours talking about counterintelligence and economic espionage issues, with handouts and a video presentation all revolving around the message that companies are under siege by foreign economic competitors, often with explicit help from foreign governments.

Optics in particular "is a targeted industry," said FBI special agent Chad Kaestle. Other frequently targeted technologies include sensors, aeronautics and marine systems.

Rabu, 19 Oktober 2011

U.S. DHS expects Anonymous to attack infrastructure

net-security.org
Anonymous is eyeing industrial control systems for future attacks, says the U.S. Department of Homeland Security, but its members have yet to demonstrate a capability to inflict damage to these systems.

"The information available on Anonymous suggests they currently have a limited ability to conduct attacks targeting ICS," says in thesecurity bulletin recently compiled by DHS' National Cybersecurity and Communications Integration Center. "However, experienced and skilled members of Anonymous in hacking could be able to develop capabilities to gain access and trespass on control system networks very quickly."

Aware that vulnerabilities in industrial control systems are plentiful, the DHS warns that common penetration testing software already uses control system exploits and packet inspection tools now support industrial protocols, so they can be taken advantage of for mounting attacks.

"In addition, there are control systems that are currently accessible directly from the Internet and easy to locate through internet search engine tools and applications," says the DHS experts. "These systems could be easily located and accessed with minimal skills in order to trespass, carry out nefarious activities, or conduct reconnaissance activities to be used in future operations."

Anonymous has still not targeted industrial control systems, but the DHS expects them to start in the near future as the collective has already made it known that its members should be targeting energy companies that don't seem to make an effort towards a "greener" production.



More...

Kamis, 13 Oktober 2011

Florida Man Arrested in “Operation Hackerazzi” for Targeting Celebrities with Computer Intrusion, Wiretapping, and Identity Theft

fbi.gov


LOS ANGELES—A man accused of targeting the entertainment industry by hacking into the personal e-mail accounts of celebrities was arrested today after being charged with a range of cyber-related crimes, announced André Birotte Jr., the United States Attorney in Los Angeles; and Steven Martinez, the Assistant Director in Charge of the FBI’s Los Angeles Field Office.
Christopher Chaney, 35, of Jacksonville, Florida, was arrested this morning by FBI agents without incident. A federal grand jury in Los Angeles returned a sealed indictment yesterday charging Chaney with violations under Title 18 of the U.S. Criminal Code, including: accessing protected computers without authorization; damaging protected computers without authorization; wiretapping; and aggravated identity theft.
According to the indictment, which was unsealed this morning, Chaney used several aliases while illegally obtaining personal information of numerous celebrities through a series of computer intrusions. The aliases used include: “trainreqsuckswhat,” “anonygrrl,” and “jaxjaguars911.”
Investigators believe that Chaney used publicly available sources to mine for data about his female and male victims, all of whom are associated with the entertainment industry. Once Chaney gained access and control of an e-mail account, he would obtain private information, such as e-mails and file attachments, according to the indictment. In addition, investigators believe that Chaney was led to new victims by accessing the address books of victims whose computers he already controlled.

Jumat, 07 Oktober 2011

SpearTip’s Top Cyber Counterespionage Expert Gives TV Interview on TRICARE Data Theft

prweb.com

Doubts custodian’s assurances. Fears possible extortion of military employees whose personal medical data was taken.


St. Louis, Missouri (PRWEB) October 07, 2011
Jarrett Kolthoff, CEO of Cyber Counterespionage firm SpearTip, was interviewed by CBS-affiliate KMOV about the recent theft of two-decades-worth of medical data on nearly five million military personnel. Part of the interview was broadcast. An expansion of that interview is included here.
The custodian of the records, Science Applications International Corporation (SAIC), reported the data breach had occurred two weeks earlier, when numerous back-up tapes were assertively stolen in a break-in of an employee’s car, while the tapes were in transit across town.
SAIC downplayed the breach, saying no financial information was involved, although SAIC acknowledged the tapes contained sensitive medical information. SAIC discounted harm from the loss of this information, saying: “The risk of harm to patients is judged to be low despite the data elements involved, since retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure.” Kolthoff said this statement is not an assurance that data was encrypted. The news report indicated that only “some” of the tapes were encrypted.

Jumat, 30 September 2011

kmov.com

(KMOV) -- Wednesday night, TRICARE, the health care program for millions of military members, retirees, and their families announced a data breach that affects an estimated 4.9 million people.

Read TRICARE's statement here: www.tricare.mil/mybenefit/Download/Forms/DataBreach_PublicStatement.pdf

Science Applications International Corporation reported that one of its employees was driving backup computer tapes from one federal office to another in San Antonio, Texas. At one point, the car was broken into and the backup tapes were stolen. SAIC says it won't disclose how many tapes were taken, but says only "some" were encrypted.

The tapes that were lost included names, Social Security numbers, addresses, and medical treatment information of patients who were treated at San Antonio military treatment facilities (or patients who have had lab work processes there) from 1992 until September 7, 2011.

TRICARE and SAIC say they are working to identify all the beneficiaries whose information may have been lost and notify the affected people. TRICARE says that the risk of harm to patients is low because the thief would have to have access to specific hardware and software and know how to pull the data from the tapes.

Jarrett Kolthoff, who runs a cyber security firm called SpearTip, LLC, says people should be concerned.

"It doesn't take a rocket scientist to grab that information and than use that data in a nefarious manner," said Kolthoff.

"If it was unencrypted, my concern would be the leverage that somebody could use against individuals."

More...

Rabu, 28 September 2011

Which Telecoms Store Your Data the Longest? Secret Memo Tells All

wired
The nation’s major mobile-phone providers are keeping a treasure trove of sensitive data on their customers, according to newly-released Justice Department internal memo that for the first time reveals the data retention policies of America’s largest telecoms.

The single-page Department of Justice document, “Retention Periods of Major Cellular Service Providers,” (.pdf) is a guide for law enforcement agencies looking to get information — like customer IP addresses, call logs, text messages and web surfing habits – out of U.S. telecom companies, including AT&T, Sprint, T-Mobile and Verizon.

The document, marked “Law Enforcement Use Only” and dated August 2010, illustrates there are some significant differences in how long carriers retain your data.

Verizon, for example, keeps a list of everyone you’ve exchanged text messages with for the past year, according to the document. But T-Mobile stores the same data up to five years. It’s 18 months for Sprint, and seven years for AT&T.

That makes Verizon appear to have the most privacy-friendly policy. Except that Verizon is alone in retaining the actual contents of text messages. It allegedly stores the messages for five days, while T-Mobile, AT&T, and Sprint don’t store them at all.

More...

The Best Spies Money Can Buy

darkreading.com
Security firms have found evidence that espionage agents are buying time on leased botnets: Will cybercriminals services lead to more efficient spying?

During the past decade, cybercriminals have specialized in the various tasks needed to compromise computers, steal data, and make money. Now, more elusive nation-state attackers could be using rented botnets and cybercriminal services to streamline their own operations, security experts say.

In June, security firm FireEye detected evidence of such a connection when it found instances of a remote-access Trojan whose code seemed to have been reused to infect machines with fake antivirus software. In another incident, cybercriminals sold access to compromised military and government computers, allowing would-be cyberspies to get direct access to their targets, says Darien Kindlund, senior staff scientist at FireEye.

The two examples are part of a building body of evidence that suggests attackers representing what the military and security industry refer to as the advanced persistent threat (APT) are not shying away from using criminals' resources to help them in their missions.

"If military and government hosts are being sold on the black market, who are the most likely buyers -- spammers?' No, they could buy something cheaper on a different network. But for APT?'Yes, it meets their mission objectives," Kindlund says.

More...

Selasa, 27 September 2011

SpearTip's Counterespionage Expert Warns of Emerging Cyber Threats to Private Industry

prweb.com

Former U.S. Counterintelligence Agent Jarrett Kolthoff keynotes conference of counterespionage practitioners and technologists.

St. Louis, Missouri (PRWEB) September 27, 2011

Espionage Research Institute (“ERI”) Conference – This year’s keynote speaker was Jarrett Kolthoff, a former U.S. Counterintelligence Agent, now CEO of cyber counterespionage firm SpearTip. Kolthoff provided valuable insights into recent and emerging domestic and foreign cyber espionage threats. Kolthoff was recognized with a plaque presented by ERI President, former CIA officer, Glenn Whidden.

SpearTip’s Kolthoff described a number of “incidents” he has dealt with for his Fortune 100 and other national and international clients to emphasize the increasing prevalence of internet-based surveillance techniques, cyber espionage, malware, APT (Advanced Persistent Threats) that requires his team to learn and adapt constantly to the ever-changing playing field.

Whidden created ERI in an effort to bring together Technical Surveillance Countermeasures (“TSCM”) specialists, security practitioners, businessmen and corporate security executives to share information about hostile global espionage targeting business and industry.

Additionally, Kolthoff sees more and more corporate espionage by departing employees electronically transferring large amounts of competitively sensitive company data. The ease with which such data can be copied and transported requires far higher levels of vigilance by company executives. According to Kolthoff, it is not a matter of “if” data theft will occur, but what the company is prepared to do in mitigation of such losses “when” a company discovers that it has already been breached.

Kolthoff notes that threats exist for enterprises of all types and sizes, from governmental to non-profits to low tech service providers, in addition to obvious targets such as technology driven multinationals. No matter the organization, corporate espionage and cyber warfare are not simply on the doorstep – they are already a dramatic reality.

More...

Kamis, 22 September 2011

Feds: Trio hacked Wi-Fi or burglarized 50 firms



Seattle police detectives say they've unraveled a theft ring that operated both in cyberspace and through old-fashioned burglaries with a technological twist — breaking into a company with the sole purpose of installing malicious software to enable future thefts.

It took nearly three years, but Seattle police detectives say they've unraveled a theft ring that operated both in cyberspace and through old-fashioned burglaries with a technological twist — breaking into a company with the sole purpose of installing malicious software to enable future thefts.

Federal prosecutors have indicted three men — Joshua Allen Witt, 34; Brad Eugene Lowe, 36; and John Earl Griffin, 36 — on charges of conspiracy and eight other counts including accessing a protected computer to further fraud, access device fraud and aggravated identity theft.

The 20-page indictment lays out a scheme that U.S. Attorney Jenny Durkan on Wednesday said was "both sophisticated and rudimentary," and combined high technology with broken glass and jimmied locks.

The trio is accused of targeting at least 53 companies, with losses expected to mount into the hundreds of thousands of dollars.

"In some cases, the victims were both burgled and cyber-burgled," Durkan said at a news conference.

The indictment accused the men of "wardriving" — cruising in a vehicle outfitted with a powerful Wi-Fi receiver to detect business wireless networks. They then would hack into the company's network from outside, cracking the security code and accessing company computers and information.

More...

Selasa, 20 September 2011

Defence contractor warns of false cyber security beliefs

crn.com.au

Four 'mindsets' that trip up specialists.

BAE Systems Australia's cyber security head has warned against four mindsets preventing security specialists from effectively dealing with cyber threats.

According to the defence contractor's Tim Scully, an overemphasis on all-encompassing defensive measures or on compliance with standards or regulations could be counterproductive.

Scully, who was also the chief executive officer of BAE subsidiary Stratsec, chaired a work group on Cyber Threat and Fortress Mentality at the second national cyber warfare conference in Canberra this week.

Fortress mindset

He described the "fortress mindset" as the traditional approach to security, where specialists aimed to keep all threats outside of their networks.

Defensive measures in a "fortress" approach focused on systems and infrastructure rather than focusing on protecting the organisation's most valuable information.

That approach was as naïve as thinking that everything inside the network was secure, he said.

“If your network is connected to the Internet, and you have something of value to a threat actor, you are likely already compromised," he said.

More...

Jumat, 09 September 2011

Researchers’ Typosquatting Stole 20 GB of E-Mail From Fortune 500 Companies

wired

Two researchers who set up doppelganger domains to mimic legitimate domains belonging to Fortune 500 companies say they managed to vacuum up 20 gigabytes of misaddressed e-mail over six months.

The intercepted correspondence included employee usernames and passwords, sensitive security information about the configuration of corporate network architecture that would be useful to hackers, affidavits and other documents related to litigation in which the companies were embroiled, and trade secrets, such as contracts for business transactions.

“Twenty gigs of data is a lot of data in six months of really doing nothing,” said researcher Peter Kim from the Godai Group. “And nobody knows this is happening.”

Doppelganger domains are ones that are spelled almost identically to legitimate domains, but differ slightly, such as a missing period separating a subdomain name from a primary domain name – as in the case of seibm.com as opposed to the real se.ibm.com domain that IBM uses for its division in Sweden.

Kim and colleague Garrett Gee, who released a paper this week (.pdf) discussing their research, found that 30 percent, or 151, of Fortune 500 companies were potentially vulnerable to having e-mail intercepted by such schemes, including top companies in consumer products, technology, banking, internet communication, media, aerospace, defense, and computer security.

More...

Rabu, 07 September 2011

Espionage? Second Web Firm Worried After Dutch Hack

foxnews.com

A company that sells certificates guaranteeing the security of websites, GlobalSign, said Tuesday it is temporarily halting the issuance of new certificates over concerns it may have been targeted by hackers.

GlobalSign, the Belgian subsidiary of Japan's GMO Internet Inc., is one of the oldest such companies globally, and large, but much smaller than industry giants VeriSign and GoDaddy.

It said in a statement it does not know whether it has actually been hacked, but is taking threats by an anonymous hacker seriously in the wake of an attack on a smaller Dutch firm, DigiNotar, that came to light last week.

The DigiNotar attack is believed to have allowed the Iranian government to spy on thousands of Iranian citizens' communications with Google email during the month of August.

Fallout from the Dutch hack continued Tuesday as the Dutch government, which used DigiNotar to authenticate many of its sites, continued to seek replacements.

Meanwhile the Netherlands' national prosecutors said they were investigating DigiNotar, a subsidiary of Chicago-based Vasco Inc., for possible criminal negligence.

The company did not return phone calls seeking comment.

More...

Senin, 08 Agustus 2011

Massive cyberspying operation targeted U.S., U.N., others

cnn.com London (CNN) -- U.S. government agencies, the United Nations, defense contractors and Olympic bodies have all been targeted by a single intruder in an "unprecedented" campaign of cyberspying, says a new report by a computer-security firm.

The operation, which targeted agencies and groups in 14 countries, bears the hallmarks of state-sponsored espionage, according to the report by security company McAfee. Other cybersecurity experts downplayed the report's findings, however.

McAfee said the attacks, which it calls Operation Shady RAT, have allowed hackers potentially to gain access to military and industrial secrets from 72 targets, most of them in the United States, over a five-year period.

McAfee did not name all the targets but said the sheer scope of victims, including 14 U.S. government bodies; the governments of Canada, India, South Korea and Taiwan; defense contractors; the International Olympic Committee; and even a cybersecurity company, indicates no one is safe.

Dmitri Alperovitch, McAfee's vice president of threat research, said attacks on political nonprofit groups indicated a "state actor" could be behind the operation. He declined to name a specific country, but media reports have pointed a finger at China.

When contacted by CNN, an official at the Chinese embassy said that the allegations were unwarranted, irresponsible and an attempt to vilify China. The official added that China, too, has been a victim of hacking and that the country wants to work with other countries to end the problem.

More...

Related Posts Plugin for WordPress, Blogger...