RSS

Archive | APT RSS feed for this section

APT and attribution

I read an interesting analysis of the malware involved in the March RSA breach. The analysis was done by J. Oquendo and posted over at Infosec Island. After his analysis of the malware involved he believes that “its inconclusive but points more to RBN than APT.”. Read through his analysis and see what you think. [...]

Continue reading...

Some things to look for in your SecurID / Remote Access logs

    The RSA SecurID token has arguably been the defacto second factor authenticator for many years. Despite the recent breach at RSA I do not see many organizations moving to alternate vendors or other second factor technologies, like PKI / SmartCards or telephone based solutions. In the wake of the RSA breach most companies [...]

Continue reading...

Giving a presentation on APT tonight in Manchester, NH

At the last meeting of the New Hampshire chapter of ISSA the subject turned to Advanced Threats (APT, SMT, etc). This was driven mostly by the RSA announcement of their breach that happened just prior to the meeting. I was asked to put something together to share at the next meeting. Most of the presentation [...]

Continue reading...

Bad Behavior has blocked 1586 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.