Blog

Blog

Supercharging Cybercrime Detection with MITRE’s ATT&CK Framework

The majority of attacks that result in successful data breaches are simply not that complex. Many rely on well-known, tried-and-true methods. Indeed, the Verizon DBIR has for many years reported that upwards of 90 percent of attacks were successfully executed because of unpatched and known vulnerabiltiies or misconfigured systems. If we can only learn a few lessons from the latest attacks: ...
Blog

Women in Information Security: Nitha Suresh

Last time, I talked with Glenda Snodgrass. She's a founder and the president of The Net Effect, a cybersecurity services company. This time, I had a fascinating discussion with Nitha Suresh. She taught me a bit about penetration testing and aircraft data networks. Kimberly Crawley: Hi, Nitha! Tell me a bit about what you do. Nitha Suresh: I am...
Blog

IoT Security: Does Such a Thing Exist?

We've been hearing a lot about IoT security recently. The news is overwhelming us with stories about baby dolls and baby monitors that can listen in on conversations at home, not to mention surveillance cameras that provide video streams to unauthorized individuals. To better understand these events, let’s start by looking at what is IoT. According...
Blog

Tripwire University: ICS/SCADA Edition

What do Robert M. Lee, Eric Byres, Sean McBride, Dr. Oliver Kleineberg, and Sid Snitkin all have in common? If any of these names do not ring a bell, they’re each industrial cybersecurity experts in different realms. Along with Tripwire customers and other industry leaders, they will be sharing fast-paced perspectives and challenging you to think...
Blog

Welcome Back, Mr. Robot

“Hello, again, friend. It all went quiet for a while and the depictions of hacking and cyber on TV seemed to become trite and clichéd again. We stopped seeing him, Mr. Robot, but now he’s back again. Did you see him, too?” This blog may contain spoilers and was written following ‘eps3.2_legacy.so,’ which seems a good enough point into the new...
Blog

Tripwire Patch Priority Index for October 2017

BULLETIN CVE APSB17-32 CVE-2017-11292 Microsoft Browser - IE CVE-2017-11790,CVE-2017-11822,CVE-2017-11813 Microsoft Browser - Edge CVE-2017-11794,CVE-2017-8726 Microsoft Browser - Scripting engine CVE-2017-11796, CVE-2017-11808, CVE-2017-11809, CVE-2017-11805, CVE...
Blog

Insights into ICS Security: An Interview with Robert Landavazo

Industrial control systems (ICS) are no strangers to digital attacks. In its Threat Landscape for Industrial Automation Systems in H1 2017 report (PDF), Kaspersky Lab blocked attack attempts against 37.6 percent of ICS computers that use the Russian security firm's products. It also detected 18,000 variants of 2,500 different malware families that...
Blog

Could Containers Save The Day? 10 Things to Consider when Securing Docker

By now, we’re all aware of the Equifax breach that affected 143 million customer records. Equifax reports that Apache Struts vulnerability CVE-2017-5638 was used by the attackers. Equifax was not running its vulnerable struts application in a container, but what if it had been? Containers are more secure, so this whole situation could have been...
Blog

How Safe Are You on Public WiFi? Not Very

At the U.S. Republican National Convention in Cleveland last year, more than 1,200 people connected to free WiFi networks with names like “I Vote Trump! Free Internet,” “I Vote Hillary! Free Internet,” and “Xfinitywifi.” They transferred gigabytes of data, doing things like checking e-mails and chatting. Some even shopped on Amazon or logged into...
Blog

Google Unveils Bug Bounty Program for Popular Android Apps

Google has announced a bug bounty program covering other developers' popular Android apps available for download in its Play Store. On 19 October, the American multinational technology company launched its Google Play Security Rewards Program. Here's a high-level description of the new framework: "Google Play is working with the independent bug...
Blog

The Need for Increased Investment in Medical Device Security

In 2014, the FBI warned that healthcare systems, including medical devices, were at an increased risk of cyber-attacks due to the unfortunate coupling of poor cybersecurity practices in the healthcare industry with patient health information (PHI) that commands high value on the dark web. This warning has largely been realized. The cost and frequency...
Blog

New Android Malware Found in Minecraft Apps on Google Play

A new, “highly prevalent” strain of Android malware was found infecting several Minecraft-related apps on the Google Play store, adding compromised devices into a botnet. According to security researchers at Symantec, at least eight mobile apps – with an install base ranging from 600,000 to 2.6 million devices – were infected with Sockbot. “The...
Blog

KRACKs: What They Are and How You Can Protect Yourself

On 16 October, news first emerged of what's known as "KRACKs." These malicious techniques exploit vulnerabilities that affect a protocol used for securing Wi-Fi networks. Bad actors could therefore leverage KRAcks to potentially expose encrypted information exchanged over otherwise secure wireless connections. As of this writing, the computer...
Blog

Will the World Really Cooperate in Curbing Cybercrime?

As part of this ongoing series (previous parts, in order, here, here, here and here), I have been trying to make the case that differing interests make cooperation on cybersecurity issues virtually impossible. This is not criticism. It’s just reality. And while it would be easy to look at Brexit or Eastern European and American politics as a push...
Blog

Security Is a Team Sport

If you've read a security blog anytime in the last year, you haven't escaped mention of the dreaded skills gap for cybersecurity professionals. There seems to be consensus that it's getting harder to hire skilled security staff, though the reason for that is up for debate – some say we're just going about it the wrong way, while others claim it is an...
Blog

VERT Threat Alert: October 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft October 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-746 on Wednesday, October 11th. In-The-Wild & Disclosed CVEs CVE-2017-8703 This CVE describes a publicly disclosed denial of service vulnerability which impacts the Windows Subsystem for...
Blog

Apple Update Addresses Password Security for Encrypted APFS Volumes

Apple has released an update that is designed to better protect passwords for encrypted APFS volumes on machines running macOS High Sierra. APFS is short for Apple File System. The Cupertino-based tech giant created it to fix some issues involving Mac OS Extended. Apple File System is meant for computers with flash or solid-state drive (SSD) storage...