<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cyber attack during long week end example in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17615#M2094</link>
    <description>&lt;P&gt;&lt;A href="https://www.cnbc.com/2018/12/29/reuters-america-cyberattack-hits-u-s-newspaper-distribution.html" target="_blank"&gt;https://www.cnbc.com/2018/12/29/reuters-america-cyberattack-hits-u-s-newspaper-distribution.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above Cyber attack prove that most of the Cyber attack are happen during long week end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During long week end we should be more vigilant on below point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disabled Wi-Fi Dhcp Pool. considering remote location as well gust Wi-Fi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ask SOC Team to monitor all gateway equipment like IPS/E-mail gateway etc.&lt;/P&gt;&lt;P&gt;Monitor permiter network whether all DMZ servers updated with latest AV definition and OS patch.&lt;/P&gt;&lt;P&gt;Check with external feed whether there is any zero day vulnerability exist.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Jan 2019 16:01:33 GMT</pubDate>
    <dc:creator>paul200310</dc:creator>
    <dc:date>2019-01-06T16:01:33Z</dc:date>
    <item>
      <title>Cyber attack during long week end example</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17615#M2094</link>
      <description>&lt;P&gt;&lt;A href="https://www.cnbc.com/2018/12/29/reuters-america-cyberattack-hits-u-s-newspaper-distribution.html" target="_blank"&gt;https://www.cnbc.com/2018/12/29/reuters-america-cyberattack-hits-u-s-newspaper-distribution.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Above Cyber attack prove that most of the Cyber attack are happen during long week end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During long week end we should be more vigilant on below point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Disabled Wi-Fi Dhcp Pool. considering remote location as well gust Wi-Fi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ask SOC Team to monitor all gateway equipment like IPS/E-mail gateway etc.&lt;/P&gt;&lt;P&gt;Monitor permiter network whether all DMZ servers updated with latest AV definition and OS patch.&lt;/P&gt;&lt;P&gt;Check with external feed whether there is any zero day vulnerability exist.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jan 2019 16:01:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17615#M2094</guid>
      <dc:creator>paul200310</dc:creator>
      <dc:date>2019-01-06T16:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cyber attack during long week end example</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17619#M2095</link>
      <description>&lt;P&gt;Which tells you a lot, whilst the employees of the business go on a well deserved break.&amp;nbsp; The bad guys are opportunists, they have all the available time and luxury of giving it a go, and many times they will succeed.&amp;nbsp;&amp;nbsp; We as the defenders need to up our game in 2019.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;73&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cautim_cautim&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jan 2019 18:37:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17619#M2095</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-01-06T18:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cyber attack during long week end example</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17641#M2098</link>
      <description>&lt;P&gt;I firmly believe that attackers are prepared months in advance and are just waiting for the perfect opportunity.&amp;nbsp; While everyone enjoys their time off, they are hatching their well-thought plans.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 16:31:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17641#M2098</guid>
      <dc:creator>dreastans</dc:creator>
      <dc:date>2019-01-07T16:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cyber attack during long week end example</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17711#M2102</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On 31st December 2018&amp;nbsp;we experienced an attack on&amp;nbsp;a&amp;nbsp;web-servers, the response to which required a change on our firewall,&amp;nbsp;which was communicated to the&amp;nbsp;MSSP handling our security devices. Effecting it&amp;nbsp;took longer than expected,&amp;nbsp;courtesy of the MSSP's staff enjoying New Year's Eve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All this occurred on a weekday ---&amp;nbsp;so at least it didn't&amp;nbsp;ruin my weekend...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 14:49:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17711#M2102</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-01-08T14:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cyber attack during long week end example</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17722#M2103</link>
      <description>&lt;P&gt;May this kind actor being activated month back and well planned...&lt;/P&gt;&lt;P&gt;Firewall rule rationalization most important prior such long holiday.....Identify Firewall posture as well.....&lt;/P&gt;&lt;P&gt;Another important thing we focus on network based IPS but often forgot to apply Host based IPS.......Remove default IPS/HIPS policy create new filter based on recent threat vector...&lt;/P&gt;&lt;P&gt;End point Security, Advanced end point Security no more helpful understand such unknown variant of malware without proper research....&lt;/P&gt;&lt;P&gt;As an example some encrypted file not scan by AEP recorded sample....&lt;/P&gt;&lt;P&gt;another recorded example encrypted file scan by AEP but taking long....&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fast example heuristic method not working and second example&amp;nbsp;heuristic method working but taking so long..process slow indeed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check this below link if it is help beyond SIEM ingratiated SOC......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/PaloAltoNetworks/minemeld" target="_blank"&gt;https://github.com/PaloAltoNetworks/minemeld&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 18:52:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-attack-during-long-week-end-example/m-p/17722#M2103</guid>
      <dc:creator>paul200310</dc:creator>
      <dc:date>2019-01-08T18:52:19Z</dc:date>
    </item>
  </channel>
</rss>

