Wednesday, October 11, 2017

Very Interesting conversation/debate on PASSWORDS - Highly recommended

Bank Heist - Reminds me of the song Smooth Criminal(s)



Interesting part is  that this Targeted attack includes good coordination at physical and technical levels.

Hussey says his company investigated heists at five different banks in post-Soviet countries. Attackers made off with sums between $3 million and $10 million per bank, for a total of over $40 million



For More:
https://www.bleepingcomputer.com/news/security/bank-cyber-thieves-get-clever-with-new-overdraft-technique/

Microsoft Patch Tuesday - CVE-2017-11826 - patch it ASAP



Microsoft's October Patch Tuesday release covered a wide spectrum of problems with the majority possibly resulting in remote code execution (RCE) and CVE-2017-11826 being publicly disclosed and actively exploited

The early take from cyber industry insiders is CVE-2017-11826, found in Microsoft Office, needs to be immediately addressed

“Top priority for patching should go to a vulnerability in Microsoft Office, CVE-2017-11826, which Microsoft has ranked as “Important” is actively being exploited in the wild,” Jimmy Graham, director of product management at Qualys.


 More Here:
https://www.scmagazine.com/patch-tuesday-microsoft-62-vulnerabilities-28-critical-one-spotted-in-the-wild/article/699296/

Tuesday, October 10, 2017

Did you know - Browsers are intermediaries in an online transaction



By moving the storage of payment card details in the browser, the responsibility of keeping these details safe is moved to the browser and the user.

The Payment Request API also demands that users take greater responsibility for their data security. 

For More:
https://www.grahamcluley.com/browser-credit-cards/

Beware - New Phishing Attack

 Cybercriminals are using a new phishing campaign that impersonates "secure messages" from private financial institutions such as Bank of America and TD Commercial banking to deliver malware to unsuspecting victims


More Here
http://www.ibtimes.co.uk/new-phishing-emails-claiming-be-secure-message-private-banks-secretly-deliver-malware-1641269?utm_content=61324933&utm_medium=social&utm_source=twitter

Thursday, October 5, 2017

5 Tenets of Cyber Security




Sweet and Simple (but , rarely followed)

Your organization does not exist to be secure, it exists to get things done.

Amateurs mitigate risk, professionals manage risk. If you are confused by the difference, you need to read some of Bruce Schneier's books. There are three ways to manage risk: you mitigate it, you accept it or you transfer it

Risk is the likelihood of an incident times the harm of that incident. Likelihood is made up of Threats and Vulnerabilities

Our job is to support the organization's mission. That means when dealing with a cyber security challenge, you may not be the one to make a decision


Managing risk is based on three core areas: Technology, Process and People.
We have hit the point of diminishing returns with Technology but continue to fail in the Process and People side.

For More:
https://securingthehuman.sans.org/blog/2017/10/05/the-five-tenets-of-cyber-security/