Sunday Reading

Published: 2014-03-02
Last Updated: 2014-03-02 15:21:16 UTC
by Stephen Hall (Version: 1)
2 comment(s)

Time to catch up with that security reading now that your favourite team is second in the league, so lets see what we can do to bring us all up to speed ready for what Monday will bring, so in no particular order:

Data breach, after data breach it would appear as 2014 is turning into the year of the use of "sophisticated techniques" to breach online security.

Securing online applications via a mechanism which is susceptible to a brute force is not a good idea! 

Digging through our mail brings a gem. Nigeria Scams are still coming in, I do love todays which is from:

122 Adenirun Ogunsanya Street,
Off Bode Thomas Road,
Surulere Lagos - Nigeria
24/7 Banking
(24/7 Customer Care HotLine)
The colour coding is not mine, but is true to the original e-mail, nice touch! What makes this one truly special is that the e-mail was spoofed (shock!) to appear to come from "ACCESS BANK PLC -".
Ping over any other weekend news, and I'll add to the list to give ISC readers some additional reading material.

Steve Hall

ISC Handler

Keywords: Weekend Reading
2 comment(s)


Steve, where did you find the Smucker breach information? Google seems to have zero links beyond the site itself. I can't say I've bought a lot of jelly on-line, but it seems curious this doesn't seem to be very visible.

[edit] of course within moments of posting that question, Krebs noted on Twitter that he's notified 25 vendors of pwnage via Cold Fusion exploits...and Smucker site runs....wait for it.....CFM....
I was keyword searching on Google for words such as sensitive / confidential / information / compromised etc. which are normally in the announcements that the Public Relations people use, with a date range of 7 days. It was half way down the page. I must admit I was looking for the latest on the potential Sears compromise and couldn't remember the name of the company!

Diary Archives