CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Researcher suggests hackers have already infiltrated critical infrastructures

For organizations that run the nation’s most critical infrastructures, it’s important to understand that today’s targeted cyber attacks are designed to carry out any number of activities including monitoring network processes to bringing down the grid. Just because hackers haven’t carried out an attack doesn’t mean malware isn’t already resident in a system waiting for the most opportune time to launch.

In the article, “Attackers can take out critical infrastructure, but profit lies elsewhere, researcher says,” Jason Larson, a security researcher at the Idaho National Laboratory, said there’s plenty of evidence that hackers have already infiltrated control systems that run power generation plants, gas and oil refineries, and other chemical factories, but so far their activity is observational. Continue reading this post…

Dissecting targeted attacks

The sharing of personal information over the Internet has been a huge driver for targeted attacks, which are designed to steal highly sensitive corporate information. According to the article, “Surviving today’s targeted attacks,” hackers who once sought fame and notoriety are now motivated by money. Targeted attacks go after the most valuable corporate data including source codes, future product information, third-party data, executives’ emails and customer information. Stefan Tanase, senior security researcher at Kaspersky Lab, said there are four steps cyber criminals take in executing a targeted attack: Continue reading this post…

From the “what more proof do you need?” file: 90% of the most secure firms may be affected by botnets…

An RSA study released on Wednesday claims that most major U.S. corporations — including up to 88% of Fortune 500 companies — may be affected by botnet activity from computers compromised by the Zeus Trojan.

In the article, “88 percent of firms show Zeus botnet activity,” RSA’s FraudAction Anti-Trojan services analyzed data stolen by Zeus from infected computers that included IP addresses and emails that belonged to the corporations. Among the stolen data found on the sites where infected computers drop the stolen data was compromised email addresses from about 60% of the firms. Continue reading this post…