“To see what is right and not do it is a lack of courage.”

–Confucius


Seven vulnerabilities addressed in OpenSSL update, one enables MitM attack http://www.scmagazine.com/seven-vulnerabilities-addressed-in-openssl-update-one-enables-mitm-attack/article/351323/

http://www.securityweek.com/new-mitm-vulnerability-plagues-client-server-versions-openssl

C-IT Recommendation

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
  2. Identify all devices which have the vulnerable versions of OpenSSL both on the workstation and servers
  3. Deploy the OpenSSL updates to test machines in your environment
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted
  6. Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.

Article Resources

OpenSSL Security Advisor

http://www.openssl.org/news/secadv_20140605.txt


Attackers hide in plain sight using data-sharing apps http://www.scmagazine.com/report-attackers-hide-in-plain-sight-using-data-sharing-apps/article/351314/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Palo Alto Networks 2014 Application Usage and Threat Report

https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/white-papers/Application_Usage_Threat_Report_2014.pdf

Microsoft Security Intelligence Report: What is a Botnet?

http://www.microsoft.com/security/sir/story/default.aspx#!botnetsection


How to Integrate Security into Core Business Processes http://www.infosecurity-magazine.com/view/38694/how-to-integrate-security-into-core-business-processes/

Article Resources

Information Security Forum

https://www.securityforum.org/