Cisco
security unit pulls plug on ransomware scammer
By Pete Carey /
October 6, 2015 at 9:03 AM
Cisco Systems’ Talos security unit said
Tuesday that it has pulled the plug on a pernicious group that
encrypted people’s computer files and demanded payment to decrypt them.
Talos threat research Nick Biasini said his group had
disrupted a group using the Angler Exploit Kit to target 90,000 victims a day,
generating more than $30 million annually in ransom. The kit has been used by
other groups for a combined $60 million in annual ransom, the company reported.
“Cisco determined that an inordinate number of proxy servers
used by Angler were located on servers of service provider Limestone Networks,”
he reported.
The crooks had used stolen credit cards for servers on
Limestone’s system. The company pulled the plug on them when Cisco contacted
it, and cooperated with security researchers, according to a report by Reuters.
The Talos unit collaborated with Level 3 Threat Research
Labs and OpenDNS to peer over the shoulder of the scammers and see how they
operated.
Then Cisco broadcast Angler protocols and mechanisms “so
others can protect their communities,” Biasini wrote.
“This is a significant blow to the emerging hacker economy
where ransomware and the black market sale of stolen IP (intellectual
property), credit card info and personally identifiable information are
generating hundreds of millions of dollars annually.”
| ||
======================================================= https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618 ============================================== Special Bulletin - My just released book, "You're Hired. Super Charge our Email Skills in 60 Minutes! (And Get That Job...) is now on sales at Amazon.comGreat Reasons for Purchasing Netiquette IQ
·
Get more
email opens. Improve 100% or more.
·
Receive
more responses, interviews, appointments, prospects and sales.
·
Be better
understood.
·
Eliminate
indecision.
·
Avoid
being spammed 100% or more.
·
Have
recipient finish reading your email content.
·
Save time
by reducing questions.
·
Increase
your level of clarity.
·
Improve
you time management with your email.
·
Have
quick access to a wealth of relevant email information.
Enjoy
most of what you need for email in a single book.
================================================**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:www.tabularosa.net In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at: www.amazon.com/author/paulbabicki If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo. I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications.
Lastly, I
am the founder and president of Tabula
Rosa Systems, a company that provides “best of breed” products for network,
security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT
product information for virtually anyone.
|
Tuesday, October 6, 2015
Tabula Rosa Systems Blog of 10/6/2015 - Cisco security unit pulls plug on ransomware scammer
Monday, October 5, 2015
Tabula Rosa Systems Blog Of The Day - Most People Say Email Etiquette Can Make or Break a Deal
The power of good Netiquette can go a very long ways in so many respects. One obvious one is jobs, another is education.
The article below is relevant to many area of employment and presents some great statistics and facts.
Good Netiquette For All!
=====================
===================================================
Have you ever wondered how it would be if your email suddenly came to life? You are about to find out.
====================================================
https://www.youtube.com/watch?v=HTgYHHKs0ZwThe article below is relevant to many area of employment and presents some great statistics and facts.
Good Netiquette For All!
=====================
Most People Say Email Etiquette Can Make or Break
a Deal
from inc.com by Kelsey Liebert
from inc.com by Kelsey Liebert
Fractl and BuzzStream surveyed more
than 1,200 men and women between the ages of 18 and 64 to find out how email
best practices differ by gender, age, and education. Here's what we found.
Within 100
milliseconds of viewing someone's face, your brain forms assumptions
on an individual's attractiveness, likability, trustworthiness, competence, and
aggressiveness. So, what happens in a lean communication channel like email,
where you only have 100 to 300 words to connect with a stranger?
Fractl and BuzzStream surveyed more than 1,200 men
and women between the ages of 18 and 64 to find out how email best practices
differ by gender, age, and education. Here's what they found.
1. More than 78 percent of respondents said email
etiquette had an impact on their decision to engage with a stranger.
2. More than 88 percent of people have rewritten emails
to sound more intelligent.
3. Older demographics want to be perceived as more
authentic, while younger demographics want to sound more educated.
4. 60 percent of people agree that brevity is most
acceptable, whereas 48 percent think wordiness is mostly unacceptable.
5. More than 60 percent of people believe humor in email
is acceptable.
6. 70 percent of people find excessive punctuation in an
email is unacceptable.
7. More than 30 percent of people think it's of little
importance to link to social networks in an email signature.
Published on: Apr 13, 2015
===================================================
Have you ever wondered how it would be if your email suddenly came to life? You are about to find out.
====================================================
===========================================================
**Important note** - contact our sister company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:
www.tabularosa.net
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
www.amazon.com/author/paulbabicki
If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo. I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications.
Lastly, I
am the founder and president of Tabula
Rosa Systems, a company that provides “best of breed” products for network,
security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT
product information for virtually anyone.
==============================================
Great
Reasons for Purchasing Netiquette IQ
·
Get more
email opens. Improve 100% or more.
·
Receive
more responses, interviews, appointments, prospects and sales.
·
Be better
understood.
·
Eliminate
indecision.
·
Avoid
being spammed 100% or more.
·
Have
recipient finish reading your email content.
·
Save time
by reducing questions.
·
Increase
your level of clarity.
·
Improve
you time management with your email.
·
Have
quick access to a wealth of relevant email information.
Enjoy
most of what you need for email in a single book.
Tabula Rosa Systems Security Bulletin - Summary for the Week of September 28, 2015
National Cyber Awareness System:
10/05/2015 08:22 AM EDT
Original
release date: October 05, 2015
The US-CERT Cyber Security Bulletin provides a
summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology
(NIST) National Vulnerability Database (NVD)
in the past week. The NVD is sponsored by the Department
of Homeland Security (DHS) National
Cybersecurity and Communications Integration Center (NCCIC) / United States Computer Emergency Readiness Team
(US-CERT). For modified or updated entries, please visit the NVD, which contains historical
vulnerability information.
======================================================= https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618 ============================================== Special Bulletin - My just released book, "You're Hired. Super Charge our Email Skills in 60 Minutes! (And Get That Job...) is now on sales at Amazon.comGreat Reasons for Purchasing Netiquette IQ
·
Get more
email opens. Improve 100% or more.
·
Receive
more responses, interviews, appointments, prospects and sales.
·
Be better
understood.
·
Eliminate
indecision.
·
Avoid
being spammed 100% or more.
·
Have
recipient finish reading your email content.
·
Save time
by reducing questions.
·
Increase
your level of clarity.
·
Improve
you time management with your email.
·
Have
quick access to a wealth of relevant email information.
Enjoy
most of what you need for email in a single book.
================================================**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions: www.tabularosa.net In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at: www.amazon.com/author/paulbabicki If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo. I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications.
Lastly, I
am the founder and president of Tabula
Rosa Systems, a company that provides “best of breed” products for network,
security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT
product information for virtually anyone.
|
Sunday, October 4, 2015
Tabula Rosa Systems - How Will The Internet Of Things Be Securely Supported?
| by John Dixon www.teccrunch.com | ||
|
The
Internet of Things (IoT) presents a significant mix of opportunity and
risk. Compared to the connected devices of the past, the gazillions of new IoT
devices that are being predicted for our homes, transportation, cities, medical
devices and elsewhere represent a unique set of security challenges for both
companies and their users.
They also offer a
host of new and attractive opportunity for attackers.
To start, IoT devices
significantly expand the attack surface. Hackers can easily purchase any IoT
device, which will often contain the same security features of other, identical
devices already deployed in hundreds or even thousands of homes. Unlike servers
or networking equipment, which are usually hacked through remote access points
and reside in protected and monitored environments, IoT devices are more
accessible to malicious threat actors.
The widespread
availability and proliferation of these devices means that once a device is
compromised, it’s very difficult for a company to flip a switch and update the
millions of devices just like it sold around the world. It also means that
hackers can use one insecure device to leapfrog their way into broader
connected networks, allowing a single device to compromise sensitive data
ranging from bank and health information to even access to broader corporate
assets as the line between work and home continues to blur.
The Internet of
Things presents a significant mix of opportunity and risk.
It’s also important
to think about the companies producing today’s top IoT devices. Often, these
companies are startups, which may not have the funds to bring to bear an army
of security experts and white hats to ensure secure deployments. Instead, they
must rely on the hardware and software provided to them through suppliers. And
commodity pricing places an enormous strain on security engineering and
maintenance. Many of the IoT devices on today’s shelves are by necessity
inexpensive to manufacture, which means companies are less likely to spend high
dollar on security throughout the development process.
Now is the time for
the technology industry to proactively address these concerns, before the
threat of widespread IoT security breaches becomes a reality. The standards
groups, enterprise organizations and the legions of startups and maker
communities working in this area must join together and get to work on
addressing the critical issue of safeguarding the IoT before it’s too late.
Getting Started
The good news is the
tech industry recognizes that something needs to be done about IoT security,
both through industry groups and at the company level. For example, the
International Standards Organization (ISO) has a working group assessing how the
ISO 27000 family of security standards might be adapted to address IoT security needs, while
the IEEE Standards Association is working on anarchitectural
framework that is
expected to address IoT security, privacy and safety issues.
What’s also encouraging
is the formation of several IoT vendor alliances, including theThread Group, the Open Interconnect Consortium, the AllSeen Alliance and theIndustrial Internet Consortium.
Although each is focused on a different IoT developer and user community, all
of the groups appear to be supporting the wider use of data encryption and
other security measures.
Daunting Challenges
Despite progress, the
task of securing the IoT still faces many daunting challenges.
McKinsey & Co.
and the Global Semiconductor Alliance (GSA) recently reported that
while some parts of the IoT landscape have well-defined standards, other
aspects either have none or multiple, competing standards.
Additionally, and
although helpful for handling the expected flood of IoT
data, software-defined networking (SDN) is creating added security
concerns because of its use of multiple communications channels and
remotely located computing resources.
Advances in
autonomous driving — such as those that will require cars to connect to each
other and to roadway infrastructure — will spur the need for more robust
safety, security and risk mitigation.
Lastly, and most
importantly, leading technology companies still haven’t fully committed
themselves to finding solutions for securing IoT applications.
Despite
progress, the task of securing the IoT still faces many daunting challenges.
If today’s titans of
technology won’t step up to secure the IoT, that vital endeavor may fall to the
multitude of startup companies that are fueling much of the industry’s current
growth. Gartner estimates that by 2017, more
than half of all IoT
products and services will be developed by companies less than three years old.
And while some of these newcomers are likely to have formidable technical
expertise, many will lack the knowhow or capability to implement the tight
security that is needed.
Securing The Future
As an industry, how
can we support this new generation of technologists and equip them with the
deep expertise and context necessary to create a truly secure IoT?
First, we should
encourage them to collaborate more closely with silicon vendors’ software, hardware
and manufacturing ecosystems. Chip vendors and their partners can be invaluable
guides for inexperienced product developers learning to navigate the complex
array of available security standards and components.
We also can do
better at education. A primary example of how this is being addressed is the
establishment of security labs, such as those launched by Microsoft, Breed
Reply and Indiegogo, where developers and partners can get hands-on access to
systems and test beds to help advance development. Participants learn that
security must be considered from the beginning of every IoT project, and should
remain a priority through design, development and manufacturing — and even
after the product or service is in operation.
In a perfect world,
security risks and breaches wouldn’t exist. But, as virtually everything in our
Internet-enabled world becomes increasingly connected, everything is becoming
accessible and, therefore, potentially vulnerable. We may never fully solve
that fundamental contradiction, but by working together, we can begin to build
the secure IoT that the world deserves.
| ||
======================================================= https://www.youtube.com/watch?v=HTgYHHKs0Zw&__scoop_post=bcaa0440-2548-11e5-c1bd-90b11c3d2b20&__scoop_topic=2455618 ============================================== Special Bulletin - My just released book, "You're Hired. Super Charge our Email Skills in 60 Minutes! (And Get That Job...) is now on sales at Amazon.comGreat Reasons for Purchasing Netiquette IQ
·
Get more
email opens. Improve 100% or more.
·
Receive
more responses, interviews, appointments, prospects and sales.
·
Be better
understood.
·
Eliminate
indecision.
·
Avoid
being spammed 100% or more.
·
Have
recipient finish reading your email content.
·
Save time
by reducing questions.
·
Increase
your level of clarity.
·
Improve
you time management with your email.
·
Have
quick access to a wealth of relevant email information.
Enjoy
most of what you need for email in a single book.
================================================**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions: www.tabularosa.net In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at: www.amazon.com/author/paulbabicki If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo. I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications.
Lastly, I
am the founder and president of Tabula
Rosa Systems, a company that provides “best of breed” products for network,
security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT
product information for virtually anyone.
|
Tabula Rosa Systems Blog Of 10/4/2015
Many companies and users are implementing encryption for their email. Even though this offers
create security, governments are quite often opposed for reasons noted
in the article below. Additionally, there is a possibility that by
encrypting traffic, there is no checking for malware which might be a
part of the payload.
==============================================================
infoworld.com 7/9/2015 - Grant Gross
==============================================================
infoworld.com 7/9/2015 - Grant Gross
FBI, DOJ want companies to back
off end-to-end encryption
The agencies want tech vendors to retain access to encrypted data to
comply with court-ordered warrants
U.S. tech companies should retain access to the encrypted information of
their customers, instead of providing end-to-end encryption, in order to give
police the tools they need to investigate crimes and terrorist activity, two
senior law enforcement officials said.
The U.S. Department of Justice and the FBI aren't seeking new legislation
to require tech companies to comply with warrant requests, at least for now,
and they don't want companies to build encryption back doors that give the
agencies direct access to communications and information stored on smartphones,
said Sally Quillian Yates, the DOJ's deputy attorney general.
Instead, the DOJ and FBI, in their continuing efforts to combat the use of
encryption by criminals and terrorists, are proposing that tech and
communications companies retain internal access to encrypted information so
that they can comply with court-ordered search warrants, she told the Senate
Judiciary Committee Wednesday. Several tech companies already retain some
access to customers' encrypted data, she said.
Legislation may eventually be necessary, but the DOJ is now looking for
voluntary compliance from tech companies, she said.
With new encryption services from tech companies, "critical
information becomes, in effect, warrant-proof," Yates said. "We are
creating safe zones where dangerous criminals and terrorists can operate and
avoid detection."
A recent push by tech companies toward end-to-end encryption, partly in
response to reports of mass surveillance programs, has led the DOJ and FBI to
raise concerns about law enforcement agencies "going dark" when
investigating crime. Last September, FBI Director James Comey Jr. first questioned decisions by Apple and Google to offer
encryption by default on their smartphone operating systems.
"The world has changed in the last two years," Comey told
senators. "Encryption has moved from something available to something that
is the default, both on devices and on data in motion."
Terrorist group ISIL (Islamic State of Iraq and the Levant) has used
encryption effectively, Yates said. ISIL makes first contact with many
potential recruits on Twitter, where the group has about 21,000 followers of
its English language feed, but then directs them to communicate further on an
encrypted messaging service, she said.
"This is a serious threat, and our inability to access these
communications with valid court orders is a real national security
problem," Yates added. "We must find a solution to this pressing
problem, and we need to find it soon."
U.S. tech companies should be able to find a way to provide law enforcement
access to encrypted data and still provide many of the security and privacy
benefits of encryption, Comey said. "The tools we are being asked to use
are increasingly ineffective in our national security work and in our criminal
work," he said. "I don't come with a solution -- this is a really,
really hard problem."
But Comey also rejected arguments by some computer scientists who say it's impossible to allow
police access to encrypted data without also opening it up to hackers.
"I think Silicon Valley is full of folks [who] have built remarkable
things that changed our lives," he said. "Maybe this is too hard, but
given the stakes ... we've got to give it a shot."
While companies like Google and Apple were not included in the hearing,
senators gave a mixed reaction to the testimonies of Yates and Comey. Some
senators suggested it would be nearly impossible to prevent foreign tech
vendors from offering encrypted communication products.
Senator Al Franken, a Minnesota Democrat, pressed Yates to provide
statistics about the number of criminal cases affected by encrypted data.
Before creating new regulations, Congress needs to have a "clear
understanding of the scope and the magnitude of law enforcement's security
interests," Franken said.
Bottom of
Form
Yates couldn't provide a number of cases affected, saying it was difficult
because, in many cases, police don't seek a warrant when they know the
information they want is encrypted. But Cyrus Vance Jr., district attorney in
Manhattan, told senators his office has tried to pull data off 92 Apple phones
running iOS 8 in the past six months, and on 74 of those devices, the data was
encrypted.
Other senators were sympathetic to the encryption dilemma faced by law
enforcement agencies. Senator John Cornyn, a Texas Republican, pressed Comey to
tell lawmakers that U.S. residents will die if a solution wasn't found. Comey
declined, saying he doesn't want to scare people. The FBI will do the best job
it can with the crime-fighting tools it has, he said.
Still, Cornyn questioned companies that offer encryption without retaining
some access to the data. "It strikes me as irresponsible, and perhaps
worse, for a company to intentionally design a product in such a way that
prevents them from complying with a lawful court order," he said.
==========================================================**Important note** - contact our company for very powerful solutions for IP management (IPv4 and IPv6, security, firewall and APT solutions:
www.tabularosa.net
In addition to this blog, Netiquette IQ has a website with great assets which are being added to on a regular basis. I have authored the premiere book on Netiquette, “Netiquette IQ - A Comprehensive Guide to Improve, Enhance and Add Power to Your Email". My new book, “You’re Hired! Super Charge Your Email Skills in 60 Minutes. . . And Get That Job!” will be published soon follow by a trilogy of books on Netiquette for young people. You can view my profile, reviews of the book and content excerpts at:
www.amazon.com/author/paulbabicki
If you would like to listen to experts in all aspects of Netiquette and communication, try my radio show on BlogtalkRadio Additionally, I provide content for an online newsletter via paper.li. I have also established Netiquette discussion groups with Linkedin and Yahoo. I am also a member of the International Business Etiquette and Protocol Group and Minding Manners among others. Further, I regularly consult for the Gerson Lehrman Group, a worldwide network of subject matter experts and have been a contributor to numerous blogs and publications.
Lastly, I
am the founder and president of Tabula
Rosa Systems, a company that provides “best of breed” products for network,
security and system management and services. Tabula Rosa has a new blog and Twitter site which offers great IT
product information for virtually anyone.
==============================================
Subscribe to:
Posts (Atom)


















