Showing posts with label Security Stats. Show all posts
Showing posts with label Security Stats. Show all posts

Wednesday, January 30, 2013

ENISA Identifies Top Cyberthreats

What are the emerging threats and vulnerabilities, and how should organizations globally respond to them?

ENISA, the European Union cyber-agency, is out with its first-ever Threat Landscape report.

Drive-by exploits, worms/Trojans and code-injection attacks are the three top cyberthreats to organizations, according to the new Threat Landscape report published by the European Network and Information Security Agency.

The ENISA Threat Landscape provides an overview of threats, together with current and emerging trends. One of the key objectives of this report is to give the information security community a comprehensive look at risks.

It is based on publicly available data and provides an independent view on observed threats, threat agents and threat trends. Over 140 recent reports from security industry, networks of excellence, standardisation bodies and other independent institutes have been analysed. 

Among the top 10 threats ID'd by the report:

  • Drive-by exploits (malicious code injected to exploit web browser vulnerabilities) Worms/Trojans;
  • Code injection attacks;
  • Exploit kits (pre-packaged software to automate cybercrime);
  • Botnets (hijacked computers used in attacks such as DDoS).

Among technology trends, mobile gets the most attention because that's the platform where users, data and adversaries increasingly converge.

Please refer here to download the report.

Wednesday, November 14, 2012

SCADA Safety In Numbers: Report highlighting SCADA insecurities

40% of SCADA systems connected to the Internet are vulnerable and can be hacked by less savvy cyber-criminals

A new report that attempts to quantify the risks to Industrial Control Systems (ICS) contends that more software flaws are being detected in the sensitive systems since the 2010 discovery of Stuxnet, but the report may be based on some faulty assumptions, according to one ICS expert.

The report, SCADA Safety In Numbers, (.pdf) was produced by Russian vulnerability management vendor Positive Technologies Security. The analysis is based on data collected from an array of vulnerability databases and exploit packs. It found that more than 40% of SCADA systems connected to the Internet are vulnerable and can be hacked by less savvy cyber-criminals.

The study also found that 64 vulnerabilities were discovered and reported in industrial-control system products by the end of 2011. And nearly 100 coding errors were reported already this year. The authors contend that for each of the bugs disclosed over the last two years, they “searched for generally available methods of exploiting the [vulnerabilities] and provided an expert evaluation of the related risks.”

“The fact that this paper attempts to identify and classify vulnerabilities based on risk level is inappropriate,” said Langill, who is also known throughout the industry by his handle SCADAhacker.

Just because a device in an ICS system is potentially vulnerable and accessible via the Internet does not necessarily mean it poses any risk to the end-user, Langill said. An end-user may have followed recommended practices and placed a device in special “zones” that offer “hidden” security controls to protect against compromise, he said.

A claim in the report that 39% of the ICS systems in North America are vulnerable to compromise is suspect and based on faulty analysis, Langill said. In order for an attacker to capitalize on a specific vulnerability, they would also have to be able to overcome all of the existing layers of security that are in place, Langill said, turning a seemingly simple exploit of a vulnerability with a high CVSS score into a very sophisticated attack that would be difficult to execute and realistically classified with a very low "effective" CVSS score.

“It is important not to confuse a ‘component’ vulnerability with a ‘system’ vulnerability," Langill said. "It is possible, and not uncommon, for vulnerable components to be installed within an ICS network that is equipped to provide a barrier against various threats. Therefore, the system compensates for these known and unknown vulnerabilities by creating isolation within the ICS architecture."

Langill said many of the vulnerable components listed in the report are from companies that do not represent any significant market share, potentially skewing the results against the actual number of vulnerable systems. He also noted that most ICS architectures contain far more embedded devices than they do Windows-based hosts, yet nearly all disclosed vulnerabilities in the report are designed to specifically target a Windows environment.

In my humble opinion, despite the weaknesses identified in the Positive Technologies report, there is still value in the research in regards to drawing more attention to the problem of sensitive ICS systems that are exposed by way of the Internet

Pls refer here to download the report.

Saturday, December 31, 2011

2011 - Year of the HACK and DATA Breaches

This year’s headlines have been made up of data breaches, hacks, APT attacks and mergers and acquisitions

Like a sleeper agent, it embeds itself in key industrial systems and waits, gathering intelligence and biding its time. It studies design documents to find weak spots for future attacks that could bring a nation to its knees.

It is the description by US security firm Symantec of the newly discovered Duqu worm in its report ‘W32.Duqu: The precursor to the next Stuxnet.

Duqu is based on the sophisticated Stuxnet worm that shut down an Iranian nuclear fuel processing plant and set back its nuclear program by years. Duqu has so far infected industrial systems in eight countries: France, the Netherlands, Switzerland, Ukraine, India, Iran, Sudan, and Vietnam.

While at this point Duqu is only able to gather intelligence, Symantec judges that it is “essentially the precursor to a future Stuxnet-like attack” against industrial control systems. These systems are used to control everything from nuclear power plants and the electricity grid to oil pipelines and large communication systems.

The discovery of Duqu was a major security event in 2011; not exactly because of the effect that the worm has had, but for its potential. Duqu signals a growing trend of malware developed not to steal identities and profit financially, but to disable and destroy critical infrastructure – the life blood of modern society.

News of Duqu was followed by a (now-mistaken) malware attack on a US water utility network that destroyed the industrial control system of a key water pump.

Destruction of critical infrastructure has been the elephant in the room for the information security profession. Many recognize the danger, but it is seen as too esoteric and remote to worry about. It is someone else’s (i.e., the government’s) problem.

But if major critical infrastructure collapses from a cyberattack, whether your boss’s iPad makes the company’s network less secure is not going to matter all that much.

Cyber Wasteland

From the mega breach at Sony to the annoying self-righteous breaches perpetrated by Anonymous et al., 2011 was a wasteland of data loss.

In March, RSA – the company that ensures its elite customers are water-tight – sprang a leak when it was penetrated by a spear-phishing attack that hooked one of its employees and resulted in a huge catch for cyberattackers.

In an open letter to RSA customers, executive chairman Art Coviello said that a sophisticated “advanced persistent threat” (APT) attack had extracted valuable information related to its SecurID two-factor authentication product used by remote workers to securely access their company’s network.
"Destruction of critical infrastructure has been the elephant in the room for the information security profession"

“While at this time we are confident that the information extracted does not enable a successful direct attack on any of our RSA SecurID customers, this information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation as part of a broader attack”, Coviello said.
Coviello, it turned out, was wrong about this assumption, as numerous SecureID token customers – including US defense giant Lockheed Martin – reported attacks resulting from the RSA breach. In an effort to limit the damage, RSA agreed to replace the tokens for its key customers.

In response to the RSA breach, APT became the new catchword for cyberattacks. “It’s not our fault our networks were breached and our data stolen, it was an APT. What could we do?”, whined many companies in the ‘year of the breach’.

April was the Cruelest Month

April was indeed a cruel month for Sony, which admitted that hackers had gained access to names, addresses, email addresess, birth dates, passwords and IDs for over 100 million PlayStation Network, Qrocity, and Online Entertainment customers.

The massive size of the breach, as well as the delay in informing customers, attracted the attention of the US Congress. A House Commerce Committee panel held a hearing on the breach, but Kazuo Hirai, chairman of Sony Computer Entertainment America, declined to appear.

Panel chairman Mary Bono Mack (R-Calif.) criticized Sony for the delay in informing its customers of the data breach and the manner of notification through its blog. “I hate to pile on, but – in essence – Sony put the burden on consumers to ‘search’ for information, instead of accepting the burden of notifying them. If I have anything to do with it, that kind of half-hearted, half-baked response is not going to fly in the future.”

More Breaches!

Marketing firm Epsilon had a breach of its extensive database, which contained the names and emails of customers at such high-profile partners as BestBuy, Walgreens, Marriott, Lacoste, Marks & Spencer, JP Morgan Chase, Barclays, Citibank, US Bank, and Capital One.

While Epsilon initially downplayed the breach, its partners could not. They began issuing warnings to millions of their customers about the breach, cautioning them to be on the lookout for subsequent spam and phishing attempts as a result of the compromised email addresses. Reuters put a $100 million price tag on the incident, which falls directly on Alliance Data Systems, Epsilon’s parent company.

And for much of 2011, Anonymous and its offspring were claiming credit for what seemed like a breach a week – in the name of improving security by showing how incredibly bad many organizations’ information security really is.

Not with a Whimper, but a Bang

In the arena of mergers and acquisitions, 2011 started off with a bang, with Dell’s acquisition of SecureWorks, an Atlanta-based security-as-a-service provider with 3,000 clients worldwide, and Verizon’s $1.4 billion purchase of Terremark, a Miami-based managed IT infrastructure and cloud service provider with advanced security offerings.

Also early in the year, Sourcefire bought Immunent, a cloud-based anti-malware startup, for $21 million, and Google agreed to acquire Zynamics, a Germany-based forensic specialist, for an undisclosed consideration.

In April, storage giant EMC acquired NetWitness, a Herndon, Va.-based network monitoring specialist, and added it to RSA. While the purchase price was not disclosed, some estimates put the price tag as high as $500 million. Too bad RSA did not have network monitoring in March!

After the April showers, there was a spurt of acquisition activity in May. In that month, Symantec acquired Clearwell Systems, a provider of e-discovery, data archiving, and data backup products, for $390 million, augmenting its information management and governance portfolio.

In addition, cloud provider VMWare purchased Shavlik Technologies, a Minnesota-based patch management and cloud-security firm; Thoma Bravo bought Tripwire, a Portland, Ore.-based network security firm; and Sophos acquired Astaro, a Germany-based private network security firm.

Other noteworthy information security acquisitions in 2011 included: IBM’s purchase of Q1Labs, a Waltham, Mass.-based provider of security event and log management software; McAfee’s purchase of NitroSecurity, a Portsmouth, N.H.-based security information and event management firm; and Check Point’s acquisition of Dynasec, an Israeli-based governance, risk, and compliance firm.

“Prediction is very difficult, especially about the future.”

Despite the wisdom of those great minds, I will venture to make some predictions for 2012. First, I predict that the world will not end. If I’m wrong about that, then no need to read further.

Certainly, Stuxnet, Duqu, and their heirs will increasingly plague governments, critical infrastructure operators, and information security professionals. It’s time to take these threats as seriously as the mundane security problems of everyday life in the 21st century.

The explosion of mobile device use, particularly in the workplace, will increasingly concern information security staffs for years to come. Malicious mobile malware has become widespread, and this trend is likely to accelerate.

Enterprises will have to come to grips with social media, particularly as cybercriminals find it a fertile ground for mischief. Should employees be banned from using it at work or is it the next great efficiency tool? The answer is: Yes.

Of course, the cloud – companies will likely accelerate cloud adoption to improve the bottom line, while security professionals will struggle with the implications of giving up control over key corporate information assets.

And the boldest prediction of all: there will be more data breaches in 2012.

Saturday, September 17, 2011

10 Most Costly Cyber Attacks in History

What we have learned from these attacks?

Cyber-attacks aren’t just fuel for poorly made movies or something teenagers do for fun. They are a serious issue with real-world consequences for companies, consumers and nations (and while good web hosting is a undoubtedly a good protective measure, it’s far from an impenetrable defense).

A recent survey by the Ponemon Institute found that 59% of those surveyed had suffered a slew of attacks in the last year, with the average cost to businesses exceeding $500,000 when they added up expenditure, overheads, labor, revenue losses, business disruption and other costs. Of course, that’s just the average outlay.

Here are the most costly cyberattacks ever carried out. These victims wish it had only cost them a paltry half a million dollars.

10. Citigroup

Tremendous amounts of wealth, from thousands of parties, flow through financial giants such as Citigroup on a daily basis. Earlier this year, in 2011, the aforementioned stacks of money and hoards of sensitive customer information provided ample incentive for cyber-hacks to organize an attack.

Over 200,000 customers’ names, contact details, account numbers and other information were compromised in the attack, as the thieves made off with $2.7m from credit card accounts. That’s a bad day at the office.

9. Titan Rain

The public face of international relations between non-warring states is usually one of diplomatic politeness, yet the 2004 discovery by Shawn Carpenter, a Sandia National Laboratories employee, of hacking into US military files brought to light the shadier underbelly of global affairs. “Titan Rain” is the FBI code-name for an extensive series of infiltrations into US military security, companies such as Lockheed and even NASA.

It is believed to have been perpetrated by cells of operatives on behalf of the Chinese government, although it is unknown whether this is actually the case or whether these were simply the actions of rogue hackers. While very difficult to quantify in objective terms, the potential to access and exploit the US government’s most secret information makes this a pretty costly attack in our book, and it is certainly one of the biggest of all time.

8. Heartland Payment Systems

Trusted payments processor Heartland Payment Systems fell victim to a 2008 plot to steal credit and debit card numbers. By secretly infesting the company’s computer network with spyware, the criminal gang responsible were able to steal over 100 million individual card numbers.

However, for one of the key masterminds behind the job, Albert Gonzalez, it was a case of his number being up when a federal jury found him guilty of his crimes and he was sentenced to 20 years in prison. As for Heartland, the episode ended up costing them around $140m. So much for their motto, “The highest standards — The most trusted transactions.”

7. Hannaford Bros

Grocery retailer Hannaford Bros suffered a four-month long breach of their security from the winter of 2007 to the spring of 2008. During this period, over 4.2 million credit and debit card numbers were exposed, along with other sensitive information.

This feat of cyber-criminality was achieved through the installation of malware on store servers, which stands in contrast to the more common tactic of hacking company databases. Experts table the costs incurred at an estimated $252m — more than the value of an average grocery list, to say the least. One of the principal hackers involved was Albert Gonzalez, who had also hacked Heartland Payment Systems as well as taking part in the TJX cyber-attack…

6. TJX

Massachusetts-based retailing company TJX, owner of such well-known chains as TJ Maxx and Marshalls, was taken for a ride by a group of cyber fiends with a fetish for electronics. The gang were able to get their hands on over 45 million credit and debit card numbers, a selection of which they then used to fund a multi-million dollar spending spree from Wal-Mart’s stock of electronics equipment.

Initially estimated at around $25m, the damage from the data-breach ended up costing over $250m in total. Perhaps the zero button on the estimators’ calculator was sticky.

5. Sven Jaschan

We’ve all heard the classic example of “chaos theory”: a butterfly flapping its wings in Brazil can set off a tornado in Texas. Well, for one German teen, a computer made an apt chrysalis for his butterfly.

In 2004, Sven Jaschan unleashed a virus which infected millions of computers around the world, reaching its highest degree of destruction when it comprehensively disabled the Delta Air Lines computer system, causing the cancellation of several transatlantic flights. Jaschan was eventually arrested after a three-month hunt, during which Mircosoft placed a $250,000 bounty on the hacker’s head.

An estimated $500 million worth of damage was generated (although other sources have put the total cost much higher, in the billions of dollars), all starting in the computer of a German college student.

4. Michael Calce

Michael Calce was not the most well-known 15-year-old; “MafiaBoy,” however, was a cyber-superstar. Widely considered approaching genius levels of computer expertise, Calce, aka MafiaBoy, conducted notorious attacks against huge companies with high levels of security. Amongst those attacked were computer manufacturer Dell, media giant CNN, and shopping sites Amazon and Ebay.

Prosecution for the estimated $1.2bn worth of damage caused went pretty smoothly, from Calce’s perspective. He ended up with a sentence of eight months open custody.

3. Sony

In a still unravelling saga, this year’s exposure of over 100 million PlayStation Network and Sony Online Entertainment accounts is forging a new chapter in the history of cyber-attacks. The personal information — including credit and debit card data — of tens of millions of users was stolen by an as yet unknown group of assailants.

Experts predict that the damage may range from $1 to $2bn, making it possibly the costliest cyber-hack ever to have been pulled off. Even worse, dedicated gamers were unable to log on while Sony attempted to deal with the breach, causing some serious tantrums.

2. Epsilon

Estimated at having a potential cost that ranges from $225m to $4bn, the March 2011 hack of e-mail handler Epsilon is another as of yet undetermined candidate for the costliest cyber-heist of all time. The Dallas-based firm provides marketing and email-handling services to organizations as large as Best Buy and JP Morgan Chase.

However, as the stolen information was mostly email addresses, the various possible criminal applications of this information mean that the estimated cost is extremely variable.

1. The Original Logic Bomb

In 1982, with the Cold War still far from thawing, the expansion of computer technology was increasingly finding its way to becoming a major tactical vehicle for the CIA. Without using a missile, bomb or other traditional explosive device, the US managed to blow up a Siberian gas pipeline, creating a monumental and historically unprecedented method of explosion.

The method used, known as a “logic bomb,” involved the insertion of a portion of code into the computer system overseeing the pipeline, causing computational chaos. Other than the obvious material cost to the Russians, this moment in history showed the world a further dimension to the costs that can be unleashed and incurred through the power of cyber-hacking.

Friday, August 5, 2011

Cyber Storm III participants found shortcomings in its cybersecurity “escalation procedures”

Australian report identifies cybersecurity gaps during Cyber Storm III exercise

An Australian report issued Monday found gaps in cybersecurity procedures and processes for both government and industry, based on a review of the US-sponsored Cyber Storm III exercise held last September.

The report, commissioned by the Australian government and carried about by former Australian Army intelligence officer Miles Jakeman, said that Cyber Storm III identified "gaps” in cybersecurity procedures, processes, and plans by government and industry.

The Australian government identified gaps in its interim cybersecurity crisis management plan, and industry found shortcomings in its cybersecurity “escalation procedures”, according to the report.

The Cyber Storm III exercise included participants from seven US federal agencies, 11 US states, 60 private companies, and 12 international partners. The Australian government sent representatives from the Defence Signals Directorate, Computer Emergency Reponse Team (CERT) Australia, and Australian Federal Police; industry was represented by Telstra, ASX, Woolworths, ANZ, and domain name registrar AuDA.

Australian Attorney General Robert McClelland said that more than 50 Australian organizations participated in Cyber Storm III. He said in releasing the report: “The Cyber Storm III exercise provided a good test of new government processes including the interim cybersecurity crisis management plan, which allowed agencies to identify gaps and revise processes.”

McClelland added: “The exercise revealed many areas where internal and cross-sector partnerships worked effectively to communicate and resolve issues, but also highlighted areas where communications and planning could be further developed….While it did highlight gaps within existing government and business cyber incident processes, particularly in regards to escalation procedures, this feedback allows both government and businesses to take steps to improve our cybersecurity.”

Saturday, June 18, 2011

Index of Cybersecurity

New Index Measures Cyberspace Safety

Quantifying the safety or danger of cyberspace is tough. But a highly respected IT security practitioner and an experienced risk management consultant have teamed to develop an index they contend reflects the relative security of cyberspace by aggregating the views of information security industry professionals.

"We don't have much to compare to in this field because hard numbers are very hard to get", advised by Mukul Pareek developed the
Index of Cybersecurity, a sentiment-based measure of the risk to the corporate, industrial and governmental information infrastructure from a range of cyberthreats.

The
index of Cybersecurity launched in April, and in an interview with Information Security Media Group's GovInfoSecurity.com say it could be months before its value to government and private-sector information security officers will be known.

The developer of the index "Mukul Pareek" suspects the index will serve as a baseline for information security officers to compare their organizations' performance against the general state of IT security. "An information security officer has among other questions the perpetual one of: Am I being targeted, am I different, what are other people seeing, is there a baseline I can compare myself to?". "And, it's a constant problem. In fact, unless you do some sort of information sharing, there is little way to tell whether your observations are unique or typical or altogether ordinary except for one feature or the like."

The
cybersecurity index features 15 sub-indices that measure malware threats, intrusion pressures, insider threat, industrial espionage, information sharing and media and public perception, to name a few.

In the interview, Geer and Pareek also explain how the index works and ways it could be employed, such as a metric to assess cybersecurity insurance policies.

Tuesday, February 15, 2011

Hacking attacks from China hit energy companies worldwide

Global Energy Cyberattacks: “Night Dragon”

Security researchers at McAfee have sounded an alarm for what is described as “coordinated covert and targeted cyberattacks” against global oil, energy, and petrochemical companies.


McAfee said the attacks begain November 2009 and combined several techniques — social engineering, spear phishing and vulnerability exploits — to load custom RATs (remote administration tools) on hijacked machines.

The attacks, which McAfee tracked to China, allowed intruders to target and harvest sensitive competitive proprietary operations and project-financing information with regard to oil and gas field bids and operations.

We have identified the tools, techniques, and network activities used in these continuing attacks—which we have dubbed Night Dragon—as originating primarily in China. Through coordinated analysis of the related events and tools used, McAfee has determined identifying features to assist companies with detection and investigation. While we believe many actors have participated in these attacks, we have been able to identify one individual who has provided the crucial C&C infrastructure to the attackers.

The company released a white paper to outline the attacks, which included the use of SQL injection and password cracking techniques.

Refer here for more details.

Friday, February 4, 2011

Cyber security has become Australia's "fundamental weakness"

Australia's cyber security 'weak' - report

AUSTRALIA is increasingly ill-equipped to deal with cyber attacks on the country's energy, water, transport and communications systems, a report states.
The study by security think-tank Kokoda Foundation, to be released today, argues cyber security has become Australia's "fundamental weakness".

"A broader understanding of the nature, scale and extent of online threats to private information is crucial to the ongoing security of this country," report co-author John Blackburn said. Mr Blackburn is a former deputy chief of the air force.

The report recommends national security adviser Duncan Lewis be given lead responsibility for coordinating cyber security "across government".

It also suggests a federal minister be given specific responsibility for tackling online threats and a 10-year plan be developed to manage cyberspace.

The full report will be released in Canberra later today.

Refer here to read the news.

Tuesday, September 7, 2010

IBM X-Force Mid-Year Trend and Risk Report

2010 Mid-year highlights

The IBM X-Force 2010 Mid-Year Trend and Risk Report reveals several key trends that demonstrate how, in the first half of 2010, attackers seeking to steal money or personal data increasingly targeted their victims via the Internet. The IBM X-Force Trend and Risk Report is produced twice per year: once at mid-year and once at year-end. This report provides statistical information about all aspects of threats that affect Internet security, including software vulnerabilities and public exploitation, malware, spam, phishing, web-based threats, and general cyber criminal activity.

Summary

Attackers are increasingly using covert techniques like Javascript obfuscation and other covert techniques which continue to frustrate IT security professionals. Obfuscation is a technique used by software developers and attackers alike to hide or mask the code used to develop their applications.

Reported vulnerabilities are at an all time high, up 36%. 2010 has seen a significant increase in volume of security vulnerability disclosures, due both to significant increases in public exploit releases and to positive efforts by several large software companies to identify and mitigate security vulnerabilities.

PDF attacks continue to increase as attackers trick users in new ways. To understand why PDFs are targeted, consider that endpoints are typically the weakest link in an enterprise organization. Attackers understand this fact well. For example, although sensitive data may not be present on a particular endpoint, that endpoint may have access to others that do. Or, that endpoint can be used as a practical bounce point to launch attacks on other computers.

The Zeus botnet toolkit continues to wreak havoc on organizations. Early 2010 saw the release of an updated version of the Zeus botnet kit, dubbed Zeus 2.0. Major new features included in this version provide updated functionality to attackers.

Vulnerabilities and exploitation highlights

=> Advanced persistent threat—What concerns X-Force most about these sophisticated attackers is their ability to successfully penetrate well defended networks in spite of significant advances in network security technology and practices. In particular, we are concerned about increasingly obfuscated exploits and covert malware command-and-control channels that fly under the radar of modern security systems.

=> Obfuscation, obfuscation, obfuscation—Attackers continue to find new ways to disguise their malicious traffic via JavaScript and PDF obfuscation. Obfuscation is a technique used by software developers and attackers alike to hide or mask the code used to develop their applications. Things would be easier if network security products could simply block any JavaScript that was obfuscated,but unfortunately, obfuscation techniques are used by many legitimate websites in an attempt to prevent unsophisticated Web developers from stealing their code. These legitimate websites act as cover for the malicious ones, turning the attacks into needles in a haystack.

=> PDF attacks continue to increase as attackers trick users in new ways. To understand why PDFs are targeted, consider that endpoints are typically the weakest link in an enterprise organization. Attackers understand this fact well. For example, although sensitive data may not be present on a particular endpoint, that endpoint may have access to others that do. Or, that endpoint can be used as a practical bounce point to launch attacks on other computers.

=> Reported vulnerabilities are at an all time high—2010 has seen a significant increase in the volume of security vulnerability disclosures, due both to significant increases in public exploit releases and to positive efforts by several large software companies to identify and mitigate security vulnerabilities.

=> Web application vulnerabilities have inched up to the 55 percent mark, accounting for fully half of all vulnerability disclosures in the first part of 2010.

=> Exploit Effort versus Potential Reward—What are attackers really going after? With the number of vulnerability announcements rising and vendors scrambling to provide patches and protection to problem areas, how can enterprises best prioritize the efforts of IT administrators to provide adequate coverage? The Exploit Effort versus Potential Reward Matrix provides a simple model for thinking about vulnerability triage from the perspective of attackers.

Please refer here to download or view the report.

Wednesday, July 22, 2009

Sophos slams US for again topping spam ranking

The US should clean up its own computers before looking to fight overseas hackers and spammers

One in six spam emails come from the US, according to a report from a security firm.
Sophos ranked the US as the top source of the unwanted messages around the world, sending 15.6 per cent of all spam globally for the second quarter of the year.


Sophos security researcher Graham Cluley called for the US to clean up its spam problem.
"Barack Obama's recent speech on cybersecurity emphasised the threat posed by overseas criminals and enemy states, but these figures prove that there is a significant problem in his own back yard,” he said in a statement.


Sophos also said that spammers are taking to social networking sites, such as Twitter, using URL shortening services such as TinyURL, bit.ly and others.

The 140 character limit on Twitter means many users turn to such services to shorten long URLs, but the shortened links obscure the actual target, letting spammers and malware writers send users to sites they might not otherwise visit.

“This is being exploited by hackers that will use the services to obscure links to offensive material or malicious websites, and then distribute the links in spam emails, as well as posting them on Twitter and other networks,” Sophos said.

The top 12 worst countries for spam distribution:

1. United States (15.6 per cent)

2. Brazil (11.1 per cent)


3. Turkey (5.2 per cent)

4. India (5.0 per cent)

5. South Korea (4.7 per cent)

6. Poland (4.2 per cent)

7. China (4.1 per cent)

8. Spain (3.4 per cent)

9. Russia (3.2 per cent)

10. Italy (2.8 per cent)

11. Argentina (2.5 per cent)

12. Vietnam (2.3 per cent)