Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How (And Why) Hackers Target Your Business
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/28/2016 | 12:34:41 PM
Re: More that the Dollar Bill
I think that was also a Fairly Oddparents episode.  ;)
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
1/28/2016 | 11:45:54 AM
Re: More that the Dollar Bill
Joe, I think the orphan scenario presents challenges, but doesn't require tools other than what is out there already.  While a person won't be at the other end of the orphan's data stream to receive/utilize stolen info, or to update instructions/features, there is risk that a potential step-parent could stumble upon them and take over their use.  If dormant, all you can do is use existing tools to comb through systems and look for known signatures in activity and code profiles.  If active and trying to reach out to its absent parent or systems long down where data would have been sent, all the same network and data analysis tools would be used to detect aberrant activity.  

Of course, if this were Ghost in the Shell, things would be a whole lot more interesting and there's be AI-driven bots out there hunting down these orphans and shredding them into digital oblivion... sorry, got carried away there :-)
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
1/27/2016 | 3:36:35 PM
Re: More that the Dollar Bill
@Christian: I'm curious to what extent "good-guy" AI tools could be used to help defeat the "self-aware" bots and tools out there that you mention.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 10:45:40 PM
Re: More that the Dollar Bill
And we haven't even mentioned autonomous RATs, bots and spiders!  There's nothing more exciting (or tragic) than trying to anticipate through the chaos of "self-sufficient" and "self-aware" hacking tools when they will next strike.  How many of these things are out there, now orphans, their creators long gone, still infecting and attacking systems...
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
1/25/2016 | 7:01:08 PM
Re: More that the Dollar Bill
It's also important to consider the potential links between ability of hackers to do damage and the kind of damage they are looking to do.  The quality of attacks you'll face from Russian cybergangs looking to make some fast bucks will be very different from the quality of attacks you'll face from Chinese nation-state hackers, which in turn are very different from the quality of attacks you'll face from independent hacktivists.  Additionally, different things are at stake in all three examples.
RetiredUser
100%
0%
RetiredUser,
User Rank: Ninja
1/25/2016 | 6:42:56 PM
More that the Dollar Bill
I look forward to the panel.  I think it is also important to remind companies that hackers are not always in their business for the money.  This is an important distinction because tactics change between those seeking profit and those seeking information, or to do harm.  Especially with mega corporations who may have leadership who are clueless as to why someone would have a grudge against their company, making the assumption that cyber attackers are only there for the money could cost dearly.  Also, how one responds to a cyber-attack might depend upon whether they are just thieves, or on a mission driven by a cause.  It's definitely a new era and "hackers" are far more than the band of thieves many imagine they are.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-2464
PUBLISHED: 2021-09-24
Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Linux executes to compromise Oracle Linux. Successful attacks of this vulnerability ca...
CVE-2021-39246
PUBLISHED: 2021-09-24
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. If --log or --verbose is used, exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp...
CVE-2021-22868
PUBLISHED: 2021-09-24
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance...
CVE-2021-22869
PUBLISHED: 2021-09-24
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group co...
CVE-2021-35313
PUBLISHED: 2021-09-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.