-
Vaibhav Shukla commented on the post, Researchers Demonstrated How NSA Broke Trillions of Encrypted Connections, on the site 8 years ago
Its a great article which even now strengthens the point that why RSA and Diffie-Hellman cryptography method may soon see the slowdown in their usage across industries .Its security relies on the fact that factoring is slow and multiplication is fast.Specialized algorithms like the Quadratic Sieve have been created to tackle the problem of prime…[Read more]
-
Vaibhav Shukla posted a new activity comment 8 years ago
As you mentioned about the virus I will illustarte regarding the virus spread in nuclear facility in Germany
The viruses were “W32.Ramnit” and “Conficker” which were discovered at Gundremmingen’s B unit in a computer system retrofitted in 2008 with data visualisation software associated with equipment for moving nuclear fuel rods
W32.Ramnit is…[Read more] -
Vaibhav Shukla posted a new activity comment 8 years ago
What Makes a Good Security Awareness Officer?
Sharing the article i found interesting that how communication skills are also important with technical skills
Communication is one of the most important soft skills that a security awareness officer will need. Time and time again its been seen that people with the strongest communication skills…[Read more] -
Vaibhav Shukla wrote a new post on the site ITACS 5211: Introduction to Ethical Hacking 8 years ago
There are three publicly known attacks against nuclear plants:
Monju NPP (Japan 2014)
Korea Hydro and Nuclear Power plant (S.Korea 2014)
Gundremmingen NPP (Germany 2016).According to the head of th […]
-
Vaibhav Shukla commented on the post, Hacked voter registration systems: a recipe for election chaos, on the site 8 years ago
I think the entire election process can be the target of hackers where there is possibility that the election database can be hacked initially to create chaos but even after the elections the hackers can target the final count to make undesirable changes to favour their desirable candidate
-
Vaibhav Shukla posted a new activity comment 8 years ago
The main motive of physbits is to enable collaboration between physical and IT security to support overall enterprise risk management needs.Converging these security environments addresses security gaps that fall between these two different security disciplines and helps protect organizations against multifaceted
security threats.The Physbits…[Read more] -
Vaibhav Shukla posted a new activity comment 8 years ago
I wanna share some snippet from Wikipedia regarding how famous is the security breached and vulnerability in WordPress
Many security issues have been uncovered in the software, particularly in 2007, 2008, and 2015. According to Secunia, WordPress in April 2009 had 7 unpatched security advisories (out of 32 total), with a maximum rating of “Less…[Read more] -
Vaibhav Shukla commented on the post, In new email phishing scam, hackers pose as IRS officials sending ACA tax bills, on the site 8 years, 1 month ago
Yeah correctly said the public awareness is one of the method to prevent such scams.It is often seen that when origin of mails are tracked they come out as some hackers group based outside country.
-
Vaibhav Shukla wrote a new post on the site ITACS 5211: Introduction to Ethical Hacking 8 years, 1 month ago
Hackers are impersonating the IRS and sending scam emails to victims asking them to pay balances related to health coverage for 2014
The fraudulent emails pretend to be a CP-2000 notice from the IRS, a notice […]
-
Thanks for sharing Vaibhav. The greatest way to prevent these scams from being successful is public awareness. Unfortunately, the victims of these scams probably are novice users of the Internet and are not aware of these types of scams. There was a post last week about a crackdown on one of the payment processors for these types of scammers (i.e. PacNet). Disrupting the financial path, is another important step in cracking down on mail/e-mail fraud attempts to solicit payments from victims. I hope the crackdown on PacNet also exposes the scammers that use these services to victimize honest citizens that are just trying to do the right thing.
-
Yeah correctly said the public awareness is one of the method to prevent such scams.It is often seen that when origin of mails are tracked they come out as some hackers group based outside country.
-
Like you Jason, public awareness is one of the method to prevent these scams. Unfortunately, these scams are uses highly sophisticated social engineering techniques that can make people feel overwhelmed and obliged to comply. Some of the things that I tell people is never to provide payment information or Social security number over the phone, unless they can provide you a call back number, which you can validate on the institutions website and call the institution yourself.
-
-
Vaibhav Shukla commented on the post, 37-Year-Old 'Syrian Electronic Army' Hacker Pleads Guilty in US Court, on the site 8 years, 1 month ago
Yeah its seriously astonishing that it is active since a long time .In 2011, the group targeted multiple entities including The Associated Press, Reuters, Microsoft, Harvard University, CNN, National Public Radio and Human Rights Watch among others .
-
Vaibhav Shukla posted a new activity comment 8 years, 1 month ago
A Syrian national sympathetic to Syrian President Bashar Al-Assad’s government has pleaded guilty to federal charges for his role in an extortion scheme that targeted US media outlets, the US government and foreign governments
In 2011, the group targeted multiple entities including The Associated Press, Reuters, Microsoft, Harvard University,…[Read more] -
Vaibhav Shukla posted a new activity comment 8 years, 1 month ago
Hackers stole airline miles to book a hotel room or airline
It’s easy for hackers to get into your airline and hotel rewards accounts, then use your hard-earned points and miles for their own gain.Hackers might use passwords from lower-security sites like shopping platforms or chat forums and try those same passwords on frequent flier accounts, o…[Read more] -
Vaibhav Shukla wrote a new post on the site ITACS 5211: Introduction to Ethical Hacking 8 years, 1 month ago
Yahoo claims that around 500 million accounts were hacked in 2014 by what it believed was a state-sponsored actor, a theft that appeared to be the world’s biggest known cyber breach by far
-
Vaibhav Shukla posted a new activity comment 8 years, 1 month ago
Salve being a CIO of Indian Bank faced one of biggest challenge that its large number of customers were offline based and in order to bring customers to online banking the IS protocols should not be so rigorous as to cause inconvenience to customers. Although HDFC Bank was not pursuing market share as a business objective in its own right,…[Read more]
-
Vaibhav Shukla wrote a new post on the site ITACS 5211: Introduction to Ethical Hacking 8 years, 1 month ago
Webex Presentation
powerpoint
summary
-
Vaibhav Shukla wrote a new post on the site ITACS 5211: Introduction to Ethical Hacking 8 years, 1 month ago
The New York State Department of Financial Services has proposed a new regulation imposing significant new cybersecurity requirements on banks, insurance companies, and other financial services institutions […]
-
I’m not sure what the Cybersecurity posture was for the 200 firms that DFS interviewed, but it seems that the “Proposed Regulation” is trying to catch up to current industry standard and practices. Financial institutions have always been and is the largest target for cyber crimes. Instead of implementing they should be refining their security controls and policies to evolve with the threats.
-
To be honest, I would be worried if a financial institution did not have these controls in place already. Why is this just now mandatory? Things like: Establishing a cyber security program and policy, conduct assessments and pen testing, and establish written incident response plan as stated in the article should already exist. If I was a CEO of a financial institution that did not already have these in place, I would start working on it immediately, as this “proposed” regulation should been passed years ago.
-
Vaibhav,
This is a very interesting article and also very eye-opening. It is almost disturbing that the DFS is now proposing new regulations on cyber security requirements for banks, insurance companies, and other financial service institutions. These practices are almost standard in the technology industry. Without these recommended regulations in place, it would be almost impossible to pass an IT audit. -
Have to agree with other commenters. Seems like to little, to late.
Wade
-
-
Vaibhav Shukla commented on the post, Cyberattacks on Athletes May Be Russian Distraction Tactic, on the site 8 years, 1 month ago
Yeah its a bit strange that athletes who put on so much efforts are even not spared from such cyber attacks.The WADA (world anto doping agency ) has actually confirmed that Russian cyber espionage group Fancy Bear, which is also known as Tsar Team, accessed the Americans’ data through an International Olympic Committee account created for the R…[Read more]
-
Vaibhav Shukla commented on the post, Volkswagen launches new cybersecurity firm to tackle car security, on the site 8 years, 1 month ago
Yeah even I came across this article and we can get an idea of how much the automobile companies are gearing up to tackle car security.There is also an 4th annual automotive cyber security summit to be held in Sanfransisco in Oct last week where the leading automobile giants gonna discuss the new emerging issue of ensuring cyber security in the…[Read more]
-
Vaibhav Shukla posted a new activity comment 8 years, 1 month ago
The term “Acceptable information system risk “is usually defined in terms of practical implementation that inspite of building security measures and risk mitigation features within an organization the risk can never be reduced to zero .When risk can not be reduced to zero, so it’s important to determine how much to spend on lessening it to an…[Read more]
-
Vaibhav Shukla commented on the post, Federal Judge: Hacking Someone's Computer Is Definitely a 'Search', on the site 8 years, 1 month ago
I really appreciate the judge ruling that in order hack a computer for investigative purposes FBI should obtain a search warrant from a local magistrate.When a person is in the list of investigation then he is just one of the source of investigation and investigation can lead to many sources its like licensing the FBI to hack any person data in…[Read more]
- Load More
Hacking and disrupting nuclear plants is a huge issue. I remember there was a virus called “Stuxnet” that disrupted Iranian nuclear ambitions. It turns out that virus was created by America and Israel. One of the fears with using the virus was the possibility of it getting out and being used on other nuclear facilities. This might be the same type of attack.
As you mentioned about the virus I will illustarte regarding the virus spread in nuclear facility in Germany
The viruses were “W32.Ramnit” and “Conficker” which were discovered at Gundremmingen’s B unit in a computer system retrofitted in 2008 with data visualisation software associated with equipment for moving nuclear fuel rods
W32.Ramnit is designed to steal files from infected computers and targets Microsoft Windows software
Conficker is able to spread through networks and by copying itself onto removable data drives
That is not good news. Luckily it was a “disruptive” attack instead of a “destructive” attack. Hacking nuclear plants can endanger a whole country. Hopefully they are taking the steps to secure their infrastructure to protect them from hackers.
Critical infrastructure protection (or lack there of) really requires some drastic improvements across the globe. Many of the power plants across the globe (including US) are run by antiquated SCADA systems that were not built with security in mind. They are non-current, End-of-Life/End-of-Support and cannot be patched for security vulnerabilities.
Additionally, most of the regulations (e;g. NERC-CIP) are self-attestation as opposed to PCI-DSS which requires an independent QSA to perform an annual review. Self-attestations are not sufficient in assessing security. Employees are sometimes reluctant to self-declare security issues because they are afraid they will be blamed or will be required to put in extra work to fix security flaws. I would recommend more independent reviews of our critical infrastructure.
Vaibhav, this is a great article. It is disturbing the lack of security nuclear sites around the world have. I was watching a news story that focused on the United States Nuclear missile sites, and showed the lack of both physical security and the out-dated technology that was being using to safeguard these sites. To think that hackers could potentially cause a nuclear disaster is a scary thought. A topic that is always brushed over in the presidential debate is cyber security, and both candidates don’t seem to stress the importance of it, especially in instances such as this in Germany.