Posts

Showing posts with the label wannacry

Book Review: Crime Dot Com, From Viruses to Vote Rigging, How Hacking Went Global

Image
I had the great delight of reading Geoff White’s new book, “ Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global ”, I thoroughly recommend it. The book is superbly researched and written, the author’s storytelling investigative journalist style not only lifts the lid on the murky underground world of cybercrime but shines a light on the ingenuity, persistence and ever-increasing global scale of sophisticated cybercriminal enterprises. Crime Dot Com: From Viruses to Vote Rigging, How Hacking Went Global In Crime Dot Com Geoff takes the reader on a global historic tour of the shadowy cybercriminal underworld, from the humble beginnings with a rare interview with the elusive creator of the ‘Love Bug’ email worm, which caused havoc and panic back in 2000, right up to the modern-day alarming phenomenal of elections hacking by nation-state actors. The book tells the tales of the most notorious hacks in recent history, explaining how they were successfully planned a...

Passwords are and have always been an Achilles Heel in CyberSecurity

Image
LogMeOnce , a password identity management suite provider, has published a detailed interview with myself titled ' Passwords are and have always been an Achilles Heel in CyberSecurity '. In the Q&A I talk about Passwords Security (obviously), Threat Actors, IoT Security, Multi-Factor Authentication (MFA), Anti-Virus, Biometrics, AI, Privacy, and a bit on how I got into a career in Cybersecurity. Quotes “I’m afraid people will remain the weakest link in security, and the vast majority of cybercriminals go after this lowest hanging fruit. It’s the least effort for the most reward.” "There is no silver bullet with password security, but MFA comes close, it significantly reduces the risk of account compromise" "The built-in biometric authentication capabilities of smartphones are a significant advancement for security" "Cybercriminals go after this lowest hanging fruit, the least effort for the most reward." "As technology becomes more sec...

12 days of Christmas Security Predictions: What lies ahead in 2020

Image
Marked by a shortage of cyber security talent and attackers willing to exploit any vulnerability to achieve their aims, this year emphasised the need for organisations to invest in security and understand their risk posture. With the number of vendors in the cyber security market rapidly growing, rising standard for managing identities and access, and organisations investing more in security tools, 2020 will be a transformational year for the sector. According to Rob Norris, VP Head of Enterprise & Cyber Security EMEIA at Fujitsu: “We anticipate that 2020 will be a positive year for security, and encourage public and private sector to work together to bring more talent to the sector and raise the industry standards. As the threat landscape continues to expand with phishing and ransomware still popular, so will the security tools, leaving organisations with a variety of solutions. Next year will also be marked by a rush to create an Artificial Intelligence silver-bullet for cyber se...

The UK Government Huawei Dilemma and the Brexit Factor

Image
In the last couple of days, Google announced it will be putting restrictions on Huawei’s access to its Android operating system , massively threatening Huawei's smartphone market. Meanwhile,  UK based chip designer ARM has told its staff to suspend all business activities with Huawei , over fears it may impact ARM's trade within the United States.  Fuelling these company actions is the United States government's decision to ban US firms with working with Huawei over cybersecurity fears. The headlines this week further ramps up the pressure on the UK government to follow suit, by implementing a similar ban on the use of Huawei smartphones and network devices within the UK, a step  beyond their initial 5G critical infrastructure ban announced last month. But is this really about a foreign nation-state security threat? Or is it more about it geo-economics and international politicking? Huawei: A Security Threat or an Economic Threat? Huawei Backdoors It’s no ...

WhatsApp, Microsoft and Intel Chip Vulnerabilities

Quickly applying software updates (patching) to mitigate security vulnerabilities is a cornerstone of both a home and business security strategy. So it was interesting to see how the mainstream news media reported the disclosure of three separate ‘major’ security vulnerabilities this week, within WhatsApp, Microsoft Windows and Intel Processors. WhatsApp The WhatsApp security flaw by far received the most the attention of the media and was very much the leading frontpage news story for a day. The WhatsApp vulnerability ( CVE-2019-3568 ) impacts both iPhone and Android versions of the mobile messaging app, allowing an attacker to install surveillance software, namely,  spyware called Pegasus , which access can the smartphone's call logs, text messages, and can covertly enable and record the camera and microphone. From a technical perspective, the vulnerability ( CVE-2019-3568 ) can be exploited with a buffer overflow attack against WhatsApp's VOIP stack, this makes remote cod...

Cyber Security Roundup for April 2019

Image
The UK government controversially gave a green light to Huawei get involved with the building of the UK's 5G networks , although the Chinese tech giant role will be limited to non-sensitive areas of the network, such as providing antennas. This decision made by Theresa May came days after US intelligence announced Huawei was Chinese state funded , and amidst reports historical backdoors in Huawei products, stoking up the Huawei political and security row even further this month, and has resulted in the UK Defence Secretary, Gavin Williamson, being sacked.  Defence Secretary Gavin Williamson sacked over Huawei leak Daily Telegraph publishes details of a meeting about using the Chinese telecoms firm to help build the UK's 5G network Huawei row: Inquiry to be held into National Security Council leak Is Huawei a Threat to UK National Security? What's the greater risk to UK 5G, Huawei backdoors or DDoS? Backdoors found in Huawei-supplied Vodafone e...