Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How (And Why) Hackers Target Your Business
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/28/2016 | 12:34:41 PM
Re: More that the Dollar Bill
I think that was also a Fairly Oddparents episode.  ;)
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
1/28/2016 | 11:45:54 AM
Re: More that the Dollar Bill
Joe, I think the orphan scenario presents challenges, but doesn't require tools other than what is out there already.  While a person won't be at the other end of the orphan's data stream to receive/utilize stolen info, or to update instructions/features, there is risk that a potential step-parent could stumble upon them and take over their use.  If dormant, all you can do is use existing tools to comb through systems and look for known signatures in activity and code profiles.  If active and trying to reach out to its absent parent or systems long down where data would have been sent, all the same network and data analysis tools would be used to detect aberrant activity.  

Of course, if this were Ghost in the Shell, things would be a whole lot more interesting and there's be AI-driven bots out there hunting down these orphans and shredding them into digital oblivion... sorry, got carried away there :-)
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/27/2016 | 3:36:35 PM
Re: More that the Dollar Bill
@Christian: I'm curious to what extent "good-guy" AI tools could be used to help defeat the "self-aware" bots and tools out there that you mention.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 10:45:40 PM
Re: More that the Dollar Bill
And we haven't even mentioned autonomous RATs, bots and spiders!  There's nothing more exciting (or tragic) than trying to anticipate through the chaos of "self-sufficient" and "self-aware" hacking tools when they will next strike.  How many of these things are out there, now orphans, their creators long gone, still infecting and attacking systems...
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
1/25/2016 | 7:01:08 PM
Re: More that the Dollar Bill
It's also important to consider the potential links between ability of hackers to do damage and the kind of damage they are looking to do.  The quality of attacks you'll face from Russian cybergangs looking to make some fast bucks will be very different from the quality of attacks you'll face from Chinese nation-state hackers, which in turn are very different from the quality of attacks you'll face from independent hacktivists.  Additionally, different things are at stake in all three examples.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 6:42:56 PM
More that the Dollar Bill
I look forward to the panel.  I think it is also important to remind companies that hackers are not always in their business for the money.  This is an important distinction because tactics change between those seeking profit and those seeking information, or to do harm.  Especially with mega corporations who may have leadership who are clueless as to why someone would have a grudge against their company, making the assumption that cyber attackers are only there for the money could cost dearly.  Also, how one responds to a cyber-attack might depend upon whether they are just thieves, or on a mission driven by a cause.  It's definitely a new era and "hackers" are far more than the band of thieves many imagine they are.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Data Breaches Affect the Enterprise
Data breaches continue to cause negative outcomes for companies worldwide. However, many organizations report that major impacts have declined significantly compared with a year ago, suggesting that many have gotten better at containing breach fallout. Download Dark Reading's Report "How Data Breaches Affect the Enterprise" to delve more into this timely topic.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-4020
PUBLISHED: 2021-11-27
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23654
PUBLISHED: 2021-11-26
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via C...
CVE-2021-43785
PUBLISHED: 2021-11-26
@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious...
CVE-2021-43776
PUBLISHED: 2021-11-26
Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other se...
CVE-2021-41243
PUBLISHED: 2021-11-26
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be add...