Posts

Chinese Takeaway InfoSec Style

Image
The Chinese and other foreign powers are said to be hacking and stealing information from UK businesses on an industrial scale, worst still is most businesses have no inkling their IT systems and information are compromised. Government agencies, the UK public sector and any businesses connected to providing services to the UK national infrastructure are primary targets of certain foreign nation states, which literally have military squads of trained hackers with their cyber sights on the UK. It is said they petty much target all of the UK FTSE 100 companies. These covert attacks do not only probe for IT weakness for future cyber warfare, but have a data theft agenda to them, targeting corporate secrets, sales projections, organisational structures and even customer contact databases. The aim here is to give foreign nation state backed businesses a competitive advantage over UK businesses, and to mimic successful UK businesses. Wi...

Cyberespionage: Stealing our IP, fetch me my angry trousers!

Image
Verizon's 2013 Data Breach Investigations Report (DBIR)  of their incident investigations during 2012, concluded one in five breaches were theft of company intellectual property, rather than the usual customer or credit card data theft.  This is a known growing problem and so a useful statistic to see in black and white, yet  the risk and realities of Cyberespionage  can be a hard pill for some business directors to swallow. It is clear foreign countries like China, are targeting western businesses, are increasingly employing sophisticated hacking techniques, all with the intent of stealing western business's information. Everything from organisational charts to the types of photocopiers in use, is all of interest and of future financial benefit, as they seek to compete on an international market. The new "Compare the Market" advert is the type of reaction I would love to see with UK business leaders when warning about ...

Your Personal Information has a value, who are you trusting to protect it?

Your personal information has a cash value to the bad guys, this is why you are plagued with malicious software (virus), scam emails and scam websites hiding malicious payloads, all attempting to steal your personal information.  But think about who you are freely sharing your personal information with, and then ask yourself, do they care to the same extent as you do in ensuring your information is protected? In the newly released  McAfee Data Loss Report 2013 , the report highlights that most data loss is occurring within data centres, as used by the those third parties you trust your personal information with. The report says the reason for data loss is not super clever hackers, no, its negligence, a basic lack of security controls on servers, storage, content, and networks. Worst still, you will be lucky if you are even told about a loss of your data, as there is no law which compels private companies to inform you if they lo...

UK InfoSec Review for February 2013

Microsoft issued one its largest ever monthly security updates Released as part ‘Patch Tuesday’ cycle on 12-Feb-13, bulletins MS13-009 to MS13-020 Addresses 57 vulnerabilities in Windows, Office, Internet Explorer, Exchange and the .NET Framework.  5 of these vulnerabilities were rated by Microsoft as ‘Critical’, Microsoft recommends to prioritise against MS13-009, MS13-010 and MS13-020 Adobe release 'Critical' Flash Player update which fixes 2 Zero-Day vulnerabilities (7-Feb) Adobe said in an advisory that one of the vulnerabilities — CVE-2013-0634 - is being exploited in the wild in attacks delivered via malicious Flash content hosted on websites that target Flash Player in Firefox or Safari on the Macintosh platform, as well as attacks designed to trick Windows users into opening a Microsoft Word document delivered as an email attachment New York Times and New York Journ...

UK Data Protection Review for February 2013

ICO fines Nursing and Midwifery Council £150,000 for breaching the DPA The council lost three DVDs related to a nurse’s misconduct hearing, which contained confidential personal information and evidence from two vulnerable children. An ICO investigation found the information was not encrypted. The council had been couriering evidence relating to a ‘fitness to practise’ case to the hearing venue. When the packages were received the discs were not present, though the packages showed no signs of tampering. Following the security breach the council carried out extensive searches to find the DVDs, but they’ve never been recovered ICO stated “failure to ensure these discs were encrypted placed sensitive personal information at unnecessary risk. No policy appeared to exist on how the discs should be handled, and so no thought was given as to whether they should be encrypted before being couriered. H...

UK InfoSec Review for January 2013

Microsoft release an Emergency “Critical” patch for Internet Explorer V6, 7 & 8   Patches released this patch out-of-band on 14th January 2013  Patch remediates a public disclosed remote code execution vulnerability in IE  Microsoft release 2 ‘Critical’ and 5 ‘Important’ Security Patches Patches released as part of the ‘Patch Tuesday’ cycle on 8th January 2013  Patches address vulnerabilities in Windows, Office, Developer Tools, .NET Framework and server  Abode release patches for fix 27 vulnerabilities in Adobe Reader, Acrobat & Flash Patches released as part of ‘Patch Tuesday’ cycle on 8th January 2013  Hackers Used Data Centres to Supercharge Attacks Researchers at Radware who investigated the attacks for several banks found that the traffic was coming from data centres around the world. They discovered that various cloud services and public Web hosting services had been infected with a particularly sophisticated form of malwar...

UK Data Protection Review for January 2013

ICO fines Sony £250,000 after millions of UK gamers  personal details are compromised Sony PlayStation Network Platform made international headlines when it was hacked in April 2011, compromising the personal information of millions of UK customers, including their names, addresses, email addresses, dates of birth and account passwords. Customers’ payment card details were also at risk.  An ICO investigation found that the attack could have been prevented if the software had been up-to-date, while technical developments also meant passwords were not secure  ICO commented  “If you are responsible for so many payment card details and log-in details then keeping that personal data secure has to be your priority”  “There’s no disguising that this is a business that should have known better”  “The penalty issued clearly substantial, but we make no apologies for that. It directly affected a huge number of consumers, and at the very least put them ...