Google Search

Showing posts with label Nasdaq. Show all posts
Showing posts with label Nasdaq. Show all posts

Thursday, October 27, 2011

Nasdaq hackers spied on company directors, report says

Nasdaq hackers spied on company directors, report says | The Digital Home - CNET News CNET News Home Reviews Cell Phones Camcorders Digital Cameras Laptops TVs Car Tech Forums Appliances Cell Phone Accessories Components Desktops Games and Gear GPS Hard Drives & Burners Headphones Home Audio Home Video Internet Access Monitors MP3 Players Networking and Wi-Fi Peripherals Printers Software Tablets Web Hosting You are here: News Latest News Webware Crave Business Tech Green Tech Wireless Security Blogs Video Photos Media Cutting Edge Apple Politics & Law Gaming & Culture Microsoft Health Tech RSS Download Windows Software Mac Software Mobile Apps Web Apps CNET TV How To Phone Tablet Computer Web Home Theater Log In | Join Log In Join CNET Sign in with My profile Log out
CNET News The Digital Home Nasdaq hackers spied on company directors, report says Don Reisinger by Don Reisinger October 21, 2011 11:20 AM PDT

The hackers who attacked the Nasdaq last year were surreptitiously spying on public company board of directors, a new report claims.

According to Reuters, citing sources with knowledge of the ongoing investigation into the Nasdaq breach, the hackers were able to access Nasdaq's Web-based software program, Directors Desk, to spy on company executives. According to Reuters, the software is used to facilitate communication and document sharing between Nasdaq and public companies.

Hackers reportedly breached Nasdaq defenses last year, but news of the breach wasn't made public until earlier this year. According to a report in February, it was believed that the hackers were simply "looking around" Nasdaq's servers, but were not able to access anything critical.

However, just a month later, sources told Bloomberg that the attack appeared to be more widespread than initially believed and the National Security Agency was involved in the investigation, prompting some to wonder if the attacks posed a national security risk.

Related stories:
? Report: NSA joins Nasdaq hack probe
? Report: Hackers penetrated Nasdaq computers
? Report: Hackers penetrated Nasdaq computers

So far, neither Nasdaq nor the NSA have commented on who might have been behind the attacks, but initial evidence seemed to point to the attacks originating in Russia. Unnamed investigators speaking to The Wall Street Journal at the time said that even though the attacks might have originated from Russia, the hackers might have been routing their attack through Russian servers to disguise their true location.

Reuters' sources didn't divulge which companies' directors were targeted in the Nasdaq attack, but they did say that "scores" of executives were spied on by the hackers until the malware that facilitated the breach was removed.

But even as Nasdaq tries to learn more about past breaches, the company must still worry about the future. In an interview with Reuters in July, Nasdaq CEO Robert Greifeld told the news service that "as we sit here, there are people trying to slam into our system every day," adding that his organization spends close to $1 billion each year on security alone.

Nasdaq did not immediately respond to CNET's request for comment.

Don Reisinger Don Reisinger is a technology columnist who has written about everything from HDTVs to computers to Flowbee Haircut Systems. Don is a member of the CNET Blog Network, posting at The Digital Home. He is not an employee of CNET. Disclosure.

Topics: Digital Home Tags: Nasdaq, breach, security, hackers, privacy

EXCLUSIVE - Nasdaq hackers spied on directors - sources

BOSTON (Reuters) - Hackers who infiltrated the Nasdaq's computer systems installed malicious software on the exchange's computers that allowed them to spy on scores of directors of publicly held companies, according to two people familiar with an investigation into the matter.

The emerging details further highlight the increasing threat hackers pose to corporations with a rash of highly sophisticated attacks on high-profile companies and financial institutions -- from Google Inc to Citigroup Inc and the International Monetary Fund.

Nasdaq OMX Group disclosed in February that its system were hacked last year. That sparked an investigation involving the FBI and National Security Agency that is ongoing.

The attack on Nasdaq is an example of a "blended attack," where hackers infiltrate one target in order to facilitate access to another. In March hackers stole digital security keys from EMC Corp's RSA Security division that they later used to access the networks of defense contractor Lockheed Martin Corp.

Nasdaq's trading platforms were not compromised, the exchange said when it disclosed the attack in February, although an Internet-based software program was attacked.

Nasdaq sells that program, called Directors Desk, to listed and private companies, which use it to let board members get access to and share documents and communicate with executives, among other things.

While the Directors Desk was infected, hackers were able to access confidential documents and communications of the directors who got access to the program, said Tom Kellermann, chief technology officer with security technology firm AirPatrol Corp.

Another person familiar with the investigation confirmed Kellermann's account of the matter, but declined to be identified by name because he is not authorized to discuss the matter.

It is unclear how long the Directors Desk application was infected before the exchange identified the breach, according to Kellermann and the other source.

Investigators have learned that hackers were able to spy on the computer systems of "scores" of directors who logged onto the application at Nasdaq's directorsdesk.com site before the malicious software was removed, potentially gathering sensitive corporate secrets, according to those sources.

"God knows exactly what they have done. The long term impact of such attack is still unknown," Kellermann said.

Kellermann is a well-regarded cyber security expert who has advised the Obama Administration on cyber security policy.

In February, Nasdaq said there was no evidence the hackers accessed or acquired customer information. A spokesman confirmed on Thursday that the investigation continues, but declined to give further details.

Army General Keith Alexander, director of the highly secretive National Security Agency and head of U.S. Cyber Command, told reporters earlier on Thursday that NSA and Nasdaq had reached conclusions about the origin of the attack.

He said the information was classified, but added that many areas were now seeing "advanced persistent threats," the cyber community's code phrase for attacks by nation states.

He said NSA was working with Nasdaq to help protect its network against further attacks.

"The key is, with attribution, you can show them how to defend against it," he said, after a speech at a security conference in Baltimore. "That's easy to do."

(Reporting by Jim Finkle. Additional reporting by Jonathan Spicer in New York and Andrea Shalal-Esa in Baltimore. Editing by Robert MacMillan and Tim Dobbyn)


View the original article here

Wednesday, October 26, 2011

Exclusive: Nasdaq hackers spied on company boards

(Reuters) - Hackers who infiltrated the Nasdaq's computer systems last year installed malicious software that allowed them to spy on the directors of publicly held companies, according to two people familiar with an investigation into the matter.

The new details showed the cyber attack was more serious than previously thought, as Nasdaq OMX Group had said in February that there was no evidence the hackers accessed customer information.

It was not known what information the hackers might have stolen. The investigation into the attack, involving the FBI and National Security Agency, is ongoing.

"God knows exactly what they have done. The long term impact of such attack is still unknown," said Tom Kellermann, a well-known cyber security expert with years of experience protecting central banks and other high-profile financial institutions from attack.

The case is an example of a "blended attack," where elite hackers infiltrate one target to facilitate access to another. In March hackers stole digital security keys from EMC Corp's RSA Security division that they later used to breach the networks of defense contractor Lockheed Martin Corp.

Nasdaq had previously said that its trading platforms were not compromised by the hackers, but they attacked a Web-based software program called Directors Desk, used by corporate boards to share documents and communicate with executives, among other things.

By infecting Directors Desk, the hackers were able to access confidential documents and the communications of board directors, said Kellermann, chief technology officer at security technology firm AirPatrol Corp.

Investigators have learned that hackers were able to spy on "scores" of directors who logged onto directorsdesk.com before the malicious software was removed, said Kellermann and another person familiar with the investigation who was not authorized to discuss the matter publicly.

It was still unclear how long Nasdaq's system was breached before the attack was discovered last October.

A Nasdaq spokesman confirmed the investigation into the attack continues, but declined to give further details.

NSA HELPS NASDAQ

Executive Assistant FBI Director Shawn Henry said the financial services sector was losing hundreds of millions of dollars to hackers every year, and the attacks were increasingly "destructive" in nature.

"We know adversaries have full unfettered access to certain networks. Once there they have the ability to destroy data," he told Reuters in a phone interview. "We see that as a credible threat to all sectors, but specifically the financial services sector." Henry declined to comment on the Nasdaq attack.

U.S. Army General Keith Alexander, head of the National Security Agency and U.S. Cyber Command, said the NSA was working with Nasdaq to help protect its network against further attacks.

Alexander told security experts at a Baltimore conference that the United States was shoring up its defenses, but still had "tremendous vulnerabilities" to a growing number of increasingly destructive electronic attacks.

"Nation states, non-nation state actors and hacker groups are creating tools that are increasingly more persistent and threatening, and we have to be ready for that," he said.

Amid a spate of high-profile cyber crimes, the Obama administration wants Congress to pass comprehensive cyber-security legislation that would increase the government's ability to thwart the growing threat.

Alexander and other top officials held a classified meeting with lawmakers on Wednesday and Thursday to discuss the issue, according to sources familiar with the meeting.

Nasdaq CEO Robert Greifeld said in July that the exchange is under constant attack, requiring it to spend nearly a billion dollars a year on information security.

"As we sit here, there are people trying to slam into our system every day," Greifeld said in the interview. "So we have to be ever vigilant against an ever-changing foe."

(Reporting by Jim Finkle. Additional reporting by Jonathan Spicer in New York, Andrea Shalal-Esa in Baltimore and Diane Bartz in Washington. Editing by Tim Dobbyn, Tiffany Wu, and Bob Burgdorfer


View the original article here

EXCLUSIVE - Nasdaq hackers spied on company boards - sources

By Jim Finkle

REUTERS - Hackers who infiltrated the Nasdaq's computer systems last year installed malicious software that allowed them to spy on the directors of publicly held companies, according to two people familiar with an investigation into the matter.

The new details showed the cyber attack was more serious than previously thought, as Nasdaq OMX Group had said in February that there was no evidence the hackers accessed customer information.

It was not known what information the hackers might have stolen. The investigation into the attack, involving the FBI and National Security Agency, is ongoing.

"God knows exactly what they have done. The long term impact of such attack is still unknown," said Tom Kellermann, a well-known cyber security expert with years of experience protecting central banks and other high-profile financial institutions from attack.

The case is an example of a "blended attack," where elite hackers infiltrate one target to facilitate access to another. In March hackers stole digital security keys from EMC Corp's RSA Security division that they later used to breach the networks of defence contractor Lockheed Martin Corp.

Nasdaq had previously said that its trading platforms were not compromised by the hackers, but they attacked a Web-based software program called Directors Desk, used by corporate boards to share documents and communicate with executives, among other things.

By infecting Directors Desk, the hackers were able to access confidential documents and the communications of board directors, said Kellermann, chief technology officer at security technology firm AirPatrol Corp.

Investigators have learned that hackers were able to spy on "scores" of directors who logged onto directorsdesk.com before the malicious software was removed, said Kellermann and another person familiar with the investigation who was not authorized to discuss the matter publicly.

It was still unclear how long Nasdaq's system was breached before the attack was discovered last October.

A Nasdaq spokesman confirmed the investigation into the attack continues, but declined to give further details.

NSA HELPS NASDAQ

Executive Assistant FBI Director Shawn Henry said the financial services sector was losing hundreds of millions of dollars to hackers every year, and the attacks were increasingly "destructive" in nature.

"We know adversaries have full unfettered access to certain networks. Once there they have the ability to destroy data," he told Reuters in a phone interview. "We see that as a credible threat to all sectors, but specifically the financial services sector." Henry declined to comment on the Nasdaq attack.

U.S. Army General Keith Alexander, head of the National Security Agency and U.S. Cyber Command, said the NSA was working with Nasdaq to help protect its network against further attacks.

Alexander told security experts at a Baltimore conference that the United States was shoring up its defences, but still had "tremendous vulnerabilities" to a growing number of increasingly destructive electronic attacks.

"Nation states, non-nation state actors and hacker groups are creating tools that are increasingly more persistent and threatening, and we have to be ready for that," he said.

Amid a spate of high-profile cyber crimes, the Obama administration wants Congress to pass comprehensive cyber-security legislation that would increase the government's ability to thwart the growing threat.

Alexander and other top officials held a classified meeting with lawmakers on Wednesday and Thursday to discuss the issue, according to sources familiar with the meeting.

Nasdaq CEO Robert Greifeld said in July that the exchange is under constant attack, requiring it to spend nearly a billion dollars a year on information security.

"As we sit here, there are people trying to slam into our system every day," Greifeld said in the interview. "So we have to be ever vigilant against an ever-changing foe."

(Reporting by Jim Finkle. Additional reporting by Jonathan Spicer in New York, Andrea Shalal-Esa in Baltimore and Diane Bartz in Washington. Editing by Tim Dobbyn, Tiffany Wu, and Bob Burgdorfer)


View the original article here

Exclusive: Nasdaq hackers spied on directors

Published October 20, 2011

| Reuters

Hackers who infiltrated the Nasdaq's computer systems installed malicious software on the exchange's computers that allowed them to spy on scores of directors of publicly held companies, according to two people familiar with an investigation into the matter.

The U.S. exchange operator disclosed in February that it was investigating a breach into its network.

Nasdaq OMX Group identified that its systems were hacked last year, and removed malicious software from its servers in October. That sparked an investigation involving the FBI and National Security Agency that is ongoing.

Trading platforms were not compromised, the exchange said when it disclosed the attack in February, although an Internet-based software program was attacked.

Nasdaq sells that program, called Directors Desk, to listed and private companies, which use it to let board members get access to and share documents and communicate with executives, among other things.

While the Directors Desk was infected, hackers were able to access confidential documents and communications of the directors who got access to the program, said Tom Kellermann, chief technology officer with security technology firm AirPatrol Corp.

Another person familiar with the investigation confirmed Kellermann's account of the matter, but declined to be identified by name because he is not authorized to discuss the matter.

(Reporting by Jim Finkle. Additional reporting by Jonathan Spicer in New York. Editing by Robert MacMillan)


View the original article here

Tuesday, October 25, 2011

Nasdaq Hackers Spied on Company Directors: Report

Hackers who infiltrated the Nasdaq's computer systems installed malicious software on the exchange's computers that allowed them to spy on scores of directors of publicly held companies, according to two people familiar with an investigation into the matter.

NASDAQ MarketSite Tower, Times Square, New York, NYNASDAQ MarketSite Tower, Times Square, New York, NYThe U.S. exchange operator [.NDX  Loading...      ()   ] disclosed in February that it was investigating a breach into its network.

Nasdaq OMX Group identified that its systems were hacked last year, and removed malicious software from its servers in October. That sparked an investigation involving the FBI and National Security Agency that is ongoing.

Trading platforms were not compromised, the exchange said when it disclosed the attack in February, although an Internet-based software program was attacked.

Nasdaq sells that program, called Directors Desk, to listed and private companies, which use it to let board members get access to and share documents and communicate with executives, among other things.

While the Directors Desk was infected, hackers were able to access confidential documents and communications of the directors who got access to the program, said Tom Kellermann, chief technology officer with security technology firm AirPatrol.

Another person familiar with the investigation confirmed Kellermann's account of the matter, but declined to be identified by name because he is not authorized to discuss the matter.

Copyright 2011 Thomson Reuters. Click for restrictions.

View the original article here

Monday, October 24, 2011

Nasdaq Hackers Spied on Company Boards

Hackers who infiltrated the Nasdaq's computer systems last year installed malicious software that allowed them to spy on the directors of publicly held companies, according to two people familiar with an investigation into the matter.

NASDAQ MarketSite Tower, Times Square, New York, NYNASDAQ MarketSite Tower, Times Square, New York, NYThe new details showed the cyber attack was more serious than previously thought, as Nasdaq OMX Group had said in February that there was no evidence the hackers accessed customer information.

It was not known what information the hackers might have stolen. The investigation into the attack, involving the Federal Bureau of Investigation and National Security Agency, is ongoing.

"God knows exactly what they have done. The long term impact of such attack is still unknown," said Tom Kellermann, a well-known cyber security expert with years of experience protecting central banks and other high-profile financial institutions from attack.

The case is an example of a "blended attack," where elite hackers infiltrate one target to facilitate access to another. In March, hackers stole digital security keys from EMC Corp.'s

[EMC  Loading...      ()   ] RSA Security division that they later used to breach the networks of defense contractor Lockheed Martin [LMT  Loading...      ()   ] .

Nasdaq had previously said that its trading platforms were not compromised by the hackers, but they attacked a Web-based software program called Directors Desk, used by corporate boards to share documents and communicate with executives, among other things.

By infecting Directors Desk, the hackers were able to access confidential documents and the communications of board directors, said Kellermann, chief technology officer at security technology firm AirPatrol Corp.

Investigators have learned that hackers were able to spy on "scores" of directors who logged onto the directorsdesk.com website before the malicious software was removed, said Kellermann and another person familiar with the investigation who was not authorized to discuss the matter publicly.

It was still unclear how long Nasdaq's system was breached before the attack was discovered last October.

A Nasdaq spokesman confirmed the investigation into the attack continues, but declined to give further details.

NSA Helps Nasdaq

Executive Assistant FBI Director Shawn Henry said the financial-services sector was losing hundreds of millions of dollars to hackers every year, and the attacks were increasingly "destructive" in nature.

"We know adversaries have full unfettered access to certain networks. Once there they have the ability to destroy data," he told Reuters in a phone interview. "We see that as a credible threat to all sectors, but specifically the financial services sector." Henry declined to comment on the Nasdaq attack.

U.S. Army General Keith Alexander, head of the National Security Agency and U.S. Cyber Command, said the NSA was working with Nasdaq to help protect its network against further attacks.

Alexander told security experts at a Baltimore conference that the U.S. was shoring up its defenses, but still had "tremendous vulnerabilities" to a growing number of increasingly destructive electronic attacks.

"Nation states, non-nation state actors, and hacker groups are creating tools that are increasingly more persistent and threatening, and we have to be ready for that," he said.

Amid a spate of high-profile cyber crimes, the Obama administration wants Congress to pass comprehensive cyber-security legislation that would increase the government's ability to thwart the growing threat.

Alexander and other top officials held a classified meeting with lawmakers on Wednesday and Thursday to discuss the issue, according to sources familiar with the meeting.

Nasdaq CEO Robert Greifeld said in July that the exchange is under constant attack, requiring it to spend nearly a billion dollars a year on information security.

"As we sit here, there are people trying to slam into our system every day," Greifeld said in the interview. "So we have to be ever vigilant against an ever-changing foe."

Copyright 2011 Thomson Reuters. Click for restrictions.

View the original article here

Nasdaq hackers spied on company boards - sources

By Jim Finkle

REUTERS - Hackers who infiltrated the Nasdaq's computer systems last year installed malicious software that allowed them to spy on the directors of publicly held companies, according to two people familiar with an investigation into the matter.

The new details showed the cyber attack was more serious than previously thought, as Nasdaq OMX Group had said in February that there was no evidence the hackers accessed customer information.

It was not known what information the hackers might have stolen. The investigation into the attack, involving the FBI and National Security Agency, is ongoing.

"God knows exactly what they have done. The long term impact of such attack is still unknown," said Tom Kellermann, a well-known cyber security expert with years of experience protecting central banks and other high-profile financial institutions from attack.

The case is an example of a "blended attack," where elite hackers infiltrate one target to facilitate access to another. In March hackers stole digital security keys from EMC Corp's RSA Security division that they later used to breach the networks of defence contractor Lockheed Martin Corp.

Nasdaq had previously said that its trading platforms were not compromised by the hackers, but they attacked a Web-based software program called Directors Desk, used by corporate boards to share documents and communicate with executives, among other things.

By infecting Directors Desk, the hackers were able to access confidential documents and the communications of board directors, said Kellermann, chief technology officer at security technology firm AirPatrol Corp.

Investigators have learned that hackers were able to spy on "scores" of directors who logged onto directorsdesk.com before the malicious software was removed, said Kellermann and another person familiar with the investigation who was not authorized to discuss the matter publicly.

It was still unclear how long Nasdaq's system was breached before the attack was discovered last October.

A Nasdaq spokesman confirmed the investigation into the attack continues, but declined to give further details.

NSA HELPS NASDAQ

Executive Assistant FBI Director Shawn Henry said the financial services sector was losing hundreds of millions of dollars to hackers every year, and the attacks were increasingly "destructive" in nature.

"We know adversaries have full unfettered access to certain networks. Once there they have the ability to destroy data," he told Reuters in a phone interview. "We see that as a credible threat to all sectors, but specifically the financial services sector." Henry declined to comment on the Nasdaq attack.

U.S. Army General Keith Alexander, head of the National Security Agency and U.S. Cyber Command, said the NSA was working with Nasdaq to help protect its network against further attacks.

Alexander told security experts at a Baltimore conference that the United States was shoring up its defences, but still had "tremendous vulnerabilities" to a growing number of increasingly destructive electronic attacks.

"Nation states, non-nation state actors and hacker groups are creating tools that are increasingly more persistent and threatening, and we have to be ready for that," he said.

Amid a spate of high-profile cyber crimes, the Obama administration wants Congress to pass comprehensive cyber-security legislation that would increase the government's ability to thwart the growing threat.

Alexander and other top officials held a classified meeting with lawmakers on Wednesday and Thursday to discuss the issue, according to sources familiar with the meeting.

Nasdaq CEO Robert Greifeld said in July that the exchange is under constant attack, requiring it to spend nearly a billion dollars a year on information security.

"As we sit here, there are people trying to slam into our system every day," Greifeld said in the interview. "So we have to be ever vigilant against an ever-changing foe."

(Reporting by Jim Finkle. Additional reporting by Jonathan Spicer in New York, Andrea Shalal-Esa in Baltimore and Diane Bartz in Washington. Editing by Tim Dobbyn, Tiffany Wu, and Bob Burgdorfer)


View the original article here

Hackers Spied on Board Directors After Nasdaq Breach

Results from Nasdaq's investigation into a breach it disclosed in February are trickling out. The bottom line: The attack was worse than initially expected.

Fox News said hackers who infiltrated the Nasdaq's computer systems installed malicious software on the exchange's computers that allowed them to spy on scores of directors of publicly held companies. Fox cited "two people familiar with an investigation" as sources.

The target of the attack was a Web-based software program called Directors Desk. Nasdaq OMX develops Directors Desk, which serves as a communications and information management solution for boards. Security is touted as one of its benefits.

An SQL Injection?

Gunter Ollman, vice president of research at security firm Damballa, said the sparse public information available on the NASDAQ breach and the nature of the Director's Desk Web-based application leads him to believe that remote hackers probably exploited vulnerabilities within the application that allowed them to peruse information exchanges between various company directors.

"Gaining remote access to confidential data held within the Director's Desk application could have been through SQL injection, broken authentication and session management, and URL restriction failures," Ollman said. "In my years of running penetration tests against Fortune 500 companies, these were the most common vulnerabilities that could be exploited to reveal this level of confidential data."

Some security experts are reporting that the attackers successfully installed malware on the system. In order to do this, Ollman said, the attacker would need the capability to upload files to the application and/or break out of the application itself and gain access to the server directly. Interestingly, he noted, several Open Web Application Security Project top-10 attack vectors will allow this to occur.

Web App Vulnerabilities

Ollman, for one, is not surprised at the Directors Desk revelations. That's because vulnerabilities within large Web-based applications are increasingly common. Web-based software is under constant development and change, he said, which means that vulnerabilities can be unintentionally introduced at any time.

"If there are multiple development teams working on the same application portal -- all developing their own micro applications -- then the probability of new vulnerabilities being introduced grows considerably," Ollman said. "This is why Web applications need to be security-tested continuously. Regular security assessments and penetration tests are standard requirements for running large and important Web services."

Ollman said automated tests and change-control monitoring ideally should be conducted daily, and skilled consultants should manually assess the Web application monthly. What's more, he continued, given the human element in most advanced testing, it is a good idea to rotate between penetration-testing vendors so that the tests are not limited by the skills of the individual consultants they employ or the tool sets they use to conduct their tests.

"Access to Web-based applications by attackers is important for cybercriminals -- as well as state actors," Ollman said. "Again, it bears repeating that very little is known about the specific nature of the Nasdaq attack. But given the level of access to the application and the potential to modify content upon the Director's Desk application, likely consequences could include the ability to eavesdrop on company director communications and the ability to use that information for 'virtual insider trading' processes."


View the original article here