Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/17/2011
12:26 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

RSA Combines Blacklist Data Feeds And Threat Monitoring In RSA CyberCrime Intelligence Service

RSA CyberCrime Intelligence Service offers new daily reports on black-listed hosts and IP addresses

BEDFORD, Mass., Aug. 17, 2011 /PRNewswire/ --

News Summary:

-- RSA announces significant new features available in the RSA(SM) CyberCrime Intelligence Service -- RSA CyberCrime Intelligence is a managed service engineered to provide information about external threats and data compromise to help enterprises monitor and harden their infrastructure against malware infection and data loss -- New daily "blacklist" reports on live malware domains can help organizations proactively block malicious traffic from Trojans and phishing sites -- Professional services consulting to help organizations improve security policies and controls

RSA, The Security Division of EMC (NYSE: EMC) announced significant updates to its RSA(SM) CyberCrime Intelligence Service designed to help enterprises monitor and harden their infrastructure against malware infection and data loss. Offered to complement RSA's broad portfolio of security and threat management solutions, the RSA CyberCrime Intelligence Service is a managed service that is designed to provide information on corporate end points, network resources, access credentials and other systems that may have been compromised by malware. Security professionals can use this information to help identify corporate end points and resources that may be at risk as a result of malware infection and remediate incidents of potential data exposure in the enterprise.

In addition to gaining insight into malware-infected resources, the RSA CyberCrime Intelligence Service offers new daily reports on black-listed hosts and IP addresses used by cybercriminals for launching attacks and communicating updates to malware-infected computers that may be part of a botnet. When automatically fed into web filtering software, intrusion detection/prevention systems and other network monitoring and security solutions, this threat intelligence feed can be used to help sever the communication channels of existing malware, eliminating its ability to siphon information from companies and gain new instructions from command and control points.

"IT organizations have traditionally focused on layered security which protects the perimeter. Now is the time to provide the same layered security model internally as well. That model, based on Governance, Risk and Compliance, must assume that malware has penetrated the enterprise and mitigate any damage which might occur," said Phil Blank, Managing Director, Security, Risk and Fraud at Javelin Strategy & Research. "By employing actionable information contained in threat intelligence reports and supplemented by active blacklist feeds to help prevent communications with command and control servers and data leakage, an enterprise can significantly improve their security posture and reduce their risks."

Advanced forms of malware such as the Zeus and SpyEye Trojans can silently capture and exfiltrate a wide variety of data and credentials contained on enterprise endpoints, including proprietary information such as legal documents, healthcare records and corporate secrets. However, many organizations are unaware of the impact of malware within their systems that pose a significant threat to their information and bottom line.

"Corporate internet users increasingly represent the largest source of infection in the enterprise by data-stealing malware via spear-phishing emails and social engineering attacks," said Sam Curry, Chief Technology Officer for RSA's Identity and Data Protection group. "The RSA CyberCrime Intelligence Service helps IT professionals further understand and isolate possible points of exposure within their enterprise so they can adjust security controls and close gaps to better protect their organizations against malware and data loss."

The RSA CyberCrime Intelligence Service is designed to offer companies insight into potential compromises through a variety of regular reports and automated data feeds that provide lists of recovered data related to an organization's:

-- Systems, applications and resources derived from monitoring corporate URLs -- Communication done over corporate email domains -- Resources based on IP addresses of infected machines

The information offered through the RSA CyberCrime Intelligence Service is gleaned from the RSA Trojan Research Labs and a network of anti-virus, firewall, anti-spam and Web crawling partners. RSA aggregates and analyzes this information to provide customers with continuous updates and broad visibility on the latest malware and malicious hosts found on the internet.

Customers can also opt to receive an additional level of security consulting expertise integrated with their RSA CyberCrime Intelligence Service offering, to help identify and implement actionable plans to reduce cybercrime risk through:

-- Exposure analysis in social media and general web presence -- Business process mapping, risk modeling and vulnerability and exposure analysis -- Understanding industry and geographic trends -- Ongoing monthly consulting for defensive and intelligence needs

Availability

Offered as a managed service, the RSA CyberCrime Intelligence Service is designed to be quickly deployed and enables organizations to minimize resource investments. The RSA CyberCrime Intelligence Service is available worldwide this month. For more information, visit www.rsa.com/cybercrime or call RSA Product Sales at +1-800-495-1095.

About RSA

RSA, The Security Division of EMC, is the premier provider of security, risk and compliance management solutions for business acceleration. RSA helps the world's leading organizations succeed by solving their most complex and sensitive security challenges. These challenges include managing organizational risk, safeguarding mobile access and collaboration, proving compliance, and securing virtual and cloud environments.

Combining business-critical controls in identity assurance, encryption & key management, SIEM, Data Loss Prevention and Fraud Protection with industry leading eGRC capabilities and robust consulting services, RSA brings visibility and trust to millions of user identities, the transactions that they perform and the data that is generated. For more information, please visit www.RSA.com and www.EMC.com.

EMC, RSA and FraudAction are registered trademarks of EMC Corporation in the United States and other countries. All other products and/or services are trademarks of their respective owners.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-27491
PUBLISHED: 2021-07-30
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Ypsomed mylife Cloud discloses password hashes during the registration process.
CVE-2021-27495
PUBLISHED: 2021-07-30
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process after redirecting the user from a HTTPS endpoint to a HTTP endpoint.
CVE-2021-32807
PUBLISHED: 2021-07-30
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects. The policies defined in `AccessControl` severely restrict acce...
CVE-2021-22521
PUBLISHED: 2021-07-30
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.
CVE-2021-34629
PUBLISHED: 2021-07-30
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.