The year’s most significant attacks highlight how hackers are changing tactics — and how IT security must evolve in the year ahead. Not a week went by in 2015 without a major data breach, significant attack campaign, or serious vulnerability report. Many of the incidents were the result of disabled security controls, implementation errors, or other basic security mistakes, highlighting how far organizations have to go in nailing down IT security basics.
0 0 Dave Burton https://www.guardicore.com/wp-content/uploads/2019/02/guardicore-logo-white-space.png Dave Burton2015-12-28 11:46:012019-11-21 04:28:58The most innovative and damaging hacks of 2015
https://www.guardicore.com/wp-content/uploads/2015/12/Yup-We-Can-See-It-Coming.jpg 187 686 Sharon Besser https://www.guardicore.com/wp-content/uploads/2019/02/guardicore-logo-white-space.png Sharon Besser2015-12-23 07:54:182019-02-25 10:54:35Yup, We Can See It Coming
On December 17th, 2015 Juniper issued an advisory indicating that they had discovered unauthorized code in the ScreenOS software that powers their Netscreen firewalls. This advisory covered two distinct issues; a backdoor in the VPN implementation that allows a passive eavesdropper to decrypt traffic and a second backdoor that allows an attacker to bypass authentication in the SSH and Telnet daemons. There are speculations that the backdoor was installed by “State Sponsored” actors. Shortly after Juniper posted the advisory, an employee of Fox-IT stated that they were able to identify the backdoor password in six hours. (So much for Government efficiency hiding their actions)
https://www.guardicore.com/wp-content/uploads/2015/12/liu-bolin-0011.jpg 633 800 Uri "Cyber" Hershcovits https://www.guardicore.com/wp-content/uploads/2019/02/guardicore-logo-white-space.png Uri "Cyber" Hershcovits2015-12-09 10:23:062019-02-25 10:55:14Pay No Attention to the Man Behind the Curtain!
How do you detect a security breach inside your network? How do you collect the necessary intelligence to protect your assets properly? Sun Tzu, author of The Art of War, said that convincing your opponents to unveil their identity without knowing that they are being watched is one of the most important keys to winning a war. Attack deception is one of the best techniques to make attackers unveil their identity and gain valuable intelligence. While it is not new, advanced attack deception methods take advantage of Sun Tzu’s strategy.
https://www.guardicore.com/wp-content/uploads/2015/12/Caught-red-handed-Alex.jpg 187 686 Daniel Goldberg https://www.guardicore.com/wp-content/uploads/2019/02/guardicore-logo-white-space.png Daniel Goldberg2015-12-02 13:50:252019-02-25 10:55:57Caught red handed – Alex
Opportunistic hackers are far from the limelight these days but they still exist and can cause large amounts of damage if they manage to break into your systems. We’ve recently observed our Data Center Security Suite catch such a hacker, an “Alex” from Romania who has kindly enough supplied his own name and private domain for publicity.