breach Archives - The Silicon Underground David L. Farquhar on technology old and new, computer security, and more Thu, 19 Feb 2026 13:58:24 +0000 en-US hourly 1 https://kerosin.digital/rss-chimp16321610 Watering hole attack prevention https://dfarq.homeip.net/watering-hole-attack-prevention/?utm_source=rss&utm_medium=rss&utm_campaign=watering-hole-attack-prevention https://dfarq.homeip.net/watering-hole-attack-prevention/#comments Wed, 02 Aug 2017 11:00:04 +0000 https://dfarq.homeip.net/?p=14263 A watering hole attack is an indirect attack on a victim. Rather than directly attacking the victim’s network, the attacker attacks a web site that the victim’s employees are likely to visit. Then the attacker attacks the victim’s network, via

The post Watering hole attack prevention appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/watering-hole-attack-prevention/feed/ 1 14263
What to do about Petya ransomware if you already deployed MS17-010 https://dfarq.homeip.net/petya-ransomware-already-deployed-ms17-010/?utm_source=rss&utm_medium=rss&utm_campaign=petya-ransomware-already-deployed-ms17-010 Wed, 28 Jun 2017 04:59:51 +0000 https://dfarq.homeip.net/?p=13466 Got MS17-010 deployed? Good, that means you’re immune to the Petya ransomware. I still want you to do something. Tell your patching team that you’re immune, and they saved the company between $300 and $300 * the number of Windows

The post What to do about Petya ransomware if you already deployed MS17-010 appeared first on The Silicon Underground.

]]>
13466
Spot phishing e-mails with Outlook https://dfarq.homeip.net/spot-phishing-e-mails-with-outlook-2010/?utm_source=rss&utm_medium=rss&utm_campaign=spot-phishing-e-mails-with-outlook-2010 Mon, 25 Jan 2016 12:00:55 +0000 https://dfarq.homeip.net/?p=8267 I got e-mail the other day from Turbotax saying someone had filed my taxes for me. Obviously a cause for concern, right? Here’s how I determined the message was fake in about three minutes. You can spot phishing e-mails with Outlook

The post Spot phishing e-mails with Outlook appeared first on The Silicon Underground.

]]>
8267
Password management advice from CSO Online https://dfarq.homeip.net/password-management-advice-from-cso-online/?utm_source=rss&utm_medium=rss&utm_campaign=password-management-advice-from-cso-online Wed, 21 Oct 2015 11:00:03 +0000 https://dfarq.homeip.net/?p=7900 Over at CSO Online, there’s a nice war story about tracking down and resetting 300 passwords. I could pick nits at a few of his details, but that’s annoying and counterproductive. His overall advice is very good–manage your passwords, set

The post Password management advice from CSO Online appeared first on The Silicon Underground.

]]>
7900
What to do after you get breached and sign up for the free credit monitoring https://dfarq.homeip.net/what-to-do-after-you-get-breached-and-sign-up-for-the-free-credit-monitoring/?utm_source=rss&utm_medium=rss&utm_campaign=what-to-do-after-you-get-breached-and-sign-up-for-the-free-credit-monitoring Wed, 14 Oct 2015 11:00:26 +0000 https://dfarq.homeip.net/?p=7892 After a large company that has your data gets breached, the standard next step is to give you credit monitoring. It’s not enough to protect yourself, but you can make it enough. I can tell you from my own experience

The post What to do after you get breached and sign up for the free credit monitoring appeared first on The Silicon Underground.

]]>
7892
New password advice from GCHQ https://dfarq.homeip.net/the-gchqs-new-advice-on-handling-passwords/?utm_source=rss&utm_medium=rss&utm_campaign=the-gchqs-new-advice-on-handling-passwords Thu, 17 Sep 2015 11:00:59 +0000 https://dfarq.homeip.net/?p=7866 The GCHQ is the British equivalent of the NSA. They recently published a new document containing the GCHQ’s new password advice in light of the things we’ve learned in the last few years. It’s worthwhile reading, whether you’re a sysadmin or

The post New password advice from GCHQ appeared first on The Silicon Underground.

]]>
7866
The workstation events you want to be logging in Splunk https://dfarq.homeip.net/the-workstation-events-you-want-to-be-logging-in-splunk/?utm_source=rss&utm_medium=rss&utm_campaign=the-workstation-events-you-want-to-be-logging-in-splunk Tue, 15 Sep 2015 11:00:55 +0000 https://dfarq.homeip.net/?p=7864 Every once in a while the NSA or another government agency releases a whitepaper with a lot of really good security advice. This paper on spotting adversaries with Windows event logs is a fantastic example. It’s vendor-neutral, just talking about

The post The workstation events you want to be logging in Splunk appeared first on The Silicon Underground.

]]>
7864
Hacktivism is real, and getting more dangerous https://dfarq.homeip.net/hacktivism-is-real-and-getting-more-dangerous/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivism-is-real-and-getting-more-dangerous Mon, 03 Aug 2015 11:00:33 +0000 https://dfarq.homeip.net/?p=7807 Lost in the stories of last week was a story I really don’t want to talk about, but I have to: Planned Parenthood got hacked, and a database of its employees was stolen. I don’t want to talk about it because

The post Hacktivism is real, and getting more dangerous appeared first on The Silicon Underground.

]]>
7807
Five things security experts do vs. five things non-experts do https://dfarq.homeip.net/five-things-security-experts-do-vs-five-things-non-experts-do/?utm_source=rss&utm_medium=rss&utm_campaign=five-things-security-experts-do-vs-five-things-non-experts-do Sun, 02 Aug 2015 11:00:57 +0000 https://dfarq.homeip.net/?p=7818 There was a fair bit of talk last week about a study that compared security advice from security experts versus security advice from people who are at least somewhat interested but don’t live and breathe this stuff. There were significant

The post Five things security experts do vs. five things non-experts do appeared first on The Silicon Underground.

]]>
7818
Expect a rough road ahead for Flash https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/?utm_source=rss&utm_medium=rss&utm_campaign=expect-a-rough-road-ahead-for-flash https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/#comments Wed, 15 Jul 2015 11:00:05 +0000 https://dfarq.homeip.net/?p=7787 Adobe has patched Flash twice in two weeks now. The reason for this was due to Hacking Team, an Italian company that sells hacking tools to government agencies, getting hacked. Hacking Team, it turns out, knew of at least three

The post Expect a rough road ahead for Flash appeared first on The Silicon Underground.

]]>
https://dfarq.homeip.net/expect-a-rough-road-ahead-for-flash/feed/ 1 7787