Sponsor

2013/10/29

| 10.29.13 | Adobe ups breach estimate from 2.9M to 38M affected users

If you are unable to see the message below, click here to view.

Editor's Corner:
Enterprises need to retire Windows XP now

What's New:
1. Adobe ups breach estimate from 2.9M to 38M affected users
2. Microsoft report finds decline in disclosed software vulnerabilities
3. Cisco patches remote code execution, DoS flaws in enterprise products
4. BYOD, cloud fueling demand for mobile encryption products
5. Enterprises struggle with access control rights

Spotlight:
Australia upholds ban on Huawei

Also Noted:
Google simplifies reCAPTCHA; DDoS tactics shift; Much more...

News From The Fierce Network:
1. UK government provides advice to CIOs grappling with BYOD
2. Centrify launches tech partner program to secure mobile, cloud apps
3. Samsung unveils Knox SDK to boost enterprise mobile security efforts

FierceITSecurity

October 29, 2013

Subscribe | Website
Refer FierceITSecurity to a Colleague

This week's sponsors:
HP
HP

Follow @fierceitsec on Twitter


This week's sponsor is HP.

 

eBook: Security for a faster world
Cybercrime is becoming increasingly sophisticated, and it often surpasses the security capabilities of even large corporations. This eBook presents a maturity model that will help you determine how secure you really are, explores five questions every CIO should be able to answer, and outlines a new approach based on intelligence gathering and research that can keep you ahead of the cybercriminals. Download Now.


Editor's Corner

Enterprises need to retire Windows XP now

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

Microsoft released this week its semi-annual Microsoft Security Intelligence Report, which contained some encouraging news on disclosed software vulnerabilities (see the article in this issue)

Perhaps more interesting for IT managers are the report's findings about malware and Windows operating systems. The report found that while Windows 8 encountered a similar amount of malware as Windows XP, end users running Windows XP were six times more likely to be infected by malware.

For users of Windows XP, the top three threats were all worms: Sality, a worm family that can steal personal information and lower PC security settings; Ramnit, a worm that infects Windows executable files, Microsoft Office files, and HTML files; and Vobfus, a family of worms that can download other malware onto a PC and can be downloaded by other malware or spread via removable drives.

The much higher vulnerability of Windows XP to malware infection is significant because more than one-third of desktops still run the older operating system, according to a recent survey by Net Applications. On the other hand, Windows 8 is running on only five percent of desktops.

In addition, Microsoft will stop providing security updates for Windows XP in April of next year. Malware infection rates are still six times higher for the supported XP operating system. So by dragging their feet in upgrading their Windows operating systems, enterprises are opening themselves up to much greater security risk.

"After April next year, when we release monthly security updates for supported versions of Windows, attackers will try and reverse engineer them to identify any vulnerabilities that also exist in Windows XP. If they succeed, attackers will have the capability to develop exploit code to take advantage of them," commented Tim Rains, director of trustworthy computing at Microsoft.

Of course, Microsoft has a financial interest in promoting the report's findings, but the facts remain that XP suffers from a higher malware infection rate that will only get much worse next year.

It's not just Microsoft that is warning about relying on Windows XP. Jason Fossen, a security trainer for the SANS Institute, commented earlier this year that hackers might be saving up their Windows XP exploits until April of next year, when they will be able to get a premium price for them.

"When someone discovers a very reliable, remotely executable XP vulnerability, and publishes it today, Microsoft will patch it in a few weeks. But if they sit on a vulnerability, the price for it could very well double," Fossen observed.

So it is time for IT managers to retire Windows XP, if their computers are still running the operating system, and upgrade to at least Windows 7. - Fred

Read more about: Microsoft, software vulnerabilities

Sponsor: HP

Events

> RSA? Conference 2014 - February 24-28 - San Francisco, CA

Marketplace

> Whitepaper: Lopez Research: The New World of Mobility Management
> IT Made Easy with ManageEngine ServiceDesk Plus
> Whitepaper: DIY SharePoint - 6 Reasons to Enable Self-Service SharePoint Customization
> Whitepaper: Avoiding the top three challenges of custom-coded SharePoint applications
> eBook: Making BYOD Work
> Whitepaper: Best Practices for Migrating to SharePoint 2013

What's New

1. Adobe ups breach estimate from 2.9M to 38M affected users

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

The Adobe data breach affected 38 million active users of its products, the firm is now admitting.

Adobe spokesperson Heather Edell told security researcher Brian Krebs, who first uncovered the breach, that hackers were able to access Adobe IDs and encrypted passwords of 38 million active Adobe users, up from an original estimate of 2.9 million users

In addition, Edell said that Adobe had completed its email notification to all affected active users and had reset their passwords. However, Adobe has yet to assess the number of inactive, invalid and test accounts involved in the security incident.

Krebs said AnonNews.org posted a file called users.tar.gz "that appears to include more than 150 million username and hashed password pairs taken from Adobe. The 3.8 GB file looks to be the same one Hold Security CISO Alex Holden and I found on the server with the other data stolen from Adobe," he noted.

In addition to IDs and passwords, the hackers stole source code for Adobe Acrobat, Reader and ColdFusion. The theft of source code prompted Holden to call the breach "one of the worst in U.S. history."

Krebs said that AnonNews.org posted another file called ph1.tar.gz, which appears to be the source code for Adobe Photoshop. Edell confirmed that the hackers did get some of the Photoshop source code. "Our investigation to date indicates that a portion of Photoshop source code was accessed by the attackers as part of the incident Adobe publicly disclosed on Oct. 3," Edell said.

For more:
- check out KrebsonSecurity blog

Related Articles:
Adobe breach 'one of the worst in US history,' says security expert
Adobe plugs 14 security holes in its popular software

Read more about: Adobe, data breach
back to top


This week's sponsor is HP.

 

Know the Top 3 Mobile Application Threats
According to Morgan Stanley Research, the smart phone will become the dominant computing platform by the end of 2013, with more units being sold than desktop and laptop computers combined. Ease of use and flexibility have outpaced security. Download this paper to learn how to prevent sensitive data leakage over insecure channels or stolen devices.


2. Microsoft report finds decline in disclosed software vulnerabilities

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

Finally there is good news on the IT security front. Software vulnerability disclosures declined 10.1 percent in the first half of 2013 compared to the same period last year and 1.3 percent compared with the second half of 2012, according to the Microsoft Security Intelligence Report released this week.

An increase in operating system vulnerability disclosures in the first half of 2013 largely offset a corresponding decrease in application vulnerability disclosures during the same period, resulting in little overall change.

Overall, software vulnerability disclosures remain "significantly lower than they were prior to 2009, when totals of 3,500 disclosures or more per half-year period were not uncommon," Microsoft's SIR noted.

In terms of malware encounter versus infection rates, Microsoft found that about 17 percent of computers worldwide encountered malware each quarter in the first half of 2012, while Microsoft detected and removed malware from 0.6 percent of computers worldwide.

Web-based HTML/JavaScript threats continued to be the most commonly encountered type of exploit in the second quarter of 2013, followed by Java exploits and operating system exploits. An exploit is malware that takes advantage of software vulnerabilities to infect, disrupt or take control of a computer without the user's consent or knowledge, explained Microsoft.

The encounter rate for HTML/JavaScript exploits peaked in the first quarter, driven by the multi-platform exploit family Blacole, which was encountered by 1.12 percent of reporting computers. The most common exploit family in the first half of 2013 was the HTML/lframeRef, a generic detection for specially formed HTML inline frame tags that redirect to remote websites that contain malicious content.

For more:
- check out the Microsoft report

Related Articles:
Surge in hacker activities expected when Windows XP is retired
Microsoft joins bug bounty party with up to $100K grand prize

Read more about: Microsoft
back to top


3. Cisco patches remote code execution, DoS flaws in enterprise products

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

Cisco has issued critical security patches for a number of products, including its Identity Services Engine and IOS XR software.

The first patch plugs a security hole related to Apache's Struts 2 development framework used in a range of Cisco products, including its Business Edition 3000, ISE, Media Experience Engine and Unified SIP Proxy.

The Struts framework suffers from a remote code execution vulnerability that could enable an attacker to gain control of the targeted system by sending a crafted Java-based Object-Graph Navigation Language request.

Apache fixed the Struts vulnerability earlier this month with its latest version of Struts, 2.3.15.3, explained Chris Brook on the Threatpost blog.

Cisco plugged two other security holes in its ISE software, a policy control platform IT managers use to manage accounts. These holes are an authenticated arbitrary command execution vulnerability and a support information download authentication bypass vulnerability.

Exploiting the first hole, an attacker could execute arbitrary code on the underlying operating system, while, exploiting the second, an attacker could obtain sensitive information such as administrative credentials.

Finally, Cisco fixed a security problem with its IOS XR software used on routers. The hole involves improper handling of fragmented packets that could enable an attacker to carry out a denial of service attack. 

For more:
- read Brock's blog

Related Articles:
Cisco boosts network security portfolio with Sourcefire buy
Cisco, Fortinet, Juniper lead explosive MidEast, Africa security market
Spotlight: Cisco kicks off new security services division

Read more about: cisco, Vulnerability
back to top


4. BYOD, cloud fueling demand for mobile encryption products

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

BYOD and cloud-based applications are fueling the need for mobile encryption software and services, a market that is forecast by ABI Research to reach $230 million by the end of this year.

Enterprises that desire to maximize the benefits of mobile and cloud technologies are running headlong into IT's need to protect corporate assets and satisfy compliance requirements, notes ABI.

"For mobile encryption technology, this means effective key management. For authentication, it may be SSO [single sign-on] or tokenless access. The field of application for mobile authentication and encryption services is wide, and the demands are varied," ABI explained in a release.

"An innovative market in mobile-specific services for authenticating users and devices has cropped up to address the growing requirements for seamless and unified access. Encryption plays a vital role in enabling VPN [virtual private network] services, and the protection of data and applications," ABI added.

Mobile encryption services will need to be integrated with the enterprise's existing mobile device management or mobile application management products, ABI cautioned.

The market, which has not yet begun to consolidate, promises to offer opportunities for security vendors and MDM service providers. Original equipment manufacturers and mobile carriers are reluctant to invest in mobile encryption until market demand becomes clearer, ABI observed.

Leading mobile encryption vendors interviewed by ABI include Centrify, Corisecio, RSA, SafeLayer and SecurAuth.

For more:
- see ABI's release

Related Articles:
IBM develops two-factor authentication for mobile transactions
How much does mobile encryption help?

Read more about: encryption, Mobile Security
back to top


5. Enterprises struggle with access control rights

By Fred Donovan Comment | Forward | Twitter | Facebook | LinkedIn

Enterprises are granting excessive privileges and access to their most sensitive data, putting corporate and customer data at risk, according to a survey of 265 IT decision makers by security vendor BeyondTrust.

More than one-quarter of respondents admitted that they have retrieved corporate information--including financial reports, salaries, human resources data and personnel documents--not relevant to their jobs.

"To illustrate just how serious of an issue this is for organizations, one IT employee at a large, well-known critical infrastructure provider admitted to having retrieved financial reports while another IT employee at well well-known professional services firm admitted to retrieving R&D plans, neither of which was relevant to their jobs," BeyondTrust explained.

A full 80 percent believe that it is at least somewhat likely that employees access sensitive or confidential data out of curiosity.

More than half of respondents said they have the ability to circumvent access controls, and close to half of employees have unnecessary access rights, the survey found.

"Allowing any employee unfettered access to non-essential company data is both unnecessary and dangerous and should be an issue that is resolved quickly," said Brad Hibbert, executive vice president of product strategy at BeyondTrust.

In addition, more than three-quarters of respondents expect that the risk to their enterprises posed by privileged access abuse will increase over the next few years.

Christopher Zannetos, co-founder, president and CEO of Courion, a Westborough, Mass.-based identity and access management firm, noted in an exclusive interview with FierceMobileIT that privileged access abuse is a growing concern for the enterprise.

"This is the opportunity for our area of the market--identity and access management--whether it's a hacker trying to break in who sends out a phishing email or it's a malicious insider taking advantage of privileged account capabilities to do things of high impact to the organization. It all comes down to who is accessing what, and what are they doing with it," he observed.

For more:
- see the BeyondTrust's release
- check out the Infographic

Related Articles:
Q&A with Christopher Zannetos of Courion
Firms turn to IAM tools to fend off cybersecurity threats

Read more about: BeyondTrust, identity and access management
back to top


Also Noted

TODAY'S SPOTLIGHT... Australia upholds ban on Huawei

Australia's new government has decided to uphold the ban on Chinese telecom gear maker Huawei's participation in the country's national broadband network, based on advice from its national security agencies, according to report by newswire AFP. Last year, the previous Labor government banned Huawei from bidding for national broadband network contracts because of security concerns. The new Conservative government, which took power after winning national elections is September, said it would uphold the ban. "The decision of the previous government not to permit Huawei to tender for the NBN was made on advice from the national security agencies," Attorney-General George Brandis told the newswire in emailed comments. Read more

> Google's reCAPTCHA anti-bot service simplified for human users. Article (eWeek)
> UDP attacks increase as DDoS tactics shift. Article (Security Week)
> Bromium, 'microvisor' champion, raises $40 million more. Article (InformationWeek)
> Scan shows 65 percent of ReadyNAS boxes on web vulnerable to critical bug. Blog (Threatpost)
> Android madware and malware trends. Blog (Symantec)

And Finally… Prayer is not the answer to security. Article (InfoWorld)

Events

> RSA? Conference 2014 - February 24-28 - San Francisco, CA

Secure your seat at RSA® Conference 2014 Feb 24-28 in San Francisco and have access to 280+ expert-led sessions spanning 21 technical tracks, 350+ sponsors and exhibitors, unprecedented networking and not-to-be-missed closing keynotes. Register by Nov. 15 and save $700 on your 5-day Full Conference pass.

Marketplace

> Whitepaper: Lopez Research: The New World of Mobility Management

Mobility management continues to evolve as BYOD and mobile application deployments become more commonplace. There isn't a "one size fits all" strategy. It is important to implement an enterprise mobility management solution that secures corporate data while maintaining employee privacy and device usability. Download to learn more.

> IT Made Easy with ManageEngine ServiceDesk Plus

ManageEngine ServiceDesk Plus is an ITIL-Ready Help Desk Software with integrated asset and project management. True to our tagline, "IT Made Easy", ServiceDesk Plus wins hands down when it comes to ease of use, out of the box settings and integration. Visit http://www.servicedeskplus.com/ to check out the list of features that come at just $995 and to download a 30-Day Free Trial!

> Whitepaper: DIY SharePoint - 6 Reasons to Enable Self-Service SharePoint Customization

More companies find that "citizen developers" – end users, not IT developers - are creating business applications. In this white paper, discover six ways to embrace citizen development in a way that minimizes risk and maximizes SharePoint. Learn More

> Whitepaper: Avoiding the top three challenges of custom-coded SharePoint applications

In this white paper, learn about the challenges of custom coded SharePoint applications. Then, see how you can overcome them to create the SharePoint sites you want. Download Today!

> eBook: Making BYOD Work

Chief information officers and enterprise IT departments face a myriad of challenges when allowing employees to bring their own mobile devices into the work environment. FierceMobileIT explores how BYOD can work best for your enterprise to solve these problems. Download for free today.

> Whitepaper: Best Practices for Migrating to SharePoint 2013

SharePoint 2013 has the industry buzzing. It’s powerful and a vast improvement over previous versions. In this white paper, get best practice to ensure your migration to SharePoint 2013 is quick, easy and cost effective. Download Today!


©2013 FierceMarkets This email was sent to ignoble.experiment@arconati.us as part of the FierceITSecurity email list which is administered by FierceMarkets, 1900 L Street NW, Suite 400, Washington, DC 20036, (202) 628-8778.
Refer FierceITSecurity to a Colleague

Contact Us

Editor: Fred Donovan. VP sales and business development: Jack Fordi. Publisher: Ron Lichtinger.

Advertise

General advertising: Jack Fordi. Press releases: Fred Donovan. Request a media kit.

Email Management

Manage your subscription

Change your email address

Unsubscribe from FierceITSecurity

No comments:

Post a Comment

Keep a civil tongue.

Label Cloud

Technology (1464) News (793) Military (646) Microsoft (542) Business (487) Software (394) Developer (382) Music (360) Books (357) Audio (316) Government (308) Security (300) Love (262) Apple (242) Storage (236) Dungeons and Dragons (228) Funny (209) Google (194) Cooking (187) Yahoo (186) Mobile (179) Adobe (177) Wishlist (159) AMD (155) Education (151) Drugs (145) Astrology (139) Local (137) Art (134) Investing (127) Shopping (124) Hardware (120) Movies (119) Sports (109) Neatorama (94) Blogger (93) Christian (67) Mozilla (61) Dictionary (59) Science (59) Entertainment (50) Jewelry (50) Pharmacy (50) Weather (48) Video Games (44) Television (36) VoIP (25) meta (23) Holidays (14)

Popular Posts (Last 7 Days)