C-IT Security Podcast : Recent Episodes

Charles Whitby: Business Security Thought Leader

View Details

“Diligence is the mother of good fortune and idleness, its opposite never brought a man to the goal of any of his best wishes.”

-Miguel De Cervantes


JPMorgan Chase customers targeted in massive phishing campaign http://www.scmagazine.com/jpmorgan-chase-customers-targeted-in-massive-phishing-campaign/article/367615/

http://www.darkreading.com/jp-morgan-targeted-in-new-phishing-campaign/d/d-id/1306589?

C-IT Recommendation

  1. Provide social engineering awareness for your customers. Ensure you communicate specifically how your organization will communicate with them. Post your communication policy on your company’s website. Warn them that any other forms of communication should be held in suspicion.
  2. Ensure your organization has a contact number on your website to reference so customers can validate contact numbers provided in correspondence that appear to come from your organization.
  3. Establish fraud monitoring services for your customers that baselines his/her account activity and alerts the customers when activity is out of bounds of their normal habits with your organization

Article Resources

Proofpoint’s Analysis of J.P Morgan and Chase Attack

http://www.proofpoint.com/threatinsight/posts/smash-and-grab-jpmorgan.php

View Details

“Out there in some garage is an entrepreneur who’s forging a bullet with your company’s name on it.”

-Gary Hamel


Cybercriminals Deliver Point-of-Sale Malware to 51 UPS Store Locations http://www.securityweek.com/cybercriminals-deliver-point-sale-malware-51-ups-store-locations

http://www.scmagazine.com/ups-announces-breach-impacting-51-us-locations/article/367257/

C-IT Recommendation

  1. Create new non-intuitive usernames for POS accounts. Disable the default usernames.
  2. Use Strong password for Terminal log in accounts and change them regularly
  3. Keep POS operating systems and POS Software Applications updated with the latest patches:
  4. Install a Firewall
  5. Ensure a solid Antivirus solution is running on the POS terminals
  6. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  7. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  8. Disallow Remote Access so that attackers cannot remotely access terminals
  9. Encrypt traffic between terminals, servers and payment card processor

Article Resources

UPS Stores impacted by the breach

http://www.theupsstore.com/security/Pages/default.aspx

US CERT- New Point of Sale Malware

https://www.us-cert.gov/sites/default/files/publications/BackoffPointOfSaleMalware.pdf

US-CERT Alert Malware Targeting Point of Sale Systems

https://www.us-cert.gov/ncas/alerts/TA14-002A

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf

View Details

Bulk of Ex-Employees Retain Access to Corporate Apps: Survey http://www.securityweek.com/bulk-ex-employees-retain-access-corporate-apps-survey

http://www.infosecurity-magazine.com/news/uk-smbs-manage-exemployee-risk/

C-IT Recommendation

  1. Verify your company has an effective and enforced access control standard and policy which requires that access be removed when an employee transfers within the organization or leaves the organization.
    1. Use Role based Access Control. Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
    2. Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
      1. ex: Database Administrator should not have the rights of the Operating System Administrator
  2. Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.

Article Resources

Intermedia Report on Rogue Access

http://www.multivu.com/players/English/7281751-intermedia-s-2014-smb-rogue-access-study-security-threat-posted-by-former-employees/

Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)

http://csrc.nist.gov/groups/SNS/rbac/

View Details

“It is not the strongest of the species that survive, nor the most intelligent, but the one most responsive to change.”

– Charles Darwin


Windows tech support scammers take root in the U.S. http://www.csoonline.com/article/2464030/security-leadership/windows-tech-support-scammers-take-root-in-the-u-s.html

Article Resources

Malwarebytes blog on the scare tactic

https://blog.malwarebytes.org/fraud-scam/2014/08/beware-of-us-based-tech-support-scams/


2014 So Far: The Year of the Data Breach http://www.infosecurity-magazine.com/news/2014-the-year-of-the-data-breach/

C-IT Recommendation

  1. Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
    1. Ensures your organization has a plan for Information Security
    2. Provides direction for developing information security policies, procedures, standards and guidelines
    3. Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior

Article Resources

Trend Micro Security Report

http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/reports/rpt-turning-the-tables-on-cyber-attacks.pdf

NIST Cyber Security Framework

http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf

ISO\IEC 27001 Framework

http://www.iso.org/iso/catalogue_detail?csnumber=54534

ISACA COBIT

http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR


Microsoft to End Support for Old Versions of Internet Explorer http://www.securityweek.com/microsoft-end-support-old-versions-internet-explorer

Microsoft’s Internet Explorer Support Information

http://blogs.msdn.com/b/ie/archive/2014/08/07/stay-up-to-date-with-internet-explorer.aspx

View Details

“It doesn’t take great men to do things, but it is doing things that make men great.”

-Arnold Glasow


PCI Council Publishes Guidance on Working With Third-party Providers http://www.securityweek.com/pci-council-publishes-guidance-working-third-party-providers

http://www.scmagazine.com/pci-council-releases-third-party-security-assurance-guidance/article/365658/

C-IT Recommendation

  1. Require your third party service provider to provide a report of compliance and require the entity to conform to conducting a risk analysis
  2. Ensure your legal department has a strong SLA and breach accountability agreement with the service provider in case critical company or customer data is compromised.
  3. Read the PCI-DSS Third-Party Security Assurance Special Interest Group PCI Security Standards Council

Article Resources

PCI-DSS Third-Party Security Assurance Special Interest Group PCI Security Standards Council Document

https://www.pcisecuritystandards.org/documents/PCI_DSS_V3.0_Third_Party_Security_Assurance.pdf


Click Fraud Malware Found Lurking Inside Image Files http://www.infosecurity-magazine.com/news/click-fraud-malware-inside-images/

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Dell SecureWorks Malware Analysis of the Lurk Downloader

http://www.secureworks.com/cyber-threat-intelligence/threats/malware-analysis-of-the-lurk-downloader/


August Patch Tuesday Addresses Critical IE Flaw http://www.infosecurity-magazine.com/news/august-patch-critical-ie-flaw/

http://www.informationweek.com/software/operating-systems/microsoft-to-patch-2-critical-bugs/d/d-id/1297920

C-IT Recommendation

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.

Article Resources

Microsoft Security Bulletin Advance Notification for August 2014

https://technet.microsoft.com/library/security/ms14-aug

View Details

“Great men undertake great things because they are great; fools, because they think them easy.”

-Luc de Vauvenargues


Hackers Demand Automakers Get Serious About Security http://www.securityweek.com/hackers-demand-automakers-get-serious-about-security

http://www.darkreading.com/application-security/automakers-openly-challenged-to-bake-in-security/d/d-id/1297902

C-IT Recommendation

  1. Find out if your organization has Security embedded into the Product Development Life Cycle. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
  2. Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
  3. Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
  4. Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.

Article Resources

Letter to Automotive Company Executive Leadership

https://www.iamthecavalry.org/wp-content/uploads/2014/08/IATC-Open-letter-to-the-Automotive-Industry.pdf

Five Star Automotive Cyber Safety Program

https://www.iamthecavalry.org/domains/automotive/5star/

MP3 of Two Researches Who Hacked Modern Vehicles

http://www.securityweek.com/podcast-car-hacking-charlie-miller-and-chris-valasek

Microsoft Updated Cybersecurity Papers on Supply Chain Security and Critical Infrastructure Protection

http://blogs.technet.com/b/security/archive/2014/05/06/revised-cybersecurity-papers-on-supply-chain-security-and-critical-infrastructure-protection.aspx


Thousands of U.S. Devices Infected With New Gameover Zeus Variant: Report http://www.securityweek.com/thousands-us-devices-infected-new-gameover-zeus-variant-report

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Perform an asset inventory of all computers running Windows XP Operating system.
  8. Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
  9. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

US-CERT GameOver Zeus P2P Malware Alert

https://www.us-cert.gov/ncas/alerts/TA14-150A


Critical Vulnerability Found in Popular WordPress Contact Form Plugin http://www.securityweek.com/critical-vulnerability-found-popular-wordpress-contact-form-plugin

http://www.infosecurity-magazine.com/news/wordpress-vulnerability-affects/

C-IT Recommendation

  1. Maintain a configuration management database of all software and add ons in your organization.
  2. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  3. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  4. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.

Article Resources

Custom Contact Forms Download to latest version

https://wordpress.org/plugins/custom-contact-forms/


View Details

“The purpose of business is to create and keep a customer.”

― Peter F. Drucker


Over 90% of Enterprises Exposed to Man-in-the-Browser Attacks: Cisco http://www.securityweek.com/over-90-enterprises-exposed-man-browser-attacks-cisco

http://www.csoonline.com/article/2459954/data-protection/cisco-patches-traffic-snooping-flaw-in-operating-systems-used-by-networking-gear.html

C-IT Recommendation

  1. Perform regular security assessments in your organization
  2. Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
    1. Material to be covered
      1. Current Risks (including potential severity and probability)
      2. Emerging Risks (including potential severity and probability)
      3. Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
      4. Monitoring Progress of Risk Handling
  3. Use Out-of-band transaction detail confirmation, followed by one-time-passcode generation: this technique leverages devices such as mobile phones that are already being carried by the intended end-users, and enables review of transaction details outside the influence of malware on the user’s PC.
  4. Fraud detection technology that monitors user behavior: this server-side monitoring of a user’s movement through a banking Web site, inclusive of transaction execution steps as well as the steps leading there, provides flexibility for financial institutions to adapt to constantly evolving malware features, and detect suspicious patterns of activity for immediate intervention. SafeNet eToken/Mobile Pass, ThreatMatrix

Article Resources

Cisco’s Midyear Security Report

http://www.cisco.com/web/offer/grs/190720/SecurityReport_Cisco_v4.pdf

Entrust WhitePaper on Preventing Man in the Browser Attacks

http://www.bankinfosecurity.com/whitepapers/defeating-man-in-the-browser-how-to-prevent-latest-malware-attacks-w-315#dynamic-popup


Reported Theft of 1.2B Email Accounts http://krebsonsecurity.com/2014/08/qa-on-the-reported-theft-of-1-2b-email-accounts/

http://www.holdsecurity.com/news/cybervor-breach/

C-IT Recommendation

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved.
  5. Ensure your organization has a password policy that requires privileged accounts to differ between various including not utilizing the same passwords on multiple systems.
  6. Ensure your password policy require complex passwords and that systems are configured to enforce the requirement. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords for privileged accounts consecutively after the passwords expire.

Article Resources

The Value of a Hacked Email Account

http://krebsonsecurity.com/2013/06/the-value-of-a-hacked-email-account/


View Details

“Genius is one percent inspiration and ninety–nine percent perspiration.”

– Thomas A. Edison


Android malware SandroRAT disguised as mobile security app http://www.scmagazine.com/android-malware-sandrorat-disguised-as-mobile-security-app/article/364455/

Article Resources

McAfee Blog Post

http://blogs.mcafee.com/mcafee-labs/sandrorat-android-rat-targeting-polish-banking-users-via-e-mail-phishing

Emory Libraries Information Security Awareness covering Phishing

http://it.emory.edu/security/security_awareness/phishing.html


Most Top Free and Paid Mobile Apps Pose Threat to Enterprises: Report https://www.securityweek.com/most-top-free-and-paid-mobile-apps-pose-threat-enterprises-report

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit malicious sites. Also, instruct employees not to apps from unofficial stores.

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

Appthority App Reputation Report

https://www.appthority.com/app-reputation-report/report/AppReputationReportSummer14.pdf

US CERT Security Tip Cybersecurity for Electronic Devices

https://www.us-cert.gov/ncas/tips/ST05-017

View Details

“If you work just for money, you’ll never make it, but if you love what you’re doing and you always put the customer first, success will be yours.”

– Ray Kroc


C-Level Execs to CISOs: No Seat for You! https://www.securityweek.com/c-level-execs-cisos-no-seat-you

http://www.scmagazine.com/study-ciso-leadership-capacity-undervalued-by-most-c-level-execs/article/364231/

C-IT Recommendation

  1. Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
    1. Material to be covered
      1. Current Risks (including potential severity and probability)
      2. Emerging Risks (including potential severity and probability)
      3. Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
      4. Monitoring Progress of Risk Handling

Article Resources

Threat Track “Chief Information Security Officers Misunderstood and Underappreciated by Their C-Level Peers” Report

http://media.scmagazine.com/documents/89/threattrack_study_on_cisos_22034.pdf


PittyTiger spearphishing campaign speaks multiple languages http://www.scmagazine.com/pittytiger-spearphishing-campaign-speaks-multiple-languages/article/363978/

https://www.securityweek.com/pitty-tiger-threat-actors-possibly-active-2008-fireeye

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Airbus Defense & Space Pitty Tiger Report

https://bbuseruploads.s3.amazonaws.com/cybertools/whitepapers/downloads/Pitty%20Tiger%20Final%20Report.pdf?Signature=DFJkN2347ctUHMcTesVVtd6Dcto%3D&Expires=1407137473&AWSAccessKeyId=0EMWEFSGA12Z1HF1TZ82

FireEye Blog Detailing Pitty Tiger

http://www.fireeye.com/blog/technical/threat-intelligence/2014/07/spy-of-the-tiger.html

Emory Libraries Informationh Security Awareness covering Phishing

http://it.emory.edu/security/security_awareness/phishing.html


Hackers Turn Remote Desktop Tools Into Gateways for Point-of-Sale Malware Attacks https://www.securityweek.com/hackers-turn-remote-desktop-tools-gateways-point-sale-malware-attacks

http://www.darkreading.com/attacks-breaches/backoff-malware-time-to-step-up-remote-access-security/a/d-id/1297731?

http://searchsecurity.techtarget.com/news/2240226048/US-government-warns-of-point-of-sale-malware-campaign

C-IT Recommendation

  1. Create new non-intuitive usernames for POS accounts. Disable the default usernames.
  2. Use Strong password for Terminal log in accounts and change them regularly
  3. Keep POS operating systems and POS Software Applications updated with the latest patches:
  4. Install a Firewall
  5. Ensure a solid Antivirus solution is running on the POS terminals
  6. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  7. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  8. Disallow Remote Access so that attackers cannot remotely access terminals
  9. Encrypt traffic between terminals, servers and payment card processor

Article Resources

US Department of Homeland Security Report on New Point of Sale Malware

http://www.us-cert.gov/sites/default/files/publications/BackoffPointOfSaleMalware.pdf

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf

View Details

“Opportunity is missed by most people because it is dressed in overalls and looks like work.”

– Thomas Edison


Vulnerability impacting multiple versions of Android could enable device takeover http://www.scmagazine.com/vulnerability-impacting-multiple-versions-of-android-could-enable-device-takeover/article/363414/

http://www.securityweek.com/android-fake-id-vulnerability-lets-malicious-apps-impersonate-trusted-apps

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit malicious sites . Also, instruct employees not to apps from unofficial stores.

Article Resources

MP3 discussing FakeID Vulnerability

http://www.buzzsprout.com/9743/192579-bluebox-labs-explains-android-fake-id-vulnerability.mp3?client_source=small_player

Bluebox Security write up on the Android FakeID Weakness

http://bluebox.com/technical/android-fake-id-vulnerability/

Bluebox Security Scanner

https://play.google.com/store/apps/details?id=com.bluebox.labs.onerootscanner&hl=en


HP tests 10 popular IoT devices, most raise privacyconcerns http://www.scmagazine.com/hp-tests-10-popular-iot-devices-most-raise-privacy-concerns/article/363426/

http://www.securityweek.com/70-iot-devices-vulnerable-cyberattacks-hp

HPs Recommendation

  1. Conduct a security review of your device and all associated components.
  2. Implement security standards that all devices must meet before production.
  3. Ensure security is a consideration throughout the product lifecycle.

Article Resources

HP Study Report

http://fortifyprotect.com/HP_IoT_Research_Study.pdf


Using Instagram on public Wi-Fi poses risk of an account hijack, researcher says http://www.csoonline.com/article/2458952/data-protection/using-instagram-on-public-wi-fi-poses-risk-of-an-account-hijack-researcher-says.html

C-IT Recommendation

  1. Refrain from connecting apple mobile devices to public wifi networks especially if there are no passwords to login to the networks.

Article Resources

Stevie Graham’s Twitter Post

https://twitter.com/stevegraham/status/493465799542468608

Instagram Co-founders Response to the hack

https://news.ycombinator.com/item?id=8099796

View Details

“The golden rule for every business man is this: Put yourself in your customer’s place.”

Orison Swett Marden


Cybercriminals Abuse Amazon Cloud to Host Linux DDoS Trojans http://www.securityweek.com/cybercriminals-abuse-amazon-cloud-host-linux-ddos-trojans

C-IT Recommendation

  1. Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
    1. Not having have total control
    2. Having your data protected by someone else
    3. Having your security managed by someone else
    4. Not having information about the cloud provider’s infrastructure
  2. As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
  3. Consider deploying technology in your organization that blocks DDoS attacks

Article Resources

Securelist blog about the Amazon attacks

https://securelist.com/blog/virus-watch/65192/elasticsearch-vuln-abuse-on-amazon-cloud-and-more-for-ddos-and-profit/

Gartner Application Delivery Controller Ratings

http://www.gartner.com/technology/reprints.do?id=1-1MCUHF2&ct=131030&st=sb


Companies accused of peddling bogus AV ordered to pay $5.1M http://www.scmagazine.com/companies-accused-of-peddling-bogus-av-ordered-to-pay-51m/article/363212/

Companies Providing Bogus Antivirus:

Pecon Software Ltd. et al;

Marczak et al.;

PCCare247 Inc. et al.;

Finmaestros, LLC et al.;

Lakshmi Infosoul Serivces Pvt. Ltd. et al.; and

Zeal IT Solutions Pvt. Ltd. et al.

C-IT Recommendation

  1. Purchase credible security solutions from credible companies. Do not take the shortcuts.

Article Resources

Federal Trade Commission article and links to court documentation

http://www.ftc.gov/news-events/press-releases/2014/07/federal-court-orders-tech-support-scammers-pay-more-51-million


EFF asks court to find NSA internet spying a violation of Fourth Amendment http://www.scmagazine.com/eff-asks-court-to-find-nsa-internet-spying-a-violation-of-fourth-amendment/article/363218/

Article Resources

EFF court filing requesting declaration of violation of Fourth Amendment

https://www.eff.org/files/2014/07/25/jewel_4th_a_mpsj_brief.pdf

View Details

“My own business always bores me to death; I prefer other people’s.”

―Oscar Wilde


WordPress Plugin Vulnerability Exploited to Compromise Thousands of Websites https://www.securityweek.com/wordpress-plugin-vulnerability-exploited-compromise-thousands-websites

http://www.csoonline.com/article/2457668/data-protection/thousands-of-sites-compromised-through-wordpress-plug-in-vulnerability.html

C-IT Recommendation

From the Website Perspective

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
  2. Identify if any of your websites are using WordPress and the MailPoet plugin.
    1. If so, backup the MailPoet configuration and update to at least version 2.6.8.
  3. Ensure your company is using a strong Web Code review process before publishing sites.
  4. Use a software code security analysis tool to check your website for potential vulnerabilities.

Article Resources

Securi’s Blogposting of MailPoet’s Weaknesses

http://blog.sucuri.net/2014/07/mailpoet-vulnerability-exploited-in-the-wild-breaking-thousands-of-wordpress-sites.html

MailPoet’s support documenation regarding its security weakness

http://support.mailpoet.com/knowledgebase/site-hacked-what-to-do/


Survey: 53 percent change privileged logins quarterly http://www.scmagazine.com/survey-53-percent-change-privileged-logins-quarterly/article/362958/

C-IT Recommendation

  1. Ensure your organization has a password policy that requires privileged accounts to differ between various including not utilizing the same passwords on multiple systems.
  2. Ensure your password policy require complex passwords and that systems are configured to enforce the requirement. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords for privileged accounts consecutively after the passwords expire.

Article Resources

Lieberman 2014 Survey of Information Security Professionals

http://media.scmagazine.com/documents/88/liberman_survey_21915.pdf

View Details

“Good executives never put off until tomorrow what they can get someone else to do today.”

-Anonymous


eBay faces class-action suit over breach http://www.scmagazine.com/ebay-faces-class-action-suit-over-breach/article/362670/

http://www.csoonline.com/article/2457981/data-protection/ebay-faces-class-action-suit-over-data-breach.html

Article Resources

Ebay’s publication of Breach

http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords

The Courtroom Paperwork for the Lawsuit

http://media.scmagazine.com/documents/88/ebaysuit_21893.pdf


Sony to shell out $15M in PSN breach settlement http://www.scmagazine.com/sony-to-shell-out-15m-in-psn-breach-settlement/article/362720/

Article Resources

Original Court Filings

http://media.scmagazine.com/documents/88/sony_settlement-1_21903.pdf

Settlement Court Documents

http://www.scribd.com/doc/234917930/Sony-agrees-to-15M-settlement

C-IT Recommendation

  1. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  2. Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
  3. Ensure your organization has an incident response plan in the case of a data breach
    1. Incident Response Team
    2. Public Relations Strategy
    3. Legal Team
  4. Consult your Risk Management team to see if your company has any cybersecurity insurance.
  5. If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.

View Details

“The two basic processes of education are knowing and valuing.”

-Robert J. Havighurst


StubHub Hit in Cyber-Attack That May Have Stolen $10M in Tickets http://www.securityweek.com/stubhub-hit-cyber-attack-may-have-stolen-10m-tickets

http://www.scmagazine.com/six-charged-in-global-stubhub-scheme-company-defrauded-out-of-1-million/article/362482/

C-IT Recommendation

  1. Ensure your organization has a security awareness program that educates users on basic security practices including not utilizing the same passwords on multiple systems.
  2. Ensure your systems require complex passwords. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords consecutively after the passwords expire.
  3. Consider using a password management program to allow users to store credentials for various accounts in a centralized repository. Encourage users to utilize a very strong password to authenticate to the password manager.

Article Resources

Krebs on Security Article

http://krebsonsecurity.com/2014/07/feds-hackers-ran-concert-ticket-racket/#more-27031

Microsoft Report: Sustainably Managing Large Numbers of Accounts

http://research.microsoft.com/pubs/217510/passwordPortfolios.pdf


InfoSec pros worried BYOD ushers in security exploits, survey says http://www.scmagazine.com/infosec-pros-worried-byod-ushers-in-security-exploits-survey-says/article/362484/

http://www.darkreading.com/cloud/infographic-with-byod-mobile-is-the-new-desktop/a/d-id/1297436?

C-IT Recommendation

  1. Ensure your organization has a clear and concise mobile device policies to ensure proper use of personal phones while accessing corporate resources.
  2. Procure and deploy a mobile device management solution, with the following capabilities:

  3. Webfiltering option which forces the cellular devices to pass through the company webfilter/proxy before accessing the internet.

  4. Anti-malware for mobile devices
  5. If possible, device segmentation that restricts non-business applications from accessing business apps.
  6. Segmentation of business data and applications from

Provide mobile device security awareness informing your employees not to visit malicious websites. Also, instruct employees not to apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money.

Article Resources

Vectra BYOD & Mobile Security Report

http://vectranetworks.hs-sites.com/byod-and-mobile-security-report-payoff?submissionGuid=ef654d16-1ce2-4a6c-ae65-7c2424b76d5f

View Details

“Every man, however wise, needs the advice of some sagacious friend in the affairs of life.”

-Plautus


Quarter of UK Shoppers Don’t Trust Retailers on Card Fraud http://www.infosecurity-magazine.com/view/39417/quarter-of-uk-shoppers-dont-trust-retailers-on-card-fraud/

C-IT Recommendation

  1. Pay attention to the news regarding data breach.
  2. Communicate your security efforts to your customer base
  3. Provide customer awareness and communicate the importance of the customer taking steps to combat card fraud because the largest segments of consumers interviewed did not recall having received any info from their financial institutions about how to protect themselves against fraud.

Article Resources

2014 Global Consumer Fraud Survey

http://www.aciworldwide.com/2014fraudsurvey.aspx

ACI Webinar on Global Consumer Fraud

http://bcove.me/xvc5e0a5


Vice.com hacked, possibly The Wall Street Journal website too http://www.scmagazine.com/vicecom-hacked-possibly-the-wall-street-journal-website-too/article/362087/

C-IT Recommendation

  1. Ensure your domain hosting sites have strong secure passwords.
  2. Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
  3. Ensure your login services have a login attempt limit and locks out accounts after a certain amount of bad attempts.
  4. Ensure your company is using a strong Web Code review process before publishing sites
  5. Use a software code security analysis tool to check your website for potential vulnerabilities
  6. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  7. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Article Resources

w0rm’s twitter posts revealing hacks

https://twitter.com/rev_priv8


Goodwill Industries investigates suspected payment card breach http://www.csoonline.com/article/2456605/data-protection/goodwill-industries-investigates-suspected-payment-card-breach.html

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Ensure your organization has an incident response plan in the case of a data breach
    1. Incident Response Team
    2. Public Relations Strategy
    3. Legal Team
    4. Possibly Data Breach Insurance

Article Resources

Krebs on Security Article

http://krebsonsecurity.com/2014/07/banks-card-breach-at-goodwill-industries/

CNN Money Article

http://money.cnn.com/2014/07/22/news/companies/goodwill-security-credit-card/

View Details

“He that will not reason is a bigot; he that cannot reason is a fool; and he that dares not reason is a slave.”

-Sir William Drummond


Password Misuse is Rampant at US Businesses http://www.infosecurity-magazine.com/view/39408/password-misuse-is-rampant-at-us-businesses/

C-IT Recommendation

  1. Ensure your organization has a security awareness program that educates users on basic security practices including not utilizing the same passwords on multiple systems
  2. Ensure your systems require complex passwords. Require passwords to expire on systems within 30-90 day window. Do not allow users to use the same passwords consecutively after the passwords expire.
  3. Consider using a password management program to allow users to store credentials for various accounts in a centralized repository. Encourage users to utilize a very strong password to authenticate to the password manager

Article Resources

US CERT Security Tip Choosing and Protecting Passwords

https://www.us-cert.gov/ncas/tips/ST04-002


Fake Air Force One Crash Messages Posted on Hacked WSJ Facebook Page http://www.securityweek.com/fake-air-force-one-crash-messages-posted-hacked-wsj-facebook-page

C-IT Recommendation

  1. Ensure your domain hosting sites have strong secure passwords
  2. Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
  3. Ensure your login services have a login attempt limit and locks out accounts after a certain amount of bad attempts.

Article Resources

US CERT White Paper : Using Social Networking Services Securely

http://www.us-cert.gov/sites/default/files/publications/safe_social_networking.pdf


Researcher finds backdoors in Apple iOS http://www.csoonline.com/article/2455975/data-protection/researcher-finds-backdoors-in-apple-ios.html

Article Resources

Jonathan Zdziarski blog

http://www.zdziarski.com/blog/

Identifying back doors, attack points, and surveillance mechanisms in iOS devices Post in Science Direct

http://www.sciencedirect.com/science/article/pii/S1742287614000036

View Details

“The successful man is the one who finds out what is the matter with his business before his competitors do.”

–Roy L. Smith


31 percent of IT security teams don’t speak to company execs http://www.scmagazine.com/report-31-percent-of-it-security-teams-dont-speak-to-company-execs/article/361263/

C-IT Recommendation

  1. Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
    1. Material to be covered
      1. Current Risks (including potential severity and probability)
      2. Emerging Risks (including potential severity and probability)
      3. Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
      4. Monitoring Progress of Risk Handling
  2. Develop a security awareness and education program which requires employees to attend some form of training. Reinforce training with periodic awareness campaigns to remind users of their role in protecting the organization.

Article Resources

Websense/Ponemon Institute Roadblocks, Refresh, & Raising the Human Security IQ Report

http://www.websense.com/content/2014-ponemon-report-part-2.aspx?cmpid=prnr7.17.14


Privileged Accounts at Root of Most Data Breaches http://www.infosecurity-magazine.com/view/39366/privileged-accounts-at-root-of-most-data-breaches/

C-IT Recommendation

  1. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  2. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  3. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  4. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

The Role of Privileged Accounts in High Profile Breaches

http://cyberark.com/contact/role-privileged-accounts-high-profile-breaches#.U8gbyvldWSo

View Details

“We generate fears while we sit. We over come them by action. Fear is natures way of warning us to get busy.”

-Dr. HenryLink


Amazon Web Services Increasingly Used to Host Malware http://www.securityweek.com/amazon-web-services-increasingly-used-host-malware-report

C-IT Recommendation

  1. Perform an information security risk assessment to see if the partnering organization handles risk in accordance with your company’s risk appetite.
  2. Ensure your organization’s legal team has a Service Level Agreement with the partnering organization that specifies tolerance for security incidents and clearly define responsibility and accountability in a data breach.

Article Resources

Solutionary Second Quarter 2014 Threat Intelligence Report

http://www.solutionary.com/_assets/pdf/research/sert-q2-2014-threat-intelligence.pdf


Endpoints Are Woefully Insecure, But There’s No Budget to Fix It http://www.infosecurity-magazine.com/view/39346/endpoints-are-woefully-insecure-but-theres-no-budget-to-fix-it/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Perform an asset inventory of all computers running Windows XP Operating system.
  8. Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
  9. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to

Article Resources

Promisec Survey

http://www.promisec.com/?attachment_id=6416

View Details

“Even if you are on the right track, You’ll get run over if you just sit there.”

– Will Rogers


Active Directory flaw opens enterprise services to unauthorized access http://www.scmagazine.com/active-directory-flaw-opens-enterprise-services-to-unauthorized-access/article/361017/

http://www.securityweek.com/active-directory-vulnerability-puts-enterprise-services-risk

http://www.darkreading.com/active-directory-flaw-lets-attackers-change-passwords/d/d-id/1297298?

http://www.csoonline.com/article/2454367/identity-access/why-the-microsoft-active-directory-design-flaw-isnt-serious.html

Aorato Mitigation Techniques

  1. Detecting authentication protocol anomalies. For instance, the use of a non-default encryption algorithm.
  2. Identifying the attack by correlating the abnormal use of encryption methods with the context in which the victim’s identity is used (e.g. unusual services accessed, unusual time of day, day of week, etc.).
  3. Applying measures to reduce the attack surface. Note that these measures only reduce the attack surface and do not eliminate it altogether or solve the root cause:
  4. Limiting the attacker’s opportunities to steal the NTLM hash in the first place. This is detailed in Microsoft document “Mitigating Pass-the-Hash (PtH) Attacks and Other Credential Theft Techniques”. However, it is important to note that this provides only partial mitigation as detailed in our blog post “Windows Update to Fix Pass-the-Hash Vulnerability? Not!”.
  5. Ensuring that Windows-based computers in the enterprise are updated with the kb2871997 patch, in which several protections had been introduced to make it harder for the attacker to steal the NTLM hashes.
  6. If using Windows Server 2012 R2 Domain Functional Level (DFL) domains, add privileged users as members of the newly added Protected Users group. This will disable RC4-HMAC usage in Kerberos for these users. Note that this measure is suitable only for privileged users since the Protected Users group imposes many other restrictions on its members.

Microsoft’s Recommendation

  1. Use a smart card authentication and second,
  2. Remove the weaker encryption (i.e. RC4-HMAC) from the systems.

Article Resources

Aorato Blog Detailing Microsoft Weakness

http://www.aorato.com/blog/active-directory-vulnerability-disclosure-weak-encryption-enables-attacker-change-victims-password-without-logged/

Microsoft in Talks to Buy Israeli Cybersecurity Firm Aorato

http://online.wsj.com/articles/microsoft-in-talks-to-buy-israeli-cybersecurity-firm-aorato-1405430773


77 percent of IT staffers have incorrectly reported the cause of a security incident http://www.scmagazine.com/survey-77-percent-of-it-staffers-have-incorrectly-reported-the-cause-of-a-security-incident/article/360993/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Ensure your organization has an incident response plan in the case of a data breach
    1. Incident Response Team
    2. Public Relations Strategy
    3. Legal Team
    4. Possibly Data Breach Insurance

Article Resources

2014 Emulex Visibility Survey

http://www.emulex.com/media-center/media-center-home/press-releases/story/?tx_news_pi1[news]=566&cHash=b9dbbcbde3fe8791bfe1e26610b2c3df


Oracle releases 113 bug fixes in Critical Patch Update http://www.scmagazine.com/oracle-releases-113-bug-fixes-in-critical-patch-update/article/361039/

http://www.securityweek.com/security-updates-java-7-will-work-windows-xp-oracle

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Oracle support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  5. Perform an asset inventory of all systems running Oracle components .
  6. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

View Details

“You are not your resume, you are your work.”

– Seth Godin


Chinese man charged with hack of Boeing, Lockheed Martin aircraft data http://www.scmagazine.com/chinese-man-charged-with-hack-of-boeing-lockheed-martin-aircraft-data/article/360786/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  5. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  6. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  7. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

The CBC News Article Containing the US District Court Complaint

http://www.cbc.ca/news/canada/british-columbia/su-bin-chinese-man-accused-by-fbi-of-hacking-in-custody-in-b-c-1.2705169

USTR Special 301 Report

http://www.ustr.gov/sites/default/files/USTR%202014%20Special%20301%20Report%20to%20Congress%20FINAL.pdf

2012 Network Computing Top Eight SIEM Vendors

http://www.networkcomputing.com/careers-and-certifications/how-the-top-eight-siem-vendors-stack-up/d/d-id/1233787?

C-IT Security Podcast May 1st

http://www.c-itsecurity.com/?p=42


DropCam Vulnerable To Hijacking http://www.darkreading.com/dropcam-vulnerable-to-hijacking/d/d-id/1297275?

Researchers at the 2014 DEF CON conference will provide a demonstration of taking over a DropCam video surveillance system in a popular WiFi video monitoring system.

DropCam is a web based video monitoring system homes, daycares, and small businesses to provide both live monitoring and cloude based recording for customers of the product.

The weaknesses in the video surveillance system could allow an attacker to view video and listen to audio from cameras connected to the system to spy on the targets. The system also has a vulnerability that enables attackers to inject their own video frames into the DropCam feed or freeze frames in order to hide malicious activity, such as a physical break-in.

The DropCam vulnerabilities are yet another example of the inherent risks of IP-based consumer devices, a.k.a. the Internet of Things. The security industry is increasingly concerned about flaws in embedded software in devices like these web cameras because many of these which run older software that may not even receive updates.

C-IT Recommendation

From the Customer Perspective

  1. Ensure your company has a test environment to introduce all new tools/devices and that security is involved in performing an assessment of the new acquisitions.
  2. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  3. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  4. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.

From the Supplier Perspective

  1. Find out if your Information Technology organization has Security embedded into the Software Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
  2. Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
  3. Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
  4. Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.

Article Resources

About DEF CON

https://www.defcon.org/html/links/dc-faq/dc-faq.html

About Dropcam

https://www.dropcam.com/small-business-security

Toward a Trusted Supply Chain: A Risk Based Approach to Managing Software Integrity White Paper

http://download.microsoft.com/download/9/B/D/9BD9FBFF-A1D9-4DA9-954C-EAE9242C689D/Toward%20a%20Trusted%20Supply%20Chain%20white%20paper.pdf

Critical Infrastructure Protection: Concepts and Continuum White Paper

http://download.microsoft.com/download/4/6/8/4688D909-116C-480A-A398-703B30C7D7B3/CIP-continuum.pdf


Kronos: New Financial Malware Sold on Russian Underground Forum http://www.securityweek.com/kronos-new-financial-malware-sold-russian-underground-forum

http://www.csoonline.com/article/2453634/data-protection/new-banking-malware-kronos-advertised-on-underground-forums.html

http://www.scmagazine.com/fraudsters-market-new-malware-kronos-on-underground/article/360779/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.

View Details

“ Progress comes from the intelligent use of experience. ”

— Elbert Hubbard


Hotel Business Centers Fall Victim to Key Logger Malware http://krebsonsecurity.com/2014/07/beware-keyloggers-at-hotel-business-centers/

Government recommendations

  1. Display a banner to users when logging onto business center computers; this should include warnings that highlight the risks of using publicly accessible machines.
  2. Create individual, unique log on credentials for access to both business center computers and Wi-Fi; this may deter individuals who are not guests from logging in.
  3. Give all accounts least privilege accesses; for example, guests logging in with the supplied user ID and password should not be able to download, install, uninstall or save files whereas one authorized employee may have a need for those privileges to carry out daily duties.
  4. Create virtual local area networks (VLANs) for all users, which will inhibit attackers from using their computer to imitate the hotel’s main server.
  5. Scan all new devices (e.g. USB drives and other removable media) before they are attached to the computer and network; disabling the auto run feature will also prevent removable media from opening automatically.
  6. Establish pre-determined time limits for active and non-active guest and employee sessions.
  7. Select safe defaults in the browsers available on the business center desktops (e.g. Internet Explorer, Mozilla Firefox). Options such as private browsing and “do not track” for passwords and websites are some of the many available.

Article Resources

http://www.dhs.gov/about-national-cybersecurity-communications-integration-center

AAHOA Lodging Business Article

http://www.aahoalodging.biz/industry-news/Feds+Issue+Advisory+on+Malware+in+Hotel+Biz+Centers/524


Security not prioritized in critical infrastructure, though most admit compromise http://www.scmagazine.com/study-security-not-prioritized-in-critical-infrastructure-though-most-admit-compromise/article/360538/

C-IT Recommendation

  1. If your organization business includes power plants, oil or gas refineries, telecommunications facilities, transportation, or water and waste control, it will most likely be using SCADA equipment. If not consult with your HVAC, telecom and facilities department and perform an asset inventory of your SCADA equipment. CMDB should include product manufacturers.
  2. Ensure your company has policies and procedures to maintain the asset inventory to include all scada systems and each piece of industrial equipment controlled by the scada technology
  3. Disable the Web Service. Disabling the HTTPS service and still maintaining manageability on the device can be accomplished in a number of ways. Manage the device through a command line service like SSH, or use a Device Cloud account to centrally manage all the devices. Further, if HTTPS service is enabled and on a public IP on the Internet, restrict or disable the HTTPS web interface to specific IPs.
  4. Check Services.
  5. Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
  6. Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
  7. When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
  8. Remove, disable or rename any default system accounts wherever possible.
  9. Implement account lockout policies to reduce the risk from brute forcing attempts.
  10. Establish and implement policies requiring the use of strong passwords.
  11. Monitor the creation of administrator level accounts by third-party vendors.
  12. Apply patches in the ICS environment, when possible, to mitigate known vulnerabilities.

Article Resources

Critical Infrastructure: Security Preparedness and Maturity Report

http://www.unisys.com/unisys/inc/pdf/misc/14-0316.pdf


Cyber Information Sharing Act Draws Uncertainty and Criticism http://www.infosecurity-magazine.com/view/39259/cyber-information-sharing-act-draws-uncertainty-and-criticism/

Article Resources

Draft of the Cyber Information Sharing Act

http://www.feinstein.senate.gov/public/index.cfm/files/serve/?File_id=08de1c1b-446b-478c-84a8-0c3f35963216

Senator Mark Udall’s Opposition to the Bill

http://www.markudall.senate.gov/?p=press_release&id=4370

View Details

“The best executive is the one who has sense enough to pick good men to do what he wants done, and self-restraint enough to keep from meddling with them while they do it.”

-Theodore Roosevelt


Hackers Attack Shipping and Logistics Firms Using Malware-Laden Handheld Scanners http://www.securityweek.com/hackers-attack-shipping-and-logistics-firms-using-malware-laden-handheld-scanners

C-IT Security Recommendation

From the product development perspective

  1. Find out if your Information Technology organization has Security embedded into the Product Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
  2. Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
  3. Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
  4. Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individual’s who have vetted the change and identified the risks associated with the changes to be acceptable.

From the product purchaser perspective

  1. Ensure your company has a test environment to introduce all new tools/devices and that security is involved in performing an assessment of the new acquisitions.
  2. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  3. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  4. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.

Article Resources

TrapX Anatomy of the Attack:Zombie Zero

http://www.trapx.com/wp-content/uploads/2014/07/TrapX_ZOMBIE_Report_Final.pdf

Toward a Trusted Supply Chain: A Risk Based Approach to Managing Software Integrity White Paper

http://download.microsoft.com/download/9/B/D/9BD9FBFF-A1D9-4DA9-954C-EAE9242C689D/Toward%20a%20Trusted%20Supply%20Chain%20white%20paper.pdf

Critical Infrastructure Protection: Concepts and Continuum White Paper

http://download.microsoft.com/download/4/6/8/4688D909-116C-480A-A398-703B30C7D7B3/CIP-continuum.pdf


Cybersecurity Review Should Be a Core Part of M&A Deals http://www.infosecurity-magazine.com/view/39238/cybersecurity-review-should-be-a-core-part-of-ma-deals/

http://www.businesstimes.com.sg/premium/top-stories/cyber-risk-complacency-could-doom-ma-deals-study-20140710

C-IT Recommendation

  1. Perform an information security risk assessment to see if the partnering organization handles risk in accordance with your company’s risk appetite.

Gmail iOS app vulnerable to MitM attack, emails and credentials at risk http://www.scmagazine.com/gmail-ios-app-vulnerable-to-mitm-attack-emails-and-credentials-at-risk/article/360346/

http://www.securityweek.com/google-gmail-app-ios-doesnt-perform-certificate-pinning-researchers

Lacoon Mobile Security Recommendations

  1. Check the configuration profiles of devices in your enterprise to ensure that they do not include root certificates.
  2. Ensure that employees use a VPN or any other secure channel when connecting to enterprise resources.
  3. Perform on-device and network analysis to detect MitM attempts.

C-IT Recommendation

  1. Encourage your end users through your information security policy not to send company email to and from personal email counts.

Article Resources

Lacoon Mobile Security Security Disclosure: Google’s iOS Gmail App Potential Target for Threat Actors

http://www.lacoon.com/blog/2014/07/security-disclosure-googles-ios-gmail-app-enables-threat-actor/

View Details

“Hopeless cases: Executives who assert themselves by saying No when they should say Yes.”

-Malcolm Forbes


Attackers brute-force POS systems utilizing RDP in global botnet operation http://www.scmagazine.com/attackers-brute-force-pos-systems-utilizing-rdp-in-global-botnet-operation/article/360156/

http://www.securityweek.com/brutpos-botnet-targets-pos-systems-brute-force-attacks

http://www.csoonline.com/article/2451773/data-protection/botnet-brute-forces-remote-access-to-point-of-sale-systems.html

C-IT Recommendation

  1. Create new non-intuitive usernames for POS accounts. Disable the default usernames.
  2. Use Strong password for Terminal log in accounts and change them regularly
  3. Keep POS operating systems and POS Software Applications updated with the latest patches:
  4. Install a Firewall
  5. Ensure a solid Antivirus solution is running on the POS terminals
  6. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  7. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  8. Disallow Remote Access so that attackers cannot remotely access terminals
  9. Encrypt traffic between terminals, servers and payment card processor

Article Resources

FireEye Blog Post Detailing BrutPOS

http://www.fireeye.com/blog/technical/botnet-activities-research/2014/07/brutpos-rdp-bruteforcing-botnet-targeting-pos-systems.html

US-CERT Alert Malware Targeting Point of Sale Systems

https://www.us-cert.gov/ncas/alerts/TA14-002A


Fresh Android Vulnerability Affects 60% of Devices http://www.infosecurity-magazine.com/view/39215/fresh-android-vulnerability-affects-60-of-devices/

A vulnerability that could affect as many as 60% of Android devices connected to Google Play has been discovered that allows applications to carry out a variety of malicious activities without the permission of the users. Activities that can take place include placing phone calls (including premium-rate calls), terminating phone calls, listening to calls in progress and sending SMS texts.

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit malicious sites including pornographic sites. Also, instruct employees not to apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

Curesec blogpost Detailing the Android Vulnerability

http://blog.curesec.com/article/blog/35.htm


McAfee Plots Security Framework for Internet of Things http://www.infosecurity-magazine.com/view/39236/mcafee-plots-security-framework-for-internet-of-things/

View Details

“A man doesn’t need brilliance or genius, all he needs is energy.”

-Albert Monroe Greenfield


AV, anti-malware most used controls for APT defense http://www.scmagazine.com/study-av-anti-malware-most-used-controls-for-apt-defense/article/359932/

http://www.isaca.org/About-ISACA/Press-room/News-Releases/2014/Pages/ISACA-Global-APT-Survey.aspx

C-IT Recommendation

  1. Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
    1. Ensures your organization has a plan for Information Security
    2. Provides direction for developing information security policies, procedures, standards and guidelines
    3. Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior

Article Resources

NIST Cyber Security Framework

http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf

ISO\IEC 27001 Framework

http://www.iso.org/iso/catalogue_detail?csnumber=54534

ISACA COBIT

http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR


Vulnerability in AVG security toolbar puts IE users at risk http://www.csoonline.com/article/2451588/data-protection/vulnerability-in-avg-security-toolbar-puts-ie-users-at-risk.html

C-IT Recommendation

  1. Purchase Anti-Malware Software with support instead of using free anti-malware software
  2. Remove local administrative privileges from user machines
  3. When software is needed consider pushing software through install packages and not web client downloads

Adobe Push Critical Fixes http://krebsonsecurity.com/2014/07/microsoft-adobe-push-critical-fixes/

C-IT Recommendation

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.

Article Resources

Flash Version Verification

https://www.adobe.com/software/flash/about/

Flash Update Download Link

http://www.adobe.com/products/flashplayer/distribution3.html

View Details

“Lack of will power and drive cause more failure than lack of imagination and ability.”

-Dennis Mahon


Restaurants in Pacific Northwest Face Card Compromises http://www.infosecurity-magazine.com/view/39193/restaurants-in-pacific-northwest-face-card-compromises/

C-IT Recommendation

  1. Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
    1. Not having have total control
    2. Having your data protected by someone else
    3. Having your security managed by someone else
    4. Not having information about the cloud providers infrastructure
  2. As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
  3. Use Strong password for Terminal log in accounts and change them regularly
  4. Keep POS operating systems and POS Software Applications updated with the latest patches:
  5. Install a Firewall
  6. Ensure a solid Antivirus solution is running on the PoS terminals
  7. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  8. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  9. Disallow Remote Access so that attackers cannot remotely access terminals
  10. Encrypt traffic between terminals, servers and payment card processor

Article Resources

Information Systems and Supplies Letter to Customer Stores

http://docs.ismgcorp.com/files/external/iss_vancouver_breach.pdf

US-CERT Common Risks of Using Business Apps in the Cloud

http://www.us-cert.gov/sites/default/files/publications/using-cloud-apps-for-business.pdf

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf


Blue Shield leaks social security numbers http://www.csoonline.com/article/2450493/privacy/blue-shield-leaks-social-security-numbers.html

C-IT Recommendation

  1. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  2. Ensure your organization has a solid data handling policy which requires confidential data to be stored in secure, encrypted locations
  3. Consider a data loss prevention solution that will safeguard against intentional and unintentional misuse of sensitive data.

Article Resources

SANS Institute Data Loss Prevention White Paper

http://www.sans.org/reading-room/whitepapers/dlp/data-loss-prevention-32883


Dailymotion Video Sharing Site Hit With Malware Attack http://www.securityweek.com/dailymotion-video-sharing-site-hit-malware-attack

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Perform an asset inventory of all computers running Windows XP Operating system.
  8. Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
  9. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

From the Website Perspective

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Article Resources

Symantec Blog Post about Dailymotion’s Exploit

http://www.symantec.com/connect/blogs/dailymotion-compromised-send-users-exploit-kit

Securing Web Application Technologies [SWAT] Checklist

http://www.securingthehuman.org/developer/swat

View Details

“Ignorance is not innocence but sin.”

– Robert Browning


Spear phishers abuse Word programming feature to infect targets http://www.scmagazine.com/spear-phishers-abuse-word-programming-feature-to-infect-targets/article/359387/

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Cisco Blog “Threat Spotlight: A String of ‘Paerls’, Part One”

http://blogs.cisco.com/security/a-string-of-paerls/

Microsoft Support Frequently Asked Questions About Word Macro Viruses

https://support.microsoft.com/kb/187243/en

Microsoft’s Consumer security software providers

http://windows.microsoft.com/en-US/windows/antivirus-partners#AVtabs=win7


Israeli Defense Force in False Nuke Warning AfterTwitter Hack http://www.infosecurity-magazine.com/view/39164/israeli-defense-force-in-false-nuke-warning-after-twitter-hack/

http://www.securityweek.com/syrian-hacktivists-target-israel-defense-forces

C-IT Recommendation

  1. Ensure your domain hosting sites have strong secure passwords
  2. Ensure your social media manager and other content management teams have strong secure passwords. Those passwords should not be the same password as any of their other passwords including their personal email, or their business email.
  3. Ensure your login services have a log on attempt limit and locks out accounts after a certain amount of bad attempts.

Article Resources

Screenshot of the message posted by the Syrian Electronic Army

https://twitter.com/Official_SEA16/status/484806353341272064/photo/1

Screenshots of the Syrian Electronic Army gaining access to the Domain management console on the IDF’s Godaddy account

http://www.sea.sy/article/id/2041/en?utm_source=dlvr.it&utm_medium=twitter


Microsoft Plans Critical Internet Explorer, Windows Updates for Patch Tuesday http://www.securityweek.com/microsoft-plans-critical-internet-explorer-windows-updates-patch-tuesday

http://www.infosecurity-magazine.com/view/39162/critical-ie-and-windows-updates-slated-for-light-july-patch-tuesday/

C-IT Recommendation

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  5. Perform an asset inventory of all computers running Windows XP Operating system.
  6. Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.

Article Resources

Microsoft Security Bulletin Advance Notification for July 2014

https://technet.microsoft.com/library/security/ms14-jul

Microsoft Security Bulletin Webcast

http://technet.microsoft.com/security/dn756352

View Details

“Things done well and with a care, exempt themselves from fear. ”

— William Shakespeare


Brazilian ‘Bolware’ Gang Targeted $3.75B in Transactions, RSA finds http://www.scmagazine.com/brazilian-bolware-gang-targeted-375b-in-transactions-rsa-finds/article/359083/

http://www.securityweek.com/cybercriminals-may-have-stolen-billions-brazilian-boletos

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

RSA Bol-ware Whitepaper

https://blogs.rsa.com/wp-content/uploads/2015/07/Bolware-Fraud-Ring-RSA-Research-July-2-FINALr2.pdf

Man in the Browser Definition

http://searchsecurity.techtarget.com/definition/man-in-the-browser


New Android Malware Targets Banking Apps, Phone Information http://www.securityweek.com/new-android-malware-targets-banking-apps-phone-information-fireeye

http://www.infosecurity-magazine.com/view/39131/android-malware-paves-way-for-serious-banking-threat/

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

http://www.fireeye.com/blog/technical/malware-research/2014/07/the-service-you-cant-refuse-a-secluded-hijackrat.html


Researchers Disarm Microsoft’s EMET http://www.securityweek.com/researchers-disarm-microsofts-emet

C-IT Recommendation

  1. Deploy a defense in depth strategy for security
    1. Do not rely on one vendor to solve all your security issues
    2. Do not rely on one type of technology to solve all your security issues.

Article References

Offensive Security Video Demonstrating Disarment of Microsoft’s Enhanced Mitigation Experience Toolkit

http://vimeo.com/99658866

Offensive Security’s Blog on Disarming EMET

http://www.offensive-security.com/vulndev/disarming-enhanced-mitigation-experience-toolkit-emet/

Microsoft’s Enhanced Mitigation Experience Toolkit

http://www.microsoft.com/en-us/download/details.aspx?id=41138

Exploit Code for Disarming EMET

http://www.exploit-db.com/exploits/33944/

View Details

“Working on the right thing is probably more important than working hard.”

—Caterina Fake


Houston Astros hacked, trade conversations posted online http://www.scmagazine.com/houston-astros-hacked-trade-conversations-posted-online/article/358952/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  5. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  6. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  7. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

Houston Astros Exposed Conversations

http://anonbin.com/753432515

http://anonbin.com/2412624498

Houston Chronicle Article: Astros GM Jeff Luhnow addresses trade leaks, Deadspin

http://blog.chron.com/ultimateastros/2014/06/30/astros-gm-jeff-luhnow-addresses-trade-leaks-deadspin/#22102101=0


P.F. Chang’s Hit With Class Action Lawsuit Over Data Breach http://www.securityweek.com/pf-changs-hit-class-action-lawsuit-over-data-breach

http://www.scmagazine.com/pf-changs-hit-with-class-action-lawsuit-following-breach/article/358909/

C-IT Recommendations

  1. Ensure your organization has an incident response plan in the case of a data breach
    1. Incident Response Team
    2. Public Relations Strategy
    3. Legal Team
    4. Possibly Data Breach Insurance

Article Resources

P.F. Chang’s Lawsuit Courtroom Paperwork

http://media.scmagazine.com/documents/83/13186094-0–21770_20721.pdf

Definition of injunction

http://www.law.cornell.edu/wex/injunction

Definition of Declaratory judgment

http://www.law.cornell.edu/wex/declaratory_judgment

Experian Data Breach Response Guide

http://www.experian.com/assets/data-breach/brochures/response-guide.pdf


Payment Services, Financial Industry Top List of Phishing Targets http://www.securityweek.com/payment-services-financial-industry-top-list-phishing-targets-research

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Phishlabs Data Analysis of Phishing Targets

http://blog.phishlabs.com/banks-epayment-top-list-of-phishing-kit-targets

View Details

“Don’t be cocky. Don’t be flashy. There’s always someone better than you.”

—Tony Hsieh


‘Lite Zeus’ has fewer tricks, but updated encryption http://www.scmagazine.com/lite-zeus-has-fewer-tricks-but-updated-encryption/article/358593/


EMOTET banking malware captures data sent over secured HTTPS connections http://www.scmagazine.com/emotet-banking-malware-captures-data-sent-over-secured-https-connections/article/358586/

http://www.securityweek.com/emotet-banking-malware-steals-data-network-sniffing

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a malware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

US-CERT Alert on Game over Zeus

http://www.us-cert.gov/ncas/alerts/TA14-150A

Trend Micros blog regarding the issue

http://blog.trendmicro.com/trendlabs-security-intelligence/new-banking-malware-uses-network-sniffing-for-data-theft/


Microsoft Darkens 4MM Sites in Malware Fight http://krebsonsecurity.com/2014/07/microsoft-darkens-4mm-sites-in-malware-fight/

View Details

“I knew that if I failed I wouldn’t regret that, but I knew the one thing I might regret is not trying.”

—Jeff Bezos


Rare SMS worm targets Android devices http://www.csoonline.com/article/2369336/rare-sms-worm-targets-android-devices.html

C-IT Recommends

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Stronly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

Adaptive Mobile Detail Analysis on

http://www.adaptivemobile.com/blog/selfmite-worm

US CERT Defending Cell Phones and PDAs Against Attack

https://www.us-cert.gov/ncas/tips/ST06-007


Most health care vendors earn ‘D’ in data protection, study finds http://www.scmagazine.com/most-health-care-vendors-earn-d-in-data-protection-study-finds/article/358280/

C-IT Recommendation

  1. Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
    1. Ensures your organization has a plan for Information Security
    2. Provides direction for developing information security policies, procedures, standards and guidelines
    3. Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
  2. Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.

  3. Material to be covered

    1. Current Risks (including potential severity and probability)
    2. Emerging Risks (including potential severity and probability)
    3. Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
    4. Monitoring Progress of Risk Handling

Article resources

The Unlocked Back Door to Healthcare Data Report

http://www.vendorsecurityrm.com/resources/healthcare-vendor-intelligence-report/

NIST Cyber Security Framework

http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf

ISO\IEC 27001 Framework

http://www.iso.org/iso/catalogue_detail?csnumber=54534

ISACA COBIT

http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR


PlugX RAT Armed With ‘Time Bomb’ Leverages Dropbox In Attack http://www.darkreading.com/cloud/plugx-rat-armed-with-time-bomb-leverages-dropbox-in-attack/d/d-id/1278946?

C-IT Recommendation

  1. Evaluate the organizational risks for allowing users in your organization to use online document sharing sites such as dropbox, Google drive, Microsoft One Drive. Understand once the information leaves your organization you no longer have controls. This evaluation should include input from your core business leaders, the legal department and the information technology and security leadership.
  2. Make an organizational decision to whether or not you will allow users to store files on online document sharing sites.
  3. Ratify a data storage policy that explicitly addresses your directives for storing files on online document sharing sites.
  4. If you decide to disallow users to use online document sharing sites, you may want to consider blocking those sites on your web content filter appliance.
  5. Evaluate the total cost of ownership and return on investment for deploying tools that manage ShadowIT

Article Resources

Shadow IT Definition

http://searchcloudcomputing.techtarget.com/definition/shadow-IT-shadow-information-technology

CIO Magazine “How to Bring Shadow IT Under Control” Article

http://www.cio.com/article/746441/How_to_Bring_Shadow_IT_Under_Control

Trend Micro Blog Detailing PlugX RAT

http://blog.trendmicro.com/trendlabs-security-intelligence/plugx-rat-with-time-bomb-abuses-dropbox-for-command-and-control-settings/

View Details

“Anything that is measured and watched, improves.”

—Bob Parsons


US airports compromised during major APT hacking campaign, says CIS http://www.csoonline.com/article/2369043/us-airports-compromised-during-major-apt-hacking-campaign-says-cis.html

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Article Resources

Center for Internet Security 2013 Annual Report

http://www.cisecurity.org/about/documents/2013AnnualReportspreads.pdf


Insider Threats Top Infosecurity Europe Attendees’ Cyber Fears http://www.infosecurity-magazine.com/view/39035/insider-threats-top-infosecurity-europe-attendees-cyber-fears/

http://www.csoonline.com/article/2385000/security-awareness/security-awareness-and-concern-are-both-on-the-rise-among-it-professionals.html

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Emory Technology Education on Phishing

http://it.emory.edu/security/security_awareness/phishing.html

Lancope Survey Results

http://www.lancope.com/files/Blog/Lancope-Infosecurity-Europe-2014-Survey-Results.pdf

Lancope Combating Insider Threat Webinar

http://www.lancope.com/resource-center/recorded-webinars/insider-threat-hunting-for-authorized-evil/


US Oil & Gas Industry Establishes Information Sharing Center http://www.infosecurity-magazine.com/view/39024/us-oil-gas-industry-establishes-information-sharing-center/

http://www.darkreading.com/analytics/threat-intelligence/oil-and-natural-gas-industry-forms-isac/d/d-id/1278885?

Article Resources

http://www.momentumpress.net/books/protecting-industrial-control-systems-electronic-threats

View Details

“Every day that we spent not improving our products was a wasted day.”

—Joel Spolsky


Montana Notifying 1.3 Million After State Health Agency Server Hacked http://www.securityweek.com/montana-notifying-13-million-after-state-health-agency-server-hacked

http://www.csoonline.com/article/2367661/montana-data-breach-exposed-13-million-records.html

C-IT Recommendation

  1. Verify your company has an effective and enforced access control standard and policy which defines roles and baselines for system administrators. Ensure the standard and policy expresses that access should be removed when an employee transfers within the organization or leaves the organization.
    1. Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
    2. Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
      1. ex: Database Administrator should not have the rights of the Operating System Administrator
  2. Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.
  3. Utilize job rotation, and mandatory vacations for all privileged roles. Job rotation allows administrators to
    1. understand that someone else is stepping in to perform the job responsibilities and may be able to detect malicious behavior and consequently deter the administrator’s malicious behavior
  4. Utilize dual control (separation of duties) for highly sensitive activities.

    1. Ex: The individual who makes changes in production source code hand off their changes to someone else for installation control.
    2. This deters malicious behavior as each individual knows an honest employee may detect the behavior
  5. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.

  6. Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
  7. Consult your Risk Management team to see if your company has any cybersecurity insurance.
  8. If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.

Article Resources

Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)

http://csrc.nist.gov/groups/SNS/rbac/

Separation of duty definition

http://www.pcmag.com/encyclopedia/term/51110/separation-of-duties

NIST Computer Security Incident Handling Guide

http://csrc.nist.gov/publications/nistpubs/800-61rev2/SP800-61rev2.pdf


‘Luuuk’ Cybercrime Operation Steals €500,000 From Bank http://www.securityweek.com/luuuk-cybercrime-operation-steals-%E2%82%AC500000-bank

http://www.darkreading.com/luuuk-stole-half-million-euros-in-one-week/d/d-id/1278845?

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Man in the browser attack definition

http://searchsecurity.techtarget.com/definition/man-in-the-browser

Securelist technical description of Luuuk attack

http://www.securelist.com/en/blog/8230/Use_the_force_Luuuk


‘Havex’ malware strikes industrial sector via watering hole attacks http://www.scmagazine.com/havex-malware-strikes-industrial-sector-via-watering-hole-attacks/article/357875/

http://www.securityweek.com/attackers-using-havex-rat-against-industrial-control-systems

C-IT Recommendation

From the end-user perspective

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
  2. Identify all devices which have the vulnerable versions of Adobe Flash Player
  3. Deploy the Adobe security update to test machines in your environment
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted
  6. Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.

From the Website Perspective

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

View Details

“Your reputation is more important than your paycheck, and your integrity is worth more than your career.”

— Ryan Freitas


Caphaw trojan being served up to visitors of AskMen.com, according to Websense http://www.scmagazine.com/caphaw-trojan-being-served-up-to-visitors-of-askmencom-according-to-websense/article/357631/

http://www.securityweek.com/askmen-compromised-distribute-financial-malware-report

C-IT Recommendation

From the end-user perspective

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
  2. Identify all devices which have Windows Operating Systems
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.

From the Website Perspective

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Content Widget Maker Taboola Is Hacked On Reuters http://www.darkreading.com/content-widget-maker-taboola-is-hacked-on-reuters/d/d-id/1278792?

http://www.scmagazine.com/taboola-hack-allows-sea-to-redirect-reuters-site-visitors/article/357375/

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them. Additionally educate your users not to use the same username and passwords across multiple systems. Encourage the use of a strong password manager to keep passwords distinct and manageable.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes

Article Resources

Taboola’s Breach Disclosure

http://taboola.com/blog/update-taboola-security-breach-identified-and-fully-resolved-0

PC Magazine’s Review of the Best Password Managers

http://www.pcmag.com/article2/0,2817,2407168,00.asp


HackingTeam tool makes use of mobile malware targeting all major platforms http://www.scmagazine.com/hackingteam-tool-makes-use-of-mobile-malware-targeting-all-major-platforms/article/357652/

http://www.csoonline.com/article/2367682/data-protection/hackingteam-mobile-pc-spyware-for-governments-spans-many-countries.html

View Details

“ Progress is the activity of today and the assurance of tomorrow. ”

— Ralph Waldo Emerson


Domino’s extortion breach highlights rise in ransom-based attacks http://www.scmagazine.com/dominos-extortion-breach-highlights-rise-in-ransom-based-attacks/article/355997/

http://www.csoonline.com/article/2364323/cyber-attacks-espionage/domino-s-pizza-large-breach-with-a-side-of-ransom.html

http://www.securityweek.com/dominos-pizza-refuses-extortion-demand-after-customer-data-stolen

http://www.infosecurity-magazine.com/view/38876/dominos-pizza-customers-exposed-after-massive-data-breach/

C-IT Recommendation

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
  5. Consider purchasing a web application firewall

New Remote Access Trojan Bypasses SSL Protection, Targets Bank Credentials http://www.securityweek.com/new-rat-bypasses-ssl-protection-targets-bank-credentials-phishme

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes

Phishme Recommendations

  1. Remove above emails from inboxes

  2. Check your proxy logs for traffic to Cubby, downloading zip files containing the name “documents” or “invoice”

  3. Search for traffic / block the IPs 85.25.148.6, 217.12.207.151, and 192.99.6.61

  4. IDS rules looking for double POST within a short period of time (this will catch copy cats, too)

  5. Look for zip files containing .exe or .scr files (web, IDS, host-based, etc)

Article Resources

Phishme article detailing Project Drye Malware

http://phishme.com/project-dyre-new-rat-slurps-bank-credentials-bypasses-ssl/


Why businesses should use caution with HTML5-based mobile apps http://www.csoonline.com/article/2364322/data-protection/why-businesses-should-use-caution-with-html5-based-mobile-apps.html

C-IT Recommendation

  1. Ensure your company is using a strong Web Code review process before publishing mobile apps
  2. Use a software code security analysis tool to check your mobile apps for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your mobile apps.
  4. If apps are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Article Resources

Mobile Security Conference Paper on HTML5 Attacks

http://mostconf.org/2014/papers/s3p5.pdf

Mobile Security Conference Slides on HTML5 Attacks

http://mostconf.org/2014/slides/s3p5-slides.pptx

Gartner report on Hybrid Mobile Apps

http://www.gartner.com/newsroom/id/2324917

View Details

“People will forget what you said, people will forget what you did, but people will never forget how you made them feel.”

– Maya Angelou


Target top security officer reporting to CIO seen as a mistake http://www.csoonline.com/article/2363210/data-protection/target-top-security-officer-reporting-to-cio-seen-as-a-mistake.html

C-IT Recommendation

  1. Analyze the reporting structure of your organization
    1. Interview your CISO and ask him or her where it is optimal in your organization to report. Ask questions such as “Do you believe security priorities have been bottlenecked by the current reporting structure?”
  2. If necessary, move CISO’s reporting structure directly into a top level officer or directly to a top level board

Article Resources

Who should the CISO report to?

http://www.csoonline.com/article/2131227/infosec-staffing/who-should-the-ciso-report-to-.html

The Global State of Information Security® Survey 2014

http://www.pwc.com/GX/EN/CONSULTING-SERVICES/INFORMATION-SECURITY-SURVEY/INDEX.JHTML


Android ‘SMS Stealer’ hides in World Cup-themed apps http://www.scmagazine.com/android-sms-stealer-hides-in-world-cup-themed-apps/article/355717/

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit pornographic sites. Also, instruct employees not to apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

View Details

“Vigilance is not only the price of liberty, but of success of any sort.”

-Henry Ward Beecher


P.F. Chang’s Confirms Credit Card Breach http://krebsonsecurity.com/2014/06/p-f-changs-confirms-credit-card-breach/

Article Resources

P.F. Chang’s Security Compromise Update

http://pfchangs.com/security/


PLXsert warns Fortune 500 companies of evolving Zeus threat http://www.scmagazine.com/plxsert-warns-fortune-500-companies-of-evolving-zeus-threat/article/355543/

http://www.infosecurity-magazine.com/view/38832/zeus-used-to-mastermind-ddos-and-attacks-on-cloud-apps/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
  8. Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
    1. Not having have total control
    2. Having your data protected by someone else
    3. Having your security managed by someone else
    4. Not having information about the cloud providers infrastructure
  9. As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised

Prolexic Mitigation Recommendation

  1. Users are tricked into running programs that infest their devices, so organizational security policies and user education can help. Enforce security policies for system security and patches and updates. Educate users about how this type of attack is executed from email clients and web browsers.
  2. Clean-up effort by the security community is fundamental. Initiatives such as ZeuS Tracker are necessary to contain and manage this threat. Takedown follow-up efforts must also be implemented to reduce the number of infected command and control centers.
  3. Learn how to prevent, detect and remove Zeus infections. Symantec Security Response provides extensive information to help you do this.
  4. Write Snort rules for Zeus traffic. Sourcefire VRT Labs has an excellent source for writing Snort rules based on Zeus traffic.

Article Resources

Prolexic Zeus Crimeware Breaches Cybersecurity Defenses of Fortune 500 Advisory

http://www.prolexic.com/knowledge-center-ddos-threat-advisory-zeus-zbot-malware-crimeware-kit-cybersecurity.html

ZeuS Tracker (tracks ZeuS Command&Control servers around the world and provides you a domain- and a IP-blocklist)

https://zeustracker.abuse.ch/


Ransomware “Svpeng” strikes US, leaves Android devices unusable http://www.scmagazine.com/ransomware-svpeng-strikes-us-leaves-android-devices-unusable/article/355530/

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit non business related sites on company issued phones. Also, instruct employees not to download apps from unofficial stores

If you do not have a mobile device management solution in a BYOD model, Stronly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

Details of Sveng Mobile malware

http://www.securelist.com/en/blog/8227/Latest_version_of_Svpeng_targets_users_in_US

View Details

“If you really want to do something, you’ll find a way. If you don’t, you’ll find an excuse.”

–Jim Rohn


P.F. Chang’s Investigates Possible Breach of Customer Credit Cards http://www.securityweek.com/pf-changs-investigates-possible-breach-customer-credit-cards

http://www.infosecurity-magazine.com/view/38818/pf-changs-may-have-leaked-info-on-thousands-of-credit-cards-/

http://krebsonsecurity.com/2014/06/banks-credit-card-breach-at-p-f-changs/


Survey respondents praise, but neglect, continuous monitoring http://www.scmagazine.com/survey-respondents-praise-but-neglect-continuous-monitoring/article/355322/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  5. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  6. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  7. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

Ponemon Institute SQL Injection Threat Study

http://www.dbnetworks.com/pdf/ponemon-the-SQL-injection-threat-study.pdf


Small businesses running cloud-based POS software hit with unique ‘POSCLOUD’ malware http://www.scmagazine.com/small-businesses-running-cloud-based-pos-software-hit-with-unique-poscloud-malware/article/355301/

C-IT Recommendation

  1. Perform a risk analysis for utilizing cloud based services. Understand your limitations of using the cloud including
    1. Not having have total control
    2. Having your data protected by someone else
    3. Having your security managed by someone else
    4. Not having information about the cloud providers infrastructure
  2. As a result, Ensure your legal department has a strong SLA and breach accountability agreement with the cloud provider in case critical company or customer data is compromised
  3. Use Strong password for Terminal log in accounts and change them regularly
  4. Keep POS operating systems and POS Software Applications updated with the latest patches:
  5. Install a Firewall
  6. Ensure a solid Antivirus solution is running on the PoS terminals
  7. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  8. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  9. Disallow Remote Access so that attackers cannot remotely access terminals
  10. Encrypt traffic between terminals, servers and payment card processor

Article Resources

IntelCrawler Cloud-Based POS Software – “New Target for Hackers?”

http://intelcrawler.com/intel/webpos.pdf

US-CERT Common Risks of Using Business Apps in the Cloud

http://www.us-cert.gov/sites/default/files/publications/using-cloud-apps-for-business.pdf

View Details

“An amazing thing, the human brain. Capable of understanding incredibly complex and intricate concepts. Yet at times unable to recognize the obvious and simple.”

-Jay Abraham


Cybercrime Costs Businesses More than $400 Billion Globally: Report http://www.securityweek.com/cybercrime-costs-businesses-more-400-billion-globally-report

http://www.csoonline.com/article/2361011/security0/annual-cost-of-cybercrime-hits-near-400-billion.html

http://www.darkreading.com/worldwide-cost-of-cybercrime-estimated-at-$400-billion/d/d-id/1269527?

C-IT Recommendation

  1. Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
    1. Ensures your organization has a plan for Information Security
    2. Provides direction for developing information security policies, procedures, standards and guidelines
    3. Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior
  2. Corporate leaders must establish a security debrief cadence with the information security teams. CSOs/CISO’s should meet with operational teams weekly to understand internal security risks. CSO/CISO’s should then meet with CFOs, CEOs, CIOs monthly or bi-weekly to communicate priority risks to the business. Executives should be prepared to provide feedback and decisions to the information security organizations.
    1. Material to be covered
      1. Current Risks (including potential severity and probability)
      2. Emerging Risks (including potential severity and probability)
      3. Plan to address Risks (Avoidance, Mitigation, Transfer, Acceptance)
      4. Monitoring Progress of Risk Handling

Article Resources

Center for Strategic and International Studies (CSIS) Report “Net Losses:Estimating the Global Cost of Cybercrime”

http://www.mcafee.com/us/resources/reports/rp-economic-impact-cybercrime2.pdf


Chinese cyberspies targeting U.S, European defense, space sectors http://www.csoonline.com/article/2361425/cyber-attacks-espionage/chinese-cyberspies-targeting-u-s-european-defense-space-sectors.html

http://www.infosecurity-magazine.com/view/38785/second-chinese-pla-hacking-unit-unmasked-in-putter-panda-report/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts from bad reputation IP addresses from countries on the watch list.
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  5. Ensure your organization has a solid data storage policy which requires confidential data to be stored in secure, encrypted locations
  6. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  7. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

Crowdstrike putter Panda report

http://resources.crowdstrike.com/putterpanda/

Countering Adversaries Part 1: Espionage and Stolen Credentials

https://www.brighttalk.com/webcast/5385/104705


Scammers Trick Thousands of Twitter Users with ‘Follower’ Bait http://www.infosecurity-magazine.com/view/38776/scammers-trick-thousands-of-twitter-users-with-follower-bait/

http://www.darkreading.com/attacks-breaches/tweetdeck-scammers-steal-twitter-ids-via-oauth/d/d-id/1269503?

C-IT Recommendation

  1. Evaluate your organizations social media presence. If your social media department is using Tweetdeck to manage its twitter account, uninstall TweetDeck and reauthorize it.
  2. run a security scan to check for malware on any devices they used to log into Twitter.

Article Resources

BitDefender Blog on the Twitter Scam

http://www.hotforsecurity.com/blog/scammers-abuse-twitter-features-trick-thousands-with-follower-scheme-9202.html

View Details

“We can evade reality but we cannot evade the consequences of evading reality.”

–Ayn Rand


RIG Exploit Kit Used to Deliver “Cryptowall” Ransomware http://www.securityweek.com/rig-exploit-kit-used-deliver-cryptowall-ransomware

http://www.infosecurity-magazine.com/view/38751/malvertising-and-cryptowall-mark-the-appearance-of-the-rig-exploit-kit-/

C-IT Recommendation

  1. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  2. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates. Consider visiting the Cisco systems site to add the identified sites to your web content filters blacklist, which will block the malicious sites.
  3. Thoroughly educate your end users on safe website browsing. Communicate to them that they should only be utilizing the internet to access legitimate sites which support the accomplishing of their job responsibilities.
  4. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes.
  5. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit.
  6. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  7. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  8. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  9. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  10. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  11. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
  12. If you are using WordPress, enforce strong password policy requiring login to be complex with at least eight characters, lower case, uppercase and symbols.

Article Resources

Cisco Systems RIG Exploit Kit Strikes Oil Blog

https://blogs.cisco.com/security/rig-exploit-kit-strikes-oil

US-CERT Alert (TA13-309A): CryptoLocker Ransomware Infections

http://www.us-cert.gov/ncas/alerts/TA13-309A

McAfee Blog: What is a “Drive-By” Download?

https://blogs.mcafee.com/consumer/drive-by-download

US-CERT Alert (TA14-150A): GameOver Zeus P2P Malware (Tools for Removal)

https://www.us-cert.gov/ncas/alerts/TA14-150A


What to avoid in Dropbox-related phishing attack http://www.csoonline.com/article/2360670/malware-cybercrime/what-to-avoid-in-dropbox-related-phishing-attack.html

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
  8. Evaluate the organizational risks for allowing users in your organization to use online document sharing sites such as dropbox, google drive, Microsoft One Drive. Understand once the information leaves your organization you no longer have controls. This evaluation should include input from your core business leaders, the legal department and the information technology and security leadership.
  9. Make an organizational decision to whether or not you will allow users to store files on online document sharing sites.
  10. Ratify a data storage policy that explicitly addresses your directives for storing files on online document sharing sites.
  11. If you decide to disallow users to use online document sharing sites, you may want to consider blocking those sites on your web content filter appliance.

Article Resources

Phishme Blog “An inside look at Dropbox phishing: Cryptowall, Bitcoins, and You”

http://phishme.com/inside-look-dropbox-phishing-cryptowall-bitcoins/

US- CERT Security Tip (ST04-014): Avoiding Social Engineering and Phishing Attacks

http://www.us-cert.gov/ncas/tips/ST04-014


Microsoft preps seven fixes, two critical, for Patch Tuesday release http://www.scmagazine.com/microsoft-preps-seven-fixes-two-critical-for-patch-tuesday-release/article/351559/

C-IT Recommendation

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.

View Details

“To see what is right and not do it is a lack of courage.”

–Confucius


Seven vulnerabilities addressed in OpenSSL update, one enables MitM attack http://www.scmagazine.com/seven-vulnerabilities-addressed-in-openssl-update-one-enables-mitm-attack/article/351323/

http://www.securityweek.com/new-mitm-vulnerability-plagues-client-server-versions-openssl

C-IT Recommendation

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
  2. Identify all devices which have the vulnerable versions of OpenSSL both on the workstation and servers
  3. Deploy the OpenSSL updates to test machines in your environment
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted
  6. Finally, as always it is good practice to run a vulnerability scan against the devices to ensure the vulnerability has been addressed.

Article Resources

OpenSSL Security Advisor

http://www.openssl.org/news/secadv_20140605.txt


Attackers hide in plain sight using data-sharing apps http://www.scmagazine.com/report-attackers-hide-in-plain-sight-using-data-sharing-apps/article/351314/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Palo Alto Networks 2014 Application Usage and Threat Report

https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/white-papers/Application_Usage_Threat_Report_2014.pdf

Microsoft Security Intelligence Report: What is a Botnet?

http://www.microsoft.com/security/sir/story/default.aspx#!botnetsection


How to Integrate Security into Core Business Processes http://www.infosecurity-magazine.com/view/38694/how-to-integrate-security-into-core-business-processes/

Article Resources

Information Security Forum

https://www.securityforum.org/

View Details

“For success, attitude is equally as important as ability.”

-Harry F. Banks


Android/Simplocker could be the first Android ransomware to encrypt files http://www.scmagazine.com/androidsimplocker-could-be-the-first-android-ransomware-to-encrypt-files/article/350070/

http://www.securityweek.com/new-ransomware-encrypts-android-files-eset

http://www.infosecurity-magazine.com/view/38716/experts-discover-fileencrypting-android-ransomware/

C-IT Recommendation

  1. Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
  2. Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
  3. Provide mobile device security awareness informing your employees not to visit suspicious sites. Also, instruct employees not to apps from unofficial stores.

If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money

Article Resources

ESET Simplocker Explanation

http://www.welivesecurity.com/2014/06/04/simplocker/?utm_source=dlvr.it&utm_medium=twitter

US-CERT Security Tip: Cybersecurity for Electronic Devices

https://www.us-cert.gov/ncas/tips/ST05-017


Hackers distribute banking malware through Buffalo site in Japan http://www.csoonline.com/article/2359426/hackers-distribute-banking-malware-through-buffalo-site-in-japan.html

C-IT Recommendation

If your company is hosting files

  1. Ensure your company is using a strong Web Code review process before publishing sites
  2. Use a software code security analysis tool to check your website for potential vulnerabilities
  3. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  4. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
  5. Review your security measures for the storage of files available for public download. Consider having an alerting mechanism when any changes are made to files in storage repositories available to your customer base

If your company downloads files:

  1. Ensure your anti-malware solution scans files for malicious software upon download of a file

Article Resources

The complete list of malicious downloads is:

airnavi2_160.exe

airnavilite-1330.exe

airnavi-1272.exe

airnavi-1040.exe

airnavi-1030.exe

kokiinst-160.exe

drivenavi_cbu2_100.exe

ls_series-168.exe

hp6v131.exe

bsbt4d09bk_21630.exe


NIST Publishes Second Draft of Federal IT Supply Chain Risk Management Guidelines http://www.securityweek.com/nist-publishes-second-draft-federal-it-supply-chain-risk-management-guidelines

C-IT Recommendation

  1. Find out if your Information Technology organization has Security embedded into the Software Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
  2. Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
  3. Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
  4. Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.

Article Resources

Microsoft Updated Cybersecurity Papers on Supply Chain Security and Critical Infrastructure Protection

http://blogs.technet.com/b/security/archive/2014/05/06/revised-cybersecurity-papers-on-supply-chain-security-and-critical-infrastructure-protection.aspx

View Details

“Restlessness and discontent are the first necessities of progress.”

-Thomas A. Edison


Soraya Malware Mixes Capabilities of Zeus and Dexter to Target Payment Card Data http://www.securityweek.com/soraya-malware-mixes-capabilities-zeus-and-dexter-target-payment-card-data

http://www.scmagazine.com/soraya-malware-targets-payment-card-data-on-pos-devices-and-home-computers/article/349880/

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints including POS terminals are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Use strong password for terminal log in accounts and change them regularly
  8. Install a local firewall
  9. Restrict access to internet. POS devices should not be allowed to access the internet
  10. Disallow remote access to the point of sales terminals
  11. Encrypt traffic between terminals, servers and payment card processor
  12. Remove local administrative privileges for users who do not need those local privileges
  13. Harden point of sales terminals to only allow services to run that are absolutely necessary to process transactions
  14. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Arbor Networks Security Report on Soraya

http://www.arbornetworks.com/asert/2014/06/the-best-of-both-worlds-soraya/

US-CERT Malware Targeting Point of Sale Systems Advisory

https://www.us-cert.gov/ncas/alerts/TA14-002A

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf


Amex to notify Calif. customers of card dump linked to Anonymous http://www.scmagazine.com/amex-to-notify-calif-customers-of-card-dump-linked-to-anonymous/article/349888/

C-IT Recommendation

  1. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  2. Ensure your organization has a security incident investigation process that includes discovering breach, and disclosing the breach. Validate your process aligns with the requirements of your regions regulations.
  3. Consult your Risk Management team to see if your company has any cybersecurity insurance.
  4. If you have coverage, ensure the organization has performed an information security risk assessment to see if the current coverage is adequate for your company’s risk appetite. If you do not have coverage, consider performing an information security risk assessment to transfer potential financial loss in case there is a need to pay for forensic investigations, credit monitoring, reputation management, business interruption, and compliance with state breach notification laws in the case of a data breach.

Article Resources

American Express’s California Incident Reporting Document

https://oag.ca.gov/system/files/Recovered%20-%20Anonymous-C2014030241%20CA%20AG%20Letter_0.pdf

NetDiligence® 2013 Cyber Liability & Data Breach Insurance Claims: A Study of Actual Claim Payouts

http://www.netdiligence.com/files/CyberClaimsStudy-2013.pdf


Security Vulnerabilities Patched in WordPress SEO Plugin http://www.securityweek.com/security-vulnerabilities-patched-wordpress-seo-plugin

C-IT Recommendation

  1. Consult with your web teams to determine if your organization is using Word Press and the All in One SEO pack for any of its website content hosting. If so, download the current version of the the SEO pack (v.2.1.6)
  2. Ensure your company is using a strong Web Code review process before publishing sites
  3. Use a software code security analysis tool to check your website for potential vulnerabilities
  4. Require your security team to perform penetration testing after any code changes to your externally facing websites.
  5. If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved

Article Resources

Securi Blog on the Word press SEO Plugin

http://blog.sucuri.net/2014/05/vulnerability-found-in-the-all-in-one-seo-pack-wordpress-plugin.html

All in One SEO Pack Plugin Download Details

https://wordpress.org/plugins/all-in-one-seo-pack/

View Details

“Truth is the cry of all, but the game of the few.”

-George Berkeley


Gameover Zeus, CryptoLocker Hit in Massive Takedown Operation http://www.securityweek.com/gameover-zeus-cryptolocker-hit-massive-takedown-operation

http://www.infosecurity-magazine.com/view/38670/international-law-enforcement-sinkhole-gameover-zeus-and-cryptolocker-botnets/

http://www.csoonline.com/article/2358623/data-protection/businesses-can-do-more-in-battle-against-gameover-zeus-like-botnets.html

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints including POS terminals are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

The U.S. Department of Justice Briefing on the Case

http://www.justice.gov/opa/gameover-zeus.html

US-CERT Advisory: GameOver Zeus P2P Malware

https://www.us-cert.gov/ncas/alerts/TA14-150A


New Heartbleed Attack Vectors Impact Enterprise Wireless, Android Devices http://www.securityweek.com/new-heartbleed-attack-vectors-impact-enterprise-wireless-android-devices

C-IT Recommendation

  1. Ensure your organization has a strong asset inventory with an accurate configuration management database.
    1. Android device running 4.1.0 or 4.1.1
      1. Avoid connecting to unknown wireless networks unless you upgrade your ROM.
    2. Linux system/device
      1. Make sure to upgrade your OpenSSL libraries to non vulnerable versions
    3. Corporate wireless solutions
      1. Examine your EAP based authentication mechanisms. Having equipment tested and contacting your device vendor and ask for more information.

Article Resources

Heartbleed and Wireless Presentation

http://www.slideshare.net/lgrangeia/heartbleed-35236317

Patches for the Cupid Vulnerability

https://github.com/lgrangeia/cupid/

SysValue Detail Description of Cupid

http://www.sysvalue.com/en/heartbleed-cupid-wireless/

Heartbleed Details

http://heartbleed.com/


Microsoft Launches Cybersecurity Startup Accelerator Program in Israel http://www.securityweek.com/microsoft-launches-cybersecurity-startup-accelerator-program-israel


Palo Alto and Fortinet Team Up on Cyber Threat-sharing http://www.infosecurity-magazine.com/view/38668/palo-alto-and-fortinet-team-up-on-cyber-threatsharing/

View Details

Senate committee OKs bill to give DHS broader security hiring authority http://www.scmagazine.com/senate-committee-oks-bill-to-give-dhs-broader-security-hiring-authority/article/348427/

C-IT Recommendation

  1. Assess your organization’s security capability to handle events an incidents. If your organization currently
  2. Ensure your organization has a structure framework to address security. Frameworks provide a foundation to build effective security practices within an organization. Examples of frameworks include the National Institute of Standards and Technology Framework, International Organization for Standardization 27001, and Information System Audit and Control Association’s Control Objectives for IT.
    1. Ensures your organization has a plan for Information Security.
    2. Provides direction for developing information security policies, procedures, standards and guidelines
    3. Ensures organizations have administrative, physical and technical controls to deter, detect and/or prevent malicious behavior

Article Resources

The National Initiative for Cybersecurity Education (NICE) National Workforce Cybersecurity Framework

http://csrc.nist.gov/nice/framework/

NIST Cyber Security Framework

http://www.nist.gov/cyberframework/upload/cybersecurity-framework-021214.pdf

ISO\IEC 27001 Framework

http://www.iso.org/iso/catalogue_detail?csnumber=54534

ISACA COBIT

http://www.isaca.org/COBIT/Pages/default.aspx?cid=1003566&Appeal=PR


New Security Fears Over Keyboard and Trackpad Data Retention http://www.infosecurity-magazine.com/view/38560/new-security-fears-over-keyboard-and-trackpad- data-retention/

Article Resources

Privacy International

https://www.privacyinternational.org/about-us

View Details

“The measure of progress of civilization is the progress of the people.”

– George Bancroft


Sleeping companies lose big from employee, executive fraud http://www.csoonline.com/article/2158625/fraud-prevention/sleeping-companies-lose-big-from-employee-executive-fraud.html

http://www.darkreading.com/vulnerabilities—threats/insider-threats/privileged-use-also-a-state-of-mind-report-finds/d/d-id/1269145?

C-IT Recommendations

  1. Set up a fraud reporting hotline educate employees on the kind of activity considered fraudulent to eliminate any grey areas.
  2. Verify your company has an effective and enforced access control standard and policy which defines roles and baselines for system administrators. Ensure the standard and policy expresses that access should be removed when an employee transfers within the organization or leaves the organization.
    1. Roles should be specifically defined by the needs to perform the duties of the roles and only those duties
    2. Privileged access should granted to the roles and not to the individual users. Individual users should then be added to the roles according to their positions
      1. ex: Database Administrator should not have the rights of the Operating System Administrator
  3. Perform periodic access reviews for privileged account users. Any users or groups who are discovered to have unnecessary access should have privileged access be immediately removed.
  4. Utilize job rotation, and mandatory vacations for all privileged roles. Job rotation allows administrators to
    1. understand that someone else is stepping in to perform the job responsibilities and may be able to detect malicious behavior and consequently deter the administrator’s malicious behavior
  5. Utilize dual control (separation of duties) for highly sensitive activities.
    1. Ex: The individual who makes changes in production source code hand off their changes to someone else for installation control.
    2. This deters malicious behavior as each individual knows an honest employee may detect the behavior

Article Resources

Association of Certified Fraud Examiners 2014 Global Fraud Study

http://www.acfe.com/rttn/docs/2014-report-to-nations.pdf

“Fraud prevention: Improving Internal Controls”

http://www.csoonline.com/article/2127917/fraud-prevention/fraud-prevention–improving-internal-controls.html

Ponemon Institute Privileged User Abuse & The Insider Threat Report

http://www.trustedcs.com/resources/whitepapers/Ponemon-RaytheonPrivilegedUserAbuseResearchReport.pdf

Role Based Access Control (has links to other resources including the “Economic Benefits of Role Based Access Control”)

http://csrc.nist.gov/groups/SNS/rbac/


‘Nemanja’ POS malware compromises 1,500 devices, half a million payment cards, worldwide http://www.scmagazine.com/nemanja-pos-malware-compromises-1500-devices-half-a-million-payment-cards-worldwide/article/348183/

http://www.securityweek.com/most-2013-data-breaches-affected-e-commerce-and-pos-systems-trustwave

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs.
  2. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  3. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  4. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  5. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage vendor support if specific applications are negatively impacted.
  6. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  7. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Diluted Freedom Act passes House to privacy advocates’ dismay http://www.scmagazine.com/diluted-freedom-act-passes-house-to-privacy-advocates-dismay/article/348211/

View Details

“In business, what’s dangerous is not to evolve.”

-Jeff Bezos


eBay hacked, all users asked to change passwords http://www.scmagazine.com/ebay-hacked-all-users-asked-to-change-passwords/article/347967/

http://www.securityweek.com/after-cyberattack-ebay-recommends-password-change

http://www.infosecurity-magazine.com/view/38528/researchers-blast-ebay-over-data-breach/

http://www.darkreading.com/attacks-breaches/ebay-database-hacked-with-stolen-employee-credentials-/d/d-id/1269093?

http://www.csoonline.com/article/2158083/data-protection/how-to-protect-your-company-from-an-ebay-like-breach.html

C-IT Recommendation

  1. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that is capable of block incoming attempts of malicious activity
  2. Verify your security appliances are reporting to a Security Information and Event Management tool (SIEM) that correlates events and displays intelligible information to security analysts.
  3. Validate your organization has an efficient Security Operations Center (SOC) of which trained analysts are trained to alert on potential malicious events or malicious sources.
  4. Ensure your entity has a log management standard, policy and procedure that addresses
    1. Log retention- ensuring that all computer logs can be accessed in the case of an investigation
    2. Log reviews- enabling the possible early detection of events based upon irregular log entries
  5. Consider using two-factor authentication for your customer base to minimize the probability of accounts being compromised
  6. Verify your company has an effective and enforced data classification standard which requires data owners to seriously assess data sensitivity and requires data custodians to properly secure the information to need-to-know only basis.
  7. Perform periodic access reviews for data stores and applications housing highly classified or confidential information to ensure appropriate access is enforced. Any users or groups who are discovered to have access and don’t have a need to have access should be immediately removed.
  8. Confirm network segmentation in your environment so that only required devices are able to access networks where highly classified or confidential data resides.

Article Resources

SANS Article “What is the Role of a SIEM in Detecting Events of Interest?”

http://www.sans.org/security-resources/idfaq/siem.php

NIST Guide to Computer Security Log Management

http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf

Ebay blog announcement

https://blog.ebay.com/ebay-inc-ask-ebay-users-change-passwords/

Ebay Frequently Asked Questions Concerning the Breach

http://www.ebayinc.com/in_the_news/story/faq-ebay-password-change


DHS: Control system of U.S. utility company hacked http://www.scmagazine.com/dhs-control-system-of-us-utility-company-hacked/article/347990/

http://www.securityweek.com/ics-cert-report-highlights-industrial-control-system-security-failures

C-IT Recommendation

  1. If your organization business includes power plants, oil or gas refineries, telecommunications facilities, transportation, or water and waste control, it will most likely be using SCADA equipment. If not consult with your HVAC, telecom and facilities department and perform an asset inventory of your SCADA equipment. CMDB should include product manufacturers.
  2. Ensure your company has policies and procedures to maintain the asset inventory to include all scada systems and each piece of industrial equipment controlled by the scada technology
  3. Disable the Web Service. Disabling the HTTPS service and still maintaining manageability on the device can be accomplished in a number of ways. Manage the device through a command line service like SSH, or use a Device Cloud account to centrally manage all the devices. Further, if HTTPS service is enabled and on a public IP on the Internet, restrict or disable the HTTPS web interface to specific IPs.
  4. Check Services. If any HTTPS services have been implemented within Python, please evaluate the code and make sure that it is not impacted. If shell scripting uses the OpenSSL commands, please ensure to mitigate the Heartbeat TLS extension.
  5. Minimize network exposure for all control system devices and/or systems, and ensure that they are not accessible from the Internet.
  6. Locate control system networks and remote devices behind firewalls, and isolate them from the business network.
  7. When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize that VPN is only as secure as the connected devices.
  8. Remove, disable or rename any default system accounts wherever possible.
  9. Implement account lockout policies to reduce the risk from brute forcing attempts.
  10. Establish and implement policies requiring the use of strong passwords.
  11. Monitor the creation of administrator level accounts by third-party vendors.
  12. Apply patches in the ICS environment, when possible, to mitigate known vulnerabilities.

Article Resources

C-IT Podcast on Industrial Control System News

http://www.c-itsecurity.com/?p=91

Industrial Control Systems Computer Emergency Response Team January -April Newsletter

http://ics-cert.us-cert.gov/sites/default/files/Monitors/ICS-CERT_Monitor_%20Jan-April2014.pdf

Industrial Control Systems Computer Emergency Response Team Defense in Depth Principles

http://ics-cert.us-cert.gov/sites/default/files/recommended_practices/Defense_in_Depth_Oct09.pdf


IBM Chokes Off APTs with Trusteer Apex Launch http://www.infosecurity-magazine.com/view/38521/ibm-chokes-off-apts-with-trusteer-apex-launch/

C-IT Recommendation

  1. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  2. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  3. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  4. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  5. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  6. Perform an asset inventory of all computers running Windows XP Operating system.
  7. Develop a deployment plan to upgrade all Windows XP OS systems to a Microsoft supported OS or purchase additional support for your Windows XP machines from Microsoft to receive Microsoft XP patch releases.
  8. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Ponemon Institute 2014 Cost of Data Breach Study News release

http://www-03.ibm.com/press/us/en/pressrelease/43825.wss


Study finds payment card info most compromised, breach detection lags http://www.scmagazine.com/study-finds-payment-card-info-most-compromised-breach-detection-lags/article/347997/


Microsoft Silverlight bugs added to Angler Exploit Kit, trojans delivered via malvertising http://www.scmagazine.com/microsoft-silverlight-bugs-added-to-angler-exploit-kit-trojans-delivered-via-malvertising/article/348001/

C-IT Recommendation

  1. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  2. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  3. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  4. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  5. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  6. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  7. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  8. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.

Article Resources

Cisco Security blog on the Angler Exploit

http://blogs.cisco.com/security/angling-for-silverlight-exploits/

CVE-2013-0074

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0074

View Details

“Most people do not listen with the intent to understand; they listen with the intent to reply.”

– Stephen Covey


Man pleads guilty to selling compromised POS systems, loading up Subway gift cards http://www.scmagazine.com/man-pleads-guilty-to-selling-compromised-pos-systems-loading-up-subway-gift-cards/article/347146/

http://www.securityweek.com/former-subway-franchise-owner-pleads-guilty-pos-system-hacking

C-IT Recommendation

  1. Use Strong password for Terminal log in accounts and change them regularly
  2. Keep POS operating systems and POS Software Applications updated with the latest patches:
  3. Install a Firewall
  4. Ensure a solid Antivirus solution is running on the PoS terminals
  5. Restrict Access to Internet. POS should not be allowed to access the internet
  6. Disallow Remote Access so
  7. Encrypt traffic between terminals, servers and payment card processor

Article Resources

US-CERT Malware Targeting Point of Sale Systems Advisory

https://www.us-cert.gov/ncas/alerts/TA14-002A

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf

Retailers join forces to share threat intelligence

http://www.scmagazine.com/retailers-join-forces-to-share-threat-intelligence/article/347215/

http://www.securityweek.com/retailers-share-cyber-threat-intelligence-through-new-retail-isac

http://www.csoonline.com/article/2156060/data-protection/how-retailers-can-boost-security-through-information-sharing.html

C-IT Recommendation

  1. Research security sharing communities your organization can participate in. Delegate someone from your organization to be a contributor and also a liason to the organization
  2. If no official organization exists, consider starting one of for your industry or your town’s key businesses to participate in.

Article Resources

Retail Cyber Intelligence Sharing Center

http://www.r-cisc.org/

Security for Business Innovation Council

http://www.emc.com/emc-plus/rsa-thought-leadership/sbic/index.htm


PayPal Fixes Vulnerabilities In MultiOrder Shipping Application http://www.securityweek.com/paypal-fixes-vulnerabilities-multiorder-shipping-application