Wednesday, October 11, 2017
Bank Heist - Reminds me of the song Smooth Criminal(s)
Interesting part is that this Targeted attack includes good coordination at physical and technical levels.
Hussey says his company investigated heists at five different banks in post-Soviet countries. Attackers made off with sums between $3 million and $10 million per bank, for a total of over $40 million
For More:
https://www.bleepingcomputer.com/news/security/bank-cyber-thieves-get-clever-with-new-overdraft-technique/
Microsoft Patch Tuesday - CVE-2017-11826 - patch it ASAP
Microsoft's October Patch Tuesday release covered a wide spectrum of problems with the majority possibly resulting in remote code execution (RCE) and CVE-2017-11826 being publicly disclosed and actively exploited
The early take from cyber industry insiders is CVE-2017-11826, found in Microsoft Office, needs to be immediately addressed
“Top priority for patching should go to a vulnerability in Microsoft Office, CVE-2017-11826, which Microsoft has ranked as “Important” is actively being exploited in the wild,” Jimmy Graham, director of product management at Qualys.
More Here:
https://www.scmagazine.com/patch-tuesday-microsoft-62-vulnerabilities-28-critical-one-spotted-in-the-wild/article/699296/
Tuesday, October 10, 2017
Did you know - Browsers are intermediaries in an online transaction
By moving the storage of payment card details in the browser, the responsibility of keeping these details safe is moved to the browser and the user.
The Payment Request API also demands that users take greater responsibility for their data security.
For More:
https://www.grahamcluley.com/browser-credit-cards/
Beware - New Phishing Attack
Cybercriminals are using a new phishing campaign that impersonates "secure messages" from private financial institutions such as Bank of America and TD Commercial banking to deliver malware to unsuspecting victims
More Here
http://www.ibtimes.co.uk/new-phishing-emails-claiming-be-secure-message-private-banks-secretly-deliver-malware-1641269?utm_content=61324933&utm_medium=social&utm_source=twitter
More Here
http://www.ibtimes.co.uk/new-phishing-emails-claiming-be-secure-message-private-banks-secretly-deliver-malware-1641269?utm_content=61324933&utm_medium=social&utm_source=twitter
Monday, October 9, 2017
Thursday, October 5, 2017
5 Tenets of Cyber Security
Sweet and Simple (but , rarely followed)
Your organization does not exist to be secure, it exists to get things done.
Amateurs mitigate risk, professionals manage risk. If you are confused by the difference, you need to read some of Bruce Schneier's books. There are three ways to manage risk: you mitigate it, you accept it or you transfer it
Risk is the likelihood of an incident times the harm of that incident. Likelihood is made up of Threats and Vulnerabilities
Our job is to support the organization's mission. That means when dealing with a cyber security challenge, you may not be the one to make a decision
Managing risk is based on three core areas: Technology, Process and People.
We have hit the point of diminishing returns with Technology but continue to fail in the Process and People side.
For More:
https://securingthehuman.sans.org/blog/2017/10/05/the-five-tenets-of-cyber-security/
Subscribe to:
Posts (Atom)
