Friday, October 31, 2014

White House breached (Russian Attack)

 

The worlds most secured line "The White House" told the NYT this week that its EOP network was hacked two or three weeks ago, and played down the breach to press by emphasizing that it was on an unclassified network only — where the hackers conducted "fairly standard espionage." So basically, the intruders accessed the network that handled everything else that happens on unclassified computers in the Executive Office of the President, which indicates that this breach is very likely much more serious than is being reported. Mitigation included staffers having to change their passwords and intranet or VPN access being temporarily shut off. The Washington Post reported that Russian hackers may be to blame.

FireEye revealed APT28 when it released its latest Advanced Persistent Threat report on Tuesday, "APT28: A Window Into Russia's Cyber Espionage Operations" (.PDF link). In a blog post FireEye wrote,
This report focuses on a threat group that we have designated as APT28. While APT28’s malware is fairly well known in the cybersecurity community, our report details additional information exposing ongoing, focused operations that we believe indicate a government sponsor based in Moscow.
In contrast with the China-based threat actors that FireEye tracks, APT28 does not appear to conduct widespread intellectual property theft for economic gain. Instead, APT28 focuses on collecting intelligence that would be most useful to a government.
Specifically, FireEye found that since at least 2007, APT28 has been targeting privileged information related to governments, militaries and security organizations that would likely benefit the Russian government.

The Shellshock attacks are stacking up. Organizations are unable to keep up with Shellshock patching processes, and incident response practices are lagging: Security researchers released two new Shellshock-related attack warnings Thursday as they witness attackers take advantage of the Bash bug in UNIX and Linux systems.

The next version of the Google Chrome browser expected in six weeks will arrive with support to fallback to SSLv3 disabled by default. Chrome 39, due to be released in six weeks' time, will be the first step in Google's plan to remove SSLv3 support from its Chrome browser.We knew two weeks ago when the Drupal team disclosed a really, really bad SQL injection vulnerability in Drupal 7 that it was important for admins to update quickly. Drupal claims a million users on project site drupal.org and over 30,000 developers. But there's no evidence yet of actual, widespread attacks.

No comments:

Post a Comment