BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Why Innocent Looking Facebook Photos Can Be Dangerous

Posted July 16, 2012    Peter McCalister

Hacker attacks are far more publicized than insider attacks. In fact, according to the 2011 CyberSecurity Watch Survey conducted by CSO Magazine and Deloitte, 70 percent of insider incidents are handled internally without legal action. This begs the question – how many of those incidents are disclosed to the public? While a majority of U.S. states have enacted security breach notification laws it hasn’t stopped some organizations from covering up insider breaches. And of even more concerning, some businesses have no idea that their intellectual property is being compromised by way of popular social media platforms.

The rapid consumerization of IT coupled with the increasingly popular use of social media platforms to increase brand visibility and socialize CRM is drastically expanding the threat landscape for enterprises. It is becoming apparent that hackers and malicious software developers are targeting social media platforms as channels to commit cybercrimes and pilfer information.

Malicious attackers have a number robust toolkits and clever methods to slip past defenses, including: emails with hidden agendas, USB drives containing malware, insider threats and now the utilization of third party social media sites with posted images, audio and video files to gain access to company networks without detection.

A recent article by Dark Reading highlights how an innocent-looking vacation picture on Facebook could conceivably traffic exfiltrated documents. According to the article, “Security researchers will unveil at Black Hat USA a new method of hiding sensitive information in the encoding of seemingly safe images shared on social media sites to avoid security mechanisms. The method employed by a new tool they developed called SNScat can not only be used to exfiltrate data off networks without detection, but to also run covert botnets through the type of social media network traffic allowed by most businesses today.”

Social media’s infiltration into the enterprise isn’t slowing down and it’s becoming critical that enterprises invest in vulnerability management, mobile device management and privilege access management to keep the pace against the dark side of innovation and malicious attackers.

Leave a Reply

Additional articles

Ponemon_Report

Big Surprise: Cost of Data Breaches Up; Are you Doing the *Right* Things to Mitigate the Costs?

Posted May 28, 2015    Scott Lang

Ponemon Institute Cost of Data Breach Study – costs are going up – to the tune of a 23% increase in total costs of data breaches, and a 12% increase in per-record cost since 2013. Are you doing the right things to mitigate costs?

Tags:
, ,
IRS-Data-Breach

The tip of the IRS data breach – and it IS an iceberg

Posted May 27, 2015    Morey Haber

The IRS has been warned for decades about their security best practices. And now, at least 100,000 Americans have had their records compromised. How? The IRS uses a service called “Get Transcript”.

Tags:
, , ,
dave-shackleford-headshot

Tales from the Datacenter: Vulnerability Management Nightmares

Posted May 27, 2015    Dave Shackleford

Vulnerability scanning, threat management, risk analysis, patching, and configuration management are some of the major activities usually associated with vulnerability management, and none of these are new…so why are we failing so badly at many of them?

Tags:
, ,