Posts

Showing posts with the label Malware

2021 Predictions in Technology

Image
Days after the beginning of 2021 and it’s time to update my annual technology prediction. As you’ll see some are a bit redux, while others look at possibilities that would be amazing. I’d note to my readers – thanks for taking time to read this rambling, and I look forward to your feedback and ideas for next year!.   2020 in review Four of my five 2020 predictions came abouts to some level. Either my predictions where spot on, or they where not as futuristic as I thought. 5G is now ubiquitous and most countries have rolled the capabilities out nationwide. In the USA all major providers have boasted the capability of 5G and in fact 5G made headlines as a cause for COVID-19 within some extremely paranoid. So 5G is available, and a great marketing gimmick – unfortunately for me, it’s a fizzle and fails to really make a difference in connection speeds over 3G. I’ve noted many say similar – that 5G over 3G is a cool idea – if it actually provided more connection speed. This ...

2020 predictions

Image
2020 is coming upon us, and it's time to reflect on my 2019 predictions I made, and look forward to this coming year with another technology prediction. So let's get started - first off - a lookback to see  progress in the areas I outlined, possibly no earth shattering results, but progress.  2019 retrospective - New UX - probably not as much evolution as I would have wanted to see in this area. For now, we use windows, android, IOS, and it's pretty much the same UX as it's been for a while. IoT the simple assistant - IoT continues to be the hot area of growth. I consider this more evolution than revolution. As we see IoT based technology being embedded into more and more devices. Cloud growth advances in   astonishing speeds - This past year all three cloud providers made strides in the cloud worth noticing.  AWS entered the quantum computing market with Bracket, introduced an in-house...

Next gen Stuxnet - Duqu 2.0?

Image
Last week the discovery of the new and revised Duqu has stirred interest around the similarities between this new malware and it's similarities to Stuxnet. A bit of history about both Duqu and Stuxnet; Stuxnet Stuxnet made its glory by attacking the Iran nuclear facilities in 2012. This worm was designed to attack the industrial programmable logic controllers (PLC) in a nuclear system. Turns out it worked great, and put several Iranian centrifuges out of commission.  Shortly after, the underlying vulnerabilities MS15-020 that Stuxnet exploited was discovered and used en mass by the underground community. However the actual code behind Stuxnet remained a mystery. Duqu Duqu has been making it's rounds for a while, primarily used to collect key strokes and general exfiltration of systems. This Trojan made it's fame with the kernel exploit in MS11-087 . And has been used by the bad guys to spy on users and even remote format hard drivers. Duqu 2.0 Now...

Protecting sensitive data

Image
Last month I wrote an article on key things to consider when protecting high valued assets or sensitive data. The article called Security Tip of the Month: Protecting Highly Sensitive Information addressed some of the key items that organizations should consider when protecting data that has the possible impact on an organization that is irreparable. As my article stated the cost of protecting this data tends to be higher than most data. Fact is that this data is not traditionally just sensitive such as credit card data, or HR data. Key indicators of what is High Value Data can be summed up like this. Assets that are considered to be of high value will frequently have the potential to cause the following conditions if they are lost or divulged: •        Loss of life - such as an informant list •        Regulatory fines - such as financial performance data •      ...

Operation Cleaver #opcleaver

Image
In this blog I wanted to take a quick look at how we should consider our adversaries today, and kudo's to a great report. The operation Cleaver report  put out by Cylance outlines how Iran has been actively targeting the world market and the Internet as a whole.  If you don't have time to read the entire report I'd recommend you review pages  32- 35 that discusses the initial methods of compromise. It's a good practice to understand how adversaries get into your network to know how to protect yourself. Here's a quick look at defenses you need to consider: Compromise 1  - SQL injection attacks -   This attack counts on administrators not setting up a SQL server with security in mind. Resolving this can be done by patching and maintaining SQL servers that are on your perimeter network. Make sure that you configure your edge with security in mind. Consider this guidance as a good practice: A quick Technet article on protecting against SQL injection...