THREATS
Capitulation One. Adding to the column above, The New York Times has a good look at the security the financial sector following Capital One's breach. The suspected hacker may have hit other targets beyond the bank. And the Wall Street Journal took a look at Capital One's low-profile CEO, Richard Fairbank, who is now begrudgingly in the spotlight.
The whistles go WOOO. Cisco has agreed to pay $8.6 million to settle a claim alleging that it knowingly sold easily hackable video surveillance cameras to hospitals, schools, governments, and other customers. A whistleblower, James Glenn, alerted the IT giant to the issues in 2008, four years before the company addressed the security flaws, the settlement said.
Rest assured. The cyber insurance industry is popping off. Premiums grew to $2 billion last year, a 26% increase since 2015, according to a report from Moody's Investors Service. CyberScoop, a cybersecurity news outlet, dug into the booming market.
Breach roundup. There's Capital One, of course. Poshmark, a market for used clothes, warned customers that a recent data breach exposed people's names, email addresses, hashed passwords, and other information. An exposed database at Honda could have allowed attackers to see which of the carmakers' IT systems had unpatched vulnerabilities . And Bank of Cardiff, a San Diego-based financial firm, left a server containing one million phone call recordings exposed online.
Trinity test. Tom Bossert, a former cybersecurity czar in the Trump administration, has joined a new startup, Trinity Cyber, as chief strategy officer. Intel Capital has supplied $23 million in venture capital funding to the concern. Wired has an intriguing profile of the business.
"Your Highness Qiao Biluo" has no clothes.
Share today's Cyber Saturday with a friend: http://fortune.com/newsletter/cybersaturday/
Looking for previous Data Sheets? Click here.
ACCESS GRANTED
Tear down this firewall. The clearest technical explanation of what likely caused the Capital One breach was penned by Evan Johnson, product security team manager at Cloudflare, a multibillion-dollar Internet infrastructure startup. Johnson's post, published on his personal blog, details the problem, as he sees it. He calls out public cloud providers, like Amazon Web Services (AWS), for not doing more to address the underlying issue.
Every indication is that the attacker exploited a type of vulnerability known as Server Side Request Forgery (SSRF) in order to perform the attack. SSRF has become the most serious vulnerability facing organizations that use public clouds. SSRF is not an unknown vulnerability, but it doesn't receive enough attention and was absent from the OWASP Top 10.
SSRF is a bug hunters dream because it is an easy to perform attack and regularly yields critical findings, like this bug bounty report to Shopify. The problem is common and well-known, but hard to prevent and does not have any mitigations built in to the AWS platform.
Server Side Request Forgery is an attack where a server can be tricked into connecting to a server it did not intend. SSRF is more deeply explained in this article by Hackerone. The impact of SSRF is being worsened by the offering of public clouds, and the major players like AWS are not doing anything to fix it.
FORTUNE RECON
Facebook Misinformation Cleanup Targeted Pages Meant to Mislead on Middle East Ideas by Sarah Frier and Kurt Wagner
Equifax Data Breach Victims Drained Its $31 Million Settlement Fund in a Week by David Z. Morris
Capital One's Data Breach Could Cost the Company up to $500 Million by Lucinda Shen
Apple Has a Million Dollar Bug Problem—And It's Only Paying Thousands to Squash Them by Xavier Harding
Recruiting Scams Are 'Prolific,' Experts Say. Here's How to Avoid Becoming a Victim by Alyssa Newcomb
Homeland Security Issuing Hacking Alert for Small Planes by Tami Abdollah
ONE MORE THING
"Moscow Mitch." Many people are taking Senate majority leader Mitch McConnell to task for blocking the passage of two election security bills. The politician's critics have bestowed upon him a new nickname: "Moscow Mitch," a moniker that suggests he is aiding and abetting Russian election interference. Ben Folds, the singer-songwriter, has piled on, debuting a song bearing the unflattering nickname as its title.
No comments:
Post a Comment