Magecart Strikes Again
Ticketmaster, British Airways, and Newegg have all been compromised. Who’s next? Read our research to see how we discovered the breaches.
IDG Connect: 2017 State of Enterprise Digital Defense Report
Findings quantify the security management gap and business impact of external web, social, and mobile threats.
Get the Research Report
Frost & Sullivan: The Digital Threat Management Platform Advantage
The material benefits of a platform-based approach to security outside the firewall.
Read the Report
2018 Holiday Shopping Season Threat Activity: A Snapshot
The 2018 holiday shopping season was the largest ever for online retailers, but threat actors filled their pockets, too.
So what did the threat activity around this shopping frenzy look like?
Rackspace Accelerates External Digital Threat Investigation with RiskIQ PassiveTotal
Download Case Study
EMA Radar™ Q4 2017 Report
RiskIQ ranked a technology and value leader in digital threat intelligence management.
Get the Analyst Report
Mozilla, the world’s second most popular browser, announced an important security decision last week to distrust a range of bad SSL certificates issued by Certificate Authorities (CAs) WoSign and Startcom, citing “technical and management failures”.
In a nutshell, the security industry agreed several years ago that SHA-1 is becoming risky to use for SSL certificates, and set a deadline of January 1st, 2016 for the industry to stop issuing SSL certs that use it. WoSign, which has acquired full ownership of Startcom, continued to issue SHA-1 SSL certs to customers, made to look valid by back-dating them, i.e., faking the date of issuance. There are several potential impacts from issuing weak certificates discussed in our technical blog, but the main business impact will be alarming “Secure Connection Failed” browser warnings when people visit your website. These certificates also present the risk for Man in the Middle attacks on users’ sessions and more.
Why would two Chinese CAs backdate certificates with weak ciphers, and then repeatedly deny it? Is this a shady operation, or simply a mistake? Keep in mind that it took Apple and Mozilla essentially saying they would put WoSign and Startcom out of business for them to finally respond to the claims of wrongdoing (we’ll let you draw your own conclusions).
Once WoSign was forced to come clean, the answer provided isn’t much of answer. To read it, jump to “9. Issue S: Backdated SHA-1 Certs (January 2016)” inside the official PDF response (if you are comfortable opening a Chinese PDF). The number of mistakes and poor judgment calls made at WoSign disclosed in this advisory, make it look like Hanlon’s Razor has been in effect there for some time.
If your organization is using SSL certificates from either of these CAs, you could be a victim of this. In fact, RiskIQ’s current global index shows 762,649 websites using Certificates belonging to the 2 CAs. If you are a RiskIQ Enterprise Digital Footprint customer, log in and go to your Insights Dashboard to review usage of WoSign and Startcom SSL Certificates.
Fig-1 For specifics on analyzing certificates, visit our technical blog
If you are unsure if—or where—you are running WoSign or Startcom SSL Certificates, you are certainly not alone. As businesses expand into digital channels, the challenge of finding and managing an increasingly decentralized attack surface grows exponentially. To demonstrate this risk, RiskIQ performed a quantitative assessment of threats facing the top 35 banks and financial service firms as a result of decentralized web and mobile attack surface in April 2015. The data we collected confirms this challenge:
Fig-2 RiskIQ’s Enterprise Digital Footprint inventories all the SSL certs in your environment
Most organizations have challenges managing their ever-expanding digital footprint and resultant Internet-exposed attack surface and struggle to find risk issues like invalid and potentially exploitable SSL Certificates. RiskIQ’s Enterprise Digital Footprint was purpose built to solve this problem.
Cyber-Risks Hiding Inside Mobile App Stores https://t.co/NeXSULKcb5 #mobile #mobileapp #googleplay #risk by @kellymsheridan
If you have a “c” in your title, you're a target both online and in the physical world. Here are 5 things to "know" about modern executive defense https://t.co/Nl3lrvEM7O
#PlayStore winning war on suspect apps https://t.co/Zw1yuLswXF
Blacklisted apps rise, antivirus apps prove more harm than good, and Google Play continues to set the trends. Download our Q1 Mobile Threat Landscape Report and 2018 review for a deep dive into the last 18 months of #MobileThreats: https://t.co/FipDUCA6wA
Check out my latest interview in Forensic Magazine: Cybercrime, Cybertargets, and Cybersecurity https://t.co/TNy7MhoUn2 @LauraMFrench @ForensicMag @RiskIQ #cybercrime #CyberSecurity #threathunting