Posts

Schneier - On the Security of Password Managers

There's new research on the security of password managers, speficially 1Password, Dashlane, KeePass, and Lastpass. This work specifically looks at password leakage on the host computer. That is, does the password manager accidentally leave plaintext copies of password lying around memory? All password managers we examined sufficiently secured user secrets while in a 'not running' state. That is, if a password database were to be extracted from disk and if a strong master password was used, then brute forcing of a password manager would be computationally prohibitive. Each password manager also attempted to scrub secrets from memory. But residual buffers remained that contained secrets, most likely due to memory leaks, lost memory references, or complex GUI frameworks which do not expose internal memory management mechanisms to sanitize secrets. This was most evident in 1Password7 where secrets, including the master password and its associated secret key, were present i...

KnowBe4 - Cyber Espionage Warning: The Most Advanced Hacking Groups Are Getting More Ambitious

Image
Once attackers might have needed the latest zero-days to gain access to corporate networks, but now it's spear- phishing emails laced with malicious content that are most likely to provide attackers with the initial entry they need. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/cyber-espionage-warning-the-most-advanced-hacking-groups-are-getting-more-ambitious

KnowBe4 - The NoRelationship Attack Bypasses Office 365 Email Attachment Security

Image
Attackers are bypassing Office 365 email attachment security by editing the relationship files that are included with Office documents, according to Yoav Nathaniel at Avanan. A relationship file is an XML file that contains a list of essential components in the document, such as font tables, settings, and external links. A number of popular email filters, including Microsoft’s Exchange Online Protection (EOP), only scan the links contained in the relationship file, rather than scanning the entire document. Attackers can remove the links from a document’s relationship file, but they will still be active in the actual document. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/the-norelationship-attack-bypasses-office-365-email-attachment-security

Krebs - Payroll Provider Gives Extortionists a Payday

Image
Payroll software provider Apex Human Capital Management suffered a ransomware attack this week that severed payroll management services for hundreds of the company’s customers for nearly three days. Faced with the threat of an extended outage, Apex chose to pay the ransom demand and begin the process of restoring service to customers. Roswell, Ga. based Apex HCM is a cloud-based payroll software company that serves some 350 payroll service bureaus that in turn provide payroll services to small and mid-sized businesses. At 4 a.m. on Tuesday, Feb. 19, Apex was alerted that its systems had been infected with a destructive strain of ransomware that encrypts computer files and demands payment for a digital key needed to unscramble the data. The company quickly took all of its systems offline, and began notifying customers that it was trying to remediate a security threat. Over a series of bi-hourly updates, Apex kept estimating that it expected to restore service in a few hours, only t...

Schneier - Friday Squid Blogging: A Tracking Device for Squid

Really : After years of "making do" with the available technology for his squid studies, Mooney created a versatile tag that allows him to research squid behavior . With the help of Kakani Katija, an engineer adapting the tag for jellyfish at California's Monterey Bay Aquarium Research Institute (MBARI), Mooney's team is creating a replicable system flexible enough to work across a range of soft-bodied marine animals. As Mooney and Katija refine the tags, they plan to produce an adaptable, open-source package that scientists researching other marine invertebrates can also use. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered. Read my blog posting guidelines here . from Schneier on Security https://www.schneier.com/blog/archives/2019/02/friday_squid_bl_664.html

SANS - Issue #15 - Volume XXI - SANS Newsbites - February 22nd, 2019

from SANS Institute | Newsletters - Newsbites - RSS https://www.sans.org/newsletters/newsbites/xxi/15

KnowBe4 - Phishing campaign attempts to spread a new brand of snooping malware

Image
Danny Palmer at ZDNet had the scoop: "A cyber espionage campaign is targeting national security think tanks and academic institutions in the US in what's believed to be an intelligence gathering operation by a hacking group working out of North Korea. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/phishing-campaign-attempts-to-spread-a-new-brand-of-snooping-malware