Recommendations
Toktumi.com

Get Dropbox!

Social
Suggested Reading
  • Think and Grow Rich
    Think and Grow Rich
    by Napoleon Hill
  • Buddha: A Story of Enlightenment
    Buddha: A Story of Enlightenment
    by Deepak Chopra
  • How To Win Friends and Influence People
    How To Win Friends and Influence People
    by Dale Carnegie
  • The Wisdom of Crowds
    The Wisdom of Crowds
    by James Surowiecki
  • Purple Cow: Transform Your Business by Being Remarkable
    Purple Cow: Transform Your Business by Being Remarkable
    by Seth Godin
  • The 7 Habits of Highly Effective People
    The 7 Habits of Highly Effective People
    by Stephen R. Covey

Entries in Cisco (2)

Tuesday
Apr282009

Phishing, with a side of Swine Flu

I just read the following on the MSNBC web site:
(http://tinyurl.com/msnbc-phishing-swine-flu)

Phishing with Swine Flu as bait


Phishers and spammers have caught Swine Flu fever and are exploiting fears around the outbreak to try to sell pharmaceutical products or steal information, security experts said Tuesday.

The e-mail scams have a subject line related to the Swine Flu and typically contain either a link to a phishing Web site or an attachment that contains malicious code, the US-CERT said in an advisory. (Read More...)


Stuff like this reminds me how evil some people can be, and how ubiquitous email has become. Let's be clear, these types of attacks always happen through email. Not through websites. Not through your fax machine. Not via instant messaging (IM), or SMS. These attacks don't reach you via your cell phone, and these attacks don't arrive via FedEx or UPS. Its ALWAYS via email.

For the last decade companies like Microsoft, Cisco, Symantec, Google, McAfee, Trend Micro, Sonic Wall, Barracuda Networks, etc. have made (and spent) billions of dollars trying to convince us they know what they are doing when it comes to the security of our email. How much longer, and how many more exploits like this one, is it going to take before people realize that email, the original social networking application, deserves to be secured the same way Facebook, Twitter, LinkedIn, AIM, and Plaxo are secured?

Isn't it time, once and for all, for authenticated email to take the main stage? What is everyone so afraid of? Threat free email is available, today, and is currently in use by millions of people and thousands of companies around the world.

It is time to stop the insanity. Continuing to do what you've always done (filtering your email) will always yield the mediocre results you are seeing today.

Thursday
Dec182008

Cisco’s annual security study is out, and...

Cisco’s annual security study is out, and not surprisingly personalized spam and phishing attacks are on the rise:

http://ibtimes.com/articles/20081217/personalized-spam-rising-sharply-study-finds.htm

Personalized spam rising sharply, study finds
By JORDAN ROBERTSON

SAN FRANCISCO (AP) — Yes, guys, those spam e-mails for Viagra or baldness cream just might be directed to you personally. So, too, are many of the other crafty come-ons clogging inboxes, trying to lure us to fake Web sites so criminals can steal our personal information.

A new study by Cisco Systems Inc. found an alarming increase in the amount of personalized spam, which online identity thieves create using stolen lists of e-mail addresses or other poached data about their victims, such as where they went to school or which bank they use.

Unlike traditional spam, most of which is blocked by e-mail filters, personalized spam, known as "spear phishing" messages, often sail through unmolested. They're sent in smaller chunks, and often come from accounts the criminals have set up at reputable Web-based e-mail services. Some of the messages are expertly crafted, linking to beautifully designed Web sites that are bogus or immediately install malicious programs.

Cisco's annual security study found that spam is growing quickly — nearly 200 billion spam messages are now sent each day, double the volume in 2007 — and that targeted attacks are also rising sharply.

More than 0.4 percent of all spam sent in September were targeted attacks, Cisco found. That might sound low, but since 90 percent of all e-mails sent worldwide are spam, this means 800 million messages a day are attempts are spear phishing. A year ago, targeted attacks with personalized messages were less than 0.1 percent of all spam.

The latest attacks include text-message spam, e-mails trying to trick business owners into coughing up credentials for their Google advertising accounts, or personalized "whaling" e-mails to executives claiming that their businesses are under investigation by the FBI or that there's a problem with their personal bank account.

As the world's largest maker of networking gear, Cisco is in a unique position to study the traffic flowing through its customers' networks, which include the biggest Internet providers and corporations. The latest study was based in part on the company's ability to monitor 30 percent of all Web and e-mail traffic through its hardware and software and a network of companies that contribute data.