Blog

Blog

Scope of FBI's National Security Letters Revealed by Lifted Gag Order

The scope of the FBI's national security letters (NSL) has been revealed by a lifted gag order on a man who fought against compliance for 11 years. On Monday, the United States District Court - Southern District of New York permitted the filing of a NSL received by Nicholas Merrill, founder of Calyx Internet Access, back in 2004. He has refused to...
Blog

The Three Principles of a Secure System

I recently attended a conference for security professionals at which a number of experienced (sounds better than seasoned) CISOs and SOs were presenting their insights into the challenges of cyber attacks and cyber crime faced by their organisations. Almost without exclusion, each presenter used the term CIA when discussing methodologies and...
Blog

Europol Takes Down 1,000 Websites Selling Counterfeit Goods

Europol, the European Union’s law enforcement agency, has seized nearly 1,000 websites illegally selling counterfeit merchandise to online consumers, authorities reported. In a press release, the agency said its international operation – known as In-Our-Sites (IOS) VI – tackled the sale of counterfeit...
Blog

The Industrial Internet of Things: Fueling a New Industrial Revolution

A transformative event is occurring where countless industrial devices, both old and new, are beginning to use Internet Protocol communication technologies. We refer to these collections of IP-enabled industrial devices and associated networks as the Industrial Internet of Things (IIoT). The Industrial IoT is at the very core of disruptive visions,...
Blog

Open Source Router Updates Its Own Security, Analyzes Network Traffic

This open source, crowdfunded router boasts a unique set of features, including the ability to update its own security and analyze the traffic between the Internet and the host network. Based on the Latin word for "tower", the Turris Omnia router is open source and runs OpenWrt, a free operating system that not only provides Omnia's users with the...
Blog

‘Tis the Season for Cyber Crime: 6 Tips for Safe Online Holiday Shopping

Cyber Monday is the heaviest online shopping day in the United States, with last year’s sales exceeding $2 billion within 24 hours. Unfortunately, for bargain-hungry consumers, the holiday shopping season is also a bonanza for cyber criminals. The huge uptick in website traffic means more potential targets, making the holiday season the perfect time...
Blog

MagSpoof Device Can Wirelessly Emulate Magnetic Stripes, Credit Cards

A security researcher has developed a device called MagSpoof that can emulate any magnetic stripe or credit card wirelessly. Hacker Samy Kamkar first came up with the idea shortly after he lost his American Express card last August. At that time, he noticed a pattern in his replacement card's last four digits when compared to those of his previous...
Blog

My SecTor Story: Root Shell on the Belkin WeMo Switch

*Updated 12/7/2015 – NOTE: The WeMo attack vector described in this article was resolved with WeMo firmware release 2.00.8643. Customers are encouraged to install the latest update immediately. There were many activities hosted at SecTor 2015. My favorite activity was the Internet of Things Hack Lab sponsored by Tripwire. The term Internet of...
Blog

How to Make Risk More Tangible for your Board

You know that cybersecurity risks exist for your company; so does your board. They know cybersecurity is a business issue, and they also know they need to be concerned about what it means to their business. But more often than not, the board doesn’t have a concrete understanding of how they can actually help. In a recent paper, Top 5 Tips for...
Blog

There Is Nothing New Under the Sun

The actual origination of the above phrase (worth reading in full) is Ecclesiastes 1:9, the Old Testament. With respect to whatever religion you worship, the point is simply to highlight the naivety in assuming something to be new or original without paying due attention to available mavens. Every “new” idea has some sort of precedent or echo from...
Blog

New Toolset Linked to Wiper Malware in Sony Hack, Finds Researchers

Researchers have discovered two new utilities that are closely associated with the wiper malware used to disrupt the computer networks of Sony Pictures Entertainment last year. After phishing for employees' login information, the attackers responsible for the breach used a strain of wiper malware known as "Destover" to wipe the files off of company...
Blog

5 Ransomware Safety Tips for Online Retailers

Just in time for the holiday shopping season, cybercriminals have developed a destructive new form of ransomware that targets the websites of online retailers. According to independent security journalist Brian Krebs, fraudsters have been leveraging the malware – dubbed ‘Linux.Encoder.1’ – to essentially hold a site’s files, pages and images for...
Blog

On Password Managers, Perspective and Patience

Throughout October this year, many tips for National Cyber Security Awareness Month focused on the password problem, including the usual warnings about weak passwords and the same password used in multiple places (known as “password re-use”). Every one of those tips (including more than one written by me) advises the use of a password manager to...