BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Identity Thief Irene More Profitable Than Memphis Raines

Posted November 7, 2011    Peter McCalister

How many of you remember the Nicholas Cage character, Memphis Raines in the action movie Gone in 60 Seconds? If you do, bravo for being an action movie buff… for those of you not “in the know” he was a (fictional) car thief who had to steal 50 high end cars in just one night.

gone 60

So how is it that I am comparing a car thief to an Identity thief in today’s blog? The answer is courtesy of Brian Krebs and his recent blog titled “Identity Theft More Profitable Than Car Theft.” In his blog he describes “Recent hacker break-ins at a half-dozen car dealerships nationwide are a reminder of just how easily one’s personal and financial information can be jeopardized by poor security at any of of tens of thousands of organizations that have access to that data.” Mr.Krebs goes on to describe how personal information was stolen from the automotive finance department of a number of dealerships using RouteOne software and what you should do to personally protect yourself.

One of the things not covered is how to protect from the dreaded insider threat and what happens if a rogue administrator decides to sell the data or if so outside hacker hijacks that admin’s credentials to steal the data under the guise of normal use. This is why we are constantly educating you on the value of least privilege and eliminating excessive admin rights across all IT systems using a privilege identity management solution.

Without an effective privilege identity management solution in place to protect your critial data, you too can be hacked by identity thieves and your data (and profitability) gone in 60 seconds.

Leave a Reply

Additional articles

normal-blog-img

New IT Security Best Practices for Maintaining “Business as Usual” Despite Evolving Threats

Posted August 13, 2014    Morey Haber

It’s time to get back to business. Here in the U.S., summer vacations are wrapping up and businesses are looking forward to closing out 2014. Over the past year, we’ve seen several incidents that warrant changes in the ways consumers make purchases and businesses conduct transactions. Consider last week’s theft of a whopping 1.2 billion…

Tags:
, , ,

Retina Vulnerability Audits – August 2014 Patch Tuesday

Posted August 12, 2014    BeyondTrust Research Team

The following is a list of Retina vulnerability audits for this August 2014 Patch Tuesday: MS14-043 - Vulnerability in Windows Media Center Could Allow Remote Code Execution (2978742) 34924 – Microsoft WMC Remote Code Execution (2978742) MS14-044 - Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340) 34915 – Microsoft SQL Server Multiple Vulnerabilities (2984340) – 2008 34916 –…

patch-tuesday

August 2014 Patch Tuesday

Posted August 12, 2014    BeyondTrust Research Team

This August Microsoft has released nine security bulletins which account for a whole variety of critical vulnerabilities. The most critical bulletins are MS14-051 (Internet Explorer), MS14-045 (Kernel-mode), and MS14-049 (Windows Installer). MS14-043 fixes a critical code execution vulnerability within Windows Media Center (people still use that?). The vulnerability itself is specifically within a COM object…

Tags:
, , ,