Showing posts with label computer. Show all posts
Showing posts with label computer. Show all posts

GCIS INTELLIGENCE BRIEFING: RSA security breach compromised federal network ID tool

ISSUED BY: GCIS Communications Command Center

SOURCE: NextGov

24March2011 7:00amEST

GCIS INTELLIGENCE UPDATE:  A product many federal employees use to log on to computers and networks should be regarded as compromised, due to the infiltration of key information about the application during a cyberattack against manufacturer RSA, some security experts said.

compromise cyber securityThe Homeland Security Department -- the civilian agency that oversees commercial and government cybersecurity -- has relayed mitigation procedures to federal agencies that have installed RSA's SecurID tools, the department announced on Friday. A DHS official on Monday said the government is not recommending that agencies replace their SecurID products. The department is helping RSA and clients who control critical infrastructure deal with the threat to the devices, which are a single point of failure in the computer security ecosystem, according to some industry observers.

Agencies "should consider [the ID tools] breached," said Tom Kellermann, a former World Bank computer specialist and now an executive at Core Security Technologies, a firm that lawfully penetrates its clients' systems to identify network weaknesses.

SecurID, which verifies the identities of authorized users, consists of a token -- a portable physical object such as a smart card or USB drive that controls access to a system. The device displays a continuously changing code that the user enters, in conjunction with a personal identification number, or PIN, to log into a network through a process known as two-factor authentication. (read full report)

"GCIS INTELLIGENCE UPDATE" is an intelligence briefing presented by Griffith Colson Intelligence Service, and provided to the public for informative purposes only. All subject matter is credited to it's source of origin, and is not intended to represent original content authored by GCIS, it's partners or affiliates. All opinions presented are those of the author, and not necessarily those of GCIS or it's partners.

GCIS INTELLIGENCE BRIEFING: Goldman Sachs Computer Programmer Sentenced for Stealing Trade Secrets

ISSUED BY: GCIS Communications Command Center

SOURCE: FBI

21March2011 1:31pmEST

GCIS INTELLIGENCE UPDATE:  PREET BHARARA, the United States Attorney for the Southern District of New York, announced that SERGEY ALEYNIKOV, a former computer programmer at Goldman Sachs & Co. (“Goldman Sachs”) was sentenced today in Manhattan federal court to 97 months in prison for stealing valuable, proprietary computer code of Goldman Sachs. A jury in Manhattan federal court previously found ALEYNIKOV guilty on December 10, 2010, of theft of trade secrets and interstate transportation of stolen property charges. U.S. District Judge DENISE L. COTE imposed the sentence on ALEYNIKOV.

computer code theftManhattan U.S. Attorney PREET BHARARA said: “Protecting the proprietary information of America’s companies is critically important. Today’s sentence sends a clear message that professionals like Sergey Aleynikov who abuse their positions of trust to steal confidential business information from their employers will be prosecuted and punished.”

According to the evidence presented at trial and at the sentencing hearing:

From May 2007 to June 2009, ALEYNIKOV was employed at Goldman Sachs as a computer programmer responsible for developing computer programs supporting the firm’s high-frequency trading on various commodities and equities markets. Since acquiring the system in 1999 for approximately $500 million, Goldman Sachs modified and maintained it and took significant measures to protect the confidentiality of its computer programs. Goldman Sachs’ trading system generated millions of dollars per year in profits for the firm. They took several measures to protect the system’s source code, including requiring all Goldman employees to agree to a confidentiality agreement.

In April 2009, ALEYNIKOV resigned from Goldman Sachs and accepted a job at Teza Technologies (“Teza”), a newly-formed company in Chicago, Illinois. He was hired to develop Teza’s own version of a computer platform that would allow Teza to engage in high-frequency trading. His last day of employment at Goldman Sachs was June 5, 2009.

Beginning at approximately 5:20 p.m. on June 5, 2009—his last day working at Goldman Sachs—ALEYNIKOV, from his desk at Goldman Sachs, transferred substantial portions of the firm’s proprietary computer code for its trading platform to an outside computer server in Germany. He encrypted the files and transferred them over the Internet without informing Goldman Sachs. After transferring the files, he deleted the program he used to encrypt them and deleted his computer's “bash history,” which records the most recent commands executed on his computer.

In addition, throughout his employment at Goldman Sachs, ALEYNIKOV transferred thousands of computer code files related to the firm’s proprietary trading program from the firm’s computers to his home computers, without the knowledge or authorization of Goldman Sachs.

On July 2, 2009, ALEYNIKOV flew to Chicago, Illinois, to attend meetings at Teza’s offices, bringing with him his laptop computer and another storage device, each of which contained Goldman Sachs’ proprietary source code. He was arrested on July 3, 2009, as he arrived at Newark Airport following that visit.

In addition to the prison sentence, Judge COTE ordered ALEYNIKOV to serve three years of supervised release following his prison sentence. Judge COTE also ordered him to pay a $12,500 fine.

During the sentencing proceeding, Judge COTE said, “[Aleynikov’s] conduct deserves a significant sentence because the scope of his theft was audacious—motivated solely by greed, and it was characterized by supreme disloyalty to his employer.”

Mr. BHARARA praised the investigative work of the FBI in this case. Mr. BHARARA also thanked Goldman Sachs for its cooperation in the investigation. (read full report)

"GCIS INTELLIGENCE UPDATE" is an intelligence briefing presented by Griffith Colson Intelligence Service, and provided to the public for informative purposes only. All subject matter is credited to it's source of origin, and is not intended to represent original content authored by GCIS, it's partners or affiliates. All opinions presented are those of the author, and not necessarily those of GCIS or it's partners.

GCIS TECHNOLOGY BRIEFING: All the Digital Data In the World Is Equivalent to One Human Brain

 

ISSUED BY: GCIS Communications Command Center

SOURCE: POPSCI

14February2011 9:57amEST

GCIS TECHNOLOGY UPDATE: If you could put all the data in the world onto CDs and stack them Super-computingup, the pile would stretch from the Earth to beyond the moon, according to a new study. The world’s technological infrastructure has a staggering capacity to store and process information, reaching 295 exabytes in 2007, a reflection of the world’s almost complete transition into the digital realm. That's a number with 20 zeroes behind it, in case you're wondering.
Martin Hilbert and Priscila López took on the unenviable task of figuring out how much information is out there, and how its storage and processing have changed over time. Some of their findings seem obvious, like the fact that Internet and phone networks have grown at quite a clip (28 percent per year), while TV and radio grew much more slowly. But others are more surprising, like the nugget that 75 percent of the world’s stored information was still in analog format in 2000, mostly in the form of video cassettes. By 2007, 94 percent of the world’s info was digital. (read full report)

 

 

"GCIS INTELLIGENCE UPDATE" is an intelligence briefing presented by Griffith Colson Intelligence Service, and provided to the public for informative purposes only. All subject matter is credited to it's source of origin, and is not intended to represent original content authored by GCIS, it's partners or affiliates. All opinions presented are those of the author, and not necessarily those of GCIS or it's partners.

GCIS CYBER-SECURITY BRIEFING: Report: Stuxnet Hit 5 Gateway Targets on Its Way to Iranian Plant

 

ISSUED BY: GCIS Communications Command Center

SOURCE: Wired.com: Threat Level

12February2011 5:39pmEST

GCIS CYBER-SECURITY UPDATE: Attackers behind the Stuxnet computer worm focused on targeting five organizations in Iran that they believed would get them to their final target in that Stuxnetcountry, according to a new report from security researchers.

The five organizations, believed to be the first that were infected with the worm, were targeted in five separate attacks over a number of months in 2009 and 2010, before Stuxnet was discovered in June 2010 and publicly exposed. Stuxnet spread from these organizations into other organizations on its way to its final target, which is believed to have been a nuclear enrichment facility or facilities in Iran.

“These five organizations were infected, and from those five computers Stuxnet spread out — not to just computers in those organizations, but to other computes as well,” says Liam O Murchu, manager of operations for Symantec Security Response. “It all started with those five original domains.” (read full report)

 

 

"GCIS INTELLIGENCE UPDATE" is an intelligence briefing presented by Griffith Colson Intelligence Service, and provided to the public for informative purposes only. All subject matter is credited to it's source of origin, and is not intended to represent original content authored by GCIS, it's advertisers or affiliates. All opinions presented are those of the author, and not necessarily those of GCIS or it's partners.

GCIS CYBER-SECURITY BRIEFING: Latest Attacks, Hacks, and Tracks

 

ISSUED BY: GCIS Communications Command Center

SOURCE:

26January2011 02:15amEST

GCIS CYBER-SECURITY UPDATE: 

Teen Arrested After Threatening to 'Shoot Up' His School on Facebook

 

By Amar Toor of Switched -

A 16-year-old high school student has been arrested in Indianapolis, after posting ominous threats on his Facebook page.

The boy, a special-needs student at Warren Central High School, allegedly wrote that he would "shoot up the school" after the Martin Luther King Day holiday. "Your dreams will be broken by Warren Central, no more Nice Guy," reads one of the suspect's posts. "I mean what I said and you are going to die tomorrow, every last one of you," declares another. (read more)

 

Spotlight On Woeful Web Security In iPad Hacking Case:

by Paul Roberts of ThreatPost -

OK - you're walking down the street and you come upon this apple tree in some one's front yard. It's a lovely tree, full of ripe apples. And, just by standing on the street, you can reach into the yard and jiggle the branch of this apple tree and these lovely, ripe apples just drop to your feet. Are you stealing the apples by shaking the branch and then walking away with the fruit that falls off? Or, how about this: you're at this vending machine and the dude who was servicing it just left the door to the machine wide open, so you can reach in and take the bag of Funyuns without paying for them. Is that stealing?

Turns out, the answer is both cases is "hell yeah!" But most of us might see these types of scenarios as more ambiguous than the cut and dry "throw-the-brick-through-the-window, snatch-the-diamond-necklace-and-run-away" kind of property crime. And those ambiguities are going to be front and center in the case of the two men who were arrested, this week, and charged in the high profile hack of a server holding the account information of VIP iPad owners. (read more)

 

Government, Military Sites Hacked, Data and Access for Sale

By Brian Donohue of ThreatPost -

The Web site of the U.S. military's Communications-Electronics Command (CECOM) was off line on Monday after reports that access to the site was among those being fenced by hackers in an underground forum.

The CECOM home page, cecom.army.mil displayed a message saying the site was "temporarily unavailable," an apparent response to the revelation on Friday that credentials offering full administrative control to the site could be had for $499 online. The CECOM site was one of a list of U.S. and foreign military, government, and educational sites being fenced in underground forums, according to a report from Krebsonsecurity.com. (read more)

 

New Phishing Campaign Targets 'First Data' Merchant Accounts

By Lucian Constantin of Softpedia -

In the pool of phishing attacks targeting online banking accounts, credit card information, personal details and other online accounts, scams aiming at merchants are not very common.

The rogue emails detected by ApprRiver bear a subject of "MERCHANT ACCOUNT UPDATE" and purport to come from "FIRSTDATA SERVICES."

The message contained within reads "Dear First Data customer, please update your login. Download the attachment in this e-mail and proceed."

The attachment is an HTML document called "Update Your Account Information.html," which, when opened inside the browser, displays a spoofed First Data Global Gateway login page.

The page contains a form for inputting the merchant's store number, user ID, tax ID, phone number and password.

"Once the hacker has gained access to the First Data account they will likely have gained control over that specific merchants account," warns Troy Gill, security researcher at AppRiver. (read more)

 

Facebook's Zuckerberg in fan-page hack - on Facebook!

by Paul Ducklin on NakedSecurity -

According to Tech Crunch - and numerous other online technophile sites - a promiment Facebook fan page has been hacked, defaced and, as a result, closed down. (read more)

 

Anti-Pirate Law Firm Succumbs to Coordinated Hacker Assault

by Warren Riddle of Switched -

Andrew Crossley, the manager of the law firm ACS:Law, made a concerted effort last year to individually punish purported file-sharers. The dismissive Crossley learned a painful and public lesson in hubris, though, when agitated Web vigilantes launched 'Operation Payback is a B****' and specifically targeted the law firm. After having suffered site attacks, network hacks, leaked confidential information and government investigations, ACS:Law has apparently succumbed to the disruptive pirate pressure.  (read more)

 

New Jersey Student Record Database Hacked

By Brian Donohue of ThreatPost -

A New Jersey school district was vandalized by members of the online mischief making group 4chan after an administrative password to a student record management system used at 160 school systems across New Jersey.

The hack occurred after the administrative account used by the Plainfield, New Jersey, school district to access the Genesis Student Information System was posted, along with the password needed to access the account: the word 'poopnugget,' according to a report on ComputerWorld. The password was posted to a 4chan message board, and from there, 4chan users infiltrated the Genesis system wreaking havoc on everything from lunch prices to the school system’s emergency broadcast system. (read more)

 

'uProtect.it' App Hides Your Facebook Comments From Facebook

By Amar Toor of Switched -

Facebook's customizable privacy settings may allow users to hide their comments from co-workers and ex-boyfriends, but a new tool called uProtect.it can conceal them from a much more ubiquitous observer: Facebook itself. (read more)