View Details
“Diligence is the mother of good fortune and idleness, its opposite never brought a man to the goal of any of his best wishes.”
-Miguel De Cervantes
JPMorgan Chase customers targeted in massive phishing campaign
http://www.scmagazine.com/jpmorgan-chase-customers-targeted-in-massive-phishing-campaign/article/367615/
http://www.darkreading.com/jp-morgan-targeted-in-new-phishing-campaign/d/d-id/1306589?
C-IT Recommendation
- Provide social engineering awareness for your customers. Ensure you communicate specifically how your organization will communicate with them. Post your communication policy on your company’s website. Warn them that any other forms of communication should be held in suspicion.
- Ensure your organization has a contact number on your website to reference so customers can validate contact numbers provided in correspondence that appear to come from your organization.
- Establish fraud monitoring services for your customers that baselines his/her account activity and alerts the customers when activity is out of bounds of their normal habits with your organization
Article Resources
Proofpoint’s Analysis of J.P Morgan and Chase Attack
http://www.proofpoint.com/threatinsight/posts/smash-and-grab-jpmorgan.php
View Details
“Out there in some garage is an entrepreneur who’s forging a bullet with your company’s name on it.”
-Gary Hamel
Cybercriminals Deliver Point-of-Sale Malware to 51 UPS Store Locations
http://www.securityweek.com/cybercriminals-deliver-point-sale-malware-51-ups-store-locations
http://www.scmagazine.com/ups-announces-breach-impacting-51-us-locations/article/367257/
C-IT Recommendation
- Create new non-intuitive usernames for POS accounts. Disable the default usernames.
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the POS terminals
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Disallow Remote Access so that attackers cannot remotely access terminals
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
UPS Stores impacted by the breach
http://www.theupsstore.com/security/Pages/default.aspx
US CERT- New Point of Sale Malware
https://www.us-cert.gov/sites/default/files/publications/BackoffPointOfSaleMalware.pdf
US-CERT Alert Malware Targeting Point of Sale Systems
https://www.us-cert.gov/ncas/alerts/TA14-002A
Protecting PoS Environments Against Multi-Stage Attacks
http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf
View Details
Bulk of Ex-Employees Retain Access to Corporate Apps: Survey
http://www.securityweek.com/bulk-ex-employees-retain-access-corporate-apps-survey
http://www.infosecurity-magazine.com/news/uk-smbs-manage-exemployee-risk/
C-IT Recommendation
- Verify your company has an effective and enforced access control standard and policy which requires that access be removed when an employee transfers within the organization or leaves the organization.
- Use Role based Access Control. Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
- Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
- ex: Database Administrator should not have the rights of the Operating System Administrator
- Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.
Article Resources
Intermedia Report on Rogue Access
http://www.multivu.com/players/English/7281751-intermedia-s-2014-smb-rogue-access-study-security-threat-posted-by-former-employees/
Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)
http://csrc.nist.gov/groups/SNS/rbac/
View Details
“It is not the strongest of the species that survive, nor the most intelligent, but the one most responsive to change.”
– Charles Darwin
Windows tech support scammers take root in the U.S.
http://www.csoonline.com/article/2464030/security-leadership/windows-tech-support-scammers-take-root-in-the-u-s.html
Article Resources
Malwarebytes blog on the scare tactic
https://blog.malwarebytes.org/fraud-scam/2014/08/beware-of-us-based-tech-support-scams/
2014 So Far: The Year of the Data Breach
http://www.infosecurity-magazine.com/news/2014-the-year-of-the-data-breach/
C-IT Recommendation
- Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
- Ensures your organization has a plan for Information Security
- Provides direction for developing information security policies, procedures, standards and guidelines
- Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
Article Resources
Trend Micro Security Report
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/reports/rpt-turning-the-tables-on-cyber-attacks.pdf
NIST Cyber Security Framework
http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
ISO\IEC 27001 Framework
http://www.iso.org/iso/catalogue_detail?csnumber=54534
ISACA COBIT
http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR
Microsoft to End Support for Old Versions of Internet Explorer
http://www.securityweek.com/microsoft-end-support-old-versions-internet-explorer
Microsoft’s Internet Explorer Support Information
http://blogs.msdn.com/b/ie/archive/2014/08/07/stay-up-to-date-with-internet-explorer.aspx
View Details
“It doesn’t take great men to do things, but it is doing things that make men great.”
-Arnold Glasow
PCI Council Publishes Guidance on Working With Third-party Providers
http://www.securityweek.com/pci-council-publishes-guidance-working-third-party-providers
http://www.scmagazine.com/pci-council-releases-third-party-security-assurance-guidance/article/365658/
C-IT Recommendation
- Require your third party service provider to provide a report of compliance and require the entity to conform to conducting a risk analysis
- Ensure your legal department has a strong SLA and breach accountability agreement with the service provider in case critical company or customer data is compromised.
- Read the PCI-DSS Third-Party Security Assurance Special Interest Group PCI Security Standards Council
Article Resources
PCI-DSS Third-Party Security Assurance Special Interest Group PCI Security Standards Council Document
https://www.pcisecuritystandards.org/documents/PCI_DSS_V3.0_Third_Party_Security_Assurance.pdf
Click Fraud Malware Found Lurking Inside Image Files
http://www.infosecurity-magazine.com/news/click-fraud-malware-inside-images/
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
Dell SecureWorks Malware Analysis of the Lurk Downloader
http://www.secureworks.com/cyber-threat-intelligence/threats/malware-analysis-of-the-lurk-downloader/
August Patch Tuesday Addresses Critical IE Flaw
http://www.infosecurity-magazine.com/news/august-patch-critical-ie-flaw/
http://www.informationweek.com/software/operating-systems/microsoft-to-patch-2-critical-bugs/d/d-id/1297920
C-IT Recommendation
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
Article Resources
Microsoft Security Bulletin Advance Notification for August 2014
https://technet.microsoft.com/library/security/ms14-aug
View Details
“Great men undertake great things because they are great; fools, because they think them easy.”
-Luc de Vauvenargues
Hackers Demand Automakers Get Serious About Security
http://www.securityweek.com/hackers-demand-automakers-get-serious-about-security
http://www.darkreading.com/application-security/automakers-openly-challenged-to-bake-in-security/d/d-id/1297902
C-IT Recommendation
- Find out if your organization has Security embedded into the Product Development Life Cycle. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
- Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
- Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
- Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.
Article Resources
Letter to Automotive Company Executive Leadership
https://www.iamthecavalry.org/wp-content/uploads/2014/08/IATC-Open-letter-to-the-Automotive-Industry.pdf
Five Star Automotive Cyber Safety Program
https://www.iamthecavalry.org/domains/automotive/5star/
MP3 of Two Researches Who Hacked Modern Vehicles
http://www.securityweek.com/podcast-car-hacking-charlie-miller-and-chris-valasek
Microsoft Updated Cybersecurity Papers on Supply Chain Security and Critical Infrastructure Protection
http://blogs.technet.com/b/security/archive/2014/05/06/revised-cybersecurity-papers-on-supply-chain-security-and-critical-infrastructure-protection.aspx
Thousands of U.S. Devices Infected With New Gameover Zeus Variant: Report
http://www.securityweek.com/thousands-us-devices-infected-new-gameover-zeus-variant-report
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all computers running Windows XP Operating system.
- Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
US-CERT GameOver Zeus P2P Malware Alert
https://www.us-cert.gov/ncas/alerts/TA14-150A
Critical Vulnerability Found in Popular WordPress Contact Form Plugin
http://www.securityweek.com/critical-vulnerability-found-popular-wordpress-contact-form-plugin
http://www.infosecurity-magazine.com/news/wordpress-vulnerability-affects/
C-IT Recommendation
- Maintain a configuration management database of all software and add ons in your organization.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
Article Resources
Custom Contact Forms Download to latest version
https://wordpress.org/plugins/custom-contact-forms/
View Details
“The purpose of business is to create and keep a customer.”
― Peter F. Drucker
Over 90% of Enterprises Exposed to Man-in-the-Browser Attacks: Cisco
http://www.securityweek.com/over-90-enterprises-exposed-man-browser-attacks-cisco
http://www.csoonline.com/article/2459954/data-protection/cisco-patches-traffic-snooping-flaw-in-operating-systems-used-by-networking-gear.html
C-IT Recommendation
- Perform regular security assessments in your organization
- Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
- Material to be covered
- Current Risks (including potential severity and probability)
- Emerging Risks (including potential severity and probability)
- Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
- Monitoring Progress of Risk Handling
- Use Out-of-band transaction detail confirmation, followed by one-time-passcode generation: this technique leverages devices such as mobile phones that are already being carried by the intended end-users, and enables review of transaction details outside the influence of malware on the user’s PC.
- Fraud detection technology that monitors user behavior: this server-side monitoring of a user’s movement through a banking Web site, inclusive of transaction execution steps as well as the steps leading there, provides flexibility for financial institutions to adapt to constantly evolving malware features, and detect suspicious patterns of activity for immediate intervention. SafeNet eToken/Mobile Pass, ThreatMatrix
Article Resources
Cisco’s Midyear Security Report
http://www.cisco.com/web/offer/grs/190720/SecurityReport_Cisco_v4.pdf
Entrust WhitePaper on Preventing Man in the Browser Attacks
http://www.bankinfosecurity.com/whitepapers/defeating-man-in-the-browser-how-to-prevent-latest-malware-attacks-w-315#dynamic-popup
Reported Theft of 1.2B Email Accounts
http://krebsonsecurity.com/2014/08/qa-on-the-reported-theft-of-1-2b-email-accounts/
http://www.holdsecurity.com/news/cybervor-breach/
C-IT Recommendation
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved.
- Ensure your organization has a password policy that requires privileged accounts to differ between various including not utilizing the same passwords on multiple systems.
- Ensure your password policy require complex passwords and that systems are configured to enforce the requirement. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords for privileged accounts consecutively after the passwords expire.
Article Resources
The Value of a Hacked Email Account
http://krebsonsecurity.com/2013/06/the-value-of-a-hacked-email-account/
View Details
“Genius is one percent inspiration and ninety–nine percent perspiration.”
– Thomas A. Edison
Android malware SandroRAT disguised as mobile security app
http://www.scmagazine.com/android-malware-sandrorat-disguised-as-mobile-security-app/article/364455/
Article Resources
McAfee Blog Post
http://blogs.mcafee.com/mcafee-labs/sandrorat-android-rat-targeting-polish-banking-users-via-e-mail-phishing
Emory Libraries Information Security Awareness covering Phishing
http://it.emory.edu/security/security_awareness/phishing.html
Most Top Free and Paid Mobile Apps Pose Threat to Enterprises: Report
https://www.securityweek.com/most-top-free-and-paid-mobile-apps-pose-threat-enterprises-report
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit malicious sites. Also, instruct employees not to apps from unofficial stores.
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
Appthority App Reputation Report
https://www.appthority.com/app-reputation-report/report/AppReputationReportSummer14.pdf
US CERT Security Tip Cybersecurity for Electronic Devices
https://www.us-cert.gov/ncas/tips/ST05-017
View Details
“If you work just for money, you’ll never make it, but if you love what you’re doing and you always put the customer first, success will be yours.”
– Ray Kroc
C-Level Execs to CISOs: No Seat for You!
https://www.securityweek.com/c-level-execs-cisos-no-seat-you
http://www.scmagazine.com/study-ciso-leadership-capacity-undervalued-by-most-c-level-execs/article/364231/
C-IT Recommendation
- Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
- Material to be covered
- Current Risks (including potential severity and probability)
- Emerging Risks (including potential severity and probability)
- Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
- Monitoring Progress of Risk Handling
Article Resources
Threat Track “Chief Information Security Officers Misunderstood and Underappreciated by Their C-Level Peers” Report
http://media.scmagazine.com/documents/89/threattrack_study_on_cisos_22034.pdf
PittyTiger spearphishing campaign speaks multiple languages
http://www.scmagazine.com/pittytiger-spearphishing-campaign-speaks-multiple-languages/article/363978/
https://www.securityweek.com/pitty-tiger-threat-actors-possibly-active-2008-fireeye
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
Airbus Defense & Space Pitty Tiger Report
https://bbuseruploads.s3.amazonaws.com/cybertools/whitepapers/downloads/Pitty%20Tiger%20Final%20Report.pdf?Signature=DFJkN2347ctUHMcTesVVtd6Dcto%3D&Expires=1407137473&AWSAccessKeyId=0EMWEFSGA12Z1HF1TZ82
FireEye Blog Detailing Pitty Tiger
http://www.fireeye.com/blog/technical/threat-intelligence/2014/07/spy-of-the-tiger.html
Emory Libraries Informationh Security Awareness covering Phishing
http://it.emory.edu/security/security_awareness/phishing.html
Hackers Turn Remote Desktop Tools Into Gateways for Point-of-Sale Malware Attacks
https://www.securityweek.com/hackers-turn-remote-desktop-tools-gateways-point-sale-malware-attacks
http://www.darkreading.com/attacks-breaches/backoff-malware-time-to-step-up-remote-access-security/a/d-id/1297731?
http://searchsecurity.techtarget.com/news/2240226048/US-government-warns-of-point-of-sale-malware-campaign
C-IT Recommendation
- Create new non-intuitive usernames for POS accounts. Disable the default usernames.
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the POS terminals
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Disallow Remote Access so that attackers cannot remotely access terminals
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
US Department of Homeland Security Report on New Point of Sale Malware
http://www.us-cert.gov/sites/default/files/publications/BackoffPointOfSaleMalware.pdf
Protecting PoS Environments Against Multi-Stage Attacks
http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf
View Details
“Opportunity is missed by most people because it is dressed in overalls and looks like work.”
– Thomas Edison
Vulnerability impacting multiple versions of Android could enable device takeover
http://www.scmagazine.com/vulnerability-impacting-multiple-versions-of-android-could-enable-device-takeover/article/363414/
http://www.securityweek.com/android-fake-id-vulnerability-lets-malicious-apps-impersonate-trusted-apps
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit malicious sites . Also, instruct employees not to apps from unofficial stores.
Article Resources
MP3 discussing FakeID Vulnerability
http://www.buzzsprout.com/9743/192579-bluebox-labs-explains-android-fake-id-vulnerability.mp3?client_source=small_player
Bluebox Security write up on the Android FakeID Weakness
http://bluebox.com/technical/android-fake-id-vulnerability/
Bluebox Security Scanner
https://play.google.com/store/apps/details?id=com.bluebox.labs.onerootscanner&hl=en
HP tests 10 popular IoT devices, most raise privacyconcerns
http://www.scmagazine.com/hp-tests-10-popular-iot-devices-most-raise-privacy-concerns/article/363426/
http://www.securityweek.com/70-iot-devices-vulnerable-cyberattacks-hp
HPs Recommendation
- Conduct a security review of your device and all associated components.
- Implement security standards that all devices must meet before production.
- Ensure security is a consideration throughout the product lifecycle.
Article Resources
HP Study Report
http://fortifyprotect.com/HP_IoT_Research_Study.pdf
Using Instagram on public Wi-Fi poses risk of an account hijack, researcher says
http://www.csoonline.com/article/2458952/data-protection/using-instagram-on-public-wi-fi-poses-risk-of-an-account-hijack-researcher-says.html
C-IT Recommendation
- Refrain from connecting apple mobile devices to public wifi networks especially if there are no passwords to login to the networks.
Article Resources
Stevie Graham’s Twitter Post
https://twitter.com/stevegraham/status/493465799542468608
Instagram Co-founders Response to the hack
https://news.ycombinator.com/item?id=8099796
View Details
“The golden rule for every business man is this: Put yourself in your customer’s place.”
Orison Swett Marden
Cybercriminals Abuse Amazon Cloud to Host Linux DDoS Trojans
http://www.securityweek.com/cybercriminals-abuse-amazon-cloud-host-linux-ddos-trojans
C-IT Recommendation
- Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
- Not having have total control
- Having your data protected by someone else
- Having your security managed by someone else
- Not having information about the cloud provider’s infrastructure
- As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
- Consider deploying technology in your organization that blocks DDoS attacks
Article Resources
Securelist blog about the Amazon attacks
https://securelist.com/blog/virus-watch/65192/elasticsearch-vuln-abuse-on-amazon-cloud-and-more-for-ddos-and-profit/
Gartner Application Delivery Controller Ratings
http://www.gartner.com/technology/reprints.do?id=1-1MCUHF2&ct=131030&st=sb
Companies accused of peddling bogus AV ordered to pay $5.1M
http://www.scmagazine.com/companies-accused-of-peddling-bogus-av-ordered-to-pay-51m/article/363212/
Companies Providing Bogus Antivirus:
Pecon Software Ltd. et al;
Marczak et al.;
PCCare247 Inc. et al.;
Finmaestros, LLC et al.;
Lakshmi Infosoul Serivces Pvt. Ltd. et al.; and
Zeal IT Solutions Pvt. Ltd. et al.
C-IT Recommendation
- Purchase credible security solutions from credible companies. Do not take the shortcuts.
Article Resources
Federal Trade Commission article and links to court documentation
http://www.ftc.gov/news-events/press-releases/2014/07/federal-court-orders-tech-support-scammers-pay-more-51-million
EFF asks court to find NSA internet spying a violation of Fourth Amendment
http://www.scmagazine.com/eff-asks-court-to-find-nsa-internet-spying-a-violation-of-fourth-amendment/article/363218/
Article Resources
EFF court filing requesting declaration of violation of Fourth Amendment
https://www.eff.org/files/2014/07/25/jewel_4th_a_mpsj_brief.pdf
View Details
“My own business always bores me to death; I prefer other people’s.”
―Oscar Wilde
WordPress Plugin Vulnerability Exploited to Compromise Thousands of Websites
https://www.securityweek.com/wordpress-plugin-vulnerability-exploited-compromise-thousands-websites
http://www.csoonline.com/article/2457668/data-protection/thousands-of-sites-compromised-through-wordpress-plug-in-vulnerability.html
C-IT Recommendation
From the Website Perspective
- Ensure your organization has a strong asset inventory with an accurate configuration management database.
- Identify if any of your websites are using WordPress and the MailPoet plugin.
- If so, backup the MailPoet configuration and update to at least version 2.6.8.
- Ensure your company is using a strong Web Code review process before publishing sites.
- Use a software code security analysis tool to check your website for potential vulnerabilities.
Article Resources
Securi’s Blogposting of MailPoet’s Weaknesses
http://blog.sucuri.net/2014/07/mailpoet-vulnerability-exploited-in-the-wild-breaking-thousands-of-wordpress-sites.html
MailPoet’s support documenation regarding its security weakness
http://support.mailpoet.com/knowledgebase/site-hacked-what-to-do/
Survey: 53 percent change privileged logins quarterly
http://www.scmagazine.com/survey-53-percent-change-privileged-logins-quarterly/article/362958/
C-IT Recommendation
- Ensure your organization has a password policy that requires privileged accounts to differ between various including not utilizing the same passwords on multiple systems.
- Ensure your password policy require complex passwords and that systems are configured to enforce the requirement. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords for privileged accounts consecutively after the passwords expire.
Article Resources
Lieberman 2014 Survey of Information Security Professionals
http://media.scmagazine.com/documents/88/liberman_survey_21915.pdf
View Details
“Good executives never put off until tomorrow what they can get someone else to do today.”
-Anonymous
eBay faces class-action suit over breach
http://www.scmagazine.com/ebay-faces-class-action-suit-over-breach/article/362670/
http://www.csoonline.com/article/2457981/data-protection/ebay-faces-class-action-suit-over-data-breach.html
Article Resources
Ebay’s publication of Breach
http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords
The Courtroom Paperwork for the Lawsuit
http://media.scmagazine.com/documents/88/ebaysuit_21893.pdf
Sony to shell out $15M in PSN breach settlement
http://www.scmagazine.com/sony-to-shell-out-15m-in-psn-breach-settlement/article/362720/
Article Resources
Original Court Filings
http://media.scmagazine.com/documents/88/sony_settlement-1_21903.pdf
Settlement Court Documents
http://www.scribd.com/doc/234917930/Sony-agrees-to-15M-settlement
C-IT Recommendation
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
- Ensure your organization has an incident response plan in the case of a data breach
- Incident Response Team
- Public Relations Strategy
- Legal Team
- Consult your Risk Management team to see if your company has any cybersecurity insurance.
- If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.
View Details
“The two basic processes of education are knowing and valuing.”
-Robert J. Havighurst
StubHub Hit in Cyber-Attack That May Have Stolen $10M in Tickets
http://www.securityweek.com/stubhub-hit-cyber-attack-may-have-stolen-10m-tickets
http://www.scmagazine.com/six-charged-in-global-stubhub-scheme-company-defrauded-out-of-1-million/article/362482/
C-IT Recommendation
- Ensure your organization has a security awareness program that educates users on basic security practices including not utilizing the same passwords on multiple systems.
- Ensure your systems require complex passwords. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords consecutively after the passwords expire.
- Consider using a password management program to allow users to store credentials for various accounts in a centralized repository. Encourage users to utilize a very strong password to authenticate to the password manager.
Article Resources
Krebs on Security Article
http://krebsonsecurity.com/2014/07/feds-hackers-ran-concert-ticket-racket/#more-27031
Microsoft Report: Sustainably Managing Large Numbers of Accounts
http://research.microsoft.com/pubs/217510/passwordPortfolios.pdf
InfoSec pros worried BYOD ushers in security exploits, survey says
http://www.scmagazine.com/infosec-pros-worried-byod-ushers-in-security-exploits-survey-says/article/362484/
http://www.darkreading.com/cloud/infographic-with-byod-mobile-is-the-new-desktop/a/d-id/1297436?
C-IT Recommendation
- Ensure your organization has a clear and concise mobile device policies to ensure proper use of personal phones while accessing corporate resources.
-
Procure and deploy a mobile device management solution, with the following capabilities:
-
Webfiltering option which forces the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Anti-malware for mobile devices
- If possible, device segmentation that restricts non-business applications from accessing business apps.
- Segmentation of business data and applications from
Provide mobile device security awareness informing your employees not to visit malicious websites. Also, instruct employees not to apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money.
Article Resources
Vectra BYOD & Mobile Security Report
http://vectranetworks.hs-sites.com/byod-and-mobile-security-report-payoff?submissionGuid=ef654d16-1ce2-4a6c-ae65-7c2424b76d5f
View Details
“Every man, however wise, needs the advice of some sagacious friend in the affairs of life.”
-Plautus
Quarter of UK Shoppers Don’t Trust Retailers on Card Fraud
http://www.infosecurity-magazine.com/view/39417/quarter-of-uk-shoppers-dont-trust-retailers-on-card-fraud/
C-IT Recommendation
- Pay attention to the news regarding data breach.
- Communicate your security efforts to your customer base
- Provide customer awareness and communicate the importance of the customer taking steps to combat card fraud because the largest segments of consumers interviewed did not recall having received any info from their financial institutions about how to protect themselves against fraud.
Article Resources
2014 Global Consumer Fraud Survey
http://www.aciworldwide.com/2014fraudsurvey.aspx
ACI Webinar on Global Consumer Fraud
http://bcove.me/xvc5e0a5
Vice.com hacked, possibly The Wall Street Journal website too
http://www.scmagazine.com/vicecom-hacked-possibly-the-wall-street-journal-website-too/article/362087/
C-IT Recommendation
- Ensure your domain hosting sites have strong secure passwords.
- Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
- Ensure your login services have a login attempt limit and locks out accounts after a certain amount of bad attempts.
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
Article Resources
w0rm’s twitter posts revealing hacks
https://twitter.com/rev_priv8
Goodwill Industries investigates suspected payment card breach
http://www.csoonline.com/article/2456605/data-protection/goodwill-industries-investigates-suspected-payment-card-breach.html
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your organization has an incident response plan in the case of a data breach
- Incident Response Team
- Public Relations Strategy
- Legal Team
- Possibly Data Breach Insurance
Article Resources
Krebs on Security Article
http://krebsonsecurity.com/2014/07/banks-card-breach-at-goodwill-industries/
CNN Money Article
http://money.cnn.com/2014/07/22/news/companies/goodwill-security-credit-card/
View Details
“He that will not reason is a bigot; he that cannot reason is a fool; and he that dares not reason is a slave.”
-Sir William Drummond
Password Misuse is Rampant at US Businesses
http://www.infosecurity-magazine.com/view/39408/password-misuse-is-rampant-at-us-businesses/
C-IT Recommendation
- Ensure your organization has a security awareness program that educates users on basic security practices including not utilizing the same passwords on multiple systems
- Ensure your systems require complex passwords. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords consecutively after the passwords expire.
- Consider using a password management program to allow users to store credentials for various accounts in a centralized repository. Encourage users to utilize a very strong password to authenticate to the password manager
Article Resources
US CERT Security Tip Choosing and Protecting Passwords
https://www.us-cert.gov/ncas/tips/ST04-002
Fake Air Force One Crash Messages Posted on Hacked WSJ Facebook Page
http://www.securityweek.com/fake-air-force-one-crash-messages-posted-hacked-wsj-facebook-page
C-IT Recommendation
- Ensure your domain hosting sites have strong secure passwords
- Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
- Ensure your login services have a login attempt limit and locks out accounts after a certain amount of bad attempts.
Article Resources
US CERT White Paper : Using Social Networking Services Securely
http://www.us-cert.gov/sites/default/files/publications/safe_social_networking.pdf
Researcher finds backdoors in Apple iOS
http://www.csoonline.com/article/2455975/data-protection/researcher-finds-backdoors-in-apple-ios.html
Article Resources
Jonathan Zdziarski blog
http://www.zdziarski.com/blog/
Identifying back doors, attack points, and surveillance mechanisms in iOS devices Post in Science Direct
http://www.sciencedirect.com/science/article/pii/S1742287614000036
View Details
“The successful man is the one who finds out what is the matter with his business before his competitors do.”
–Roy L. Smith
31 percent of IT security teams don’t speak to company execs
http://www.scmagazine.com/report-31-percent-of-it-security-teams-dont-speak-to-company-execs/article/361263/
C-IT Recommendation
- Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
- Material to be covered
- Current Risks (including potential severity and probability)
- Emerging Risks (including potential severity and probability)
- Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
- Monitoring Progress of Risk Handling
- Develop a security awareness and education program which requires employees to attend some form of training. Reinforce training with periodic awareness campaigns to remind users of their role in protecting the organization.
Article Resources
Websense/Ponemon Institute Roadblocks, Refresh, & Raising the Human Security IQ Report
http://www.websense.com/content/2014-ponemon-report-part-2.aspx?cmpid=prnr7.17.14
Privileged Accounts at Root of Most Data Breaches
http://www.infosecurity-magazine.com/view/39366/privileged-accounts-at-root-of-most-data-breaches/
C-IT Recommendation
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
The Role of Privileged Accounts in High Profile Breaches
http://cyberark.com/contact/role-privileged-accounts-high-profile-breaches#.U8gbyvldWSo
View Details
“We generate fears while we sit. We over come them by action. Fear is natures way of warning us to get busy.”
-Dr. HenryLink
Amazon Web Services Increasingly Used to Host Malware
http://www.securityweek.com/amazon-web-services-increasingly-used-host-malware-report
C-IT Recommendation
- Perform an information security risk assessment to see if the partnering organization handles risk in accordance with your company’s risk appetite.
- Ensure your organization’s legal team has a Service Level Agreement with the partnering organization that specifies tolerance for security incidents and clearly define responsibility and accountability in a data breach.
Article Resources
Solutionary Second Quarter 2014 Threat Intelligence Report
http://www.solutionary.com/_assets/pdf/research/sert-q2-2014-threat-intelligence.pdf
Endpoints Are Woefully Insecure, But There’s No Budget to Fix It
http://www.infosecurity-magazine.com/view/39346/endpoints-are-woefully-insecure-but-theres-no-budget-to-fix-it/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all computers running Windows XP Operating system.
- Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to
Article Resources
Promisec Survey
http://www.promisec.com/?attachment_id=6416
View Details
“Even if you are on the right track, You’ll get run over if you just sit there.”
– Will Rogers
Active Directory flaw opens enterprise services to unauthorized access
http://www.scmagazine.com/active-directory-flaw-opens-enterprise-services-to-unauthorized-access/article/361017/
http://www.securityweek.com/active-directory-vulnerability-puts-enterprise-services-risk
http://www.darkreading.com/active-directory-flaw-lets-attackers-change-passwords/d/d-id/1297298?
http://www.csoonline.com/article/2454367/identity-access/why-the-microsoft-active-directory-design-flaw-isnt-serious.html
Aorato Mitigation Techniques
- Detecting authentication protocol anomalies. For instance, the use of a non-default encryption algorithm.
- Identifying the attack by correlating the abnormal use of encryption methods with the context in which the victim’s identity is used (e.g. unusual services accessed, unusual time of day, day of week, etc.).
- Applying measures to reduce the attack surface. Note that these measures only reduce the attack surface and do not eliminate it altogether or solve the root cause:
- Limiting the attacker’s opportunities to steal the NTLM hash in the first place. This is detailed in Microsoft document “Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques”. However, it is important to note that this provides only partial mitigation as detailed in our blog post “Windows Update to Fix Pass-the-Hash Vulnerability? Not!”.
- Ensuring that Windows-based computers in the enterprise are updated with the kb2871997 patch, in which several protections had been introduced to make it harder for the attacker to steal the NTLM hashes.
- If using Windows Server 2012 R2 Domain Functional Level (DFL) domains, add privileged users as members of the newly added Protected Users group. This will disable RC4-HMAC usage in Kerberos for these users. Note that this measure is suitable only for privileged users since the Protected Users group imposes many other restrictions on its members.
Microsoft’s Recommendation
- Use a smart card authentication and second,
- Remove the weaker encryption (i.e. RC4-HMAC) from the systems.
Article Resources
Aorato Blog Detailing Microsoft Weakness
http://www.aorato.com/blog/active-directory-vulnerability-disclosure-weak-encryption-enables-attacker-change-victims-password-without-logged/
Microsoft in Talks to Buy Israeli Cybersecurity Firm Aorato
http://online.wsj.com/articles/microsoft-in-talks-to-buy-israeli-cybersecurity-firm-aorato-1405430773
77 percent of IT staffers have incorrectly reported the cause of a security incident
http://www.scmagazine.com/survey-77-percent-of-it-staffers-have-incorrectly-reported-the-cause-of-a-security-incident/article/360993/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your organization has an incident response plan in the case of a data breach
- Incident Response Team
- Public Relations Strategy
- Legal Team
- Possibly Data Breach Insurance
Article Resources
2014 Emulex Visibility Survey
http://www.emulex.com/media-center/media-center-home/press-releases/story/?tx_news_pi1[news]=566&cHash=b9dbbcbde3fe8791bfe1e26610b2c3df
Oracle releases 113 bug fixes in Critical Patch Update
http://www.scmagazine.com/oracle-releases-113-bug-fixes-in-critical-patch-update/article/361039/
http://www.securityweek.com/security-updates-java-7-will-work-windows-xp-oracle
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Oracle support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all systems running Oracle components .
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
View Details
“You are not your resume, you are your work.”
– Seth Godin
Chinese man charged with hack of Boeing, Lockheed Martin aircraft data
http://www.scmagazine.com/chinese-man-charged-with-hack-of-boeing-lockheed-martin-aircraft-data/article/360786/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
The CBC News Article Containing the US District Court Complaint
http://www.cbc.ca/news/canada/british-columbia/su-bin-chinese-man-accused-by-fbi-of-hacking-in-custody-in-b-c-1.2705169
USTR Special 301 Report
http://www.ustr.gov/sites/default/files/USTR%202014%20Special%20301%20Report%20to%20Congress%20FINAL.pdf
2012 Network Computing Top Eight SIEM Vendors
http://www.networkcomputing.com/careers-and-certifications/how-the-top-eight-siem-vendors-stack-up/d/d-id/1233787?
C-IT Security Podcast May 1st
http://www.c-itsecurity.com/?p=42
DropCam Vulnerable To Hijacking
http://www.darkreading.com/dropcam-vulnerable-to-hijacking/d/d-id/1297275?
Researchers at the 2014 DEF CON conference will provide a demonstration of taking over a DropCam video surveillance system in a popular WiFi video monitoring system.
DropCam is a web based video monitoring system homes, daycares, and small businesses to provide both live monitoring and cloude based recording for customers of the product.
The weaknesses in the video surveillance system could allow an attacker to view video and listen to audio from cameras connected to the system to spy on the targets. The system also has a vulnerability that enables attackers to inject their own video frames into the DropCam feed or freeze frames in order to hide malicious activity, such as a physical break-in.
The DropCam vulnerabilities are yet another example of the inherent risks of IP-based consumer devices, a.k.a. the Internet of Things. The security industry is increasingly concerned about flaws in embedded software in devices like these web cameras because many of these which run older software that may not even receive updates.
C-IT Recommendation
From the Customer Perspective
- Ensure your company has a test environment to introduce all new tools/devices and that security is involved in performing an assessment of the new acquisitions.
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
From the Supplier Perspective
- Find out if your Information Technology organization has Security embedded into the Software Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
- Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
- Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
- Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.
Article Resources
About DEF CON
https://www.defcon.org/html/links/dc-faq/dc-faq.html
About Dropcam
https://www.dropcam.com/small-business-security
Toward a Trusted Supply Chain: A Risk Based Approach to Managing Software Integrity White Paper
http://download.microsoft.com/download/9/B/D/9BD9FBFF-A1D9-4DA9-954C-EAE9242C689D/Toward%20a%20Trusted%20Supply%20Chain%20white%20paper.pdf
Critical Infrastructure Protection: Concepts and Continuum White Paper
http://download.microsoft.com/download/4/6/8/4688D909-116C-480A-A398-703B30C7D7B3/CIP-continuum.pdf
Kronos: New Financial Malware Sold on Russian Underground Forum
http://www.securityweek.com/kronos-new-financial-malware-sold-russian-underground-forum
http://www.csoonline.com/article/2453634/data-protection/new-banking-malware-kronos-advertised-on-underground-forums.html
http://www.scmagazine.com/fraudsters-market-new-malware-kronos-on-underground/article/360779/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
View Details
“ Progress comes from the intelligent use of experience. ”
— Elbert Hubbard
Hotel Business Centers Fall Victim to Key Logger Malware
http://krebsonsecurity.com/2014/07/beware-keyloggers-at-hotel-business-centers/
Government recommendations
- Display a banner to users when logging onto business center computers; this should include warnings that highlight the risks of using publicly accessible machines.
- Create individual, unique log on credentials for access to both business center computers and Wi-Fi; this may deter individuals who are not guests from logging in.
- Give all accounts least privilege accesses; for example, guests logging in with the supplied user ID and password should not be able to download, install, uninstall or save files whereas one authorized employee may have a need for those privileges to carry out daily duties.
- Create virtual local area networks (VLANs) for all users, which will inhibit attackers from using their computer to imitate the hotel’s main server.
- Scan all new devices (e.g. USB drives and other removable media) before they are attached to the computer and network; disabling the auto run feature will also prevent removable media from opening automatically.
- Establish pre-determined time limits for active and non-active guest and employee sessions.
- Select safe defaults in the browsers available on the business center desktops (e.g. Internet Explorer, Mozilla Firefox). Options such as private browsing and “do not track” for passwords and websites are some of the many available.
Article Resources
http://www.dhs.gov/about-national-cybersecurity-communications-integration-center
AAHOA Lodging Business Article
http://www.aahoalodging.biz/industry-news/Feds+Issue+Advisory+on+Malware+in+Hotel+Biz+Centers/524
Security not prioritized in critical infrastructure, though most admit compromise
http://www.scmagazine.com/study-security-not-prioritized-in-critical-infrastructure-though-most-admit-compromise/article/360538/
C-IT Recommendation
- If your organization business includes power plants, oil or gas refineries, telecommunications facilities, transportation, or water and waste control, it will most likely be using SCADA equipment. If not consult with your HVAC, telecom and facilities department and perform an asset inventory of your SCADA equipment. CMDB should include product manufacturers.
- Ensure your company has policies and procedures to maintain the asset inventory to include all scada systems and each piece of industrial equipment controlled by the scada technology
- Disable the Web Service. Disabling the HTTPS service and still maintaining manageability on the device can be accomplished in a number of ways. Manage the device through a command line service like SSH, or use a Device Cloud account to centrally manage all the devices. Further, if HTTPS service is enabled and on a public IP on the Internet, restrict or disable the HTTPS web interface to specific IPs.
- Check Services.
- Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
- Remove, disable or rename any default system accounts wherever possible.
- Implement account lockout policies to reduce the risk from brute forcing attempts.
- Establish and implement policies requiring the use of strong passwords.
- Monitor the creation of administrator level accounts by third-party vendors.
- Apply patches in the ICS environment, when possible, to mitigate known vulnerabilities.
Article Resources
Critical Infrastructure: Security Preparedness and Maturity Report
http://www.unisys.com/unisys/inc/pdf/misc/14-0316.pdf
Cyber Information Sharing Act Draws Uncertainty and Criticism
http://www.infosecurity-magazine.com/view/39259/cyber-information-sharing-act-draws-uncertainty-and-criticism/
Article Resources
Draft of the Cyber Information Sharing Act
http://www.feinstein.senate.gov/public/index.cfm/files/serve/?File_id=08de1c1b-446b-478c-84a8-0c3f35963216
Senator Mark Udall’s Opposition to the Bill
http://www.markudall.senate.gov/?p=press_release&id=4370
View Details
“The best executive is the one who has sense enough to pick good men to do what he wants done, and self-restraint enough to keep from meddling with them while they do it.”
-Theodore Roosevelt
Hackers Attack Shipping and Logistics Firms Using Malware-Laden Handheld Scanners
http://www.securityweek.com/hackers-attack-shipping-and-logistics-firms-using-malware-laden-handheld-scanners
C-IT Security Recommendation
From the product development perspective
- Find out if your Information Technology organization has Security embedded into the Product Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
- Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
- Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
- Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individual’s who have vetted the change and identified the risks associated with the changes to be acceptable.
From the product purchaser perspective
- Ensure your company has a test environment to introduce all new tools/devices and that security is involved in performing an assessment of the new acquisitions.
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
Article Resources
TrapX Anatomy of the Attack:Zombie Zero
http://www.trapx.com/wp-content/uploads/2014/07/TrapX_ZOMBIE_Report_Final.pdf
Toward a Trusted Supply Chain: A Risk Based Approach to Managing Software Integrity White Paper
http://download.microsoft.com/download/9/B/D/9BD9FBFF-A1D9-4DA9-954C-EAE9242C689D/Toward%20a%20Trusted%20Supply%20Chain%20white%20paper.pdf
Critical Infrastructure Protection: Concepts and Continuum White Paper
http://download.microsoft.com/download/4/6/8/4688D909-116C-480A-A398-703B30C7D7B3/CIP-continuum.pdf
Cybersecurity Review Should Be a Core Part of M&A Deals
http://www.infosecurity-magazine.com/view/39238/cybersecurity-review-should-be-a-core-part-of-ma-deals/
http://www.businesstimes.com.sg/premium/top-stories/cyber-risk-complacency-could-doom-ma-deals-study-20140710
C-IT Recommendation
- Perform an information security risk assessment to see if the partnering organization handles risk in accordance with your company’s risk appetite.
Gmail iOS app vulnerable to MitM attack, emails and credentials at risk
http://www.scmagazine.com/gmail-ios-app-vulnerable-to-mitm-attack-emails-and-credentials-at-risk/article/360346/
http://www.securityweek.com/google-gmail-app-ios-doesnt-perform-certificate-pinning-researchers
Lacoon Mobile Security Recommendations
- Check the configuration profiles of devices in your enterprise to ensure that they do not include root certificates.
- Ensure that employees use a VPN or any other secure channel when connecting to enterprise resources.
- Perform on-device and network analysis to detect MitM attempts.
C-IT Recommendation
- Encourage your end users through your information security policy not to send company email to and from personal email counts.
Article Resources
Lacoon Mobile Security Security Disclosure: Google’s iOS Gmail App Potential Target for Threat Actors
http://www.lacoon.com/blog/2014/07/security-disclosure-googles-ios-gmail-app-enables-threat-actor/
View Details
“Hopeless cases: Executives who assert themselves by saying No when they should say Yes.”
-Malcolm Forbes
Attackers brute-force POS systems utilizing RDP in global botnet operation
http://www.scmagazine.com/attackers-brute-force-pos-systems-utilizing-rdp-in-global-botnet-operation/article/360156/
http://www.securityweek.com/brutpos-botnet-targets-pos-systems-brute-force-attacks
http://www.csoonline.com/article/2451773/data-protection/botnet-brute-forces-remote-access-to-point-of-sale-systems.html
C-IT Recommendation
- Create new non-intuitive usernames for POS accounts. Disable the default usernames.
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the POS terminals
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Disallow Remote Access so that attackers cannot remotely access terminals
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
FireEye Blog Post Detailing BrutPOS
http://www.fireeye.com/blog/technical/botnet-activities-research/2014/07/brutpos-rdp-bruteforcing-botnet-targeting-pos-systems.html
US-CERT Alert Malware Targeting Point of Sale Systems
https://www.us-cert.gov/ncas/alerts/TA14-002A
Fresh Android Vulnerability Affects 60% of Devices
http://www.infosecurity-magazine.com/view/39215/fresh-android-vulnerability-affects-60-of-devices/
A vulnerability that could affect as many as 60% of Android devices connected to Google Play has been discovered that allows applications to carry out a variety of malicious activities without the permission of the users. Activities that can take place include placing phone calls (including premium-rate calls), terminating phone calls, listening to calls in progress and sending SMS texts.
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit malicious sites including pornographic sites. Also, instruct employees not to apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
Curesec blogpost Detailing the Android Vulnerability
http://blog.curesec.com/article/blog/35.htm
McAfee Plots Security Framework for Internet of Things
http://www.infosecurity-magazine.com/view/39236/mcafee-plots-security-framework-for-internet-of-things/
View Details
“A man doesn’t need brilliance or genius, all he needs is energy.”
-Albert Monroe Greenfield
AV, anti-malware most used controls for APT defense
http://www.scmagazine.com/study-av-anti-malware-most-used-controls-for-apt-defense/article/359932/
http://www.isaca.org/About-ISACA/Press-room/News-Releases/2014/Pages/ISACA-Global-APT-Survey.aspx
C-IT Recommendation
- Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
- Ensures your organization has a plan for Information Security
- Provides direction for developing information security policies, procedures, standards and guidelines
- Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
Article Resources
NIST Cyber Security Framework
http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
ISO\IEC 27001 Framework
http://www.iso.org/iso/catalogue_detail?csnumber=54534
ISACA COBIT
http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR
Vulnerability in AVG security toolbar puts IE users at risk
http://www.csoonline.com/article/2451588/data-protection/vulnerability-in-avg-security-toolbar-puts-ie-users-at-risk.html
C-IT Recommendation
- Purchase Anti-Malware Software with support instead of using free anti-malware software
- Remove local administrative privileges from user machines
- When software is needed consider pushing software through install packages and not web client downloads
Adobe Push Critical Fixes
http://krebsonsecurity.com/2014/07/microsoft-adobe-push-critical-fixes/
C-IT Recommendation
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
Article Resources
Flash Version Verification
https://www.adobe.com/software/flash/about/
Flash Update Download Link
http://www.adobe.com/products/flashplayer/distribution3.html
View Details
“Lack of will power and drive cause more failure than lack of imagination and ability.”
-Dennis Mahon
Restaurants in Pacific Northwest Face Card Compromises
http://www.infosecurity-magazine.com/view/39193/restaurants-in-pacific-northwest-face-card-compromises/
C-IT Recommendation
- Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
- Not having have total control
- Having your data protected by someone else
- Having your security managed by someone else
- Not having information about the cloud providers infrastructure
- As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the PoS terminals
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Disallow Remote Access so that attackers cannot remotely access terminals
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
Information Systems and Supplies Letter to Customer Stores
http://docs.ismgcorp.com/files/external/iss_vancouver_breach.pdf
US-CERT Common Risks of Using Business Apps in the Cloud
http://www.us-cert.gov/sites/default/files/publications/using-cloud-apps-for-business.pdf
Protecting PoS Environments Against Multi-Stage Attacks
http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf
Blue Shield leaks social security numbers
http://www.csoonline.com/article/2450493/privacy/blue-shield-leaks-social-security-numbers.html
C-IT Recommendation
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data handling policy which requires confidential data to be stored in secure, encrypted locations
- Consider a data loss prevention solution that will safeguard against intentional and unintentional misuse of sensitive data.
Article Resources
SANS Institute Data Loss Prevention White Paper
http://www.sans.org/reading-room/whitepapers/dlp/data-loss-prevention-32883
Dailymotion Video Sharing Site Hit With Malware Attack
http://www.securityweek.com/dailymotion-video-sharing-site-hit-malware-attack
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all computers running Windows XP Operating system.
- Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
From the Website Perspective
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
Article Resources
Symantec Blog Post about Dailymotion’s Exploit
http://www.symantec.com/connect/blogs/dailymotion-compromised-send-users-exploit-kit
Securing Web Application Technologies [SWAT] Checklist
http://www.securingthehuman.org/developer/swat
View Details
“Ignorance is not innocence but sin.”
– Robert Browning
Spear phishers abuse Word programming feature to infect targets
http://www.scmagazine.com/spear-phishers-abuse-word-programming-feature-to-infect-targets/article/359387/
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
Cisco Blog “Threat Spotlight: A String of ‘Paerls’, Part One”
http://blogs.cisco.com/security/a-string-of-paerls/
Microsoft Support Frequently Asked Questions About Word Macro Viruses
https://support.microsoft.com/kb/187243/en
Microsoft’s Consumer security software providers
http://windows.microsoft.com/en-US/windows/antivirus-partners#AVtabs=win7
Israeli Defense Force in False Nuke Warning AfterTwitter Hack
http://www.infosecurity-magazine.com/view/39164/israeli-defense-force-in-false-nuke-warning-after-twitter-hack/
http://www.securityweek.com/syrian-hacktivists-target-israel-defense-forces
C-IT Recommendation
- Ensure your domain hosting sites have strong secure passwords
- Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
- Ensure your login services have a log on attempt limit and locks out accounts after a certain amount of bad attempts.
Article Resources
Screenshot of the message posted by the Syrian Electronic Army
https://twitter.com/Official_SEA16/status/484806353341272064/photo/1
Screenshots of the Syrian Electronic Army gaining access to the Domain management console on the IDF’s Godaddy account
http://www.sea.sy/article/id/2041/en?utm_source=dlvr.it&utm_medium=twitter
Microsoft Plans Critical Internet Explorer, Windows Updates for Patch Tuesday
http://www.securityweek.com/microsoft-plans-critical-internet-explorer-windows-updates-patch-tuesday
http://www.infosecurity-magazine.com/view/39162/critical-ie-and-windows-updates-slated-for-light-july-patch-tuesday/
C-IT Recommendation
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all computers running Windows XP Operating system.
- Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
Article Resources
Microsoft Security Bulletin Advance Notification for July 2014
https://technet.microsoft.com/library/security/ms14-jul
Microsoft Security Bulletin Webcast
http://technet.microsoft.com/security/dn756352
View Details
“Things done well and with a care, exempt themselves from fear. ”
— William Shakespeare
Brazilian ‘Bolware’ Gang Targeted $3.75B in Transactions, RSA finds
http://www.scmagazine.com/brazilian-bolware-gang-targeted-375b-in-transactions-rsa-finds/article/359083/
http://www.securityweek.com/cybercriminals-may-have-stolen-billions-brazilian-boletos
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
RSA Bol-ware Whitepaper
https://blogs.rsa.com/wp-content/uploads/2015/07/Bolware-Fraud-Ring-RSA-Research-July-2-FINALr2.pdf
Man in the Browser Definition
http://searchsecurity.techtarget.com/definition/man-in-the-browser
New Android Malware Targets Banking Apps, Phone Information
http://www.securityweek.com/new-android-malware-targets-banking-apps-phone-information-fireeye
http://www.infosecurity-magazine.com/view/39131/android-malware-paves-way-for-serious-banking-threat/
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
http://www.fireeye.com/blog/technical/malware-research/2014/07/the-service-you-cant-refuse-a-secluded-hijackrat.html
Researchers Disarm Microsoft’s EMET
http://www.securityweek.com/researchers-disarm-microsofts-emet
C-IT Recommendation
- Deploy a defense in depth strategy for security
- Do not rely on one vendor to solve all your security issues
- Do not rely on one type of technology to solve all your security issues.
Article References
Offensive Security Video Demonstrating Disarment of Microsoft’s Enhanced Mitigation Experience Toolkit
http://vimeo.com/99658866
Offensive Security’s Blog on Disarming EMET
http://www.offensive-security.com/vulndev/disarming-enhanced-mitigation-experience-toolkit-emet/
Microsoft’s Enhanced Mitigation Experience Toolkit
http://www.microsoft.com/en-us/download/details.aspx?id=41138
Exploit Code for Disarming EMET
http://www.exploit-db.com/exploits/33944/
View Details
“Working on the right thing is probably more important than working hard.”
—Caterina Fake
Houston Astros hacked, trade conversations posted online
http://www.scmagazine.com/houston-astros-hacked-trade-conversations-posted-online/article/358952/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
Houston Astros Exposed Conversations
http://anonbin.com/753432515
http://anonbin.com/2412624498
Houston Chronicle Article: Astros GM Jeff Luhnow addresses trade leaks, Deadspin
http://blog.chron.com/ultimateastros/2014/06/30/astros-gm-jeff-luhnow-addresses-trade-leaks-deadspin/#22102101=0
P.F. Chang’s Hit With Class Action Lawsuit Over Data Breach
http://www.securityweek.com/pf-changs-hit-class-action-lawsuit-over-data-breach
http://www.scmagazine.com/pf-changs-hit-with-class-action-lawsuit-following-breach/article/358909/
C-IT Recommendations
- Ensure your organization has an incident response plan in the case of a data breach
- Incident Response Team
- Public Relations Strategy
- Legal Team
- Possibly Data Breach Insurance
Article Resources
P.F. Chang’s Lawsuit Courtroom Paperwork
http://media.scmagazine.com/documents/83/13186094-0–21770_20721.pdf
Definition of injunction
http://www.law.cornell.edu/wex/injunction
Definition of Declaratory judgment
http://www.law.cornell.edu/wex/declaratory_judgment
Experian Data Breach Response Guide
http://www.experian.com/assets/data-breach/brochures/response-guide.pdf
Payment Services, Financial Industry Top List of Phishing Targets
http://www.securityweek.com/payment-services-financial-industry-top-list-phishing-targets-research
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
Phishlabs Data Analysis of Phishing Targets
http://blog.phishlabs.com/banks-epayment-top-list-of-phishing-kit-targets
View Details
“Don’t be cocky. Don’t be flashy. There’s always someone better than you.”
—Tony Hsieh
‘Lite Zeus’ has fewer tricks, but updated encryption
http://www.scmagazine.com/lite-zeus-has-fewer-tricks-but-updated-encryption/article/358593/
EMOTET banking malware captures data sent over secured HTTPS connections
http://www.scmagazine.com/emotet-banking-malware-captures-data-sent-over-secured-https-connections/article/358586/
http://www.securityweek.com/emotet-banking-malware-steals-data-network-sniffing
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a malware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
US-CERT Alert on Game over Zeus
http://www.us-cert.gov/ncas/alerts/TA14-150A
Trend Micros blog regarding the issue
http://blog.trendmicro.com/trendlabs-security-intelligence/new-banking-malware-uses-network-sniffing-for-data-theft/
Microsoft Darkens 4MM Sites in Malware Fight
http://krebsonsecurity.com/2014/07/microsoft-darkens-4mm-sites-in-malware-fight/
View Details
“I knew that if I failed I wouldn’t regret that, but I knew the one thing I might regret is not trying.”
—Jeff Bezos
Rare SMS worm targets Android devices
http://www.csoonline.com/article/2369336/rare-sms-worm-targets-android-devices.html
C-IT Recommends
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Stronly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
Adaptive Mobile Detail Analysis on
http://www.adaptivemobile.com/blog/selfmite-worm
US CERT Defending Cell Phones and PDAs Against Attack
https://www.us-cert.gov/ncas/tips/ST06-007
Most health care vendors earn ‘D’ in data protection, study finds
http://www.scmagazine.com/most-health-care-vendors-earn-d-in-data-protection-study-finds/article/358280/
C-IT Recommendation
- Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
- Ensures your organization has a plan for Information Security
- Provides direction for developing information security policies, procedures, standards and guidelines
- Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
-
Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
-
Material to be covered
- Current Risks (including potential severity and probability)
- Emerging Risks (including potential severity and probability)
- Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
- Monitoring Progress of Risk Handling
Article resources
The Unlocked Back Door to Healthcare Data Report
http://www.vendorsecurityrm.com/resources/healthcare-vendor-intelligence-report/
NIST Cyber Security Framework
http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
ISO\IEC 27001 Framework
http://www.iso.org/iso/catalogue_detail?csnumber=54534
ISACA COBIT
http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR
PlugX RAT Armed With ‘Time Bomb’ Leverages Dropbox In Attack
http://www.darkreading.com/cloud/plugx-rat-armed-with-time-bomb-leverages-dropbox-in-attack/d/d-id/1278946?
C-IT Recommendation
- Evaluate the organizational risks for allowing users in your organization to use online document sharing sites such as dropbox, Google drive, Microsoft One Drive. Understand once the information leaves your organization you no longer have controls. This evaluation should include input from your core business leaders, the legal department and the information technology and security leadership.
- Make an organizational decision to whether or not you will allow users to store files on online document sharing sites.
- Ratify a data storage policy that explicitly addresses your directives for storing files on online document sharing sites.
- If you decide to disallow users to use online document sharing sites, you may want to consider blocking those sites on your web content filter appliance.
- Evaluate the total cost of ownership and return on investment for deploying tools that manage ShadowIT
Article Resources
Shadow IT Definition
http://searchcloudcomputing.techtarget.com/definition/shadow-IT-shadow-information-technology
CIO Magazine “How to Bring Shadow IT Under Control” Article
http://www.cio.com/article/746441/How_to_Bring_Shadow_IT_Under_Control
Trend Micro Blog Detailing PlugX RAT
http://blog.trendmicro.com/trendlabs-security-intelligence/plugx-rat-with-time-bomb-abuses-dropbox-for-command-and-control-settings/
View Details
“Anything that is measured and watched, improves.”
—Bob Parsons
US airports compromised during major APT hacking campaign, says CIS
http://www.csoonline.com/article/2369043/us-airports-compromised-during-major-apt-hacking-campaign-says-cis.html
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Article Resources
Center for Internet Security 2013 Annual Report
http://www.cisecurity.org/about/documents/2013AnnualReportspreads.pdf
Insider Threats Top Infosecurity Europe Attendees’ Cyber Fears
http://www.infosecurity-magazine.com/view/39035/insider-threats-top-infosecurity-europe-attendees-cyber-fears/
http://www.csoonline.com/article/2385000/security-awareness/security-awareness-and-concern-are-both-on-the-rise-among-it-professionals.html
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Emory Technology Education on Phishing
http://it.emory.edu/security/security_awareness/phishing.html
Lancope Survey Results
http://www.lancope.com/files/Blog/Lancope-Infosecurity-Europe-2014-Survey-Results.pdf
Lancope Combating Insider Threat Webinar
http://www.lancope.com/resource-center/recorded-webinars/insider-threat-hunting-for-authorized-evil/
US Oil & Gas Industry Establishes Information Sharing Center
http://www.infosecurity-magazine.com/view/39024/us-oil-gas-industry-establishes-information-sharing-center/
http://www.darkreading.com/analytics/threat-intelligence/oil-and-natural-gas-industry-forms-isac/d/d-id/1278885?
Article Resources
http://www.momentumpress.net/books/protecting-industrial-control-systems-electronic-threats
View Details
“Every day that we spent not improving our products was a wasted day.”
—Joel Spolsky
Montana Notifying 1.3 Million After State Health Agency Server Hacked
http://www.securityweek.com/montana-notifying-13-million-after-state-health-agency-server-hacked
http://www.csoonline.com/article/2367661/montana-data-breach-exposed-13-million-records.html
C-IT Recommendation
- Verify your company has an effective and enforced access control standard and policy which defines roles and baselines for system administrators. Ensure the standard and policy expresses that access should be removed when an employee transfers within the organization or leaves the organization.
- Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
- Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
- ex: Database Administrator should not have the rights of the Operating System Administrator
- Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.
- Utilize job rotation, and mandatory vacations for all privileged roles. Job rotation allows administrators to
- understand that someone else is stepping in to perform the job responsibilities and may be able to detect malicious behavior and consequently deter the administrator’s malicious behavior
-
Utilize dual control (separation of duties) for highly sensitive activities.
- Ex: The individual who makes changes in production source code hand off their changes to someone else for installation control.
- This deters malicious behavior as each individual knows an honest employee may detect the behavior
-
Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
- Consult your Risk Management team to see if your company has any cybersecurity insurance.
- If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.
Article Resources
Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)
http://csrc.nist.gov/groups/SNS/rbac/
Separation of duty definition
http://www.pcmag.com/encyclopedia/term/51110/separation-of-duties
NIST Computer Security Incident Handling Guide
http://csrc.nist.gov/publications/nistpubs/800-61rev2/SP800-61rev2.pdf
‘Luuuk’ Cybercrime Operation Steals €500,000 From Bank
http://www.securityweek.com/luuuk-cybercrime-operation-steals-%E2%82%AC500000-bank
http://www.darkreading.com/luuuk-stole-half-million-euros-in-one-week/d/d-id/1278845?
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Man in the browser attack definition
http://searchsecurity.techtarget.com/definition/man-in-the-browser
Securelist technical description of Luuuk attack
http://www.securelist.com/en/blog/8230/Use_the_force_Luuuk
‘Havex’ malware strikes industrial sector via watering hole attacks
http://www.scmagazine.com/havex-malware-strikes-industrial-sector-via-watering-hole-attacks/article/357875/
http://www.securityweek.com/attackers-using-havex-rat-against-industrial-control-systems
C-IT Recommendation
From the end-user perspective
- Ensure your organization has a strong asset inventory with an accurate configuration management database.
- Identify all devices which have the vulnerable versions of Adobe Flash Player
- Deploy the Adobe security update to test machines in your environment
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted
- Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.
From the Website Perspective
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
View Details
“Your reputation is more important than your paycheck, and your integrity is worth more than your career.”
— Ryan Freitas
Caphaw trojan being served up to visitors of AskMen.com, according to Websense
http://www.scmagazine.com/caphaw-trojan-being-served-up-to-visitors-of-askmencom-according-to-websense/article/357631/
http://www.securityweek.com/askmen-compromised-distribute-financial-malware-report
C-IT Recommendation
From the end-user perspective
- Ensure your organization has a strong asset inventory with an accurate configuration management database.
- Identify all devices which have Windows Operating Systems
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.
From the Website Perspective
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
Content Widget Maker Taboola Is Hacked On Reuters
http://www.darkreading.com/content-widget-maker-taboola-is-hacked-on-reuters/d/d-id/1278792?
http://www.scmagazine.com/taboola-hack-allows-sea-to-redirect-reuters-site-visitors/article/357375/
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them. Additionally educate your users not to use the same username and passwords across multiple systems. Encourage the use of a strong password manager to keep passwords distinct and manageable.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
Article Resources
Taboola’s Breach Disclosure
http://taboola.com/blog/update-taboola-security-breach-identified-and-fully-resolved-0
PC Magazine’s Review of the Best Password Managers
http://www.pcmag.com/article2/0,2817,2407168,00.asp
HackingTeam tool makes use of mobile malware targeting all major platforms
http://www.scmagazine.com/hackingteam-tool-makes-use-of-mobile-malware-targeting-all-major-platforms/article/357652/
http://www.csoonline.com/article/2367682/data-protection/hackingteam-mobile-pc-spyware-for-governments-spans-many-countries.html
View Details
“ Progress is the activity of today and the assurance of tomorrow. ”
— Ralph Waldo Emerson
Domino’s extortion breach highlights rise in ransom-based attacks
http://www.scmagazine.com/dominos-extortion-breach-highlights-rise-in-ransom-based-attacks/article/355997/
http://www.csoonline.com/article/2364323/cyber-attacks-espionage/domino-s-pizza-large-breach-with-a-side-of-ransom.html
http://www.securityweek.com/dominos-pizza-refuses-extortion-demand-after-customer-data-stolen
http://www.infosecurity-magazine.com/view/38876/dominos-pizza-customers-exposed-after-massive-data-breach/
C-IT Recommendation
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
- Consider purchasing a web application firewall
New Remote Access Trojan Bypasses SSL Protection, Targets Bank Credentials
http://www.securityweek.com/new-rat-bypasses-ssl-protection-targets-bank-credentials-phishme
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
Phishme Recommendations
-
Remove above emails from inboxes
-
Check your proxy logs for traffic to Cubby, downloading zip files containing the name “documents” or “invoice”
-
Search for traffic / block the IPs 85.25.148.6, 217.12.207.151, and 192.99.6.61
-
IDS rules looking for double POST within a short period of time (this will catch copy cats, too)
-
Look for zip files containing .exe or .scr files (web, IDS, host-based, etc)
Article Resources
Phishme article detailing Project Drye Malware
http://phishme.com/project-dyre-new-rat-slurps-bank-credentials-bypasses-ssl/
Why businesses should use caution with HTML5-based mobile apps
http://www.csoonline.com/article/2364322/data-protection/why-businesses-should-use-caution-with-html5-based-mobile-apps.html
C-IT Recommendation
- Ensure your company is using a strong Web Code review process before publishing mobile apps
- Use a software code security analysis tool to check your mobile apps for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your mobile apps.
- If apps are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
Article Resources
Mobile Security Conference Paper on HTML5 Attacks
http://mostconf.org/2014/papers/s3p5.pdf
Mobile Security Conference Slides on HTML5 Attacks
http://mostconf.org/2014/slides/s3p5-slides.pptx
Gartner report on Hybrid Mobile Apps
http://www.gartner.com/newsroom/id/2324917
View Details
“People will forget what you said, people will forget what you did, but people will never forget how you made them feel.”
– Maya Angelou
Target top security officer reporting to CIO seen as a mistake
http://www.csoonline.com/article/2363210/data-protection/target-top-security-officer-reporting-to-cio-seen-as-a-mistake.html
C-IT Recommendation
- Analyze the reporting structure of your organization
- Interview your CISO and ask him or her where it is optimal in your organization to report. Ask questions such as “Do you believe security priorities have been bottlenecked by the current reporting structure?”
- If necessary, move CISO’s reporting structure directly into a top level officer or directly to a top level board
Article Resources
Who should the CISO report to?
http://www.csoonline.com/article/2131227/infosec-staffing/who-should-the-ciso-report-to-.html
The Global State of Information Security® Survey 2014
http://www.pwc.com/GX/EN/CONSULTING-SERVICES/INFORMATION-SECURITY-SURVEY/INDEX.JHTML
Android ‘SMS Stealer’ hides in World Cup-themed apps
http://www.scmagazine.com/android-sms-stealer-hides-in-world-cup-themed-apps/article/355717/
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
View Details
“Vigilance is not only the price of liberty, but of success of any sort.”
-Henry Ward Beecher
P.F. Chang’s Confirms Credit Card Breach
http://krebsonsecurity.com/2014/06/p-f-changs-confirms-credit-card-breach/
Article Resources
P.F. Chang’s Security Compromise Update
http://pfchangs.com/security/
PLXsert warns Fortune 500 companies of evolving Zeus threat
http://www.scmagazine.com/plxsert-warns-fortune-500-companies-of-evolving-zeus-threat/article/355543/
http://www.infosecurity-magazine.com/view/38832/zeus-used-to-mastermind-ddos-and-attacks-on-cloud-apps/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
- Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
- Not having have total control
- Having your data protected by someone else
- Having your security managed by someone else
- Not having information about the cloud providers infrastructure
- As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
Prolexic Mitigation Recommendation
- Users are tricked into running programs that infest their devices, so organizational security policies and user education can help. Enforce security policies for system security and patches and updates. Educate users about how this type of attack is executed from email clients and web browsers.
- Clean-up effort by the security community is fundamental. Initiatives such as ZeuS Tracker are necessary to contain and manage this threat. Takedown follow-up efforts must also be implemented to reduce the number of infected command and control centers.
- Learn how to prevent, detect and remove Zeus infections. Symantec Security Response provides extensive information to help you do this.
- Write Snort rules for Zeus traffic. Sourcefire VRT Labs has an excellent source for writing Snort rules based on Zeus traffic.
Article Resources
Prolexic Zeus Crimeware Breaches Cybersecurity Defenses of Fortune 500 Advisory
http://www.prolexic.com/knowledge-center-ddos-threat-advisory-zeus-zbot-malware-crimeware-kit-cybersecurity.html
ZeuS Tracker (tracks ZeuS Command&Control servers around the world and provides you a domain- and a IP-blocklist)
https://zeustracker.abuse.ch/
Ransomware “Svpeng” strikes US, leaves Android devices unusable
http://www.scmagazine.com/ransomware-svpeng-strikes-us-leaves-android-devices-unusable/article/355530/
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit non business related sites on company issued phones. Also, instruct employees not to download apps from unofficial stores
If you do not have a mobile device management solution in a BYOD model, Stronly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
Details of Sveng Mobile malware
http://www.securelist.com/en/blog/8227/Latest_version_of_Svpeng_targets_users_in_US
View Details
“If you really want to do something, you’ll find a way. If you don’t, you’ll find an excuse.”
–Jim Rohn
P.F. Chang’s Investigates Possible Breach of Customer Credit Cards
http://www.securityweek.com/pf-changs-investigates-possible-breach-customer-credit-cards
http://www.infosecurity-magazine.com/view/38818/pf-changs-may-have-leaked-info-on-thousands-of-credit-cards-/
http://krebsonsecurity.com/2014/06/banks-credit-card-breach-at-p-f-changs/
Survey respondents praise, but neglect, continuous monitoring
http://www.scmagazine.com/survey-respondents-praise-but-neglect-continuous-monitoring/article/355322/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
Ponemon Institute SQL Injection Threat Study
http://www.dbnetworks.com/pdf/ponemon-the-SQL-injection-threat-study.pdf
Small businesses running cloud-based POS software hit with unique ‘POSCLOUD’ malware
http://www.scmagazine.com/small-businesses-running-cloud-based-pos-software-hit-with-unique-poscloud-malware/article/355301/
C-IT Recommendation
- Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
- Not having have total control
- Having your data protected by someone else
- Having your security managed by someone else
- Not having information about the cloud providers infrastructure
- As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the PoS terminals
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Disallow Remote Access so that attackers cannot remotely access terminals
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
IntelCrawler Cloud-Based POS Software – “New Target for Hackers?”
http://intelcrawler.com/intel/webpos.pdf
US-CERT Common Risks of Using Business Apps in the Cloud
http://www.us-cert.gov/sites/default/files/publications/using-cloud-apps-for-business.pdf
View Details
“An amazing thing, the human brain. Capable of understanding incredibly complex and intricate concepts. Yet at times unable to recognize the obvious and simple.”
-Jay Abraham
Cybercrime Costs Businesses More than $400 Billion Globally: Report
http://www.securityweek.com/cybercrime-costs-businesses-more-400-billion-globally-report
http://www.csoonline.com/article/2361011/security0/annual-cost-of-cybercrime-hits-near-400-billion.html
http://www.darkreading.com/worldwide-cost-of-cybercrime-estimated-at-$400-billion/d/d-id/1269527?
C-IT Recommendation
- Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
- Ensures your organization has a plan for Information Security
- Provides direction for developing information security policies, procedures, standards and guidelines
- Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
- Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
- Material to be covered
- Current Risks (including potential severity and probability)
- Emerging Risks (including potential severity and probability)
- Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
- Monitoring Progress of Risk Handling
Article Resources
Center for Strategic and International Studies (CSIS) Report “Net Losses:Estimating the Global Cost of Cybercrime”
http://www.mcafee.com/us/resources/reports/rp-economic-impact-cybercrime2.pdf
Chinese cyberspies targeting U.S, European defense, space sectors
http://www.csoonline.com/article/2361425/cyber-attacks-espionage/chinese-cyberspies-targeting-u-s-european-defense-space-sectors.html
http://www.infosecurity-magazine.com/view/38785/second-chinese-pla-hacking-unit-unmasked-in-putter-panda-report/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
Crowdstrike putter Panda report
http://resources.crowdstrike.com/putterpanda/
Countering Adversaries Part 1: Espionage and Stolen Credentials
https://www.brighttalk.com/webcast/5385/104705
Scammers Trick Thousands of Twitter Users with ‘Follower’ Bait
http://www.infosecurity-magazine.com/view/38776/scammers-trick-thousands-of-twitter-users-with-follower-bait/
http://www.darkreading.com/attacks-breaches/tweetdeck-scammers-steal-twitter-ids-via-oauth/d/d-id/1269503?
C-IT Recommendation
- Evaluate your organizations social media presence. If your social media department is using Tweetdeck to manage its twitter account, uninstall TweetDeck and reauthorize it.
- run a security scan to check for malware on any devices they used to log into Twitter.
Article Resources
BitDefender Blog on the Twitter Scam
http://www.hotforsecurity.com/blog/scammers-abuse-twitter-features-trick-thousands-with-follower-scheme-9202.html
View Details
“We can evade reality but we cannot evade the consequences of evading reality.”
–Ayn Rand
RIG Exploit Kit Used to Deliver “Cryptowall” Ransomware
http://www.securityweek.com/rig-exploit-kit-used-deliver-cryptowall-ransomware
http://www.infosecurity-magazine.com/view/38751/malvertising-and-cryptowall-mark-the-appearance-of-the-rig-exploit-kit-/
C-IT Recommendation
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates. Consider visiting the Cisco systems site to add the identified sites to your web content filters blacklist, which will block the malicious sites.
- Thoroughly educate your end users on safe website browsing. Communicate to them that they should only be utilizing the internet to access legitimate sites which support the accomplishing of their job responsibilities.
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes.
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit.
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
- If you are using WordPress, enforce strong password policy requiring login to be complex with at least eight characters, lower case, uppercase and symbols.
Article Resources
Cisco Systems RIG Exploit Kit Strikes Oil Blog
https://blogs.cisco.com/security/rig-exploit-kit-strikes-oil
US-CERT Alert (TA13-309A): CryptoLocker Ransomware Infections
http://www.us-cert.gov/ncas/alerts/TA13-309A
McAfee Blog: What is a “Drive-By” Download?
https://blogs.mcafee.com/consumer/drive-by-download
US-CERT Alert (TA14-150A): GameOver Zeus P2P Malware (Tools for Removal)
https://www.us-cert.gov/ncas/alerts/TA14-150A
What to avoid in Dropbox-related phishing attack
http://www.csoonline.com/article/2360670/malware-cybercrime/what-to-avoid-in-dropbox-related-phishing-attack.html
C-IT Recommendation
- Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
- Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Thoroughly educate your end users on phishing attacks and how to avoid them.
- Encourage your end users through your information security policy not to give their company email out for non-business related purposes
- Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
- Evaluate the organizational risks for allowing users in your organization to use online document sharing sites such as dropbox, google drive, Microsoft One Drive. Understand once the information leaves your organization you no longer have controls. This evaluation should include input from your core business leaders, the legal department and the information technology and security leadership.
- Make an organizational decision to whether or not you will allow users to store files on online document sharing sites.
- Ratify a data storage policy that explicitly addresses your directives for storing files on online document sharing sites.
- If you decide to disallow users to use online document sharing sites, you may want to consider blocking those sites on your web content filter appliance.
Article Resources
Phishme Blog “An inside look at Dropbox phishing: Cryptowall, Bitcoins, and You”
http://phishme.com/inside-look-dropbox-phishing-cryptowall-bitcoins/
US- CERT Security Tip (ST04-014): Avoiding Social Engineering and Phishing Attacks
http://www.us-cert.gov/ncas/tips/ST04-014
Microsoft preps seven fixes, two critical, for Patch Tuesday release
http://www.scmagazine.com/microsoft-preps-seven-fixes-two-critical-for-patch-tuesday-release/article/351559/
C-IT Recommendation
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
View Details
“To see what is right and not do it is a lack of courage.”
–Confucius
Seven vulnerabilities addressed in OpenSSL update, one enables MitM attack
http://www.scmagazine.com/seven-vulnerabilities-addressed-in-openssl-update-one-enables-mitm-attack/article/351323/
http://www.securityweek.com/new-mitm-vulnerability-plagues-client-server-versions-openssl
C-IT Recommendation
- Ensure your organization has a strong asset inventory with an accurate configuration management database.
- Identify all devices which have the vulnerable versions of OpenSSL both on the workstation and servers
- Deploy the OpenSSL updates to test machines in your environment
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted
- Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.
Article Resources
OpenSSL Security Advisor
http://www.openssl.org/news/secadv_20140605.txt
Attackers hide in plain sight using data-sharing apps
http://www.scmagazine.com/report-attackers-hide-in-plain-sight-using-data-sharing-apps/article/351314/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Palo Alto Networks 2014 Application Usage and Threat Report
https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/white-papers/Application_Usage_Threat_Report_2014.pdf
Microsoft Security Intelligence Report: What is a Botnet?
http://www.microsoft.com/security/sir/story/default.aspx#!botnetsection
How to Integrate Security into Core Business Processes
http://www.infosecurity-magazine.com/view/38694/how-to-integrate-security-into-core-business-processes/
Article Resources
Information Security Forum
https://www.securityforum.org/
View Details
“For success, attitude is equally as important as ability.”
-Harry F. Banks
Android/Simplocker could be the first Android ransomware to encrypt files
http://www.scmagazine.com/androidsimplocker-could-be-the-first-android-ransomware-to-encrypt-files/article/350070/
http://www.securityweek.com/new-ransomware-encrypts-android-files-eset
http://www.infosecurity-magazine.com/view/38716/experts-discover-fileencrypting-android-ransomware/
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit suspicious sites. Also, instruct employees not to apps from unofficial stores.
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
ESET Simplocker Explanation
http://www.welivesecurity.com/2014/06/04/simplocker/?utm_source=dlvr.it&utm_medium=twitter
US-CERT Security Tip: Cybersecurity for Electronic Devices
https://www.us-cert.gov/ncas/tips/ST05-017
Hackers distribute banking malware through Buffalo site in Japan
http://www.csoonline.com/article/2359426/hackers-distribute-banking-malware-through-buffalo-site-in-japan.html
C-IT Recommendation
If your company is hosting files
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
- Review your security measures for the storage of files available for public download. Consider having an alerting mechanism when any changes are made to files in storage repositories available to your customer base
If your company downloads files:
- Ensure your anti-malware solution scans files for malicious software upon download of a file
Article Resources
The complete list of malicious downloads is:
airnavi2_160.exe
airnavilite-1330.exe
airnavi-1272.exe
airnavi-1040.exe
airnavi-1030.exe
kokiinst-160.exe
drivenavi_cbu2_100.exe
ls_series-168.exe
hp6v131.exe
bsbt4d09bk_21630.exe
NIST Publishes Second Draft of Federal IT Supply Chain Risk Management Guidelines
http://www.securityweek.com/nist-publishes-second-draft-federal-it-supply-chain-risk-management-guidelines
C-IT Recommendation
- Find out if your Information Technology organization has Security embedded into the Software Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
- Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
- Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
- Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.
Article Resources
Microsoft Updated Cybersecurity Papers on Supply Chain Security and Critical Infrastructure Protection
http://blogs.technet.com/b/security/archive/2014/05/06/revised-cybersecurity-papers-on-supply-chain-security-and-critical-infrastructure-protection.aspx
View Details
“Restlessness and discontent are the first necessities of progress.”
-Thomas A. Edison
Soraya Malware Mixes Capabilities of Zeus and Dexter to Target Payment Card Data
http://www.securityweek.com/soraya-malware-mixes-capabilities-zeus-and-dexter-target-payment-card-data
http://www.scmagazine.com/soraya-malware-targets-payment-card-data-on-pos-devices-and-home-computers/article/349880/
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints including POS terminals are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Use strong password for terminal log in accounts and change them regularly
- Install a local firewall
- Restrict access to internet. POS devices should not be allowed to access the internet
- Disallow remote access to the point of sales terminals
- Encrypt traffic between terminals, servers and payment card processor
- Remove local administrative privileges for users who do not need those local privileges
- Harden point of sales terminals to only allow services to run that are absolutely necessary to process transactions
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Arbor Networks Security Report on Soraya
http://www.arbornetworks.com/asert/2014/06/the-best-of-both-worlds-soraya/
US-CERT Malware Targeting Point of Sale Systems Advisory
https://www.us-cert.gov/ncas/alerts/TA14-002A
Protecting PoS Environments Against Multi-Stage Attacks
http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf
Amex to notify Calif. customers of card dump linked to Anonymous
http://www.scmagazine.com/amex-to-notify-calif-customers-of-card-dump-linked-to-anonymous/article/349888/
C-IT Recommendation
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
- Consult your Risk Management team to see if your company has any cybersecurity insurance.
- If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.
Article Resources
American Express’s California Incident Reporting Document
https://oag.ca.gov/system/files/Recovered%20-%20Anonymous-C2014030241%20CA%20AG%20Letter_0.pdf
NetDiligence® 2013 Cyber Liability & Data Breach Insurance Claims: A Study of Actual Claim Payouts
http://www.netdiligence.com/files/CyberClaimsStudy-2013.pdf
Security Vulnerabilities Patched in WordPress SEO Plugin
http://www.securityweek.com/security-vulnerabilities-patched-wordpress-seo-plugin
C-IT Recommendation
- Consult with your web teams to determine if your organization is using Word Press and the All in One SEO pack for any of its website content hosting. If so, download the current version of the the SEO pack (v.2.1.6)
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
Article Resources
Securi Blog on the Word press SEO Plugin
http://blog.sucuri.net/2014/05/vulnerability-found-in-the-all-in-one-seo-pack-wordpress-plugin.html
All in One SEO Pack Plugin Download Details
https://wordpress.org/plugins/all-in-one-seo-pack/
View Details
“Truth is the cry of all, but the game of the few.”
-George Berkeley
Gameover Zeus, CryptoLocker Hit in Massive Takedown Operation
http://www.securityweek.com/gameover-zeus-cryptolocker-hit-massive-takedown-operation
http://www.infosecurity-magazine.com/view/38670/international-law-enforcement-sinkhole-gameover-zeus-and-cryptolocker-botnets/
http://www.csoonline.com/article/2358623/data-protection/businesses-can-do-more-in-battle-against-gameover-zeus-like-botnets.html
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints including POS terminals are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
The U.S. Department of Justice Briefing on the Case
http://www.justice.gov/opa/gameover-zeus.html
US-CERT Advisory: GameOver Zeus P2P Malware
https://www.us-cert.gov/ncas/alerts/TA14-150A
New Heartbleed Attack Vectors Impact Enterprise Wireless, Android Devices
http://www.securityweek.com/new-heartbleed-attack-vectors-impact-enterprise-wireless-android-devices
C-IT Recommendation
- Ensure your organization has a strong asset inventory with an accurate configuration management database.
- Android device running 4.1.0 or 4.1.1
- Avoid connecting to unknown wireless networks unless you upgrade your ROM.
- Linux system/device
- Make sure to upgrade your OpenSSL libraries to non vulnerable versions
- Corporate wireless solutions
- Examine your EAP based authentication mechanisms. Having equipment tested and contacting your device vendor and ask for more information.
Article Resources
Heartbleed and Wireless Presentation
http://www.slideshare.net/lgrangeia/heartbleed-35236317
Patches for the Cupid Vulnerability
https://github.com/lgrangeia/cupid/
SysValue Detail Description of Cupid
http://www.sysvalue.com/en/heartbleed-cupid-wireless/
Heartbleed Details
http://heartbleed.com/
Microsoft Launches Cybersecurity Startup Accelerator Program in Israel
http://www.securityweek.com/microsoft-launches-cybersecurity-startup-accelerator-program-israel
Palo Alto and Fortinet Team Up on Cyber Threat-sharing
http://www.infosecurity-magazine.com/view/38668/palo-alto-and-fortinet-team-up-on-cyber-threatsharing/
View Details
Senate committee OKs bill to give DHS broader security hiring authority
http://www.scmagazine.com/senate-committee-oks-bill-to-give-dhs-broader-security-hiring-authority/article/348427/
C-IT Recommendation
- Assess your organization’s security capability to handle events an incidents. If your organization currently
- Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
- Ensures your organization has a plan for Information Security.
- Provides direction for developing information security policies, procedures, standards and guidelines
- Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
Article Resources
The National Initiative for Cybersecurity Education (NICE) National Workforce Cybersecurity Framework
http://csrc.nist.gov/nice/framework/
NIST Cyber Security Framework
http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf
ISO\IEC 27001 Framework
http://www.iso.org/iso/catalogue_detail?csnumber=54534
ISACA COBIT
http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR
New Security Fears Over Keyboard and Trackpad Data Retention
http://www.infosecurity-magazine.com/view/38560/new-security-fears-over-keyboard-and-trackpad- data-retention/
Article Resources
Privacy International
https://www.privacyinternational.org/about-us
View Details
“The measure of progress of civilization is the progress of the people.”
– George Bancroft
Sleeping companies lose big from employee, executive fraud
http://www.csoonline.com/article/2158625/fraud-prevention/sleeping-companies-lose-big-from-employee-executive-fraud.html
http://www.darkreading.com/vulnerabilities—threats/insider-threats/privileged-use-also-a-state-of-mind-report-finds/d/d-id/1269145?
C-IT Recommendations
- Set up a fraud reporting hotline educate employees on the kind of activity considered fraudulent to eliminate any grey areas.
- Verify your company has an effective and enforced access control standard and policy which defines roles and baselines for system administrators. Ensure the standard and policy expresses that access should be removed when an employee transfers within the organization or leaves the organization.
- Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
- Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
- ex: Database Administrator should not have the rights of the Operating System Administrator
- Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.
- Utilize job rotation, and mandatory vacations for all privileged roles. Job rotation allows administrators to
- understand that someone else is stepping in to perform the job responsibilities and may be able to detect malicious behavior and consequently deter the administrator’s malicious behavior
- Utilize dual control (separation of duties) for highly sensitive activities.
- Ex: The individual who makes changes in production source code hand off their changes to someone else for installation control.
- This deters malicious behavior as each individual knows an honest employee may detect the behavior
Article Resources
Association of Certified Fraud Examiners 2014 Global Fraud Study
http://www.acfe.com/rttn/docs/2014-report-to-nations.pdf
“Fraud prevention: Improving Internal Controls”
http://www.csoonline.com/article/2127917/fraud-prevention/fraud-prevention–improving-internal-controls.html
Ponemon Institute Privileged User Abuse & The Insider Threat Report
http://www.trustedcs.com/resources/whitepapers/Ponemon-RaytheonPrivilegedUserAbuseResearchReport.pdf
Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)
http://csrc.nist.gov/groups/SNS/rbac/
‘Nemanja’ POS malware compromises 1,500 devices, half a million payment cards, worldwide
http://www.scmagazine.com/nemanja-pos-malware-compromises-1500-devices-half-a-million-payment-cards-worldwide/article/348183/
http://www.securityweek.com/most-2013-data-breaches-affected-e-commerce-and-pos-systems-trustwave
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs.
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Diluted Freedom Act passes House to privacy advocates’ dismay
http://www.scmagazine.com/diluted-freedom-act-passes-house-to-privacy-advocates-dismay/article/348211/
View Details
“In business, what’s dangerous is not to evolve.”
-Jeff Bezos
eBay hacked, all users asked to change passwords
http://www.scmagazine.com/ebay-hacked-all-users-asked-to-change-passwords/article/347967/
http://www.securityweek.com/after-cyberattack-ebay-recommends-password-change
http://www.infosecurity-magazine.com/view/38528/researchers-blast-ebay-over-data-breach/
http://www.darkreading.com/attacks-breaches/ebay-database-hacked-with-stolen-employee-credentials-/d/d-id/1269093?
http://www.csoonline.com/article/2158083/data-protection/how-to-protect-your-company-from-an-ebay-like-breach.html
C-IT Recommendation
- Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts of malicious activity
- Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
- Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
- Ensure your entity has a log management standard, policy and procedure that addresses
- Log retention- ensuring that all computer logs can be accessed in the case of an investigation
- Log reviews- enabling the possible early detection of events based upon irregular log entries
- Consider using two-factor authentication for your customer base to minimize the probability of accounts being compromised
- Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
- Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
- Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.
Article Resources
SANS Article “What is the Role of a SIEM in Detecting Events of Interest?”
http://www.sans.org/security-resources/idfaq/siem.php
NIST Guide to Computer Security Log Management
http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf
Ebay blog announcement
https://blog.ebay.com/ebay-inc-ask-ebay-users-change-passwords/
Ebay Frequently Asked Questions Concerning the Breach
http://www.ebayinc.com/in_the_news/story/faq-ebay-password-change
DHS: Control system of U.S. utility company hacked
http://www.scmagazine.com/dhs-control-system-of-us-utility-company-hacked/article/347990/
http://www.securityweek.com/ics-cert-report-highlights-industrial-control-system-security-failures
C-IT Recommendation
- If your organization business includes power plants, oil or gas refineries, telecommunications facilities, transportation, or water and waste control, it will most likely be using SCADA equipment. If not consult with your HVAC, telecom and facilities department and perform an asset inventory of your SCADA equipment. CMDB should include product manufacturers.
- Ensure your company has policies and procedures to maintain the asset inventory to include all scada systems and each piece of industrial equipment controlled by the scada technology
- Disable the Web Service. Disabling the HTTPS service and still maintaining manageability on the device can be accomplished in a number of ways. Manage the device through a command line service like SSH, or use a Device Cloud account to centrally manage all the devices. Further, if HTTPS service is enabled and on a public IP on the Internet, restrict or disable the HTTPS web interface to specific IPs.
- Check Services. If any HTTPS services have been implemented within Python, please evaluate the code and make sure that it is not impacted. If shell scripting uses the OpenSSL commands, please ensure to mitigate the Heartbeat TLS extension.
- Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
- Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
- When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
- Remove, disable or rename any default system accounts wherever possible.
- Implement account lockout policies to reduce the risk from brute forcing attempts.
- Establish and implement policies requiring the use of strong passwords.
- Monitor the creation of administrator level accounts by third-party vendors.
- Apply patches in the ICS environment, when possible, to mitigate known vulnerabilities.
Article Resources
C-IT Podcast on Industrial Control System News
http://www.c-itsecurity.com/?p=91
Industrial Control Systems Computer Emergency Response Team January -April Newsletter
http://ics-cert.us-cert.gov/sites/default/files/Monitors/ICS-CERT_Monitor_%20Jan-April2014.pdf
Industrial Control Systems Computer Emergency Response Team Defense in Depth Principles
http://ics-cert.us-cert.gov/sites/default/files/recommended_practices/Defense_in_Depth_Oct09.pdf
IBM Chokes Off APTs with Trusteer Apex Launch
http://www.infosecurity-magazine.com/view/38521/ibm-chokes-off-apts-with-trusteer-apex-launch/
C-IT Recommendation
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Perform an asset inventory of all computers running Windows XP Operating system.
- Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Ponemon Institute 2014 Cost of Data Breach Study News release
http://www-03.ibm.com/press/us/en/pressrelease/43825.wss
Study finds payment card info most compromised, breach detection lags
http://www.scmagazine.com/study-finds-payment-card-info-most-compromised-breach-detection-lags/article/347997/
Microsoft Silverlight bugs added to Angler Exploit Kit, trojans delivered via malvertising
http://www.scmagazine.com/microsoft-silverlight-bugs-added-to-angler-exploit-kit-trojans-delivered-via-malvertising/article/348001/
C-IT Recommendation
- Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
- Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
- Test business functionality of each type of device and record any issues impacting any business functions on the devices.
- If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
- Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
- Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
- Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
- Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
Article Resources
Cisco Security blog on the Angler Exploit
http://blogs.cisco.com/security/angling-for-silverlight-exploits/
CVE-2013-0074
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0074
View Details
“Most people do not listen with the intent to understand; they listen with the intent to reply.”
– Stephen Covey
Man pleads guilty to selling compromised POS systems, loading up Subway gift cards
http://www.scmagazine.com/man-pleads-guilty-to-selling-compromised-pos-systems-loading-up-subway-gift-cards/article/347146/
http://www.securityweek.com/former-subway-franchise-owner-pleads-guilty-pos-system-hacking
C-IT Recommendation
- Use Strong password for Terminal log in accounts and change them regularly
- Keep POS operating systems and POS Software Applications updated with the latest patches:
- Install a Firewall
- Ensure a solid Antivirus solution is running on the PoS terminals
- Restrict Access to Internet. POS should not be allowed to access the internet
- Disallow Remote Access so
- Encrypt traffic between terminals, servers and payment card processor
Article Resources
US-CERT Malware Targeting Point of Sale Systems Advisory
https://www.us-cert.gov/ncas/alerts/TA14-002A
Protecting PoS Environments Against Multi-Stage Attacks
http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf
Retailers join forces to share threat intelligence
http://www.scmagazine.com/retailers-join-forces-to-share-threat-intelligence/article/347215/
http://www.securityweek.com/retailers-share-cyber-threat-intelligence-through-new-retail-isac
http://www.csoonline.com/article/2156060/data-protection/how-retailers-can-boost-security-through-information-sharing.html
C-IT Recommendation
- Research security sharing communities your organization can participate in. Delegate someone from your organization to be a contributor and also a liason to the organization
- If no official organization exists, consider starting one of for your industry or your town’s key businesses to participate in.
Article Resources
Retail Cyber Intelligence Sharing Center
http://www.r-cisc.org/
Security for Business Innovation Council
http://www.emc.com/emc-plus/rsa-thought-leadership/sbic/index.htm
PayPal Fixes Vulnerabilities In MultiOrder Shipping Application
http://www.securityweek.com/paypal-fixes-vulnerabilities-multiorder-shipping-application