Phishing Survey: Attackers Evolve and Aggressive

  (a snapshot of APWG website today) Antiphishing Organization  APWG – an organization that is worldwide (Anti-Phishing Working Group) founded in 2003 by Tumbleweed corp as well as financial and ecommerce companies. Is a 501c6 tax- exempt corporation. http://www.antiphishing.org/download/document/245/APWG_Global_Phishing_Report_2H_2014.pdf This is a very interesting document – and deserves more understanding. Top ten targets of phishers … Read more

2nd Tuesday(Patch Tuesday) came & went now what?

I did not post about Patch Tuesday last week, So here is the rundown of what happened: Microsoft:   Cisco issued an Advisory on the 13th (Wednesday actually) http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp It is for their TelePresence products. http://windowsitpro.com/patch-tuesday/patch-tuesday-may-2015-brings-unlucky-13-3-critical-updates I had to show this picture of me on the switchboard after seeing the image in WindowsITPRo   The … Read more

IT Security work seems like we are in “Groundhog Day” the movie

You know the movie which makes Phil(Bill Murray) relive the same day until he gets it right.  http://www.imdb.com/title/tt0107048/ I asked Google how many days are in the movie “Groundhog Day”?   8 years, 8 months and 16 days, the director said 10 years.   IT security is just like that except it should be called … Read more

I Want My Internet 24/7- HACKERS KNOW THAT

Yes, we realize that everyone wants to Google something whenever you need to look up something. Our Website must be up all the time. Email has to work. YouTube watching, surfing the Internet – it is our right to go wherever we want. Visit Government websites when needed. Watch Netflix, and all our News channels … Read more

Must Patch Microsoft MS015-034 ASAP

Tuesday the patch was released: Here is where it started CVE-2015-1635  Description: HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka “HTTP.sys Remote Code Execution Vulnerability.” the vulnerability was created 20150217 MS:MS15-034 http://technet.microsoft.com/security/bulletin/MS15-034 … Read more