“Restlessness and discontent are the first necessities of progress.”

-Thomas A. Edison


Soraya Malware Mixes Capabilities of Zeus and Dexter to Target Payment Card Data http://www.securityweek.com/soraya-malware-mixes-capabilities-zeus-and-dexter-target-payment-card-data

http://www.scmagazine.com/soraya-malware-targets-payment-card-data-on-pos-devices-and-home-computers/article/349880/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints including POS terminals are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Use strong password for terminal log in accounts and change them regularly
  8. Install a local firewall
  9. Restrict access to internet. POS devices should not be allowed to access the internet
  10. Disallow remote access to the point of sales terminals
  11. Encrypt traffic between terminals, servers and payment card processor
  12. Remove local administrative privileges for users who do not need those local privileges
  13. Harden point of sales terminals to only allow services to run that are absolutely necessary to process transactions
  14. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Arbor Networks Security Report on Soraya

http://www.arbornetworks.com/asert/2014/06/the-best-of-both-worlds-soraya/

US-CERT Malware Targeting Point of Sale Systems Advisory

https://www.us-cert.gov/ncas/alerts/TA14-002A

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf


Amex to notify Calif. customers of card dump linked to Anonymous http://www.scmagazine.com/amex-to-notify-calif-customers-of-card-dump-linked-to-anonymous/article/349888/

C-IT Recommendation

  1. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  2. Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
  3. Consult your Risk Management team to see if your company has any cybersecurity insurance.
  4. If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.

Article Resources

American Express’s California Incident Reporting Document

https://oag.ca.gov/system/files/Recovered%20-%20Anonymous-C2014030241%20CA%20AG%20Letter_0.pdf

NetDiligence® 2013 Cyber Liability & Data Breach Insurance Claims: A Study of Actual Claim Payouts

http://www.netdiligence.com/files/CyberClaimsStudy-2013.pdf


Security Vulnerabilities Patched in WordPress SEO Plugin http://www.securityweek.com/security-vulnerabilities-patched-wordpress-seo-plugin

C-IT Recommendation

  1. Consult with your web teams to determine if your organization is using Word Press and the All in One SEO pack for any of its website content hosting. If so, download the current version of the the SEO pack (v.2.1.6)
  2. Ensure your company is using a strong Web Code review process before publishing sites
  3. Use a software code security analysis tool to check your website for potential vulnerabilities
  4. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  5. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Article Resources

Securi Blog on the Word press SEO Plugin

http://blog.sucuri.net/2014/05/vulnerability-found-in-the-all-in-one-seo-pack-wordpress-plugin.html

All in One SEO Pack Plugin Download Details

https://wordpress.org/plugins/all-in-one-seo-pack/