1-888-643-2217 Email ABEX
Keeping you updated

Category Archives: Cyber Risk Management

eBay Urges Password Changes After Breach


Source: KrebsOnSecurity

eBay is asking users to pick new passwords following a data breach earlier this year that exposed the personal information of an untold number of the auction giant’s 145 million customers.

In a blog post published this morning, eBay said it had “no evidence of the compromise resulting in unauthorized activity for eBay users, and no evidence of any unauthorized access to financial or credit card information, which is stored separately in encrypted formats. However, changing passwords is a best practice and will help enhance security for eBay users.”

Assisted by federal investigators, eBay determined that the intrusion happened in late February and early march, after a “small number of employee log-in credentials” that allowed attackers access to eBay’s corporate network were compromised. The company said the information compromised included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth. eBay also said it has no evidence of unauthorized access or compromises to personal or financial information for PayPal users.

The company said it will begin pushing out emails today asking customers to change their passwords. eBay has not said what type of encryption it used to protect customer passwords, but it previous breaches are any indication, the attackers are probably hard at work trying to crack them.

If you’re an eBay user, don’t wait for the email; change your password now, and make it a good one. Most importantly, don’t re-use your eBay or PayPal password elsewhere. If you did that prior to today, it’s a good idea to change that password to something unique at the other sites that shared it. And be extra wary of phishing emails that spoof eBay and PayPal and ask you to click on some link or download some security tool; attackers are likely to capitalize on this incident to spread malware and to hijack accounts.

eBay and PayPal users who haven’t already done so should consider using the PayPal Security Key, a two-factor authentication solution that can be used to add for additional security on both sites.


Heartbleed bug: What’s affected and what passwords you need to change

Source: globalnews.ca Published: 04/11/14

password screenAn encryption flaw now known as the Heartbleed bug has made a major impact on online security. The flaw has affected many online services and websites that Canadians access every day.

Security experts have gone as far to call it one of the biggest security threats the Internet has ever faced.

The flaw affects OpenSSL – a widely used open-source set of libraries for encrypting online services.

Heartbleed creates an opening in SSL/TLS, an encryption technology marked by the small, closed padlock and “https:” on Web browsers to show that traffic is secure. The flaw makes it possible to snoop on Internet traffic even if the padlock is closed, leaving users’ information vulnerable.

For now, the best  you can do to protect yourself is change the password to any accounts associated with websites affected by the bug once the website confirms it’s deployed a fix.

Global News has created a list of some of the most popular services to let you know what’s affected and what passwords you need to change:


Were Canadian banks affected? No. Do you need to change your password? No – but this is a good reminder that yourInternet banking password should be very secure.

“The online banking applications of Canadian banks have not been affected by the Heartbleed bug,” the Canadian Bankers Association said in statement issued Wednesday afternoon. “Canadians can continue to bank [online] with confidence.”


Was it affected? Yes Do you need to change your password? Yes

As of Friday the CRA’s online services were still offline due to the security concern. But according to a statement issued Friday, the websites will be back online by the weekend. Those with accounts should update their passwords once the site comes back online to be safe.



Was it affected? Unclear Do you need to change your password? Yes

“We added protections for Facebook’s implementation of OpenSSL before this issue was publicly disclosed. We haven’t detected any signs of suspicious account activity, but we encourage people to […] set up a unique password,” Facebook said in a statement.


Was it affected? No Do you need to change your password? No


Was it affected? Yes Do you need to change your password? Yes

“Our security teams worked quickly on a fix and we have no evidence of any accounts being harmed,” the company said.


Was it affected? No Do you need to change your password? No

“We were able to determine that twitter.com and api.twitter.com servers were not affected by this vulnerability. We are continuing to monitor the situation,” Twitter said on its website Wednesday.


Was it affected? Yes Do you need to change your password? Yes

“We have no evidence of any breach and, like most networks, our team took immediate action to fix the issue. This might be a good day to call in sick and take some time to change your passwords everywhere,” Tumblr said in a statement on Tuesday.


Was it affected? Yes Do you need to change your password? Yes



Was it affected? Yes Do you need to change your password? Probably.

According to a statement from Google, the company proactively looks for vulnerabilities in order to fix them before they are exploited and therefore fixed this bug “early.” Google said users do not need to change their passwords because of this – but better safe than sorry in this case.

“We’ve assessed this vulnerability and applied patches to key Google services such as Search, Gmail, YouTube, Wallet, Play, Apps, and App Engine.  Google Chrome and Chrome OS are not affected,” a post on Google’s security blog published Wednesday said.


Was it affected? No Do you need to change your password? No


Was it affected? No Do you need to change your password? No


Was it affected? Yes Do you need to change your password? Yes

“Our team has fixed the Heartbleed vulnerability across our main properties & is implementing the fix across our entire platform now,” the company tweeted Tuesday.

Yahoo is also the email provider for Rogers customers.

According to a statement issued to Global News, “Rogers. com doesn’t use the impacted versions of the SSL software, so was not impacted by the bug.” But a spokesperson added that the company recommends customers update their passwords frequently as best practice.



Was it affected? No* Do you need to change your password? No

*Amazon said with the exception of some services – Elastic Load Balancing, Amazon EC2, Amazon CloudFront, AWS OpsWorks and AWS Elastic Beanstalk – its services were unaffected. If you use these, you should probably change your password.


Was it affected? No Do you need to change your password? No


Was it affected? Yes Do you need to change your password? Yes

“As of right now, we have no indication that an attack has been conducted against Etsy beyond testing the vulnerability, but this type of issue makes it very difficult to detect, so we’re proceeding with a high degree of caution,” read a security update on Etsy’s website Tuesday.


Was it affected? No Do you need to change your password? No



Was it affected? Yes Do you need to change your password? Yes

“We’ve patched all of our user-facing services & will continue to work to make sure your stuff is always safe,” the company tweeted Tuesday.


Was it affected? Yes Do you need to change your password? Yes


Was it affected? No Do you need to change your password? No

“Evernote does not use, and has not used, OpenSSL, so we were not vulnerable to this bug. As an Evernote user, you don’t need to take any action,” read the company’s blog.

CCIRC Handles 58 Cyber Incidents in 2 Weeks

Network security crashDuring a two week reporting period (Feb 16 – Mar 1, 2014) Canadian Cyber Incident Response Centre (CCIRC) handled 58 incidents including malware targeting Canadian financial institutions, spread of ransomware, malware attacks and more.

Three Canadian energy and utilities sector organizations were attacked using watering hole techniques.  Users were being redirected to a compromised website that was serving the Lightsout Exploit kit and Havex remote access Trojan (RAT).

Canadian Internet protocol addresses were used in distributed denial of service attacks.

Please click on the link below to access the full report of incidents reported and sectors affected.  Also, read about latest news reports and some best practices for protection:

CCIRC Operational Summary – Feb 16 – Mar 1, 2014

The Internet of Things – Looming Security Nightmare?

Internet Concept The Internet of Things (IoT) is a term that describes a new paradigm emerging in our cyber world. It has been described as “uniquely identifiable objects and their virtual representations in an Internet-like structure”.1 Essentially this means an interconnected network of pretty much anything we can think of (refrigerators, televisions, highway sensors, tracking personal activity, monitoring groundwater runoff, etc.). If you haven’t heard of IoT before, you will hear a lot about it from now on. Our global world is shrinking, and an inherently human trait is finding ways of doing things smarter, faster, and more efficiently.

What does this have to do with Cyber Risk?

There are two sides to the coin. As we strive to do things smarter, there are always unintended consequences. Bringing a smart TV into our homes means having it automatically connect to our home network so we can enjoy movies when we want. But that also means cybersecurity becomes an issue. For example, if someone manages to get inside of our network, finds all of the devices connected to that network, and starts using that computer power as part of their BotNet, then society at large has a big problem. And that is exactly what is happening.

 What is the solution?

The Internet of Things, just like the public Internet, is now growing extremely fast. It is estimated that in just six years (2020), there will be more than 30 billion things interconnected via the Internet.2 Being aware of the growing cyber security problem, and learning what it means to each of us, is a critical first step. And as we develop these new things, and decide to connect them to our networks, we must keep the risk in mind. When deciding to use technology in our lives we must always consider, Is the risk worth the benefit?

Is the risk worth the benefit?

In our highly interconnected global village of people and things, our interdependencies with each other is undeniable. Like it or not, the IoT will continue to grow and affect our lives. It is up to each of us to make sure we understand and manage the risks, so that we realize a net benefit in this new world, the world of IoT.

1 http://en.wikipedia.org/wiki/Internet_of_Things

2 https://www.abiresearch.com/press/more-than-30-billion-devices-will-wirelessly-conne

Senior Management Poses Greatest Security Risk

Executive with laptopAccording to security firm Stroz Friedberg’s poll of 764 information workers who regularly use a computer for their jobs, senior management shows the highest risk of leaking sensitive information. Fifty-eight per cent of the polled senior managers said they have mistakenly sent sensitive information, and 51 per cent said they have taken sensitive data with them after leaving a job—twice as many as lower-level workers.

Other statistics from the poll:

  • Nearly 75 per cent of workers upload work files to a personal email or cloud account.

The reason for this potentially risky behavior? Thirty-seven per cent say they simply prefer using their personal computers, and 14 per cent say it’s too much work to bring their work computer home.

  • Only 37 per cent of workers say they’ve received mobile device security training.

Cyber security isn’t just IT’s problem—it takes a company-wide effort to ensure your sensitive data remains safe.  Contact us today to find out what else you can be doing to enhance your security efforts.


© 2014 Zywave, Inc. All rights reserved.



Receive notifications of new posts automatically.


Like us on Facebook

Connect with us on LinkedIn