New Security Force to Debut Soon in Mexico

MEXICO CITY — A vaunted plan to create a new security force, known as the Gendarmerie, has been watered down sharply in the past two years but is about to come to fruition.

Sometime in late July, the government of President Enrique Pena Nieto will put the 5,000-member Gendarmerie into action, National Security Commissioner Monte Alejandro Rubido said Friday.

The force will not be anywhere near the scope of what Pena Nieto outlined while running for president back in 2012. At that time, he suggested the new force might have up to 50,000 officers.

Since then, the government has steadily scaled back its vision of the force. By February 2013, a previous national security commissioner, Manuel Mondragon y Kalb, forecast 10,000 gendarmes. Four months after that, Interior Secretary Miguel Angel Osorio Chong announced the force might have only 5,000 people.

In a briefing with foreign reporters Friday, Rubido said Friday that gendarme recruits are getting final training in Colombia. Other nations that have provided assistance include Spain, France, and the United States.

Second-Hand Smartphones Are a Trove of Personal Information

Many mobile device users rely on simply deleting the private information on the storage card of the phone before selling it, in order to ensure that sensitive details are not passed to the new owner. However, items are stored persistently, and unless they are corrupted through overwrite action, they can be recovered.

Avast carried out an experiment with 20 Android phones purchased through eBay, and then tried to find out how much of the deleted information could be retrieved.

The results showed that a numerous amount of items belonging to the previous owners could be recovered by using a mainstream utility.

According to their report, they managed to bring back more than 40,000 photos, and learned about over 1,000 Google searches, more than 750 email and text messages and over 250 contact names and email addresses.

By putting together these bits and pieces, cybercriminals can learn important details about the potential victim and start targeted phishing campaigns with a high rate of success, which could bring them a pretty income.

Blackmailing activities can also be deployed by the criminals, as Avast says that more than 750 of the images retrieved were with women in various stages of nakedness.

Among their findings were the identities of four previous owners, which can also be leveraged to conduct nefarious activities against them.

Zetas Fuel Veracruz Security Crisis in South East Mexico

Rising kidnappings, the discovery of mass graves, and security force shootouts with alleged Zetas members have created a security storm in the state of Veracruz in southeast Mexico, but what lies behind this streak of violence?

On July 2, authorities discovered a clandestine grave containing at least eight bodies in a southern municipality of Veracruz, reported Animal Politico. This followed the June discovery of 12 mass graves in which at least 31 bodies were unearthed.

Accompanying these chilling finds has been a series of shootouts in urban areas of the state, reported Proceso. On July 5, security forces killed six alleged criminals in the city of Veracruz, while three alleged members of the Zetas criminal organization were killed in nearby Orizaba. A day earlier, police killed four suspected Zetas near the coast, including the group’s alleged Veracruz plaza chief — the local leader in charge of that territory.

Crime in Mexico Costs Companies $5.8 Billion Annually

Roughly 37 percent of companies have fallen victim to crime of some form, including corruption, robbery of merchandise, shoplifting, kidnapping and extortion, the head of the Coparmex employers’ association said

MEXICO CITY – Crime and a climate of insecurity in Mexico cost companies some 75 billion pesos ($5.8 billion) annually, the head of the Coparmex employers’ association said.

Roughly 37 percent of companies have fallen victim to the crime of some form, including corruption, robbery of merchandise, shoplifting, kidnapping, and extortion, Juan Pablo Castañon told a group of foreign correspondents.

Top 6 Vulnerabilities Found Via Penetration Tests

The basement-dwelling teenager poring over lines of scrolling code as he rips through the security of a government or corporate server is a popular trope in Hollywood movies. Although this widespread image of the hacker isn’t accurate, the threat of cyberattacks against government networks is very much a real-world concern.

In order to be more prepared for cybersecurity breaches, agencies should consider a comprehensive penetration test – ethical hacking with the goal of attacking or bypassing the established security mechanisms of an agency’s systems, and using the same tactics as a malicious intruder.

Penetration testing can be conducted by way of a cyberattack or by exploiting a physical vulnerability of an organization.

After gaining access to a system, the penetration testers will report back with detailed information about what vulnerabilities were exploited, how they were able to breach the system, what level of data was accessed and how to prevent future exploitation. The following is a compilation of the six most common vulnerabilities found during penetration tests:

Read More

French Cyber Spies Stealing U.S. Technology

Washington made clear this week that China is America’s biggest cyber nemesis, at least in terms of the theft of U.S. intellectual property. So who’s next? Not Russia, nor North Korea, according to former Defense Secretary Robert Gates. It’s France — one of America’s closest allies

“There are probably a dozen or 15 countries that steal our technology in this way,” Gates said in an interview the Council on Foreign Relations posted online Thursday. “In terms of the most capable, next to the Chinese, are the French — and they’ve been doing it a long time.”

Gates, who was also director of the Central Intelligence Agency in the first Bush administration, said that when he talks to business audiences, he asks, “How many of you go to Paris on business?’ Hands go up. ‘How many of you take your laptops?’ Hands go up. ‘How many of you take your laptops to dinner?’ Not very many hands.”

“For years,” Gates said, “French intelligence services have been breaking into the hotel rooms of American businessmen and surreptitiously downloading their laptops if they felt those laptops had technological information or competitive information that would be useful for French companies.

Facebook Accounts Are Gold for Cybercrooks

By taking a swing at a social network account and successfully hijacking it, a cybercriminal opens the door to plenty more potential victims.

Facebook is the main target in such cases because it is so good a platform for sharing information, which allows bad actors to lure a lot of users.

Malware, spam and phishing links directing users to pages serving carefully planted threats are easily distributed from a stolen Facebook account.

As noted by Nadezhda Demidova, Web Content Analyst at Kaspersky Lab, criminals can use the account for financial gains, “such as extorting money from the hijacked account’s friends. The fraudster can send messages asking people to send money for help.”

Other reasons are the collection of information for launching targeted phishing attacks and even selling the account to other criminals.

Getting their hands on a social network account is done through various methods, ranging from fake notifications, emails sent from a compromised address of a friend and forum messages to banners on third-party resources.

In all these cases, the victim can be attracted to phishing pages where they are asked to log into a fake social network; the details are then sent to the attacker. A compromised Facebook account can also be used to direct the friends of the owner to malicious pages.