Running Your Own Phishing Campaign
At SecureState, we often stress to our clients that Social Engineering is one of the most common methods for attackers to gain access. Social Engineering attacks can take many forms, from people...
View ArticleWhat Did We Learn from the 2015 DBIR, Part 2
The second half of the 2015 Verizon Data Breach Incident Report is dedicated to the nine basic incident patterns that were originally identified in the 2013 DBIR. Over 96% of the data breaches examined...
View ArticleFired Up
A recent article on Slate ended with the statement, “There’s still no answer to the question of how to get Americans fired up about cybersecurity.” SecureState’s cybersecurity experts decided to get...
View ArticleCyber Threat Intelligence: Is Sharing the New Defense?
What’s the saying, “If you can’t beat ‘em, join ‘em.”? Sure. Something like that. Doesn’t really work in the world of cybersecurity, though. Staying ahead of the curve does. I guess you can say Target...
View ArticleWhat Did We Learn from the 2015 DBIR
Verizon Enterprise’s 2015 Data Breach Investigations Report (DBIR) was recently released, and SecureState is here to give you some of the big takeaways from this massive report. Verizon works with...
View ArticleShould You FREAK Out?
Recently, a team of cryptographers at INRIA, Microsoft, and IMDEA discovered an SSL vulnerability in OpenSSL and Apple’s SecureTransfer that allow attackers to downgrade the encryption being used from...
View ArticleInformation Security Economics
In a free market, supply and demand should ideally self-regulate, maximizing value. The market (often in the form of consumers) responds to negative corporate events such as faulty products or warranty...
View ArticlePhishing for Awareness
Phishing is a social engineering tactic used by unauthorized users to gain access to sensitive data. Within the last few years, social engineering attacks have been growing in popularity and while end...
View ArticleLinux “Ghost” Vulnerability (CVE-2015-0235)
Researchers at Qualys recently warned organizations about a remote code execution vulnerability in the Linux GNU C Library (glibc). Named GHOST, this is a buffer overflow vulnerability that affects the...
View ArticleHacking the Gibson
With our recent pleasant surprise at the realistic nature of hacking in the movie Blackhat, we decided to find a few other realistic depictions of hacking in fictional media. While everyone has seen...
View ArticleDiagnosis: Data Breach
With the recent breach of Anthem, the focus on information security, particularly for the healthcare sector is higher than ever. SecureState has worked with a variety of healthcare companies, including...
View ArticleAre You Handing Them the Key?
SplashData recently announced its annual list of the 25 most commonly used “worst” passwords. Passwords like 12345, password, 123456, and michael show that, if given the choice, users will continue to...
View ArticleCyber Security Concerns in the Mergers & Acquisitions Due Diligence Process
With data breaches remaining a steady concern across industries, far too many Mergers & Acquisitions teams are ignoring information security as a key piece of data for decision making. How secure...
View Article7 Tips for Protecting Your Social Media
With the recent hack of Taylor Swift’s Instagram and Twitter accounts, and the upcoming annual social media spectacle around the Super Bowl, now is a good time to check on the security of your social...
View ArticleThe Top 3 Reasons President Obama’s Security Initiatives Will Fail
Following the Sony breach, President Obama is preparing legislation and security initiatives intended to help strengthen the security of the US and companies that operate here. While it is good to see...
View ArticleBlackhat Inaccuracies
Released today, the movie Blackhat centers on several cyber-attacks perpetuated against a Chinese nuclear facility and the stock market, and the hunt for the perpetrator of the attacks by Chinese and...
View ArticleChanges in PCI Requirement 11.3 Encourages Greater Network Security
While PCI DSS has required penetration testing for quite some time, the soon-to-be-mandatory PCI 3.0 has made a few changes to how penetration testing should be done, and where/when it is needed....
View ArticleMasked Attackers Tunneling into your Networks
“TOR is a network of virtual tunnels that allows people and groups to improve their privacy and security on the Internet,” according to TORProject.org. TOR is a type of Darknet or private network in...
View ArticleWishing You a Prosperous New Year
To our Colleagues in the Security Community, As we prepare for the New Year, we have the opportunity to reflect on 2014. This past year brought news of the recovering US economy. Job growth was steady...
View ArticleWatch for Falling Rocks
Somewhere, in a dark quiet room, they sit and stare into their cathode ray tube monitors. The smoke cloud from spent cigarettes lingers. Someone coughs. The sound of a toilet flush upstairs cuts...
View Article