The Coalfire Blog

Welcome to the Coalfire Blog, a resource covering the most important issues in IT security and compliance. You'll also find information on Coalfire's insights into the unique cybersecurity issues that impact the industries we serve, including Cloud Service Providers, RetailFinancial Services, Healthcare, Higher Education, Payments, Government, Restaurants, and Utilities.

The Coalfire blog is written by the company's leadership team and our highly-credentialed security assessment experts. We look forward to your comments, so please join the conversation.

  • The PCI Enforcement Hammer is Ready to Drop

    October 31, 2014, Rick Dakin, CEO, Co-founder and Chief Security Strategist

    The time for nervous anticipation for PCI breach response is over …. VISA has issued dramatic PCI Data Security Standard Compliance enforcement guidance for Level 1 and 2 merchants and all Service Providers.  Effective January 1st, 2015, noncompliance costs will be applied sooner and will escalate quicker.  For many merchants and service providers looking for a reason to improve compliance just got one.  The cost for noncompliance will easily hit $250,000 for many small and mid-sized merchants and service providers.

    Read more
  • Truth is SCARIER than Fiction Redux

    October 30, 2014, Mike Weber, Vice President, Coalfire Labs

    Yes... To be honest, although we really do some neat stuff here at Coalfire Labs that can be pretty scary, I’ve got to give a shout out to “reality” for being even scarier than any emulated attack we could possibly develop.  The astounding number of data breaches announced this year is just shocking, really.  It really felt like there was a new one every month.  As it turns out, there was!  Even more than that on average, as we’ve had at least 14 of them over a 10 month span.

    Read more
  • IT Security Horror Story: Is your Network an Unsegmented Haunted House?

    October 29, 2014, Mark Manousogianis, Information Security Consultant, Coalfire Labs

    One day I went to a client site to perform internal penetration test to emulate the insider threat. This testing was designed to help this client understand the damage a rogue employee or an intruder who gained physical access to the network could do.  The site that I was visiting was a storefront and had public WiFi.  I told the store staff who I was there to meet, and while I waited for the client to become available I connected to the public WiFi just to have a look.

    Read more
  • IT Security Horror Story: Digging your own grave with Default Credentials

    October 29, 2014, Mark Manousogianis, Information Security Consultant, Coalfire Labs

    I recently performed a penetration test that really required no “hacking skills” whatsoever. I was able to obtain domain administrator rights simply by logging into web applications and network hardware using default credentials.

    Read more
  • IT Security Horror Story: Slow Network, Big Phish

    October 29, 2014, Mark Manousogianis, Information Security Consultant, Coalfire Labs

    It was a typical morning, just like any other for Annie. She arrived at the office just in time to fill her coffee mug and get to her desk to read her email that had been piling up since Friday. After reading through the standard office wide emails she came across one from the help desk.

    Read more
  • POODLE vulnerability assessment

    October 15, 2014, Mike Weber, Vice President, Coalfire Labs

    Vulnerability Summary: The POODLE vulnerability is due to a bug in SSL protocol, whereas Heartbleed and Shellshock were vulnerability due to a bug in software.  Heartbleed and Shellshock were confined to systems that ran vulnerable versions of software, whereas POODLE affects any system running any software that implements SSL 3.0, which is a widely implemented protocol used to provide encrypted network transmissions.  This is an “industry-wide” vulnerability.  Of Heartbleed and Shellshock, POODLE is most similar to Heartbleed as both Heartbleed and POODLE exploit vulnerabilities having to do with SSL. 

    Read more

Recent Posts

Post Topics

Archives

Tags