Tuesday, December 5, 2017

BEC - Business Email Compromise - Stats and Solution

5 computer security facts that surprise most people (including some IT Security Folks)



  1. Every company is hacked
  2. Most companies don’t know the way they are successfully attacked the most
  3. A criticality gulf exists between real and perceived threats
  4. Firewalls and antivirus software aren’t that important
  5. Two problems are almost 100 percent of the risk (unpatched software or a social engineering)


Remember: Most risks can be reduced with the following

  • Patch regularly
  • Use non-admin / root accounts for regular activities
  • Think before you CLICK
  • Never give away sensitive information over email or phone (unless you get it from reliable Search engines)



For More:
https://www.csoonline.com/article/3239644/data-breach/5-computer-security-facts-that-surprise-most-people.html#tk.twt_cso

Are you using one of the 33 eMail clients that could be exploited by MailSploit?


German security researcher Sabri Haddouche has discovered a set of vulnerabilities that he collectively refers to as Mailsploit, and which allow an attacker to spoof email identities, and in some cases, run malicious code on the user's computer



The real issue is the email spoofing attack that circumvents all modern anti-spoofing protection mechanisms such as DMARC (DKIM/SPF) or various spam filters.



The full list is given here:
https://docs.google.com/spreadsheets/d/1jkb_ZybbAoUA43K902lL-sB7c1HMQ78-fhQ8nowJCQk/htmlview?sle=true




For More:
https://blog.knowbe4.com/mailsploit-bypasses-dmarc-and-lets-attackers-send-spoofed-phishing-emails-on-over-33-email-clients

Could this be true or is it scaremongering - 100,000-strong botnet built on router 0-day could strike at any time



What sets this latest variant apart is its ability to exploit a recently discovered zeroday vulnerability to infect two widely used lines of home and small-office routers even when they're secured with strong passwords or have remote administration turned off altogether.




More Here:
https://arstechnica.com/information-technology/2017/12/100000-strong-botnet-built-on-router-0-day-could-strike-at-any-time

Monday, December 4, 2017

Malware (called Troubleshooter) can now perform (fake) Tech support functions.



It presents a fake BSOD (Blue Screen of Death) that appears to lock out the user. Then, a “troubleshooting wizard” pops up, masquerading as a Windows utility. It detects “issues” on the PC, and then recommends that the victim pony up $25 via PayPal to buy a package called Windows Defender Essentials to take care of them.

Malwarebytes said that it’s spreading via a cracked software installer that loads various files, including the malware. Troubleshooter then registers itself as a Windows service.

If a victim pays the $25, they are redirected to a “thank you” webpage and the malware is terminated

For More
https://www.infosecurity-magazine.com/news/tech-support-scam-malware-fake?utm_source=twitterfeed&utm_medium=twitter

Friday, December 1, 2017

STATS for RISK based security - IT professionals listed sysadmins as the biggest threat (42%) followed by C-level executives (16%).

While these executives typically have  limited IT skills, their credentials are worth more to hackers than any  other group.

Other targets:


  1. Social engineering - HR and finance departments are the easiest targets.
  2. Insider risk - IT staff.


For More:
https://www.infosecurity-magazine.com/news/it-staff-blame-themselves-for/

Could you be one of those 40,000 consumer whose sensitive data was exposed (NOT Stolen)



Some 111GB of highly sensitive information including consumer credit histories has been exposed by the National Credit Federation as the result of yet another misconfigured Amazon Web Services (AWS) S3 cloud storage bucket.


Although the leak affected only around 40,000 consumers, the data concerned is highly sensitive, including credit reports from the big three agencies — Equifax, Experian and TransUnion.


What is the most common response by organization- Add additional data/alert feed, Don't spend time filtering/prioritizing them, eventually ignore them (did it resolve the issue?).

More Here
https://www.infosecurity-magazine.com/news/100gb-secret-consumer-credit-data