Showing posts with label cyber attacks. Show all posts
Showing posts with label cyber attacks. Show all posts

Thursday, 24 March 2011

Serious cyber attack targets EU institutions on eve of summit

Today is the first day of the first EU summit that takes place under the Hungarian presidency, and European leaders have gathered in Brussels to discuss matters such as the rising European debt crisis and the Libyan unrest and the subsequent military action.



But on the very eve of the summit, an unexpected occurrence cast a dark shadow over the event. The BBC reports that the European Commission and the External Action Service - the Community's diplomatic arm - have been hit by a "serious" cyber attack.

So far, details about the attack have not been divulged.

"We are already taking urgent measures to tackle this. An inquiry's been launched. This isn't unusual as the commission is frequently targeted," said EU spokesman Anthony Gravali.

An anonymous source confirms: "We're often hit by cyber attacks but this is a big one." Other sources compare the attack to the recently revealed one that targeted the computers of the French Ministry of Finance, when more than 150 machines were compromised.

Even though Gravali says that the European Commission will not speculate on the origin of the attacks, the similarities raise the possibility that the attackers could be the same ones that targeted the French. At the time, internal sources said that some of the files were redirected to Chinese sites, but they conceded that this fact doesn't say much.

The entire European Commission staff has been asked to change their passwords and to make sure to exchange information via secure email systems. The Commission has also shut down external access to email and the Comission's intranet, so that unauthorized information doesn't leak out.

[Net-Security]

Monday, 21 March 2011

CSIS expert lists worst cyber security breaches since January 2010

According to Bank Info Security, testimony was given before the House Homeland Security Committee last week by James Lewis, senior fellow at the Center for Strategic and International Studies (CSIS).

Lewis's testimony included a list of serious security incidents that have taken place since January 2010.

This list is reproduced below, with thanks to Bank Info Security.

Lewis is reported to have stated that the list "is not a record of success". He added "Whatever we are doing is not working...While individual government agencies have made strenuous efforts to improve our cyberdefenses, as a nation, despite all the talk, we are still not serious about cybersecurity."

This looks really rather damning of today's security infrastructure. But, I can't help but wonder how many cyber attacks weren't successful, thanks to the security that is place today? While I would agree that no one should rest on their laurels when it comes to security, I also know that there is no silver bullet.

I wonder if Lewis will also be providing advice on what needs to be done to help better secure against attacks. No one wants to be a victim, and most companies out there are doing what they can to stave off attacks.
January 2010: Google announced that an attack had penetrated its networks, along with the networks of more than 80 other US high-tech companies. The goal of the penetrations, which Google ascribed to China, were to collect technology, gain access to activist G-mail accounts and to Google's password management system. 
January 2010: At the same time, Intel experienced a harmful cyberattack. 
January 2010: Global financial services firm Morgan Stanley experienced a "very sensitive" break-in to its network by the same hackers who attacked Google, according to leaked e-mails. 
March 2010: A number of successful cyberattacks against NATO and European Union networks have increased significantly over the past 12 months, the international organizations revealed. 
March 2010: Australian authorities say there were more than 200 attempts to hack into the networks of the legal defense team for executives from Australian energy company Rio Tinto, to gain inside information on the trial defense strategy. 
April 2010: Hackers break into classified systems at the Indian Defense Ministry and Indian embassies around the world, gaining access to Indian defense and armament planning.
May 2010: A leaked memo from the Canadian Security and Intelligence Service says, "Compromises of computer and combinations networks of the government of Canada, Canadian universities, private companies and individual customer networks have increased substantially. ... In addition to being virtually unattributable, these remotely operated attacks offer a productive, secure and low-risk means to conduct espionage."
October 2010: Stuxnet, a complex piece of malware designed to interfere with Siemens industrial control systems discovered in Iran, Indonesia and elsewhere, results in significant physical damage to the Iranian nuclear program. 
October 2010: The Wall Street Journal reports that hackers using Zeus malware, available in cybercrime black markets for about $1,200, were able to steal over $12 million from five banks in the United States and Britain. 
December 2010: British Foreign Minister William Hague reported last month attacks by a foreign power on the British Foreign Ministry, a defense contractor and other British interests. The attack succeeded by pretending to come from the White House. 
January 2011: The Canadian government reports a major cyberintrusion involving the Defense Research and Development Canada, a research agency for the departments of National Defense Finance and the Treasury Board, Canada's main economic agencies. The intrusions forced the Finance Department and the Treasury Board to disconnect from the Internet. 
March 2011: Hackers penetrate French government computer networks in search of sensitive information on upcoming G-20 meetings. 
March 2011: South Korea said that foreign hackers penetrated its defense networks in an attempt to steal information on the American-made Global Hawk unmanned aircraft, provided to Korea as it considers whether to buy the aircraft.
CSIS experts conduct research and analysis and develop policy initiatives grouped under three themes: defense and security policy, global trends, and world regions. James Andrew Lewis focuses on technology, national security, and the international economy. Before joining CSIS, he worked in the federal government as a foreign service officer and as a member of the senior executive service. His assignments involved Asian regional security, military intervention and insurgency, conventional arms negotiations, technology transfer, sanctions, Internet policy, and military space programs.

[NakedSecurity]

Sunday, 13 March 2011

How to Avoid Falling For Social Engineering Attacks

I am one of the “end-users” in our organization.

I’m not a tech, but over the years have had my eyes opened regarding information security and ways I can safeguard my own private data.

My favorite tool is a password vault, which helps tremendously as I belong to dozens of sites. Quite frankly, I can’t remember what I had for dinner yesterday much less recall all the different passwords needed to access all those sites. So a password vault is incredibly helpful.

But what really fascinated me was the discovery of social engineering. Social engineering is when someone uses deceptive methods in order to get you to release confidential information. Sometimes it’s almost obvious, sometimes it’s sneaky. But on most occasions, people don’t realize what’s happening until it’s too late.

I’ll give an example: One time I received several phone messages from my credit union. I was told there was an issue and to return the call. I called my credit union to discover that (surprise, surprise), there was no “issue” and they never called me.

So when this shady outfit called me two days later, I was home and answered the phone. After the woman went through some type of script (needing my account number, natch), I blew up.

“For your information, I contacted my credit union and there IS no issue and no need to speak to me. How in the world do you sleep at night, deliberately trying to get people to give you confidential information so you can steal from them? You’ve got a helluva lotta nerve to keep calling!”  The woman was silent. I slammed the phone down. I never heard from them again.

The point of this colorful little story is that thieves and hackers are everywhere. With our information becoming more digitalized, we need to be on guard more than ever before and use the most powerful weapon we’ve got.

QUESTION EVERYTHING.


And follow some of these tips:
  • If you receive an email from PayPal or a credit card company and they want to “verify” your account, check the URL. If a letter of the company’s name is off or it looks totally different, do NOT click on it. (You can see the URL usually by hovering your mouse over the link.)
  • Never  click on a link in an email to a financial institution. If you are a member of this institution, call their customer service number. Have them check your account to see if indeed there was a need to contact you.
  • Always check the identity of anyone who is calling you on the phone to ask for confidential information. Say you’re about to run out the door and get their name and phone number. Then call the organization they represent to verify that this person is legit.
  • At your workplace, use the same approach. Be friendly, but wary in a good way. If you have a courier who needs to give their package directly to the recipient, casually ask a co-worker if they could accompany the courier to their destination and then ensure they leave promptly afterward. Use this method for any strangers who are visiting your organization such as repairmen, copier salespeople, or phone technicians.
Speaking of copiers, beware of “boiler-room” phone calls. These are attempts to gather information about your copier (i.e., serial number, make and model of copier) so the unscrupulous company can ship expensive supplies to a company and then bill you, as though it was a purchase initiated by your company.

These types are scumballs in my book. After I learned what they did, I’d have a bit of fun with them before hanging up. Now I don’t have the patience for it. I just hang up.

You have to be sharper than ever to see through a social engineering attack. The challenge is to retain that sharpness while in the midst of multiple tasks.

Most of the time, the attacker will take advantage of a busy receptionist, a chaotic office, or a tired staff when they try their dastardly deed. (Ever notice you hardly get these attempts early in the morning, when you’re awake and alert? And how many happen close to quitting time on a Friday?)

Just a few thoughts to keep you sane and safe. Confound the social engineering attacks so you won’t be the one confounded! Good luck!

[InfoSecIsland]

Monday, 7 March 2011

Report: Anonymous To Avenge Alleged Wiki Leaker Manning

Anonymous The shadowy online collective Anonymous said it will step up attacks on those it believes are responsible for persecuting Bradley Manning, the U.S. Army private who is currently being held on suspicion of leaking classified military documents.

The announcement, by the group's public spokesman, Barrett Brown, appeared on the Web site The Daily Kos on Thursday. Brown said the new campaign, dubbed #opbradley, is a response to the filing of new charges against Manning on Wednesday, including a possible capital offense: aiding the enemy.

The campaign - one of a flurry announced by the group in recent weeks, will be a "supplement" to ongoing campaigns against the firm Palantir, which was a business partner of an earlier Anonymous target, HBGary, and #anonleaks, the group's Website that allows visitors to search the HBGary e-mail archive.

Read more at The Daily Kos. 

[ThreatPost]

Cyber attack on France targeted Paris G20 files

The French finance ministry has confirmed it came under a cyber attack in December that targeted files on the G20 summit held in Paris in February.

Budget Minister Francois Baron said an investigation had been launched, adding: "We have leads".
It follows a report in Paris Match magazine that claimed a sustained cyber attack sought documents related to the G20 and international economic affairs.

More than 150 computers at the ministry were affected.

'Determined professionals'


"We noted that a certain amount of the information was redirected to Chinese sites," an anonymous official was quoted by the French magazine. "But that [in itself] does not say very much."

An official complaint has been filed with French courts, and the matter has been taken up by the secret service.

"The actors were determined professionals and organised," Patrick Pailloux, director general of the French National Agency for IT Security told Paris Match.

"It is the first attack of this size and scale against the French state."

The summit agreed a list of targets for reducing imbalances in the global economy in order to head off future financial crises.

The topic was particularly contentious for the Chinese, who resisted calls to target exchange rate valuations, currency reserves and economic surpluses.

The US and other countries accuse China of buying up trillions of dollars in foreign reserves in order to hold down the value of the yuan and gain an unfair competitive advantage in trade.

[BBC]

Friday, 4 March 2011

South Korea hit by cyber attacks

South Korea has been hit by a series of cyber attacks which have targeted some of the country's leading websites.

Government ministries, the National Assembly, the military headquarters, US Forces in Korea and major banks were among those hit.

It is believed that the attackers injected malware into two peer-to-peer file-sharing websites.
The attacks are similar to those that targeted South Korean websites in July 2009.

Some 29 institutions were affected by so-called distributed denial-of-service attacks (DDoS) which overload a site with data causing it to fall over.

The web page of the Financial Services Commission, the country's financial regulator, was overloaded and an online stock trading system was shut down for a few minutes but both soon recovered, according to government sources.

North Korea


"There was a DDoS attack, but no damage was done," said an official from the presidential office.
South Korean security firm AhnLab expected another wave of attacks on Friday, targeting up to 40 government and corporate websites.

It estimates that up to 11,000 personal computers were infected by malware and recruited for the attack. It is distributing free software to clean PCs.

The South Korean cyber investigation unit has sent investigators to the two file-sharing sites that are believed to have spread the malicious code, according to the National Police Agency.

The cyber attacks against South Korea in 2009 were blamed on North Korea, although no link has been proven.

South Korean media outlets have, in the past, accused North Korea of running an internet warfare unit aimed at hacking into US and South Korean military networks.

[BBC]