231-922-9460 | Google +

Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Tuesday, October 7, 2014

HACKERS’ ATTACK CRACKED 10 COMPANIES IN MAJOR ASSAULT

Original Story: nytimes.com

The huge cyberattack on JPMorgan Chase that touched more than 83 million households and businesses was one of the most serious computer intrusions into an American corporation. But it could have been much worse.

Questions over who the hackers are and the approach of their attack concern government and industry officials. Also troubling is that about nine other financial institutions — a number that has not been previously reported — were also infiltrated by the same group of overseas hackers, according to people briefed on the matter. The hackers are thought to be operating from Russia and appear to have at least loose connections with officials of the Russian government, the people briefed on the matter said. An Atlanta Intellectual Property Lawyer assist clients in protecting their intellectual property and exclusive technologies.

It is unclear whether the other intrusions, at banks and brokerage firms, were as deep as the one that JPMorgan disclosed on Thursday. The identities of the other institutions could not be immediately learned. A Boston Intellectual Property Lawyer has experience in protecting the intellectual property assets of their clients.

The breadth of the attacks — and the lack of clarity about whether it was an effort to steal from accounts or to demonstrate that the hackers could penetrate even the best-protected American financial institutions — has left Washington intelligence officials and policy makers far more concerned than they have let on publicly. Some American officials speculate that the breach was intended to send a message to Wall Street and the United States about the vulnerability of the digital network of one of the world’s most important banking institutions. A Boston Business Lawyer is reviewing the details of this case.

“It could be in retaliation for the sanctions” placed on Russia, one senior official briefed on the intelligence said. “But it could be mixed motives — to steal if they can, or to sell whatever information they could glean.”

Ways to Protect Yourself After the JPMorgan Hacking

The JPMorgan hackers burrowed into the digital network of the bank and went down a path that gave them access to information about the names, addresses, phone numbers and email addresses of account holders. They never made it into where the more critical financial information and personal information are stored.

The bank’s security team, which first discovered the attack in late July, managed to block the hackers before they could compromise the most sensitive information about tens of millions of JPMorgan customers, said several security experts and others briefed on the matter. The attack was not completely halted until the middle of August and it was only in recent days that the bank began to tally its full extent.

American officials say they have been working with JPMorgan since the intrusion was detected, chiefly through the Treasury, the Secret Service and intelligence agencies that seek to find the source of the attacks. But that is slow work and one official cautioned against leaping to conclusions about the identities or the motives of the attackers.

“We’ve been wrong before,” he said.

JPMorgan, the nation’s largest bank, has begun contacting customers and making clear that no money was taken from any accounts. There has been no evidence of any fraudulent use of customer information. Most of the household accounts belong to United States residents. The hackers ended up with the addresses, email addresses and phone numbers of everyone who logged into JPMorgan’s websites and mobile applications in the recent past.

Still, the recent attacks on the financial firms raise the possibility that the banks may not be up to the job of defending themselves. The attacks will also stoke questions about regulations governing when companies must inform regulators and their customers about a breach.

“It was a huge surprise that they were able to compromise a huge bank like JPMorgan,” said Al Pascual, a security analyst with Javelin Strategy and Research. “It scared the pants off many people.”

Several financial regulators have warned that a coordinated attack on the banking system could set off another financial crisis.

On Friday, George Jepsen, the Connecticut attorney general, opened an investigation into the breach at JPMorgan, while Benjamin M. Lawsky, New York’s top financial regulator, began calling bank officials to warn them to take the threat more seriously.

“There needs to be far more urgency,” Mr. Lawsky said in an interview.

JPMorgan has also been working with law enforcement, including the F.B.I., since shortly after detecting the intrusion, which affected about 90 of the bank’s computer servers. The bank said it believed that its systems were now secure and that the threat of the hackers’ returning was over.

“To date, we have not seen any unusual fraud activity related to this incident,” said Kristin Lemkau, a bank spokeswoman. “We have identified and closed the known access paths. We have no evidence that the attackers are still in our system. We have apologized to our customers.”

But much remains unanswered about the intrusion, including just who the hackers are, which other financial institutions were hit and why the hackers went down a path inside JPMorgan’s computer system that contained troves of customer information, but not financial data.

The intrusion also highlights a possible gap in United States regulations. Banks are not required to report data breaches and online intrusions unless the incident is deemed to have resulted in a financial loss to customers. Breach notification laws differ by state, but most laws require only that companies disclose a breach if customer names were stolen in conjunction with other information like a credit card, Social Security number or driver’s license number.

In some states, companies can wait up to a month to inform customers of a breach. Other state laws are more vague.

In California, for example, banks, companies and large organizations must inform the state attorney general’s office and consumers about a breach without unreasonable delay — a rule that some companies interpret liberally, officials say. This year, Kamala Harris, the California attorney general, sued the Kaiser Foundation Health Plan, saying that it took four months for the foundation to disclose to some employees that their personal information may have been compromised.

For years, there have been attempts in Congress to force companies to inform customers more quickly when their information has been compromised, but recent bills have failed to muster enough support. One bill, sponsored by Senator Edward J. Markey, Democrat of Massachusetts, would create a clearinghouse where companies could exchange information about attacks.

United States bank executives say privately that they already share intelligence informally about attacks, which are occurring frequently on their systems.

This summer, Treasury Secretary Jacob J. Lew called on Congress to pass legislation that he said would bolster the information sharing process.

“As it stands, our laws do not do enough to foster information sharing and defend the public from digital threats,” Mr. Lew said.

That the hackers were apparently able to move around JPMorgan’s computer system undetected for several weeks is perhaps the most troubling aspect of the recent breach, officials at other large banks say.

The hackers were able to attain high administrative privileges within JPMorgan’s network, rooting more than 90 servers and rummaging through customer databases with detailed information for 76 million households and seven million small-business online accounts.

As they looked around, according to one person with knowledge of the breach, the hackers gleaned some critical details of customers’ accounts. With these, the hackers were able to determine whether the accounts fell within the private bank or in other business categories like mortgages.

Some people briefed on the results of the attack contend that it was only a matter of time before attackers could have gained access to customer funds and critical personal data.

Weeks into the attack, in mid-July, unusual behavior on the bank’s network was spotted, and the attackers were stopped before they had a chance to pull any customer data back to their servers abroad.

But they did make off with one file which has unnerved executives. That file contained a list of every application and program deployed on standard JPMorgan computers that hackers can crosscheck with known, or new, vulnerabilities in each system in a search for a backdoor entry.

Swapping out those programs is costly and time-consuming, people say, because the bank would have to renegotiate licensing deals with technology suppliers and swap out programs and applications for hundreds of thousands of bank employees.

As one former employee explained: “It’s as if they stole the schematics to the Capitol — they can’t just switch out every single door and window pane overnight.”

The attack came after a recent turnover within JPMorgan’s information security group.

A number of staff members followed Frank Bisignano, JPMorgan’s former co-chief operating officer, to First Data last year. This year, First Data agreed to pay JPMorgan over accusations that by wooing other executives to the payment processor, Mr. Bisignano had violated the terms of his former employment contract.

By then, First Data had already hired JPMorgan’s chief information officer, Guy Chiarello; its cybersecurity czar, Anthony Belfiore; its head of compliance, Cindy Armine; and Tom Higgins, JPMorgan’s head of operation control.

Anish Bhimani, the bank’s chief information risk officer, remained. Mr. Bhimani, who is well respected in the cybersecurity industry, is a co-author of a 1996 book on cybersecurity, “Internet Security for Business.”

Ms. Lemkau said the bank was pleased with its current cybersecurity personnel. “This is the highest-quality team we have ever had,” she said.

Last December, JPMorgan hired Dana Deasy as chief information officer from BP. Greg Rattray, a former Air Force lieutenant colonel who specialized in cyberdefense was named the head of information security in June.

Challenges quickly followed. That same month, hackers found a way into the bank’s systems.

Wednesday, May 30, 2012

Flame Malware A Real Scare

Story first appeared in The Wall Street Journal.
The complexity, size and geographic location of the computers affected by Flame, the malware that came to light Monday, points to state-sponsored cyber-espionage, and has been seen mainly as a geopolitical event. But the Flame code, which extracts data from networked computers and sends it to remote servers controlled by hackers, should also be seen by CIOs as a potential commercial threat and should cause them to reassess their Security Solutions – both on-premise and in the cloud.

Flame represents a next generation of malware because, while it combines many known ways of attacking systems and transmitting data back to remote servers, it is unique in how it has combined all of those malicious characteristics. Although many cyber-security experts have said most companies that create intellectual property – including a wide assortment of activities from pharmaceutical research to financial services and oil drilling – have already had their systems hacked, it may not be too late for CIOs to protect critical data. But, say experts, they will have to carefully assess their own networks, as well as their relationships with software vendors and cloud service providers with whom they do business.

Help Desk Services and analysts say that Flame should serve as a reminder to CIOs of how vulnerable they are, and give them a greater sense of urgency. Indeed the CIO of Land O’ Lakes, says he learned about Flame on the radio on his way into the office Tuesday, and his thoughts turned immediately to his cloud vendors. Like many CIOs, he has software running both on-premise and in the cloud, and says Flame is equally threatening to cloud and on-premise applications, but he wonders more about the risk mitigation strategies employed by his cloud partners. The question is, who will respond more quickly — cloud providers or his own internal data centers?

That’s a good question – cloud vendors generally do not accept liability for their clients data in the cloud.

The terms of service for Amazon’s AWS web services stipulate that the cloud vendor doesn’t accept liability for lost or altered data, and that customers are responsible for taking your own steps to maintain appropriate security, protection and backup of Your Content, which may include the use of encryption technology to protect Your Content from unauthorized access and routine archiving Your Content.

A Microsoft spokesperson said the company does accept liability for customer data on its Azure cloud platform, unless the customers themselves configured software improperly or otherwise created the conditions for a data breach. Rackspace and Google did not reply to requests for comment at the time of this writing.

Maintaining network security is hard enough on company-owned networks, but if you throw it over the wall to the cloud vendor and you don’t have visibility and control, it becomes impossible. Cloud vendors should provide customers with security tools, even if the customers themselves are responsible for configuring them.

The senior vice president and CIO of Hostess Brands Corporation, seemed to have these challenges in mind when he said he believes companies are limiting much of the data that they move to the cloud to less-critical information, because they are concerned about security.  Until CIOs can get a comfort level that is tenable and sustained, the movement to the cloud will be selective.

Closer to home, however, CIOs still have work to do. A security and privacy expert with the IEEE, a professional IT organization, says even a next generation of malware such as Flame can only get a toehold in an organization’s network by taking advantage of bad software. He blames vendors for building software that leaves customers susceptible to a malware attack, but says customers have to ask their vendors if the stuff you’re buying from them is secure or not, because a lot of people don’t even ask.

He says responsible vendors will respond honestly to that question.

CIOs need to ensure that software written by their own developers has security built into it, and can do this by following guidelines established in the BSIMM [Building Security In Maturity Model] standard. Beyond that, he said good security practice includes using tools to analyze existing software architecture, review code, and regularly hiring third parties to test the network for vulnerabilities by trying to penetrate it. McGraw says he’s “optimistic we’re actually making progress” in making safe software more ubiquitous. But, he said, the only way we can get in front of [issues like Flame] is building systems to be secure in the first place.

A Gartner analyst says Flame highlights the fact that we have to take a multi-pronged approach to malware. No single approach will be a silver bullet. New technologies that analyze the behavior of applications on networks can identify malware before it executes its code. Older anti-virus applications depend on being able to recognize the code used by malware, whereas newer generations of technology can see whether a particular type of application, like a PDF file, is trying to execute code – which it shouldn’t normally do.

An independent cybersecurity analyst, says CIOs should create an inventory of all a company’s data and classify it according to its value, much like the government does with state secrets. They should then take the equivalent of “top secret” data off the Internet. CIOs should also segregate data that is important but not critical, and monitor which persons and applications have access to it.

The reason this isn’t common practice is that many CIOs think about security in terms of legal requirements rather than common-sense approaches. Security is often a matter of compliance. Knowing where your critical data is isn’t an obligation, so it’s not done.


For more national and worldwide Business News, visit the Peak News Room blog.
For more local and state of Michigan Business News, visit the Michigan Business News blog.
For more Health News, visit the Healthcare and Medical News blog.
For more Electronics News, visit the Electronics America blog.
For more Real Estate News, visit the Commercial and Residential Real Estate blog.
For more Law News, visit the Nation of Law blog.
For more Advertising News, visit the Advertising, Marketing and Media blog.
For more Environmental News, visit the Environmental Responsibility News blog.
For information on website optimization or for the latest SEO News, visit the SEO Done Right blog.

Tuesday, May 8, 2012

Cyber Hackers Attack Natural Gas Lines

Story first appeared in USA Today.

Homeland Security has warned U.S. utilities that the computer networks controlling natural gas pipelines have been under attack since December, according to news reports out of Washington.

Canadian pipelines may also be affected by the cyber intrusion campaign, according to confidential Homeland Security alerts first reported by the Christian Science Monitor.

A Homeland Security spokesman today told The Hill that DHS is working with the FBI and other federal agencies to address the spear-phishing attacks, which involve fraudulent e-mails sent to gas company employees. The companies were not named.

DHS has issued at least three "amber" alerts -- the second-highest warning -- since March 29. Those warnings were reiterated late Friday in a report from Homeland Security's Industrial Control Systems Cyber Emergency Response Team based in Idaho.

ICS-CERT has recently identified an active series of cyber intrusions targeting natural gas pipeline sector companies. Multiple natural gas pipeline organizations have reported either attempts or intrusions related to this campaign. The campaign appears to have started in late December 2011 and is active today.

But DHS has asked utilities to not remove any malware or patch security holes if they don't jeopardize safe operations, according to people who have seen the alerts. One would expect stronger Security Solutions to be put in place once this is resolved.

The newspaper says that about 200,000 miles of pipelines deliver 25% of U.S. energy.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Tuesday, May 1, 2012

Skype Investigating Anonymous IP Hackers

Story first appeared on Slash Gear.

Skype has said today that it is investigating a method that can discover a user’s last known IP address when using the VOIP service. Information on how to unearth IP addresses was posted to Pastebin several days ago, which involved downloading a modified version of Skype 5.5 and enabling debug log file creation in the Windows registry settings.

The method describes how to resolve a user’s IP address without them being on your contact list. With the patched version of Skype, you need only follow the instructions to add a Skype contact, but clicking on their generation information instead of adding them. The debug log file will then contain the public IP address of the user, which could lead to the discovery of their whereabouts thanks to WHOIS services.

Skype put out a statement via email saying that it was looking into the issue, which is apparently faced by all peer-to-peer software companies. Skype is committed to the safety of customers and developing applicable Security Solutions

It’s not the first time that Skype has acknowledged the issue: a research paper published in October showed how the IP address could be resolved and linked to BitTorrent usage.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Sony Reaches Out to PS3 Hacker

Story first appeared in TG Daily.
A new interview with the infamous PS3 hacker reveals that at one point he had a confidential meeting with Sony.

The hacker is the subject of a new expose in the New Yorker, and it's revealed that after he reached a legal settlement with Sony, the company wanted to pick his brain.

He shot to online stardom last year as the center of attention in a highly publicized lawsuit from Sony. The hacker had been publishing information on how to hack the PS3, which Sony said was a violation of the console's terms of use.

Supporters said that Sony was going too far and had no reason to sue him. Attackers took down various Sony websites and servers in protest to the Hotz case.

Not everyone agreed, though. Some said he knowingly broke the rules, facilitated illegal software piracy, and should be tried to the full extent of the law.

In the end, the case was settled for less than a slap on the wrist. He merely had to agree to end his hacking exploits.

But a couple months later, Sony reached out to him and asked him all sorts of questions, hoping to gain insights that it could use to help the company prevent future attacks.

He said he was worried there would be lawyers present, but in fact he really just met with what he described as "respectful" PS3 engineers who wanted to learn from him.

The Sony SVP explained the meeting, saying that the last year had demonstrated how sophisticated cybercriminals can be. Sony is always interested in exploring all avenues to better safeguard our systems and protect consumers. This is a good example of why sophisticated Security Solutions are a must for businesses and corporations.

The hacker went on to land a job that most people would kill for - an engineering position at Facebook. But he ended up quitting because he didn't like the monotony of office life.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.

Monday, April 30, 2012

Cybersecurity Bill Up In The Air

Story first appeared in The Wall Street Journal.

Congress moved toward gridlock over how to improve the security of the nation's computer networks when the House of Representatives approved a measure opposed by the White House and at odds with Senate efforts on the issue.

House passage of its measure, the Cyber Intelligence Sharing and Protection Act, came on a 248-168 vote Thursday and was supported by both Republicans and Democrats.

The House vote came despite a warning by the White House that senior advisers would recommend a presidential veto if the measure also passed the Senate, which is considered unlikely.

The White House prefers a Senate bill that would concentrate cybersecurity efforts in the Department of Homeland Security and would require companies to bolster security for critical infrastructure, such as electrical and water systems. The House bill only facilitates the swapping of threat data between private companies and the National Security Agency and other government departments.

The House version also was criticized by civil-liberties groups that said its provisions allowing businesses to share information with the government to improve cybersecurity could compromise American citizens' privacy. The American Civil Liberties Union called it "a dangerously overbroad bill that would allow companies to share our private and sensitive information with the government without a warrant and without proper oversight."

The Obama administration says cybersecurity and IT security solutions should be overseen by civilian agencies. The Senate bill favored by the White House and supported by Democrats would place Homeland Security officials in charge of the effort.

However, the Senate measure is opposed by business groups because of requirements that businesses adopt measures to improve security, steps executives see as burdensome.

The twin controversies—whether to regulate security and whether a civilian agency should head up the effort—seem likely to snarl efforts to plug the growing gaps in network security.

Earlier attempts at cybersecurity legislation drew broad, bipartisan support but little momentum. In the past year, the debate has grown more polarized over whether government should play a larger role in requiring businesses to strengthen their cybersecurity.

House sponsors of the legislation cast it as a necessary first step in the process to protect American networks from groups in places like China and Russia who are pilfering intellectual property from U.S. businesses. Government and industry experts warn that as cyberattack tools become more widely available, capabilities once reserved for governments could extend to rogue states, terrorists or so-called hacktivist groups.

Setting aside the criticism, the House put together a strong bill that will help stop cyberattacks that threaten our economy and our privacy while keeping the Internet free from government control.

But sponsors of the leading Senate measure said Friday that the House should have included provisions to protect computer systems running critical infrastructure, as the Senate bill does.


For more national and worldwide related business news, visit the Peak News Room blog.
For local and Michigan business related news, visit the Michigan Business News blog.
For healthcare and medical related news, visit the Healthcare and Medical blog.
For law related news, visit the Nation of Law blog.
For real estate and home related news, visit the  Commercial and Residential Real Estate blog.
For technology and electronics related news, visit the Electronics America blog.
For organic SEO and web optimization related news, visit the SEO Done Right blog.