Cyber Security Training Courses via Simpliv
[pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2020/11/Simpliv-Links.pdf” title=”Simpliv Links”]
To review each course download a pdf of Cyber Security Training Courses
InfoSec Compliance & AI Governance For over 20 years, DISC InfoSec has been a trusted voice for cybersecurity professionals—sharing practical insights, compliance strategies, and AI governance guidance to help you stay informed, connected, and secure in a rapidly evolving landscape.
Nov 02 2020
[pdf-embedder url=”https://blog.deurainfosec.com/wp-content/uploads/2020/11/Simpliv-Links.pdf” title=”Simpliv Links”]
Oct 30 2020
Hackers can now reverse-engineer updates or write their own custom firmware.
Source: In a first, researchers extract secret key used to encrypt Intel CPU code
Oct 29 2020
A relative newcomer in the “malware-as-a-service” scene is starting to attract the big-money ransomware criminals.
Source: Buer Loader “malware-as-a-service” joins Emotet for ransomware delivery
Understanding malware as a service
httpv://www.youtube.com/watch?v=VoOJaKZvZ-o&ab_channel=BitdefenderOEM
MaaS Chaos. Is Malware-as-a-Service Growing?
In the legitimate business world, there’s something known as Software-as-a-Service, or SaaS. Here’s a definition: A software licensing-and-delivery model in which centrally located and controlled software is made available and licensed/rented on a subscription basis by users. SaaS clients are generally businesses.
Now, organized online crooks have moved into that space and business model too. It didn’t take long for that large-scale approach to not only hit the Internet, but to create a lucrative malware business for criminals who are selling viruses and more to anyone who wants it and is willing to pay for it. It’s “MBA-like” thinking for the purpose of making money by committing technologically based crimes.
Malware-as-a-Service is the latest term for the business of a network of sophisticated cyber-crooks providing illegal services, for a fee.
One of the reasons that cybercrime has grown so rapidly is that the criminals at the top of the “food chain” have built scalable business models for their crimes. This allows experienced hacking groups to collaborate, and new criminals to leverage the resources of veteran hackers. “Crime-as-a-service” is nothing new, but the tools change rapidly as crimeware developers work to exploit the latest vulnerabilities and stay ahead of security. The Emotet banking trojan has emerged as a leader in providing malware delivery services to other hacking groups, and you will want to make sure you understand and defend against this threat.
Emotet emerges as a leader in Malware-as-a-Service
Oct 27 2020
For the second time in as many years, Google is working to fix a weakness in its Widevine digital rights management (DRM) technology used by online streaming sites like Disney, Hulu and Netflix to prevent their content from being pirated.
The latest cracks in Widevine concern the encryption technology’s protection for L3 streams, which is used for low-quality video and audio streams only. Google says the weakness does not affect L1 and L2 streams, which encompass more high-definition video and audio content.
“As code protection is always evolving to address new threats, we are currently working to update our Widevine software DRM with the latest advancements in code protection to address this issue,” Google said in a written statement provided to KrebsOnSecurity.
In January 2019, researcher David Buchanan tweeted about the L3 weakness he found, but didn’t release any proof-of-concept code that others could use to exploit it before Google fixed the problem.
Source: Google Mending Another Crack in Widevine
Oct 26 2020
KashmirBlack has been targeting popular content management systems, such as WordPress, Joomla, and Drupal, and using Dropbox and GitHub for communication to hide its presence.
The botnet, dubbed KashmirBlack, uses a modular infrastructure that includes features such as load balancing communications with command-and-control servers and storing files on cloud storage services, such as Dropbox and GitHub, to speed access to any new code updates for the systems infected with the software. The KashmirBlack botnet mainly infects popular CMS platforms, exploiting dozens of known vulnerabilities on targeted servers and performing millions of attacks per day on average, according to a pair of reports published by Imperva researchers today.
Source: Botnet Infects Hundreds of Thousands of Websites
CyberHub Podcast – Practitioner Brief 10-26-20 Emotet upgrades, Kashmirblack & ransomware surge
httpv://www.youtube.com/watch?v=2td9wQ4LleY&ab_channel=TheCyberHubPodcast
Oct 21 2020
PayPal Holdings Inc joined the cryptocurrency market on Wednesday, allowing customers to buy, sell and hold bitcoin and other virtual coins using the U.S. digital payments company’s online wallets.
Source: PayPal to allow cryptocurrency buying, selling and shopping on its network
PayPal to Allow Cryptocurrency Buying, Selling and Shopping on its Network ₿₿₿
httpv://www.youtube.com/watch?v=QdOvU6YzNbU&ab_channel=RulesForRebels
Oct 19 2020
Hackers with access to the Signaling System 7 (SS7) used for connecting mobile networks across the world were able to gain access to Telegram messenger and email data of high-profile individuals in the cryptocurrency business.
Source: Hackers hijack Telegram, email accounts in SS7 mobile attack
Telegram SS7 attack
httpv://www.youtube.com/watch?v=dkvQqatURdM&ab_channel=ThomasBrewster
Oct 15 2020
Nook, line and sinker: Servers restored from backups, punters unable to download purchased e-books
Oct 12 2020
FS-ISAC, ESET, Lumen’s Black Lotus Labs, NTT, Symantec, and the Microsoft Defender team participated in the takedown.
Source: Microsoft and others orchestrate takedown of TrickBot botnet | ZDNet
Microsoft takes action against Trickbot ransomware attacks
httpv://www.youtube.com/watch?v=39MFGABNf2U&ab_channel=CBCNews%3ATheNational
Oct 09 2020
Here’s why it may be impossible to delete your personal information from Houseparty and other social media services – despite privacy legislation!
Source: So you thought your personal data was deleted? Not so fast | WeLiveSecurity
How to erase your iPhone — Apple Support
httpv://www.youtube.com/watch?v=zX4xvkJDHVw&ab_channel=AppleSupport
Oct 08 2020
The Springfield Public Schools district in Massachusetts has become the victim of a ransomware attack that has caused the closure of schools while they investigate the cyberattack.
Source: Massachusetts school district shut down by ransomware attack
FBI warning schools to create a ransomware attack plan
httpv://www.youtube.com/watch?v=riLtsU9IKiI&ab_channel=News5Cleveland
Oct 06 2020
Including HP Official Ink and Toner cartridge security, HP announced rewards up to $10,000 under the new printer bug bounty program.
After pioneering a bug rewards program for printer security, HP takes another step in this direction. As announced, HP has expanded its bug bounty program for printers to include cartridge security vulnerabilities.
Source: HP Printer Bug Bounty Expands To Include Cartridge Security
Oct 05 2020
Jailbreak involves combining last year’s checkm8 exploit with the Blackbird vulnerability disclosed this August.
Source: Hackers claim they can now jailbreak Apple’s T2 security chip | ZDNet
How to Disable T2 Security
httpv://www.youtube.com/watch?v=rzjXgPmVtdQ
👉 Download a Virtual CISO (#vCISO) and Security Advisory Fact Sheet & Cybersecurity Cheat Sheet
Download a Security Risk Assessment Steps paper!
DISC InfoSec 🔒 securing the business 🔒 via latest InfoSec titles
Subscribe to DISC InfoSec blog by Email
Oct 04 2020
No patients were affected, but the incident was another reminder of the risks in the increasingly common assaults on healthcare computer networks.
A Philadelphia company that sells software used in hundreds of clinical trials, including the crash effort to develop tests, treatments and a vaccine for the coronavirus, was hit by a ransomware attack that has slowed some of those trials over the past two weeks.
The attack on eResearch Technology, which has not previously been reported, began two weeks ago when employees discovered that they were locked out of their data by ransomware, an attack that holds victims’ data hostage until they pay to unlock it. ERT said clinical trial patients were never at risk, but customers said the attack forced trial researchers to track their patients with pen and paper.
Source: Clinical Trials Hit by Ransomware Attack on Health Tech Firm
Clinic.al Trials Hit by Ransomware Attack on Health Tech Firm
httpv://www.youtube.com/watch?v=9wYhmwTtZ3w&ab_channel=NewsHotDailyc
👉 Download a Virtual CISO (#vCISO) and Security Advisory Fact Sheet & Cybersecurity Cheat Sheet
Download a Security Risk Assessment Steps paper!
DISC InfoSec 🔒 securing the business 🔒 via latest InfoSec titles
Subscribe to DISC InfoSec blog by Email
Oct 02 2020
Suitable for senior management and the C-suite, general or legal counsel, IT executives, IT organizations, and IT and security students, this pocket guide will give you a solid introduction to the CMMC and its requirements.
A clear, concise primer on the CMMC (Cybersecurity Maturity Model Certification), this pocket guide:
Oct 02 2020
Christopher Wright is one of IT Governance Publishing’s most prolific writers, having released five books with us over the past six years.
His work covers many different topics, including advice on organizational cyber security, project management and risk management auditing.
In How Cyber Security Can Protect Your Business – A guide for all stakeholders, Wright provides an effective and efficient framework to help organizations manage cyber governance, risk and compliance.
How Cyber Security Can Protect Your BusinessBusinesses must protect themselves and their reputations, while reassuring stakeholders they take cyber security seriously. Wright’s pocket guide:
Receive 15% off all of Christopher Wright’s books throughout October by entering the voucher code WRIGHT15 at the checkout. |
![]()
|
Oct 01 2020
Take a look at the top data breaches and cyber attacks in September, as well as our full list of 102 incidents.
Sep 29 2020
The newly published Building Security in Maturity Model provides the software security basics organizations should cover to keep up with their peers.
As application security methodology and best practices have evolved over more than a decade, the Building Security in Maturity Model (BSIMM) has been there each year to track how organizations are making progress. BSIMM11, released last week by Synopsys, is based on the software security practices in place at 130 different firms across numerous industries, including financial services, software, cloud, and healthcare.
The practices were measured by the model’s proprietary yardstick, which lumps 121 different software security metrics into four major domains: governance, intelligence, secure software development lifecycle (SSDL) touchpoints, and deployment. Each of these domains are further broken down into three practice categories containing numerous activities that slide from simple to very mature.
Similar to previous reports, BSIMM11 shows that most organizations are at the very least hitting the basics — including activities like performing external penetration testing and instituting basic software security training across development organizations. The following are the most common activities cited for each practice category, providing an excellent yardstick for the bare minimum that organizations should be doing to keep up with their peers.
Source: 12 Bare-Minimum Benchmarks for AppSec Initiatives
DISC InfoSec 🔒 securing the business 🔒 via latest InfoSec titles
Subscribe to DISC InfoSec blog by Email
👉 Download a Virtual CISO (#vCISO) and Security Advisory Fact Sheet & Cybersecurity Cheat Sheet
Download a Security Risk Assessment Steps paper!
Sep 28 2020
The mass transition to working from home clearly shows the best technologies for a secure and convenient remote environment.
Users receive the maximum security benefits by connecting to virtual desktops from thin clients.
A thin client is a terminal-mode device. It often doesn’t even have any internal storage, being just a box that connects to a server and lets users connect a monitor and peripheral devices (configuration may vary depending on the specific model). The thin client does not process or store any work data.
Of course, a thin client requires a good communications channel. In recent years, however, that’s not much of a hurdle.
Communication between a thin client and a server is usually conducted over an encrypted protocol, solving the problem of the unreliable network environment.
Source: Thin clients from a security perspective
2020 Security Playbook
1) Data discovery
2) Compartmented Data Access
3) Move to thin client
4) Increase focus on AAA
DISC InfoSec 🔒 securing the business 🔒 via latest InfoSec titles
Subscribe to DISC InfoSec blog by Email
👉 Download a Virtual CISO (#vCISO) and Security Advisory Fact Sheet & Cybersecurity Cheat Sheet
Download a Security Risk Assessment Steps paper!