Problem 1: The bank should have had a much better (anything would have been better!) protected network
From The Register:
Security vendors are pushing for a more comprehensive revamp of the
SWIFT international inter-bank financial transaction messaging system
beyond a update prompted by an $81m hack against Bangladesh's central
bank.
The loss of $81m (part of an attempted $950m heist)
in February’s Bangladesh cyber-heist – reckoned to be the biggest ever
bank theft – has subsequently been linked to the bank’s use of
second-hand $10 switches on its network and a lack of firewalls.
Friday, April 29, 2016
American Dental Association given malware USB drives
From SC Magazine:
Malware embedded on a USB drive was delivered to members of the American Dental Association (ADA).
The mailing contained a PDF file of dental procedure codes, but some of the drives also held code capable of redirecting recipients to a website known to host malicious code. If a user opened the file, the site downloaded code that could enable miscreants to gain control of a user's Windows computer.
Wednesday, April 27, 2016
German nuclear plant infected with computer viruses
![]() |
| The nuclear power plant of Gundremmingen is pictured on March 11, 2012. (Reuters Image) |
"As an example, Hypponen said he had recently spoken to a European aircraft maker that said it cleans the cockpits of its planes every week of malware designed for Android phones. The malware spread to the planes only because factory employees were charging their phones with the USB port in the cockpit."
"Because the plane runs a different operating system, nothing would befall it. But it would pass the virus on to other devices that plugged into the charger"
Umm. That must not be just a USB charger then. It must be attached to a FAT file system of some sort. (Android won't mount and ext* file system out of the box)
The article is from Reuters:
"A nuclear power plant in Germany has been found to be infected with computer viruses, but they appear not to have posed a threat to the facility's operations because it is isolated from the Internet, the station's operator said on Tuesday."
"The Gundremmingen plant, located about 120 km (75 miles) northwest of Munich, is run by the German utility RWE"
Thursday, March 24, 2016
Hospital Gets Hacked with Ransomware
It's been noted by a number of security specialists that this will be the year of medical hacks. Not only hacking medical devices but hospital IT infrastructure. I seems like a lot of victims are just paying up. This one is demanding about $1600 in bit coins. I guess that's not a lot to pay for a hospital to get back online if the attackers actually deliver with the decryption key. There's no guarantee that they won't just encrypt the system again.
From CNBC:
From CNBC:
Methodist Hospital, based in Henderson, Kentucky, is the victim of a ransomware attack in which hackers infiltrated its computer network, encrypted files and are now holding the data hostage, Krebs reported Tuesday.
Monday, March 7, 2016
Maybe
Thinking about moving the Insecure By Default blog over here since it would be easier to maintain and post to.
Subscribe to:
Posts (Atom)

