SlideShare une entreprise Scribd logo
1  sur  13
Andrew Horbury
Product Marketing Manager
andy_horbury@symantec.com
Andrew Shepherd
EMEA Marketing Manager
andrew_shepherd@symantec.com
WEBSITE SECURITY THREATS:
APRIL 2014 UPDATE
Thursday 17th April 2014
Website Security Threats: April 2014 Update
Agenda
Website Security Threats: April 2014 Update
1
2
3
4
5
6
Heartbleed Update
Month in Numbers
Annoying Malware
Watering Holes and Phishing
Insider Threats
Stranger than Fiction
7 Good news
Heartbleed – OpenSSL Vulnerability
• This is not a vulnerability with SSL/TLS
• SSL/TLS is not broken, nor are the SSL certificates issued by Symantec
• Users of Open SSL versions 1.0.1 through (and including) 1.0.1f are affected
Advice for Businesses
Check your version of OpenSSL and either:
• Recompile OpenSSL without the heartbeat extension
• Update to the latest fixed version of the software (1.0.1g) if you are using
OpenSSL versions 1.0.1 through (and including) 1.0.1f
• After moving to a fixed version of OpenSSL, contact the SSL certificate’s
issuing Certification Authority for a replacement
• Finally, businesses should also consider resetting end-user passwords that
potentially may have been visible in compromised server memory.
Website Security Threats: April 2014 Update
Heartbleed – OpenSSL Vulnerability 2
Advice for Consumers
• Be aware that your sensitive data such as passwords may
have been seen by a third party if the sites you visit used a
vulnerable version of the OpenSSL library
• Monitor any notices from the vendors or companies you use.
Once a vendor has communicated to you to change your
passwords, please change promptly
• Watch out for potential phishing emails from attackers asking
you to update your password.
• Stick to reputable websites and services. They are most likely
to have immediately addressed the vulnerability.
• Monitor your bank and credit card statements to check for
any unusual transactions.
www.safeweb.com/heartbleed
Website Security Threats: April 2014 Update
The month in numbers
• Zero
• 91% the number that targeted attack campaigns
increased over 2012
• 1 in 392 overall Phishing Rate
• 6,787 New Vulnerabilities
• 23 New 0-Day Vulnerabilities
• 78% of Websites scanned found with vulnerabilities
• 1 in 8 Websites have critical vulnerabilities
• 1 in 566 Websites scanned found with malware
• Ransomware attacks grew by 500% in 2013
Website Security Threats: April 2014 Update
The month in numbers 2
• Slow to fix vulnerabilities
– 342 days Education
– 276 days Healthcare
– 274 Insurance
• 158,000 Boxee.TV forum accounts leaked
• 18 Months – Miss Teen USA’s extortionist sentenced
Website Security Threats: April 2014 Update
New Annoying Malware
Website Security Threats: April 2014 Update
• Browlock ups the ransom price
– Infections have increased
– Uses JavaScript to prevent user from
closing a browser tab
– Poses as local law enforcement
• Trojan.Zbot variant
– Locks desktop by displaying multiple
websites
– Prevents users opening any other
windows or files
– Can be avoided using “show desktop”
command
Watering holes and Phishing attacks
• Attackers infect Chinese takeaway
menu to enter company’s
network
• EA Games website hacked,
hosting fake Apple phishing page
• Grand Theft Auto V – PC beta
testers wanted
Website Security Threats: April 2014 Update
Insider Threats
Website Security Threats: April 2014 Update
• Angry ex-Microsoft employee
leaked OS code
– Worked at Microsoft for 7 years
– Leaked to blogger as revenge after
poor performance review
– Charged with theft of trade secrets
• UK supermarket Morrisons suffers
data theft
– Data stolen from staff payroll system
and published online
– “initial investigations suggest that this
theft was not the result of an external
penetration of our systems”
Stranger than fiction
Website Security Threats: April 2014 Update
• Triathlete wiped out by “hacked” camera
drone
• Man receives threats from his own
printer
• Prince Harry needs some new parquet
floors at Buckingham Palace
– Or does he…?
• US Army Commander causes widespread
confusion in multiple agencies
Good News
• Hacked domain and website takeover
of Ramshackleglam.com ends well
– Risky sting pays off for tenacious blogger
who was not helped by her hosting
company or domain name registrar.
• Five years on UK agency fixes XSS
vulnerability in their website
• CyrptoDefense criminals bundle
encryption keys with Ransomware
Website Security Threats: April 2014 Update
Link Glossary (Print screen now)
• Heartbleed
– http://www.symantec.com/outbreak
– https://www.staysecureonline.com/heartbleed
– https://ssltools.websecurity.symantec.com/checker/
– www.safeweb.com/heartbleed
• ISTR Resources
– Report http://bit.ly/1ip92jU
– ISTR Blog http://bit.ly/1ip93UQ
• Speed of different verticals to fix vulnerabilities http://bit.ly/1iZMaEi
• Hackers Lurking in Vents and Soda Machines (and menus) http://nyti.ms/1eyxmjM
• Ramshackglam hack http://on.mash.to/1ip9gaC
• ICO XSS Vulnerability http://bit.ly/1mcxJk4
• CryptoDefense Blog http://bit.ly/1hLezT8
Website Security Threats: April 2014 Update
Thank you!
Copyright © 2013 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in
the U.S. and other countries. Other names may be trademarks of their respective owners.
This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied,
are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice.
Andrew Shepherd
andrew_shepherd@symantec.com / +44 7912 552 896
Andrew Horbury
andy_horbury@symantec.com / +44 7703 468 966
@andyhorbury
Website Security Threats: April 2014 Update
Next webinar: Thursday 22nd May 2014
9.30am UK / 10.30am CET

Contenu connexe

Plus de Symantec Website Security

Plus de Symantec Website Security (19)

Symantec Code Sign (NAM)
Symantec Code Sign (NAM)Symantec Code Sign (NAM)
Symantec Code Sign (NAM)
 
Symantec Code Signing (SE)
Symantec Code Signing (SE)Symantec Code Signing (SE)
Symantec Code Signing (SE)
 
Сертификаты подписания кода Symantec
Сертификаты подписания кода SymantecСертификаты подписания кода Symantec
Сертификаты подписания кода Symantec
 
Symantec Code Signing (FR)
Symantec Code Signing (FR)Symantec Code Signing (FR)
Symantec Code Signing (FR)
 
Code signing de Symantec (ES)
Code signing de Symantec (ES)Code signing de Symantec (ES)
Code signing de Symantec (ES)
 
Symantec Code Signing (DE)
Symantec Code Signing (DE)Symantec Code Signing (DE)
Symantec Code Signing (DE)
 
Symantec Code Signing (CH)
Symantec Code Signing (CH)Symantec Code Signing (CH)
Symantec Code Signing (CH)
 
Symantec Code Signing (UK)
Symantec Code Signing (UK)Symantec Code Signing (UK)
Symantec Code Signing (UK)
 
Um guia de e-commerce para a aquisição e manutenção de novos clientes da Syma...
Um guia de e-commerce para a aquisição e manutenção de novos clientes da Syma...Um guia de e-commerce para a aquisição e manutenção de novos clientes da Syma...
Um guia de e-commerce para a aquisição e manutenção de novos clientes da Syma...
 
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
 
Guida per l'e-commerce Symantec - Come acquisire nuovi clienti e conservarli
Guida per l'e-commerce Symantec - Come acquisire nuovi clienti e conservarliGuida per l'e-commerce Symantec - Come acquisire nuovi clienti e conservarli
Guida per l'e-commerce Symantec - Come acquisire nuovi clienti e conservarli
 
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clientsGuía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
 
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clientsGuía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
Guía de comercio electrónico de Symantec: Cómo atraer y retener a nuevos clients
 
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
Guide Symantec de conquête et de fidélisation de nouveaux clients sur vos sit...
 
Leitfaden von Symantec: „Das 1×1 der Kundengewinnung und -bindung im E-Commerce“
Leitfaden von Symantec: „Das 1×1 der Kundengewinnung und -bindung im E-Commerce“Leitfaden von Symantec: „Das 1×1 der Kundengewinnung und -bindung im E-Commerce“
Leitfaden von Symantec: „Das 1×1 der Kundengewinnung und -bindung im E-Commerce“
 
Symantec Website Security Threats: February 2014 Update.
Symantec Website Security Threats: February 2014 Update.Symantec Website Security Threats: February 2014 Update.
Symantec Website Security Threats: February 2014 Update.
 
Symantec SSL Explained
Symantec SSL ExplainedSymantec SSL Explained
Symantec SSL Explained
 
Website Security Threats - January 2014 Update
Website Security Threats - January 2014 Update Website Security Threats - January 2014 Update
Website Security Threats - January 2014 Update
 
Cybercrime - Attack of the Cyber Spies
Cybercrime - Attack of the Cyber SpiesCybercrime - Attack of the Cyber Spies
Cybercrime - Attack of the Cyber Spies
 

Dernier

Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Dernier (20)

Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 

Symantec Website Security Threats:April 2014 Update.

  • 1. Andrew Horbury Product Marketing Manager andy_horbury@symantec.com Andrew Shepherd EMEA Marketing Manager andrew_shepherd@symantec.com WEBSITE SECURITY THREATS: APRIL 2014 UPDATE Thursday 17th April 2014 Website Security Threats: April 2014 Update
  • 2. Agenda Website Security Threats: April 2014 Update 1 2 3 4 5 6 Heartbleed Update Month in Numbers Annoying Malware Watering Holes and Phishing Insider Threats Stranger than Fiction 7 Good news
  • 3. Heartbleed – OpenSSL Vulnerability • This is not a vulnerability with SSL/TLS • SSL/TLS is not broken, nor are the SSL certificates issued by Symantec • Users of Open SSL versions 1.0.1 through (and including) 1.0.1f are affected Advice for Businesses Check your version of OpenSSL and either: • Recompile OpenSSL without the heartbeat extension • Update to the latest fixed version of the software (1.0.1g) if you are using OpenSSL versions 1.0.1 through (and including) 1.0.1f • After moving to a fixed version of OpenSSL, contact the SSL certificate’s issuing Certification Authority for a replacement • Finally, businesses should also consider resetting end-user passwords that potentially may have been visible in compromised server memory. Website Security Threats: April 2014 Update
  • 4. Heartbleed – OpenSSL Vulnerability 2 Advice for Consumers • Be aware that your sensitive data such as passwords may have been seen by a third party if the sites you visit used a vulnerable version of the OpenSSL library • Monitor any notices from the vendors or companies you use. Once a vendor has communicated to you to change your passwords, please change promptly • Watch out for potential phishing emails from attackers asking you to update your password. • Stick to reputable websites and services. They are most likely to have immediately addressed the vulnerability. • Monitor your bank and credit card statements to check for any unusual transactions. www.safeweb.com/heartbleed Website Security Threats: April 2014 Update
  • 5. The month in numbers • Zero • 91% the number that targeted attack campaigns increased over 2012 • 1 in 392 overall Phishing Rate • 6,787 New Vulnerabilities • 23 New 0-Day Vulnerabilities • 78% of Websites scanned found with vulnerabilities • 1 in 8 Websites have critical vulnerabilities • 1 in 566 Websites scanned found with malware • Ransomware attacks grew by 500% in 2013 Website Security Threats: April 2014 Update
  • 6. The month in numbers 2 • Slow to fix vulnerabilities – 342 days Education – 276 days Healthcare – 274 Insurance • 158,000 Boxee.TV forum accounts leaked • 18 Months – Miss Teen USA’s extortionist sentenced Website Security Threats: April 2014 Update
  • 7. New Annoying Malware Website Security Threats: April 2014 Update • Browlock ups the ransom price – Infections have increased – Uses JavaScript to prevent user from closing a browser tab – Poses as local law enforcement • Trojan.Zbot variant – Locks desktop by displaying multiple websites – Prevents users opening any other windows or files – Can be avoided using “show desktop” command
  • 8. Watering holes and Phishing attacks • Attackers infect Chinese takeaway menu to enter company’s network • EA Games website hacked, hosting fake Apple phishing page • Grand Theft Auto V – PC beta testers wanted Website Security Threats: April 2014 Update
  • 9. Insider Threats Website Security Threats: April 2014 Update • Angry ex-Microsoft employee leaked OS code – Worked at Microsoft for 7 years – Leaked to blogger as revenge after poor performance review – Charged with theft of trade secrets • UK supermarket Morrisons suffers data theft – Data stolen from staff payroll system and published online – “initial investigations suggest that this theft was not the result of an external penetration of our systems”
  • 10. Stranger than fiction Website Security Threats: April 2014 Update • Triathlete wiped out by “hacked” camera drone • Man receives threats from his own printer • Prince Harry needs some new parquet floors at Buckingham Palace – Or does he…? • US Army Commander causes widespread confusion in multiple agencies
  • 11. Good News • Hacked domain and website takeover of Ramshackleglam.com ends well – Risky sting pays off for tenacious blogger who was not helped by her hosting company or domain name registrar. • Five years on UK agency fixes XSS vulnerability in their website • CyrptoDefense criminals bundle encryption keys with Ransomware Website Security Threats: April 2014 Update
  • 12. Link Glossary (Print screen now) • Heartbleed – http://www.symantec.com/outbreak – https://www.staysecureonline.com/heartbleed – https://ssltools.websecurity.symantec.com/checker/ – www.safeweb.com/heartbleed • ISTR Resources – Report http://bit.ly/1ip92jU – ISTR Blog http://bit.ly/1ip93UQ • Speed of different verticals to fix vulnerabilities http://bit.ly/1iZMaEi • Hackers Lurking in Vents and Soda Machines (and menus) http://nyti.ms/1eyxmjM • Ramshackglam hack http://on.mash.to/1ip9gaC • ICO XSS Vulnerability http://bit.ly/1mcxJk4 • CryptoDefense Blog http://bit.ly/1hLezT8 Website Security Threats: April 2014 Update
  • 13. Thank you! Copyright © 2013 Symantec Corporation. All rights reserved. Symantec and the Symantec Logo are trademarks or registered trademarks of Symantec Corporation or its affiliates in the U.S. and other countries. Other names may be trademarks of their respective owners. This document is provided for informational purposes only and is not intended as advertising. All warranties relating to the information in this document, either express or implied, are disclaimed to the maximum extent allowed by law. The information in this document is subject to change without notice. Andrew Shepherd andrew_shepherd@symantec.com / +44 7912 552 896 Andrew Horbury andy_horbury@symantec.com / +44 7703 468 966 @andyhorbury Website Security Threats: April 2014 Update Next webinar: Thursday 22nd May 2014 9.30am UK / 10.30am CET