BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Why Innocent Looking Facebook Photos Can Be Dangerous

Posted July 16, 2012    Peter McCalister

Hacker attacks are far more publicized than insider attacks. In fact, according to the 2011 CyberSecurity Watch Survey conducted by CSO Magazine and Deloitte, 70 percent of insider incidents are handled internally without legal action. This begs the question – how many of those incidents are disclosed to the public? While a majority of U.S. states have enacted security breach notification laws it hasn’t stopped some organizations from covering up insider breaches. And of even more concerning, some businesses have no idea that their intellectual property is being compromised by way of popular social media platforms.

The rapid consumerization of IT coupled with the increasingly popular use of social media platforms to increase brand visibility and socialize CRM is drastically expanding the threat landscape for enterprises. It is becoming apparent that hackers and malicious software developers are targeting social media platforms as channels to commit cybercrimes and pilfer information.

Malicious attackers have a number robust toolkits and clever methods to slip past defenses, including: emails with hidden agendas, USB drives containing malware, insider threats and now the utilization of third party social media sites with posted images, audio and video files to gain access to company networks without detection.

A recent article by Dark Reading highlights how an innocent-looking vacation picture on Facebook could conceivably traffic exfiltrated documents. According to the article, “Security researchers will unveil at Black Hat USA a new method of hiding sensitive information in the encoding of seemingly safe images shared on social media sites to avoid security mechanisms. The method employed by a new tool they developed called SNScat can not only be used to exfiltrate data off networks without detection, but to also run covert botnets through the type of social media network traffic allowed by most businesses today.”

Social media’s infiltration into the enterprise isn’t slowing down and it’s becoming critical that enterprises invest in vulnerability management, mobile device management and privilege access management to keep the pace against the dark side of innovation and malicious attackers.

Leave a Reply

Additional articles

powerbroker-for-mac-diagram-small

PowerBroker for Mac: A Least-Privileged Apple a Day…

Posted July 27, 2015    Jason Silva

BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

Tags:
, ,
PrivilegedAccountManagement

On Demand Webinar – Now is the time for Privileged Account Management

Posted July 24, 2015    BeyondTrust Software

In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

Tags:
, ,
dave-shackleford-headshot

Privileged Account Management: The Time is Now

Posted July 22, 2015    Dave Shackleford

There’s plenty of problems we don’t have great options for in InfoSec today. Malware is a pain point that keeps evolving rapidly. 0-day exploits are tough to prepare for. Privileged account management? We got this. We know the root causes, we know how it manifests, we know how to get it under control effectively, and there are great technology solutions that are enterprise-class.

Tags:
, ,