Showing posts with label Security Alerts. Show all posts
Showing posts with label Security Alerts. Show all posts

Wednesday, June 19, 2013

SCAM Alert: Puppy Scams & Business Executive Scams

NEVER send money or give credit card or online account details to anyone you do not know and trust.

Almost everyone will be approached by a scammer at some stage. Some scams are very easy to spot while other scams may appear to be genuine offers or bargains. Scams can even take place without you doing anything at all.

Two scams have been identified prominent and needs awareness are:

(1) The “Puppy Scam” which is aimed at the dog lover, has been around for many years and appears to be rising again.

(2) The “Business Executive Scam” looks to victimize businesses in both Canada and the United States of America.

The Puppy Scam Method of Solicitation: Purebred dogs are offered at lower than normal prices. Straight forward ads are placed in free on-line sales sites like Gumtree, Craigslist and community web pages. The use of standard Newspapers ads has also been identified.

A twist to the scam also sees the seller leaving countries to do a ‘Christian Mission’ in other country. They must sell their dog because of their commitment to this mission where they will be helping people less fortunate. Although mobile phones have been used mainly the communication is done through an email address.

Victim Remittances: The use of money service businesses (MSB) is the primary method the fraudster uses to collect victim funds. Once the price is confirmed and the original payment is made the victim can expect many more communications from the fraudsters because the victim has to pay the “certified Transportation Company”, the “out of country tax”, the “Anti-terrorist fee” or the “verification of vaccination fee” just to name a few.

Additional emails will follow until the complainant finally realizes they are a victim and will never get a dog. Most of the destinations of the MSB transfers are West African nations including Nigeria, Ghana and Cameroon.

Refer here and here for more information.

The Business Executive Scam Fraudsters are researching companies on-line via company websites. To make this scam work, the fraudsters need to identify a company executive (IE CEO, President, manager, owner) as well as an email address to the accounting department. Once identified the fraudster creates an email address using the free emails of Yahoo, MSN or Google. The email address will be for instance “The executives name@ Yahoo.com”.

A message will be emailed to the accounting department advising that the executive is working at home or off-site and the executive has identified an outstanding payment that needs to be made ASAP.

The Executive instructs that a payment be made, generally in the amount of 25,000 to 80,000 dollars to an identified person and bank account.

Bank accounts associated to this fraud have been identified across North America thanks to the efforts of the complainants and the banks. Currently the victimization rate is very low but it has the potential for high dollar loss. Identified bank accounts require prompt action.

Refer here to learn more types of Business Executive Scams.

Wednesday, April 17, 2013

Can Enterprise rely on MDM to achieve Mobile Security?


mRAT spyware bypasses mobile enterprise controls
Mobile remote access Trojan (mRAT) infections are increasing and bypassing mobile enterprise security controls, putting businesses at risk of cyber espionage, research has revealed.
mRATs are capable of intercepting third-party applications such as WhatsApp, despite guarantees of encrypted communications, the study of 2 million smartphone users by Lacoon Mobile Security found.
The research also showed that mRATs are similarly able to bypass security controls in mobile device management (MDM) systems, which a growing number of businesses rely-on for mobile security.
mRATs are designed to carry out cyber espionage and typically enable eavesdropping on calls and meetings, extracting information from email and text messages and location tracking of executives.
The spyware requires a backdoor for installation, through the rooting of Google Android or the jailbreaking of Apple iOS devices.
The research found that mRATs can bypass rooting and jailbreaking detection mechanisms installed on handsets, with 52% of infected devices found running iOS and 35% running Android.
The attacks undermine the basic notion of a secure container on which most MDM systems are based, according to Lacoon Mobile Security.
MDM systems create secure containers that separate business and personal data on the mobile, in an attempt to prevent business-critical data from leaking.
However, the research team demonstrated that mRATs do not need to directly attack the encryption mechanism of the secure container, but can grab it at the point where the user pulls up the data to read it.

Mobile best practices and technologies include:
  • Remotely analyse the risk involved with each device, including behavioural analysis of the downloaded applications;
  • Calculate the risk associated with the device's operating system vulnerabilities and usage;
  • Conduct event analysis to uncover new, emerging and targeted attacks by identifying anomalies in outbound communications to C&C servers;
  • Enable network protection layer to block exploits and drive-by attacks and contain the device from accessing enterprise resources when the risk is high.


Saturday, July 28, 2012

5 Tips to Improve Intrusion Detection

NIST Revising Guide on Detection, Prevention Software


Intrusion detection and prevention software has become a necessary addition to the information security infrastructure of many organizations, so the National Institute of Standards and Technology is updating its guidance to help organizations to employ the appropriate programs.


NIST is seeking comments from stakeholders on the guidance, Special Publication 800-93, Revision 1 (Draft): Guide to Intrusion Detection and Prevention Systems, before publishing a final version. SP 800-93 describes the characteristics of intrusion detection and prevention software technologies and provides recommendations for designing, implementing, configuring, securing, monitoring and maintaining them.


The types of intrusion detection and prevention technologies differ primarily by the types of events that they monitor and the ways in which they are deployed. The NIST publication addresses four types of intrusion detection and prevention software technologies:

  • Network-based, which monitors network traffic for particular network segments or devices and analyzes the network and application protocol activity to identify suspicious activity.
  • Wireless, which monitors wireless network traffic and analyzes it to identify suspicious activity involving the wireless networking protocols themselves. IDPS for wireless is an important type for all organizations to have because of the growth of mobile devices and employees' desire to use their own wireless device for work.
  • Network Behavior Analysis, which examines network traffic to identify threats that generate unusual traffic flows, such as denial of service attacks, certain forms of malware and policy violations such as client system providing network services to other systems.
  • Host-based, which monitors the characteristics of a single host and the events occurring within that host for suspicious activity.

Intrusion detection systems automate the intrusion detection process whereas intrusion prevention systems have all the capabilities of an intrusion detection system and also can attempt to stop possible incidents. These technologies offer many of the same capabilities, and administrators can usually disable prevention features in intrusion protection products, causing them to function as intrusion detection software.


The Recommendations NIST says organizations that implement the following recommendations should facilitate more efficient and effective intrusion detection and prevention system use:

  1. Organizations should ensure that all intrusion detection and provision system components are secured appropriately because these systems are often targeted by attackers who want to prevent them from detecting attacks or want to gain access to sensitive information in the intrusion detection and prevention system, such as host configurations and known vulnerabilities.
  2. Organizations should consider using multiple types of intrusion detection and prevention technologies to achieve more comprehensive and accurate detection and prevention of malicious activity. The four primary types of intrusion detection and prevention technologies - network-based, wireless, network behavior analysis and host-based - each offer fundamentally different information gathering, logging, detection and prevention capabilities.
  3. Organizations planning to use multiple types of intrusion detection and prevention technologies or multiple products of the same technology type should consider whether or not the systems should be integrated. Direct intrusion detection and prevention system integration most often occurs when an organization uses multiple products from a single vendor, by having a single console that can be used to manage and monitor the multiple products. Some products can also mutually share data, which can speed the analysis process and help users to better prioritize threats.
  4. Before evaluating intrusion detection and prevention products, organizations should define the requirements that the products should meet. Evaluators must understand the characteristics of the organization's system and network environments, so that a compatible intrusion detection and prevention system can be selected that can monitor the events of interest on the systems and/or networks.
  5. When evaluating intrusion detection and prevention products, organizations should consider using a combination of several sources of data on the products' characteristics and capabilities. Common product data sources include test lab or real-world product testing, vendor-provided information, third-party product reviews and previous experience from individuals within the organization and trusted individuals at other organizations.

Comments on the draft guidance should be sent to 800-94comments@nist.gov by Aug. 31.

Monday, June 4, 2012

Free Framework for Vulnerability Reporting

Breach Info Sharing Tool Enhanced


The Industry Consortium for Advancement of Security on the Internet has introduced an enhanced version of its free security vulnerability reporting framework designed to ease the sharing of breach information.


The framework enables stakeholders across different organizations to share vulnerability information in an open and common machine-readable format. ICASI, a non-profit association of eight major information technology companies, says Version 1.1 of the Common Vulnerability Reporting Framework offers users a more comprehensive and flexible format, while reducing duplication and the possibility of errors.


"CVRF replaces the many nonstandard reporting formats previously in use, thus speeding up information exchange and processing," the association says. Russell Smoak, ICASI's president, in an earlier interview with Information Security Media Group, explained that the framework allows for consistency among vendors, researchers and customers in exchanging vulnerability information. "It speeds the response in the event of a breach," he said.


For example, by using the framework, an organization that's a customer of three companies that have all been affected by a data breach could receive consistent reports and then more promptly take appropriate action, Smoak explained. The framework is available for free at the consortium's website, which also includes information about a May 30 webcast on the framework.

Monday, April 30, 2012

Russian Hackers Made $4.5 Billion in Cyber Crime

Russians are hacking into computers and cell phones to make millions!


Few nationalities are as good at making money from hacking than the Russians. Their share of the global cyber crime market, an estimated $12.5 billion black market, doubled last year to $4.5 billion, according to Moscow-based Group-IB, a cyber security services firm working mainly with the Russian government and banks to help reduce online fraud.


Earlier this year, Facebook blew the cover off the malware gang Koobface. All five of their members were Russians from St. Petersburg. Eugene Kapersky, the CEO of software security firm Kaspersky Lab, also based in Moscow, said that the Koobface gang had become millionaires thanks to their hacking skills. “The cybercrime market originating from Russia costs the global economy billions of dollars every year,” said Ilya Sachkov, Group-IB’s CEO. 
“Although the Russian government has taken some very positive steps, we think it needs to go further by changing existing law enforcement practices, establishing proper international cooperation and ultimately improving the number of solved computer crimes.”
The word “hacking” can cause tempers to flare up to 120 degrees or more among hard core computer geeks. Not all hacking is intolerable, or illegal. But a lot of it is, and the Russian computer geniuses walk the red carpet within the international hacker community.


Refer here to read the full news.

Tuesday, September 27, 2011

Skype for iPhone may leak Address Book

A vulnerability could see your entire Address Book uploaded to a remote system

A cross-site scripting vulnerability in Skype for iOS has been used to remotely extract the victim device's Address Book. In the proof of concept (PoC) described on the Superevr blog, a piece of JavaScript is inserted in the Full Name field of the attacker's profile.

When a message is received by the victim, the JavaScript runs and initiates a connection to a server, which sends the real payload. That payload instructs the device to upload the entire Address Book file, which can then be read using SQLite-based programs.

The author of the PoC says there's no indication on the device that anything untoward is happening. The issue is said to affect Skype 3.0.1 and earlier, and the PoC was demonstrated on iOS 4.3.5.

The author of the PoC says he reported the issue to Skype in late August, and was told an update would be released early this month. He made a public disclosure this week after the update did not materialise.

The only current mitigations appear to be to ensure that Skype is set to accept messages only from existing contacts, and to be careful to only accept contact requests from people you trust.

Thursday, November 11, 2010

Beware - New, Improved Trojans Target Banks

Malware Variants Seek Corporate Accounts

Security researchers are warning financial institutions about the Qakbot Trojan, a rare kind of malware that is allegedly infiltrating large banks and other global financial institutions. It's unlike other types of malware because it has the ability to spread like a worm, but still infect users like a Trojan.

The Qakbot Trojan, named for its primary executable file, _qakbot.dll, is not new, but its qualities and difference in attack set it head and shoulders above other more well-known Trojans, such as Zeus, in that it can infect multiple computers at a time.

In another disturbing find, security researchers at TrustDefender Labs have found a new Gozi Trojan variant that shows a zero percent detection rate. The Trojan targets financial institutions and is invisible to the most used anti-virus software.

Gozi has been attacking banks for three years, but has managed to stay low and undetected. TrustDefender researchers warn that by targeting specific financial institutions, mainly business and corporate banking, Gozi has avoided wider attention from businesses as the Zeus Trojan has grabbed the headlines.

The new Gozi variant has many of the same characteristics of its earlier variants that were researched a year ago. Gozi developers evade signature patterns so much that the history of the Trojan is mostly unknown. TrustDefender's CTO Andreas Baumhof states that an increasing number of Trojans are using SSL and HTTPS to hide their presence. Gozi is also using client-side logic to go around two-factor authentication, as are other Trojans including Zeus, Spyeye and Carberp.

Sunday, October 10, 2010

Protect Yourself from Migration Fraud

Online help for immigrants

IMMIGRANTS planning a move to Australia have been warned of scams that leave them broke and without a visa. Immigration Minister Chris Bowen has launched a new online tool to help keep potential immigrants on the right path.

"It is vital that people are aware of fraudsters' tricks before handing over money for immigration assistance which is never provided," quote from his statement.

The Protect Yourself from Migration Fraud information kit includes victims' stories, tips for staying safe online, help with identifying non-genuine websites and fake emails and links to other resources. Mr Bowen said the most widespread scam involved online registration and the provision of a credit card number.

Thursday, May 20, 2010

Visa Warns of New Fraud Scheme

Alert to Banks, Processors Describes Bogus Batch Settlement

Banking institutions and payments processors are on heightened alert after notification from Visa that a criminal group plans to execute a large, fraudulent batch settlement scheme.
According to Visa's alert, a copy of which was obtained by Information Security Media Group, the payment card giant has information about criminals who claim to have access to account numbers and the ability to submit a large batch settlement upload to occur over a weekend. (Merchants usually send their credit card transactions by batches at the end of a business day to be settled by the credit card companies and acquiring banks.)

Visa does not have any information as to when the fraudulent settlement activity may occur. The criminals claim to have access to a merchant account placed with a bank in Eastern Europe.

"Although the source of the information is reliable, the information that Visa has received coming forward so far is limited," the alert states. "Visa suspects that this scheme may be linked to a consortium of online merchants that have been trying to secure processing arrangements after being shut down at several acquirers across many geographies."

This alert comes after last year's record-breaking Heartland Payment Systems data breach and other noted incidents, including the Network Solutions breach that involved its merchant client database of more than 4,000 small business accounts.

Once Visa received the information from the third-party source, according to the alert, it immediately implemented monitoring of large settlement activity for banks located in Eastern Europe. Up to now, Visa says it hasn't seen abnormal or large settlement activity. Visa says it is continuing to monitor and will alert any affected Visa clients of abnormal activity, if needed.

Institutions should monitor for large or unusual settlement activity -- particularly during weekends and holidays. They should also closely review settlement and chargeback activity for high risk merchants and agents.

Analyst: Banks Should Be 'Very Concerned'

These types of thefts have been around for a long time, says Gartner analyst Avivah Litan.

"Financial institutions should be very concerned about this alert because they are the ones who get stuck with the bill and the chargebacks once cardholders notice the unauthorized charges. These 'fake' merchants will undoubtedly bail out of the system once they get their money, so the banks don't have a prayer of recovering money from the bad guys.

This type of fraud is likely to continue, as the biggest problem in preventing batch settlement fraud is how merchant accounts get created and underwritten in the first place. "Visa, MasterCard and the acquiring banks need to tighten up their accreditation process and how they onboard new merchants. There are too many 'third parties' and ISOs in the system, allowing too many illegitimate merchants to establish accounts and access to the payment systems.