Showing posts with label Vulnerabilities. Show all posts
Showing posts with label Vulnerabilities. Show all posts
Friday, 23 March 2018
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Facebook Controversy: What to Know About Cambridge Analytica and Your Data
This week’s uproar over Facebook Inc. started years ago, with the mishandling of user data. Now that incident, and what followed, is at the center of a debate over how well the world’s largest social network protects its trove of user data. Read more…
Atlanta Ransomware Attack Freezes City Business
Ransomware that struck the city of Atlanta early Thursday morning froze internal and customer-facing applications, but officials say backups are in place and they expect to pay city employees on time next week. Read more…
Cryptocurrency mining malware uses five-year old vulnerability to mine Monero on Linux servers
Hackers are using a five-year-old security vulnerability to infect Linux servers with cryptocurrency-mining malware. The cryptojacking campaign exploits CVE-2013-2618, an old vulnerability in Cacti's Network Weathermap plug-in, an open source tool which is used by network administrators to visualise network activity. Read more…
House passes controversial legislation giving the US more access to overseas data
This week, the House of Representatives passed controversial legislation that would clarify and expand how data held overseas can be obtained by law enforcement in the United States. The change is part of the massive omnibus spending bill, and it incorporates measures first submitted earlier this year as the CLOUD Act. Read more…
Friday, 16 February 2018
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Equifax breach worsens, additional consumer data exposed
The Equifax breach compromised even more consumer data, including tax identification numbers, than originally reported. But the credit rating agency didn't disclose the update. Read more…
FedEx customer information exposed in data breach
An unsecured FedEx server was breached, exposing thousands of customers' personal information, a prominent security research firm discovered earlier this month. An unsecured Amazon S3 server was holding more than 100,000 scanned documents including passports, drivers licenses, and security IDs. Read more…
Criminals Hide 'Billions' in Cryptocurrency, Europol Warns
The value of a bitcoin has fallen from a high of around $20,000 last December, hovering on Thursday around the $10,000 mark. But despite bitcoin's volatility, cryptocurrencies remain a valuable tool for money laundering, law enforcement agencies warn. Read more…
Banks preparing for heightened New York cybersecurity laws to take effect
This week, senior executives from more than 3,000 banks, insurers and other financial services companies doing business in New York will have to personally certify that their computer networks are protected by a cybersecurity program appropriate for their organization’s risk profile. Read more…
Friday, 19 January 2018
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Meltdown-Spectre: Intel says newer chips also hit by unwanted reboots after patch
Intel says the unexpected reboots triggered by patching older chips affected by Meltdown and Spectre are happening to its newer chips, too. Read more…
BEC Attacks to Exceed $9B in 2018: Trend Micro
Business email compromise (BEC) attacks are projected to exceed $9 billion in 2018. To put that number in context, it has been less than a year since the FBI reported BEC attacks had become a $5.3 billion industry. Read more…
Mailchimp Found Leaking Email Addresses
MailChimp, the bulk email company responsible for sending millions of newsletters, promotional mail and other mass communiques every day, has been leaking respondents’ email addresses. Read more…
Cryptocurrency Investors Worry, Wait After Bitcoin Price Drop
Over the last month, in a series of volatile swings, the price of the cryptocurrency bitcoin rose to a record high — then plunged to less than half that value. The abrupt changes have inspired comparisons to the dot-com bubble, and underscored the extremely speculative nature of investing in cryptocurrency. Read more…
Thursday, 11 January 2018
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Equifax could face a massive fine for another security breach — if two top Senate Democrats get their way
Two top Senate Democrats are seeking broad new powers for the U.S. government to slap Equifax and its peers with massive fines if they suffer major cyberattacks — money that would then be returned to the millions of Americans affected by such a breach. Read more…
Toy firm VTech fined $650,000 over data breach
Electronic toymaker VTech will pay $650,000 (£480,000) to settle charges that it failed to protect the privacy of children using its gadgets. The US Federal Trade Commission (FTC) levelled the charges at VTech following a data breach in 2015. Read more…
Cryptominer malwares in RIG EK spread via malvertising
Malwarebytes researcher Jerome Segura analyzed a RIG exploit campaign distributing malware coin miners delivered via drive-by download attacks from malvertising. Read more…
Microsoft hits the brakes, stops rolling out Meltdown/Spectre patches for AMD devices
In response to BSOD errors, Microsoft paused rolling out Meltdown and Spectre patches to AMD devices. If an antivirus solution on other boxes is not compatible, then you won't be getting Windows security patches. Read more…
Friday, 22 December 2017
Weekly News Roundup
Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.
Open AWS S3 bucket exposes sensitive Experian and census info on 123 million U.S. households
Another cloud-based data repository, this one belonging to Alteryx, has publicly exposed datasets from the data analytics firm's partner Experian and the U.S. Census Bureau that contain sensitive personal information on 123 million U.S. households. Read more…
Fileless Malware Attacks Hit Milestone in 2017
Fileless malware attacks using PowerShell or Windows Management Instrumentation (WMI) tools accounted for 52% of all attacks this year, beating out malware-based attacks for the first time according to a new report. Read more…
Bitcoin and almost every other cryptocurrency crashed hard today
Bitcoin has been on a tear this past with the value of the cryptocurrency jumping from $8,000 to nearly $20,000. Well that run hit an abrupt end today as the price crashed as much as 23 percent on Coinbase. The price briefly dipped below $12,000 on some exchanges. Read more…
North Korean hackers turn focus to cryptocurrency, point-of-sale systems during holiday season
Cybercriminals linked to North Korea appear to be simultaneously targeting point-of-sale (POS) systems as well as cryptocurrency platforms as the annual holiday spike continues in retail stores and the hype surrounding bitcoin surges, according to new research. Read more…
Tuesday, 14 November 2017
The BOHH Breakdown, Part 11: Famous Data Breaches & How BOHH's Approach Could Have Helped
In our last post, we talked about the state of security for the Internet of Things (IoT) and how BOHH Labs’ approach brings more confidence to keeping these devices secure. This week, we will take a look at some of the most famous corporate data breaches to occur, and how BOHH could have prevented them.
Breach: Equifax (2017)
One of the biggest data breaches to dominate headlines recently is the Equifax breach. While it may not go down in history as one of the biggest breaches, it certainly made a big splash due to the sensitive nature of the data that was leaked. Over 143 million consumer records were exposed, and the information exposed included names, Social Security numbers, birth dates, addresses and in some cases, driver's license numbers. Due to poor network security and failure to update its software, hackers gained access to Equifax’s database through a web application vulnerability. While it was thought it was a US attack, its impact was global and affected Equifax customers and non-customers.
Type of Breach: Web Application Attack, leaving gaping holes to its network for hackers to exploit.
How BOHH Would Have Prevented It: Because BOHH’s service intersects all data requests, it is able to stop malicious attacks on the back-end database. Each data request has to go through a validation process before it gains authorized access to the backend database. BOHH also uses a patented system so a user’s data request never has direct access to the network server It can also check the return from the database, making sure only authorized information is returned.
Breach: Target (2013)
Though this breach took place several years ago, this is still one of the most famous breaches that has occurred due to the volume of people affected that compromised millions of its customers’ credit card and debit card accounts. All it took for 70 million people to have their credentials stolen was changing one line to the source code in the payment processing system and voilĂ . Target was unaware of the redirection of credit card details for a significant period of time which impacted their ability to resolve the issue and reduce the customer and finance impact.
Type of Breach: Phishing Attack, threat from unwanted access to a website, where changes are made to the website code enabling data to be re-routed/pushed to thief.
How BOHH Would Have Prevented It: BOHH prevents data from being re-routed through its patented block file system enabling full encryption of a website inside the firewall. When a user requests the website, BOHH goes to the server, and the AI engine pulls up the right blocks and decrypts them. It then puts the page together and passes it in memory to the web browser. This is without any direct access to the server from the requester, preventing phishing attacks and website changes to confidential data.
Breach: NSA Contractor Edward Snowden (2013)
One of the biggest intelligence leak in US history took place thanks to a NSA contractor abusing his system administrator insider access to the database and confidential information.
Type of Breach: Insider Threat/System Administrator abusing internal control and weakness in security procedures to leak confidential information.
How BOHH Would Have Prevented It: With BOHH, each dataset is encrypted with dynamically allocated keys and no encryption keystore, making it impossible for any user (including database admin) to steal useable data. This means that even if an insider gets access to confidential information, it is unreadable because there is no way to hack the encryption key.
These are just a few of the many attacks that could have been prevented by BOHH’s innovative approach to security.
Now that we’ve highlighted how BOHH could have helped prevented some of the most famous breaches around, come back next Tuesday when we take a look at some of the best security techniques being used to keep our data protected and give thanks in honor of Thanksgiving.
Subscribe to:
Posts (Atom)


