Showing posts with label 2015. Show all posts
Showing posts with label 2015. Show all posts

Thursday, 17 December 2015

Top security stories of 2015

Not a shocker to have data breaches lead the way as criminals get ever more devious.


More data breaches

Hacking Team, Comcast, Ashley Madison… the list goes on of companies who became just another notch in the belt of cybercriminals. Like in years past, data breaches were top of the list for our year in review story. Here are some stories that made headlines in 2015.

Dell puts privacy at risk with dangerous root certificate
Dell has come under fire for shipping PCs with a pre-installed trusted root certificate that can be used to compromise the security of encrypted HTTPS connections.

"Surely Dell had to have seen what kind of bad press Lenovo got when people discovered what Superfish was up to. Yet, they decided to do the same thing but worse. This isn't even a third-party application that placed it there; it's from Dell's very own bloatware," commented the Reddit poster under the name "rotorcowboy".

Comcast Xfinity Wi-Fi discloses customer names and addresses
The Xfinity Wi-Fi service from Comcast disclosed the full name and home address of residential customers, which is something the company says isn’t supposed to happen. The disclosure of such information increases an already exposed attack surface, by allowing anyone with malicious intent to selectively target their marks.

It has been just over two years since Comcast launched the Xfinity Wi-Fi service, which created a separate wireless network in homes and businesses for existing customers and the general public.

Police arrest 15-year-old in TalkTalk hack
UK telecom TalkTalk disclosed a possible breach, which could impact upwards of 4 million customers. Those responsible for the attack likely compromised names, addresses, birthdays, phone numbers, email addresses, TalkTalk account information, credit card data, and banking information. A 15-year-old boy was later arrested.

Soon after the disclosure, TalkTalk reported that someone claiming to be responsible for the attack demanded a ransom, but the company didn't go into detail on the demand itself.

4.6M customers impacted by Scottrade breach
Brokerage firm Scottrade alerted customers to a data breach, which affected 4.6 million people. Scottrade learned about the problem after being contacted by the FBI. According to the email sent to customers, and a public notice, the authorities learned that Scottrade was compromised while investigating other data-theft cases.

"If your information was contained in the affected database, you will receive a letter or email from Scottrade with additional information and resources. We have secured the known intrusion point and conducted an internal data forensics investigation on this incident with assistance from a leading computer security firm. We have taken appropriate steps to further strengthen our network defenses," Scottrade told customers.

T-Mobile US says Experian breach exposed 15M customers
T-Mobile US CEO, John Legere, said that the names, addresses, Social Security numbers, birthdays, and ID information on more than 15 million customers had been compromised after a breach at Experian.

"The investigation is ongoing, but what we know right now is that the hacker acquired the records of approximately 15 million people, including new applicants requiring a credit check for service or device financing from September 1, 2013 through September 16, 2015," a statement from T-Mobile's head executive added.

Ashley Madison hackers publish compromised records
The group responsible for the Ashley Madison hack published the compromised records on Tuesday, delivering on the promise made when the hack was announced in July. The compromised records include account profile information, personal information, financial records, and more.

In July, a group calling themselves Impact Team leaked a selection of files that they claimed originated form Avid Life Media (ALM), the company behind adult playgrounds of Ashley Madison, Cougar Life, Established Men, and others.

IRS: Breach larger than first reported, 220k additional taxpayers affected
The Internal Revenue Service (IRS) said that the data breach reported in May has now impacted a total to 330,000 taxpayers. In addition, the agency sent 170,000 taxpayers notifications that their personal information was potentially exposed during the incident.

The compromise occurred through the "Get Transcript" application used by the tax agency. Using previously acquired personal information (PII), criminals were able to access the "Get Transcript" application to obtain old tax returns.

OPM says second breach compromised 21 million records
The breach at the Office of Personnel Management impacted 21.5 million people.The incident exposed Social Security Numbers and biometric data for federal employees and in some cases their families. OPM became aware of the second breach while investigating the first one disclosed in June.

At the time, the OPM said that the breach impacted the personal information of 4.2 million current and former federal employees. This second incident began in May of 2014 and went undiscovered for a year, however the OPM has stated that patches applied to systems in January halted the extraction of data.

Hacking Team hacked, attackers claim 400GB in dumped data
Specializing in surveillance technology, Hacking Team is now learning how it feels to have their internal matters exposed to the world, and privacy advocates are enjoying a bit of schadenfreude at their expense.

Hacking Team is an Italian company that sells intrusion and surveillance tools to governments and law enforcement agencies.

The attackers published a Torrent file with 400GB of internal documents, source code, and email communications to the public at large.

CareFirst data breach affects 1.1 million people
CareFirst BlueCross BlueShield (CareFirst) disclosed a data breach that impacts 1.1 million current and former members, who registered to use the insurer's websites or who did business with them online prior to June 20, 2014.

CareFirst stated that they detected the initial compromise and took action to contain the attack. The assumption made was that their actions helped avoid a crisis.

Anthem: 78.8 million affected, FBI close to naming suspect
Anthem, the nation's second largest health insurer, said that 8.8 to 18.8 million people who were not customers could be impacted by their recent data breach, which at last count is presumed to affect some 78.8 million people. This latest count now includes customers of independent Blue Cross Blue Shield (BCBS) plans in several states.

Saturday, 31 October 2015

2015 technology industry graveyard

2015 technology industry graveyard
Cisco, Microsoft, Google and others bury outdated technologies to move ahead with new ones.

Ba-bye
The Technology Industry Graveyard is pretty darn full in 2015, and we’re not even including the near-dead such as RadioShack and Microsoft’s IE browser. Pay your respects here…

GrooveShark
The self-described “World’s Music Library” is no more after shutting down in April in the wake of serious legal pressure by music companies whose songs GrooveShark allowed to be shared but had never licensed. Apple and Google had each kicked GrooveShark out of their app stores years ago due to complaints from music labels. Much more sadly than the 9-year-old company’s demise, however, was the death of co-founder Josh Greenberg in July at the age of just 28.

Typo iPhone keyboard
Not even the glamor of being co-founded by American Idol host Ryan Seacrest could help Typo Innovations save its iPhone keyboard, which BlackBerry said infringed on its patents. So instead, Typo bailed on the iPhone model and settled for selling ones for devices with screens 7.9-inches or larger (like iPads).

Amazon Fire Phone
With a product name like Fire, you’re just asking for colorful headlines if it bombs. And indeed, Amazon has stopped making its Fire Phone about a year after introducing it and media outlets were quick to highlight the company “extinguishing” it or remarking on the phone being “burnt out.” Amazon has had some success on the hardware front, namely with its Kindle line, but the Fire just didn’t distinguish itself and was going for free with a carrier contract by the end.

Interop New York
Interop Las Vegas carries on as one of the network industry’s top trade shows next May, but little sibling Interop New York is no more this year. The Fall show, traditionally held at the Javits Center since 2005, was always smaller and was discontinued for 2015 despite lively marketing material last year touting “More Than 30 Interop New York Exhibitors and Sponsors to Make Announcements in Anticipation of the Event.”

GTalk
Google ditched so many things in 2015 that we devoted an entire slideshow to Google’s Graveyard. So to choose just one representative item here, we remember Google Talk, which had a good run, starting up in 2005. But it’s never good when Google pulls out the term “deprecated” as it did in February in reference to this chat service’s Windows App. Google said it was pulling the plug on GTalk in part to focus on Google Hangouts in a world where people have plenty of other ways to chat online. However, Google Talk does live on via third-party apps.

Cisco Invicta storage products
Cisco has a good touch when it comes to acquisitions, but its $415 mlllion WHIPTAIL buyout from 2013 didn’t work out. The company in July revealed it had pulled the plug on its Invicta flash storage appliances acquired via that deal. It’s not unthinkable though that Cisco could go after another storage company, especially in light of the Dell-EMC union.

RapidShare
The once-popular file hosting system, begun in 2002, couldn’t withstand the onslaught of competition from all sides, including Google and Dropbox. Back in 2009, the Switzerland-based operation ran one of the Internet’s 20 most visited websites, according to Wikipedia. It shut down on March 31, and users’ leftover files went away with it.

Windows RT devices
This locked-down Microsoft OS for tablets and convertible laptops fared about as well as Windows 8, after being introduced as a prototype in 2011 at the big CES event in Las Vegas. Microsoft’s software for the 32-bit ARM architecture was intended to enable devices to exploit that architecture’s power efficiency, but overall, the offering proved to be a funky fit with existing Windows software. Production of RT devices stopped earlier in 2015 as Microsoft focuses on Win10 and more professional-focused Surface devices.

OpenStack vendor Nebula
As Network World’s Brandon Butler wrote in April, Nebula became one of the first casualties of the open source OpenStack cloud computing movement when it shuttered its doors. The company, whose founder was CIO for IT at NASA before starting Nebula in 2011, suggested in its farewell letter that it was a bit ahead of its time, unable to convert its $38 million in funding and hardware/software appliances into a sustainable business.

FriendFeed
Facebook bought this social news and information feed aggregator in 2009, two years after the smaller business started, and then killed it off in April. People have moved on to other means of gathering and discovering info online, so FriendFeed died from lack of use. It did inspire the very singular website, Is FriendFeed Dead Yet, however, so its legacy lives on.

Apple Aperture
Apple put the final nails in its Aperture photo editing app in 2015, ending the professional-quality post-production app’s 10-year run at Version 3.6. In its place, Apple introduced its Photos app for users of both its OS X Mac and iOS devices.

Secret
One of the co-founders of anonymous sharing app shared this in April: The company was shutting down and returning whatever part of its $35 million in funding was left. The company’s reality was just not going to meet up with his vision for it, said co-founder David Byttow. The company faced criticism that it, like other anonymous apps such as Yik Yak, allowed for cyberbullying.

Amazon Wallet
Amazon started the year by announcing its Wallet app, the company’s 6-month-old attempt to get into mobile payments, was a bust. The app, which had been in beta, allowed users to store their gift/loyalty/rewards cards, but not debit or credit cards as they can with Apple and Google mobile payment services.

Circa News app
Expired apps could easily fill an entire tech graveyard, so we won’t document all of their deaths here. But among them not making it through 2015 was Circa, which reportedly garnered some $4 million in venture funding since starting in 2012 but didn’t get enough takers for its app-y brand of journalism.


Monday, 5 January 2015

2015 Unified Communications Predictions Part I

As has been our custom for over a decade, it’s time for our annual predictions on what will happen in the coming year for Unified Communications (UC). We’ll start with what is a clear 2014 trend that will continue in 2015: the growing adoption of cloud-based UC.

Most cloud providers have reported double-digit growth this year of their IP Telephony (IPT) and UC portfolios, while premise-based systems growth remains in the high single digits year-over-year. We attribute this to both to the adoption of stand-alone cloud services, plus the adoption of cloud-based UC as a hybrid solution that also includes premise-based components. We expect to see continued UC endpoint growth as organizations move beyond simple IPT, especially in hybrid solutions that integrate cloud-based UC with private IPT systems.

Both end users and IT organizations continue to become more comfortable with a mobile device or softphone as an IPT endpoint, and we expect that trend to continue, although many users will cling to their desktop phones for years to come.

Another 2014 trend that will accelerate is the proliferation of Voice over LTE (VoLTE) in the U. S. market. AT&T and Verizon network adoption of VoLTE will be especially noteworthy in 2015, as these two carriers move to eventually retire their 3G voice network—providing consumers and business customers with wideband (high-definition) voice and increased compatibility/interoperability with video and other collaboration media. VoLTE acceleration will also help as a prerequisite for replacing the legacy PSTN for carriers who maintain both wired and wireless networks.

The PSTN will continue a steady march toward retirement as AT&T and Verizon lay the groundwork to replace their legacy switching with an all-IP network. AT&T plans to retire its TDM and SS7 infrastructures by 2020. We expect that AT&T and Verizon will still need a host of gateways in 2020 to interconnect with other carriers that aren’t as aggressive with full-scale replacement within the next five years, so the network planners will be very busy with internal projects and interconnect proposals for an orderly transition.

Next time, we’ll cover some other UC news, and then return in 2015 after the holidays with part two of our predictions.



Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com