May 15, 2022
Dec 18, 2020
SolarWinds Hack to Signal a new form of Warfare?
The list keeps on growing... The new war. The new espionage. Call it what you will, but this was not a simple attack.
It started by manipulating SolarWinds Orion system updates hackers (state sponsored hackers, i.e. cyber warfare). This updated version allowed the hackers to access any of the servers which hosted the SolarWinds application, which is an IT monitoring and management tool used by administrators and network engineers. This allowed the hackers to have full administrator access to at least one server inside the victim's network, and download any additional malware they needed to get full access of the victims' networks. To set things in perspective, hackers breached the US nuclear weapons agency.
The list of victims is huge. Till now, 40+ major companies or government departments and agencies have been identified. I expected the final number to reach at least a 100+ hi-profile victims. Hackers had around 9 months to do whatever they wanted without being caught. 80%
of which are located in the United States, with the rest being spread across
seven other countries —namely Canada, Mexico, Belgium, Spain, the UK, Israel,
and the UAE.
Companies breached so far:
- Microsoft
- SolarWinds
- Fireeye
Main US targets:
- The US Treasury Department
- The US Department of Commerce's National Telecommunications and Information Administration (NTIA)
- The Department of Health's National Institutes of Health (NIH)
- The Cybersecurity and Infrastructure Agency (CISA)
- The Department of Homeland Security (DHS)
- The US Department of State
- The National Nuclear Security Administration (NNSA)
- The US Department of Energy (DOE)
- Three US states
- City of Austin (also disclosed today)
While not the first attack of its kind, the fact that we are still at the tip of the iceberg in discovering the scale is worrisome. The types of victims, the amount of data that could have been stolen during a 9-month breach, and the fact that it is a state sponsored attack all indicate that the new wars will be fought online as well as with real weapons.
Finally, so many questions come to mind, and I am sure those would be answered within the coming days:
- How did the hackers bypass all internal SolarWinds controls, application controls and Quality Assurance to publish such a malicious update.
- How were they left undetected for 9 months.
- How many companies have been really breached and what type of data has been stolen
- What long lasting impact will this have on the cyber world, how can we ensure that software installed on our infrastructure is secure?
- Will the US retaliate?
Sep 9, 2020
Aug 22, 2020
Warning: A Google Drive 'Feature' Could Let Attackers Trick You Into Installing Malware
An unpatched security weakness in Google Drive could be exploited by malware attackers to distribute malicious files disguised as legitimate documents or images, enabling bad actors to perform spear-phishing attacks comparatively with a high success rate.
The latest security issue—of which Google is aware but, unfortunately, left unpatched—resides in the "manage versions" functionality offered by Google Drive that allows users to upload and manage different versions of a file, as well as in the way its interface provides a new version of the files to the users.
For more info, https://thehackernews.com/2020/08/google-drive-file-versions.html
Aug 21, 2020
Dec 3, 2018
So.... I'm back......
A lot has changed since then. On a personal level and on a bigger scale. Infosec and hacking have become on everybody's lips. So many hacks. So many issues. So many breaches and yes..... GDPR. GDPR everywhere.
Well..... This won't be a long post. I'll just leave you with this:
Aug 7, 2014
Companies to blame as much as end users!
When computers were being developed, no one had security in mind. When the internet was created, no one thought about security. Security came as an afterthought, years and years after people started using computers, programs and the internet. So when cyber criminals decided to cash in, a new domain called information security was created, and the game of cat and mouse started. Cyber criminals always have the upper hand, and security professionals are always running behind to fix the holes.
Almost in all situations, the problem in any security flow starts from the programmer(s) who design and write code. When programming languages were created, many security flows existed. Even though those flows are always being fixed, programmers are under a lot of pressure to finish their work in record time. They are barely given time to test a program let alone check it for security flows. What used to be an issue with lack of security knowledge has now transformed into an issue with management. Get the program out as soon as possible is what’s important; you can fix the problems later.
I used to think that since I live in a third-world country, it was an issue with companies in this country. I truly believed that in advanced countries, security is a prime concern and that the whole system would not allow for such flows. The more I read about the topic, and got interested in it, the more I realized that it’s a universal problem. How many “top” companies had defected products, systems hacked and passwords stolen?
The idea is that it is impossible to secure systems/website unless you don’t want to use them; that is have them inaccessible by anyone. Any other way? No!. The closest is having a dedicated security team of at least a 100 employees (which should all be competent)… Having the management on the security wagon. Programmers, network people and server people all sufficiently trained and believing in what it takes to secure the system. Only then would you have a chance of being partially secure.
Back to the initial question… Why is it easy to hack into our data… Well it’s because even if you do whatever you can do from your end as an end-user, and follow every single guideline… It’s still not in your hands! The truth is that many people working in the cyber world are incompetent, unhappy, pressured or just not interested. As long as we are playing the cat and mouse game, we will always be the losers. Security has to be part of any design of the future of internet… Not just a simple afterthought.
Jun 21, 2014
Jan 10, 2014
2014 Norfect Security Predictions!!!
But before that, a small message to my amazing wife. HAPPY BIRTHDAY! My life would mean nothing without you by my side.
So without further ado, here are my predictions!
1. Many house users, corporations and websites will be attacked by new vulnerabilities found in Windows XP, Office 2003, and Java 6. You see, support and security patches will be suspended for these products in 2014 as they have reached their end of support life cycle. This means anyone using these products won't be able to patch any newly found vulnerabilities. Can you guess who will benefit most?
2. Hackers will increase the use of ransom-ware. They will attack end-users and corporations in order to get easy money to use elsewhere. It will be "fast money" used for other bigger breaches.
3. Which gets us to the prediction that major data breaches will increase significantly. At the end of 2013, not a month passed without at least 1 million user ID and password were hacked from known companies. In 2014, even more world-wide companies will be hacked. More usernames and passwords will be published online.
4. Due to the whistle-blowing actions of Edward Snowden, more and more people will be aware about their online privacy. Users will have less trust in the internet because anything they do can and is being traced by governments. Web activists will be pushing towards an internet reform.
5. Corporate mobile devices will be targeted by specific malware to gather sensitive data/emails. Many of these malware will be left undetected for a long period of time. Antiviruses for mobiles in my opinion are still pretty weak with many false positives that make you ignore real threats.
6. With more and more people storing information on the cloud, at least one major cloud storage provider will be hacked and millions of terrabytes of user data will be exposed.
7. Attacks will become more personalized. The attackers will spend more time focusing on their targets to be able to craft personalized attacks via emails or the social network.
And that's the end folks! What are your predictions?
Dec 22, 2013
Computer Security Jokes ~ 3
Jun 17, 2013
Two-factor Authentication .... Microsoft/Outlook
![]() |
| After Logging into outlook, press your name and then account settings |
![]() |
| Press Edit Security Info |
![]() |
| Microsoft double checks that it is truly you accessing your security info |
![]() |
| After receiving the code on your alternate email, add it here. If you do not have an alternate email, create one asap. It is very useful when/if you lose your password. |
![]() |
| The email received from Microsoft for double checking. To be honest, it looks fishy (phishing), yet it is legitimate! |
![]() |
| After inputting the code, you reach this screen. Press "set up two-step verification" |
![]() |
| After activation, Microsoft explains that some of your accounts might require special permission to be able to access your accounts. |
![]() |
| Extra info on setting up your devices and applications. |
![]() |
| http://windows.microsoft.com/en-us/windows/app-passwords-two-step-verification |
Feb 17, 2013
Want to click? Think again…
attack Twitter, Facebook, New York Times and Wall Street Journal.




















































