Wednesday, March 4, 2020
90 Seconds of Security: What is Common Vulnerability Scoring System (CVSS)
90 Seconds of Security: What is Common Vulnerabilities & Exposures (CVE)
Saturday, December 14, 2019
90 Seconds of Security: Breach Trends for 2019
Wednesday, May 29, 2019
90 Seconds of Security: In the Wild Malware for April 2019
Get the details at: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities--exploits--and-malware-driving-attack-campaigns-in-april-2019
ps
Wednesday, November 29, 2017
The OWASP Top 10 - 2017 vs. BIG-IP ASM
First, here's how the 2013 edition compares to 2017.
Vulnerability
|
BIG-IP ASM Controls
| |
A1
|
Injection Flaws
|
Attack signatures
Meta character restrictions
Parameter value length restrictions
|
A2
|
Broken Authentication and Session Management
|
Brute Force protection
Session tracking
HTTP cookie protection
|
A3
|
Sensitive Data Exposure
|
Data Guard
|
A4
|
XML External Entities (XXE)
|
Attack signatures (see below)
|
A5
|
Broken Access Control
|
File types
URL
URL flows
Session tracking
URL flows
Attack signatures (Directory traversal)
|
A6
|
Security Misconfiguration
|
Attack Signatures
|
A7
|
Cross-site Scripting (XSS)
|
Attack signatures
Parameter meta characters
Parameter value length restrictions
Parameter type definitions (such as integer)
|
A8
|
Insecure Deserialization
|
Attack Signatures (see below)
|
A9
|
Using components with known vulnerabilities
|
Attack Signatures integration
|
A10
|
Insufficient Logging and Monitoring
|
BIG-IP ASM can help with the monitoring process to detect, alarm and deter attacks
|
- 200018018 External entity injection attempt
- 200018030 XML External Entity (XXE) injection attempt (Content)
For “A8:2017-Insecure Deserialization” we have many signatures, which usually include the name “serialization” or “serialized object”, like:
- 200004188 PHP object serialization injection attempt (Parameter)
- 200003425 Java Base64 serialized object - java/lang/Runtime (Parameter)
- 200004282 Node.js Serialized Object Remote Code Execution (Parameter)
ps
Related:
Friday, March 11, 2016
Hello Infiltrators - Our Doors are Wide Open
![]() |
| Image courtesy: https://en.wikipedia.org/wiki/File:Gossamer_restored.jpg |
Today, it is likely the case that you are being watched by the strange (internet of) things that are starting to infiltrate our homes, cars, bodies and the whole of society. While there is a mad rush by people purchasing these things and a similar rush for companies to develop applications and services around those, many are not pausing to either understand the risks or build security into the products.
From home security systems to surveillance cameras to baby monitors to televisions to thermostats, examples pour in daily about flaws and vulnerabilities that leave you, your family and your home exposed. The way things are going, even if you’ve closed and locked your front door physically, that door is wide open to the digital world.
Here are just a few recent examples.
Might as well start with our dwellings. Security researchers at Rapid7 found flaws in in Comcast’s Xfinity Home Security system that would cause it to falsely report that the home’s windows and doors are closed and secured even if they’ve been opened. It also failed to detect an intruder’s motion inside the house. Attacking the system’s communications protocol, they used radio jamming equipment to block the signals that pass from the door, window, or motion sensor to the home’s baseband hub. The system didn’t notice the communication was breached and essentially, failed open without any alert to the owner. When the jammers were turned off, it took minutes to hours for the sensors to reconnect and still didn’t give any indication that a catastrophe could have occurred.
Next, to some of the things inside the insecure house. Experts are predicting that as more connected, smart-TVs enter the home, this will be an avenue for the bad guys to breach your home network. Almost half of U.S. households already have a smart-TV and close to 70% of the sets sold this year will have connectivity capabilities. A threat researcher with Symantec was able to infect his new Andriod-based smart-tele with some ransomware. Within a few seconds, the TV was locked and unusable with the fear inducing pay-up-pop-up ransom note.
Also giving outsiders a view of the inside, Princeton researchers found that certain IoT thermostats were leaking customer zip codes over the internet in clear text. Fortunately, when the manufacturer was notified they quickly issued a patch. There are many horror stories about strangers watching and talking to children via insecure baby monitors. Add to that, toys that record your kid's conversations puts the whole family at risk.
And out on the road, we’ve seen how researchers were able to control a Jeep and last week, researchers were able to remotely control any of the Nissan Leaf’s functions by using the mobile app’s insecure APIs. The unsecured APIs allowed anyone who knows the VIN of a car to access non-critical features like climate control and battery charge management from anywhere on the Internet. Also, someone exploiting the unauthenticated APIs can see the car's estimated driving range. They too, pulled access to the app until they can properly secure the infrastructure and application that supports the mobile app.
Lastly, if you think this is contained within a consumer based household, think again. A recent Ponemon/Lookout survey revealed that an average of 1,700 malware laced mobile devices per company, connect to an enterprise network. Wait ‘til all the insecure wearables start connecting. Employees are often referred to as the weakest link. Today it is mostly their insecure mobile devices but multiply that by a wardrobe, now the risk is enhanced.
ps
Related:
Tuesday, April 15, 2014
The Weekend of Discontent
This past weekend, like many of you, I started getting the blood curdling password resets from a bunch of OpenSSL affected sites. I also got a few emails from sites indicating that I had nothing to worry about. Bad news, good news. Probably the biggest security story thus far for 2014 is Heartbleed, the OpenSSL vulnerability which potentially allows attackers to extract 64 kilobyte batches of memory at random without being noticed and leaving no trace. Sounds like the perfect crime.
It also got me thinking.
First, I wondered if this was a new era of security by force. The vulnerability and the totality of the hole forced many of us to change passwords on many sites. What a pain. It was a huge reminder that no matter how many 'experts' urge regular password rotation, it is a real time consuming, frustrating task. It's no wonder that so many keep the same password for years or use the same password across multiple sites. With so many sites requiring some authentication or verification for either resources or customization, people can have hundreds username/password combinations. Sure there are password keepers but part of me is reluctant to put all my web identities with one entity. What if that gets hit? There are just some sites that I chose not to save and auto-fill but enter it every time. Then, of course, I'm susceptible to key loggers. Great.
Then there are the developers. I imagine that this past weekend was the most worked ever by the entire coding community. Administrators across many sectors were working to patch vulnerable systems all over the globe to reduce the security threat. A massive undertaking to help fix over two-thirds of the internet. The weekend work of many fingers plugging dikes was probably only surpassed by the marketers and PR folks maneuvering their stories around what it is, what's at risk, what you should do and other FAQs surrounding this security superstar. @LanceUlanoff speculated on twitter, 'Is Heartbleed the first Internet bug with its own Web site? http://t.co/M9u976X9ui'
With so many sites and so many people affected along with the massive media coverage, will things change? Or will this be like Y2K with a bunch of dire warnings only to have nothing major occur? Is this a wake up call or will it dissolve into yesterday's news as new 'breaking' stories grab our attention? I think (and hope) that this is so critical that many organizations will be taking a more detailed look at their security infrastructure even if they are not vulnerable to Heartbleed. It forces many, if not all internet users, including the administrators themselves, to take a look at how we are protecting ourselves. It'll be interesting to see if '12345678' or 'qwertyui' or even 'password' continues to be the most popular pass codes after this massive reset.
If you need assistance with your Heartbleed crisis, click here to learn how F5 can help.
ps
Related
- The Heartbleed Bug
- Where you mitigate Heartbleed matters
- 3 big lessons to learn from Heartbleed
- OpenSSL HeartBleed, CVE-2014-0160
- Mitigate OpenSSL Heartbleed
- F5 Helping Customers Mitigate Heartbleed Bug
| Connect with Peter: | Connect with F5: |
| |
Tuesday, October 15, 2013
The One Millionth Mobile Malware
Milestone has been breached according to Trend Micro. Just a few months ago, they reported in their 2Q Security Roundup that there were 718,000 malicious or risky Andriod mobile apps available (up from 509,000 in Q1) and crystal-ball'd that the million mobile malware milestone would be reached by the end of 2013. Well, it came a couple months early.
Contained in that million are straight pieces of malware, those that abuse premium services like sending unauthorized text messages to certain numbers and registering people to costly services along with high-risk apps, those that aggressively serve ads that lead to dubious sites. They found that 75% perform outright malicious routines, while another 25% exhibit dubious routines, which include adware.
The most infamous malware families included FAKEINST at 34% and OPFAKE at 30%. FAKEINST is typically disguised as a legitimate app and was responsible for the fake Bad Piggies versions, which were found right after the game’s release. They can also register users for costly services by sending unauthorized text messages to those services for enrollment. in its ability to wolf legitimate apps clothing but it was also able to launch a web page that asks the person to download a potentially malicious file. Those are the primary risks but there are many others with this type of malware. Such fun.
For the high risk apps, ARPUSH came in at 33% and LEADBLT garnered 27% of the total. These are known to steal data like GPS location and OS information along with delivering malware.
The threats don't stop with these gems. Crooks are also looking to hijack mobile banking transactions with FAKEBANK and FAKETOKEN malware variants. They like to spoof legitimate financial apps along with the ever popular phishing notices enticing people to enter personal info.
And I thought mobile devices were supposed to make our lives easier. Hmm. The dedicated circuit of a couple cans with high speed twine (HST) sounds a lot more secure these days.
ps
Related:
- Mobile Malware, High-Risk Apps Hit 1M Mark
- 2Q Security Roundup: Mobile Flaws Form Lasting Security Problems
- Mobile Malware, High-Risk Apps Hit 1 Million Mark: Trend Micro
- Mobile Malware Issues Persist as Devices Remain Exposed
- Malicious apps, mobile malware reaches 1 million mark
- Mobile Security Apps Perform Dismally against Spyware
- OpFake, FakeInst Android Malware Variants Continue to Resist Detection
- A Look at Mobile Banking Threats
- Mobile Threats Rise 261% in Perspective
- Where Do You Wear Your Malware?
- Q. The Safest Mobile Device? A. Depends
- The Malware Mess
- Can two cans and a string really be used to talk over a distance?
| Connect with Peter: | Connect with F5: |
| |
Tuesday, September 17, 2013
World's Biggest Data Breaches [Infographic]
Cool and disturbing at the same time. A fully interactive version can be found here where you can click each circle to get more information. I thought about adding all the numbers but stopped at 140,621,000 between 2012 and 2013.
ps
Related:
- How To Cushion The Impact Of A Data Breach
- Security Spending On The Rise As Threats Proliferate
- Quantifying Reputation Loss From a Breach
- 5 Stages of a Data Breach
- 20,000 For Every 1
- Lost Records a Day Shows Doctors are Blasé
- The Real Reasons to Secure Your Infrastructure
- Small Business is a Big Target
| Connect with Peter: | Connect with F5: |
| |
Tuesday, August 20, 2013
DNS Doldrums
DNS is one of the primary technologies enabling the Internet – translating the names people type into a browser into an IP address so the requested service can be found on the internet. It is one of the key elements in the network that delivers content and applications to the user. If DNS goes down, most web applications will fail to function properly so it is critical to have a strong, secure and scalable DNS infrastructure.
A bunch of recent DNS outages show that while protecting the application from the typical SQLi, XSS and other OWASP Top 10 related risks is important, if DNS is not answering, those application hacks do not really matter since no one can get to the site anyway.
This month, 3 Dutch web hosting companies had their name servers altered by attackers. They, according to articles, changed the various company's name servers to malicious servers hosted by the crooks. They apparently managed to break into the national domain registrar, SIDN, to make the malicious change along with setting the Time to Live value to 24 hours. This meant that any ISP that cached the bad information would continue to deliver the wrong address for the next day. Among others, a large Dutch electronic retailer had to take down a bunch of servers that were delivering malware due to the breach but thousands of domains were affected.
This past June, the popular business social network LinkedIn was offline for at least a half a day due to a DNS issue. The company claims that this was not due to criminal behavior but internal human error. Somehow the main home page was redirected to a domain parking page which indicated the name was up for sale.
Also in June, DNSimple detected a DNS Amplification Attack on their network. This is where an attacker attempts to use additional servers to 'amplify' the attack - small queries that turn into huge responses. Instead of allowing the bounce, DNSimple tried to absorb the attack by blocking some IP addresses but ultimately at some point, all the name servers were no longer responding. All hands to respond. In their incident report, they noted that their current DNS server implementation allowed ANY queries on UDP to pass through and attempted to respond to them, albeit with the TC (truncation) bit set. In addition, the overhead created by their ALIAS resolution system was also a factor, especially with ALIAS records pointing to other records within DNSimple. With some adjustments they hope to mitigate this from happening again.
There were a few others of note, In June, Network Solutions had its DNS servers hijacked and reconfigured to a malicious website after it botched efforts to thwart a DDoS attack. The Spamhaus Project was nailed by a DNS DDoS attack. And last week, a reported vulnerability in the BIND DNS software could give an attacker the ability to easily and reliably control queried name servers.
We rely on DNS for almost every interaction we have with web applications. It helps us find our favorite e-tailer, social network, travel, news, gaming or entertainment site along with potentially finding our work related resources when we are mobile. For organizations, it helps direct and bring people to your content. Without it, our letter managed mind would have to start remembering a bunch of numbers. Imagine how much you'd use the internet if you had to remember dozens of number combinations to do anything. I bet the growth, the internet of everything, would come to a screeching halt.
ps
Related:
- BIND Vulnerability Enables DNS Cache Poisoning Attack
- DNS impairment redirects thousands of websites to malware
- How Spamhaus’ attackers turned DNS into a weapon of mass destruction
- LinkedIn hit by outage from 'DNS issue'
- Incident Report: DNS Outage due to DDoS Attack
- DDoS Attack Behind Latest Network Solutions Outage
- How whitehats stopped the DDoS attack that knocked Spamhaus offline
- The Domino Effect of LinkedIn’s DNS Outage
- RSA2013: BIG-IP DNS Services (video)
- F5 DNS Express: DNS Die Another Day (video)
- F5 DNS Series (videos)
| Connect with Peter: | Connect with F5: |
| |
Tuesday, June 18, 2013
Is 2013 Half Empty or Half Full?
It certainly has been a wild ride thus far for 2013 as we head into the second half. Breaches, hacks, exposures, leaks, along with things like BYOD and SDN should make the next 6 months interesting. From the many headlines in 2012, you'd think organizations would be locked down tight but alas, intruders are still kicking a$$ and taking names...literally.
Media and news organizations, like the New York Times and Wall Street Journal, experienced data breaches due to spear fishing and malware. According to various news articles, certain journalists were targeted based on their story coverage but more interesting to me is the fact that the anti-virus along with the IPS/IDS in place failed to catch the malware. Unless there is a signature in place for a known piece of evil code, that demon will make it's way through.
Financial institutions up to and including the Federal Reserve were breached. While many bank hacks are driven by monetary gain, sometimes they are the targets of political activists. Humans are very passionate about their beliefs and like to express those feelings. There have always been protesters and activists - some write letters, some picket on the sidewalk, some throw rocks and with the advent of the internet, now you can protest by creating digital havoc. Instead of hoping that people boycott a particular entity, you can simply take it out yourself so no one can get to the site.
Social media networks continue to feel the heat from breaches. Many social media sites are now deploying two-factor authentication to help reduce password exposures and increase verification checks. Many news stories have talked about password usage and it's good that two factor is being deployed...but,in many cases, it is only after the bad news hits the media. Why wait?
To help organizations understand the various web threats, OWASP has released their Top 10 for 2013 (with changes from 2010 Edition):
- A1 Injection
- A2 Broken Authentication and Session Management (was formerly 2010-A3)
- A3 Cross-Site Scripting (XSS) (was formerly 2010-A2)
- A4 Insecure Direct Object References
- A5 Security Misconfiguration (was formerly 2010-A6)
- A6 Sensitive Data Exposure (2010-A7 Insecure Cryptographic Storage and 2010-A9 Insufficient Transport Layer Protection were merged to form 2013-A6)
- A7 Missing Function Level Access Control (renamed/broadened from 2010-A8 Failure to Restrict URL Access)
- A8 Cross-Site Request Forgery (CSRF) (was formerly 2010-A5)
- A9 Using Components with Known Vulnerabilities (new but was part of 2010-A6 – Security Misconfiguration)
- A10 Unvalidated Redirects and Forwards
Along with their Top 10 Mobile Risks:
- M1: Insecure Data Storage
- M2: Weak Server Side Controls
- M3: Insufficient Transport Layer Protection
- M4: Client Side Injection
- M5: Poor Authorization and Authentication
- M6: Improper Session Handling
- M7: Security Decisions Via Untrusted Inputs
- M8: Side Channel Data Leakage
- M9: Broken Cryptography
- M10: Sensitive Information Disclosure
These are guides to help organizations understand the threats but always make sure you understand you own risks and focus on mitigating those first whether they are on the OWASP Top 10 or not. Then make sure you're covered on the rest.
So far, 2013 has been full of breaches that empties an organization's information.
ps
Related:
- Following New York Times Breach, Wall Street Journal Says China Hacked It, Too
- US Federal Reserve confirms it was hacked during the Super Bowl
- Does Lax Network Security Lead To Cyber Attacks: 2013’s Top Hacks
- Twitter introduces 'two-factor authentication' to stop password hacking
- Motorola shows off tattoo and swallowable password hardware
- OWASP Top 10 2013 - PDF
- OWASP Mobile Security Project
| Connect with Peter: | Connect with F5: |
| |
Tuesday, June 11, 2013
Small Business is a Big Target
If you think that small businesses are not an enticing enough target to breach, think again. While the media has certainly upped it's coverage over the last couple years pertaining to data loss, many of the headlines involved global brands and tens of thousands records...not the corner deli, the mom/pop shop or the new start up. Yet a couple of recent reports show that small businesses and start-ups are prime targets for data loss.
The annual, chuck full of stats, Verizon Data Breach Report noted that of the 621 confirmed data breaches, almost half happened at companies with less than 1000 employees and almost 200 at companies with less than 100 employees. A Symantec report echoed the finding. In theirs, small businesses with less than 250 employees accounted for 31% of the attacks in 2012, up 18% from 2011. Symantec also notes that start-ups are especially vulnerable in the early going.
Why are these groups targets?
They have valuable data - intellectual property, financial information, digital identities - but may not have the resources to properly protect that data. Many large, global companies have beefed up their security in fear of becoming the next headline in a major newspaper. Thieves usually go after the easiest target - those with limited resources to protect against such an attack. Thieves may also infiltrate a smaller organization to jump on a global network if a partnership is in place. Take out the villages before entering the capital. In a start-up's situation, as they quickly launch, employees may be enticed to click a malicious link in an email...which then spreads. Most startups get infected with malware within the first year.
From marketing organizations to cleaning products to credit repair services, here are some stories of how cyber attacks almost destroyed 5 small businesses.
ps
Related:
- Targets of Opportunity
- Cyberattacks devastated my business!
- Cybercrime's easiest prey: Small businesses
- New startups prime targets for cyberattacks
- Cybercrime, the Easy Way
- Ride The Crime Coaster
- Offering Secure Managed Access Services with BIG-IP Devices
| Connect with Peter: | Connect with F5: |
| |
Wednesday, April 24, 2013
Targets of Opportunity
#dbir
...Is one of the findings in #Verizon's 2013 Data Breach Investigations Report, which is chuck full of interesting data. 75% of the attack victims were selected because they had a weakness that an attacker knew how to exploit rather than being specifically chosen. The difficulty of the initial compromise was low for 68% of the breaches meaning the attackers used basic methods or automated tools and scripts. It also means that there are sloppy configurations, needless services and exposed vulnerabilities that are bringing this attention.
Overall, the report covers 47,000 reported security incidents, of which, there were 621 confirmed data breaches. This is important since they focus on the 621 confirmed data loss incidents rather than the 47,000 reports. There will probably be a ton of articles reporting the results but a good place to start is securosis.com with their How to Use the 2013 Verizon Data Breach Investigations Report. This is a great primer for the document.
There is a pretty even distribution of industries hit from financial to retail and restaurants to manufacturing, transportation and utilities to government and defense contractors. The overwhelming majority of attacks are perpetrated by outsiders at 92% of the confirmed data breaches with insiders at 14%. Interestingly, for all reports (the 47,000 not just the 621 confirmed) insiders accounted for 69% of the incidents. Typically this was due to carelessness rather than criminal misuse. 76% of the network intrusions exploited weak or stolen credentials and most often, the attack was driven by financial motives at 75%.
Some other interesting data for me was that 66% of the breaches remained undiscovered for months or more and 69% of those were discovered by outside entities. So organizations are in the dark about their intrusions, and it takes an outsider to point it out. It's like those people who drive away with the gas hose still hooked to their tank.
I was also curious about breaches as a result of BYOD. Not many. In 2011 they only saw 1 breach that involved personally owned devices and only a couple more in 2012. They will keep watching and do expect that it may increase but for now, so far so good. Could be because while BYOD is a hot topic, most surveys indicate that only around half the organizations are digging in.
There is a ton more valuable data in the report and it is an easy, fun read for 63 pages of stats. Right on page 2 they say, 'Some organizations will be a target regardless of what they do, but most become a target because of what they do. If your organization is indeed a target of choice, understand as much as you can about what your opponent is likely to do and how far they are willing to go.' Put it on your list.
ps
Related:
- 2013 Data Breach Investigations Report
- How to Use the 2013 Verizon Data Breach Investigations Report
- Verizon's 2013 Data Breach Investigations Report: Highlights
- OBSERVATIONS ON THE 2013 VERIZON DATA BREACH INVESTIGATIONS REPORT
- Hacktivists Change Tactics From Data Breaches to Disruption: Verizon
| Connect with Peter: | Connect with F5: |
| |
Wednesday, April 10, 2013
Ride The Crime Coaster
Now that would be a fun amusement park ride - the Crime Coaster - with the hills and valleys designed based on crime statistic charts. You can even get a digital photo of yourself as you fly thru the Tunnel of Turmoil. Muuhahahahahahahahahah!
With all the dire warnings of how cybercrime is the nation's top priority, I was wondering how other crimes have been faring. And NO, this is not a for/against 'gun control' rant but for instance, is burglary loosing its luster to smashing a server's window? Since cyber crime is a billion dollar business will the door-to-door thief change tactics? Probably not for now but as physical, non-cyber crimes drop, does digital crime go up? Or, since 'stealing something' is the ultimate goal, as more available methods (like cyber) to accomplish the goal become available, does all crime go up? I should also note that crime stats should be taken with a grain of salt since law enforcement can only comment on the crimes that have been reported to them. Crimes like car theft are often reported due to insurance claims while other crimes, like domestic disputes, are under reported due to embarrassment or other hindering factors. Add to that, different jurisdictions have various scales of classification, penalties and measurement. Plus, the recent report that says few companies report that cybercrime results in big losses only adds to the confusion.
According to the FBI, violent crimes in the US are down for the 5th year in a row. Granted, for now, cybercrime is probably more property related than violent but that could change. Cities like Los Angeles, are reporting that crime - violent and property- is down significantly even though, overall, LA is much higher than the rest of California and violent crime in LA occurs at a rate higher than in most communities of all population sizes in America, according to neighborhoodscout.com. Most criminologists agree that several factors are contributing to the decline. We have one of the highest incarceration rates in the world; there has been an increased police presence; there are security cameras everywhere; the aging population; and programs to help both the youngsters and those in need can all be attributed to the decline.
So while our physical bodies and personal property in the material world are safer, our identity, privacy, passwords, infrastructure, and other digital collateral are more at risk than ever. On a daily basis, companies are getting probed and breached yet might not know or simply might not report it. I bet, however, if someone threw a rock smashing their lobby window, a couple Five-O's will be on the scene taking statements. The company, local employees and the police will have a BOLO issued and everyone will be on heightened alert. There might also be additional security measures taken, tempered glass, CCTV, key card entry and other physical protection mechanisms.
We readily deploy layered security for our physical property with locks, alarms, dogs, cameras, window bars, weapons, panic rooms, etc all within the context of what we are trying to protect. We should do the same for our digital assets. Imagine if we took the same safeguards (or paranoia in this case), albeit with different technologies, to protect our bits and bytes. Yes, there will still be breaches but maybe things like D/DoS, SQLi and other well known vulnerabilities can be greatly reduced since we do have the technology to protect against such attacks. It just has to be deployed.
We thwart criminals and protect our personal physical property with a vast array of mechanisms and we feel/are secure...maybe we should take that same focus, fear and fever in protecting our digital self. Then, as you peel off the pixilated mask you'll hear, '...and I would've gotten away with it, too, if it hadn't been for those meddling firewalls!'
ps
Related:
- Why Cyber Crime Is Now the Top Threat Facing U.S.
- FBI Uniform Crime Report
- Violent crimes in U.S. down fifth year in a row, says FBI
- Cyberattacks Abound Yet Companies Tell SEC Losses Are Few
- Crime in Los Angeles is down so far in 2013, report says
- Hackers Are Multiplying and Targeting the U.S.
- Crime Rates Are Down -- But Why?
- The 5 biggest online privacy threats of 2013
| Connect with Peter: | Connect with F5: |
| |



