Showing posts with label threats. Show all posts
Showing posts with label threats. Show all posts

Monday, 7 March 2011

Report: Anonymous To Avenge Alleged Wiki Leaker Manning

Anonymous The shadowy online collective Anonymous said it will step up attacks on those it believes are responsible for persecuting Bradley Manning, the U.S. Army private who is currently being held on suspicion of leaking classified military documents.

The announcement, by the group's public spokesman, Barrett Brown, appeared on the Web site The Daily Kos on Thursday. Brown said the new campaign, dubbed #opbradley, is a response to the filing of new charges against Manning on Wednesday, including a possible capital offense: aiding the enemy.

The campaign - one of a flurry announced by the group in recent weeks, will be a "supplement" to ongoing campaigns against the firm Palantir, which was a business partner of an earlier Anonymous target, HBGary, and #anonleaks, the group's Website that allows visitors to search the HBGary e-mail archive.

Read more at The Daily Kos. 

[ThreatPost]

Tuesday, 1 March 2011

Dispelling Myths about Apple Products and Viruses

For years, Apple products have had one up on the PC regarding viruses and malware.  However, due to increased market share, that time may be coming to an end.

Throughout the history of Apple products there has been a long standing consumer myth that they are incapable of becoming infected with viruses.  Most believe that the Mac Operating System was simply more secure than that of PC. 
Although the system may be more secure, it is still vulnerable to malware and other infections.  One needs to look no further than the fact that Apple sells anti-virus software from many of the leading names in the virus protection industry.  What really gave Apple its edge was their lack of market penetration, a result of occupying a small portion of the computer sales industry. 
Simply put, if you want to catch a fish, you go to the pond with the most fish.  That “pond” has always been PC’s.  However, along with their growing popularity and rise in market share, Apple products are becoming more vulnerable to viruses and other harmful infections.

BACKGROUND

The myth that Apple products are impervious to viruses is almost like a virus in and of itself.  Only instead of infecting Apple products, it is infecting the way Apple users think about the product.  This “myth” continues to mislead Apple users into believing they are safe from viruses and there is no need for anti-virus programming.
Unfortunately, life would just be too simple if this was the case. From reading forums and discussing the topic with owners of Apple products, it is blatantly obvious that Apple users are completely unaware of the harm to which they are exposing their computers.

Currently there are several types of viruses that can potentially harm Apple products.  One of the main areas of concern is downloading files that are infected with Trojan horses, spyware, and worms.  These types of files can be found on pirated software and games. 
Versions of Microsoft Office infected with viruses can also infect Mac products using the program.  Also, browser plug-ins for viewing video content can harbor malware, making your Mac more vulnerable to other infections.  These problems are really just the beginning because they do not take into account the growth and success of Apple and their products.

STRATEGIC PLANNING ASSUMPTIONS

-Apple, the company, must do a better job of informing their customers of the risk to their computers.  What was once a selling point, needs to now be addressed as a concern.

-Apple users need to become more educated.  They need to open their eyes to the problem and take appropriate action.

-Acquire an anti-virus program.  Many of the major anti-virus companies, such as McAfee, Intego, Norton and Symantec have all released programs for Apple products.

ANALYSIS

The main reason for the recent increase in viruses infecting Apple products goes hand in hand with the success of the company.  In just the past two years, Apple has consumed nearly 3% of the entire computer sales in the United States, raising their overall market share to 10.4%. 
Although that may not sound like a large increase, Apple’s annual growth is nearly off the charts.  Over those same two years, Apple’s year to year growth has been 24.1%, which dwarfs the overall industry’s growth of 3.8%.  With the wild popularity of the iPad, iPhone and other Apple products, this percentage will only continue to grow.

In any business venture, success has its drawbacks, and this same theory can be applied to Apple and their current surge in the United States computer sales industry.  As stated previously, the idea that Apple products were incapable of being infected with viruses was a selling point. 
Many businesses opted to use Apple computers for their convenience and savings that go along with not having to worry about viruses or spend more money on anti-virus programming.  While Apple products once enjoyed the safety of their own anonymity, they must now accept what comes along with their new found popularity.

IMPLICATIONS

-The “myth” of Apple products not being able to contract viruses is simply not true.

-Apple has become a mainstay of the computer industry, holding a market share of nearly 11%, a figure which continues to rise.  As a result of the increased penetration, the most secure days of the Mac OS are in the past.

-The vulnerability of Apple products goes hand in hand with the success of the company, which is growing at a rate nearly eight times that of the rest of the computer industry.

-While the sales figures of HP and Dell have plateaued, Apple continues to grow at an annual growth rate of 24.1%.

-Apple currently holds the number four ranking in the computer sales industry, behind HP, Dell, and Acer.  Following market trends, by this time next year, Apple will be well ahead of Acer and catching up to HP and Dell.

-Due to the wild success of the iPad, iPhone and the Mac OS, there are no signs of Apple’s growth slowing down.

KEY FINDINGS

-The majority of Apple users are completely unaware of the susceptibility of their computers when it comes to malware.  Stay informed with updates from Apple and other security upgrades.

-The easiest way to prevent computers from being infected with viruses is to stop them before they start.  We all know how difficult computers can be to work with when they are infected with any type of virus.

-Nearly all the major anti-virus companies now sell programs for Apple products.  (A sign of things to come?)

RECOMMENDATIONS

-Verify that your computer is protected by an anti-virus program.  There are some free anti-virus programs available, such as iAntiVirus and ClamXav, however they are not considered as robust as the major companies such as McAfee, Intego, Norton and Symantec.

-Use common sense when surfing the web.  Do not visit websites that are not known to be secure and do not download files or documents from an unknown sender.  Also make sure your virus scanner and security updates are frequently updated with the newest protection.

-Stay ahead of the curve by educating yourself with the current viruses and other problems infecting computers.

-Happy surfing!

[infosecisland]

Unmasking Security Threats in the Workplace

Corporate security risks can creep up on you from anywhere in your company. Most people think that the greatest risks reside outside of the organization, from hackers trying to get their hands on company lists and other information they can sell.

Unfortunately, there are still a lot of internal risks that need to be addressed, as employees remain a major corporate security threat as well. Keeping up to date on new threats is important, as cyber-criminals and those from within your company can move from one scheme to the next in the blink of an eye.

Knowing where to start can be difficult. In the SANS document, "The Top Cyber Security Risks," it states:

"The number of attacks is now so large and their sophistication so great, that many organizations are having trouble determining which new threats and vulnerabilities pose the greatest risk and how resources should be allocated to ensure that the most probable and damaging attacks are dealt with first."

Common Corporate Security Threats

In order to determine where to start, you need to assess the workplace and figure out which threats exist inside and outside of the organization. Then, you'll want to prioritize these risks to figure out which ones to address first. Here are some of the common security threats your company might encounter:

Human Error: Intentional or not, people are security threats. Some examples of common human errors include:
  • Misplacing information.
  • Opening spammy emails.
  • Failure to properly process information.
  • Improper disposal of documents (electronic and paper).
  • Sending email to someone other than the intended recipient (one of the dangers of auto fill!)
Disgruntled Employees: If your systems aren't secure, employees could be stealing all kinds of data before anyone notices it. There are a lot of reasons why a disgruntled employee might engage in these types of activities, including the fact that the employee see the opportunity and could use the money, or they feel the desire to take revenge on the company. Simple measures such as removing disc drives from computer towers can make a difference.

Cyber Criminals: Cyber criminals have developed a number of sneaky tactics to break into systems to get the information they want. In an article I read about a big-time cyber criminal in the NY Times, it almost seemed as if it wasn't about the information or the money, but simply the ability to hack into as many systems as possible. The tactics used by cyber criminals can be hard to catch, as many companies report that their systems had been invaded long before they knew anything was wrong.

Property Theft/ Misplacement: Information stored on laptops, USB keys and other portable devices increases security risks as these devices can be misplaced or stolen. These devices must be guarded by strong passwords and other recognition systems- facial scan, fingerprint, etc., in order to make sure information stays protected.

Insufficient Network Security: If your systems aren't properly guarded, it's easy for someone to break in. There are tons of ways that hackers weasel their way into your systems, so I recommend consulting a security or IT professional to find out which types of attacks you need to be on the lookout for. Find out which ones are most common and which ones could do the most damage, this way you can prioritize your actions.

Accessibility: When everyone has access to information in your organization, everyone could potentially steal that information. Sensitive information or information that doesn't pertain to one's job shouldn't be accessible to that employee. Clearly defined access roles make it easier to take control over sensitive information.

Social Media: The main security risk surrounding social media is personal information breaches and the sharing of confidential information over these networks. Some people post work related information in a Facebook wall post or when tweeting at someone, making the information available for a lot of people to see. There's a time and place for everything, and it's probably best not to have sensitive work related conversations with a colleague on a social media site.

Corporate security is the responsibility of everyone in the organization - not just the IT department. Security requires commitment from the upper-most levels of the organization so that the appropriate resources are available. No employee should be lazy about corporate security.

[infosecisland]