Google Search

Showing posts with label still. Show all posts
Showing posts with label still. Show all posts

Thursday, December 19, 2013

Humans still the weakest link as phishing gets smarter and more focused

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The latest figures from the Anti-Phishing Working Group (APWG) show a distinct decline in the numbers of phishing sites reported to it, and in the number of separate brands targeted.

A survey compiled by Verizon, on the other hand, implies that almost all incidents of cyber espionage reported in the last year included some phishing component.

An academic study into human susceptibility to phishing has found that 92% of people misclassify phishing emails, despite efforts to educate people about the dangers.

Put together, this seems to confirm a general feeling that phishing attacks are becoming less scatter-gun, focusing more on specific targets, with more care and attention put into making them more enticing, more believable and harder to spot.

The APWG quarterly report, covering the first three months of 2013 but only released earlier this week, found that phishing attack dropped 20% between January and March, with February figures the lowest since October 2011.

The number of brands targeted is also down on the previous quarter, although 2012 numbers were considered exceptionally high.

As the stats are based on phishing pages and incidents reported to the APWG by the public, it's not clear if the drop in numbers is down to a real drop in actual attacks, or simply due to them becoming harder for people to spot, leading to fewer reports.

Ihab Shraim, CISO at news behemoth Thomson Reuters and quoted in the APWG report, talks about the trends in a way that supports both explanations:

These changes are likely due to a shift to more advanced and targeted techniques for credential theft including malware and stealthier spear phishing.

Phishing has been around for years now, with a fairly well-known set of targets, tricks and tell-tale signs, but we still see new techniques emerging, making the smarter scams harder for both machines and humans to detect.

Spear-phishing of highly focused targets has been the driving force behind a number of major compromises lately, from high-profile hacktivism like the recent Viber heist to more stealthy targeted penetrations.

Educating users to keep a wary eye out for phishing attempts has been a major focus for security admins and providers, but it seems like the bad guys are managing to keep ahead of the curve.

Academics at North Carolina State University have been looking into the characteristics of people who fall for phishes, combining personality studies with experiments using swathes of legitimate and phishing emails.

They found that confidence is high, with 89% thinking they can spot the dodgy messages, but 92% didn't get it right every time, with 52% getting it wrong more than half the time and 54% having at least one false positive incident, trashing a real email in the belief that it was a scam.

They also found that people who thought of themselves as “less trusting, introverts, or less open to new experiences” threw out more genuine mails, while women were less adept than men at spotting phishing messages.

The researchers, whose work is part-funded by the beleaguered NSA, suggest that as the human mind is the main issue, education remains the most important weapon in the battle against the phishers.

The team is working towards a system of teaching which will effectively prepare people to avoid being tricked.

While technical countermeasures such as improvements in secure browsing will play a part, as will making sure the bad guys are brought to book wherever possible, it's clear that the psychological battleground is vital.

Phishing has come a long way from the old days when simply keeping an eye out for dodgy grammar and sloppy spelling was enough. Education techniques clearly need to evolve to keep pace with the growing sophistication of phishing scams.

A major difficulty is the tendency to focus on specifics; any list of tell-tale signs is likely to date quickly, as techniques evolve and old mistakes are learnt from.

The main thing is to maintain a skeptical disposition. Social engineering relies on leveraging the most potent human emotions, its main weapons being sex, greed, fear and other basic urges. These can only be combated by logic, clear thinking and good sense.

So next time you see an unexpected message asking for your login info or other sensitive data, stop a moment. Take a few deep breaths, and have a good look around.

Ask yourself a few key questions: Am I sure I am where I think I am? How exactly did I get here? Do I really need to provide this info? What could possibly happen if this info got into the wrong hands? Am I being hurried into something I wouldn't normally do?

You may find that simply stepping back and looking at things with a cool head will keep you from blundering into danger.

Follow @VirusBtn
Follow @NakedSecurity


View the original article here

Sunday, September 8, 2013

May Patch Tuesday coming up - Microsoft still not sure if latest 0-day fix will make the cut

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft's Patch Tuesday for May 2013 will be published in the coming week.

It'll be out on Tuesday 14 May 2013. (Wednesday 14 May for everywhere from about Malaysia eastwards.)

Here's the elevator pitch:

33 vulnerabilities identified and fixed.Ten separate patches.Eight rated Important. (Apply ASAP.) Two rated Critical. (Apply immediately.) A reboot is required.

Loosely translated, Microsoft's interpretation of important means that an exploit against the vulnerability is likely to be found, but you'll probably get some sort of warning, such as a pop-up dialog, if an attacker tries to use it.

On the other hand, critical means not just that a exploit is likely (or already known), but that it can be used silently - what's known as a drive-by install - without popups or any other kind of warning.

The burning question about the May 2013 Patch Tuesday is this: will it fix CVE-??2013-??1347?

This is a remote code execution flaw in Internet Explorer 8 that has already been exploited in the wild to disseminate malware, most notably via a hacked website belonging to the US Department of Labor.

Microsoft has already published a temporary patch for CVE-??2013-??1347 in the form of a Fix it tool, and has announced that it would like to have a permanent patch available in time for the coming patch Tuesday.

As Microsoftie Dustin Childs from the Trustworthy Computing team wrote:

Of note, we are working to have the Internet Explorer Security Update address the issue described in Security Advisory 2847140 [relating to CVE-2013-1347], supplementing the currently available Fix it.

In plain English, that means: "We've got a patch ready. We'd love to ship it out to everyone on Patch Tuesday, but we haven't quite decided whether it's 100% ready yet."

I suggest you assume that Microsoft will miss the Tuesday deadline for the CVE-?2013-?1347 patch, and will publish it in a so-called out of band, one-off update later in May.

In other words, prepare to patch twice in the month.

If Microsoft does hit its deadline, treat it as a handy bonus.

Follow @duckblog


View the original article here

Wednesday, February 20, 2013

Phishing attack against MSN/Hotmail users - a new year, but old tricks still persist

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

MSN and HotmailIt's a brand new year and you would like to think that computer users are getting smarter about securing their systems, and not falling for the age-old tricks used by cybercriminals.

However, we still see our fair share of elementary unsophisticated attacks designed to steal credentials from the unwary.

Take this example, an email which claims to come from the "Windows Live Team" and warns Hotmail/MSN users that their account is at risk of immediate closure after different computers logged into it, and multiple attempts were made to guess the password:

Simple email phishing attack

Part of the email reads:

VERIFY THIS EMAIL ADDRESS TO AVOID IMMEDIATE CLOSURE

We have recently confirmed that different computers have logged onto your Hotmail and Msn account and multiple password errors have been entered. We are hereby suspending your account; as it has been used for fraudulent purposes.. Now we need you to reconfirm your account information to us. Click your reply tab, fill in the columns below and send it back to us or your email account will be suspended permanently.

The email, which has the subject line "CONFIRMATION ALERT RESET (2013)" and comes from an unofficial-looking @msn.com email address, urges the user to reply via email with their full name, username, password, date of birth, and country in order to confirm their identity.

In case that seems a little brusque, the would-be thieves who spammed out this email provided some helpful tips at the end of the email about managing email accounts.

Of course, Microsoft would never ask you to confirm your identity in this fashion - especially not by sending your password in an (unencrypted) email.

But less security-savvy computer users might be duped into believing it is true, and respond with all the information the cybercriminals want, before having a chance to think twice.

It's a highly unsophisticated attack - but if it works against just a small number of people that the spammers send it out to, what does that matter?

Don't be a cybercrime statistic, make sure that you, your friends and your family are wise to such tricks and don't share your login information with anybody.

Follow @gcluley

Hat-tip: Thanks to Naked Security reader Jack for forwarding us this phishing email.


View the original article here