Websense News & Views
all posts insights blog channel blog news releases media coverage accolades
Published Monday, October 29, 2012 10:38 AM by Jason Woo
Every week I hear cyber security teams say they’re worried about spear-phishing . They’re struggling to defend against them with their current technology. But to exacerbate matters, their users also struggle to understand how to spot a malicious...

Published Tuesday, October 09, 2012 4:58 AM by Patrik Runald
Spear-phishing is a huge concern for today’s government and enterprises. While high profile attacks like last week’s spear-phishing attack against the White House and last year’s attack against Oak Ridge National Laboratory underscore...

Published Tuesday, September 18, 2012 1:14 PM by Jason Clark

I recently hosted a Websense customer round-table discussion with 20 CSOs from top U.S. companies. We swapped war stories, hashed out the security challenges they face every day and they shared how they’ve been successful. These CSOs work in a variety of industries, including federal, finance and healthcare. Recently, there have been a number of highly public targeted attacks, which led to a lengthy discussion on spear-phishing. I found their insights very valuable and I wanted to share some key points...

...

Published Tuesday, August 28, 2012 9:54 AM by Jason Woo
Leading analyst firm Gartner just released the 2012 Magic Quadrant for Secure Email Gateways (SEG) * and noted an uptick in targeted phishing attacks. The report states "Phishing attacks continue to oscillate, while more targeted phishing attacks...

Published Tuesday, June 19, 2012 3:01 PM by Jason Woo
Phishing. It’s been around for ages and continues to evolve. From the simple money wire scams and the attempts to steal AOL user passwords, to ultimately the threat that makes IT managers shake in their boots: “spear-phishing.” In recent...

Published Sunday, January 15, 2012 10:00 PM by Patrik Runald

When we were looking at putting out our Websense Security Labs predictions for 2012, we knew that mobile threats were going to be big this year. While we included one prediction on it, there was one piece that I had thought of, but didn’t include. It’s still a ways away, but Paul Henry has an excellent write up on “QR Codes – Leading Lambs To the Slaughter.”

He correctly points out that these “ultimate url-obfuscators” can be a serious threat down the line.

It’s a good reminder that any applications on workforce mobile devices need to be properly sandboxed from the operating system. We’ve already noted in Websense Security Labs research that there are challenges with certain platforms and there are a number of mobile malware variants, including Trojans on handhelds.

It’s interesting to think QR codes as threats continue to evolve in the mobile landscape. What’s funny is as I was writing this, our Security Labs researches discovered QR codes being used a new way – through a spam campaign

What do you think about QR codes?

 

 

...

Published Friday, July 29, 2011 11:23 AM by Jason Clark

Recently, I was speaking with a CSO of a major corporation and the topic of how much money is made with cybercrime came up. Now, many of us talk about the proliferation of easily monetizable cybercrime, but because it is an invisible enemy, some people have trouble understanding the threat. I wanted to quickly share with you a great article that should be required reading for everyone in IT security:http://www.wired.com/magazine/2011/01/ff_hackerville_romania/all/1

The story covers the evolution of the small town of Râmnicu Vâlcea, Romania and how it went from having “a decades-old chemical plant and a modest tourism industry” to become what the article calls “Cybercrime Central.”

 

...

Published Monday, May 09, 2011 12:37 PM by Patrik Runald

 

 

Cybercriminals are on the move again. And, this time, Canada is the prime target. IP addresses in China and Eastern Europe are highly scrutinized and undergoing intense evaluation. So hackers are on a quest to move their networks to countries, like Canada, that have better cyber reputations. 

It's a little surprising to me as well. Previously, Canada was a place of great beer and hockey (next year, Habs!). But Websense recently conducted an analysis of Canada’s cyber security risk profile, and all trends pointed to Canada as the new launchpad for cybercriminals. For example:

Jump in Hosted Phishing Sites - Canada saw a huge increase in the number of servers hosting phishing sites, jumping 319 percent in the last year.  This tremendous increase over the last 12 months is second only to Egypt in terms of the growth of sites hosting crime ware.                        

 Increase in Bot Networks – Cyber criminals are moving their command and control centers to safer grounds. In the past eight months, Canada saw a53 percent increase in bot networks. In fact, Canada scored the second highest for hosting bot networks, when compared to the U.S., France, Germany and China.  

Malicious Websites – We’re seeing a trend of malicious websites decline across the board. However, Canada’s decline is tremendously slower, when compared to the countries listed above.

Overall Increase in Cyber Crime – In Websense’s most recent Threat Report, Canada is #6 in the world for hosting cyber crime . And, this number continues to rise.

 

 

 

...

Published Tuesday, April 12, 2011 7:54 PM by Dave Meizlik

 

 

 

How many letters have you received? You know what I’m talking about. Let’s talk data breaches. Let’s avoid the hype of the headlines and some of the sensationalism of the media coverage. And look at a few facts from recent episodes to see if we can identify the root issue at the heart of the breaches.

I’ve already posted a first glance look at the Epsilon breach, but, let’s talk about this in a little more detail. There are three critical elements that need to be addressed here.

1.       The business imperatives that lead to this episode

2.       Why most organizations aren’t currently equipped to prevent such breaches

3.       What companies need to do to protect themselves from third part breaches

 

...

Published Tuesday, April 05, 2011 9:53 AM by Dave Meizlik

 

The parade of large data breaches just came knocking on my front door. Or more accurately, in my home email. I received *three* almost identical messages from three different companies that told me in almost identical language that my name and email address had been leaked and, “you may receive spam email messages as a result. We want to urge you to be cautious when opening links or attachments from unknown third parties.” Epsilon, an online marketing firm with a huge portfolio of diverse clients, lost a huge amount of customer data. In volume, it might be the largest breach in history.

At little risk of overstatement, let us rephrase the warning: “Don’t feel safe just because they only got your name and email and not your social. Make no mistake about it, you are about to become the target of a spear phishing attack.” For the uninitiated, spear phishing attacks take advantage of trusted relationships. You expect emails from these trusted companies, so you are less suspicious, less vigilant, and more likely to fall for a scam. Think you are too savvy? This is exactly how RSA just lost their valuable data—by an executive clicking on an email with a link to a web site that looked like it was from a known vendor.

 

...

More Posts Next page »