Tag Archive for: compromises

Cisco seeks faster time to discovery for breaches, compromises

Cisco has announced security upgrades to cut the time compromises go unnoticed on endpoints, giving attackers less time to do damage if they get past preventive security measures.

Unveiled at the Cisco Partner Summit this week, the new AMP for Endpoints comes with a lightweight agent to gather data that is analyzed in the Cisco AMP cloud. This lifts the processing burden from customers’ infrastructure.

And the platform now includes an agentless feature for devices that can’t take an agent, such as visitors’ laptops.

In addition to the cloud version, the analytics part of the platform can also be purchased for deployment on customer premises in their own private clouds. Detection, analysis and recommended response are handled in the cloud and pushed to the endpoints.

To read this article in full or to leave a comment, please click here

Network World Tim Greene

Cluster of “megabreaches” compromises a whopping 642 million passwords

(credit: CBS)

Less than two weeks after more than 177 million LinkedIn user passwords surfaced, security researchers have discovered three more breaches involving MySpace, Tumblr, and dating website Fling that all told bring the total number of compromised accounts to more than 642 million.

“Any one of these 4 I’m going to talk about on their own would be notable, but to see a cluster of them appear together is quite intriguing,” security researcher Troy Hunt observed on Monday. The cluster involves breaches known to have happened to Fling in 2011, to LinkedIn in 2012, and to Tumblr 2013. It’s still not clear when the MySpace hack took place, but Hunt, operator of the Have I been pwned? breach notification service, said it surely happened sometime after 2007 and before 2012. He continued:

There are some really interesting patterns emerging here. One is obviously the age; the newest breach of this recent spate is still more than 3 years old. This data has been lying dormant (or at least out of public sight) for long periods of time.

The other is the size and these 4 breaches are all in the top 5 largest ones HIBP has ever seen. That’s out of 109 breaches to date, too. Not only that, but these 4 incidents account for two thirds of all the data in the system, or least they will once MySpace turns up.

Then there’s the fact that it’s all appearing within a very short period of time – all just this month. There’s been some catalyst that has brought these breaches to light and to see them all fit this mould and appear in such a short period of time, I can’t help but wonder if they’re perhaps related.

All four of the password dumps are being sold on a darkweb forum by peace_of_mind, a user with 24 positive feedback ratings, two neutral ratings, and zero negative ratings. That’s an indication the unknown person isn’t exaggerating the quality of the data. The megabreach trend is troubling for at least a couple of reasons. First, it demonstrates that service providers are either unable to detect breaches or are willing to keep them secret years after they’re discovered. Second, it raises the unsettling question where the trend will end, and if additional breaches are in store before we get there?

Read 2 remaining paragraphs | Comments

Technology Lab – Ars Technica

Apple zero-day vulnerability fully compromises your devices – ZDNet


ZDNet

Apple zero-day vulnerability fully compromises your devices
ZDNet
A zero-day vulnerability discovered within Apple's OS X operating system allows hackers to exploit key protection features and steal sensitive data from devices. Speaking at at the security conference SysCan360 2016 in Singapore, SentinelOne researcher …
Apple Zero-Day Flaw Leaves OS X Systems Vulnerable to AttackDark Reading
Businesses urged to update Apple software to dodge zero-day attacksComputerWeekly.com
Zero day OS X flaw can bypass System Integrity ProtectionBetaNews
Infosecurity Magazine –Neowin –Softpedia News
all 12 news articles »

“zero day” – read more

National data breach compromises voter information – KRQE News 13


KRQE News 13

National data breach compromises voter information
KRQE News 13
ALBUQUERQUE (KRQE) – An investigation is underway to figure out how the personal information of millions of American voters was exposed during a massive data breach. Security researchers have discovered a data file containing the personal …
Massive data breach affects registered votersWWMT-TV
U.S. Security Researches Find Massive Data Breach of Registered Voter Information9&10 News

all 7 news articles »

“data breach” – Google News