Saturday, February 28, 2015

MITRE Malicious Insiders

MITRE Malicious Insiders:



Malicious insiders, who have legitimate access to an organization's network, pose a serious threat to an organization.

HIMSS Security Survey | Privacy & Security | HIMSS

... the greatest "security threat motivator" they encounter is that of healthcare workers potentially snooping into the electronic health information of friends, neighbors, spouses or co-workers.

http://www.himss.org/ResourceLibrary/genResourceDetailPDF.aspx?ItemNumber=28270

SecureScan: Free Cloud-based Vulnerability Scanner | Tripwire

More connected devices mean more opportunity for compromise. Tripwire® SecureScan makes it easy for smaller organizations to know exactly which devices are on their networks.

http://www.tripwire.com/securescan/

Schneier on Security: Regin Malware

https://www.schneier.com/blog/archives/2014/12/corporate_abuse.html

"...We want, and need, our antivirus companies to tell us everything they can about these threats as soon as they know them, and not wait until the release of a political story makes it impossible for them to remain silent."

Friday, February 27, 2015

Links Found between NSA, Regin Spy tool and QWERTY Keylogger in NSA

"Regin" is a highly advanced, sophisticated piece of malware the researchers believe was developed by nation state ...

http://www.wikileaks-forum.com/nsa/332/links-found-between-nsa-regin-spy-tool-and-qwerty-keylogger/33070/


From My iPhone

check-and-secure | powered by cyscon GmbH!

check-and-secure | powered by cyscon GmbH!: This web service is a free online tool provided by cyscon GmbH and Vodafone. Based on the results we lead you through a variety of checks step by step.

Thursday, February 26, 2015

Spam Uses Default Passwords to Hack Routers — Krebs on Security

If successful, the attacker's script would modify the domain name system (DNS) settings on the victim's router, adding the attacker's own DNS server as the primary server while leaving the secondary setting as-is. 

http://krebsonsecurity.com/2015/02/spam-uses-default-passwords-to-hack-routers/

Wednesday, February 25, 2015

Transpacific Airline Settlement > mainpage > Claim Form

Transpacific Airline Settlement > mainpage > Claim Form:



if you bought a ticket for air travel from one of the Defendants or Co-Conspirators; the ticket included at least one flight segment between the U.S. and Asia or the U.S. and Oceania (Australia, New Zealand or the Pacific Islands); your purchase was made between January 1, 2000 and the Effective Date*, and you were not reimbursed for your purchase by someone else.

Everyday Risk Assessment

Everyday Risk Assessment: This 30-minute lesson is designed to introduce you to risk management concepts and practices at the U.S. Customs Service.

USATODAY.com - Schwarzenegger took sexual harassment course

USATODAY.com - Schwarzenegger took sexual harassment course: Gov. Arnold Schwarzenegger, whose campaign was dogged by allegations of sexual misconduct, volunteered to take a two-hour course about preventing sexual harassment earlier this year.

Tuesday, February 24, 2015

Monday, February 23, 2015

“SSL hijacker” behind Superfish debacle imperils large number of users | Ars Technica

“SSL hijacker” behind Superfish debacle imperils large number of users | Ars Technica: "In fairness to Komodia and Superfish, many applications—some provided by Microsoft or trusted security companies—install custom root certificates on end user machines."



'via Blog this'

Saturday, February 21, 2015

Businesses Need Rapid Incident Detection & Response- Why Obama’s Cybersecurity Proposal Misses the Mark | InfoSec Insights

Businesses Need Rapid Incident Detection & Response- Why Obama’s Cybersecurity Proposal Misses the Mark | InfoSec Insights: "the 30-day window is nothing more than rhetoric trying to mask the underlying problem- lack of proper investment in Intel-Detection-Response (IDR) capabilities."



'via Blog this'

A Hacker Personality Quadrant - The Security Skeptic

A Hacker Personality Quadrant - The Security Skeptic: ""Hacking is a late-modern transgressive craft.""



'via Blog this'

Anthem Hackers Tried To Breach System As Early As December

Anthem Hackers Tried To Breach System As Early As December: "Investigators now believe the hackers somehow compromised the credentials of five different tech workers, possibly through some kind of "phishing" scheme that could have tricked a worker into unknowingly revealing a password or downloading malicious software."



'via Blog this'

Superfish Uninstall Instructions - Lenovo Support (US)

Superfish Uninstall Instructions - Lenovo Support (US): "Please download and run the Automatic Removal tool executable to ensure complete removal of Superfish and Certificates for all major browsers."



'via Blog this'

Friday, February 20, 2015

LastPass - LastPass Superfish Checker

LastPass - LastPass Superfish Checker: News broke on Wednesday, February 18th that Lenovo devices had shipped with adware that may compromise secure connections to websites and leave sensitive consumer information exposed

Check if you trust the Superfish CA

Check if you trust the Superfish CA: Check below. If you see an image with "YES" written on it,
you have a problem. Do the test with all browsers installed.

Un experto afirma que los ataques de los hackers precisan de control

Un experto afirma que los ataques de los hackers precisan de control / Sputnik Mundo: Los ataques de los hackers contra las infraestructuras de defensa estatal, incluyendo las instituciones militares, se han tornado tan efectivos, que los programas da�inos han de ser controlados en modo especial, al mismo nivel que las armas de exterminio en masa, declar�Arti�m Bar�nov, analista de virus de ESET Russia.

Hacker Says He Was Hit With 44 Felonies After He Declined to Work With FBI

"Fundamentally this represents the FBI trying to recruit by indictment."

http://www.slate.com/blogs/future_tense/2015/02/19/hacker_says_he_was_hit_with_44_felonies_after_he_declined_to_work_with_fbi.html


From My iPhone

Thursday, February 19, 2015

U.S. Terrorism Agency to Tap a Vast Database of Citizens - WSJ

U.S. Terrorism Agency to Tap a Vast Database of Citizens - WSJ:



December 13, 2012:



"Now, NCTC can copy entire government databases—flight records, casino-employee lists, the names of Americans hosting foreign-exchange students and many others. The agency has new authority to keep data about innocent U.S. citizens for up to five years, and to analyze it for suspicious patterns of behavior. Previously, both were prohibited. Data about Americans "reasonably believed to constitute terrorism information" may be permanently retained."

Monday, February 16, 2015

Cybersecurity Sharing: The Latest Fad or a Real Security Breakthrough?

Cybersecurity Sharing: The Latest Fad or a Real Security Breakthrough?:



"Unless the stated goal is to identify bad actors more swiftly, and sanction them with greater precision and immediacy, we’re not going to deter the kind of attacks that provoked this new initiative."



'via Blog this'

Report Connects Elite Hacking Group to NSA-Linked Cyberweapons | SecurityWeek.Com

Report Connects Elite Hacking Group to NSA-Linked Cyberweapons | SecurityWeek.Com: "the Equation Group has infected thousands, “even tens of thousands,” of victims, in more than 30 countries worldwide, "



'via Blog this'

9 Confessions From A Former Enterprise Rental Salesman – Consumerist

9 Confessions From A Former Enterprise Rental Salesman – Consumerist: 9 tips, 5 pages of insider info about how the car rental game really works.

Cyber-security experts judge '$1bn bank hack' report - BBC News

But security experts are split over the severity of the alleged breaches, and on how much cash was stolen.

http://m.bbc.com/news/technology-31487258


From My iPhone

Maikel Zweerink / WhatsSpy-Public | GitLab

Maikel Zweerink / WhatsSpy-Public | GitLab: "WhatsSpy Public (not to confuse with WhatsSpy) is an web-oriented application that tracks every move of whoever you like to follow. This application is setup as an Proof of Concept that WhatsApp is broken in terms of privacy."



'via Blog this'

WhatDaHell, WhatsApp? Student claims 'stalker' tool shows security flaws • The Register

WhatDaHell, WhatsApp? Student claims 'stalker' tool shows security flaws • The Register: "A newly discovered security flaw in WhatsApp allows anyone to track a user’s status, regardless of their privacy settings, a student claims."



'via Blog this'

How to Protect Your Business Against Fraud | Inc.com

How to Protect Your Business Against Fraud | Inc.com: three-fourths of the crimes against businesses in the U.S. were carried out by insiders.

Sunday, February 15, 2015

Security services capable of bypassing encryption, draft code reveals | UK news | The Guardian

Security services capable of bypassing encryption, draft code reveals | UK news | The Guardian: "The publication of the draft code follows David Cameron’s speech last month in which he pledged to break into encryption and ensure there was no “safe space” for terrorists or serious criminals which could not be monitored online by the security services with a ministerial warrant, effectively spelling out how it might be done."



'via Blog this'

Forbes, Jason Hope Point to Big Data Mistake in Industrial IoT

Forbes, Jason Hope Point to Big Data Mistake in Industrial IoT: ""The key will be to gain access to this older data, so predictive apps and devices can have a full range of data with which to make predictions.""



'via Blog this'

LexisNexis, Retail Workers Get Nod For $2.38M Settlement - Law360

LexisNexis, Retail Workers Get Nod For $2.38M Settlement - Law360: "A Pennsylvania federal judge has given preliminary approval to a $2.38 million settlement in a proposed class action claiming LexisNexis Risk Solutions Inc. illegally distributed damaging information about retail workers to current and potential employers.
Under the settlement, LexisNexis has suspended its Esteem database"



'via Blog this'

Jamie Bartlett: The coming online privacy revolution - Index on Censorship | Index on Censorship

Jamie Bartlett: The coming online privacy revolution - Index on Censorship | Index on Censorship: "This trend towards decentralised, encrypted systems has become an important aspect of the current crypto-wars."



'via Blog this'

How the NSA is improving security for everyone | Network World

NSA is also expected to secure and protect sensitive information, and as part of that role NSA security experts have launched a program to integrate more commercial off-the-shelf products.

http://www.networkworld.com/article/2880477/security0/how-the-nsa-is-improving-security-for-everyone.html


From My iPhone

Saturday, February 14, 2015

Groove Armada - Wikipedia, the free encyclopedia

Groove Armada are an electronic music duo from London, England

Edge Hill

http://en.m.wikipedia.org/wiki/Groove_Armada

Jeremy Dean's Dare Not Walk Alone at the Dikeou Collection

Jeremy Dean's Dare Not Walk Alone at the Dikeou Collection:



Five years in the making, DNWA offers an insight into the artist's engagement with the various socioeconomic and political challenges that have been at the crux of his visual art practice over the last decade.

David B. Smith Gallery | Contemporary Art Gallery in Denver | Constructed Histories

David B. Smith Gallery | Contemporary Art Gallery in Denver | Constructed Histories: Constructed Histories

Press Release

Opening reception on Friday, February 13, 7-9pm

Friday, February 13, 2015

Common Sense Guide to Mitigating Insider Threats, 4th Edition

Common Sense Guide to Mitigating Insider Threats, 4th Edition: This fourth edition of the Common Sense Guide to Mitigating Insider Threats provides the most current recommendations of the CERT� Program (part of Carnegie Mellon University's Software Engineering Institute), based on an expanded database of more than 700 insider threat cases and continued research and analysis. 144 pages

Personal weather stations can expose your Wi-Fi network | ITworld

Personal weather stations can expose your Wi-Fi network | ITworld:



In the latest Internet of Things security blunder, personal weather station devices made by Netatmo were found sending users’ Wi-Fi passwords back to the company over unencrypted connections.

Executive Order -- Promoting Private Sector Cybersecurity Information Sharing | The White House

Executive Order -- Promoting Private Sector Cybersecurity Information Sharing | The White House:



"The purpose of this order is to encourage the voluntary formation of such organizations, to establish mechanisms to continually improve the capabilities and functions of these organizations, and to better allow these organizations to partner with the Federal Government on a voluntary basis.



 Such information sharing must be conducted in a manner that protects the privacy and civil liberties of individuals, that preserves business confidentiality, that safeguards the information being shared, and that protects the ability of the Government to detect, investigate, prevent, and respond to cyber threats to the public health and safety, national security, and economic security of the United States."



'via Blog this'

Critical Fixes for the Computer Fraud and Abuse Act | Electronic Frontier Foundation

Critical Fixes for the Computer Fraud and Abuse Act | Electronic Frontier Foundation: Violations of contractual obligations like a website's terms of service must not be the basis for criminal charges.

ESET Security Day London | ESET Security Days 2015 | Live the Experience

ESET Security Day London | ESET Security Days 2015 | Live the Experience: The first ESET Security Day of 2015 is taking place in London at Millbank Tower, overlooking the stunning views of the Thames river and Westminster.