Tampilkan postingan dengan label cybertscm. Tampilkan semua postingan
Tampilkan postingan dengan label cybertscm. Tampilkan semua postingan

Kamis, 16 Februari 2012

Securing Corporate Data in a Law Office's Computer Network

Note: An excellent article, and a serious subject... When is the last time your law firm had a Cyber TSCM sweep? Ever? Contact me, I can help. ~JDL

law.com

The dramatic rise in electronic economic espionage against U.S. corporations came into full view with a report on the trend issued by the U.S. government last November. That same month, the Federal Bureau of Investigation held a meeting in New York City with some of the weaker links in the online spy game: law firms.

It’s an issue that should be getting the attention of in-house counsel, especially as they share sensitive--and potentially valuable--data with outside counsel.

Rich with client information, law firms are often much less equipped to fend off cyberattacks than the corporations they represent. Ergo “a hacker can hit a law firm and it’s a much, much easier quarry,” Mary Galligan, head of the cyber division in the FBI’s New York City office told Bloomberg. Likewise, in a series of blog posts on this issue currently running in Forbes, cybersecurity expert Alan Paller says: “The important files relating to clients’ international activities are usually much easier to find in the law firms’ files than in the corporate files.”

Digital risk consultancy Stroz Friedberg has advised both law firms and corporate clients on this growing problem. Firms need to take a risk-oriented approach to protecting client information, says company co-president Eric Friedberg, a former federal prosecutor and an expert in cybercrime response. At the same time, he says, there are important questions in-house counsel can ask about how their files will be protected (seeCounsel’s Dozen list below).

“Attackers go where the money is,” says Friedberg. These days, law firms should assume that hackers will infiltrate their network, and they should identify which digital assets are most at risk and put the most security around those areas, he says.


More...

Sabtu, 04 Februari 2012

Anons' FBI Phone Snooping Casts Long Shadow on Cybersecurity

technewsworld.com

Members of Anonymous managed to tap into an FBI conference call recently, after which they put a recording of the call on the open Web. The news has raised concern in many corners of the security industry. "The odds are that cybersecurity at the FBI and Scotland Yard is on par with, or superior to, security at most corporations," Abrams said.

The hacker community Anonymous on Friday landed another blow in its war with the United States Federal Bureau of Investigation (FBI).
It posted an internal memo from the law enforcement agency about an upcoming international call to discuss hackers. Anonymous also put up a recording of the call itself onYouTube.
"The information was intended for law enforcement officers only and was illegally obtained," the FBI said in a statement sent to TechNewsWorld by spokesperson Jenny Shearer. "A criminal investigation is underway to identify and hold accountable those responsible." 
The recorded call was a conversation between the FBI and Scotland Yard regarding tracking Anonymous members and other digital activists. It also involved other details about the efforts against such groups.

Jumat, 20 Januari 2012

10 Sites Skewered by Anonymous, Including FBI, DOJ, U.S. Copyright Office

techland.time.com

By the time East Coasters were finishing dinner last night, 10 websites had fallen to what hacktivist group Anonymous calls its “low orbit ion cannon,” or LOIC — a public domain software tool named after a weapon in a popular sci-fi real-time strategy game that’s designed to stress test whether a network can handle a distributed denial of service attack.
According to Anonymous, 10 well-known governmental and corporate sites with ties to the entertainment industry were assaulted and knocked offline in retaliation for the FBI shutting down Megaupload.com, one of the world’s largest file-sharing sites. The FBI had closed Megaupload.com earlier Thursday afternoon, accusing the company of more than $500 million in revenue losses stemming from copyright violations, and arresting four people in connection with the indictment.
Dubbing its DDoS spree “OpMegaupload,” Anonymous claims it took down usdoj.govand justice.gov (the U.S. Department of Justice), universalmusic.com (Universal Music Group),RIAA.org (the Recording Industry Association of America), MPAA.org (the Motion Picture Association of America), copyright.gov (the U.S. Copyright Office), hadopi.fr (France’s copyright-enforcement agency), wmg.com (Warner Music Group), bmi.com (Broadcast Music, Inc.) andfbi.gov (the Federal Bureau of Investigation). The DOJ’s website was first to fall, about an hour after the Justice Department announced its indictment of Megaupload.com.

Selasa, 17 Januari 2012

Facebook names $2m 'Koobface' hacking gang

telegraph.co.uk
Facebook has publicly identified a gang of five alleged cyber criminals it believes are behind Koobface, a piece of malicious software that has hijacked hundreds of thousands of Facebook users’ computers and made millions for its creators.

After an investigation by Facebook and several independent security researchers, the gang behind Koobface have been named as a group of Russians operating relatively openly in central St Petersburg.
According to their own social networking profiles, the five men have enjoyed a luxurious lifestyle. On one group holiday, they visited Spain, Nice and Monte Carlo, before ending the trip at a casino in Germany, according to Sophos, a British security firm involved in the investigation.
Facebook said it has known the identities of the gang for some time, but has decided to name them publicly after being frustrated by the lack of law enforcement action against them. The Telegraph has chosen not to name them for legal reasons.
“We’ve had a picture of one of the guys in a scuba mask on our wall since 2008,” said Ryan McGeehan, manager of investigations at Facebook.

Kamis, 12 Januari 2012

Cyber-Crimes Pose 'Existential' Threat, FBI Warns

huffingtonpost.com

Despite the increased frequency and severity of online crime and espionage in 2011, many American corporations and consumers are still not taking the threat seriously, the FBI's top cyber official said Thursday.

The risk posed by criminal hackers is "existential, meaning it could eliminate whole companies," said Shawn Henry, the FBI's executive assistant director. If hackers were able to tamper with critical infrastructure such as the power grid, "it could actually cause death," Henry said in remarks at the International Conference on Cyber Security in New York.

To highlight the growing threat, Henry cited several recent FBI investigations, such as one involving a smaller company that went out of business after hackers stole $5 million from accounts, another concerning a larger firm that "virtually overnight" lost a decade of research and development worth $1 billion, and still another regarding hackers who encrypted millions of records of a health services company and demanded money for the password.

"We've seen the number and sophistication of the attacks by these cyber actors increase dramatically," Henry said.

"Hundreds of millions of dollars have been stolen, primarily through the financial services sector, just in the last couple years," he said. An organized crime ring in Eastern Europe, for example, earned about $750,000 per week from cyber theft, he added.

More...

Note: Does your company have a Cyber TSCM / Cyber Counterespionage plan in place? Contact me, I can help. ~JDL

Selasa, 10 Januari 2012

Cyber Attacks May Be Revealed to Investors as SEC Rules Push Disclosures

Note: This was bound to happen as more and more companies become victims of Cyber Espionage. Has your company become a victim of Cyber Espionage? And, more importantly, does your company have a Cyber TSCM / Cyber Counterespionage strategy in place to mitigate this risk? 
Contact me, I can help. ~JDL

bloomberg.com

China-based hackers rifled the computers of DuPont Co. (DD) at least twice in 2009 and 2010, hunting the technological secrets that made the company one of the world’s most successful chemical makers.
It’s not something investors would have learned from DuPont’sregulatory filings, or from those of other companies victimized by hackers. The 10-K’s DuPont submitted to the U.S. Securities and Exchange Commission over the period don’t identify hacking as even a significant risk, much less reveal what two U.S. intelligence officials later said was a successful case of industrial espionage.
Over the next three months, as publicly traded companies file 10-K’s, investors may see new admissions of corporate networks being hacked after the SEC said companies can’t continue to hold back the details of those incidents.
As cyberspies from China, Russia and other countries ransack the computer networks of one major U.S. and European firm after the next, the SEC in October offered its new interpretation of disclosure requirements as applied to cybercrime. The amount of information that’s forthcoming will depend on whether company lawyers determine the incidents had, or will have, a material effect on the enterprise.
Daniel Turner, a spokesman for Wilmington, Delaware-based DuPont, said, regarding the previously-reported hack, “We let our disclosures speak for themselves.”

Senin, 09 Januari 2012

Symantec Confirms Anonymous Took Product Source Code

crn.com

Symantec (NSDQ:SYMC) confirmed Friday that an India-based chapter of hacker collective Anonymous had accessed the network of an unidentified third party and had taken source code from two of its corporate security products.
The vendor said code samples provided Thursday to an online community of security professionals called Infosec Island were from two products: Symantec Endpoint Protection 11 and Symantec AntiVirus 10.2. The vendor supports the latter, but no longer sells it, while the former is currently on version 12.1. The code was four or five years old, according to Symantec.
"It would be very difficult to do anything with (the code), because it is so old," Symantec spokesman Cris Paden said.
Malware designed to take advantage of the code would only work on the older products. Therefore, hackers would have to find a company that had not updated its security software in years, an unlikely scenario. "They would have been annihilated a long time ago from cyber threats," Paden said.
Symantec claimed the theft did not indicate that source code in its current products could be taken. The software today is architected differently, so the techniques used to take code from the older products won't work, Paden said. "It's not possible that they would be able to access current-day code."

Kamis, 05 Januari 2012

Brute force tools crack Wi-Fi security in hours, millions of wireless routers vulnerable

computerworld.com


If you set WPA/WPA2 security protocol on your home or small business wireless router, and you think your Wi-Fi is secure, there two recently released brute force tools that attackers may use to bypass your encryption and burst your security bubble. The irony is that the vulnerability which can be exploited was intended to be a security strength, a usability issue to help the technically clueless setup encryption on their wireless networks. Wi-Fi Protected Setup (WPS) is enabled by default on most major brands of wireless routers including Belkin, Buffalo, D-Link, Cisco's Linksys and Netgear, leaving millions of wireless routers around the world vulnerable to brute force attacks which can crack the Wi-Fi router's security in two to ten hours.
Most wireless routers come with a WPS personal identification number (PIN) printed on the device. When a user is setting up a wireless home network via a network setup wizard, enabling encryption is often as easy as pushing a button on the router and then entering the eight digit PIN which came with it. When an attacker is attempting to brute force the PIN and an incorrect value was entered, a message is sent that basically tells an attacker if the first half of the PIN was right or not. Additionally, according to Stefan Viehbock, the security researcher who reported the flaw, "The 8th digit of the PIN is always the checksum of digit one to digit seven," meaning it only takes an attacker about 11,000 brute force guesses to own the password. Unfortunately most wireless routers don't have a lockout policy after several failed password attempts.

Minggu, 01 Januari 2012

Anonymous exposes 75,000 credit card numbers

washingtonpost.com

Hacker collective Anonymous has just dumped 200 GB of names, email addresses and passwords for around 860,000 Stratfor users. Anonymous also exposed credit card numbers for 75,000 paying customers of Stratfor.

Stratfor, a security think tank, provides reports on international security and related threats to government and military personnel as well as to the private sector. It is unknown whether Anonymous gained access to other, more sensitive information during the Stratfor hacks, which occurred on December 24.

“The time for talk is over,” wrote Anonymous last night on Pastebin.

“It’s time to dump the full 75,000 names, addresses, CCs and md5 hashed passwords to every customer that has ever paid Stratfor. But that’s not all: we’re also dumping ~860,000 usernames, email addresses, and md5 hashed passwords for everyone who’s ever registered on Stratfor’s site… Did you notice 50,000 of these email addresses are .mil and .gov?”

Anonymous’ motives for the attack are also somewhat hazy. In last night’s statement, representatives of the movement wrote, “All our lives we have been robbed blindly and brutalized by corrupted politicians, establishmentarians and government agencies sex shops, and now it’s time to take it back.”

In addition to the Stratfor attack and exposure, Anonymous is threatening a new action on New Year’s Eve, December 31.

More...

Senin, 26 Desember 2011

U.S. Headed For Cyberwar Showdown With China In 2012

forbes
The new year is likely to bring a distinct shift in U.S. national security priorities, as the Obama Administration and Congress sharpen their response to China’s continuous assault on U.S. information networks.  Although intelligence-community analysts believe the most sophisticated intrusions are being executed by a relatively small number of agents linked to the general staff of China’s Peoples Liberation Army, the damage they are inflicting on U.S. security and economic competitiveness is judged to be extensive.

Thus far, China’s cyber campaign consists mainly of espionage aimed at stealing military secrets and intellectual property.  However, Gen. Keith Alexander, head of the Pentagon’s joint Cyber Command established to counter such campaigns, said in November that, “We see a disturbing track from exploitation to disruption to destruction.”  Alexander wasn’t talking just about the Chinese, but there’s little doubt among intelligence analysts that Beijing is the biggest and most persistent perpetrator of cyber crimes.
The question is what to do about it.  To date, U.S. cyber efforts have been focused mainly on defensive measures, seeking to repel network intruders in a fashion that Alexander likens to the famously failed Maginot Line.  The National Security Agency and other U.S. security organizations are known to have developed their own network-attack capabilities, but former White House cyber-security advisor Richard Clarke has warned that it would be dangerous for the U.S. to step up its own campaign against Chinese networks while U.S. safeguards against retaliation are so weak.

Rabu, 21 Desember 2011

Chinese Computer Hackers Hit U.S. Chamber of Commerce

foxnews


A group of hackers in China breached the computer defenses of America's top business-lobbying group and gained access to everything stored on its systems, including information about its three million members, according to several people familiar with the matter.
The break-in at the U.S. Chamber of Commerce is one of the boldest known infiltrations in what has become a regular confrontation between U.S. companies and Chinese hackers. The complex operation, which involved at least 300 internet addresses, was discovered and quietly shut down in May 2010.
It isn't clear how much of the compromised data was viewed by the hackers. Chamber officials say internal investigators found evidence that hackers had focused on four Chamber employees who worked on Asia policy, and that six weeks of their email had been stolen.

It is possible the hackers had access to the network for more than a year before the breach was uncovered, according to two people familiar with the Chamber's internal investigation.
One of these people said the group behind the break-in is one that U.S. officials suspect of having ties to the Chinese government. The Chamber learned of the break-in when the FBI told the group that servers in China were stealing its information, this person said. The FBI declined to comment on the matter.
A spokesman for the Chinese Embassy in Washington, Geng Shuang, said cyberattacks are prohibited by Chinese law and China itself is a victim of attacks. He said the allegation that the attack against the Chamber originated in China "lacks proof and evidence and is irresponsible," adding that the hacking issue shouldn't be "politicized."


More...

Selasa, 22 November 2011

Cyber attack on water utility an 'eye-opener' for security professionals

securitydirectornews.com

YARMOUTH, Maine—A cyber attack that apparently originated in Russia and targeted a water utility in Illinois may be the purview of IT security specialists, but it should be of concern to all security professionals with responsibilities over vital infrastructure, say utility security experts who spoke with Security Director News.
The cyber attack, which targeted the Curran-Gardner Township Public Water District, apparently took place on Nov. 8 and was traced to an IP address in Russia. By taking remote control of the Supervisory Control and Data Acquisition (SCADA) systems, the attackers were able to burn out a water pump. However, the event wasn't widely reported until Nov. 17, when Joe Weiss, a well-known expert on cyber security of utilities, wrote about the attack, citing a report from the Illinois Statewide Terrorism and Intelligence Center.
Though the cyber attack's only result was a burned-out pump at a small Illinois water utility, Allan Wick, security manager for the Tri-State Generation and Transmission Association and chairman of the ASIS Utilities Security Council, told Security Director News it's a very significant event. "This is the first documented instance in the United States of a SCADA system of a critical infrastructure being compromised," he said.
People have been talking about the potential for such an attack for years, Wick said, but not everyone in the utilities sector took the threat seriously. The event should be an "eye-opener" for security professionals with responsibility over vital infrastructure, Wick said. "Take the threat seriously," he said. "It's not someone crying wolf."

Rabu, 16 November 2011

Fox-IT and TNO to Work on System for Detecting Digital Espionage

digitaljournal.com


Delft, The Netherlands (PRWEB) November 16, 2011
The threat of targeted cyber attacks, especially digital espionage is increasing rapidly. The current security measures against cybercrime focus primarily on the detection of massive and indiscriminate attacks. To protect businesses and governments against cyber espionage Fox-IT and TNO are developing the Cyber Attack Detector (CAD).
Analyzing a large number of digital espionage indicators will allow users to be instantly alerted when there are activities that indicate fraud or espionage. The Ministry of Economic Affairs, Agriculture and Innovation in The Netherlands has granted €800,000 via the “Innovation for Public Security” program for the development of this joint solution.
Digital espionage threat is increasing, protection lagging
The social and economic impact of cybercrime is increasing, as is the demand for an effective protection against cybercrime. The attack methods of the digital spy have become more sophisticated, with increasing reports of very specific and targeted attacks. Traditional protective equipment such as intrusion detection systems, firewalls, virus scanners, and log analyzers offer inadequate protection.


More...

Facebook Hacked: Porn and Graphic Material Floods Users' Accounts

christianpost.com


Facebook has been under heavy attack the last two or three days as the popular social networking site has become the victim of a severe hacking spree affecting nearly every user on the site.

The hacks do not seem to have specific targets but happen at random with some user’s newsfeeds being littered with objectionable content and others not seeing anything.
Some of the hacks happen in the form of "click' spam being sent out. A popular spam involves Kim Kardashian with a link to a video. It will say something like "After watching this video I lost all respect for Kim." Upon clicking, the link takes the unsuspecting person nowhere, and hacks the account sending the same spam to all of the user’s friends.
Other spams include mass messages and tagged photos leading people to believe they are in the link or involved with it because it is not personalized. Those will also have the same result, and continue the spamming of others walls.

Senin, 31 Oktober 2011

Cyber spy campaign targets chemical industry: Symantec

(AFP)
SAN FRANCISCO — US Internet security firm Symantec on Monday exposed a cyber spying campaign targeting trade secrets at top chemical firms and linked the industrial espionage to a man in China.
At least 48 companies, including some that make advanced materials for military vehicles, were targeted in a campaign Symantec dubbed "Nitro" given the type of information at risk.
"Attacks on the chemical industry are merely their latest attack wave," Symantec security response team members Eric Chien and Gavin O'Gorman said in a report released on Monday.
The attacks targeted NGOs supporting human rights from late April to early May before switching to the motor industry, according to the report.
Major chemical firms, mainly in the United States, Britain, and Bangladesh, came under fire by cyber spies from late July to mid September, Symantec said.
Nitro was aimed at stealing intellectual property for competitive advantage, according to Chien and O'Gorman.
Attackers researched firms, sending selected workers booby-trapped emails that, once opened, secretly infected computers with malicious "Poison Ivy" software designed to steal information.
While various ruses were used to trick workers into opening email attachments to unleash spy software in machines, a typical pretext was to fake a meeting invitation from an established business partner.
Another tactic used by cyber spies was to send employees email purporting to be a security software update that needed to be installed in computers, according to Symantec.
Poison Ivy code was written by a Chinese speaker and Nitro attacks were traced to a server located in the United States but owned by a "20-something male" in the Hebei region of China, the report said.

Spouse Spy’s on the case

scpr.org

Tailing a philandering mate used to be so messy, complicated – and expensive. Private detectives aren’t cheap, after all, and someone always seems to end up dead – at least in the movies. But nowadays, suspicious spouses don’t need to call on Philip Marlowe. You can shadow your significant other just by installing Spouse Spy, or one of many similar apps, onto his or her cell phone.
A simple download lets you track comings and goings, read text messages, ogle photos, even listen in on conversations – all in real time. And of course, it’s all on the Q-T. – these apps are designed to be undetectable. But are they legal? A bipartisan group of senators, led by Al Franken (D-Minnesota) and Charles Grassley (R-Iowa) has asked the Department of Justice to look into whether these so-called “stalking apps” violate any laws.

Sabtu, 29 Oktober 2011

Facebook hack attacks strike 600,000 times per day, security firm reports

nydailynews.com

Social media company admits to massive lapse in security

Facebook accounts are hacked 600,000 times daily during users’ log-in, the social networking site conceded this week.
The Internet powerhouse said that it records more than 1 billion log-ons each day, and that .06% of those log-ons are compromised.
The shocking lapse in security was first reported by UK-based computer security firm Sophos.
Facebook could not be reached late Friday, although a note that accompanied the startling statistic said, “At Facebook, we take the privacy and safety of the people who use our site very seriously.
“Using a combination of technological innovations...we’re working 24/7 to ensure everyone’s information is safe and secure.”
The scary scope of the security breach was conceded by Facebook on a hard-to-find graphic accompanying a note dilating on its newest efforts to combat Internet piracy.
The post, authored by “Facebook Security” is entitled, “National Cybersecurity Awareness Month Updates,” and can be found on the site.


Read more...

Over 700 Companies Infiltrated by Cyber-Attack

mobiledia.com

At least 760 companies' networks were compromised by the same breach that affected security firm RSA, elevating concern over data security.



Bedford, Mass.-based RSA, the security division of EMC, provides security, risk and compliance solutions to major corporations and disclosed a data breach in March.
Security analyst Brian Krebs' blog identifies hundreds of business and organizations, including 20 percent of Fortune 500 companies, believed to be affected by the RSA security breach.
Krebs' list includes Abbott Labs, Cisco Systems, eBay, the European Space Agency, Facebook, Google, IBM, Intel, the IRS, Motorola, Research in Motion and Wells Fargo.
His list reveals the RSA attack was greater than previously understood, underscoring the challenges of detecting a breach and identifying the parties behind it, especially when the intrusion goes unnoticed until activated.
Shortly after hackers compromised RSA's network, it became clear the security firm wasn't the only corporation victimized in the attack, as dozens of other multinational companies were infiltrated using many of the same tools.

Jumat, 14 Oktober 2011

Welcome to the World of Cyber-Terror Vulnerability

foxnews.com
Did you open your BlackBerry Wednesday or even Thursday morning and find – nothing? No new e-mails, or tweets. No new text messages. Just blackness and that familiar screen saver photo of your child, spouse or dog? Welcome to the world of cyber-terrorism vulnerability.

The mysterious, world-wide virus that crippled BlackBerrys this week and spread like the plague – more on that threat later – across crossing oceans and five continents may spell financial catastrophe for the struggling Research In Motion aka RIM, whose stock shares have lost 60 percent of their value since the start of the year.

An RIM spokesman has said that the outage was caused by what Security Week called “a core switch failure within RIM’s infrastructure,” and not by a deliberate disabling attack. But the outage highlights the threat that determined cyber-warriors could pose to the nation’s communications systems if they target them.

For over a decade cyber-experts have urged the U.S. to upgrade critical infrastructure to protect vital dams, power plants, and communications systems from cyber-crime or cyber-attacks from rival countries. But the country remains complacent and highly vulnerable, as the BlackBerry outage shows.

During a recent cyber-security summit in New York, numerous experts warned that cyber-attacks could not only cause billions of dollars in damage to such vital systems, but endanger national security.

Read more: http://nation.foxnews.com/blackberry-outage/2011/10/13/welcome-world-cyber-terror-vulnerability#ixzz1amzsvuvp

Rabu, 28 September 2011

Which Telecoms Store Your Data the Longest? Secret Memo Tells All

wired
The nation’s major mobile-phone providers are keeping a treasure trove of sensitive data on their customers, according to newly-released Justice Department internal memo that for the first time reveals the data retention policies of America’s largest telecoms.

The single-page Department of Justice document, “Retention Periods of Major Cellular Service Providers,” (.pdf) is a guide for law enforcement agencies looking to get information — like customer IP addresses, call logs, text messages and web surfing habits – out of U.S. telecom companies, including AT&T, Sprint, T-Mobile and Verizon.

The document, marked “Law Enforcement Use Only” and dated August 2010, illustrates there are some significant differences in how long carriers retain your data.

Verizon, for example, keeps a list of everyone you’ve exchanged text messages with for the past year, according to the document. But T-Mobile stores the same data up to five years. It’s 18 months for Sprint, and seven years for AT&T.

That makes Verizon appear to have the most privacy-friendly policy. Except that Verizon is alone in retaining the actual contents of text messages. It allegedly stores the messages for five days, while T-Mobile, AT&T, and Sprint don’t store them at all.

More...

Related Posts Plugin for WordPress, Blogger...