Posts

Showing posts with the label aws

Top Five Most Infamous DDoS Attacks

Image
Guest article by Adrian Taylor, Regional VP of Sales for A10 Networks  Distributed Denial of Service (DDoS) attacks are now everyday occurrences. Whether you’re a small non-profit or a huge multinational conglomerate, your online services—email, websites, anything that faces the internet—can be slowed or completely stopped by a DDoS attack. Moreover, DDoS attacks are sometimes used to distract your cybersecurity operations while other criminal activity, such as data theft or network infiltration, is underway.  Why are DDoS attacks bigger and more frequent than ever? DDoS attacks are getting bigger and more frequent The first known Distributed Denial of Service attack occurred in 1996 when Panix, now one of the oldest internet service providers, was knocked offline for several days by an SYN flood, a technique that has become a classic DDoS attack. Over the next few years, DDoS attacks became common and  Cisco predicts that the total number of DDoS a...

Cyber Security Roundup for October 2019

Image
The UK National Cyber Security Centre (NCSC) released its annual review . The report showcases the NCSC successes with its core mission to make the UK the safest place to live and work online. The NCSC is certainly having a positive impact in helping British businesses of all sizes with their cyber defences, and with their excellent ' CyberFirst ' initiative, which encourages and supports youngsters into the cybersecurity professional. NCSC Annual Review 2019 The NCSC reported it had  "handled" 658 attacks on 900 organisations, including schools, airports and emergency services, with many attacks were "from hostile nation-states ".  The NCSC said cyberattacks from Russia, China, Iran and North Korea pose "strategic national security threats to the UK", and  also warned that "large-scale global cybercrime" was a threat to "our social fabric, our way of life and our economic prosperity", despite often being "low in sop...

Cyber Security Roundup for September 2019

Image
Anyone over the age of 40 in the UK will remember patiently browsing for holidays bargains on their TV via Teletext. While the TV version of Teletext Holidays died out years ago due to the creation of the world-wide-web, Teletext Holidays, a  trading name of Truly Travel,  continued as an online and telephone travel agent business.  Verdict Media discovered an unsecured Amazon Web Services Service (Cloud Server) used by Teletext Holidays and was able to access 212,000   call centre audio recordings with their UK customers. The audio recordings were taken between 10th April and 10th August 2016 and were found in a data repository called 'speechanalytics'. Businesses neglecting to properly secure their cloud services is an evermore common culprit behind mass data breaches of late. Utilising cloud-based IT systems does not absolve businesses of their IT security responsibilities at their cloud service provider.  Booking Holidays on Ceefax in the 1980s W...

Cyber Security Roundup for October 2018

Aside from Brexit, Cyber Threats and Cyber Attack accusations against Russia are very much on the centre stage of UK government's international political agenda at the moment.  The government publically accused Russia's military 'GRU' intelligence service of being behind four high-profile cyber-attacks , and named 12 cyber groups it said were associated with the GRU. Foreign Secretary Jeremy Hunt said, " the GRU had waged a campaign of indiscriminate and reckless cyber strikes that served no legitimate national security interest ". UK Police firmly believe the two men who carried out the Salisbury poisoning in March 2018 worked for the GRU. What is Russia's GRU Intelligence Agency? The risks of cyber-conflict with Russia Russia accused of net hack attacks Russian spy: What happened to the Skripals? The UK National Cyber Security Centre said it had assessed "with high confidence" that the GRU was "almost certainly responsible...

Cyber Security Roundup for March 2018

In the wake of the global political fallout over the Salisbury nerve agent attack, there are reports of a growing threat of Russian state or Russian state-affiliated hacking groups conducting cyber attack reprisals against UK organisations, government officials have directly warned bosses at electricity, gas and water firms, Whitehall departments and NHS hospitals to prepare for a state-sponsored cyber assault .  Russian group Fancy Bear (APT28) were suspected of being behind an unsuccessful attack against the UK anti-doping agency , and China tied hacking group APT15 were found to have infiltrated a UK government contractor’s computer systems by NCC researchers . Large-scale data breaches were disclosed with Under Armour’s Fitness App MyFitnessPal (1.5 million personal records compromised) , Orbitz (880k payment cards at risk) , and at a Walmart partner (1.3 million personal records compromised) . The latter was caused when an AWS S3 bucket holding a Walmart dat...

Cyber Security Roundup for January 2018

2018 started with a big security alert bang after Google Security Researchers disclosed serious security vulnerabilities in just about every computer processor in use on the planet.  Named 'Meltdown' and 'Spectre ’, when exploited by a hacker or malware, these vulnerabilities disclose confidential data. As a result, a whole raft of critical security updates was hastily released for computer and smartphone operating systems, web browsers, and processor drivers. While processor manufacturers have been rather lethargic in reacting and producing  patches for the problem, software vendors such as Microsoft, Google and Apple have reacted quickly, releasing security updates to protect their customers from the vulnerable processors, kudos to them. The UK Information Commission's Office (ICO) heavily criticised the Carphone Warehouse for security inadequacies and fined the company £400K following their 2015 data breach , when the personal data, includin...