FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Monday, October 28, 2019

Microsoft previews Azure Sphere with Cloud Security controls

Microsoft has announced the release date of its Azure Sphere which happens to be February 9th of 2020. The Linux based chip which was earlier named ‘Project Sopris’ by the tech giant was previewed to the world yesterday at the IoT Solutions World Congress.

 

Microsoft Azure Sphere is a Linux based silicon wafer that can be used to power internet-connected devices. Operating with a MediaTek MT3620 processor and an Azure Sphere OS entailed with Linux Kernel, the architecture is ambled to provide authentication, threat response and info related to on-device resources and application failure.

 

In the coming days, Azure Sphere will also be enriched with artificial intelligence, graphics, and richer UI experiences.

 

As of now, those who got an opportunity to have hands-on the chip are testing it by integrating it into consumer appliances meant for retail and manufacturing equipment.

 

Even the news is out that Azure Sphere is being used in mission-critical appliances such as “Guardian Modules” for securely connecting the devices to the internet.

 

At the same conference, Microsoft took an opportunity to introduce Azure RTOS which will be offered as a complimentary to Sphere.

 

In the coming days, the American software giant is also thinking to revamp its Azure IoT Hub with several features and that includes Azure Time Insights, a multi-layered flexible cold storage and rich analytical skills with improved scale and performance.

 

Note- MediaTek MT3620 chips were developed to support high-level security in modern connected appliances and are being used in smart homes, commercial, industrial and many other domains.

The post Microsoft previews Azure Sphere with Cloud Security controls appeared first on Cybersecurity Insiders.


October 29, 2019 at 10:17AM

Over 2K of Media, Government and TV station websites hacked in Georgia

More than 2,000 websites are reported to be hacked in Georgia in a massive cyberattack launched late yesterday. And security analysts suggest that it was a sophisticated attack made on web hosting provider Pro-Service which led to the disruption.

Highly placed sources say that the shutdown websites include those related to government agencies, Media and TV stations and a few from local banks and legal courts. TV Channel Pirveli was also partially affected by the cyber incident.

As all those websites were being hosted on a single provider, hackers managed to target the servers of the service provider to disrupt the website services of many- the toll could reach the number of 15,000.

In a media statement issued early Tuesday, Pro-Service provider took the blame wholly and confessed that a hacker/s were able to infiltrate into its network through a configuration flaw. More details will be revealed on an official note as the probe unfolds.

Cybersecurity Insiders has learned that the first response team of the Pro- Service provider was able to recover more than half of the impacted websites by 8 PM on Monday the day after the Halloween party.

People in Georgia who were busy with their Halloween parties panicked as the cyberattack was of a “Defacement” Genre.

The interesting point in this attack is that almost 70% of websites faced defacement and the homepage was replaced with a picture of former Georgian President Mikheil Saakashvili. So, the attack could have been launched either by a protester or a fan of Saakashvili, who is now a Ukrainian citizen due to developments.

The post Over 2K of Media, Government and TV station websites hacked in Georgia appeared first on Cybersecurity Insiders.


October 29, 2019 at 10:14AM

Cybersecurity Ethics: How Far Is Too Far?

Session photoWhen doing their work, cybersecurity professionals often come across situations that put their skills to the test. And sometimes those tests have far less to do with technology or business than with questions of ethics.

When cyber professionals discover vulnerabilities while performing penetration tests or some other security-related work, is it OK to disclose those vulnerabilities publicly? What happens if system owners are made aware of issues but decide to ignore them? And at which point, while testing systems containing private information, do cyber professionals reach a line they should not cross?

These questions were part of a lively panel discussion today at the (ISC)2 Security Congress 2019, taking place in Orlando this week. The session, “Ethics Dilemmas Information Security Professionals Face,” was moderated by Biljana Cerin, CISSP, CEO of Ostendo Consulting and Chair of the (ISC)2  Ethics Commission. Joining her were committee members Wim Remes, CISSP, Founder and Principal Consultant of NRJ Security; William H. Murray, CISSP, retired security professional; and William Campbell, President of Predictable Solutions.

Legal Coverage

Much of the discussion centered on the ethical boundaries of penetration testing. There have been cases in which security researchers were arrested for doing their work. To avoid such a fate, Remes stressed the importance of clarity upfront.

“Make sure there is a clear contract,” Remes said. “The contract is where everything starts and and stops.”

Sometimes, during penetration tests, researchers may find vulnerabilities in third-party systems, which raises questions on how to proceed. If the client, who is paying the security consultant, decides not to notify the third party, it can create an ethical dilemma for the consultant.

In such situations, it may be tempting to act unilaterally. But Murray strongly advised against doing so, pointing out that is how security professionals end up in trouble. It is always best to seek the counsel of others, including client’s superiors and professional peers to make the best possible informed decision, he argued.

“Consulting with peers as a security professional is something you should definitely consider,” Remes added. “I don’t think I’ve ever made good decisions in isolation.”

Campbell noted that one of the challenges cyber professionals face is that they function as advisors. Security professionals can make recommendations and spell out the consequences of pursuing one path or another, but it is up to managers or clients to make decisions.

Whatever the outcome of a penetration test or some other cybersecurity-focused pursuit, Murray advised documenting the work and decisions made. If management, in weighing cyber risks, decides to ignore the cybersecurity professional’s recommendations, ask them to sign a statement to that effect and file it with other relevant documentation.

Communicating Risk

In getting business leaders to make sound risk management decisions, Campbell stressed the importance of communicating to them in ways they understand. Cybersecurity professionals have often been guilty of being too technical and not understanding what makes executives tick.

Company leaders typically have sales backgrounds, where maximizing revenue is the priority, or come from finance, where costs take precedence. It is important to understand that and communicate in that context when talking about security investments, he said.

Building on Campbell’s point, Murray said: “General managers are not good at making expressions of risk tolerance. That’s not what they do, so we have to express the risk tolerance in such a way that general management says, ‘Oh yea, that’s what I intend.’”

Remes put it in even simpler terms: “In my opinion, if you are not expressing risk in financial terms, then you are not talking about risk at all.”

But what should a CISO or other member of the cybersecurity team do when their advice falls on deaf ears? When nothing else works, the panelists agreed that you should walk away. “If management is not doing the right things, it’s your obligation to forgo that paycheck and leave,” Remes said.

The post Cybersecurity Ethics: How Far Is Too Far? appeared first on Cybersecurity Insiders.


October 29, 2019 at 09:08AM

Security Congress Kickoff: Creating a Safe World

Squared is thereThe spotlight was on safety at the kickoff this morning of (ISC)² Security Congress 2019, taking place this week in Orlando. First, (ISC)² CEO David Shearer talked about the role that association members have in protecting society through their cybersecurity work.

Then, Capt. Chesley Burnett “Sully” Sullenberger, the pilot of flight 1549, which landed on the Hudson River in January 2009, related the events of that day and how he and his co-pilot, Jeff Skiles, safely landed their U.S. Airways Airbus with everyone aboard surviving the event.

Shearer spent much of his kickoff address on the importance of abstracting what cybersecurity professionals do from the very users they are protecting. “Our customers’ users simply want to be able to do their jobs and live their lives and passions unencumbered by cybersecurity,” he told the gathered crowd of attendees. This year’s Security Congress has attracted 2,500 professionals to the Walt Disney Dolphin Resort and features more than 250 speakers.

Shearer’s point was that users shouldn’t have to think or worry about cybersecurity. Cybersecurity professionals need to be able to do their work without interrupting users; otherwise, users tend to find ways to circumvent security, which produces the exact opposite effect of what cyber professionals are trying to accomplish.

Drawing parallels between what cyber professionals do and how Walt Disney runs its theme parks and shows, he noted that a lot of behind-the-scenes work has to take place for the magic to happen. When people visit the parks and see the shows, they are not thinking about what goes on behind the curtain, but what they are experiencing. Such is the work of cybersecurity professionals – to toil behind the scenes for the safety of users, their systems and their organizations.

Quoting the rock band Rush, who in turn was quoting Shakespeare, Shearer said: “All the world’s indeed a stage / And we are merely players / Performers and portrayers / Each another’s audience / Outside the gilded cage.’’

Drawing another parallel with the work of cyber pros, Shearer said: “As cybersecurity pros, our goal isn’t the limelight but all the world is indeed our stage.”

Always be Learning

After his address, Shearer ceded the stage to the “Miracle on the Hudson” hero, Sullenberger, who kept the audience engrossed as he related the events of Jan. 15, 2019, when he and Skiles had to ditch on the Hudson, saving all 150 passengers and crew.

While no one ever really prepares for an event like that, Sullenberger says, he attributed his ability to communicate with his co-pilot and make the right decisions under such stressful circumstances to the training and discipline he has received through a lifetime of learning. That training and discipline came not only from the values his parents passed on to him, Sullenberger said, but also from his experience in the Air Force Academy and his work as a fighter pilot and commercial airline captain.

He challenged attendees to challenge themselves: “Never stop investing in yourselves. Never stop learning.” As the pace of change accelerates, he said, “most of us cannot get through a lifetime with only one set of skills.” He urged attendees to reinvent themselves and figure out how to innovate.

Sullenberger also talked about the importance of understanding the reality around your in order to make the best possible decisions. “As citizens, we have an obligation to be not just literate but scientifically literate. When we make important decisions, we must make them based facts, not fears and certainly not untruths.”

The post Security Congress Kickoff: Creating a Safe World appeared first on Cybersecurity Insiders.


October 28, 2019 at 09:08PM

UK offers a £20M worth Cyberthreat contract to CGI

Canadian Global Information is shortly known as CGI has bagged a government contract worth £20M to develop a Cyber Threat analysis system for the UK’s Ministry of Defense. A white paper released by the government of Britain recently has confirmed the same and added that the service will be utilizing a combination of various data sources to support the decision-making skills for authorities in the field of Cyber Defense.

 

Readers of Cybersecurity Insiders have to notify a fact that the same company won a £5.6 million contract two years back to building a cyber situational awareness fusion architecture for Britain.

 

The resource page released by the contract finder of the UK says that the CGI will from now act as a technical authority on the MODs Defensive Cyber Capability.

 

“It’s becoming crucial to increase the defense budget to stay ahead of our adversaries when it comes to improving UK’s defensive measures against cyberattacks said Michael Fallon, the Defense Secretary of the UK.

 

He added that his government is all set to invest in protecting the digital infrastructure against cyber threats- all as a part of the year 2016 initiative. 

 

Note- CGI has a reputation in working for more than 40 years with MOD and the company is excited about bagging another contract. Steve Smart the Senior Vice President of CGI expressed his happiness in building a strong relationship with MoD and hopes to live up to the expectations in framing out the Cyber Threat Analysis System.

 

The post UK offers a £20M worth Cyberthreat contract to CGI appeared first on Cybersecurity Insiders.


October 28, 2019 at 08:49PM

Sunday, October 27, 2019

UK suspects China is conducting espionage with few among 100,000 Chinese University students

MI5 and GCHQ have warned universities and educational institutes operating across their region that the Chinese government could be conducting espionage on its research and computer systems through hidden spies among the 100,000 Chinese students who are studying on the campus. The agency suspects that the investment made by the Beijing in the research work of UK Universities was multi-purpose as it could be using students as espionage agents to transmit data related to research to the Xi Jinping government.

It has to be notified over here that Chinese students who are pursuing post-graduate courses have to pay a fee of £50k as yearly fees. And half of the fees are reimbursed to them as a scholarship by the Chinese government.

Britain’s Intelligence sources suspect that the students pay-back financial help by passing secrets related to the UK’s government projects to the Chinese government.

It is estimated that in the past 10 years, over 500 Chinese Military Scientists have purposed degrees from Britain’s top Universities in the fields related to supercomputers, jet aircraft, missiles and thin film which is used to disguise water tanks powered by solar energy.

As per an article in Times, the Center for the Protection of National Infrastructure has warned Universities in the UK to keep a tab of students pursuing studies from hostile nations as they could be used by adversaries to steal personal data, research data, intellectual property related to military, commercial and authoritarian interests.

The post UK suspects China is conducting espionage with few among 100,000 Chinese University students appeared first on Cybersecurity Insiders.


October 28, 2019 at 10:14AM

Adobe Cloud Storage vulnerability leaks 7.5 Million User Account Information

American Computer Software provider Adobe witnessed an embarrassing Halloween weekend yesterday when a security researcher named Bob Diachenko, in association with Cybersecurity firm Comparitech discovered a vulnerability in its database which exposed information of more than 7.5 million users of the company’s popular Creative Cloud Subscription Service.

 

As the information was accessible to anyone as the access remained unprotected with a password, there is speculation that hackers could have accessed the information database.

 

However, the researcher has confirmed that the users’ passwords and payment information such as credit card detailed weren’t exposed by the vulnerability as they could have been stored on another server.

 

The exposed 7.5 million Adobe Creative Cloud Users information includes email addresses, account creation date, the adobe products being used by the users, subscription status, whether the user in any way connected to adobe, Member IDs, country, time since their last login and payment success status.

 

Although the accessible information wasn’t critical, security researchers from Comparitech argue that such personal details could expose the victims to phishing attacks shortly- which is true!

 

As per the details available to our Cybersecurity Insiders, on October 19th this year, the researcher alerted the California based software giant about the vulnerability. And Adobe took note of the situation and immediately secured the access to the database with various means. But as the database exposure could be prolonging for one week, chances of the information getting exposed to nefarious actors are super- high.

 

Note 1- In the year 2013, Adobe Company faced a data breach when hackers succeeded in accessing information including payment card details of nearly 38 million Adobe users- termed as the largest breach in the history of the cloud-based software provider.

 

Note 2- Adobe Creative Cloud happens to be a central repository where subscribers have access to a range of software useful to edit videos, graphical content related designs, web development, and photography. Earlier, the Creative Cloud was hosted on Amazon Web Services (AWS), but now it is being hosted on Microsoft Azure since 2017.

The post Adobe Cloud Storage vulnerability leaks 7.5 Million User Account Information appeared first on Cybersecurity Insiders.


October 28, 2019 at 10:12AM