Tampilkan postingan dengan label cyber espionage. Tampilkan semua postingan
Tampilkan postingan dengan label cyber espionage. Tampilkan semua postingan

Kamis, 23 Februari 2012

IT and espionage on Wall Street

economist.com

An overturned conviction creates uncertainty about what constitutes a crime


ASK a programmer at an investment bank where he works, and the answer will often simply be “Wall Street”. Isolated from clients and—it was once thought—assets with proprietary value, technologists bounce from firm to firm, from one high-rise building to another.
To this footloose community, the case of Sergey Aleynikov, a Goldman Sachs programmer, came as a shock. Mr Aleynikov was convicted in December 2010 of stealing code tied to Goldman’s lucrative high-speed proprietary-trading operations for use by a new employer. On February 16th, after he had spent nearly a year in prison, three judges in a federal appeals court unanimously reversed his conviction in a hearing that lasted just a single morning. Their written opinion is now eagerly awaited.
Mr Aleynikov admitted to taking code with him on his way out of Goldman, but argued successfully that this did not constitute a crime, or, to be more specific, a federal crime. He benefited from the help of a thorough lawyer, who adroitly knocked down two key claims. Because the computer trading system was not licensed or offered for sale, claimed Kevin Marino, the defendant’s lawyer, it was not a product to be bought or sold for interstate commerce, a key provision for a federal case. Because computer coding constitutes intangible intellectual property, Mr Marino said, it did not qualify under the goods, wares or merchandise components that are protected under the corporate-espionage act.

Kamis, 16 Februari 2012

Chinese Telecoms May Be Spying on Large Numbers of Foreign Customers

theatlantic.com
A U.S. Congressional probe is investigating whether China's state-linked firms, which built much of the communications infrastructure in several Asian countries, is using its access for snooping.

Two Chinese telecommunications giants are under scrutiny by a US congressional committee. The outcome of the probe could have revealing implications for Central Asian states, which have used these companies to modernize their telecom sectors.
US legislators have expressed concern that Huawei and ZTE act as front companies for the Chinese government, and represent a grave "cyber-security threat." The chairman of the House Permanent Select Committee on Intelligence, Michigan Republican Mike Rogers, asserted during a congressional hearing last October that China is engaged in the "brazen and wide-scale theft of intellectual property from foreign commercial competitors."
"Attributing this espionage isn't easy, but talk to any private sector cyber analyst, and they will tell you there is little doubt that this is a massive campaign being conducted by the Chinese government," he added.

More...

Selasa, 14 Februari 2012

Traveling Light in a Time of Digital Thievery

Note: Having recently traveled to China, I can attest to Mr. Lieberthal's concerns....Do yourself (and your company) a favor, Just accept the fact that you "will" be collected against...and take Mr. Lieberthal's advice...very seriously.  JDL

nytimes.com

SAN FRANCISCO — When Kenneth G. Lieberthal, a China expert at the Brookings Institution, travels to that country, he follows a routine that seems straight from a spy film.
He leaves his cellphone and laptop at home and instead brings “loaner” devices, which he erases before he leaves the United States and wipes clean the minute he returns. In China, he disables Bluetooth and Wi-Fi, never lets his phone out of his sight and, in meetings, not only turns off his phone but also removes the battery, for fear his microphone could be turned on remotely. He connects to the Internet only through an encrypted, password-protected channel, and copies and pastes his password from a USB thumb drive. He never types in a password directly, because, he said, “the Chinese are very good at installing key-logging software on your laptop.”
What might have once sounded like the behavior of a paranoid is now standard operating procedure for officials at American government agencies, research groups and companies that do business in China and Russia — like Google, the State Department and the Internet security giant McAfee. Digital espionage in these countries, security experts say, is a real and growing threat — whether in pursuit of confidential government information or corporate trade secrets.


More...

Selasa, 17 Januari 2012

Facebook names $2m 'Koobface' hacking gang

telegraph.co.uk
Facebook has publicly identified a gang of five alleged cyber criminals it believes are behind Koobface, a piece of malicious software that has hijacked hundreds of thousands of Facebook users’ computers and made millions for its creators.

After an investigation by Facebook and several independent security researchers, the gang behind Koobface have been named as a group of Russians operating relatively openly in central St Petersburg.
According to their own social networking profiles, the five men have enjoyed a luxurious lifestyle. On one group holiday, they visited Spain, Nice and Monte Carlo, before ending the trip at a casino in Germany, according to Sophos, a British security firm involved in the investigation.
Facebook said it has known the identities of the gang for some time, but has decided to name them publicly after being frustrated by the lack of law enforcement action against them. The Telegraph has chosen not to name them for legal reasons.
“We’ve had a picture of one of the guys in a scuba mask on our wall since 2008,” said Ryan McGeehan, manager of investigations at Facebook.

Senin, 09 Januari 2012

Symantec Confirms Anonymous Took Product Source Code

crn.com

Symantec (NSDQ:SYMC) confirmed Friday that an India-based chapter of hacker collective Anonymous had accessed the network of an unidentified third party and had taken source code from two of its corporate security products.
The vendor said code samples provided Thursday to an online community of security professionals called Infosec Island were from two products: Symantec Endpoint Protection 11 and Symantec AntiVirus 10.2. The vendor supports the latter, but no longer sells it, while the former is currently on version 12.1. The code was four or five years old, according to Symantec.
"It would be very difficult to do anything with (the code), because it is so old," Symantec spokesman Cris Paden said.
Malware designed to take advantage of the code would only work on the older products. Therefore, hackers would have to find a company that had not updated its security software in years, an unlikely scenario. "They would have been annihilated a long time ago from cyber threats," Paden said.
Symantec claimed the theft did not indicate that source code in its current products could be taken. The software today is architected differently, so the techniques used to take code from the older products won't work, Paden said. "It's not possible that they would be able to access current-day code."

Kamis, 05 Januari 2012

Brute force tools crack Wi-Fi security in hours, millions of wireless routers vulnerable

computerworld.com


If you set WPA/WPA2 security protocol on your home or small business wireless router, and you think your Wi-Fi is secure, there two recently released brute force tools that attackers may use to bypass your encryption and burst your security bubble. The irony is that the vulnerability which can be exploited was intended to be a security strength, a usability issue to help the technically clueless setup encryption on their wireless networks. Wi-Fi Protected Setup (WPS) is enabled by default on most major brands of wireless routers including Belkin, Buffalo, D-Link, Cisco's Linksys and Netgear, leaving millions of wireless routers around the world vulnerable to brute force attacks which can crack the Wi-Fi router's security in two to ten hours.
Most wireless routers come with a WPS personal identification number (PIN) printed on the device. When a user is setting up a wireless home network via a network setup wizard, enabling encryption is often as easy as pushing a button on the router and then entering the eight digit PIN which came with it. When an attacker is attempting to brute force the PIN and an incorrect value was entered, a message is sent that basically tells an attacker if the first half of the PIN was right or not. Additionally, according to Stefan Viehbock, the security researcher who reported the flaw, "The 8th digit of the PIN is always the checksum of digit one to digit seven," meaning it only takes an attacker about 11,000 brute force guesses to own the password. Unfortunately most wireless routers don't have a lockout policy after several failed password attempts.

Sabtu, 31 Desember 2011

Internet Crime Complaint Center's (IC3) Scam Alerts December 29, 2011

ic3.gov

This report, which is based upon information from law enforcement and complaints submitted to the IC3, details recent cyber crime trends, new twists to previously-existing cyber scams, and announcements.

POPULAR PASSWORDS

An Internet site who manages passwords recently posted an article pertaining to the lack of secure passwords being utilized which may be a factor in data breaches — past, present, and future. One reason for the lack of security is the amount of passwords a user is required to remember to access the many databases, applications, multiple networks, etc., used on a daily basis. Sharing passwords among users in a workplace is becoming a common theme to continue the flow of operations. Users have prioritized convenience over security when establishing passwords.
The article provided a list of millions of stolen passwords posted on-line by hackers and ranked the top 25 common passwords.
  1. password
  2. 123456
  3. 12345678
  4. qwerty
  5. abc123
  6. monkey
  7. 1234567
  8. letmein
  9. trustno1
  1. dragon
  2. baseball
  3. 111111
  4. iloveyou
  5. master
  6. sunshine
  7. ashley
  8. bailey
  9. passw0rd
  1. shadow
  2. 123123
  3. 654321
  4. superman
  5. qazwsx
  6. michael
  7. football











Senin, 26 Desember 2011

2012 Will See Rise in Cyber-Espionage and Malware, Experts Say

pcworld.com

The security industry expects the number of cyber-espionage attacks to increase in 2012 and the malware used for this purpose to become increasingly sophisticated.



In the past two years there has been a surge in the number of malware-based attacks that resulted in sensitive data being stolen from government agencies, defense contractors, Fortune 500 companies, human rights organizations and other institutions. (See also "How to Remove Malware From Your Windows PC.")
"I absolutely expect this trend to continue through 2012 and beyond," said Rik Ferguson, director of security research and communication at security firm Trend Micro. "Espionage activities have, for hundreds of years, taken advantage of cutting-edge technologies to carry out covert operations; 2011 was not the beginning of Internet-facilitated espionage, nor will it be the end," he added.
Threats like Stuxnet, which is credited with setting back Iran's nuclear program by several years, or its successor, Duqu, have shocked the security industry with their level of sophistication. Experts believe that they are only the beginning and that more highly advanced malware will be launched in 2012.

Rabu, 21 Desember 2011

Chinese Computer Hackers Hit U.S. Chamber of Commerce

foxnews


A group of hackers in China breached the computer defenses of America's top business-lobbying group and gained access to everything stored on its systems, including information about its three million members, according to several people familiar with the matter.
The break-in at the U.S. Chamber of Commerce is one of the boldest known infiltrations in what has become a regular confrontation between U.S. companies and Chinese hackers. The complex operation, which involved at least 300 internet addresses, was discovered and quietly shut down in May 2010.
It isn't clear how much of the compromised data was viewed by the hackers. Chamber officials say internal investigators found evidence that hackers had focused on four Chamber employees who worked on Asia policy, and that six weeks of their email had been stolen.

It is possible the hackers had access to the network for more than a year before the breach was uncovered, according to two people familiar with the Chamber's internal investigation.
One of these people said the group behind the break-in is one that U.S. officials suspect of having ties to the Chinese government. The Chamber learned of the break-in when the FBI told the group that servers in China were stealing its information, this person said. The FBI declined to comment on the matter.
A spokesman for the Chinese Embassy in Washington, Geng Shuang, said cyberattacks are prohibited by Chinese law and China itself is a victim of attacks. He said the allegation that the attack against the Chamber originated in China "lacks proof and evidence and is irresponsible," adding that the hacking issue shouldn't be "politicized."


More...

Chinese hackers hit Boston Scientific

massdevice.com
Boston Scientific is one of 760 firms hit by China-based cyber attacks.
Med-tech titan Boston Scientific (NYSE:BSX) was one of 760 companies hit by Chinese cyber attacks that also targeted U.S. government agencies, research universities and Internet providers.
It's not clear whether the Natick, Mass.-based medical device maker lost any sensitive information in the attack.
"We're talking about stealing entire industries," Scott Borg, director of the U.S. Cyber Consequences Unit, told the news service. "This may be the biggest transfer of wealth in a short period of time that the world has ever seen."
The attacks were aimed at the medical device, biotechnology, clean energy, advanced semiconductor, high-end manufacturing and information technology industries, according toBloomberg
Along with BSX, Abbott Laboratories (NYSE:ABT) and pharmaceutical giant Pfizer's (NYSE:PFE) Wyeth subsidiary were victims. The Chinese government is denying responsibility for the attacks.
The cyber-warfare is just the latest item in a string of bad luck for Boston Scientific, which got hit with a half-billion-dollar tax bill from the U.S. Internal Revenue Service last week.
The latest tab, for $581 million plus interest and penalties, comes out of an IRS audit of Boston Scientific's 2006 acquisition of pacemaker firm Guidant Corp.

Sabtu, 17 Desember 2011

China ‘Incredibly Aggressive’ in Cyber Theft

cnbc.com
China is stealing online information from the United States and feeding the data to homegrown companies for commercial benefit, Michael Hayden, Former Director of the Central Intelligence Agency said at the Black Hat Technical Security Conference in Abu Dhabi on Wednesday.

He pointed out that as an intelligence officer, he was "impressed" with the sophistication of Chinese cyber espionage, although spying in cyber space is an activity that all states, including the United States, take part in.
According to Hayden, "We steal secrets, you bet. But we steal secrets that are essential for American security and safety. We don't steal secrets for American commerce, for American profit. There are many other countries in the world that do not so self limit."
Despite the difficulty in tracing the origins of cyber attacks, Hayden believes China is the culprit behind various incidents of data theft.
"The body of evidence makes me quite comfortable and confident in saying that there's an incredibly large amount of this cyber activity coming from China," he told CNBC on the sidelines of the conference.
The retired general, who also served as the Director of the National Security Agency, added that, "I have come to the conclusion that the Chinese, the Chinese state and others in China are incredibly aggressive in the cyber domain, when it comes to the theft of property: state on state or against commercial targets."

Selasa, 22 November 2011

Compliance vs. Security: The Multiple Dimensions of Corporate Espionage

sys-con.com

You've spent months fixing the red items on an internal audit report and just passed a regulatory exam. You've performed a network vulnerability assessment and network pen test within the last year and have fixes in place. You've tightened up your information security policy and recently invested in a security information and event management (SIEM) solution. You're secure, right?
Put yourself in the shoes of a criminal. He knows that most security programs focus on regulatory compliance. He knows that IT departments have limited budgets. He also knows that you must defend against an almost unlimited number of attack vectors, while he just has to find one way in.
How do you protect against a sophisticated, motivated criminal? A professional spy who has targeted your company's trade secrets? A skilled insider with a specific purpose in mind? These types of people know that information comes in many forms, not just electronic, and they are trained to exploit any vulnerability. An effective information security program must incorporate more than just traditional pen tests and vulnerability assessments. 

Corporate espionage is on the rise for multiple reasons: the down economy, frequent job changes, and even governments that boost their economies through acquisition of trade secrets. In most cases, the end product is not as valuable as obtaining the means of production, the research and development, or the "know-how." This type of information will help to cut down on development costs and aid in the long-term production of a particular good. In the end, a company must get the best product to market first, at the best cost, through maneuvering around the competition.


Cyber attack on water utility an 'eye-opener' for security professionals

securitydirectornews.com

YARMOUTH, Maine—A cyber attack that apparently originated in Russia and targeted a water utility in Illinois may be the purview of IT security specialists, but it should be of concern to all security professionals with responsibilities over vital infrastructure, say utility security experts who spoke with Security Director News.
The cyber attack, which targeted the Curran-Gardner Township Public Water District, apparently took place on Nov. 8 and was traced to an IP address in Russia. By taking remote control of the Supervisory Control and Data Acquisition (SCADA) systems, the attackers were able to burn out a water pump. However, the event wasn't widely reported until Nov. 17, when Joe Weiss, a well-known expert on cyber security of utilities, wrote about the attack, citing a report from the Illinois Statewide Terrorism and Intelligence Center.
Though the cyber attack's only result was a burned-out pump at a small Illinois water utility, Allan Wick, security manager for the Tri-State Generation and Transmission Association and chairman of the ASIS Utilities Security Council, told Security Director News it's a very significant event. "This is the first documented instance in the United States of a SCADA system of a critical infrastructure being compromised," he said.
People have been talking about the potential for such an attack for years, Wick said, but not everyone in the utilities sector took the threat seriously. The event should be an "eye-opener" for security professionals with responsibility over vital infrastructure, Wick said. "Take the threat seriously," he said. "It's not someone crying wolf."

Rabu, 16 November 2011

Fox-IT and TNO to Work on System for Detecting Digital Espionage

digitaljournal.com


Delft, The Netherlands (PRWEB) November 16, 2011
The threat of targeted cyber attacks, especially digital espionage is increasing rapidly. The current security measures against cybercrime focus primarily on the detection of massive and indiscriminate attacks. To protect businesses and governments against cyber espionage Fox-IT and TNO are developing the Cyber Attack Detector (CAD).
Analyzing a large number of digital espionage indicators will allow users to be instantly alerted when there are activities that indicate fraud or espionage. The Ministry of Economic Affairs, Agriculture and Innovation in The Netherlands has granted €800,000 via the “Innovation for Public Security” program for the development of this joint solution.
Digital espionage threat is increasing, protection lagging
The social and economic impact of cybercrime is increasing, as is the demand for an effective protection against cybercrime. The attack methods of the digital spy have become more sophisticated, with increasing reports of very specific and targeted attacks. Traditional protective equipment such as intrusion detection systems, firewalls, virus scanners, and log analyzers offer inadequate protection.


More...

Facebook Hacked: Porn and Graphic Material Floods Users' Accounts

christianpost.com


Facebook has been under heavy attack the last two or three days as the popular social networking site has become the victim of a severe hacking spree affecting nearly every user on the site.

The hacks do not seem to have specific targets but happen at random with some user’s newsfeeds being littered with objectionable content and others not seeing anything.
Some of the hacks happen in the form of "click' spam being sent out. A popular spam involves Kim Kardashian with a link to a video. It will say something like "After watching this video I lost all respect for Kim." Upon clicking, the link takes the unsuspecting person nowhere, and hacks the account sending the same spam to all of the user’s friends.
Other spams include mass messages and tagged photos leading people to believe they are in the link or involved with it because it is not personalized. Those will also have the same result, and continue the spamming of others walls.

Kamis, 03 November 2011

U.S. Calls Out China and Russia for Cyber Espionage Costing Billions

foxnews


Hey, China and Russia, get off of our clouds.
That's the warning from a new U.S. national intelligence director's report to Congress released Thursday that states China and Russia are the biggest perpetrators of economic espionage through the Internet. 
The report, Foreign Spies Stealing U.S. Economic Secrets in Cyberspace, also warns that the efforts to calculate the cost of lost research and development is nearly impossible to calculate but could be costing up to $398 billion. As mobile devices proliferate, it's only going to get easier for spies to steal.


Analysts note that this is the first time the U.S. government report has so openly blamed countries that support cyber attacks and espionage at the national and state level.
"The computer networks of a broad array of U.S. government agencies, private companies,
universities, and other institutions -- all holding large volumes of sensitive economic information -- were targeted by cyber espionage; much of this activity appears to have originated in China," reads the report.
Drawing on data from 13 agencies, including the CIA and FBI, over the past two years, the report concludes that attacks against U.S. government networks and military contracts are on the rise. But one of the most worrying trends is the growing number of attacks on businesses that are smaller than the Fortune 500 companies.
Additionally, the report states that China's intelligence services -- as well as private companies and other entities -- are exploiting Chinese citizens or others with family ties in China who have "insider access to corporate networks to steal trade secrets using removable media devices or e-mail."



More...

Note: Worried about Cyber Espionage? Contact us, we can help. ~JDL

Senin, 31 Oktober 2011

Cyber spy campaign targets chemical industry: Symantec

(AFP)
SAN FRANCISCO — US Internet security firm Symantec on Monday exposed a cyber spying campaign targeting trade secrets at top chemical firms and linked the industrial espionage to a man in China.
At least 48 companies, including some that make advanced materials for military vehicles, were targeted in a campaign Symantec dubbed "Nitro" given the type of information at risk.
"Attacks on the chemical industry are merely their latest attack wave," Symantec security response team members Eric Chien and Gavin O'Gorman said in a report released on Monday.
The attacks targeted NGOs supporting human rights from late April to early May before switching to the motor industry, according to the report.
Major chemical firms, mainly in the United States, Britain, and Bangladesh, came under fire by cyber spies from late July to mid September, Symantec said.
Nitro was aimed at stealing intellectual property for competitive advantage, according to Chien and O'Gorman.
Attackers researched firms, sending selected workers booby-trapped emails that, once opened, secretly infected computers with malicious "Poison Ivy" software designed to steal information.
While various ruses were used to trick workers into opening email attachments to unleash spy software in machines, a typical pretext was to fake a meeting invitation from an established business partner.
Another tactic used by cyber spies was to send employees email purporting to be a security software update that needed to be installed in computers, according to Symantec.
Poison Ivy code was written by a Chinese speaker and Nitro attacks were traced to a server located in the United States but owned by a "20-something male" in the Hebei region of China, the report said.

Sabtu, 29 Oktober 2011

Facebook hack attacks strike 600,000 times per day, security firm reports

nydailynews.com

Social media company admits to massive lapse in security

Facebook accounts are hacked 600,000 times daily during users’ log-in, the social networking site conceded this week.
The Internet powerhouse said that it records more than 1 billion log-ons each day, and that .06% of those log-ons are compromised.
The shocking lapse in security was first reported by UK-based computer security firm Sophos.
Facebook could not be reached late Friday, although a note that accompanied the startling statistic said, “At Facebook, we take the privacy and safety of the people who use our site very seriously.
“Using a combination of technological innovations...we’re working 24/7 to ensure everyone’s information is safe and secure.”
The scary scope of the security breach was conceded by Facebook on a hard-to-find graphic accompanying a note dilating on its newest efforts to combat Internet piracy.
The post, authored by “Facebook Security” is entitled, “National Cybersecurity Awareness Month Updates,” and can be found on the site.


Read more...

Over 700 Companies Infiltrated by Cyber-Attack

mobiledia.com

At least 760 companies' networks were compromised by the same breach that affected security firm RSA, elevating concern over data security.



Bedford, Mass.-based RSA, the security division of EMC, provides security, risk and compliance solutions to major corporations and disclosed a data breach in March.
Security analyst Brian Krebs' blog identifies hundreds of business and organizations, including 20 percent of Fortune 500 companies, believed to be affected by the RSA security breach.
Krebs' list includes Abbott Labs, Cisco Systems, eBay, the European Space Agency, Facebook, Google, IBM, Intel, the IRS, Motorola, Research in Motion and Wells Fargo.
His list reveals the RSA attack was greater than previously understood, underscoring the challenges of detecting a breach and identifying the parties behind it, especially when the intrusion goes unnoticed until activated.
Shortly after hackers compromised RSA's network, it became clear the security firm wasn't the only corporation victimized in the attack, as dozens of other multinational companies were infiltrated using many of the same tools.

Minggu, 23 Oktober 2011

FBI: Tech firms face spy risk

democratandchronicle.com


Kexue Huang, a scientist and native of China, pleaded guilty last week in a federal court to swiping millions of dollars worth of trade secrets from Dow Chemical Co. and Cargill Inc. for other people doing research in Germany and China.


A federal jury last month ordered South Korea's Kolon Industries to pay DuPont Co. $920 million for stealing trade secrets regarding synthetic fibers used in such products as Kevlar body armor. A former DuPont engineer hired by Kolon, Michael Mitchell of Virginia, was sentenced in March last year to 18 months in prison for theft of trade secrets for passing on key DuPont data to Kolon.

And area technology companies are likely fooling themselves if they think they're not in the cross-hairs of such spy efforts, according to the Federal Bureau of Investigation. "If you haven't been a victim yet, it's because you have been and you don't know it, or you will be," Barry W. Couch, a special agent with FBI's Buffalo division, told a conference room full of area optics industry executives last week. "Don't be blindsided."

Chili's Sydor Optics played host as the FBI spent a handful of hours talking about counterintelligence and economic espionage issues, with handouts and a video presentation all revolving around the message that companies are under siege by foreign economic competitors, often with explicit help from foreign governments.

Optics in particular "is a targeted industry," said FBI special agent Chad Kaestle. Other frequently targeted technologies include sensors, aeronautics and marine systems.
Related Posts Plugin for WordPress, Blogger...