Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Friday, December 2, 2011

FBI Warns of New Fraud Scam

FBI Warns of New Fraud ScamZeus Variant Can Defeat
Two-Factor Authentication

By Tracy Kitten


The Federal Bureau of Investigation has issued a warning about a new Zeus malware attack targeting commercial bank accounts, ultimately leading to incidents of corporate account takeover. The Zeus variant used: a malware called Gameover, which the FBI says is able to defeat several forms of dual-factor authentication. To protect themselves, the FBI suggests consumers and businesses pay attention to suspicious e-mails. In the case of the Gameover attacks, e-mails purporting to come from NACHA-The Electronic Payments Association contained malicious links. NACHA does not traditionally send e-mails directly to businesses or consumers. Receipt of a direct e-mail from an organization such as NACHA should raise a red flag.

But according to the FBI's Denver Cyber Squad, it's not just phishy emails and dual-factor get-arounds that have made the Gameover attacks forces to be reckoned with. As it turns out, the fraudsters behind this scheme combined a number of tactics, including the use of money mules and denial of service attacks, to con businesses and banks out of funds.

To read the entire article, click here:
http://ffiec.bankinfosecurity.com/articles.php?art_id=4295&rf=2011-12-02-eb&elq=5209da99abcc4e7b8fa7af3303c5ca23&elqCampaignId=904

Wednesday, January 26, 2011

Facebook in the Workplace: Privacy

7 Privacy Tips for Safer Social Networking

By Upasana Gupta

Every day I hear from employees accessing Facebook in their workplace about how a friend tagged them in a photo that caused an awkward position with their bosses, and how could they avoid it?

We all know that on any social media network, the audience is unlimited, and the content is permanent. An employee may post one photo or get tagged in another and quickly remove it, but someone could still archive the page or make a copy, and that could result in their career and job being in jeopardy.

For employees using Facebook at work, whether to connect with friends during their lunch break or to develop relations with potential clients, I suggest a few privacy tips based on my conversation with Amber Yoo, director of communications at the Privacy Rights Clearinghouse.

To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=858&rf=2011-01-24-eb




Wednesday, December 15, 2010

More Americans Say They're Cybercrime Victims

11% of U.S. Households Report Computer-Related Crime in Past Year

By Eric Chabrow

Americans are nearly as likely to be victimized by an Internet-based crime as they are of other forms of nonviolent theft. At least that's the perceptions expressed by Americans when asked about crimes committed against themselves and their families.

Eleven percent of American adults report that they or a household member fell victim to a computer or Internet crime on their home computers in the past year, according to a Gallup Poll released Monday. By comparison, over the previous seven years, the percentage of Americans saying their were victimized by computer or Internet crimes ranged from between 6 percent and 8 percent.

Gallup says:

 "At 11 percent, computer/Internet-based crime is edging closer in reported frequency to the most common traditional forms of crime involving nonviolent theft of personal property and vandalism. Further, the increase is an exception in the overall crime picture, in that Americans' victimization reports have been fairly steady over the past several years. Not only has the overall percentage of Americans experiencing any type of crime been fairly flat, but Americans' reports of specific crimes have been flat as well."

to read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=820&rf=2010-12-14-eb
 
 


Saturday, November 6, 2010

ID Theft: SSN Is 'Key to the Kingdom'

Incidents Prove Link Between Social Security Numbers, ID Theft

Tracy Kitten, Managing Editor

The Colorado Supreme Court decision to reverse a conviction for criminal impersonation has stirred debate among identity theft protection advocates. In short, advocates say the Oct. 25 ruling sets a precedent that provides a loophole for those who impersonate others by stealing and/or misusing Social Security numbers.

"The Social Security number is the key to the kingdom of almost every type of identity theft," says attorney and certified information privacy expert Mari Frank. "It's the key to medical-benefit theft, government-benefit theft, you name it. This case, I think, sets a very bad precedent," she says, "because there are a number of people with bad credit or a criminal record or even illegal immigrants in this country that would use a stolen Social Security number to get a job, take out a car loan or get other benefits."

The Colorado Supreme Court overturned by a 4-3 decision the 2006 conviction of Felix Montes-Rodriguez for misusing another person's Social Security number to find work and apply for a car loan. Montes-Rodriguez' immigration status is not known; but the court found that because he used his own address, birth date and place of employment when he applied for the car loan, the use of the stolen Social Security number did not constitute false identity.

To read the entire article, click here -
http://www.bankinfosecurity.com/articles.php?art_id=3069&rf=2010-11-06-eb

Friday, November 5, 2010

Incident Response: Drafting the Team

What are the Key Skills for Your Organization?

Upasana Gupta, Contributing Editor

Nearly a year ago, IBM's client organization suffered a major malware attack. When Don Weber, then an incident response professional with IBM, arrived on-site with his team, they demonstrated timeline-based analysis that quickly provided them with system-based artifacts associated with the malware on the compromised systems.

Although the malware solutions were able to tell them which systems were currently infected, they had no way of telling which systems had been compromised, or whether the malware had been removed or instead rolled over to something that was not being detected.

Using the information available, Weber and his team took a step back from data analysis and developed a perl-based tool that detected specific registry keys that would work on live systems. Using this tool, the client's security team was able to distribute and reach all of their resources. This allowed them to systematically (over the course of several days) identify approximately 10 systems out of over 30,000 that needed to be added to the scope of the incident.

To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=3060&rf=2010-11-05-eg&amp

Saturday, October 23, 2010

PCI: Smaller Merchants Threatened

Criminals Now Picking Less Compliant Targets

Linda McGlasson, Managing Editor

The Payment Card Industry's Security Standards Council may be doing a good job helping lock down larger retailers, but the smaller "Mom and Pop" merchants are becoming the new targets of cyber criminals, says a PCI expert.

A recent report on PCI compliance by Verizon Business shows some unsettling trends, says Jen Mack, Verizon's director of global PCI consulting services.

Mack says Level 3 and 4 retailers are now being targeted by cyber criminals for the theft of credit card data. Examples of these targets include restaurants in several states that were hit in the past several months -- the latest being one that had its POS system breached in Tallahassee, Fla.

Level 3 merchants are defined by those merchants that have 20,000 or more credit card transactions annually. Level 4 are those that have fewer than 20,000 credit card transactions per year.

The PCI report shows that businesses of every size "are better at planning, doing -- not at checking if they are compliant," says Mack, a former member of the PCI Security Standards Council. The overwhelming majority of data breaches occur because of failures to check things were in place. Despite arguments to the contrary, Mack says "There's no open hole causing data breaches that isn't covered by the PCI standards."

To read the entire article, click here -  http://www.bankinfosecurity.com/articles.php?art_id=3019&rf=2010-10-23-eb


Friday, October 22, 2010

Two Cyberfraud Advisories Issued

Protecting Against Account Takeover, Money Mule Schemes

Linda McGlasson, Managing Editor

An industry group and federal law enforcement agencies have issued a set of much anticipated cyberfraud advisories for businesses and consumers. The two advisories address one of the fastest growing crimes, corporate account takeover, and related fraud, money mule schemes.

The two advisories, Fraud Advisory for Businesses: Corporate Account Take Over, and Fraud Advisory for Consumers: Involvement in Criminal Activity through Work from Home Scams, were issued by the Financial Services Information Sharing and Analysis Center (FS-ISAC), the Federal Bureau of Investigation, the United States Secret Service and the Internet Crime Complaint Center.

These advisories come just weeks after authorities in the U.S. and Europe arrested more than 100 people involved in a cybercrime gang that was stealing millions from U.S. businesses.

To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3023








 

Wednesday, October 6, 2010

Cybersecurity as a Catalyst for Economic Growth

Lessons from Sputnik: Producing Benefits Beyond Safeguarding IT

Eric Chabrow, Executive Editor, GovInfoSecurity.com

Fear is a great motivator. Fear helped the United States overtake the Soviet Union in the space race after the launch of Sputnik in the late 1950s. Americans feared our Cold War adversaries would conquer space, so the United States invested heavily, not only in technology, but in educating our young citizens in math and science to challenge the Soviets.

"We were really pretty far behind and we were kind of surprised that the Soviet Union was so far ahead in science and technology," Patrick Gorman, former associate director of the Office of the Director of National Intelligence, said in an interview with GovInfoSecurity.com (transcript below).

The return on that investment, just over a decade later, resulted in the United States landing men on the moon. And, the investments produced additional benefits such as the creation of the IT industry and other technological advancements unrelated to space.

To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2982&rf=2010-10-06-eg

Tuesday, October 5, 2010

Is CyberScope Ready for Prime Time?

Survey: Most Agencies Had Yet to Employ FISMA Reporting Tool

Eric Chabrow, Executive Editor, GovInfoSecurity.com

If you're a federal CIO or CISO, you either love CyberScope or are ignorant about it.

That's the takeaway of a survey published Monday by six IT security vendors on CyberScope, the automated FISMA reporting tool unveiled a year ago by Federal Chief Information Office Vivek Kundra. Major federal departments and agencies are to employ CyberScope by Nov. 15 to report on how they have complied this past year with the requirements of the Federal Information Security Management Act, the law that governs cybersecurity in the federal government, according to a memo issued by Kundra and White House Cybersecurity Coordinator Howard Schmidt in April.

Only 15 percent of the 34 federal chief information and chief information security officers surveyed in July had used CyberScope. Those CIOs and CISOs grave CyberScope a grade of A or B.

To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2978&rf=2010-10-05-eg   

                                                                                           

Do Do You Keep Your Career Options Open?

Do Do You Keep Your Career Options Open?
Call The POWER Group Organization Team at (502) 209-TEAM {8326}!

OSBW Blog Archive

Powered By Blogger