Tuesday, July 14, 2015

Quad-core phones better than Octa-Core?



This is common knowledge for those who have followed server technology. Adding more processors does not mean increase in performance.


From the article:

As cores shut off, overall performance rises, particularly at the dual-core mode. With most of the chip offline, performance jumps. One potential conclusion that would explain these results is that applications are poorly threaded, which prevents them from taking advantage of higher core counts. But the fact that performance increases at the two core mark suggests something more fundamental at work — the chips in question are hitting their thermal trip points unless more cores are shut down.

As things stand, there are some benefits to quad-core devices and virtually no gains from octa-core. In a few cases, moving to more cores actually makes things worse.


For more info:

Friday, July 10, 2015

New event (that could have) happened at a ZOO near you - Credit Card Breach



Just be careful (I am not talking about the wild animals here)




From the article:
Service Systems Associates, a company that serves gift shops and eateries at zoos and cultural centers across the United States, has acknowledged a breach of its credit and debit card processing systems.

If a guest used a credit or debit card in the gift shop at one of our partner facilities between March 23 and June 25, 2015, the information on that card may have been compromised.”

At least two dozen cities, including:

Birmingham, Ala.
Tucson, Ariz.
San Francisco, Calif.
Fresno, Calif.
Sacramento, Calif.
Colorado Springs, Colo.
Palm Desert, Calif.
Miami, Fla.
Honolulu, HI
Boise, Id.
Fort Wayne, Ind.
Louisville, Ky.
Baltimore, Md.
Battle Creek, Mich.
Apple Valley, Minn.
Cincinnati, Ohio
Tulsa, Okla.,
Pittsburgh, Penn.
Columbia, SC
Dallas, Texas
El Paso, Texas
Houston, Texas
Nashville, Tenn.
Salt Lake City, Utah

For more info:

93 PERCENT OF CLOUD SERVICES IN HEALTHCARE ARE MEDIUM TO HIGH RISK


What else to say?


From the article:

  1. Only 7.0% of cloud services are enterprise ready
  2. Undetected Insider Threats
  3. Employee Passwords on the Loose - 14.4% of all healthcare employees have a login credential for sale online, exposing 89.2% of organizations
  4. The Most Prolific Cloud User - The average employee uses 26 cloud services, but the most prolific cloud user actually employs an impressive 444 cloud services including 97 collaboration services and 74 social media services. A surprising 30.6% of these services were high-risk – much greater than the industry average of 5.6%.


For more info:

Thursday, July 9, 2015

8 FREE TOOLS FOR PENTESTING


For those in IT Security, this is not new.
For the rest, this is a small and concise article 



  1.  Metasploit
  2.  Nessus Vulnerability Scanner
  3.  Nmap
  4.  Burp Suite
  5.  OWASP ZAP
  6.  SQLmap
  7.  Kali Linux
  8.  Jawfish



For More Info:
http://www.csoonline.com/article/2943524/data-protection/8-penetration-testing-tools-that-will-do-the-job.html#tk.rss_dataprotection

Sunday, July 5, 2015

Hackers Hacked - Confused?, A company that sells hacking tools has been hacked



Apparently, they know how to create hacking tools for government but, somehow failed to protect their data.

400 GB of data uploaded in torrent!!


From the article:
Hacking Team is now learning how it feels to have their internal matters exposed to the world.

Hacking Team is an Italian company that sells intrusion and surveillance tools to governments and law enforcement agencies.

Hacking Team's customers include South Korea, Kazakhstan, Saudi Arabia, Oman, Lebanon, and Mongolia. 

One such item is this invoice for 58,000 Euro to Egypt for Hacking Team's RCS Exploit Portal.

An invoice leaked with the Hacking Team cache shows that Ethiopia paid $1,000,000 Birr (ETB) for Hacking Team's Remote Control System, professional services, and communications equipment.


For more info.

Saturday, July 4, 2015

Harward University - Data Breach



Best business school does not automatically mean best security.


From the Article

Anne Margulies, Harvard’s vice president and chief information officer, sent a memo to students and faculty late Wednesday night that eight schools and administrative organizations may have been implicated in a June 19 breach.

As the breach appears to be largely email based the school is calling on certain students and faculty – anyone involved with the compromised schools – to change passwords associated with their @fas.harvard.edu accounts. 


For more info:
https://threatpost.com/june-harvard-breach-hit-multiple-schools/113601

Thursday, July 2, 2015

Windows 10 - Has WiFi Sense


Makes life little easier for users but, how secure will it be?
My concern is that it is enabled by default, I prefer the opposite.



From the Article:

If you wander close to a wireless network, and your friend knows the password, and you both have Wi-Fi Sense, you can now log into that network

Wi-Fi Sense doesn’t reveal the plaintext . The password must be stored centrally by Microsoft, and is copied to a device for it to work.

The password is sent over an encrypted connection and stored in an encrypted file on a Microsoft server, and then sent over a secure connection to your contacts' phone


In theory, someone who wanted access to your company network could befriend an employee or two, and drive into the office car park to be in range, and then gain access to the corporate wireless network.

Microsoft enables Windows 10's Wi-Fi Sense by default, and access to password-protected networks are shared with contacts unless the user remembers to uncheck a box when they first connect.  


For More information: