Archive for news

You are browsing the archives of news.

The Bluetooth Dilemma

This article describes how criminals have begun to integrate bluetooth technology into card reader skimmers to make it more effective for them to collect stolen card information. Josh Wright is an expert on bluetooth and wireless security in general and is a Senior Instructor at the SANS Institute, where he authored (and often teaches) the [...]

US – Australia – Cyber Treaty

U.S., Australia to add cyber realm to defense treaty – [reuters.com] (Reuters) – The United States and Australia will take the rare step on Thursday of declaring the cyber realm as part of a mutual defense treaty, meaning that a cyber attack on one could lead to a response by both nations. U.S.-Australia Ministerial Consultations [...]

Botnets Attack from the Sky

It’s now become fairly easy and cheap to make an autonomous flying model drone. Telemetry that relays information collected by a drone back to the ground has been demonstrated. Wireless hacking from equipment mounted on a flying drone has been demonstrated. Flying drones are becoming smaller, cheaper and more automated. Flying model aircraft have been [...]

Chinese Cyberwarfare Exposed

Slip-Up in Chinese Military TV Show Reveals More Than Intended – [theepochtimes.com] Piece shows cyber warfare against US entities A standard, even boring, piece of Chinese military propaganda screened in mid-July included what must have been an unintended but nevertheless damaging revelation: shots from a computer screen showing a Chinese military university is engaged in [...]

Deciphering Stuxnet

How Digital Detectives Deciphered Stuxnet, the Most Menacing Malware in History – [wired.com] “the world’s first real cyberweapon” It was January 2010, and investigators with the International Atomic Energy Agency had just completed an inspection at the uranium enrichment plant outside Natanz in central Iran, when they realized that something was off within the cascade [...]

DLL Hijacking

DLL hijacking vulnerabilities – [sans.edu] For the last couple of days there have been a lot of discussions about a vulnerability published by a Slovenian security company ACROS. HD Moore (of Metasploit fame) also independently found hundreds of vulnerable applications and, as he said, the cat is now really out of the bag. In order [...]

Robin Sage

Robin Sage is not a real person. Fictitious femme fatale fooled cybersecurity – [washingtontimes.com] Call her the Mata Hari of cyberspace. Robin Sage, according to her profiles on Facebook and other social-networking websites, was an attractive, flirtatious 25-year-old woman working as a “cyber threat analyst” at the U.S. Navy’s Network Warfare Command. Within less than [...]

Cyberwarfare

The metaphor of warfare used to apply to cyber-conflict is strained, but is still the paradigm most often used in discussions of this area by government and military. The concepts of “target” and “territory” are vastly different in a network. Likewise, the meanings of terms like: capture, destroy, defend, attack, hold, flank, surround, and many [...]

Hacking Cars

A research paper from the Center for Automotive Embedded Systems Security, describes an attack methodology against embedded computer systems in modern automobiles. The attackers were able to activate or disengage the brakes while driving, control the engine and the lights, by plugging a laptop computer into a control socket. While this was done using direct [...]

AV Bypass Attack

An attack that can bypass Anti-Virus defenses has been detailed in a research paper by matousec.com. Matousec developed an engine called KHOBE (Kernel HOok Bypassing Engine) that uses an “argument switch” strategy, or SSDT hooking, to convince the AV scanner that everything is okay. KHOBE – 8.0 earthquake for Windows desktop security software – [matousec.com] [...]