<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3606598690147536673</id><updated>2011-07-28T18:34:54.467-07:00</updated><title type='text'>The Maverick Cyber-Defense Threat Feed</title><subtitle type='html'>Maverick provides this daily threat feed as a FREE service to our government and critical infrastructure customers.  It is intended to collect the relevant cyber news and events that most affect the Federal Government and America's critical infrastructures.  

Once a week, or more as needed, Maverick will also provide topical threat analysis posts to help keep our clients ahead of the threat.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://maverick-security.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-7369673089698867793</id><published>2009-10-05T07:17:00.001-07:00</published><updated>2009-10-05T07:59:34.771-07:00</updated><title type='text'>Maverick Fed Gov Security Topic 05Oct09-01 &gt; "SOA Security Is An Oxymoron</title><content type='html'>SOA: Service-Oriented Architecture&lt;br /&gt;&lt;br /&gt;I am sitting presently in a Mitre-sponsored SOA conference for the Federal Government.  The 40 or so folks are supposed to represent the Fed Gov community when it comes to SOA and what it can do / is doing for the government.  So far, I'm not feeling it.&lt;br /&gt;&lt;br /&gt;We have a data issue in government.  No one would dispute that.  Terabytes or more of data, emails, images, files, all need to be categorized, linked, and accessible.  At this conference there are lots of discussions about architecture, data structure, and even data standardization for platform independence.  All important things, and necessary.&lt;br /&gt;&lt;br /&gt;But what was missing, as usual, was any thought whatsoever to security: security of data, security at rest, security in transit, access controls, or encryption.  Nothing.  So of course, I asked,  I asked the same question different ways for different presentations, just to see how different presenters would respond.  This would give me a good sense of whether or not I was dealing with people who understood security, cared about security's role in their efforts, or even considered it at all.&lt;br /&gt;&lt;br /&gt;It was the last, unfortunately.  The last on that list...the last thing considered - if at all.&lt;br /&gt;&lt;br /&gt;One presentation showed that 19 government agencies had agreed to SOA data standards for platform independence.  A great feat, to be sure, getting 19 government agencies to agree on anything.  ...but security was, as the presenter told me, "orthaganal".  ie: ignored.  Someone else's problem.&lt;br /&gt;&lt;br /&gt;The best statement that came out of the conference was the following quote: "There is a huge difference between building something and executing on it."&lt;br /&gt;&lt;br /&gt;When we create a standards-driven architecture that makes data connectivity interactive, easy, and operable, we make it a HUGE target.  We also make it way easier for the bad guys to suck the teet of our government until they are fat with data.&lt;br /&gt;&lt;br /&gt;If we are to remain the number one power on the planet, we must drive security as part of the process.  It is key, or we are toast.&lt;br /&gt;&lt;br /&gt;We are told in the government that disparate bits of data, though unclassified, when put together can tell an enemy too much.  Yet with SOA, that is exactly what we are building towards.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-7369673089698867793?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://maverick-security.blogspot.com/feeds/7369673089698867793/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://maverick-security.blogspot.com/2009/10/maverick-fed-gov-security-topic-05oct09.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7369673089698867793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7369673089698867793'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/10/maverick-fed-gov-security-topic-05oct09.html' title='Maverick Fed Gov Security Topic 05Oct09-01 &gt; &quot;SOA Security Is An Oxymoron'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-7216119986684222388</id><published>2009-01-31T06:58:00.000-08:00</published><updated>2009-01-31T07:00:20.706-08:00</updated><title type='text'>Link to Fannie Mae Hacker Story</title><content type='html'>http://www.wusa9.com/news/local/story.aspx?storyid=81025&amp;amp;catid=158&lt;br /&gt;&lt;br /&gt;This video will be on the New Maverick web site in the next two weeks as well.  If you have any questions, or require more assistance, contact Maverick.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-7216119986684222388?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://maverick-security.blogspot.com/feeds/7216119986684222388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://maverick-security.blogspot.com/2009/01/link-to-fannie-mae-hacker-story.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7216119986684222388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7216119986684222388'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/01/link-to-fannie-mae-hacker-story.html' title='Link to Fannie Mae Hacker Story'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-7242997469306483370</id><published>2009-01-30T17:46:00.000-08:00</published><updated>2009-01-30T20:00:14.927-08:00</updated><title type='text'>Maverick Analysis: Lessons From The Fannie Mae Hacker</title><content type='html'>Rajendrashinh Makawa, a 35 year-old Indian Unix system administrator contractor for OmniTech, was arraigned this week in Maryland for attempting to hack Fannie Mae - the company he was subcontracted to.  After being fired in the early afternoon of October 24th, Makawa was allowed to continue working.  By the time he turned in his badge and laptop in at the end of the day he had written and implanted four separate scripts in the Fannie Mae system.  These were designed to wipe all of the data from the over 4,000 servers and storage devices in a revenge attempt.  Luckily, another sys admin uncovered one of the malicious scripts and the plan was thwarted.&lt;br /&gt;&lt;br /&gt;     The biggest lesson to be learned from this incident is in the behavior of Fannie Mae and OmniTech during the dismissal of Makawa.  Makawa's access should have been revoked just prior to his dismissal and he should have been immediately escorted from the building.  Instead, he was allowed to finish his day and - in barely 4 hours' time - put thousands and thousands of Fannie Mae clients' records and millions of the company's dollars at risk.&lt;br /&gt;&lt;br /&gt;     &lt;span style="font-weight: bold;"&gt;Remember:&lt;/span&gt; the termination process should take place swiftly and should begin with the removal of all access of the person to be terminated.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-7242997469306483370?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://maverick-security.blogspot.com/feeds/7242997469306483370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://maverick-security.blogspot.com/2009/01/maverick-analysis-lessons-from-fannie.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7242997469306483370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/7242997469306483370'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/01/maverick-analysis-lessons-from-fannie.html' title='Maverick Analysis: Lessons From The Fannie Mae Hacker'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-183472931690034028</id><published>2009-01-30T08:17:00.000-08:00</published><updated>2009-01-30T08:19:49.185-08:00</updated><title type='text'>30JAN09-02: No Hacking Required - U.S. Consulate in Israel Auctions Sensitive Information</title><content type='html'>The U.S. consulate in Israel held an auction in December 2005 to get rid of old furniture and reportedly sold cabinets containing hundreds of files with Social Security numbers of U.S. Marines and state department staff stationed in Israel. The files also included U.S. State Department bank account numbers and documents tracking the U.S. funding of local political movements.  Among the files was a dossier marked "Secret" detailing an encounter between a U.S. Marine and a young Israeli woman in a Jerusalem hotel bar.&lt;br /&gt;&lt;br /&gt;The woman who bought the filing cabinets, an American-Israeli, recently returned them to U.S. control but only after the Israeli police intervened and threatened her with unspecified charges. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;SOURCE: http://blog.wired.com/27bstroke6/2009/01/us-consulate-in.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-183472931690034028?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/183472931690034028'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/183472931690034028'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/01/30jan09-02-no-hacking-required-us.html' title='30JAN09-02: No Hacking Required - U.S. Consulate in Israel Auctions Sensitive Information'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-4999373913356493325</id><published>2009-01-30T08:12:00.000-08:00</published><updated>2009-01-30T08:17:11.291-08:00</updated><title type='text'>30JAN09-01: Russian "Cyber-Militia" Takes Kyrgyzstan Offline</title><content type='html'>Kyrgyzstan's two main Internet service providers -- &lt;span style="font-style: italic;"&gt;ns.kg and domain.kg&lt;/span&gt; – recently came under a massive online assault. Details have emerged that the cyber-attack was orchestrated by Russia-based "cyber militia," shutting down more than 80 percent of Kyrgyzstan's bandwidth.  Speculation is that the attack was meant to thwart Kyrgyzstan's embattled political opposition -- which depends on the Internet to organize -- or to pressure Kyrgyzstan's government, which hosts a U.S. airbase outside of the capital, Bishkek.&lt;br /&gt;&lt;br /&gt;SOURCE: http://blog.wired.com/defense/2009/01/cyber-militia-t.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-4999373913356493325?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/4999373913356493325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/4999373913356493325'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/01/30jan09-01-russian-cyber-militia-takes.html' title='30JAN09-01: Russian &quot;Cyber-Militia&quot; Takes Kyrgyzstan Offline'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-3606598690147536673.post-126083638143262858</id><published>2009-01-30T07:49:00.000-08:00</published><updated>2009-01-30T08:12:00.085-08:00</updated><title type='text'>Welcome to the NEW Maverick Cyber-Defense Threat Feed!</title><content type='html'>You may access this blog FREE as a courtesy service of Maverick Cyber-Defense.  As we know many of our clients already have their own daily analysis shops, we provide this blog as a collector for cyber-indicators and information you can use to analyze and generate intelligence applicable to your own organization. &lt;br /&gt;&lt;br /&gt;Each Thursday, Maverick will provide analysis of some topic related to cyber-security.  Sometimes the posts will be topical, based upon major events of the week.  Other times, we will post periodic intelligence we feel our clients need to stay ahead of the global threat.&lt;br /&gt;&lt;br /&gt;If you have suggestions for topics or other inputs, feel free to contact us.  We always try to tailor our intelligence to meet your needs.  Just email us at info (at) maverick-security.com (replace the (at) with @ ).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3606598690147536673-126083638143262858?l=maverick-security.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://maverick-security.blogspot.com/feeds/126083638143262858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://maverick-security.blogspot.com/2009/01/welcome-to-new-maverick-cyber-defense.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/126083638143262858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3606598690147536673/posts/default/126083638143262858'/><link rel='alternate' type='text/html' href='http://maverick-security.blogspot.com/2009/01/welcome-to-new-maverick-cyber-defense.html' title='Welcome to the NEW Maverick Cyber-Defense Threat Feed!'/><author><name>The Maverick Cyber-Defense Threat Feed</name><uri>http://www.blogger.com/profile/02606448289220509227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
