Using a risk model based on security statistics is a valid and useful approach to defending against cyber attacks. A company can decide that if one type of attack is affecting a large percentage of companies, then chances are, they may be next. The company can take steps to defend against that attack. However, sometimes past statistics are not enough and can be … [Read more...]
The Seattle CTO Club ~ Sharing Security Information
Yesterday I had the honor of presenting some security information at the Seattle CTO Club. I loosely based the discussion on a similar presentation I gave last week at an event for Equinox IT, a WatchGuard partner, covering the cyber security landscape and top threats businesses face. Members of the group learned common attack patterns and discussed strategies for effectively … [Read more...]
DNSMasq Vulnerabilities Affect Network Devices, Microservices, and More
On October 2nd, the Google security blog announced several vulnerabilities in a piece of software called DNSMasq, which offers DNS forwarding and DHCP services for small computer networks. Days before, IT Briefcase published an article I wrote about indicators of compromise in DNS logs. The article explains that an exploited DNS server may offer the path from an external to an … [Read more...]
Where in The World Is That Network Traffic Coming From?
In a past article, I explained how to auto-block hosts with a WatchGuard Firebox. Yesterday alone my logs showed over 100 IP addresses auto-blocked in one day on a Firebox used for testing purposes. The list included over 1000 blocked IP addresses. I also noticed the Firebox shows a limited number of blocked hosts so the total number of blocked hosts may be longer than what the … [Read more...]
Are Social Media Bots Influencing You?
Fake Facebook Ads, Twitter Bots, and Fraudulent LinkedIn Accounts If you haven’t heard by now, many fake accounts exist on Twitter, Facebook, and LinkedIn. A social media bot refers to an account that programmatically posts content. Many bots serve good purposes such as reporting and gathering information. The data from bots can help businesses, governments, news agencies … [Read more...]