Wednesday, June 24, 2020

Secure the Attack Surface | HackerOne

Secure the Attack Surface | HackerOne

Secure the Attack Surface

Secure the Attack Surface - Secure Existing Applications

Secure Existing Applications

Keep your applications secure and demonstrate your commitment to security. HackerOne offers a suite of products designed to fit your needs and integrate into your systems: public and private bug bounty programs, vetted security researchers, pentesting, and more.

Move to the Cloud with Confidence

Cloud migration is challenging. Even in a best case scenario, your organization has to apply new firewall solutions, integrate new security systems, and transfer data. Each change opens up new attack surfaces. Avoid exposing yourself to risk by inviting ethical hackers to vet your application security. Strengthen your cloud security posture and avoid misconfigurations known to cause security breaches.

Secure the Attack Surface - Move to the Cloud with Confidence
Secure the Attack Surface - M&A Agility Minus the Risk

Less is More: Consolidate Tools & Cut Costs

Security teams must stay ahead of advanced threats and increased vulnerability sophistication. To increase visibility, reduce clutter, and manage costs, many teams are looking to consolidate their security solutions. Thousands of companies rely on hacker-powered security to address evolving threats and scale while reducing their reliance on point solutions.

Recommended HackerOne Solutions

Vulnerability Disclosure

Vulnerability Disclosure

Establish the process for and receive reporting of unknown or harmful security vulnerabilities to the proper person or team in your organization.

Learn More

HackerOne Clear

HackerOne Clear

Partner with proven, background-checked security researchers with the skills and reputation to match your specific needs.

Learn More

Bug Bounty

Bug Bounty

Let trusted hackers continuously test for vulnerabilities with defined scope of coverage.

Learn More

Do You Have Hackers on Your Side?

Every 5 minutes, a hacker reports a vulnerability. Every 60 seconds, a hacker partners with an organization on HackerOne. That's more than 1,000 interactions per day towards improved security. Our CISOs Guide to Reducing Risk with Responsible Disclosure details why hacker-powered security is a must for scaling security across your attack surface.

Get the Guide

"Our HackerOne bug bounty program has one of the most permissive scopes in the industry. This allows us to work with security researchers to test the broadest attack surface possible. The impressive contributions from the community have made Dropbox, and the internet as a whole, a safer place."

Rajan Kapoor, Former Director of Security at Dropbox



Elyssa 

Just me, e. ELyssaD

Just me, e. ELyssaD™

Top Down Policy Failure in Public Education – Elyssa D. Durant, Ed.M.

Top Down Policy Failure in Public Education
Elyssa D. Durant, Ed.M.

MNPS does not have the answers, nor does our newly elected Mayor who recently launched an aggressive media campaign to recruit new teachers willing to work within the constraints our over-regulated, under-funded public schools.

This article glossed over the magnitude of the desperate situation in Metro Nashville Public Schools (MNPS).

But it does raise questions about the hiring and retention practices by the Board of Ed.

The basic fact that students are not making adequate progress is a reflection of the top-down policy failure by MNPS and the Board of Ed.

Students are not making adequate progress, and teachers are being shuffled around in a desperate attempt to fix a problem that they do not fully understand.

This data seems to support the need for performance based incentives such as the study on performance incentives at the National Center for Performance Incentives on the Peabody Campus at Vanderbilt University.

Teachers in the experimental group receive a $15,000 bonus if their students demonstrate a pre-determined level of achievement and demonstrate proficiency.

In conjunction with the RAND corporation, data will be collected twice a year: at the beginning of the academic term to establishing the baseline level of competency for each student.

Data is then collecting at the end of the year to measure achievement.
Several waves of data will be collected and evaluated over the next several years will be evaluated in conjunction with the RAND Corporation.

In order to fix our broken schools, we need to look at schools that work.

There are in fact public schools in urban neighborhoods that are successfully educating the students despite limited budgets, supplies, and adequate funding.

So what is it about these schools that allows them to successfully educate disadvantaged, at-risk students and how can we replicate their success?

As an educator employed by MNPS, I earn $10.46 / hour (without benefits) teaching at-risk students. What does this say about the fiscal priorities of our community?

My graduate degree in education is from the very same university that Mayor Karl Dean attended in New York City. What does that say about our values as a society? What does that say about the value of a graduate degree from the Ivy League?

I called HR and the "Certificated Office" to inquire about obtaining a provisional teaching license and alternative certification, I was simply told that I was not eligible for alternative certification and without additional course work, and tuition and fees, I was not deemed qualified to teach in Metro.

I am not qualified to teach in Metro since, apparently, Metro "does not teach education." What a joke. To make matters worse- I had to pay them to find out that I was not even qualified to work with Head Start.

I went to Head Start! Shouldn't that be enough? I find it difficult to believe that a city so desperate for teachers is not willing to bend the rules just a little or waive the application fee for anyone who is willing to work in such a hostile environment.

The state Department of Education could not offer any realistic solution to the simple fact that I cannot afford to pay the fees associated with the application fees certification requirements.

If the Mayor really needs applicants, perhaps the city should comp the application fees necessary to be considered for employment.

They are strangely unfamiliar with the political process, and teachers are expected to implement and carry out policies that were designed by academic professionals or educational consultants.

If MNPS truly wants a better-qualified staff, then the Mayor, the Board of Education, and school administrators need to take a closer look at the methods used to recruit, retain, and reward qualified individuals willing to sacrifice their financial stability for a career in public service.

The high rate of student mobility is compounded by the constant shifting of school personnel. Many schools may just lose the few experienced, dedicated teachers they still have left have, to surrounding districts, cities, and states.

Such instability in the system may even prompt the younger set to leave the profession all together and discourage future teachers from applying for jobs in Metro.

Now that I realize my education was a complete waste of time and money, is it any wonder that I am ready to give up on teaching and maybe even ready to leave Nashville for good. The local hardware store has more to offer including benefits!

Everything we know about the positive outcomes in neighborhood schools is their strong reliance upon community buy-in and parental involvement.

One thing that makes magnet, lottery, charter schools, parochial, and private schools so good is the fact that parents, teachers, students, and administrators fight to get in, and fight to stay there.

The act of choosing, in effect, leads to an enhanced sense of community and builds a supportive, consistent, and structured environment.

Calling rezoning and teacher shuffling in Metro "Project Fresh Start" is ridiculous– it would be more accurate.

Sent from my BlackBerry® RIM Job



Elyssa 

Sunday, June 21, 2020

Cyber-attack: Is my computer at risk? - BBC News

Cyber-attack: Is my computer at risk? - BBC News


Cyber-attack: Is my computer at risk?

Your PC is at risk screen PA

Experts are warning that there could be further ransomware cases this week after the global cyber-attack. So, what has happened and how can organisations and individuals protect themselves from such attacks?

What is the scale of the attack?

Ransomware - a malicious program that locks a computer's files until a ransom is paid - is not new but the size of this attack by the WannaCry malware is "unprecedented", according to EU police body Europol.

It said on Sunday that there were believed to be more than 200,000 victims in 150 countries. However, that figure is likely to grow as people switch on their computers on Monday if their IT has not been updated and their security systems patched over the weekend.

There are also many other strains of ransomware which cyber-security experts say they are seeing being given new leases of life.

In the UK, the NHS was hit hard, but by Saturday morning the majority of the 48 affected health trusts in England had their machines back in operation. The NHS has not yet revealed what steps it took.

The malware has not proved hugely profitable for its owners so far. The wallets set up to receive ransom payments - $300 (£230) in virtual currency Bitcoin was demanded for each infected machine - contained about $30,000 when seen by the BBC. This suggests that most victims have not paid up.

Is my computer at risk?

WannaCry infects only machines running Windows operating systems. If you do not update Windows, and do not take care when opening and reading emails, then you could be at risk.

However, home users are generally believed to be at low risk to this particular strain.

You can protect yourself by running updates, using firewalls and anti-virus software and by being wary when reading emailed messages.

Regularly back up your data so you can restore files without having to pay up should you be infected, as there is no guarantee that paying the ransom will result in your files being unlocked.

The UK's National Cyber Security Centre website contains advice on how to apply the patch to stop the ransomware - MS17-010 - and what to do if you can't.

How did the attack spread so fast?

The culprit is malware called WannaCry and seems to have spread via a type of computer malware known as a worm.

Unlike many other malicious programs, this one has the ability to move around a network by itself. Most others rely on humans to spread by tricking them into clicking on an attachment harbouring the attack code.

WannaCry Webroot
The ransomware has been identified as WannaCry

Once WannaCry is inside an organisation, it will hunt down vulnerable machines and infect them too. This perhaps explains why its impact is so public - because large numbers of machines at each victim organisation are being compromised.

It has been described as spreading like the vomiting bug norovirus.

Why weren't people protected?

In March, Microsoft issued a free patch for the weakness that has been exploited by the ransomware. WannaCry seems to be built to exploit a bug found by the US National Security Agency.

When details of the bug were leaked, many security researchers predicted it would lead to the creation of self-starting ransomware worms. It may, then, have taken only a couple of months for malicious hackers to make good on that prediction.

It was originally thought that a number of victims were using Windows XP, a very old version of the Windows operating system that is no longer supported by Microsoft.

However, according to cyber-security expert Alan Woodward, from Surrey University, the latest statistics suggest this figure is actually very small.

Large organisations have to test that security patches issued by the provider of their operating systems will not interfere with the running of their networks before they are applied, which can delay them being installed quickly.

Who was behind the attack?

It's not yet known, but some experts are saying that it was not particularly sophisticated malware. The "kill switch" that stopped it spreading - accidentally discovered by a security researcher - may have been intended to stop the malware working if captured and put in what's called a sandbox - a safe place where security experts put computer malware to watch what they do - but not applied properly.

Ransomware has been a firm favourite of cyber-thieves for some time as it lets them profit quickly from an infection. They can cash out easily thanks to the use of the Bitcoin virtual currency, which is difficult to trace.

However it's unusual for an expert criminal gang to use so few Bitcoin wallets to collect their ransom demands - as in this case - as the more wallets there are, the more difficult the gang is to trace.



Elyssa 

Global cyber-attack: How roots can be traced to the US - BBC News

Global cyber-attack: How roots can be traced to the US - BBC News

Global cyber-attack: How roots can be traced to the US

File image of a man using a computer keyboard Reuters
Organisations have been blamed for not keep their systems updated

The flaw in Windows behind a huge cyber-attack affecting organisations around the world, including some UK hospitals, can be traced back to the US National Security Agency (NSA) - raising questions over the US government's decision to keep such flaws a secret.

Elements of the malicious software used in Friday's attacks were part of a treasure trove of cyber-attack tools leaked by hacking group the Shadow Brokers in April.

One of the tools contained in the Shadow Brokers leak, codenamed EternalBlue, proved to be "the most significant factor" in the spread of Friday's global attack, according to cyber-security firm Kaspersky Lab.

The tool was said to have been created by the NSA - though, as is typical, the agency has neither confirmed nor denied this.

EternalBlue was made public on 14 April, and while Microsoft had fixed the problem a month prior to its leak, it appeared many high-profile targets had not updated their systems to stay secure.

Friday's attack has reignited the debate over whether or not governments should disclose vulnerabilities they have discovered or bought on the black market.

"It would be deeply troubling if the NSA knew about this vulnerability but failed to disclose it to Microsoft until after it was stolen," said Patrick Toomey, a lawyer working for the American Civil Liberties Union.

"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world.

"Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer."

Edward Snowden, who famously leaked many internal NSA files in June 2013, criticised the NSA on Friday in a series of tweets.

"In light of today's attack, Congress needs to be asking [the NSA] if it knows of any other vulnerabilities in software used in our hospitals," he wrote.

"If [the NSA] had privately disclosed the flaw used to attack hospitals when they found it, not when they lost it, this may not have happened."

Outdated systems

However, others focused the blame at institutions for being too slow in updating their systems, given that this attack happened almost two months after a (free) fix was made available by Microsoft.

"Say what you want to say about the NSA or disclosure process," said Zeynep Tufeki, a professor at the University of North Carolina.

"But this is one in which what's broken is the system by which we fix."

For the UK's National Health Service, the problem is perhaps more acute.

Security firms have continually raised alarms about the NHS's reliance on Windows XP, an operating system that is no longer supported by Microsoft.



Elyssa 

Saturday, June 20, 2020

Global cyber-attack: Security blogger halts ransomware 'by accident' - BBC News

Global cyber-attack: Security blogger halts ransomware 'by accident' - BBC News

Global cyber-attack: Security blogger halts ransomware 'by accident'

LISTEN: How 'Malware Tech' became an 'accidental hero'

A UK security researcher has told the BBC how he "accidentally" halted the spread of the malicious ransomware that has affected hundreds of organisations, including the UK's NHS.

The 22-year-old man, known by the pseudonym MalwareTech, had taken a week off work, but decided to investigate the ransomware after hearing about the global cyber-attack.

He managed to bring the spread to a halt when he found what appeared to be a "kill switch" in the rogue software's code.

"It was actually partly accidental," he told the BBC, after spending the night investigating. "I have not slept a wink."

Although his discovery did not repair the damage done by the ransomware, it did stop it spreading to new computers, and he has been hailed an "accidental hero".

"I would say that's correct," he told the BBC.

Cyber-attack scale 'unprecedented'

NHS 'robust' after cyber-attack

"The attention has been slightly overwhelming. The boss gave me another week off to make up for this train-wreck of a vacation."

What exactly did he discover?

The researcher first noticed that the malware was trying to contact a specific web address every time it infected a new computer.

But the web address it was trying to contact - a long jumble of letters - had not been registered.

MalwareTech decided to register it, and bought it for $10.69 (£8). Owning it would let him see where computers were accessing it from, and give him an idea of how widespread the ransomware was.

World map MalwareTech
Owning the web address let MalwareTech monitor where infections were happening

By doing so, he unexpectedly triggered part of the ransomware's code that told it to stop spreading.

Analysis: How did it start?

What is the ransomware?

This type of code is known as a "kill switch", which some attackers use to halt the spread of their software if things get out of hand.

He tested his discovery and was delighted when he managed to trigger the ransomware on demand.

"Now you probably can't picture a grown man jumping around with the excitement of having just been 'ransomwared', but this was me," he said in a blog post.

MalwareTech now thinks the code was originally designed to thwart researchers trying to investigate the ransomware, but it backfired by letting them remotely disable it.

Does this mean the ransomware is defeated?

While the registration of the web address appears to have stopped one strain of the ransomware spreading from device-to-device, it does not repair computers that are already infected.

Security experts have also warned that new variants of the malware that ignore the "kill switch" will appear.

"This variant shouldn't be spreading any further, however there'll almost certainly be copycats," said security researcher Troy Hunt in a blog post.

MalwareTech warned: "We have stopped this one, but there will be another one coming and it will not be stoppable by us.

"There's a lot of money in this, there is no reason for them to stop. It's not much effort for them to change the code and start over."



Elyssa