Last week we took an in depth look at social engineering, and looked a phone and email examples in depth.
Cybersecurity awareness training is one of the most effective ways to combat these threats. Not everyone engaged in cybersecurity practice agrees about the effectiveness of this solution, but I have been delivering public cybersecurity courses for over a decade, and I know from the responses that ...
Continue Reading →FEB


Here’s a provocative statement: If you could just prevent your staff for clicking on links or opening attachments in phishing emails, 95% of your cybersecurity problems would be prevented.
Your phone rings. The caller identifies themselves as someone from a “tech support” company. Your computer has problems, he says, and he called to help you fix them. You agree to pay some sort of fee. You help them set up remote access to your computer. And now you have been hacked and helped them do it.
This should really be called “anti-social” engineering. A good definition is “social engineering is a non-technical method of intrusion hackers use that relies heavily on human interaction and often involves tricking people into breaking normal security procedures. It is one of the greatest threats that organizations today encounter.”
There is a small company in the Czech Republic called
Monday we looked at issues with the business class routers at Juniper Networks and Cisco Systems. Today we are going to look at an exploit affecting the Ubiquiti brand of cable modems.
At the end of December last year Juniper Networks discovered that some malicious actors had added code to the firmware and software that run their routers, creating a back door that would allow attackers to access the router remotely, assume administrator privileges, and view and decrypt VPN traffic running through the routers. As the story unfolded, it turns out that Juniper was using a random number generator from NIST, and that the ...