Newsflash – US Nuclear secrets leaked online through Shadow IT

by | Jun 16, 2021 | Security

This sounds like a nightmare that could never happen.

US soldiers have been putting sensitive information online in non-secure third party websites. It defies belief, yet we’re reading that it happened. The story popped up on ‘Gizmodo’ .

It is alleged that US Soldiers were saving sensitive information on a couple of common flashcard sites, presumably of things they were trying to memorise and learn.  It seems these are common learning tools used in universities to help students memorise facts.  That works well so long as the facts aren’t top secret!  Even worse, their settings were on ‘public’ not ‘private’!

It is a classic warning about the risk of people, however well intentioned, saving critical data online in places the organisation is unaware of, and can’t control. That’s why our KARE FOUNDATION proactive cyber-security plan helps identify use of these sites in your organisation.

For more detail : Why you need to know all the cloud services that your organisation uses – part 2 – (US DoD Nuclear Secrets!) – IT Solutions and Managed Services (kinetics.co.nz)

Shadow IT is part of our 10-point cyber-security check list

While there is no single layer of technology that can guarantee you will be safe from hackers, you can reduce your risk by adding layers of protection. How many of our 10-point check list are in place for you?

Don’t be in the 67,500

Don’t be in the 67,500

It might be our nearest neighbour, rather than us, but its still a good indicator of the trends that we're also seeing in New Zealand. We have to remember that much cyber-crime is still not reported.  Whether it's out of embarrassment or commercial sensitivity, we...

Urgent – “Zero Day” exploit 9 Sept 2021

Urgent – “Zero Day” exploit 9 Sept 2021

Today's news is full of stories about increased cyber-threats in NZ - Cyber attacks against Kiwibank, ANZ, NZ Post, MetService - experts see lockdown link - NZ Herald We've seen several days of issues caused by these "DDOS" attacks.   Overnight, another...

Have you heard about “typosquatting”?

Have you heard about “typosquatting”?

"Typosquatting" is the name given to criminals pretending to be someone they aren't - taking a domain name that uses a clever combination of legitimate-looking original sender email addresses, with spoofed display sender addresses that contain the target usernames and...

Cyber-war Seminar

Cyber-war Seminar

Stories from the Cyber-war The simple reality is that cyber-crime is now a mega-business.  The cost and effort to combat it grows all the time. "Is it worth it?"  Good question.  Every organisation needs to choose a level of security and resulting cost, effort and...

Pretending to be you or your colleagues

Pretending to be you or your colleagues

Just because it seems safe, doesn't mean it is. On some emails, you might see a warning that marks them as being ‘external’. This gets added as the email comes into your organisation. The idea is a simple one – if you see an email marked as external, then you will be...

Avoiding ad trackers when you browse the ‘net

Avoiding ad trackers when you browse the ‘net

Your own personalised stalker It always seemed slightly creepy that your computer shows advertising that is strangely accurately targeted at things you might have been interested in.  On the surface, that seems quite useful.  If you have to tolerate ads on your...