{"id":335,"date":"2017-07-28T14:25:17","date_gmt":"2017-07-28T14:25:17","guid":{"rendered":"http:\/\/securitycurve.com\/?p=335"},"modified":"2017-07-28T14:25:17","modified_gmt":"2017-07-28T14:25:17","slug":"lots-of-stuff-today-so-just-a-fly-over","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=335","title":{"rendered":"Lots of stuff today, so just a fly-over"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignright lazyload\" data-src=\"https:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/a\/a7\/Cornucopia_Wisconsin_Welcome_Sign.jpg\/590px-Cornucopia_Wisconsin_Welcome_Sign.jpg\" width=\"493\" height=\"401\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 493px; --smush-placeholder-aspect-ratio: 493\/401;\" \/>Today is a serious news day in the security world, so I won&#8217;t break down everything that&#8217;s going on, but instead will just recap a few highlights and put some of them in context.<\/p>\n<p>So, number 1: Remember the ShadowBrokers? \u00a0<a href=\"https:\/\/securitycurve.com\/shadowbroker-notice-probably-want-to-pay-attention\/\">I do too<\/a>. \u00a0The ThreatPost has <a href=\"https:\/\/threatpost.com\/shadowbrokers-remain-an-enigma\/127072\/\">an interesting article<\/a> summing up what we do and don&#8217;t know as of now about the group. \u00a0Most people seem to agree that this is the GRU &#8211; but I don&#8217;t know that anybody has this definitively (if they do, it&#8217;s not public). \u00a0And the &#8220;dump of the month&#8221; service? \u00a0Who knows where that is. Remains a mystery. \u00a0Like Amelia Earhart I guess.<\/p>\n<p>Number 2: Russian dude, apparently involved in BTC-e, was\u00a0<a href=\"http:\/\/www.zdnet.com\/article\/russian-bitcoin-exchange-chief-arrested-in-connection-to-mt-gox-hack\/\">arrested for Mt. Gox<\/a> attacks. \u00a0If true, this guy stole a bunch of money, conducted some serious money laundering, and knocked out a competitor at the same time. \u00a0How&#8217;s that for efficiency?<\/p>\n<p>Number 3: \u00a0New attack <a href=\"https:\/\/threatpost.com\/attack-uses-docker-containers-to-hide-persist-plant-malware\/126992\/\">allows malicious use of Docker containers<\/a>. \u00a0This is an interesting one and should highlight why using certificate-based authentication for API access is a good idea. \u00a0Are you using certificates? \u00a0Good for you, I knew you would be.<\/p>\n<p>Number 4: There&#8217;s now something akin to a <a href=\"http:\/\/www.ul.com\/marks\/ul-listing-and-classification-marks\/promotion-and-advertising-guidelines\/specific-guidelines-and-rules\/#listed\">UL listing<\/a>\u00a0but <a href=\"https:\/\/nakedsecurity.sophos.com\/2017\/07\/27\/independent-labs-to-probe-medical-devices-for-security-flaws\/\">for medical devices<\/a>. \u00a0It includes a consortium of device manufacturers, academia, technology firms, and (presumably) providers. \u00a0Finally. \u00a0Let&#8217;s hope people take it seriously. \u00a0It would also be nice if there was some regulatory &#8220;encouragement&#8221; to select products that have been accredited in some way.<\/p>\n<p>Anyway, that&#8217;s all for now. \u00a0Happy Friday.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today is a serious news day in the security world, so I won&#8217;t break down everything that&#8217;s going on, but instead will just recap a few highlights and put some of them in context. So, number 1: Remember the ShadowBrokers? \u00a0I do too. \u00a0The ThreatPost has an interesting article summing up what we do and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[16,43,81,108],"class_list":["post-335","post","type-post","status-publish","format-standard","hentry","category-security","tag-bitcoin","tag-docker","tag-medical-devices","tag-shadowbrokers"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=335"}],"version-history":[{"count":0,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/335\/revisions"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}