Showing posts with label Incidents. Show all posts
Showing posts with label Incidents. Show all posts

Tuesday, July 9, 2013

10 Principles To Guide Companies in Creating and Implementing Incident Response Plans

It's common that many companies have response plans but don't truly operationalize them!

With cyber criminals successfully targeting organizations of all sizes across all industry sectors, organizations need to be prepared to respond to the inevitable data breach.

A response should be guided by a response plan that aims to manage a cyber security incident in such a way as to limit damage, increase the confidence of external stakeholders, and reduce recovery time and costs.

Here are 10 principles to guide companies in creating and implementing incident-response plans:
  1. Assign an executive to take on responsibility for the plan and for integrating incident-response efforts across business units and geographies.
  2. Develop a taxonomy of risks, threats, and potential failure modes. Refresh them continually on the basis of changes in the threat environment.
  3. Develop easily accessible quick-response guides for likely scenarios.
  4. Establish processes for making major decisions, such as when to isolate compromised areas of the network.
  5. Maintain relationships with key external stakeholders, such as law enforcement.
  6. Maintain service-level agreements and relationships with external breach-remediation providers and experts.
  7. Ensure that documentation of response plans is available to the entire organization and is routinely refreshed.
  8. Ensure that all staff members understand their roles and responsibilities in the event of a cyber incident.
  9. Identify the individuals who are critical to incident response and ensure redundancy.
  10. Train, practice, and run simulated breaches to develop response "muscle memory." The best-prepared organizations routinely conduct war games to stress-test their plans, increasing managers' awareness and fine-tuning their response capabilities.

An effective incident response plan ultimately relies on executive sponsorship. Given the impact of recent breaches, we expect incident response to move higher on the executive agenda. Putting the development of a robust plan on the fast track is imperative for companies.

When a successful cyber attack occurs and the scale and impact of the breach comes to light, the first question customers, shareholders, and regulators will ask is, "What did this institution do to prepare?"

Monday, October 8, 2012

When universities will take SECURITY seriously?

Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

Hackers published online Monday thousands of personal records from 53 universities, including Harvard, Stanford, Cornell, Princeton, Johns Hopkins, the University of Zurich and other universities around the world. The group of hackers, calling themselves Team GhostShell, claimed responsibility for the attack on Twitter and published some 36,000 e-mail addresses and thousands of names, usernames, passwords, addresses and phone numbers of students, faculty and staff, to the Web site Pastebin.com.

In most cases the data was already publicly available, but in some instances the records included additional sensitive information such as students’ dates of birth and payroll information for university employees. Typically, hackers seek such information because it can be used to steal identities, crack bank accounts or can be sold on the black market.

Universities make ripe targets because they store vast numbers of personal records, often in decentralized servers. The records can be a gold mine because students often have pristine credit reputations and do not monitor their account activity and credit scores as vigilantly as adults. Dozens of universities have been plagued by breaches recently.

Last August alone, the University of Rhode Island warned that students and faculty that their information may have been exposed. And at the University of Arizona, a student discovered a breach after a Google search exposed her personal information — and that of thousands of others at the university. Smaller computer breaches at Queens College and Marquette University were also reported.

In this case, the hackers said they were not motivated by profit but to “raise awareness towards the changes made in today’s education.” In a message accompanying the stolen data, they bemoaned changing education laws in Europe and spikes in tuition fees in the United States. But they also noted that in many cases, the servers they breached had already been compromised. 

“When we got there, we found that a lot of them have malware injected,” the hackers wrote on Pastebin. To breach servers, the hackers used a technique known as an SQL injection, in which they exploit a software vulnerability and enter commands that cause a database to dump its contents.

In the case of some universities, the hackers breached multiple servers. At colleges across the country, some students set up sites that allowed students and faculty to search the leaked data for their information. For instance, at the University of Pennsylvania, Matt Parmett, a junior, created a Web site that made it possible for classmates to search the leaked data by name.

Wednesday, September 12, 2012

Insiders suspected in Saudi cyber attack

Biggest Security Threat? Insiders?

One or more insiders with high-level access are suspected of assisting the hackers who damaged some 30,000 computers at Saudi Arabia’s national oil company last month, sources familiar with the company’s investigation say.

The attack using a computer virus known as Shamoon against Saudi Aramco – the world’s biggest oil company – is one of the most destructive cyber strikes conducted against a single business. Shamoon spread through the company’s network and wiped computers’ hard drives clean.

Saudi Aramco says damage was limited to office computers and did not affect systems software that might hurt technical operations. The hackers’ apparent access to a mole, willing to take personal risk to help, is an extraordinary development in a country where open dissent is banned.
“It was someone who had inside knowledge and inside privileges within the company,” said a source familiar with the ongoing forensic examination. 
Hackers from a group called “The Cutting Sword of Justice” claimed responsibility for the attack. They say the computer virus gave them access to documents from Aramco’s computers, and have threatened to release secrets. No documents have so far been published.

Reports of similar attacks on other oil and gas firms in the Middle East, including in neighboring Qatar, suggest there may be similar activity elsewhere in the region, although the attacks have not been linked. - Reuters

Saturday, June 18, 2011

Index of Cybersecurity

New Index Measures Cyberspace Safety

Quantifying the safety or danger of cyberspace is tough. But a highly respected IT security practitioner and an experienced risk management consultant have teamed to develop an index they contend reflects the relative security of cyberspace by aggregating the views of information security industry professionals.

"We don't have much to compare to in this field because hard numbers are very hard to get", advised by Mukul Pareek developed the
Index of Cybersecurity, a sentiment-based measure of the risk to the corporate, industrial and governmental information infrastructure from a range of cyberthreats.

The
index of Cybersecurity launched in April, and in an interview with Information Security Media Group's GovInfoSecurity.com say it could be months before its value to government and private-sector information security officers will be known.

The developer of the index "Mukul Pareek" suspects the index will serve as a baseline for information security officers to compare their organizations' performance against the general state of IT security. "An information security officer has among other questions the perpetual one of: Am I being targeted, am I different, what are other people seeing, is there a baseline I can compare myself to?". "And, it's a constant problem. In fact, unless you do some sort of information sharing, there is little way to tell whether your observations are unique or typical or altogether ordinary except for one feature or the like."

The
cybersecurity index features 15 sub-indices that measure malware threats, intrusion pressures, insider threat, industrial espionage, information sharing and media and public perception, to name a few.

In the interview, Geer and Pareek also explain how the index works and ways it could be employed, such as a metric to assess cybersecurity insurance policies.

Sunday, March 27, 2011

9 Ways to Help Safeguard RSA's SecurID

RSA Strongly Urges Customers to Act Immediately

Security vendor RSA is providing remediation steps for customers to strengthen their RSA SecurID implementations in light of an advanced persistent threat attack against the company, which it says was directed at its SecurID two-factor authentication product (see Hackers Target RSA's SecurID Products).

Here are the nine steps RSA recommends customers take:

1. Increase focus on security for social media applications and the use of those applications and websites by anyone with access to their critical networks.

2. Enforce strong password and PIN policies.

3. Follow the rule of least privilege when assigning roles and responsibilities to security administrators.

4. Re-educate employees on the importance of avoiding suspicious emails, and remind them not to provide user names or other credentials to anyone without verifying that person's identity and authority. Employees should not comply with email or phone-based requests for credentials and should report any such attempts.

5. Pay special attention to security around their active directories, making full use of their SIEM (Security Information and Event Management) products and implement two-factor authentication to control access to active directories.

6. Watch closely for changes in user privilege levels and access rights using security monitoring technologies such as SIEM, and consider adding more levels of manual approval for those changes.

7. Harden, closely monitor and limit remote and physical access to infrastructure that is hosting critical security software.

8. Examine help desk practices for information leakage that could help an attacker perform a social engineering attack..

9. Update security products and the operating systems hosting them with the latest patches.

"We strongly urge immediate customer attention to this advisory," the company said.

Tuesday, August 31, 2010

The Human Side of Security

Most corporate security breaches are a result of low-tech oversights and employee negligence - not the work of systems hackers.

With all the focus on high-tech security, organizations are overlooking some basic gaps that leave them vulnerable to data loss and network intrusion. Despite a handful of high-profile hacking incidents, the preponderance of corporate security breaches are tied to low-tech oversights or employee negligence.

Insider negligence was a significant factor in more than 88 percent of all cases in a January 2009 study of the cost of data breaches by the Ponemon Institute. About 35 percent of the breaches identified in the study involved lost or stolen laptop computers or other mobile data-bearing.

Other common gaps: improperly disposed of PCs or backup tapes, unattended shredders and countless other seemingly mundane and benign events that occur regularly in the course of daily offlice life.

People may not realize that the vast majority of high-impact security breaches - particularly the ones that involve loss of important business or personally indentifiable data -- are not not the result of a pierced and tattooed hacker in the basement, but often the result of either mistakes or mischief by insiders who have access to that data in the course of their normal work.

Sunday, July 25, 2010

"Accountability What’s That?”

Pay-At-The-Pump Skimming - a Growing Threat

Card fraud is growing. At the root of the problem is skimming. This is a global challenge that impacts all types of card-reading machines, including ATMs and POS devices. The Secret Service estimates that in 2008 some $8.5 billion was lost as a result of skimming and phishing attacks.
A rash of attacks in Utah resulted in the compromise of 180 pay-at the-pump terminals with skimming devices and Bluetooth technology to transmit card data.
When it comes to the ATM, the global financial industry has invested heavily in solutions to thwart skimming. Visa and MasterCard have mandated several security precautions, such as encrypting PIN pads and Triple DES compliance, to ensure ATM deployers adequately protect cardholder data.

But what about unattended self-service devices, which have proven to be much more vulnerable?

Case in point: The pay-at-the-pump terminal.

Pay-at-the-pump terminals are targets because they can easily be entered with universal gas keys. Once the terminals are opened, skimmers can be placed inside, away from view. In comparison, ATMs are required to have unique keys and codes for service and maintenance checks.
Let's be fair. Unless a skimming device is found, or law enforcement notifies a business that its terminals have been compromised, a typical merchant would never see the fraud. The cards are skimmed, duplicates are created, and the fake cards are used at ATMs, online and/or at retailers globally.

But does that free the merchant from bearing some of the responsibility?

Friday, June 25, 2010

IPS needs to have SSL inspection

The Next-Generation IPS


The network IPS isn't like the firewall -- it's not a must-have security device found in most every enterprise network. Even so, today's intrusion prevention system is still gaining new features and becoming more tightly integrated into the security infrastructure.

The IPS is sharing more traffic attack data with the firewall and gaining virtualization features, horsepower, and enhancements to become more application-aware, as well as to help secure client machines. Compliance has helped keep the IPS alive and well, despite predictions of its demise over the years.

And it could be the federal government that gives IPSes a big boost: The U.S. Department of Homeland Security is currently testing out an IPS system called EINSTEIN 3 that could eventually be deployed across all executive branch civilian networks. Even so, some security experts remain skeptical about the IPS finding a real home in the enterprise.

Refer here to read more details.

Monday, May 3, 2010

How to Respond to Vishing Attacks

Tips for Incident Response Plan

Vishing is a form of phishing, where instead of people receiving an email trying to lure them into giving personal information, the criminal uses a phone call, either live or automated, to attack the bank or credit union customer and get critical information. (Here is an actual vishing attempt recorded by one institution.) In response to this spree of attacks, banking/security leaders from one of the impacted states have put together a vishing incident response plan for financial institutions.

Vishing Incident Response Plan

1 - Set Procedures to Report Calls

Have procedure for employees to report at the time of first (and subsequent) notification. This should include:

  • information on originating phone number (if known);
  • any pertinent details of phone conversation or recorded message;
  • what information was solicited (account numbers, debit card information)?
  • did customer give out information and, if so, was account closed or debit card inactivated?
  • what was the callback number if the customer was directed to return a call?
  • was the call made to your customer's cell phone or a landline?
  • if the call was to a cell, who was the carrier (eg ATT, Optus, Telstra)?
2 - Alert Customers

Notify customers as soon as you see a pattern of calls. Specifically:
  • Explain phone phishing (vishing) and text message phishing (smishing) to customers reporting calls. Have a script ready for your call center staff to refer to that describes what it is, and actions that the customer needs to take when they receive such calls.

  • Consider initiating a news article in your local paper or other media. This article needs to make clear that your bank is protecting customers with this information, and you have not suffered a breach. Non-customers will also be getting these calls, and that is proof that the calls are randomly generated to your area and not the result of any breach. This is a great time to reinforce that you will never call, email, or text to have your customer provide an account number or debit card information, as you already have that information available.

    Encourage anyone receiving these calls to hang up and call their financial institution directly on a number that they obtain themselves. Also provide a reminder that any caller ID is easily "spoofed." Fraudsters can put in the number of any financial institution with a spoofing system and that will be displayed on the customer's phone.

  • Place a banner with news of vishing attempts on your web page to let customers know that it is occurring in your area and you are protecting them through the notification. Consider adding signage and posters for drive-throughs and lobby areas to alert customers to the scam.
3 - Run Down the Source
  • Identify the area code(s) on calls of origination and lines that customers are requested to call (simply Google the area code, "XXX area code").

  • If the calls appear to be generated in the U.S., contact your local FBI office and ask for their cybercrime specialists or white collar crime division, which will handle bank fraud. They can help to get the phone line shut down immediately. You will also want to contact your local law enforcement contacts to alert them to the scam because consumers will be calling them to report the attempts.

  • If the calls are Canadian-based, contact the PhoneBusters in Ontario. This is the Canadian Anti-Fraud Call Center and is staffed by the Royal Canadian Mounted Police. They can be reached at www.phonebusters.com or 888-495-8501. They can assist in shutting down Canadian lines and will provide you with a reference number on your case in the event you secure additional information to report to them.

  • If the calls are Australian-based, contact your local police station with all the relevant details.
4 - Notify Telecomm Carriers

Lamb of Central National Bank in Enid, OK, has compiled a list of email addresses and a sample email that he uses to get lines shut down.

Email addresses: 'QwestFraud@qwest.com'; 'abuse@att.com'; 'abuse@verizon.com'; 'abuse@qwest.com'; 'fraud@qwest.com'; 'abuse@sprint.com'; 'fraud@sprint.com'; 'abuse@level3.com'; 'abuse@alltel.com'; 'fraud@alltel.com'; 'fraud@tmccom.com'.

Samples email text: Fraudulent Text messages are being sent to cell phones in Northeastern Oklahoma: "This is an automated message from XXXX National bank. Your ATM card has been suspended. To reactivate call urgent at 18775895978." This is an IVR that attempts to get card numbers and PINs. If this 877 number is yours please shut it down, if not please forward to the responsible organization.

The words "Criminal Activity" in the subject line help get faster responses.

5 - Make Customer Education a Priority

Keep the educational awareness of these types of scams in front of your customers by adding sections on the institution's webpage about the types of crimes that may happen. Add the same messages to your statement stuffers, call waiting feature and newsletters for added impact. Also be sure to tell your customers that no one will ever call them from the institution, soliciting information from them. Always remind your customers to alert you when they receive a call, text, or email from your institution that doesn't seem right

Thursday, April 22, 2010

Fraudsters Swapping Out POS Devices, Stealing Card Data

Data at Risk

Once the device has been swapped, the amount of data to be stolen is related to the amount of time the compromised terminal is in place at the retail location. It also depends on the number of cards that transact during that time. It can run into thousands of cards.


In most of the POS terminal compromises Urban says he has seen in the U.S. that the data is stored on the POS terminal until the terminal is swapped back out. But there is a trend where card compromising devices will broadcast data via Bluetooth or other wireless protocols.

The Hancock Fabrics data breach continues to raise new questions about the security of point of sale (POS) devices at retail stores.

In March, the national fabric store chain publicly confirmed the breach it suffered last summer, sending an open letter to its customers, revealing: "PIN pad units at a limited number of Hancock Fabrics stores were stolen and replaced with visually identical, but fraudulent, PIN pad units. This may have allowed criminals to capture - or "skim" -- payment card data during transactions."

Hancock didn't reveal the locations or number of stores where point of sale scanners were compromised -- nor the number of customers who had their card data taken -- but at least 140 reports from customers in California, Wisconsin and Missouri show the pervasive nature of the fraud.

The lesson here: It is relatively easy for fraudsters to tamper with or even swap out POS PIN Entry Device (PED) pads, and these types of incidents are likely to increase, putting retailers, consumers and banking institutions at risk of future card-related fraud.

According to Bank Info Security, It is conceivable that the data captured can be Track 2 data plus the user's PIN, "which means the criminal may be able to manufacture fake debit cards," says Chuvakin. This data with full access to bank account withdrawal up to a daily limit of $500 could inflict real damage to individual victims - with banking institutions then footing the bill to replace cards and/or monitor accounts.

Prevention and Education

The Hancock Fabrics breach points to several steps that retailers can take to prevent this kind of crime from happening to them:

Ensure PCI Compliance -- Making sure all POS terminals are PCI compliant, using Derived Unique Key Per Transaction (DUKPT). Securely install terminals with unique hardware as a deterrent, and visibly inspect them along with the registers every day.

Educate Employees -- Security awareness training for all store employees would be a great start. Newer pin pads that have more built-in security measures like device tamper resistance can help, but it's important to keep spare PIN pads locked away, and employees should periodically check them while at work to make sure the device ID still matches.

Auditing the PEDs -- on a regular basis, recording them and cross checking the serial numbers. Chuvakin, who recommends retailers follow PED Security Guidelines and review the condition and placement of internal CCTV systems to cover all till areas.

Watch Your Staff -- The PCI Security Council's PIN Transaction working group also recommends performing background checks on employees, as well as keeping a complete record of any work done on the POS pads by service providers. If a service engineer arrives at the store unannounced to do work on the PEDs, the working group recommends that before any work is performed that their identity be confirmed by contacting the service company.

Tuesday, February 16, 2010

Criminals are harvesting and selling Facebook users' information

Facebook users 'easy prey'

Facebook users have become easy prey for criminals as more and more people share personal information on the social networking site, says a computer anti-virus company.

Criminals are harvesting and selling Facebook users' information, stealing identities, sending spam and planting viruses, according to AVG (AU/NZ).

People put themselves at risk every day by carelessly clicking on invitations sent by 'friends' to join groups or write on their wall. They put all their personal information including date of birth and photos on their page. They even respond to fake Facebook requests for security details.

To help people stay safe on Facebook, AVG gave 10 tips:

1. Think about who you add: accepting a friend request provides your new mate with access to posts, photographs, messages and background information about yourself. Perhaps go through your list of friends and think about who you really want accessing your stuff.

2. Check privacy settings: Facebook recently got a face-lift, changing default privacy settings. It's worth going through them again - you may be sharing more than intended.

3. Why are you on Facebook? Is it just to share photos? Keep in touch with people? Share links and updates of your activities? Ask yourself what you want to achieve with your profile. It could be better to cut down on information-sharing.

4. Be smart about your password: try not to use the same passwords for all your accounts. Think about the type of security questions you set and where you are sending your updates.

5. Be aware of where you sign in from: When signing in from a different computer, check that it doesn't store your e-mail address and password. It's easy to accidentally choose it to "remember you".

6. Be careful what you say: once status updates and comments are posted, anyone can see, copy, and post it elsewhere. Do you really want people to know you'll be home alone tonight or away on vacation next week?

7. Watch out for phishing attacks: there have been numerous attempts to get users' login and passwords by tricking them with fake Facebook e-mails. Never select any e-mail links asking you to reset your password. Always go directly to Facebook.


8. Take immediate action: If friends start receiving spam from you or status updates appear that you didn't make, your account may be compromised. Immediately change your password. If you can't log into your account, go to the Help link at the bottom of any Facebook page and click on "security" to notify Facebook.


9. Protect your mobile device: Many mobile phones have direct access to social networking sites, including Facebook. Be mindful about who has access to your cellphone and make sure you log off the sites.

10. Monitor suspicious activity: Watch out for suspicious activity on your wall, news feeds and Facebook inbox. Never click on a suspicious link. Look closely, if the link does not look authentic, don't click.

Tuesday, January 19, 2010

Top-Five Facebook Scams

You Should Protect Yourself From hackers and spammers

As Facebook has grown in popularity, it has also become a primary target for hackers and spammers. An increasing number of Facebook users are having their accounts compromised. Each newly compromised account is then used by the hackers and scammers to propagate their scam further. You don’t need to be an idiot to have your account compromised. If you are caught off guard for a second, you may accidentally fall for one of these scams.
  1. IQ Quiz Adds

    While Facebook has spent the past year trying to cut down on the number of misleading advertisements on the site, the fact remains that a small percentage of users still get duped into purchasing services they don’t really want. The IQ Quiz Scam has become ubiquitous on the Facebook Platform, and those users who install applications can expect to see an advertisement for an IQ Quiz Scam at some point. In December one application was discovered in which developer was using spammy techniques to get new users to install their application and ultimately click on the IQ Quiz advertisements.

    As soon as you click on one of the ads, you’ll be brought to a site where you’re asked up to 10 questions which are relatively easy to answer. You will then be prompted to enter your phone number to view the results. Don’t enter your phone number! If you do, you will be charged upwards of $10 a week directly to your phone bill. While most phone companies are willing to refund you for your first purchase, they won’t do it after the first occurrence. That’s because the phone companies generate billions of dollars each year off of these types of transactions.

    If you want to protect yourself from IQ quiz scams, do not enter your phone number into any sites outside of Facebook.

  2. I’ve Been Robbed! Western Union Me Money!

    You’re browsing around Facebook and suddenly one of your friends IMs you to tell you that they’re stuck in another country; they’ve been robbed, don’t have a wallet, and need money to get out of the country. It’s a horrible situation but what are the odds that they found a computer to log on to in order to instant message you? Even worse, what are the odds that one of your friends who was travelling abroad got robbed and wasn’t able to find anybody to help them out?

    I’ve been with people who’ve lost their wallet abroad and needed to get money sent via Western Union, however if the person can get access to Facebook, they probably can access a phone. While you should always help out your friends, you can avoid being duped by international fraudsters by asking your friend to call you in order to wire the money. Unless your friend is in the middle of a jungle in the Congo, they should be able to call you.

    Most of the times in such incidents, it is a scammer who has stolen your friend’s account and is systematically going through and IMing each of their friends to try and get money wired to them. Don’t fall for it, try to talk to them on the phone before offering any help.

  3. Facebook Phishing Landing Pages

    One of the most common ways Facebook accounts get compromised is through simple phishing scams. The way it works is that a user’s account is compromised by a hacker and the hacker then uses that account to automatically post links on each of that user’s friends’ walls. Sometimes the system will send messages to the friends such as “Check out this funny video of you!” with a link that redirects to a page with a fake Facebook login page.

    It’s pretty straight forward, and it’s easy to avoid, however countless people have fallen for this scam. The easiest way to tell if it’s a scam is by looking at the URL of the page you land on. The best way to protect yourself is, anytime you see a Facebook login page, leave it and go to http://www.facebook.com in your browser. This way you can ensure you are logging in to the correct site.

  4. Koobface Worm That Automatically Hijacks Your Account

    Facebook has worked aggressively to prevent this worm, it still continues to spread rapidly. The scam is pretty straight forward. In this attack, a user will receive a message from what appears to be one of their friends. The message will say things like “Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments” and many others.

    Included in the message will be a link to a page which appears to be a YouTube video. If you click on the video, you will be prompted to “upgrade your Flash player now” and will ask to download a file which contains the Koobface worm. If you download and install the file, your computer will automatically log in to Facebook and send similar messages to your friends.

    The best way to avoid this scam is to avoid all links that are posted on your wall or in your inbox that are out of the ordinary. Also, never download a file / codecs after clicking on a link.

    To learn more about the Koobface worm, check out the information at the
    Kapersky Lab.

  5. Other Malware Applications And Links

    While we’ve attempted to highlight the primary scams, hackers and scammers are constantly evolving their strategies to steal passwords, and take over computers. The best thing to do is always be careful of strange links posted to your profile or messages sent to your inbox. While many of the scams on Facebook are harmless to your computer, it's still important to protect yourself against any viruses and worms.

    Some Facebook applications have used toolbars among other things to make money from their application. Some of these toolbars will significantly damage your computer.

The bottom line is: be on guard any time you see anything suspicious. If you do notice anything suspecious or happen to fall for a scam, make sure to immediately change your password. If you aren’t able to access your account because you were phished and your password was changed, fill out this form, which might help you get your account back.

Monday, January 7, 2008

Boeing New 787 May Be Vulnerable to Hacker Attack

Unbelievable - Hacking Boeing Jet.

Well, it will really sound scary when i will say Boeing NEW 787 maybe hacked. Just picture this, someone sitting in the New 787 and notice on of the passenger has hacked the Dreamliner Jet.

"This is serious," said Mark Loveless, a network security analyst with Autonomic Networks, a company in stealth mode, who presented a conference talk last year on Hacking the Friendly Skies (PowerPoint). "This isn’t a desktop computer. It's controlling the systems that are keeping people from plunging to their deaths. So I hope they are really thinking about how to get this right."

Please read full article on: New 787 May Be Vulnerable to Hacker Attack.