Web Toolbar by Wibiya Security Firm Bit9 Hacked, Used to Spread Malware

The Cuckoo's Nest

Conspiracy UFO Alternative News Paranormal Debate
 
HomeLatest imagesSearchRegisterLog in



 

 Security Firm Bit9 Hacked, Used to Spread Malware

Go down 
AuthorMessage
I⊥∀NIW∩LLIʞ
Admin
Admin
I⊥∀NIW∩LLIʞ


Posts : 1386
Reputation : 3
Join date : 2012-12-27

Security Firm Bit9 Hacked, Used to Spread Malware Empty
PostSubject: Security Firm Bit9 Hacked, Used to Spread Malware   Security Firm Bit9 Hacked, Used to Spread Malware I_icon_minitimeFri Feb 08, 2013 7:57 pm

Bit9, a company that provides software and network security services to the U.S. government and at least 30 Fortune 100 firms, has suffered an electronic compromise that cuts to the core of its business: helping clients distinguish known “safe” files from computer viruses and other malicious software.

Waltham, Massachusetts-based Bit9 is a leading provider of “application whitelisting” services, a security technology that turns the traditional approach to fighting malware on its head. Antivirus software, for example, seeks to identify and quarantine files that are known bad or strongly suspected of being malicious. In contrast, Bit9 specializes in helping companies develop custom lists of software that they want to allow employees to run, and to treat all other applications as potentially unknown and dangerous.

But earlier today, Bit9 told a source for KrebsOnSecurity that their corporate networks had been breached by a cyberattack. According to the source, Bit9 said they’d received reports that some customers had discovered malware inside of their own Bit9-protected networks, malware that was digitally signed by Bit9′s own encryption keys.

That last bit is extremely important, because Bit9 is a default trusted publisher in their software, which runs on customer PCs and networks as an “agent” that tries to intercept and block applications that are not on the approved whitelist. The upshot of the intrusion is that with a whitelist policy applied to a machine, that machine will blindly trust and run anything signed by Bit9.

An hour after being contacted by KrebsOnSecurity, Bit9 published a blog post acknowledging a break-in. The company said attackers managed to compromise some of Bit9′s systems that were not protected by the company’s own software. Once inside, the firm said, attackers were able to steal Bit9′s secret code-signing certificates.

“Due to an operational oversight within Bit9, we failed to install our own product on a handful of computers within our network,” Bit9′s Patrick Morley wrote. “As a result, a malicious third party was able to illegally gain temporary access to one of our digital code-signing certificates that they then used to illegitimately sign malware. There is no indication that this was the result of an issue with our product. Our investigation also shows that our product was not compromised.”

more here: http://krebsonsecurity.com/2013/02/security-firm-bit9-hacked-used-to-spread-malware/
Back to top Go down
https://thecuckoosnest.forumotion.com
 
Security Firm Bit9 Hacked, Used to Spread Malware
Back to top 
Page 1 of 1
 Similar topics
-
» Software that tracks people on social media created by defence firm
» 'Red October' malware: what you need to know
» Welcome to the Malware-Industrial Complex
» Tit for Tat - China was the top malware infected country in 2012
» Fake LinkedIn notifications lead to phishing and malware

Permissions in this forum:You cannot reply to topics in this forum
The Cuckoo's Nest :: The Cuckoo's Nest-
Jump to:  
Affiliates

Future Google PR for thecuckoosnest.forumotion.com - 4.00 Free Url Submission Forum Topsite
conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy, conspiracy