Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How (And Why) Hackers Target Your Business
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/28/2016 | 12:34:41 PM
Re: More that the Dollar Bill
I think that was also a Fairly Oddparents episode.  ;)
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
1/28/2016 | 11:45:54 AM
Re: More that the Dollar Bill
Joe, I think the orphan scenario presents challenges, but doesn't require tools other than what is out there already.  While a person won't be at the other end of the orphan's data stream to receive/utilize stolen info, or to update instructions/features, there is risk that a potential step-parent could stumble upon them and take over their use.  If dormant, all you can do is use existing tools to comb through systems and look for known signatures in activity and code profiles.  If active and trying to reach out to its absent parent or systems long down where data would have been sent, all the same network and data analysis tools would be used to detect aberrant activity.  

Of course, if this were Ghost in the Shell, things would be a whole lot more interesting and there's be AI-driven bots out there hunting down these orphans and shredding them into digital oblivion... sorry, got carried away there :-)
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/27/2016 | 3:36:35 PM
Re: More that the Dollar Bill
@Christian: I'm curious to what extent "good-guy" AI tools could be used to help defeat the "self-aware" bots and tools out there that you mention.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 10:45:40 PM
Re: More that the Dollar Bill
And we haven't even mentioned autonomous RATs, bots and spiders!  There's nothing more exciting (or tragic) than trying to anticipate through the chaos of "self-sufficient" and "self-aware" hacking tools when they will next strike.  How many of these things are out there, now orphans, their creators long gone, still infecting and attacking systems...
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
1/25/2016 | 7:01:08 PM
Re: More that the Dollar Bill
It's also important to consider the potential links between ability of hackers to do damage and the kind of damage they are looking to do.  The quality of attacks you'll face from Russian cybergangs looking to make some fast bucks will be very different from the quality of attacks you'll face from Chinese nation-state hackers, which in turn are very different from the quality of attacks you'll face from independent hacktivists.  Additionally, different things are at stake in all three examples.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 6:42:56 PM
More that the Dollar Bill
I look forward to the panel.  I think it is also important to remind companies that hackers are not always in their business for the money.  This is an important distinction because tactics change between those seeking profit and those seeking information, or to do harm.  Especially with mega corporations who may have leadership who are clueless as to why someone would have a grudge against their company, making the assumption that cyber attackers are only there for the money could cost dearly.  Also, how one responds to a cyber-attack might depend upon whether they are just thieves, or on a mission driven by a cause.  It's definitely a new era and "hackers" are far more than the band of thieves many imagine they are.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/6/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15505
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1, and Sentry before 9.7.3 and 9.8.x before 9.8.1, allow remote attackers to execute arbitrary code via unspecified vectors.
CVE-2020-15506
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1 allow remote attackers to bypass authentication mechanisms via unspecified vectors.
CVE-2020-15507
PUBLISHED: 2020-07-07
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10.5.2.x before 10.5.2.1, and 10.6.x before 10.6.0.1 allow remote attackers to read files on the system via unspecified vectors.
CVE-2020-15096
PUBLISHED: 2020-07-07
In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affecte...
CVE-2020-4075
PUBLISHED: 2020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` on all new-window events where the `url` or `options` is not ...