Blog

Blog

OmniRAT - the $25 way to hack into Windows, OS X and Android devices

Image Just last week, police forces across Europe arrested individuals who they believed had been using the notorious DroidJack malware to spy on Android users. Now attention has been turned on to another piece of software that can spy on communications, secretly record conversations, snoop on browsing histories and take complete...
Blog

ProtonMail Suffers 'Extremely Powerful' DDoS Attack

Image ProtonMail, a Switzerland-based encrypted email service, recently suffered an "extremely powerful" distributed denial-of-service (DDoS) attack that has temporarily knocked it offline. Image On Tuesday, ProtonMail tweeted out that it was experiencing a DDoS attack and that it...
Blog

Beware the Cyber Blind Spots

Image A blind spot is defined as “an area where a person's view is obstructed.” As a longstanding professional in the industry, seeing the rhetoric change over the years, from Information Security, through Information Assurance and now to “cyber security,” what is occurring is the creation of a significant and worrying blind spot....
Blog

Mainframe Insecuritites or Hack the Gibson. No, Really!

Image You can hack a toaster, a TV and a car... but a mainframe? Isn’t everything on Windows and Linux? Who still uses mainframes (specifically IBM’s flagship System Z running Z/OS)? They’re obsolete, specialized and cumbersome, just like the stuff that runs on them: TSO, JES, Walker, CICS, VTAM, MVS, IMS. And they’re pretty much...
Blog

The TalkTalk Breach: Timeline of a Hack (UPDATED 11/25/15)

Image The UK telecommunications provider TalkTalk has made headlines in recent weeks following a breach against its website. Initially, the incident was believed to have compromised the personal and financial information of as many as four million TalkTalk customers. However, these estimates have since been revised as a result of an...
Blog

Android 6.0 (Marshmallow) Security At a Glance

Image After just a few hours with a shiny new Nexus 5X running the latest version of Android 6.0 AKA “Marshmallow” release, a few behaviors have already caught my attention as welcomed security and privacy changes for the user-experience. (A few other items have caught my interest as points of potential vulnerability, but I’ll leave...
Blog

Snowden-Endorsed Signal Private Messenger App Comes to Android

Image Signal Private Messenger, an end-to-end encrypted communications app used by Edward Snowden, is now available to Android devices on the Google Play Store. On its website, Open Whisper Systems (OWS), the maker of Signal, released the following statement: "Today we’ve started rolling out Signal for Android, which unites simple...
Blog

Empowering Pipeline SCADA Cybersecurity

Image Our nation depends heavily on the more than 2.3 million miles of pipelines in the United States that move oil, gas and other liquid products cross country to delivery points, such as airports, refineries, homes, and businesses. At an average of every 40 miles for natural gas pipelines, there are compressor stations that move the...
Blog

US, UK Banks To Test Resiliency in Cyber Attack Simulation

Image The Bank of England, in partnership with some of the biggest US Banks, will take part in an extensive cyber-attack simulation, as officials examine the financial industry’s readiness in the event of a security breach on its systems. The exercise, known as Operation Resilient Shield, is intended to be the most sophisticated test...
Blog

A New Twist on Ransomware

Image There is a new and scary development in ransomware. Ransomware is software that encrypts data on your computer and shared drives and then displays a message demanding payment for the decryption key. Generally, if you do not keep good backups of your data, your data will be lost. According to a report on a German website, there...
Blog

Second Teen Arrested in Connection with TalkTalk Breach

Image London law enforcement have announced the arrest of a second teenager in connection with the recent breach against UK telecommunications company TalkTalk. On Friday, the Metropolitan Police released the following statement: "On Thursday, 29 October, detectives from the Metropolitan Police Cyber Crime Unit (MPCCU) executed a...
Blog

The Security Hypocrisy Conundrum

Image This year’s Cyber Awareness Month has once again, seen some great articles, tips and practical advice that we can share with our colleagues, friends, family and children. Actively encouraging a positive security aware culture is a vital part of what we do as security professionals, and we should always be seen to be setting the...
Blog

Security for Life: Promoting the Development of a Security Professional

Image This week marks the fifth and final week of National Cyber Security Awareness Month (NCSAM) 2015. A program sponsored by the Department of Homeland Security (DHS) in cooperation with the National Cyber Security Alliance and the Multi-State Information Sharing and Analysis Center, NCSAM emphasizes our shared responsibility in...
Blog

British Gas Urges Customers to Change Passwords Following Login Leak

Image British Gas has emailed approximately 2,200 customers urging them to change their passwords after their login credentials were posted online. According to The Guardian, the account details were posted to the online text-sharing service Pastebin and, if accessed, could have allowed an attacker to view the names, addresses, and...
Blog

Point of Sale Cyber Crime: The Gift that Keeps on Giving

Image In spite of continuous efforts to improve the security of credit card transactions by both the financial services and retail industries, we see nearly endless headlines about new card data breaches. Banks want to improve security to avoid incurring the expenses associated with fraudulent purchases and investigations efforts....
Blog

Home Network Analysis: DVRs and my Network Interact

Image My last on-topic post pontificated about the dangers and surprise of letting third parties into your house or codebase, where I discussed the addition of a TV DVR system to my home network. In this post, I'm going to go into some details about what I found on the network for the pure pleasure of it – no pontificating about...
Blog

Ransomware Victims Should 'Just Pay the Ransom,' Says the FBI

Image A member of the Federal Bureau of Investigations (FBI) has recommended that ransomware victims "just pay the ransom" if no other option exists and if they need access to their encrypted data. Last Wednesday, during Cyber Security Summit 2015 at Boston's Back Bay Events Center, Joseph Bonavolonta, the Assistant Special Agent in...
Blog

Joomla SQL Injection Flaw Exploited Hours After Disclosure

Image Malicious actors began exploiting a patched critical vulnerability found in Joomla—a popular open-source content management system—just four hours after its details were disclosed. Discovered by researchers at Trustwave, the SQL injection flaw (CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858) found in versions 3.2 through 3.4.4...