Posts

Weekly Infosec News Brief 7-13 August

Image
Malvertising Attacks Via Major Sites and Advertising Providers Persist Dynamic web advertisements containing malicious code are continuing to show up on major, reputable sites and advertising networks. The latest such attack announced involved malicious advertisements distributed through Yahoo's advertising network beginning in late July. In many ways, such malvertising attacks are becoming as big a threat as phishing attacks. The targeting capabilities of web advertising networks enable attackers to use such networks to aim their malware campaigns at users based on common attributes such as income, purchasing interests, etc. Proactive protection against exploits is the best solution, as well as limiting exposure to common web-based vulnerabilities such as Flash-based advertisements. http://www.scmagazine.com/hackers-spread-malware-via-yahoo-ads/article/437075/ http://www.scmagazine.com/drudge-report-other-high-traffic-websites-delivered-malware-over-three-week-period/article...

Weekly Infosec News Brief August 24-30

Image
Survey Shows Many Federal Government Workers Ignore Mobile Security Rules A survey by mobile security software vendor Lookout indicates that a large proportion of government employees ignore their agencies' rules concerning mobile devices, web services, and security. Twenty-four percent of respondents indicated they forwarded work documents to their personal email accounts, 17% used cloud-based file sharing services for work documents, and nearly half used their personal mobile devices for work documents, despite policies prohibiting these behaviors (and annual training to reinforce these policies). While it is important to have policies governing these types of employee behaviors, without technical controls to prevent or monitor them you are likely to experience high levels of non-compliance. https://www.lookout.com/resources/reports/federal-byod http://www.eweek.com/small-business/mobile-device-security-ignored-by-federal-workers.html Google to Configure Chrome Browser ...

Security Basics -- Privileged Account Management

Image
This post is one in a series of blog posts on the fundamentals of an information security program. You can see the complete list of posts in this series here . Account management is a basic security function, but not all accounts are created equal. Generally, any network or system has a few key accounts that have privileges or capabilities beyond those of "regular" users accounts. Administrative functions must be performed, and it is unavoidable that accounts and credentials for this purpose must exist. However, if these privileges are abused, the potential for destruction or loss is enormous. Administrative privileges can be abused by an insider who has rightful access to the account(s) in question, or the credentials may be compromised and used by a malicious outside attacker. Stealing or otherwise obtaining administrative credentials is one of the top objectives of any hacker upon gaining initial access to a system, because these will allow them to deepen and bro...

Weekly Infosec News Brief August 17-23

Image
New Security Information Sharing Organization for the Legal Industry Begins Operation The legal industry, facing increasing cyber threats and receiving increased client security demands, has followed the lead of many other industries in establishing a threat information sharing center. The Legal Services Information Sharing and Analysis Organization (LS-ISAO) began operating last week, with services provided by the long-standing Financial Services Information Sharing and Analysis Center (FS-ISAC). http://www.darkreading.com/perimeter/law-firms-form-their-own-threat-intel-sharing-group/d/d-id/1321846 https://www.fsisac.com/ls-isao Microsoft Issues Emergency Patch for Internet Explorer; Vulnerability Already Being Exploited Last Tuesday Microsoft issued a critical out-of-cycle patch for Internet Explorer to address a memory flaw (CVE-2015-2502) that could allow an attacker to execute code remotely against a victim system. The problem affects IE versions 7 through 11 on all Wi...

Weekly InfoSec News Brief August 10-16

Image
Microsoft Issues Fourteen Patches, Three for Critical Vulnerabilities Last week was the first "Patch Tuesday" since the full release of Windows 10, and sure enough the new OS gets six patches of its own (which are bundled into a single installer, so it's essentially impossible to pick and choose which of them you want to install). The critical vulnerabilities patched include one ( MS15-079 ) in Internet Explorer that could result in remote code execution from a malicious webpage, one in Office ( MS15-081 ) that could allow code execution from a malicious document, and yet another vulnerability in a Windows graphics component ( MS15-080 ) that could be exploited by a malicious font file (potentially embedded in a web page). MS15-081 https://technet.microsoft.com/en-us/library/security/ms15-aug.aspx http://www.computerworld.com/article/2970493/microsoft-windows/its-alive-patch-tuesday-survives-for-windows-10.html Adobe Issues Flash Updates, Patches 34 Vulnerabilit...

Security Basics: Full-Disk Encryption

Image
This post is one in a series of blog posts on the fundamentals of an information security program. You can see the complete list of posts in this series here . U.S. Healthworks, a California-based healthcare provider, reported a breach recently where a company laptop was stolen from an employee's car. The laptop drive was not encrypted, and it is believed that the personal information of a significant number of customers/patients was stored on this machine. This is an old, old story, heard many times over. The need to encrypt laptop hard drives first became widely publicized due to an incident in June of 2006 . An employee from the Department of Veteran's Affairs had a department laptop containing personal information on large numbers of veterans (as many as 26 million) at his home, and the laptop was stolen in a burglary. The most widely-recommended measure for reducing risk of data loss due to a lost or stolen computer is full-disk encryption. Once the drive is e...

Weekly InfoSec News Brief 3-9 August

Image
Serious Firefox Vulnerability Potentially Exposes Local Files to Unauthorized Access Last Thursday, Mozilla released a security update for FIrefox (v 39.0.3) to patch a serious vulnerability that was being actively exploited by hackers apparently out of Russia or Ukraine. The flaw is in the built-in PDF reader, allowing arbitrary JavaScript execution with access to the local file system. The flaw affects Firefox on all operating systems. This allowed the attackers to search for and upload files, and they used this capability to steal common files that would contain login information on Windows and Linux systems. If your organization runs Firefox at all, it is important to update to the latest version as soon as possible. https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/ http://arstechnica.com/security/2015/08/0-day-attack-on-firefox-users-stole-password-and-key-data-patch-now/ Yahoo's Ad Network Hijacked to Deliver Malware Malwarebytes di...