Posts

Showing posts from May, 2019

The Price of Loyalty, almost half of UK Office Workers are willing to sell Company's Information

Image
A new report  released by Deep Secure revealed 45% of office workers surveyed would sell their company's corporate information. Just £1,000 would be enough to tempt 25% of employees to give away company information, while 5% would give it away for free. 59% of staff admitted at some point to have taken company information from a corporate network or devices, which matches up to known industry trends.  What is the Price of Loyalty?   Common Staff Data Exfiltration Tactics Digital; email, uploading to cloud services and copying to external storage (11%) Using steganography or encryption tools to hide exfiltration (8%) Printing information (11%) Handwriting copying information (9%) Photographing information (8%) Type of Information Taken Personal Work (19%) Customer Information i.e. contact details, confidential market information, sales pipeline  (11%) Company Assets i.e. passwords to subscription services, company benefits (7%) The Mot...

UK Pub Chain 'Greene King' Gift Card Website Hacked

Image
Major UK pub chain, Greene King (Bury St. Edmunds), had its gift card website ( https://www.gkgiftcards.co.uk ) compromised by hackers. The personal data breach was discovered on 14th May 2019 and confirmed a day later. The pub, restaurant and hotel chain informed their impacted customers by email today (28th May 2019). Greene King said the hackers were able to access: name email address user ID encrypted password address post code The pub chain did not disclose any further details on how passwords were "encrypted", only to say within their customer disclosure email " Whilst your password was encrypted, it may still be compromised".  It is a  long established good industry coding practice for a website application's password storage to use a one-way 'salted' hash function, as opposed to storing customer plaintext passwords in an encrypted form . No details were provided on how the hackers were able to compromise the gift card website, but th...

The UK Government Huawei Dilemma and the Brexit Factor

Image
In the last couple of days, Google announced it will be putting restrictions on Huawei’s access to its Android operating system , massively threatening Huawei's smartphone market. Meanwhile,  UK based chip designer ARM has told its staff to suspend all business activities with Huawei , over fears it may impact ARM's trade within the United States.  Fuelling these company actions is the United States government's decision to ban US firms with working with Huawei over cybersecurity fears. The headlines this week further ramps up the pressure on the UK government to follow suit, by implementing a similar ban on the use of Huawei smartphones and network devices within the UK, a step  beyond their initial 5G critical infrastructure ban announced last month. But is this really about a foreign nation-state security threat? Or is it more about it geo-economics and international politicking? Huawei: A Security Threat or an Economic Threat? Huawei Backdoors It’s no ...

WhatsApp, Microsoft and Intel Chip Vulnerabilities

Quickly applying software updates (patching) to mitigate security vulnerabilities is a cornerstone of both a home and business security strategy. So it was interesting to see how the mainstream news media reported the disclosure of three separate ‘major’ security vulnerabilities this week, within WhatsApp, Microsoft Windows and Intel Processors. WhatsApp The WhatsApp security flaw by far received the most the attention of the media and was very much the leading frontpage news story for a day. The WhatsApp vulnerability ( CVE-2019-3568 ) impacts both iPhone and Android versions of the mobile messaging app, allowing an attacker to install surveillance software, namely,  spyware called Pegasus , which access can the smartphone's call logs, text messages, and can covertly enable and record the camera and microphone. From a technical perspective, the vulnerability ( CVE-2019-3568 ) can be exploited with a buffer overflow attack against WhatsApp's VOIP stack, this makes remote cod...

ZombieLoad: Researchers discover New Hardware Vulnerability in Modern Intel Processors

Image
A brand new processor hardware vulnerability affecting modern Intel CPUs has been uncovered by Bitdefender researchers  Coined "ZombieLoad side-channel processor", the vulnerability defeats the architectural safeguards of the processor and allows unprivileged user-mode applications to steal kernel-mode memory information processed on the affected computer. https://www.bitdefender.com/files/News/CaseStudies/study/257/Bitdefender-Whitepaper-YAM-en-EN.pdf A Concerning Impact on Cloud Services The new vulnerability can b e exploited by attackers to leak privileged information data from an area of the processor's memory meant to be strictly off-limits. This flaw could be used in highly targeted attacks that would normally require system-wide privileges or deep subversion of the operating system. The flaw has an extremely large impact on cloud service providers and within multi-tenant environments, as potentially a 'bad neighbour' could leverage this flaw to ...

Zavvi Champions League Final Competition Winner Email Blunder

Image
Like many Zavvi customers this morning, I received an email titled " Congratulations, you're our Mastercard Competition WINNER! " in my inbox. An amazing prize consisting of two tickets to watch Liverpool and Spurs battle it out in the 2019 UEFA Champions League Final in Madrid. The prize also included two nights at a 4-star hotel, flights, transfers and a £250 prepaid card. Zavvi Winners Email Obviously, my initial thought it was a phishing email, decent quality and a well-timed attempt given Liverpool and Tottenham Hotspur were confirmed as finalists after very dramatic semi-final matches on the previous nights. I logged into my Zavvi account directly, then reset my password just in case, and after a bit checking with the embedded links within the email, and research on the Zavvi website, I soon established it was a genuine email from Zavvi. But before embarking on a  Mauricio  Pochettino style injury-time winning goal celebration, I had a quick scan of my soc...

2019 Verizon Data Breach Investigations Report (DBIR) Key Takeaways

Image
The 2019 Verizon Data Breach Investigations Report (DBIR ) was released today, and I was lucky enough to be handed a hot off the press physical copy while at the Global Cyber Alliance Cyber Trends 2019 event at Mansion House, London. For me, the DBIR provides the most insightful view on the evolving threat landscape, and is the most valuable annual “state of the nation” report in the security industry. Global Cyber Alliance Cyber Trends 2019 The DBIR has evolved since its initial release in 2008, when it was payment card data breach and Verizon breach investigations data focused. This year’s DBIR involved the analysis of 41,686 security incidents from 66 global data sources in addition to Verizon. The analysed findings are expertly presented over 77 pages, using simple charts supported by ‘plain English’ astute explanations, reason why then, the DBIR is one of the most quoted reports in presentations and within industry sales collateral. DBIR 2019 Key Takeaways Financial g...

Top Tips On Cyber Security for SMEs

Guest article by Damon Culbert of Cyber Security Jobs Cyber criminals are a part of modern life, from Uber account hacks to major business data breaches, our online identities are rarely safe. And, while big-name companies under threat often make the news, it’s small and medium-sized enterprises who are actually their biggest targets. Large businesses and government departments may seem like more obvious hacking targets with bigger payoffs, but these organisations can afford much more robust, well-kept and successful IT security measures and cyber security professionals working round the clock. Due to this, cyber criminals are much more likely to swing for easy targets like family businesses. With the introduction of GDPR across Europe, all businesses are now much more responsible for the personal data they keep, meaning companies of all size can’t really afford to not have at least the basic security measures in place. The UK National Cyber Security Centre (NCSC) have created a list ...

Cyber Security Roundup for April 2019

Image
The UK government controversially gave a green light to Huawei get involved with the building of the UK's 5G networks , although the Chinese tech giant role will be limited to non-sensitive areas of the network, such as providing antennas. This decision made by Theresa May came days after US intelligence announced Huawei was Chinese state funded , and amidst reports historical backdoors in Huawei products, stoking up the Huawei political and security row even further this month, and has resulted in the UK Defence Secretary, Gavin Williamson, being sacked.  Defence Secretary Gavin Williamson sacked over Huawei leak Daily Telegraph publishes details of a meeting about using the Chinese telecoms firm to help build the UK's 5G network Huawei row: Inquiry to be held into National Security Council leak Is Huawei a Threat to UK National Security? What's the greater risk to UK 5G, Huawei backdoors or DDoS? Backdoors found in Huawei-supplied Vodafone e...