The US Department of Defense Cyber Strategy

July 16, 2011

Remarks on the Department of Defense Cyber Strategy As Delivered by Deputy Secretary of Defense William J. Lynn, III, National Defense University, Washington, D.C., Thursday, July 14, 2011
Link to the speech
Link to the Strategy document

Cisco Updates IronPort Security to Thwart Spear Phishing, Targeted Attacks

July 14, 2011

Whenever the user opens an e-mail message that fits the filter parameters, the IronPort system rewrites the malicious URLs embedded in those messages to go through Cisco’s ScanSafe Cloud Web Security system. If the user still goes ahead and clicks on the rewritten link, the Web content is passed through additional Cisco filters in the cloud security service which scans and identifies any potential malware that may be on the site and blocks them from downloading when necessary.
Link


Energy lab still offline in wake of July 1 attack

July 12, 2011

Ten days after being targeted by what a spokesman called a “highly sophisticated cyber attack,” the Energy Department’s Pacific Northwest National Laboratory in Richland, Wash., remains cut off from most of its Internet access as staff works to find and correct problems.

Internal e-mail and intranet services and some external services were restored last week, but the lab’s Web site at www.pnnl.gov remained down July 11 and the lab still has no Internet connection.

Link


Zeus Trojan for Google Android

July 12, 2011

The authors of the Zeus Trojan, probably the most successful Crimeware bundle on the planet, have added a new variant, this time for Google’s Android OS, and part of the Zitmo (Zeus in the Mobile) line of products rolling out from the Zeus group since last year.

This only emphasizes the trend of serious malware coming to mobile platforms.

Link


Cyber-BCP

July 10, 2011

בועז דולב, ממייסדי חברת סייברוויז’ן הרצה בכנס של אנשים ומחשבים על חזרה לכשירות עסקית בהתמודדות עם מתקפת סייבר.
מצורף לינק לכתבה על ההרצאה.


U.S. Suspects Contaminated Foreign-Made Components Threaten Cyber Security

July 10, 2011

Some foreign-made computer components are being manufactured to make it easier to launch cyber attacks on U.S. companies and consumers, a security official at the the Department of Homeland Security said.

“I am aware of instances where that has happened,” said Greg Schaffer, who is the Acting Deputy Undersecretary National Protection and Programs Director at the DHS.

Link


Apple scrambles to fix iPhone security flaw

July 8, 2011

Apple is working to remedy a security hole in its iOS mobile operating system that leaves iPhones and iPads vulnerable to cyber attack.
(This is a result from “Jailbreakme.com” release)

The German Federal Office for Information Security warned Wednesday that the flaw–most vulnerable when consumers are viewing PDF files–gives cyber criminals an opening to infect iOS devices with malicious software granting them administrative rights to the device. From there, attackers can access security passwords, stored text messages and emails, online banking data and related personal information. The agency added that the security flaw is present across multiple iterations of the iOS platform.

Link


Video from the forum on cyber deterrence hosted by the Potomac Institute for Policy Studies in Washington

July 8, 2011

“If we don’t act boldly, something really bad is going to happen,” said retired Air Force General Michael Hayden, a former director of central intelligence and ex-head of the Pentagon’s National Security Agency. “Then we’ll over-react.”

General Hayden spoke from a forum on cyber deterrence hosted by the Potomac Institute for Policy Studies in Washington. Hayden didn’t give any specifics regarding how the U.S. might “over-react” to a cyber attack. Michael Tiffany, Chief Architect at Recursion Ventures, also spoke. He described how he demonstrated before a group of U.S. intelligence experts how hackers can bring 90 percent of a major U.S. city’s vital systems down without anyone noticing.

Link to the videocast of the forum on youtube


North Korea has been conducting “drills” for cyberwar against south Korea

July 7, 2011

North Korea has been conducting “drills” for cyberwar against its southern neighbor using simple, but very effective denial-of-service attacks, according to security experts.

A team from McAfee looked into the attacks on South Korean internet networks in July 2009 and March this year, and concluded they were probably efforts by North Korea to test cyberwar weapons.

Link to the research pdf


US Pacific Northwest Laboratories still trying to get back to normal after cyber attack

July 7, 2011

Days after a highly sophisticated cyber attack, the employees at Pacific Northwest Laboratories are finally able to e-mail with the outside world.  Their website and Internet access is still down.

Link