36 Followers
16 Following
12 Posts
“No such thing as spare time, no such thing as free time, no such thing as down time. All you got is life time. Go.”
— Henry Rollins
Long holidays, zero hours cyber - 100 hours bird warching. Thousands of photos waiting for rainy days, including 400 photos of this kestrel.
ISC Diary: @malware_traffic reviews DocuSign-themed email leads to script-based infection https://i5c.us/d29888

Latitude Financial Services Data Breach Impacts 300,000 Customers

First analysis from the victim:

"Latitude Financial has experienced a data theft as the result of what appears to be a sophisticated and malicious cyberattack."

I've never seen a statement that says "...of what appears to be just one of those unsophisticated opportunistic cyberattacks."

https://www.securityweek.com/latitude-financial-services-data-breach-impacts-300000-customers/

Latitude Financial Services Data Breach Impacts 300,000 Customers

Latitude Financial Services says the personal information of 300,000 customers was stolen in a cyberattack.

SecurityWeek

New, by me: ODIN Intelligence, the police tech firm whose website was defaced last weekend, was hacked. A huge trove of confidential police data was exfiltrated and provided to transparency collective DDoSecrets. The data contains tactical plans of police raids, and use of surveillance, like facial recognition.

More: https://techcrunch.com/2023/01/21/odin-intelligence-breach-police-surveillance/

TechCrunch is part of the Yahoo family of brands

I don't often just rant at the void much anymore, but here's one that really gets me...

The fact that you are a Big Company and Powerful will not save you from a cybersecurity incident.

The fact that you can put pressure on your cybersecurity contracting and consulting companies through $$$ does not change the fact that you might need their actual real life assistance someday.

I consistently see some very powerful, large companies buying incident response and services contracts across the industry and using their weight and brand power to try to skip things like retainer on-boarding, critical document sharing, and preparatory exercises.

Oh. My. Sweet. And Fuzzy. Lord.

I understand that you are very busy. I understand that it is hard to get everybody on a call, and find the right documentation. I understand there are lawyers and bureaucracy that make it more difficult to share certain materials. I understand you're getting a retainer because your insurer or regulator says to.

This changes nothing. If you really need to call an incident response / digital forensics consultant (and you probably will), they're going to need that information and preparation. No amount of money in the world will be able to magic away necessary prep work. No amount of money thrown at the compromise will make it go away without work - unless you intend to replace your entire domain and computer network (also a lot of work). Your insurer will not fix it. Your brand will not fix it.

The requirements your legitimate retainer company put forth exist for a reason. They are not to steal your money or retainer hours. They are to make sure that an entirely unrelated team to your operations and technology will be able to walk in during a crisis and meaningfully assist without days of ramp up time. We need context to be able to do that. Network maps. Response plans. System and facility access directions. Understanding of your organization and comms plan.

That can't be wished away with money. Anyone, absolutely anybody legitimate in DFIR on planet Earth will need that information. If we don't get it ahead of time, we will be getting it on expensive hour burn before we can actually start to put out a fire.

That's all I have to say about that.

#cybersecurity #infosec #databreach

Being sick when you should be preparing Christmas stuff...

(in pic: our shiba pup Rosa when she was very little)

’That a man ought to study philosophy, up to the point of looking on generals and donkey-drivers in the same light’ (Laertius, 1853)
What is this #Mondog thing @jerry is talking about? Rosa wants to know. #shiba

Local stuff in Finnish:

Kyberturvallisuuskeskuksen viikkoraportissa on hyvää tietoa mm. alkavaan kaupalliseen ajanjaksoon, mitä myös jouluksikin kutsutaan.

https://www.kyberturvallisuuskeskus.fi/fi/ajankohtaista/kyberturvallisuuskeskuksen-viikkokatsaus-452022

#tietoturva #certfi #ncscfi

Kyberturvallisuuskeskuksen viikkokatsaus - 45/2022 | Kyberturvallisuuskeskus

Tämä on Kyberturvallisuuskeskuksen viikkokatsaus (raportointijakso 4.11. - 10.11.2022). Viikkokatsauksessa jaamme tietoa ajankohtaisista kyberilmiöistä. Viikkokatsaus on tarkoitettu laajalle yleisölle kyberturvallisuuden ammattilaisista tavallisiin kansalaisiin.

Kyberturvallisuuskeskus

For those following phishing scene here's a well written analysis of Robin Banks a phishig-as-a-service plaform. Written by IronNet.

Part 1:
https://www.ironnet.com/blog/robin-banks-a-new-phishing-as-a-service-platform

Part 2:
https://www.ironnet.com/blog/robin-banks-still-might-be-robbing-your-bank-part-2

#phishing #threatintelligence #infosec

Robin Banks might be robbing your bank

In mid-June, IronNet researchers discovered a new large-scale campaign utilizing the Robin Banks platform to target victims via SMS and email.