Wednesday, July 8, 2015
NORSE: Watch cyber attacks real time
◼ WATCH IT HERE
Every second, Norse collects and analyzes live threat intelligence from darknets in hundreds of locations in over 40 countries. The attacks shown are based on a small subset of live flows against the Norse honeypot infrastructure, representing actual worldwide cyber attacks by bad actors. At a glance, one can see which countries are aggressors or targets at the moment, using which type of attacks (services-ports).
Hovering over the ATTACK ORIGINS, ATTACK TARGETS, or ATTACK TYPES will highlight just the attacks emanating from that country or over that service-port respectively. Hovering over any bubble on the map, will highlight only the attacks from that location and type.
NYSE TRADING HALTED...
Today's glitches are imitating the plot of 'Die Hard' 4 http://t.co/aCBZ8UUV0X pic.twitter.com/kwhQFtnWTD
— Washington Examiner (@dcexaminer) July 8, 2015#NYSE: "We're currently experiencing a technical issue that we're working to resolve as quickly as possible." pic.twitter.com/od7ECfNj2e
— FOX Business (@FoxBusiness) July 8, 2015Anonymous targeted Wall Street in cryptic tweet on eve of #NYSE shutdown: http://t.co/3XkiyusR6P pic.twitter.com/thMxDhgROC
— The Hill (@thehill) July 8, 2015Here's the cryptic message Anonymous posted last night before New York Stock exchange outage http://t.co/dWthewpvol pic.twitter.com/C12oLeZlWk
— TheBlaze (@theblaze) July 8, 2015BREAKING UPDATE: No indications at this point of a cyberattack. (@PeteWilliamsNBC)
READ: http://t.co/5whAvi91X6 pic.twitter.com/epW17CIem5
— Breaking News Feed (@PzFeed) July 8, 2015Cybersecurity Stocks Surge... http://t.co/78Nnh33h6c
— DRUDGE REPORT (@DRUDGE_REPORT) July 8, 2015
Friday, September 5, 2014
Huge Chinese cyberattack against the US right now,
WATCH IT LIVE
WOW!!!!!!!!!!!! RT @PaulSzoldra There’s a pretty huge Chinese cyberattack against the US right now, watch it live: http://t.co/aKclKFHqwc
— slone (@slone) September 6, 2014◼ Hold the cursor over the China entry under attack options and you can see all the attacks. - Weasel Zippers
Monday, February 3, 2014
HHS searching for malware from Belarus in Obamacare software... “Every shred of data one would need to steal your identity or access your confidential credit information would be available at the fingertips of a skilled hacker, producing a staggering security threat”
U.S. intelligence agencies last week urged the Obama administration to check its new healthcare network for malicious software after learning that developers linked to the Belarus government helped produce the website, raising fresh concerns that private data posted by millions of Americans will be compromised.
The intelligence agencies notified the Department of Health and Human Services, the agency in charge of the Healthcare.gov network, about their concerns last week. Specifically, officials warned that programmers in Belarus, a former Soviet republic closely allied with Russia, were suspected of inserting malicious code that could be used for cyber attacks, according to U.S. officials familiar with the concerns....
Officials disclosed the software compromise last week after the discovery in early January of statements by Belarusian official Valery Tsepkalo, director of the government-backed High-Technology Park (HTP) in Minsk.
Tsepkalo told a Russian radio station in an interview broadcast last summer that HHS is “one of our clients,” and that “we are helping Obama complete his insurance reform.”
“Our programmers wrote the program that appears on the monitors in all hospitals and all insurance companies—they will see the full profile of the given patient,” Tsepkalo said June 25 on Voice of Russia Radio.
White House National Security Council spokeswoman Caitlin Hayden said an intelligence report on the Belarusian software was “recalled by the intelligence community shortly after it was issued.”
...House Permanent Select Committee on Intelligence Chairman Rep. Mike Rogers (R., Mich) said he was surprised by media reports from Belarus indicating “some parts of Healthcare.gov or systems connected to it may have in fact been written overseas.” He called for an independent security review of the Obamacare website.
Rogers said he was especially concerned by the potential software vulnerability because a CGI executive, Vice President Cheryl Campbell, testified to Congress that all software work for the network had been done in the United States.
“We need an independent, thorough security evaluation of this site, and we need the commitment from the administration that the findings will be acknowledged and promptly addressed,” Rogers told the Free Beacon.
“I continue to call on HHS to shut down and properly stress test the site to ensure that consumers are protected from potential security risks from across the globe.”
...According to HHS, between Oct. 1 and the end of the year, 1. 9 million people signed up for healthcare through the federal website. Another 956,000 enrolled through state websites. More than 55 million people visited both the federal and state websites.
The threat of data diversion is compounded by the discovery last year that Belarus covertly diverted massive amounts of U.S. Internet traffic to Belarus.
According to the New Hampshire-based security firm Renesys, which discovered the data diversion, throughout February 2013, Internet traffic from the United States was sent to Belarus. The purpose likely was to allow hackers or government agencies to sift for data for financial, economic, or government intelligence.
◼ Obamacare data hub looms as privacy threat - USA Today Rep. Mike Rogers, chairman of the House Intelligence Committee.
Friday, January 17, 2014
World's greatest hacker calls Healthcare.gov security 'shameful'
...His comments were backed up by testimony by Kennedy, who is CEO and founder of TrustedSec LLC and a self-described "white hat hacker," meaning someone who hacks in order to fix security flaws and not commit cybercrime. In November, Kennedy and other experts testified before the same panel about security issues on Healthcare.gov.
Kennedy testified that most of the flaws they identified at the time still exist on the site, and said "indeed, it's getting worse," telling the panel that he and other experts have seen little improvement in the past two months.
◼ Hackers: HealthCare.gov still riddled with potential security issues - NBC
Cybersecurity researchers slammed HealthCare.gov's security during a House hearing on Thursday, saying the site is still riddled with problems that could put consumers' sensitive health details at risk.
“The reason we’re concluding that this is so shockingly bad is that the issues across the site are so varied,” David Kennedy, founder of the information security firm TrustedSec, told NBC News. “You don’t even have to hack into the system to see big issues – which means there are [major problems] underneath.”
...“Some issues still include critical or high-risk findings to personal information,” Kennedy said in his written testimony. He also submitted statements from seven other security researchers who expressed serious concerns.
◼ Democrat Claiming to be Obamacare Watchdog Just Voted Against Improving Healthcare.gov Security - Bryan Preston/PJMedia
Democrat Rep. Ann Kirkpatrick (AZ) is running a re-election ad in which she claims that she is blowing the whistle on problems with the Obamacare rollout. That in and of itself is a joke — she supported the law when it was passed and still supports it.
Today, it became even more of a joke. The House passed a bill today, H.R. 3362, that requires that the government disclose to Americans when their information has been compromised via Healthcare.gov. Thirty-three Democrats joined the GOP majority in passing the bill, 259-154. It was not a close vote.
But Rep. Ann Kirkpatrick was not among the yays. The so-called watchdog just voted against letting Americans know when Healthcare.gov has endangered their privacy and personal information.
Tuesday, December 17, 2013
Obama Administration ‘has thrown Americans’ data security out the window’
◼ Congresswoman: Require Feds to Disclose Security Breaches on Healthcare.gov - Washington Free Beacon
A bill in the House of Representatives would require the federal government to tell Americans if their personal information has been stolen while using Healthcare.gov.
Rep. Diane Black (R., Tenn.) introduced the “Federal Exchange Data Breach Notification Act of 2013” on Thursday to address privacy concerns regarding the Obamacare insurance website, which has been live for months despite its lack of fundamental security safeguards.
“IT experts have repeatedly raised red flags about the security of the information people are putting into the exchanges, and it is only fair that the administration gives people proper notice if this information has been compromised,” she said. “Americans deserve this basic notice so that they can protect themselves from cyber attacks and identity theft.”
Monday, December 2, 2013
"...vulnerabilities remain on "everything from hacking someone's computer so when you visit the website it actually tries to hack your computer back, all the way to being able to extract email addresses, users names—first name, last name—[and] locations"
Another online security expert—who spoke at last week's House hearing and then on CNBC—said the federal Obamacare website needs to be shut down and rebuilt from scratch. Morgan Wright, CEO of Crowd Sourced Investigations said: "There's not a plan to fix this that meets the sniff test of being reasonable."
◼ LATE IT CASH SURGE FORESHADOWED HEALTH-LAW WOES Although the Affordable Care Act has been law for three and a half years, one third of the funds going to the top contractors working on the federal exchanges were awarded in the six months before the new insurance marketplaces opened Oct. 1, a Bloomberg Government Analysis has found.
The torrent of late spending — almost $352 million of $1 billion in awards to the top 10 contractors — indicates the magnitude of the work still to be done as opening day approached, and helps explain the information technology problems that have dogged the exchange system since its launch. In a typical IT project, spending ramps up to a peak, then trails off during the final phase....
...unlike the GAO study, which focused solely on contracting for the exchanges and a related data services hub, BGOV used its federal contracts database to look at all health law-related contract awards to the firms since the ACA was enacted in March 2010.
It included all awards where the acronym “ACA,” or the names or acronyms of programs closely related to the law appeared in the contract descriptors. It excluded all contracts where a direct link could not be made to the law, although it assumed that most recent IT awards by the Department of Health and Human Services are ACA-related because the law’s implementation has consumed an increasing share of the department’s time and resources....
Besides showing the rush to issue contract awards in the months leading up to the opening of exchanges, the BGOV analysis also revealed that the implementation of the health law is costing substantially more than generally is portrayed.
Although the GAO made clear that its study focused solely on the costs of implementing the federal exchanges and the data services hub, its $394 million tally for work through March 31 has been widely cited as the price tag for the entire launch of the law. But in looking at the full range of ACA-related contracts for just 10 firms, the BGOV analysis found more than $1 billion worth of contract awards.
Friday, October 4, 2013
Friday, June 7, 2013
Obama orders US to draw up overseas target list for cyber-attacks
◼ Read the secret presidential directive here
◼ Obama draws up plans for cyber attacks on China as he meets leader in California - ASSOCIATED PRESS and ROSEMARIE LENTINI via Daily Mail
◼ In a countermove to Mr. Obama´s charges that Chinese hackers are targeting the U.S., Xi said Friday that his country is also a victim of cyber-attacks. But through "good faith cooperation," said Xi, the U.S. and China can make cybersecurity "a positive area of cooperation." - CBS
Tuesday, April 23, 2013
Internet 'security' bill CISPA moves to Senate
The House vote, 288-127, puts the spotlight on the Senate, which hasn't taken up the issue and is consumed with other high-profile issues such as gun control and immigration. The lack of enthusiasm in the Senate and objections by the White House mean that the legislation is in limbo despite an aggressive push by lobbyists representing nearly every corner of industry.
But supporters said they were gaining momentum: Despite the White House veto threat 92 Democrats voted for the measure, compared to only 42 for a similar bill last year.
Tuesday, February 12, 2013
The Executive Order The Press Agreed To Keep Secret For Five Hours
The order — setting up new programs aimed at stopping online espionage and terrorism — was already the law of the land, signed by the president. But it was also secret.
The document was "embargoed until delivery of the President's in the State of the Union address" — despite the fact it had already been signed....
White House spokesman Tommy Vietor explained in an email Administration's decision to, temporarily, conceal the new order: "We wanted to release the EO early on an embargoed basis because the subject matter is complicated and we knew you guys would have questions. It seemed more helpful for the press corps than sending it concurrent with the speech."
Vietor added "this isn't unprecedented. Take for example sanctions Executive Orders. They are signed one day, go into effect at midnight but are not released until the next day."
The new order appears, however, to have taken effect immediately; Vietor didn't respond to a follow up question about when the order took effect.
Keeping White House executive orders secret is far from unprecedented, but usually concerns actual secrets. In 2002, the Bush White House signed a controversial executive order allowing for warrantless surveillance on those suspected of terrorism. - Read more at the link
◼ Cybersecurity Executive Order Is a Mistake Every Way You Look at It - David Inserra/Heritage: The Foundry
Monday, May 28, 2012
FLAME: ‘ONE OF THE MOST COMPLEX THREATS EVER DISCOVERED’: NEW CYBER WEAPON FOUND IN IRAN
The presence of the virus — dubbed “Flame” — was announced by the Russian-based Kaspersky Labs on Monday. Reuters reports the security software firm has not said whether the cyber weapon was deployed with a specific mission like that of the Stuxnet worm, which is suspected to have been launched to help take down Iran’s nuclear infrastructure.
Comparing Flame to Stuxnet, Reuters reports experts finding the virus has 20 times more code. Compared to most computer viruses that steal financial information, Flame has 100 times more code. Kaspersky Labs found it exploits a vulnerability in Windows, like Stuxnet. BBC reports that this newly discovered virus is being called “one of the most complex threats ever discovered.”
Monday, May 7, 2012
“We’re not going to subpoena reporters in the future. We don’t need to. We know who you’re talking to.”
...The public is generally unaware of how essential nominally classified information is to coverage of diplomatic and strategic news. As Steven Aftergood, director of the Federation of American Scientists’ government secrecy project, put it: “The administration’s aggressive pursuit of leaks represents a challenge to the practice of national security reporting, which depends on the availability of unauthorized sources if it is to produce something more than ‘authorized’ news.”
What’s behind the administration’s fervor isn’t clear, but the news media have largely rolled over and yawned. A big reason is that prosecutors aren’t hassling reporters as they once did. Thanks to the post-9/11 explosion in government intercepts, electronic surveillance, and data capture of all imaginable kinds — the NSA is estimated to have intercepted 15-20 trillion communications in the past decade — the secrecy police have vast new ways to identify leakers.
So they no longer have to force journalists to expose confidential sources. As a national security representative told Lucy Dalglish, director of the Reporters Committee for Freedom of the Press, “We’re not going to subpoena reporters in the future. We don’t need to. We know who you’re talking to....”
Wednesday, December 14, 2011
In the name of protecting copyright, this bill bring about the end of the Internet as we know it.
What began as an attempt to restrain foreign piracy on the Internet has morphed into a domestic “kill switch” on First Amendment freedom in the fastest-growing corner of the marketplace of ideas.
Proposed federal legislation purporting to protect online intellectual property would also impose sweeping new government mandates on internet service providers — a positively Orwellian power grab that would permit the U.S. Justice Department to shut down any internet site it doesn’t like (and cut off its sources of income) on nothing more than a whim.


