What's New The Adobe data breach affected 38 million active users of its products, the firm is now admitting. Adobe spokesperson Heather Edell told security researcher Brian Krebs, who first uncovered the breach, that hackers were able to access Adobe IDs and encrypted passwords of 38 million active Adobe users, up from an original estimate of 2.9 million users. In addition, Edell said that Adobe had completed its email notification to all affected active users and had reset their passwords. However, Adobe has yet to assess the number of inactive, invalid and test accounts involved in the security incident. Krebs said AnonNews.org posted a file called users.tar.gz "that appears to include more than 150 million username and hashed password pairs taken from Adobe. The 3.8 GB file looks to be the same one Hold Security CISO Alex Holden and I found on the server with the other data stolen from Adobe," he noted. In addition to IDs and passwords, the hackers stole source code for Adobe Acrobat, Reader and ColdFusion. The theft of source code prompted Holden to call the breach "one of the worst in U.S. history." Krebs said that AnonNews.org posted another file called ph1.tar.gz, which appears to be the source code for Adobe Photoshop. Edell confirmed that the hackers did get some of the Photoshop source code. "Our investigation to date indicates that a portion of Photoshop source code was accessed by the attackers as part of the incident Adobe publicly disclosed on Oct. 3," Edell said. For more: - check out KrebsonSecurity blog Related Articles: Adobe breach 'one of the worst in US history,' says security expert Adobe plugs 14 security holes in its popular software Read more about: Adobe, data breach back to top | This week's sponsor is HP. |  | Know the Top 3 Mobile Application Threats According to Morgan Stanley Research, the smart phone will become the dominant computing platform by the end of 2013, with more units being sold than desktop and laptop computers combined. Ease of use and flexibility have outpaced security. Download this paper to learn how to prevent sensitive data leakage over insecure channels or stolen devices. | Finally there is good news on the IT security front. Software vulnerability disclosures declined 10.1 percent in the first half of 2013 compared to the same period last year and 1.3 percent compared with the second half of 2012, according to the Microsoft Security Intelligence Report released this week. An increase in operating system vulnerability disclosures in the first half of 2013 largely offset a corresponding decrease in application vulnerability disclosures during the same period, resulting in little overall change. Overall, software vulnerability disclosures remain "significantly lower than they were prior to 2009, when totals of 3,500 disclosures or more per half-year period were not uncommon," Microsoft's SIR noted. In terms of malware encounter versus infection rates, Microsoft found that about 17 percent of computers worldwide encountered malware each quarter in the first half of 2012, while Microsoft detected and removed malware from 0.6 percent of computers worldwide. Web-based HTML/JavaScript threats continued to be the most commonly encountered type of exploit in the second quarter of 2013, followed by Java exploits and operating system exploits. An exploit is malware that takes advantage of software vulnerabilities to infect, disrupt or take control of a computer without the user's consent or knowledge, explained Microsoft. The encounter rate for HTML/JavaScript exploits peaked in the first quarter, driven by the multi-platform exploit family Blacole, which was encountered by 1.12 percent of reporting computers. The most common exploit family in the first half of 2013 was the HTML/lframeRef, a generic detection for specially formed HTML inline frame tags that redirect to remote websites that contain malicious content. For more: - check out the Microsoft report Related Articles: Surge in hacker activities expected when Windows XP is retired Microsoft joins bug bounty party with up to $100K grand prize Read more about: Microsoft back to top Cisco has issued critical security patches for a number of products, including its Identity Services Engine and IOS XR software. The first patch plugs a security hole related to Apache's Struts 2 development framework used in a range of Cisco products, including its Business Edition 3000, ISE, Media Experience Engine and Unified SIP Proxy. The Struts framework suffers from a remote code execution vulnerability that could enable an attacker to gain control of the targeted system by sending a crafted Java-based Object-Graph Navigation Language request. Apache fixed the Struts vulnerability earlier this month with its latest version of Struts, 2.3.15.3, explained Chris Brook on the Threatpost blog. Cisco plugged two other security holes in its ISE software, a policy control platform IT managers use to manage accounts. These holes are an authenticated arbitrary command execution vulnerability and a support information download authentication bypass vulnerability. Exploiting the first hole, an attacker could execute arbitrary code on the underlying operating system, while, exploiting the second, an attacker could obtain sensitive information such as administrative credentials. Finally, Cisco fixed a security problem with its IOS XR software used on routers. The hole involves improper handling of fragmented packets that could enable an attacker to carry out a denial of service attack. For more: - read Brock's blog Related Articles: Cisco boosts network security portfolio with Sourcefire buy Cisco, Fortinet, Juniper lead explosive MidEast, Africa security market Spotlight: Cisco kicks off new security services division Read more about: cisco, Vulnerability back to top BYOD and cloud-based applications are fueling the need for mobile encryption software and services, a market that is forecast by ABI Research to reach $230 million by the end of this year. Enterprises that desire to maximize the benefits of mobile and cloud technologies are running headlong into IT's need to protect corporate assets and satisfy compliance requirements, notes ABI. "For mobile encryption technology, this means effective key management. For authentication, it may be SSO [single sign-on] or tokenless access. The field of application for mobile authentication and encryption services is wide, and the demands are varied," ABI explained in a release. "An innovative market in mobile-specific services for authenticating users and devices has cropped up to address the growing requirements for seamless and unified access. Encryption plays a vital role in enabling VPN [virtual private network] services, and the protection of data and applications," ABI added. Mobile encryption services will need to be integrated with the enterprise's existing mobile device management or mobile application management products, ABI cautioned. The market, which has not yet begun to consolidate, promises to offer opportunities for security vendors and MDM service providers. Original equipment manufacturers and mobile carriers are reluctant to invest in mobile encryption until market demand becomes clearer, ABI observed. Leading mobile encryption vendors interviewed by ABI include Centrify, Corisecio, RSA, SafeLayer and SecurAuth. For more: - see ABI's release Related Articles: IBM develops two-factor authentication for mobile transactions How much does mobile encryption help? Read more about: encryption, Mobile Security back to top Enterprises are granting excessive privileges and access to their most sensitive data, putting corporate and customer data at risk, according to a survey of 265 IT decision makers by security vendor BeyondTrust. More than one-quarter of respondents admitted that they have retrieved corporate information--including financial reports, salaries, human resources data and personnel documents--not relevant to their jobs. "To illustrate just how serious of an issue this is for organizations, one IT employee at a large, well-known critical infrastructure provider admitted to having retrieved financial reports while another IT employee at well well-known professional services firm admitted to retrieving R&D plans, neither of which was relevant to their jobs," BeyondTrust explained. A full 80 percent believe that it is at least somewhat likely that employees access sensitive or confidential data out of curiosity. More than half of respondents said they have the ability to circumvent access controls, and close to half of employees have unnecessary access rights, the survey found. "Allowing any employee unfettered access to non-essential company data is both unnecessary and dangerous and should be an issue that is resolved quickly," said Brad Hibbert, executive vice president of product strategy at BeyondTrust. In addition, more than three-quarters of respondents expect that the risk to their enterprises posed by privileged access abuse will increase over the next few years. Christopher Zannetos, co-founder, president and CEO of Courion, a Westborough, Mass.-based identity and access management firm, noted in an exclusive interview with FierceMobileIT that privileged access abuse is a growing concern for the enterprise. "This is the opportunity for our area of the market--identity and access management--whether it's a hacker trying to break in who sends out a phishing email or it's a malicious insider taking advantage of privileged account capabilities to do things of high impact to the organization. It all comes down to who is accessing what, and what are they doing with it," he observed. For more: - see the BeyondTrust's release - check out the Infographic Related Articles: Q&A with Christopher Zannetos of Courion Firms turn to IAM tools to fend off cybersecurity threats Read more about: BeyondTrust, identity and access management back to top |
No comments:
Post a Comment
Keep a civil tongue.