Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts













SOCIAL "NOT SO" SECURITY
 
The Internal Revenue Service today issued an alert to payroll and human resources professionals to beware of an emerging phishing email scheme that purports to be from company executives and requests personal information on employees.
 
The IRS has learned this scheme — part of the surge in phishing emails seen this year — already has claimed several victims as payroll and human resources offices mistakenly email payroll data including Forms W-2 that contain Social Security numbers and other personally identifiable information to cybercriminals posing as company executives.

“This is a new twist on an old scheme using the cover of the tax season and W-2 filings to try tricking people into sharing personal data. Now the criminals are focusing their schemes on company payroll departments,” said IRS Commissioner John Koskinen.

“If your CEO appears to be emailing you for a list of company employees, check it out before you respond. Everyone has a responsibility to remain diligent about confirming the identity of people requesting personal information about employees.”

IRS Criminal Investigation already is reviewing several cases in which people have been tricked into sharing SSNs with what turned out to be cybercriminals. Criminals using personal information stolen elsewhere seek to monetize data, including by filing fraudulent tax returns for refunds.

This phishing variation is known as a “spoofing” email. It will contain, for example, the actual name of the company chief executive officer. In this variation, the “CEO” sends an email to a company payroll office employee and requests a list of employees and information including SSNs.

The following are some of the details contained in the e-mails:
  • Kindly send me the individual 2015 W-2 (PDF) and earnings summary of all W-2 of our company staff for a quick review.
  • Can you send me the updated list of employees with full details (Name, Social Security Number, Date of Birth, Home Address, Salary).
  • I want you to send me the list of W-2 copy of employees wage and tax statement for 2015, I need them in PDF file type, you can send it as an attachment. Kindly prepare the lists and email them to me asap.
The IRS recently renewed a wider consumer alert for e-mail schemes after seeing an approximate 400 percent surge in phishing and malware incidents so far this tax season and other reports of scams targeting others in a wider tax community.

The IRS, state tax agencies and tax industry are engaged in a public awareness campaign — Taxes. Security. Together. — to encourage everyone to do more to protect personal, financial and tax data. See IRS.gov/taxessecuritytogether or Publication 4524 for additional steps you can take to protect yourself. 



















FROM A SECURITY PERSPECTIVE, IF YOU'RE CONNECTED, YOU'RE SCREWED

John Brennan, director of the notoriously secretive US Central Intelligence
Agency (CIA) has said that no one is safe from hackers only a few months after his personal email account was breached and the contents leaked online.

"The cyber environment can pose a very, very serious and significant attack vector for our adversaries if they want to take down our infrastructure, if they want to create havoc in transportation systems, if they want to do great damage to our financial networks," he said.

When asked whether other nations have the capability to 'turn off the lights' of the US he said: "I think fortunately right now those who may have the capability do not have the intent. Those who may have the intent right now I believe do not have the capability.














HONEY, WHO'S WATCHING THE KIDS?

Security flaws have been discovered in smart toys and kids' watches

 Rapid7 researchers have unearthed serious flaws in two Internet of Things devices:

  • The Fisher-Price Smart Toy, a "stuffed animal" type of toy that can interact with children and can be monitored via a mobile app and WiFi connectivity, and
  • The HereO, a smart GPS toy watch that allows parents to track their children's physical location.

In the first instance, API calls from the toy were not appropriately verified, so an attacker could have sent unauthorized requests and extract information such as customer details, children's profiles, and more.

"Most clearly, the ability for an unauthorized person to gain even basic details about a child (e.g. their name, date of birth, gender, spoken language) is something most parents would be concerned about.



While names and birthdays are nominally non-secret pieces of data, these could be combined later with a more complete profile of the child in order to facilitate social engineering or other malicious campaigns against either the child or the child's caregivers."

In the second instance, the flaw allowed attackers to gain access to the family's group by adding an account to it, which would allow them to access the family member's location, location history, etc.

Rapid7 has been working with the companies to correct the problems.

This further highlights nascence of the Internet of Things with regard to information security. While many clever & useful ideas are constantly being innovated for market segments that may have never even existed before, this agility into consumers's hands must be weighed against the potential risks of the technology's use,

Consumer brands must pay greater attention to application security when building smart devices. When a toy becomes connected to the Internet, a child is exposed to a potentially hostile environment. Regulations have not yet caught-up with the need for good application security.



Excerpt from Help Net Security, authored by Zeijka Zora











LOOK WHO'S LURKING AT YOUR FRONT DOOR 

Here’s the physical security that the Wi-Fi enabled, Internet of Things Ring smart doorbell gives you:

1) automatic activation and notification on your mobile phone when people come close to your home or loiter around it, and 2) a CCTV camera and high-quality intercom to talk to whomever comes knocking, even if you’re miles away.

Here’s the physical hole it was putting in your Wi-Fi: somebody could easily pop it off your front door (it’s secured with two standard screws), flip it over, retrieve the Wi-Fi password, and Presto! own your network.

To set it up, you have to connect the Ring to your Wi-Fi router, which means that you have to give it the password.The set-up button is connected to a back plate that attaches the doorbell to the wall providing power from an AC source. After you set it up, you attach it to the house with two screws.

If thieves are more interested in intruding into your Wi-Fi network than grabbing a $200 doorbell, they can turn it over and press the setup button, which sets the doorbell’s wireless module and creates an access point that’s simple to connect to.

In sum, an attacker can gain access to a homeowner’s wireless network by unscrewing the Ring, pressing the setup button, and accessing the configuration URL, all without any visible form of tampering..

Pen Test Partners, the company that found the vulnerability, did however, hand out kudos to Ring for responding to the vulnerability alert “within a matter of minutes,” with a firmware update released to fix the issue just two weeks after it was disclosed privately.

Internet of Insecure Things?

From kettles to intruder alarms, baby monitors, and drug pumps, anything that is part of the Internet of Things needs security built in right from the start.


Excerpt from Naked Security by Sophos, LLC  by Lisa Vaas















THE NOT SO SECRET SERVICE

This, today from the National Journal ....

"The federal government is expecting to spend more than $500 million in the next five years to manage data breaches. The money will be spent to clean up the damage that results from exposed data which often includes private information such as email passwords, credit card numbers and social security numbers. The government is budgeting this money to pay contractors that can mange these events."

The 2015 Ponemon Institute's Cost of Data Breach Study examined the cost incurred by 62 U.S. companies across 16 industry sectors.

According to this year's benchmark findings, data breaches cost companies an average of $217 per compromised record, of which $143 pertains to indirect costs which include abnormal customer turnover, and $74 represents the direct costs incurred to resolve the data breach such as investments in tech and legal fees.

According to the study, malicious attacks continue to be the primary cause of data breaches accounting for 49% of incidents. Nineteen percent concerned employee negligence and 32% involved IT and business process failures.

The total average organizational cost in 2014 rose to $6.53 million.  The study suggests steps to decrease the cost of a breach, but diligence and up-front investments appear to be front and center.

The statistics are chilling and should serve as a wake up call that has been ringing off the hook for several years.

The Feds are obviously concerned as they will be investing in excess of 15X the average rate of a U.S. firm's cost for the next 5 years, at minimum, to manage these expected events.  

Note to the Feds: How about managing increased security before the breach event?