Braxton Ehle and Sean Williams rant about the latest in information security news to help enterprises and mere mortals defend their information.
Discussed Articles 1) FICO Enterprise Security Score The venerable Fair Isaac Corporation known for it's credit ratings metrics releases a metric to gauge the likelihood of a breach within the next 12 months. * http://www.fico.com/en/newsroom/fico-enterprise-security-score-gives-long-term-view-of-cyber-risk-exposure-10-27-2016 * https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/liu * https://www.privacyrights.org/data-breaches 2) Shamoon disk-wiping malware resurfaces with renewed cyberattacks on Saudi Arabia Iran-attributed malware attacks Saudi Aramco machines and wipes the MBR. * http://www.ibtimes.co.uk/shamoon-disk-wiping-malware-resurfaces-renewed-cyberattacks-saudi-arabia-1594494 * https://www.bloomberg.com/news/articles/2016-12-01/destructive-hacks-strike-saudi-arabia-posing-challenge-to-trump * http://researchcenter.paloaltonetworks.com/2016/11/unit42-shamoon-2-return-disttrack-wiper/ * http://www.irongeek.com/i.php?page=videos/bsideslasvegas2015/pw22-blind-hashing-jeremy-spilman 3) Honorable Mention: US fails to renegotiate arms control rule for hacking tools A nearly two-year effort to renegotiate language related to export controls around intrusion software in the Wassenaar Arrangement was rejected earlier this month during the member states’ plenary meeting. * http://hosted2.ap.org/APDEFAULT/89ae8247abe8493fae24405546e9a1aa/Article_2016-12-19-US--Cybersecurity%20Exports/id-580c483618a04410879cf61da6b7e675 * https://threatpost.com/wassenaar-renegotiation-will-be-in-trump-administrations-hands/122653/ Breach of the Week All the Breaches Bringing you not one, not two, but four breaches: DNC/Russian compromise follow up, Lynda, Yahoo, and Ashley Madison follow up. * http://www.nytimes.com/2016/12/13/us/politics/russia-hack-election-dnc.html * https://dyn.com/blog/dyn-analysis-summary-of-friday-october-21-attack/ * https://krebsonsecurity.com/2016/12/yahoo-one-billion-more-accounts-hacked/ * http://www.csoonline.com/article/3150426/security/ashley-madison-to-pay-16m-settlement-related-to-data-breach.html * http://www.lockheedmartin.com/content/dam/lockheed/data/corporate/documents/LM-White-Paper-Intel-Driven-Defense.pdf * https://gallery.technet.microsoft.com/SAMRi10-Hardening-Remote-48d94b5b


