Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

Japan’s Mitsubishi Targeted by Cyber Attackers

A large-scale cyber attack has been launched on dominant Japanese weapons firm MHI (Mitsubishi Heavy Industries).

The attackers apparently sought to obtain data relating to MHI's nuclear power plants, submarines and missiles. According to the firm, 45 of its servers and 38 of its PCs were found to be hosting viruses when examined in August.

No evidence has been supplied that suggests the MHI hackers managed to extract any sensitive data but, even so, at the request of the Japanese Defence Ministry, the issue will be investigated in full.

Details of the Mitsubishi cyber attack emerged during a press event featuring Yasuo Ichikawa - the Japanese Defence Minister - held on 20 September 2011. Here, Ichikawa stressed that MHI would be told to carry out "a review of their information control systems", adding: "The ministry will continue to monitor the problem and conduct investigations if necessary."

Already, MHI knows that the attack isn't attributable to anyone using its own, in house network. Further to that, one element of the Japanese media, the Yomiuri daily, has suggested that the machine used to coordinate the attack featured a Chinese language display - allegations that China has since strongly denied.

"The Chinese government has consistently opposed hacking activities", Chinese foreign ministry representative Hong Lei commented today.

"China is one of the main victims of hacking...criticising China as being the source of the hacking attacks is not only baseless, it is also not beneficial for promoting international co-operation for internet security."

A pre-existing agreement established between Mitsubishi and the government in Japan makes the firm obliged to immediately disclose security breaches but, in this instance, officials appear to have got word of the Japanese cyber attack via the press - a situation that's said to have made them angry.

"It's up to the defence ministry to decide whether or not the information is important", an unnamed official stated in comments quoted by news agency Reuters, after Mitsubishi had been targeted, adding: "That is not for Mitsubishi Heavy to decide. A report should have been made."

2011 has seen a number of high profile cyber attacks launched against some of the world's most prominent defence firms. These include May's Lockheed Martin cyber attack where, again, no critical information is thought to have been obtained.

Image copyright Yusuke D - Courtesy Wikimedia Commons

See also:

Products and Services;

Companies supplying IT Security


View the original article here

Misspelt Addresses Are Cyber Security Concern

Something as simple as forgetting to insert a dot in an email address could result in a major cyber security breach, according to a newly-published report.

The report describes the findings from research carried out by representatives of information security think tank the Godai Group. It describes how, after they set up web domains containing some of the most frequently-misspelt names, the researchers collected no less than 20 gigabytes worth of data, representing 120,000 messages that wouldn't normally have been received.

Among this data were passwords, user names and information relating to corporate networks and, from this, the researchers established that close to one-third of the US' 500 most profitable firms (the ‘Top 500') could be considered susceptible to cyber attacks.

The vulnerability issue's linked to the way email systems are set up in the world of business. A significant number of businesses have a hierarchical URL set-up in place, with a main domain and, below that, sub domains for divisions within the firm. The words that make up these sub domains are separated by dots creating, for example, something like ‘bank.com' as the main domain and ‘us.bank.com' for a sub domain.

Misspelt email addresses, intended to be sent through to these sub domains, aren't normally delivered and, instead, are bounced back to the original user. The potential's there, however, for cyber criminals to exploit this scenario by creating lookalike domains (so-called doppelganger domains) with the goal of deliberating attracting emails containing misspelt addresses and that's exactly what the researchers did.

‘Doppelganger domains have a potent impact via email as attackers could gather information such as trade secrets, user names and passwords, and other employee information', they said in their report, adding: ‘essentially, a simple mistype of the destination domain could send anything that is sent over email to an unintended destination.'

Of the misspelt company domains that the research team created, reportedly only one of the firms involved realised what was happening and took action to confront the cyber security concern.

"It's striking that the researchers managed to capture so much information by focusing on just one common mistake", Sophos blog contributor Mark Stockley was quoted by the BBC as having said.

"A determined attacker with a modest budget could easily afford to buy domains covering a vast range of organisations and typos."

See also:

Companies supplying Email Security

Companies supplying Internet Security


View the original article here

LulzSec Claims Sun Newspaper Cyber Hack

A cyber hack event has resulted in The Sun newspaper’s website being breached and the URL redirecting to a false story covering the death of the paper’s owner, Rupert Murdoch, being posted up.

Since the Sun breach occurred, hacking organisation LulzSec has said it was responsible. While the link was intact, online users trying to access the newspaper’s website, sun.co.uk, in the usual way, were instead redirected to a site named new-times.co.uk, where a piece titled ‘Media Mogul’s Body Discovered’ had been posted up.

The story intimated that a “large quantity of [rare metal] palladium” had been ingested by Murdoch. This, it said, led to his death, which saw him “...stumbling into his famous topiary garden late last night, passing out in the early hours of the morning.”

This site went down after a while but, thereafter, another URL temporarily replaced The Sun’s address, this time linking out to LulzSec’s Twitter page.

The newspaper is part of News International’s portfolio and, in a statement, the parent firm confirmed, via a representative, knowledge of the Sun cyber hack events, but declined to comment further.

The Sun’s official website subsequently seemed to be inaccessible for a while but, as of mid-morning on the 19 July, appeared to be working as per normal.

LulzSec – short for Lulz Security – was established in May of this year and, since then, has taken credit for a number of significant security breaches.

The LulzSec Sun hack coincided with recent revelations concerning the behaviour of employees working for another News International publication, the News of the World. As a result of the phone-hacking that’s claimed to have taken place, the News of the World now no longer exists.

Commenting on the implications of this attack on the Sun and other recent events of a similar kind, IT firm 2e2’s security director, Russell Poole, stressed: “we need to be more vigilant.”

“In the past attacks were very general in nature, whereas now we are seeing these hacking groups focus in on a specific organisation”, Poole told PC Advisor.

“Essentially, hackers are constantly evolving their weapons of attack - the challenge for businesses is to stay one step ahead.”

See also:

Companies supplying Internet Security


View the original article here

DHS Guidance to Prevent Cyber Attacks

DHS Guidance to Prevent Cyber Attacks

The US Department for Homeland Security (DHS) unveiled new guidance on Monday designed to improve software security in the face of the growing problem of cyber attacks.

Central to the guidance to prevent cyber attacks is a list of 25 programming errors that enable the most serious hacks to occur - and advice on how to avoid them.

It released a list of software vulnerabilities called the Common Weakness Enumeration and set up a scoring system and analysis framework which organizations can use to measure and assess the threat level posed to them by hackers.

The DHS worked with a number of security consultancies, research organizations and private companies to compile the study.

Noting that human errors in programming are the cause of most attacks, the DHS said businesses should take heed of the advice and improve their software security, investing in far more superior and secure software protection systems. It also called for better training and education for software programmers.

Common Weakness Enumeration

At the top of the Common Weakness Enumeration, the list of 25 top security software vulnerabilities, was SQL injection which tricks systems into revealing secure information on databases to outsiders.

Mitre, the federal research laboratory which was contracted by the DHS to investigate the software security issue, said this flaw lay behind many of the recent high-profile hacks that led to organizations like Citigroup, Sony, the IMF and public agencies losing secure data.

The DHS intends the Common Weakness Enumeration and the accompanying scoring system to be a standard against which companies can measure and assess their security framework, and from these results take remedial action. It hopes the guidance - which is voluntary - will spur industry into making improvements.

Alan Peller from SANs, a consultancy involved in the DHS' work, said better quality software programming was the only way in which to really stop damaging cyber attacks.

"The only possible defense is to stop the error from being in the software in the first place," he told the Washington Post.

The Common Weakness Enumeration website can be accessed here:
http://cwe.mitre.org/

Further resources:

Computer Security 

Network Security Software


View the original article here

Iranian Armed Forces Cyber Command Planned

Iran is set to establish a dedicated cyber security force, according to comments made by a high-level official in mid-June 2011.

The planned cyber command centre will form part of a wider programme, boosting Iran's capability to defend itself against the threat of cyber attacks.

Speaking to Iranian media organisations, Brigadier General Massoud Jazzayeri - Deputy Chief of Staff for Cultural Affairs and Defense Publicity for the Iranian Armed Forces - explained how the cyber command topic has already been looked into and, at some point soon, the IAF will explore its potential further.

Once established, the Iranian Cyber Command would be the latest in a whole host of similar units set up in recent years by other nations.

The US took the lead when, in 2009, it announced the launch of USCYBERCOM. This reached IOC (Initial Operational Capability) in May 2010. Meanwhile, South Korea, China and the UK have all, since, started working within cyber defence.

In the case of Iran, it's considered that such a programme is needed to take on so-called ‘soft warfare' - i.e. attacks with a perceived emotional edge, launched away from the traditional battlefield setting.

To this end, according to Jazzayeri, Iranian troops need to have a dedicated cyber command up and running, equipped with ultra hi-tech cyber defence tools.

At the end of 2010, Mohammad Baqeri - senior commander of the Iranian Army - stressed that soft war was a real prospect for the Islamic Republic and explained how the country's enemies had shaken up national self-belief.

These enemies were attempting to "...affect the thoughts of the other side to gain victory and attains its goals by invading the values and patterns of behavior and changing them", Baqeri reportedly told news organisation Fars.

Since then, officials have issued out alerts to people living in Iran to be on their guard and watch out for plans to attack Islamic beliefs and values.


View the original article here

Cyber Security Challenge 2011 Competition Begins

A competition has been launched in the UK to try and discover the next generation of IT security workers.

Established in 2010, the Cyber Security Challenge is a 12-month long series of tasks which, at its conclusion, will establish the UK's most capable cyber warrior. It'll judge just how well its competitors can defeat the threat of cyber attacks launched within simulated hack scenarios - ultimately using actual malware of the kind used by hackers today - and it'll assess their ability to identify the source of the attacks, too.

The 2011 Cyber Security Challenge was initiated on 1 June and it's supported by a whole raft of sponsors including defence technology organisation QinetiQ, accounting firm PWC and computer security company Sophos, along with HP Labs, Cassidian and SANS Institute.

Prospective entrants are encouraged to register their details at the official Cyber Security Challenge competition website.

Earlier this year, the winner of the initial Cyber Security Challenge was announced as Dan Summers. At approximately the same time, data issued by UK government organisation e-Skills highlighted how, between 2005 and 2010, there was a 50 per cent drop in the number of new IT security workers.

The shortfall inspired the creation of this annual event which, in its first year, attracted 4,000 competitors, according to comments made by its director, Judy Baker, at the 2010 Challenge's conclusion.

"The idea started because of the skills shortage in cyber security", she said, adding: "It is clear that companies and government bodies are having huge problems finding the talent they need."

"Last year's Challenge was a great success and we learned a great deal from our first batch of candidates", PWC representative Jay Abbott stated, in a press release published online at the Cyber Security Challenge 2011 website.

"By feeding that back into our competition structure and design, this year's Challenge is going to be bigger and a more comprehensive test that truly showcases the array of experiences encountered in a professional cyber security environment.

"It offers a great introduction to those making a first attempt, and something different for those testing their mettle for the second time."

See also:

MoD to Recruit Cyber Security Army


View the original article here

Sony Playstation Network Cyber Attack Revealed

Sony has issued a major security warning to its Playstation Network users, after experiencing a massive hacking attack by an unknown source earlier on this month.

The Playstation Network user warning highlights the risk of personal data, such as credit card information, having been stolen as a result of the hack and advises Network users to be on the lookout for faux emails and phone calls from now on.

"We have discovered that between April 17 and April 19 2011, certain PlayStation Network and Qriocity service user account information was compromised in connection with an illegal and unauthorized intrusion into our network", Nick Caplin - Sony's European communications head - stated in an official blog release.

The same release detailed the type of Playstation user data that may have stolen, including name, address, email address, date of birth and Playstation Network user data.

"For your security, we encourage you to be especially aware of email, telephone, and postal mail scams that ask for personal or sensitive information", Caplin added, in the Playstation Network hack statement.

The sheer popularity of the Sony Playstation Network could make any data theft that has taken place a potentially massive security incident.

As this article was being prepared, the Sony Playstation Network, access to which was suspended on 20 April, was still unable to be accessed by any of its 77 million global users.

Meanwhile, an unnamed security organisation is set to launch an investigation into the Sony cyber attack, while Playstation Network users themselves await the restoration of service.

No official word on its return has yet been released, but Sony has described its decision to seal it up, for the time being, as a response to an ‘illegal and unauthorised intrusion.'

"We greatly appreciate your patience, understanding and goodwill as we do whatever it takes to resolve these issues as quickly and efficiently as practicable", Caplin told users.

Security Technology will revisit this subject in future news coverage.

See also:

Cyber Europe 2010 Online Security Exercise


View the original article here

Iran Mobilises Cyber Hacking Army

Iran is reportedly mobilising an army of cyber hackers in response to a series of online attacks in 2010.

These attacks were said to have badly hit the country's nuclear enrichment site at Natanz and, now, Iran is moving towards retaliation. This will potentially involve the Passive Defence Organization, which is led by Brigadier General Gholamreza Jalali.

In comments made to the Bultannews website and quoted in subsequent reports, he appeared to be actively seeking new recruits, stating: "Regarding the cyber issue, we welcome the presence of those hackers who are willing to work for the goals of the Islamic Republic with good will and revolutionary activities."

In separate comments quoted by Fox News, Jalali outlined the scale of these planned Iranian cyber attacks. The Islamic Republic, he said, intended "to fight our enemies with abundant power in cyberspace and Internet warfare."

It's possible there will be a long line of candidates keen to be involved in this project. Internet censorship is in place in Iran, but that doesn't stop large numbers of teenagers blogging and networking. In order to do so, they're knowingly bypassing the laws of the land and, according to some, Iran's younger generation potentially includes the hackers of the future.

The potential's also there for IT technicians and others to feed the cyber hacking army without realising it, according to ex-Iranian Revolutionary Guard Mohsen Sazegara.

"Computer experts working on piecemeal projects wouldn't even necessarily know they were working on a government cyber attack plan", he told Fox."It's a process. They write complicated programs and divide and subdivide the work in such a way that even a highly qualified person might not know the end results. So they can recruit many people who would not know that the end result of their work might be a computer worm."

Iran already has a dedicated cyber warfare organisation up and running. Iran's Cyber Army, as it's known, has claimed it's been behind multiple recent attacks including, reportedly, one on the Voice of America. Information on Iran's Cyber Army is sketchy - we don't know who heads it, who supports it and where it's based (not necessarily Iran).

A bigger question, though, is what form the Iranian cyber attacks take from here on in. Security Technology will present updated coverage on this subject in future News Items.


View the original article here

More Cyber Attacks Against Government In 2010

Cyber attacks against the US federal government rose by nearly 40 percent last year, reports the Federal times.

The Office of Management Budget's annual report on the federal cybersecurity effort showed that there were no fewer than 41,776 cyber attacks on government systems during 2010. This was up from the 30,000 recorded the previous year, a rise of 39 per cent.

The figures were released by the Department of Homeland Security (DHS) U.S. Computer Emergency Readiness Team (US-CERT).

Chris Ortman, DHS spokesman, said that the DHS "anticipates that malicious cyber activity will continue to become more common, more sophisticated and more targeted - and range from unsophisticated hackers to very technically competent intruders using state-of-the-art techniques."

Out of the total number of cyber attacks 12,864 were classified as malicious. Another 11,336 are under investigation, with unauthorized access, denial of service attacks, improper usage, scans probes and attempted access making up the remainder. Phishing was the major threat, with reported 56,579 attacks. There were 11,001 reports of attacks by trojan worms and viruses.

OMB's report said that particular cyber security threats for government were attacks exploiting so-called "zero-day", or unknown, vulnerabilities in software. The report said the "exploit codes" used to undertake such attacks are often made public through the internet.

The report said government cyber security is let down by the fact that two-thirds of federal are not yet continuously monitoring their networks. The report said 8 per cent had no monitoring systems in place at all.

However, the report also praised federal government's response to the growing cyber security threat by saying that agencies are now changing their policies to implement the Federal Information Security Management Act (FISMA) which lays down standards and policies about how agencies should deal with information security.

Last year also saw the introduction of a security threat reporting metric called Cyberscope, which aims to create a picture of how agencies are meeting their security obligations. During fiscal year 2011 a management model called CyberStat will be introduced across federal government which will allow agencies to examine security metrics and develop security plans to respond to any threats.

Further resources:

IT Security


View the original article here

More Cyber Attacks Against Government In 2010

Cyber attacks against the US federal government rose by nearly 40 percent last year, reports the Federal times.

The Office of Management Budget's annual report on the federal cybersecurity effort showed that there were no fewer than 41,776 cyber attacks on government systems during 2010. This was up from the 30,000 recorded the previous year, a rise of 39 per cent.

The figures were released by the Department of Homeland Security (DHS) U.S. Computer Emergency Readiness Team (US-CERT).

Chris Ortman, DHS spokesman, said that the DHS "anticipates that malicious cyber activity will continue to become more common, more sophisticated and more targeted - and range from unsophisticated hackers to very technically competent intruders using state-of-the-art techniques."

Out of the total number of cyber attacks 12,864 were classified as malicious. Another 11,336 are under investigation, with unauthorized access, denial of service attacks, improper usage, scans probes and attempted access making up the remainder. Phishing was the major threat, with reported 56,579 attacks. There were 11,001 reports of attacks by trojan worms and viruses.

OMB's report said that particular cyber security threats for government were attacks exploiting so-called "zero-day", or unknown, vulnerabilities in software. The report said the "exploit codes" used to undertake such attacks are often made public through the internet.

The report said government cyber security is let down by the fact that two-thirds of federal are not yet continuously monitoring their networks. The report said 8 per cent had no monitoring systems in place at all.

However, the report also praised federal government's response to the growing cyber security threat by saying that agencies are now changing their policies to implement the Federal Information Security Management Act (FISMA) which lays down standards and policies about how agencies should deal with information security.

Last year also saw the introduction of a security threat reporting metric called Cyberscope, which aims to create a picture of how agencies are meeting their security obligations. During fiscal year 2011 a management model called CyberStat will be introduced across federal government which will allow agencies to examine security metrics and develop security plans to respond to any threats.

Further resources:

IT Security


View the original article here

Iran Mobilises Cyber Hacking Army

Iran is reportedly mobilising an army of cyber hackers in response to a series of online attacks in 2010.

These attacks were said to have badly hit the country's nuclear enrichment site at Natanz and, now, Iran is moving towards retaliation. This will potentially involve the Passive Defence Organization, which is led by Brigadier General Gholamreza Jalali.

In comments made to the Bultannews website and quoted in subsequent reports, he appeared to be actively seeking new recruits, stating: "Regarding the cyber issue, we welcome the presence of those hackers who are willing to work for the goals of the Islamic Republic with good will and revolutionary activities."

In separate comments quoted by Fox News, Jalali outlined the scale of these planned Iranian cyber attacks. The Islamic Republic, he said, intended "to fight our enemies with abundant power in cyberspace and Internet warfare."

It's possible there will be a long line of candidates keen to be involved in this project. Internet censorship is in place in Iran, but that doesn't stop large numbers of teenagers blogging and networking. In order to do so, they're knowingly bypassing the laws of the land and, according to some, Iran's younger generation potentially includes the hackers of the future.

The potential's also there for IT technicians and others to feed the cyber hacking army without realising it, according to ex-Iranian Revolutionary Guard Mohsen Sazegara.

"Computer experts working on piecemeal projects wouldn't even necessarily know they were working on a government cyber attack plan", he told Fox."It's a process. They write complicated programs and divide and subdivide the work in such a way that even a highly qualified person might not know the end results. So they can recruit many people who would not know that the end result of their work might be a computer worm."

Iran already has a dedicated cyber warfare organisation up and running. Iran's Cyber Army, as it's known, has claimed it's been behind multiple recent attacks including, reportedly, one on the Voice of America. Information on Iran's Cyber Army is sketchy - we don't know who heads it, who supports it and where it's based (not necessarily Iran).

A bigger question, though, is what form the Iranian cyber attacks take from here on in. Security Technology will present updated coverage on this subject in future News Items.


View the original article here

Iran Mobilises Cyber Hacking Army

Iran is reportedly mobilising an army of cyber hackers in response to a series of online attacks in 2010.

These attacks were said to have badly hit the country's nuclear enrichment site at Natanz and, now, Iran is moving towards retaliation. This will potentially involve the Passive Defence Organization, which is led by Brigadier General Gholamreza Jalali.

In comments made to the Bultannews website and quoted in subsequent reports, he appeared to be actively seeking new recruits, stating: "Regarding the cyber issue, we welcome the presence of those hackers who are willing to work for the goals of the Islamic Republic with good will and revolutionary activities."

In separate comments quoted by Fox News, Jalali outlined the scale of these planned Iranian cyber attacks. The Islamic Republic, he said, intended "to fight our enemies with abundant power in cyberspace and Internet warfare."

It's possible there will be a long line of candidates keen to be involved in this project. Internet censorship is in place in Iran, but that doesn't stop large numbers of teenagers blogging and networking. In order to do so, they're knowingly bypassing the laws of the land and, according to some, Iran's younger generation potentially includes the hackers of the future.

The potential's also there for IT technicians and others to feed the cyber hacking army without realising it, according to ex-Iranian Revolutionary Guard Mohsen Sazegara.

"Computer experts working on piecemeal projects wouldn't even necessarily know they were working on a government cyber attack plan", he told Fox."It's a process. They write complicated programs and divide and subdivide the work in such a way that even a highly qualified person might not know the end results. So they can recruit many people who would not know that the end result of their work might be a computer worm."

Iran already has a dedicated cyber warfare organisation up and running. Iran's Cyber Army, as it's known, has claimed it's been behind multiple recent attacks including, reportedly, one on the Voice of America. Information on Iran's Cyber Army is sketchy - we don't know who heads it, who supports it and where it's based (not necessarily Iran).

A bigger question, though, is what form the Iranian cyber attacks take from here on in. Security Technology will present updated coverage on this subject in future News Items.


View the original article here

Related Posts Plugin for WordPress, Blogger...