Posts

The Price of Loyalty, almost half of UK Office Workers are willing to sell Company's Information

Image
A new report  released by Deep Secure revealed 45% of office workers surveyed would sell their company's corporate information. Just £1,000 would be enough to tempt 25% of employees to give away company information, while 5% would give it away for free. 59% of staff admitted at some point to have taken company information from a corporate network or devices, which matches up to known industry trends.  What is the Price of Loyalty?   Common Staff Data Exfiltration Tactics Digital; email, uploading to cloud services and copying to external storage (11%) Using steganography or encryption tools to hide exfiltration (8%) Printing information (11%) Handwriting copying information (9%) Photographing information (8%) Type of Information Taken Personal Work (19%) Customer Information i.e. contact details, confidential market information, sales pipeline  (11%) Company Assets i.e. passwords to subscription services, company benefits (7%) The Mot...

UK Pub Chain 'Greene King' Gift Card Website Hacked

Image
Major UK pub chain, Greene King (Bury St. Edmunds), had its gift card website ( https://www.gkgiftcards.co.uk ) compromised by hackers. The personal data breach was discovered on 14th May 2019 and confirmed a day later. The pub, restaurant and hotel chain informed their impacted customers by email today (28th May 2019). Greene King said the hackers were able to access: name email address user ID encrypted password address post code The pub chain did not disclose any further details on how passwords were "encrypted", only to say within their customer disclosure email " Whilst your password was encrypted, it may still be compromised".  It is a  long established good industry coding practice for a website application's password storage to use a one-way 'salted' hash function, as opposed to storing customer plaintext passwords in an encrypted form . No details were provided on how the hackers were able to compromise the gift card website, but th...

The UK Government Huawei Dilemma and the Brexit Factor

Image
In the last couple of days, Google announced it will be putting restrictions on Huawei’s access to its Android operating system , massively threatening Huawei's smartphone market. Meanwhile,  UK based chip designer ARM has told its staff to suspend all business activities with Huawei , over fears it may impact ARM's trade within the United States.  Fuelling these company actions is the United States government's decision to ban US firms with working with Huawei over cybersecurity fears. The headlines this week further ramps up the pressure on the UK government to follow suit, by implementing a similar ban on the use of Huawei smartphones and network devices within the UK, a step  beyond their initial 5G critical infrastructure ban announced last month. But is this really about a foreign nation-state security threat? Or is it more about it geo-economics and international politicking? Huawei: A Security Threat or an Economic Threat? Huawei Backdoors It’s no ...

WhatsApp, Microsoft and Intel Chip Vulnerabilities

Quickly applying software updates (patching) to mitigate security vulnerabilities is a cornerstone of both a home and business security strategy. So it was interesting to see how the mainstream news media reported the disclosure of three separate ‘major’ security vulnerabilities this week, within WhatsApp, Microsoft Windows and Intel Processors. WhatsApp The WhatsApp security flaw by far received the most the attention of the media and was very much the leading frontpage news story for a day. The WhatsApp vulnerability ( CVE-2019-3568 ) impacts both iPhone and Android versions of the mobile messaging app, allowing an attacker to install surveillance software, namely,  spyware called Pegasus , which access can the smartphone's call logs, text messages, and can covertly enable and record the camera and microphone. From a technical perspective, the vulnerability ( CVE-2019-3568 ) can be exploited with a buffer overflow attack against WhatsApp's VOIP stack, this makes remote cod...

ZombieLoad: Researchers discover New Hardware Vulnerability in Modern Intel Processors

Image
A brand new processor hardware vulnerability affecting modern Intel CPUs has been uncovered by Bitdefender researchers  Coined "ZombieLoad side-channel processor", the vulnerability defeats the architectural safeguards of the processor and allows unprivileged user-mode applications to steal kernel-mode memory information processed on the affected computer. https://www.bitdefender.com/files/News/CaseStudies/study/257/Bitdefender-Whitepaper-YAM-en-EN.pdf A Concerning Impact on Cloud Services The new vulnerability can b e exploited by attackers to leak privileged information data from an area of the processor's memory meant to be strictly off-limits. This flaw could be used in highly targeted attacks that would normally require system-wide privileges or deep subversion of the operating system. The flaw has an extremely large impact on cloud service providers and within multi-tenant environments, as potentially a 'bad neighbour' could leverage this flaw to ...

Zavvi Champions League Final Competition Winner Email Blunder

Image
Like many Zavvi customers this morning, I received an email titled " Congratulations, you're our Mastercard Competition WINNER! " in my inbox. An amazing prize consisting of two tickets to watch Liverpool and Spurs battle it out in the 2019 UEFA Champions League Final in Madrid. The prize also included two nights at a 4-star hotel, flights, transfers and a £250 prepaid card. Zavvi Winners Email Obviously, my initial thought it was a phishing email, decent quality and a well-timed attempt given Liverpool and Tottenham Hotspur were confirmed as finalists after very dramatic semi-final matches on the previous nights. I logged into my Zavvi account directly, then reset my password just in case, and after a bit checking with the embedded links within the email, and research on the Zavvi website, I soon established it was a genuine email from Zavvi. But before embarking on a  Mauricio  Pochettino style injury-time winning goal celebration, I had a quick scan of my soc...

2019 Verizon Data Breach Investigations Report (DBIR) Key Takeaways

Image
The 2019 Verizon Data Breach Investigations Report (DBIR ) was released today, and I was lucky enough to be handed a hot off the press physical copy while at the Global Cyber Alliance Cyber Trends 2019 event at Mansion House, London. For me, the DBIR provides the most insightful view on the evolving threat landscape, and is the most valuable annual “state of the nation” report in the security industry. Global Cyber Alliance Cyber Trends 2019 The DBIR has evolved since its initial release in 2008, when it was payment card data breach and Verizon breach investigations data focused. This year’s DBIR involved the analysis of 41,686 security incidents from 66 global data sources in addition to Verizon. The analysed findings are expertly presented over 77 pages, using simple charts supported by ‘plain English’ astute explanations, reason why then, the DBIR is one of the most quoted reports in presentations and within industry sales collateral. DBIR 2019 Key Takeaways Financial g...