Monday, August 6, 2018

Virus Attack - We have heard that before , how about this, the company expects the virus to Inflict 250 Million Loss in Revenue (does this get your attention?)




The world's largest makers of semiconductors and processors TSMC lost an entire day of production after several of its factories systems were halted by a computer virus in the middle of the ramp-up for chips to be used by Apple's future lines of iPhones.

TSMC expects the shutdown will result in shipment delays and additional costs, and estimated that two days of outages will impact revenue by about 3 percent (approx. 250 Million)


https://thehackernews.com/2018/08/tsmc-iphone-computer-virus.html

FREE - For would-be Pentesters and Hackers - How to Set up your own malware analysis lab with VirtualBox, INetSim and Burp


A Good starting point for would-be Pentesters and Hackers

https://blog.christophetd.fr/malware-analysis-lab-with-virtualbox-inetsim-and-burp/

You can have the best security controls in the world but, it will not help if, you do not understand the following statement - When an enterprise engages with a third party , they become responsible for that third party’s security controls.




ICBA Bancard Inc. subsidiary TCM Bank, a company that aids community banks in issuing credit cards to their customers, announced that the personal data of thousands of people who applied for credit cards with their local banks was exposed

The information that was leaked between early March and mid-July 2018 included the names, addresses, dates of birth and Social Security numbers of thousands of people across the more than 750 community banks that work with TCM Bank

In this instance, misconfiguration – a critical application-security risk – resulted in the a leak of customer information.

“When partnering with third parties, organizations cannot relieve themselves from the responsibility of security. In the eyes of the affected consumers, they provided the data to the organization and they hold that organization responsible.”




https://www.infosecurity-magazine.com/news/third-party-web-manager-exposes

Thursday, August 2, 2018

Last year was "Targeted Attack" and "Phishing". 2018 is the year of "Targeted Phishing Attack" (used in a "Sextortion" scam)

A key component of a targeted phishing attack is personalization. 

This uses a inverted  threat model: Most phishing campaigns try to steal your password, whereas this one leads with it.

On July 12 a new "sextortion" based phishing scheme began and tricked dozens of people into paying anywhere from a few hundred to thousands of dollars in Bitcoin. What spooked people was that its salutation included a password that each recipient legitimately used at some point online.

https://krebsonsecurity.com/2018/08/the-year-targeted-phishing-went-mainstream/

Wake-up call to those who still rely on SMS-based authentication and believes it is secure (don't give up, just replace SMS with OTP apps)


According to Reddit, the unknown hacker(s) managed to gain read-only access to some of its systems that contained its users' backup data, source code, internal logs, and other files

According to Slowe, the most significant data contained in the backup was account credentials (usernames and their corresponding salted and hashed passwords), email addresses and all content including private messages.

The hack was accomplished by intercepting SMS messages that were meant to reach Reddit employees with one-time passcodes, eventually circumventing the two-factor authentication (2FA) Reddit had in place attacks.

https://thehackernews.com/2018/08/hack-reddit-account.html

Wednesday, August 1, 2018

SmartHome (meaning, home loaded with IoT) is the new craze. So far IoT manufacturers have not been concerned about security so, what can we do to protect our home.

What is the relationship between google and Dragonfly? - Dragonfly is Censored Google Search Engine for China


Since spring last year Google engineers have been secretly working on a project, dubbed "Dragonfly," which currently includes two Android mobile apps named—Maotai and Longfei—one of which will get launched by the end of this year after Chinese officials approve it

The mobile app reportedly aims to "blacklist sensitive queries" and filter out all websites (news, human rights, democracy, religion) blocked by the Chinese government, including Wikipedia, BBC News, Instagram, Facebook, and Twitter.

Google will also blacklist words like human rights, democracy, religion and peaceful protests in Chinese of its search engine ap

 The censorship will also be embedded in Google's image search, spell check, and suggested search features, which eventually means the search engine will not display Chinese users potentially "sensitive" terms or images banned by their government.

https://thehackernews.com/2018/08/censored-google-search-china.html