Finjan Inc., a leader in secure web gateway products, today announced its discovery of a server controlled by hackers (Crimeserver) containing more than 500Mb of premium
data. The data included healthcare and business related data, as well as
personal identifiable information (stolen Social Security Numbers). This
data is part of the premium offering that the cybercriminals operating the
Crimeservers were selling to the highest bidder online.
The compromised data came from all around the world and contained
information from individuals, businesses, airlines and healthcare
providers. The report contains examples of compromised data that Finjan
found on the Crimeserver, such as:
- Compromised medical related data of hospitals and publicly owned
healthcare providers
- Compromised business related data of a U.S. airline carrier
- Identity theft (stolen Social Security Numbers)
Some of the implications of stolen medical and patient data include:
illegal and/or bogus treatments; obtaining prescription drugs for the
purpose of selling them; loss of health coverage for the victimized
patient; inaccurate records of victimized patients, which could result in
incorrect and potentially harmful treatments. Healthcare providers could
also face potential HIPAA violations or breach of general data protection
legislation.
Finjan's Malicious Code Research Center (MCRC) detected a Crimeserver
operated by cybercriminals who used campaigns to steal data. These
campaigns consisted of highly sophisticated attacks, incorporating
Crimeware toolkits, Trojans and Command and Control (C&C) servers to drive
traffic from a specific region, with specific characteristics.
"This report illustrates the latest development in cybercrime. It shows
the business cycle of data collecting and trading by today's
cybercriminals. Crimeware infecting PCs is a serious business problem that
has far-reaching consequences, such as impacting the security of businesses
and patients around the world," said Yuval Ben-Itzhak, CTO of Finjan. "We
see that cybercriminals go after premium data that they can trade for
substantial profit. The increase in Web-based attacks is staggering.
Industry figures include a growth of more than 200% of Web-based malware,
with an increase of over 800% in backdoor and password-stealing malware,
illustrating that sensitive corporate and medical are at risk."
According to Finjan, the fact that sensitive business, patient and
personal data were compromised in a timeframe of less than one calendar
month underscores the necessity for enterprises and organizations to have a
comprehensive security technology in place that provides effective
protection against these sophisticated threats.
The compromised data and the Crimeserver applications were detected
using Finjan's patented active real-time code inspection technology while
diagnosing users' Web traffic.
My New Blog
June 18, 2008
More Data Stolen
June 4, 2008
University Students Scammed- Is your info secure?
A data breach at United Healthcare Services Inc. has led to a rash of identity-theft crimes at the University of California, Irvine.
So far, Nearly 155 medical students have had their information stolen. The attackers stole the social security numbers stolen from an internal database. This breach affects nearly 1300 students, putting them at risk for Credit Card fraud as well as Tax scams. So far, the spammers have stolen 155 students Tax returns.
"In February, the police began getting reports from graduate students that when they filed their income tax returns, they were being told that their returns had already been filed using their Social Security numbers," she said.
So all that the attacker needed was a simple set of numbers, and they took students for hundreds, even thousands of dollars. All because of crappy security measures.
This is why people, This is why.
Checklist To ask your school IT Department
[] What security measures do you have in place for physical IT Infrastructre?
[] What security measures are in place to ensure the confidentiality of my information
[] If there is a unapproved access of my information- How promptly will I be notified?
[] Do you have set guidelines for partners of the university to follow in virtual exchanges?
[] WHO has access to my information and WHEN/WHY can they access it?
Posted by
Gillis57
at
5:23 PM
0
comments
Labels: Computer, Credit Card, FBI, Graduate, Hacked, Hacker, Hacking, Healthcare, IRS, Medical, Police, Rebate, Security, Server, Surgery, Tax, Vulnerability
HP Support Hacked! UPGRADE NOW!
A customer support application that comes bundled with HP PCs have been found to harbour multiple security vulnerabilities.
The pre-installed software is designed to make it easy for users to keep drivers and HP software automatically updated. But flaws in ActiveX components within HP Instant Support give rise to multiple vulnerabilties that lend themselves to drive-by download malware attacks in cases where Windows users running the vulnerable software stray onto insecure or hacker controlled websites, CSIS Security Group warns.
HP Instant Support HPISDataManager.dll version 1.0.0.22 and earlier are vulnerable. Users need to upgrade to version 1.0.0.24 as explained in a security bulletin from HP here.
A CSIS advisory containing proof of concept demos of the flaws can be found here. And there's an easy to digest bit from Secunia here.
It's not the first trouble HP has had with rogue ActiveX controls in its pre-installed utilities. In December last year two ActiveX bugs created a mechanism for hackers to either thrash or inject hostile code onto HP PCs running either HP Software Update or HP Info Center, respectively.
June 1, 2008
Alert: LinkedIN Scams Rampant
Have you heard of the professional networking site linkedin? Well, a number of professional users (Including Myself) have been using this site to increase their job prospects, clientele, and associates. It seems that more and more, professional scam artists are trying to prey off of the unsuspecting users of LinkedIn. It seems that common sense isn't all that common. Just because someone has a LinkedIn profile- Doesn't mean that they are trustworthy.
Unsuspecting professionals, driven by the urge to make quick millions off of a simple transaction, willingly turn over their bank information to a person who has made their acquaintance online. Why? Well, the scammers are using a '419 Scam'. What happens is the attacker claims to have inherited/ claimed a large sum of money, and is willing to give you a large fee to deposit the newly acquired funds into a US Bank account.
The best possible way to prevent this kind of attack is to: (A) Only accept mail from people you know, Or who have a related Interest (B) Never execute any financial transactions based solely upon knowledge recieved via virtual communications, Be it Email, Social Networking, Or other communications. Unless you know the person, don't allow someone access to your account.
Posted by
Gillis57
at
8:31 PM
0
comments
Labels: Bank, BBB, FBI, Gillis Jones, Hacker, Hacking, LinkedIn, Money, Network, Networking, NSA, Professional, Scam, Scammer, Security
May 30, 2008
Is your cell phone vulnerable?
Recently, it was disclosed that a malformed JPEG image could allow a remote attacker to execute arbitrary commands on a MOTOROLA RAZR phone firmware.
A corrupt JPEG received via MMS can cause a memory corruption which can be leveraged to execute arbitrary code on the affected device.
So some user interaction is required — accepting the MMS. However, people by and large generally trust image files so that isn't a difficult social engineering challenge.
Perhaps we'll see this JPEG exploit used to simplify unlocking older Razrs. Jailbreaking the iPhone was simplified by a TIFF handling exploit after all.
However, next time that cute chick you met on myspace sends you an "Picture"- Think twice about opening it.