Google Search

Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Friday, December 26, 2014

Sony pulls 'The Interview' after 9/11 terror threat

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The InterviewSony Pictures is close to monopolizing security news with post-cyber-attack ripples.

Those ripples now include getting sued by ex-employees over privacy violations, being threatened with a terrorist attack similar to 9/11, having its film The Interview pulled from several cinemas as a result, and the subsequent announcement that Sony has cancelled the theatrical release altogether.

On the breathe-one-small-sigh-of-relief side of the ledger, it's received compliance with a DCMA takedown request from Reddit, which has banned users from sharing documents pilfered from the movie studio.

On Tuesday, those purportedly behind the hack threatened a terrorist attack on theaters and movie goers who attend screenings of The Interview.

The GOP had previously promised to deliver a "Christmas gift," which originally sounded like another batch of leaked data.

But in Tuesday's message, which Mashable reports was sent to itself and several other news outlets, along with new batch of Sony Entertainment CEO Michael Lynton's hacked emails, warned people to stay away from the movie, specifically mentioning the 2001 attacks on New York and the Pentagon:

We will clearly show it to you at the very time and places "The Interview" be shown, including the premiere, how bitter fate those who seek fun in terror should be doomed to.

Soon all the world will see what an awful movie Sony Pictures Entertainment has made.

The world will be full of fear.

Remember the 11th of September 2001.

We recommend you to keep yourself distant from the places at that time.

(If your house is nearby, you’d better leave.)

A Department of Homeland Security (DHS) official who requested anonymity told Fortune that the DHS isn't aware of any active plot against movie theaters in connection with the attack against Sony.

From his or her statement:

We are still analyzing the credibility of these statements, but at this time there is no credible intelligence to indicate an active plot against movie theaters within the United States. ... As always, DHS will continue to adjust our security posture, as appropriate, to protect the American people.

At least one New York theater canceled the premiere of the film, which is a Seth Rogen/James Franco comedy about a plot to kill North Korea's leader Kim Jong-Un.

Carmike Cinemas, a movie theater chain that's based in Columbus, Georgia, and which has theaters in 41 states, also chose not to show The Interview, according to The Hollywood Reporter.

In addition, the two stars canceled all of their upcoming press events, according to BuzzFeed, which was hosting an event with the two.

Sony announced yesterday that it wouldn't be releasing The Interview on Christmas Day as planned:

In light of the decision by the majority of our exhibitors not to show the film The Interview, we have decided not to move forward with the planned December 25 theatrical release. We respect and understand our partners' decision and, of course, completely share their paramount interest in the safety of employees and theater-goers.

Sony Pictures has been the victim of an unprecedented criminal assault against our employees, our customers, and our business. Those who attacked us stole our intellectual property, private emails, and sensitive and proprietary material, and sought to destroy our spirit and our morale — all apparently to thwart the release of a movie they did not like. We are deeply saddened at this brazen effort to suppress the distribution of a movie, and in the process do damage to our company, our employees, and the American public. We stand by our filmmakers and their right to free expression and are extremely disappointed by this outcome.

In other fallout, two of the movie studio's ex-employees have sued the company for failing to protect their private information.

They'd like to turn it into a class action lawsuit of up to 15,000 former employees.

The plaintiffs haven't been specific about the amount of money they're seeking, but according to Money CNN, they want Sony to provide five years of credit monitoring, bank monitoring, identity theft insurance and credit restoration service. They're also seeking for Sony to be subject to regular privacy audits.

Finally, a ray of hope that somebody on the internet is going to take down Sony's doxed materials.

As it is, Sony on Monday warned the media not to publish the details of anything that was stolen in last month's breach.

By Wednesday, Reddit had acceded to a DMCA takedown request from Sony.

Reddit removed a hub for sharing the company’s hacked files, deleted posts, blocked individual user accounts, and banned a subreddit devoted to sharing the files.

However, as Reddit told Business Insider, "discussions and news stories" about the attack were unaffected by the bans - similar to how Reddit recently banned stolen celebrity nude photos but allowed discussion about the thefts.

Follow @LisaVaas

Follow @NakedSecurity

View the original article here

Sunday, November 10, 2013

Who is SophosLabs: Numaan Huq, Threat Researcher

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SophosLabs is at the center of Sophos. It's the place where highly skilled experts in the field work round the clock to build protection from the latest threats.

But who works there?

In the first of this series, we're talking to Numaan Huq, Senior Threat Researcher from SophosLabs Vancouver.

Numaan HuqI am originally from Dhaka, Bangladesh. I moved to Canada for school back in 2000.

I have a BSc ('04) and MSc ('09) in Computer Science from the University of Victoria (UVic) in Victoria, BC. My focus in my senior years and in grad school was on networks. My MSc project thesis entitled "Performance Analysis of Cascaded Policing System" was on network traffic shaping.

I've been an avid fan of fantasy novels since grade 7. I listen to whatever music fits my mood and my fancy - I don’t have a fascination for any particular genre.

I'm a big fan of soccer and Formula 1 racing. I’m currently harboring a dream of going mountaineering and am targeting a climb of Mount Rainier (elevation 14,410 feet) in Washington State next year. But first I need to whip myself into shape.

I can't live without my internet enabled phone.

My friends say I cook tasty food, but then maybe they're just happy getting a free meal. They sing songs about my deeds so I invite them again.

I did an internship where I worked on programming Voice over IP (VoIP) phones. Part of my responsibility included pen-testing the VoIP phones to see if we could get root access to the device.

When I was looking for employment, the job at Sophos seemed like a natural extension of my experience. It also helped that it was in the same city I was living in!

My specialty within the Labs is on APTs (advanced persistent threats), web threats and vulnerabilities. I am co-author of a paper titled "Trapping unknown malware in a context web" which has been accepted to the VB2013 conference in Berlin this October.

Currently I'm conducting research on malware that targets point of sale (PoS) systems.

I am also the SophosLabs contact for Microsoft's MAPP and I coordinate and contribute to SophosLabs' Patch Tuesday processing. My other interests include OS architecture and encryption algorithms.

The best thing about my work is definitely the team. We have a set of very talented and hardworking people here in Canada who truly believe that we can do things better, while at the same time making a difference. That attitude rubs off on you quickly, and it motivates me.

I've had two super memorable moments in SophosLabs:

When I wrote my first ever virus detection and disinfection, W32/Ngvck-U, back in August 2007. I worked very hard in analyzing the virus, figuring out how the infection routine worked and then writing and re-writing disinfection to meet the Labs standard. I felt very proud that day and it solidified my self confidence.I was asked to figure out the "attack graph" of an APT for a very important customer. All I had was a mess of packed, seemingly disjointed files, out of which I needed to build a complete picture. It took almost a week of intense reversing to try to connect the dots and decipher where the APT had come from, how it penetrated/propagated and finally what it attempted to mine. Again, it was a superbly satisfying exercise.

To me, the biggest threat in the next few years is APTs. Though it is a term much loved by the media, in reality it is a serious threat which will only mature. The threat vectors will get more complicated because the operating and eco systems are becoming more secure and dynamic all at once. This requires the creation of more complicated and innovative methods of exploitation.

Social engineering is as old as malware. There is a popular saying in SophosLabs: "The biggest vulnerability lies between the chair and the computer."

The business of mass-produced malware generated using crime kits is in its infancy and I predict it will become more sophisticated and user-friendly, leading to an exponential increase in the volume of malware. I think new business models will emerge for malware, driven mostly by the latest technology trends of that period.

SophosLabsWhen giving security advice, I tend to tell people to run Macs. It's not like OSX is bullet-proof, but their market share is small so they don't make a lucrative target for malware authors. This is why we see so little malware for OSX.

If you're tech-savvy, go ahead and run Linux.

My recommendations: Encrypt, encrypt, encrypt everything! Most modern operating systems have simple options to enable encryption. And always protect your mobile device with a strong password.

For security reading, I recommend Naked Security of course! And Virus Bulletin has a link to most of the popular computer security blogs.

If you're trying to break into the security field - read lots. This is a dynamic place and following blogs and forums is a great way to get your head around the security space. Visit a couple of conferences to 'meet and greet' people in the industry.

A popular free conference is Security B-Sides and most major conferences have student registration prices. Attend a "dojo" or training session at one of these conferences; they are a bit pricey but extremely helpful.

In the future, I would definitely like to stay within the realms of computer security. In ten years I might transition from researcher to a management role but as they say, "Yesterday is history. Tomorrow is a mystery. Today is a gift."

Want to know more about SophosLabs?

Check out our YouTube playlist, or read more here.

Follow @SophosLabs
Follow @NakedSecurity


View the original article here

Saturday, December 8, 2012

National security threat or not? Huawei offers Australia unrestricted access to code

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Huawei and AustraliaHuawei is offering unrestricted access to its code and hardware in an attempt to prove that it's not a security threat.

The Chinese telecom giant made the offer to Australia, which has blocked Huawei's bid to work on its national broadband network.

John Lord, chairman of Huawei's Australian arm, blamed the company's lousy communication for what he called "myths and misinformation" that have led to the company being shunned by multiple countries.

In a speech to Australia's National Press Club, he told the audience that Huawei must be more open, according to the BBC:

"Huawei has done a very poor job of communicating about ourselves and we must take full responsibility for that."

According to the BBC, Lord also said that Huawei will give the Australian authorities "complete and unrestricted access" to its software source code and equipment.

He also suggested that Australia set up a cyber evaluation centre to test communications network equipment, funded by telcos and operated by "security-cleared Australian nationals".

Lord said that such a centre has been established in the UK and that Huawei has already given British security agencies access to source code so they can check the security bona fides on its equipment.

He said that it shouldn't be up to a single vendor, country, agency or telco to solve computer security issues:

"It requires a collaborative approach by all to ensure we can create the most secure telecommunications environment possible."

Huawei also pitched the concept to US lawmakers during the Committee on Intelligence's investigation of the company.

The committee's report rejected the proposal on the grounds that Huawei's equipment is too complex, making it too difficult to assess whether the goods could be manipulated.

As it is, the US has already suggested that Huawei and another Chinese firm, ZTE, be banned from the US market because their products could be used to undermine domestic cyber security, given the potential for spying and espionage they could enable.

Circuit boardHuawei has a lot of people to convince.

India, for one. In 2010 the country banned telecoms from importing Chinese networking equipment, fearing that it's infested with spyware.

Then in March of this year, Australia banned Huawei from participating in multi-billion dollar deals to supply equipment for its national broadband network, given similar fears that the Chinese government could exploit the equipment to carry out cyber attacks.

The company's track record isn't helping to assure anybody.

Reuters on Thursday reported that an Iranian partner of Huawei last year offered to sell banned US antenna equipment to an Iranian mobile phone operator.

The would-be buyer told Reuters that it nixed the deal when it learned that the equipment was outlawed under US sanctions.

In spite of the deal falling through, the fact that Huawei tried it at all backs up the US's wariness about the company.

The US just isn't convinced that Huawei complies with international sanctions or US export laws, as the House Intelligence Committee charged in its report [PDF], which it issued earlier in October.

The documents and interviews Reuters relied on point to the almost-sale being an error on the part of the Iranian Huawei partner, rather than an intentional premeditated breach.

Whatever the truth of the matter, the facts point to Huawei being, in the very best case scenario, sloppy.

Follow @LisaVaas
Follow @NakedSecurity

Tags: australia, ban, China, cyber attack, cyber espionage, Huawei, Iran, John Lord, National Press Club, sanctions, spying


View the original article here

Friday, May 25, 2012

Technical paper - Fake anti-virus: The journey from Trojan to a persistent threat

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Fake stamp, courtesy of ShutterstockFake anti-virus (also known as scareware) has grown over the years into a persistent and prevalent threat and is now one of the largest families of malware that we've seen in recent history.

In this new technical paper from SophosLabs, threat researcher Jagadeesh Chandraiah studies the evolution of fake anti-virus over the last three and a half years.

He looks at the major fake anti-virus events, infection vectors and some important anti-emulation/anti-reverse engineering (RE) tricks used by fake anti-virus packers.

He also analyses how exploit kits are used to infect users with fake anti-virus and studies how a polymorphic packer found in underground internet forums is used to encrypt and compress the malware binary.

Read: Fake anti-virus: The journey from Trojan to a persistent threat

http://twitter.com/SophosLabs

Fake stamp image, courtesy of Shutterstock


View the original article here

Thursday, May 17, 2012

What the FBI didn't tell us about the hotel malware threat

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Internet access in hotel room. Image from ShutterstockIf you follow the field of computer security chances are that you saw the warning issued by the FBI's Internet Crime Complaint Center (IC3) this week about using hotel internet connections.

Here's the full text of the advisory, with some responses sprinkled throughout from yours truly:

Malware Installed on Travelers' Laptops Through Software Updates on Hotel Internet Connections

Recent analysis from the FBI and other government agencies demonstrates that malicious actors are targeting travelers abroad through pop-up windows while establishing an Internet connection in their hotel rooms.

"Malicious actors"? Are we talking cybercriminal gangs and fraudsters or state-sponsored bad guys from an enemy nation?

"Travelers abroad"? So, you mean that this can't possibly happen within the United States?

Why the coyness about naming countries? Is it because the FBI doesn't know which countries this pertains to (other than it's definitely not happening in the USA)? Is it because they have a list of countries, but they're not sure if it's a complete, exhaustive list? Or is it because the authorities don't want to say which countries?

Recently, there have been instances of travelers' laptops being infected with malicious software while using hotel Internet connections.

"Malicious software"? Can you tell us what malicious software? Is it a particular malware family? Can you at least tell us what the malware is attempting to do?

In these instances, the traveler was attempting to setup the hotel room Internet connection and was presented with a pop-up window notifying the user to update a widely-used software product.

"A widely-used software product"? Why not name it? The FBI isn't saying a variety of popular products, it's saying "a widely-used software product". Should it really be up to us to place bets as to whether it's likely to be Adobe Flash or not?

If the user clicked to accept and install the update, malicious software was installed on the laptop. The pop-up window appeared to be offering a routine update to a legitimate software product for which updates are frequently available.

Which operating system are we talking about here? Windows? Mac OS X? Linux? iOS? Might have been handy to mention..

The FBI recommends that all government, private industry, and academic personnel who travel abroad take extra caution before updating software products on their hotel Internet connection.

"Government, private industry, and academic personnel..take extra caution"? Hang on. What about the rest of us? Shouldn't we also be careful if we're taking our computers overseas, perhaps on vacation? Or is the un-named country where this is happening not the kind of place people go on holiday to?

Checking the author or digital certificate of any prompted update to see if it corresponds to the software vendor may reveal an attempted attack.

But is likely to be beyond the ken of the vast majority of users..

The FBI also recommends that travelers perform software updates on laptops immediately before traveling, and that they download software updates directly from the software vendor’s Web site if updates are necessary while abroad.

Sensible. No complaints with that. But the idea of business people travelling for weeks on end without installing security updates while they're on the road sounds like it could backfire.

Anyone who believes they have been a target of this type of attack should immediately contact their local FBI office, and promptly report it to the IC3's website at www.IC3.gov. The IC3's complaint database links complaints together to refer them to the appropriate law enforcement agency for case consideration. The complaint information is also used to identify emerging trends and patterns.

What's fascinating about the advisory is what it doesn't say. And without more information it's hard to know how computer users are supposed to take meaningful action to protect themselves other than follow the normal advice of running security software, being careful what you install, running a VPN to hide your browsing from snoopers, etc.

It's certainly very peculiar that the FBI didn't share more information in its warning, or mention where in the world it believes it has seen these attacks taking place.

By coincidence, earlier this week, for the first time in almost ten years, a Chinese defense minister visited the United States.

The day before the FBI's warning was issued, US Defence Secretary Leon Panetta met his Chinese counterpart Liang Guanglie in Washington DC, and told the world's press that the two countries must work together to avoid cyber war, and emphasised the importance of the relationship between China and the USA.

US and Chinese military chiefs met in Washington this week, to discuss cyber attacks

Maybe there was more that the authorities could have said about this hotel malware threat, but thought it undiplomatic to publicise.

Follow @gcluley

Laptop in hotel room image, courtesy of Shutterstock.


View the original article here