Website Phish hijacks email accounts

Garwarner Blog post reveals some details of  various posts on the Internet that discuss the paper written by Google and other University of San Diego residents Here is the Abstract: “Online accounts are inherently valuable resources—both for the data they contain and the reputation they accrue over time. Unsurprisingly, this value drives criminals to steal, … Read more

Patch Tuesday Report November 2014

Patch Tuesday has passed, but the ramifications have not.  All over sysadmins are deciding what patches to apply and when.   Here is the report of what is happening: https://support.microsoft.com/kb/2992611    MS14-066 Schannel vulnerability is a bad remote code execution bug (must be patched) Internet Storm Center recommends this is a patch now kind of … Read more

Before patching IE11 install EMET5.1

Microsoft Security research and Defense Blog has the scoop:  Also Internet Storm center Post “If you are using Internet Explorer 11, either on Windows 7 or Windows 8.1, and have deployed EMET 5.0, it is particularly important to install EMET 5.1 as compatibility issues were discovered with the November Internet Explorer security update and the … Read more

Cyberattack Lessons for Companies and People

I am going to list various events and their lessons that we “should” learn from(my weekend reading): Home Depot hack from KrebsonSecurity Nov7 post: 56 million emails were harvested as well as the 53 million credit card numbers. “Home Depot said the crooks initially broke in using credentials stolen from a third-party vendor. The company … Read more

Belkin N750 router has Zero-day exploit

This router has a big security hole:   Integrity Labs says there is a guest wifi Zero-day exploit, this means that an unportected (without a password) wifi zone can be attacked and the machine can be taken over by the hacker.   If you have a Belkin N750 you should consider replacing it ASAP. Believe … Read more