<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecBits &#187; data breach</title>
	<atom:link href="https://www.infosecbits.com/category/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.infosecbits.com</link>
	<description>Information Security Bits by Carlos Villalba &#38; Friends</description>
	<lastBuildDate>Mon, 16 Feb 2015 23:38:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.1.41</generator>
	<item>
		<title>Department of Justice  Cybersecurity Unit will be created</title>
		<link>https://www.infosecbits.com/department-of-justice-cybersecurity-unit-will-be-created/</link>
		<comments>https://www.infosecbits.com/department-of-justice-cybersecurity-unit-will-be-created/#comments</comments>
		<pubDate>Mon, 08 Dec 2014 15:22:03 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=30</guid>
		<description><![CDATA[The US Department of justice is creating a dedicated Cybersecurity Unit within the Criminal Division. Assistant Attorney General Leslie R. Caldwell explained The Cybersecurity Unit will work hand-in-hand with law enforcement and will also work with private sector partners and&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/department-of-justice-cybersecurity-unit-will-be-created/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>The US Department of justice is creating a dedicated Cybersecurity Unit within the Criminal Division.<br />
Assistant Attorney General Leslie R. Caldwell explained The Cybersecurity Unit will work hand-in-hand with law enforcement and will also work with private sector partners and Congress.<br />
If implemented properly this could be a great effort that could benefit all sectors against cyber threats.</p>
<p>I would be very interested to find out more information about this and how they will engage the community.</p>
<p>http://www.justice.gov/opa/speech/assistant-attorney-general-leslie-r-caldwell-speaks-cybercrime-2020-symposium</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/department-of-justice-cybersecurity-unit-will-be-created/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wiper threat update</title>
		<link>https://www.infosecbits.com/wiper-threat-update/</link>
		<comments>https://www.infosecbits.com/wiper-threat-update/#comments</comments>
		<pubDate>Wed, 03 Dec 2014 06:16:32 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=27</guid>
		<description><![CDATA[Today the FBI released FBI Liaison Alert System #A-000044-mw. In the release they describe the workings of the malware. It attacks the MBR and all data files. After infection the infected systems to connect to one of three random, one&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/wiper-threat-update/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>Today the FBI released FBI Liaison Alert System #A-000044-mw.</p>
<p>In the release they describe the workings of the malware. It attacks the MBR and all data files. After infection the infected systems to connect to one of three random, one of these three IP addresses (88.53.215.64, 217.96.33.164, 203.131.222.102) via either port 8080 or 8000.<br />
Sony Pictures Entertainment is dealing with the aftermath of a massive infection that must be keeping them very busy and many people out of work.</p>
<p>Snort can be configured to detect the traffic. The FBI also release the following siganture:</p>
<pre>Alert tcp any any – &gt; [88.53.215.64, 217.96.33.164, 203.131.222.102] [8080, 8000] (msg: “wiper_callout”;
dsize:42; content: “|ff ff ff ff|”; offset: 26; depth: 4; sid: 314;</pre>
<p>It&#8217;s time to check your log files and check if those IPs are listed as destination IPs in any of your traffic or log data.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/wiper-threat-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Black Friday Hackers &#8211; Not All Threats are Equal</title>
		<link>https://www.infosecbits.com/black-friday-hackers-not-all-threats-are-equal/</link>
		<comments>https://www.infosecbits.com/black-friday-hackers-not-all-threats-are-equal/#comments</comments>
		<pubDate>Wed, 26 Nov 2014 20:55:31 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[compliance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=22</guid>
		<description><![CDATA[With the biggest sales event of the year coming to US retailers this week, there is also increased concern about the possibility of additional data breach incidents. This week and next week, many organizations are consumed with keeping the lights&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/black-friday-hackers-not-all-threats-are-equal/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>With the biggest sales event of the year coming to US retailers this week, there is also increased concern about the possibility of additional data breach incidents.</p>
<p>This week and next week, many organizations are consumed with keeping the lights on and making sure e-commerce platforms keep up with the anticipated spike in demand due to the big sale event. We are days away from Black Friday and many are crying foul before the whistle blows to start the game.</p>
<p>Justified or unjustified fear? I can tell you with certainty, coupled with many years of experience, that some of that fear is justified. American holidays such as Thanksgiving, Christmas and the Super Bowl are days when security operation center monitors go up, up, up in events volume.</p>
<p>So, make no mistake, Black Friday and Cyber Monday will not only attract shoppers, they will also attract hackers.</p>
<p>Unfortunately, most organizations do not have the resources to keep a fully staffed 24/7 network event monitoring effort, especially around non-working days such as weekends and holidays. Is it really necessary? My answer will bother some, but yes, it is necessary.</p>
<p>Why?</p>
<p>Well, is your network important to you? Are those assets important to you? Will your brand be affected by unauthorized access? Are there legal ramifications in the event of a data breach? The answer to all of these is most likely yes. However, the most important question is will a data breach negatively affect your clients? This is a yes/no question. If the answer is yes then, unequivocally, your organization must find ways to monitor your networks twenty-four hours a day seven days a week.</p>
<p><strong>In that effort, I&#8217;d like to offer some insights:</strong></p>
<ul>
<li>Monitor both external and internal events.</li>
<li>Aggregate and analyze your logs to establish a baseline.</li>
<li>If outsourcing is not possible, combine automatic alerting with on-call designations, or staff a 24/7 security operations center. A minimum of nine analysts with one manager should suffice. In terms of technologies, the options are plenty and varied.</li>
<li>Reduce unnecessary noise without ignoring relevant events.</li>
<li>Address the alerts generated, otherwise members of the organization will soon treat these alerts the same way they treat spam email.</li>
<li>Define your incident response and apply the priority that the risk deserves. Not all threats are equal.</li>
<li>Do not overlook access control related events such as failed logon attempts, even if it painful due to the volume.</li>
</ul>
<p>In terms of commercial tools, there are many out there and some could be very pricey. In terms of open source tools, there are also plenty of options; icinga, snort, logstash, etc.</p>
<p>Is it possible to combine open source tools with commercial tools? Absolutely. It requires a solid architecture design and strategic planning, but very possible.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/black-friday-hackers-not-all-threats-are-equal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Breaches since July</title>
		<link>https://www.infosecbits.com/data-breaches-since-july/</link>
		<comments>https://www.infosecbits.com/data-breaches-since-july/#comments</comments>
		<pubDate>Thu, 20 Nov 2014 04:45:20 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=20</guid>
		<description><![CDATA[Helpnet security just released an article where they claim that since July there has been 320 breaches. Seems like an exorbitant number but is probably falling short. Although we read on a daily basis about these events we also know&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/data-breaches-since-july/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.net-security.org/secworld.php?id=17659" target="_blank">Helpnet</a> security just released an article where they claim that since July there has been 320 breaches. Seems like an exorbitant number but is probably falling short.</p>
<p>Although we read on a daily basis about these events we also know that not all data breach incidents are reported or who knows if even discovered.</p>
<p>More comprehensive stats are available are at DatalossDb where they are reporting that so far in 2014 there has been 831 incidents. The same site reported 1472 incidents for 2013. When we compare 2014 against 2013 it seem that 2014 has been better but it feels otherwise.</p>
<p>My take on this is that this year the press has been paying more attention to these type of news and the public is now more concerned about their credit cards.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/data-breaches-since-july/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.S. Government Hacked, again?</title>
		<link>https://www.infosecbits.com/u-s-government-hacked-again/</link>
		<comments>https://www.infosecbits.com/u-s-government-hacked-again/#comments</comments>
		<pubDate>Thu, 20 Nov 2014 04:15:47 +0000</pubDate>
		<dc:creator><![CDATA[cavallal]]></dc:creator>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.infosecbits.com/?p=18</guid>
		<description><![CDATA[The White House, NOAA, USPS (Postal Service), and now the State Department. Wondering what the level of forensics, if the incident response teams were in place to handle the incidents and aftermath. Is it based on NIST 800-61? Who could&#8230;<p class="more-link-p"><a class="more-link" href="https://www.infosecbits.com/u-s-government-hacked-again/">Read more &#8594;</a></p>]]></description>
				<content:encoded><![CDATA[<p>The White House, NOAA, USPS (Postal Service), and now the State Department.</p>
<p>Wondering what the level of forensics, if the incident response teams were in place to handle the incidents and aftermath. Is it based on NIST 800-61?</p>
<p>Who could it been? Russia, China, Venezuela, Brazil, a teenager from a basement?</p>
<p>On this day and age as soon as an organization is breach we get to read about the dirty details, the how, and more especially the who. How come we are not hearing these this time around?</p>
<p>The security community deserves an explanation and more importantly tax payers have the right to know.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>https://www.infosecbits.com/u-s-government-hacked-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
