<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Advanced Persistent Threat</title>
	<atom:link href="http://advanced-persistent-threat.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://advanced-persistent-threat.com</link>
	<description>A Free Resource for APT related info</description>
	<lastBuildDate>Tue, 06 Nov 2012 18:00:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='advanced-persistent-threat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Advanced Persistent Threat</title>
		<link>http://advanced-persistent-threat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://advanced-persistent-threat.com/osd.xml" title="Advanced Persistent Threat" />
	<atom:link rel='hub' href='http://advanced-persistent-threat.com/?pushpress=hub'/>
		<item>
		<title>The Industrialization of Hacking &#8211; A New Era in IT Security</title>
		<link>http://advanced-persistent-threat.com/2012/11/06/the-industrialization-of-hacking-a-new-era-in-it-security/</link>
		<comments>http://advanced-persistent-threat.com/2012/11/06/the-industrialization-of-hacking-a-new-era-in-it-security/#comments</comments>
		<pubDate>Tue, 06 Nov 2012 18:00:45 +0000</pubDate>
		<dc:creator>vmtrain</dc:creator>
				<category><![CDATA[APT in the news]]></category>
		<category><![CDATA[CyberWar]]></category>
		<category><![CDATA[Defending Against APT]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[cyberwar]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=76</guid>
		<description><![CDATA[An article on securityweek.com (http://www.securityweek.com/industrialization-hacking-new-era-it-security) examines what author Marc Solomon calls the “Industrialization of Hacking” likening it to the rise of the Industrial Revolution. He also offers advice on how to best protect systems from these increasingly sophisticated attacks. According to Mr. Solomon, in order to properly defend your network you have to understand it. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=76&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>An article on securityweek.com (<a href="http://www.securityweek.com/industrialization-hacking-new-era-it-security">http://www.securityweek.com/industrialization-hacking-new-era-it-security</a>) examines what author Marc Solomon calls the “Industrialization of Hacking” likening it to the rise of the Industrial Revolution. He also offers advice on how to best protect systems from these increasingly sophisticated attacks.</p>
<p>According to Mr. Solomon, in order to properly defend your network you have to understand it. You also have to build in flexibility to your protection in order to respond to changing security needs. If you can add and change protection to evolve with your environment, you won’t have to start over as new threats develop.</p>
<p>Hacking has grown from a hobby to an organized system. Much like in the Industrial Revolution, innovation has led to easier ways for hackers to attack systems. As hacking has become increasingly profitable, new methods are developed to make it more efficient.</p>
<p>Much as transportation improvements in the Industrial Revolution led to a more connected world, so have new advances in networks, devices and technologies have made it easier to transport malware and conduct attacks anywhere in the world. Communications innovations such as mobile devices allow for widespread connections for users, exposing new security threats. It is increasingly easier for hackers to gather personal information from unwitting users and to upload malware from the wide variety of platforms used to access the internet. It is difficult for IT administrators to control and keep up with new threats posed by the variety of devices used to connect to the network.</p>
<p>Hackers used to be motivated simply by the ability to break into a system. Now hackers are motivated by financial gains. Hackers are becoming more secretive about their methods and have more incentive to launch new and increasingly sophisticated attacks. Security technologies need to stay ahead of hackers while staying within an organization’s budget constraints. Mr. Solomon suggest methods that provide the ability to detect malware and quarantine files, as well as analyze and evolve threat detection based on information gathered from attempted attacks.</p>
<p>The best investment seems to be hands-down, training. Advanced training that covers the leading advanced persistent threat (<a href="http://www.trainace.com/courses/apt/">here is my Advanced Persistent Threat training class</a>) techniques that are new and cutting edge.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/76/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=76&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2012/11/06/the-industrialization-of-hacking-a-new-era-in-it-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/15b47965f67eb6cb275089334092f297?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vmtrain</media:title>
		</media:content>
	</item>
		<item>
		<title>I&#8217;m doing Hacker&#8217;s Breakfast. 3-hr Wor</title>
		<link>http://advanced-persistent-threat.com/2012/02/21/im-doing-hackers-breakfast-3-hr-wor/</link>
		<comments>http://advanced-persistent-threat.com/2012/02/21/im-doing-hackers-breakfast-3-hr-wor/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 20:01:23 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/2012/02/21/im-doing-hackers-breakfast-3-hr-wor/</guid>
		<description><![CDATA[I&#8217;m doing Hacker&#8217;s Breakfast. 3-hr Workshops in MD and VA. Check it out: http://ow.ly/9bRnG<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=73&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m doing Hacker&#8217;s Breakfast. 3-hr Workshops in MD and VA. Check it out: <a href="http://ow.ly/9bRnG" rel="nofollow">http://ow.ly/9bRnG</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=73&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2012/02/21/im-doing-hackers-breakfast-3-hr-wor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>CyberWar&#8230;CyberWar&#8230;CyberWar</title>
		<link>http://advanced-persistent-threat.com/2011/11/29/cyberwar-cyberwar-cyberwar/</link>
		<comments>http://advanced-persistent-threat.com/2011/11/29/cyberwar-cyberwar-cyberwar/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 10:00:22 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[CyberWar]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=70</guid>
		<description><![CDATA[I don&#8217;t know how I hadn&#8217;t seen this before, but I have to admit that I thought General Hayden gave a really thought provoking speech that touched a lot of important areas. I strongly encourage you to watch the video. Here are some thoughts I had while I was watching it: Cyber is a DOMAIN [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=70&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I don&#8217;t know how I hadn&#8217;t seen this before, but I have to admit that I thought General Hayden gave a really thought provoking speech that touched a lot of important areas. I strongly encourage you to watch the video.</p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/pKZDYgj0KTA?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<p>Here are some thoughts I had while I was watching it:</p>
<ul>
<li>Cyber is a DOMAIN (eg: Land, Sea, Air, Space – now Cyber)</li>
<li>Shaping military thinking (Global, Strategic, etc)</li>
<li>My thought is – how feasible/scalable is this? It’s not kinetic/measurable!</li>
</ul>
<p>He makes an analogy of how we (IT people) make the IT world like the north German plain (flat). Then we bitch about getting invaded.</p>
<ul>
<li>In terms of military strategy how would you deal with this.</li>
<li>There is no high ground to seek.</li>
<li>There is no real front or rear.</li>
<li>From a military standpoint I think your advantage would be visibility, and you would focus on ensuring that you are not flanked or overrun.</li>
<li>Immediate tasks to execute are:</li>
<li>Set up extended observation posts to know when the enemy is approaching</li>
<li>Dig in (trenches, foxholes, etc), focus on communication and the ability to move</li>
<li>Set up strategic firing positions</li>
<li>I guess the question is how do you replicate this in the Cyber world &#8211; which seems to be his point as well.</li>
</ul>
<p>&nbsp;</p>
<p>The General made a statement that was very powerful (MARTIN C. LIBICKI: CounterDeterrance &amp; CyberWar)</p>
<ul>
<li>I think this is the reference from RAND (I could be wrong): <a href="http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf">Cyberdeterrence and Cyberwar</a></li>
<li>I think this is his book: <a href="http://www.amazon.com/Cyberdeterrence-Cyberwar-Martin-C-Libicki/dp/0833047345">http://www.amazon.com/Cyberdeterrence-Cyberwar-Martin-C-Libicki/dp/0833047345</a></li>
</ul>
<p>&nbsp;</p>
<p>I would sum all of this up with what I hear from a lot of the military people I work with.</p>
<ul>
<li>The problem with selling CyberWar is that it is NOT kinetic.</li>
<li>Attribution is nearly impossible</li>
</ul>
<p>In the &#8220;Cyber&#8221; world I see a lot of the functional equivalent of Explosive Ordinance Disposal (EOD) – analyzing malware and trying to collect Intel on it like an EOD guy examines bombs to learn about the enemy. I think there are just too many rules placed on those guys doing that kind of work. The General references it (in my opinion) by talking about the relationship between CND/CNE/CNA.</p>
<ol>
<li>Interesting paradigm:
<ul>
<li>CND = DHS money and rules</li>
<li>CNE = Intel community – title 50 (secret squirrel stuff – people stuck in a SCIF)</li>
<li>CNA = DoD – title 10 laws of armed conflict</li>
</ul>
</li>
</ol>
<ol>
<li>Chinese Espionage Effort (23 minute point)
<ul>
<li>Build/Buy/Steal whatever it is they need to make things equal</li>
</ul>
</li>
</ol>
<ol>
<li>Cyber Domain Difference:
<ul>
<li>Intel precedes OPs in the physical world</li>
<li>OPs preceeds intel in the Cyber world</li>
<li>This is profoundly important – way to go on articulating this sir.</li>
</ul>
</li>
</ol>
<p>I don&#8217;t know if it is just because the military is so near and dear to my heart, or if I&#8217;m just a freak for CyberWar stuff, or what. I thought this was a really good presendation.</p>
<p>To wrap up the subject of CyberWar for this blog post I want to add one other tidbit of info. It&#8217;s part of a blog post that I started writing a few weeks ago and of course didn&#8217;t finish, but I think it will wrap up this post here fairly well.</p>
<p>It all started a few weeks ago. I was talking to a good friend of mine <a title="Marco Figueroa" href="http://twitter.com/MarcoFigueroa">Marco</a> about CyberWar, and APT. We were talking specifically about ney sayers &#8211; people that don&#8217;t believe in APT and CyberWar.</p>
<p>I did some Googling and found a pretty interesting debate about whether the CyberWar threat is grossly exagerated or not.</p>
<p>It&#8217;s not deeply technical, but it does have some good speakers or debators if you will.</p>
<p>Arguing for the Cyber War Threat being grossly exagerated are Bruce Schneier, and Marc Rotenberg.</p>
<p>Arguing against the Cyber War Threat not being exagerated Mike McConnell, and Jonathan Zitrain.</p>
<p>Bruce Schneier is..well&#8230;umm..he&#8217;s Bruce. There are no words to describe Bruce.</p>
<p><a title="Bruce Schneier" href="http://en.wikipedia.org/wiki/Bruce_Schneier">http://en.wikipedia.org/wiki/Bruce_Schneier</a></p>
<p>Marc Rotenberg is an Internet Privacy rights type.</p>
<p><a title="Marc Rotenberg" href="http://en.wikipedia.org/wiki/Marc_Rotenberg">http://en.wikipedia.org/wiki/Marc_Rotenberg</a></p>
<p>Mike McConnel was a Vice Admiral in the Navy, former Director of the NSA, and Director of National Intelligence (2007 &#8211; 2009), and now Executive Vice President at Booz Allen Hamilton.</p>
<p><a title="Mike McConnel" href="http://en.wikipedia.org/wiki/John_Michael_McConnell">http://en.wikipedia.org/wiki/John_Michael_McConnell</a></p>
<p>Jonathon Zitrain is an Internet Law professor at Harvard</p>
<p><a title="Jonathon Zitrain" href="http://en.wikipedia.org/wiki/Jonathan_Zittrain">http://en.wikipedia.org/wiki/Jonathan_Zittrain</a></p>
<p>I thought the debate was good (for the most part) &#8211; there were a few times that I thought Marc Rotenberg was pushing the Internet privacy agenda a bit too much, but overall I thought it was a good debate.</p>
<p>Take a look for yourself and let me know what you think.</p>
<p><strong>Intelligence Squared US: Cyber War Debate</strong></p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/3N6Mnq1cIs4?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/7pEc9gDDs4Q?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/QJVvAv98A8U?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/oQwhD6hfjzI?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/zwBzrMze8FY?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/70/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/70/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=70&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/11/29/cyberwar-cyberwar-cyberwar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>Help Advanced Persistent Threat</title>
		<link>http://advanced-persistent-threat.com/2011/10/04/help-advanced-persistent-threat/</link>
		<comments>http://advanced-persistent-threat.com/2011/10/04/help-advanced-persistent-threat/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 09:20:59 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[CyberWar]]></category>
		<category><![CDATA[Defending Against APT]]></category>
		<category><![CDATA[Tactics & Techniques]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=67</guid>
		<description><![CDATA[I Need Help!!!! My goal is for this site to become the top resource on the internet for Advanced Persistent Threat related information, and more importantly have everything on the site be free. I don&#8217;t want the site to be about FUD (Fear Uncertainty and Doubt), hype, or vendor BS. Anyone that deals with APT [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=67&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><strong>I Need Help!!!!</strong></p>
<p>My goal is for this site to become the top resource on the internet for Advanced Persistent Threat related information, and more importantly have everything on the site be free. I don&#8217;t want the site to be about FUD (Fear Uncertainty and Doubt), hype, or vendor BS.</p>
<p>Anyone that deals with APT is tired of the hype, and even more tired of vendors trying to scare us into buying their products only to find out that they don&#8217;t work for identifying and stopping APT.</p>
<p>I&#8217;m looking for help with developing relevant content for this site. I&#8217;m hoping to get the community involved in the following areas:</p>
<p><strong> </strong></p>
<p><strong>Intel (you can be completely anonymous &#8211; we won&#8217;t leak who you are or where you work):</strong></p>
<ul>
<li>Providing information about state sponsored hackers (Targets, tactics, techniques, etc)</li>
<li>Providing information about cyber crime hackers (Targets, tactics, techniques, etc)</li>
<li>Providing information about zero-day exploits, highly specialized back doors</li>
</ul>
<p>&nbsp;</p>
<p><strong>Tool Development:</strong></p>
<ul>
<li>Providing tools that can be used to either emulate APT tools/tactics</li>
<li>Providing tools that can be used to identify APT attacks</li>
</ul>
<p>&nbsp;</p>
<p><strong>Signatures:</strong></p>
<ul>
<li>Providing signatures that can be used in helping organizations identify APT attacks</li>
</ul>
<p>&nbsp;</p>
<p>Please contact me at: joe {no spam} strategicsec.com. If you need to encrypt emails to me, you can you use my <a href="http://strategicsec.com/JoeStrategicSec_Public.key">public key</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/67/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=67&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/10/04/help-advanced-persistent-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>State Sponsored Hackers and The Above Ground Exploit Market</title>
		<link>http://advanced-persistent-threat.com/2011/09/26/state-sponsored-hackers-and-the-above-ground-exploit-market/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/26/state-sponsored-hackers-and-the-above-ground-exploit-market/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 05:00:52 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Zero-Day Exploit]]></category>
		<category><![CDATA[crimeware]]></category>
		<category><![CDATA[nation state attackers]]></category>
		<category><![CDATA[state sponsored attackers]]></category>
		<category><![CDATA[zero-day exploit]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=58</guid>
		<description><![CDATA[I just finished reading a pretty good article from Kaspersky&#8217;s ThreatPost.com website. The article was about how Nation State Attackers target Adobe products (PDF reader, flash, shockwave, etc). I especially liked the part about the article where Dennis Fisher, the article writer describes the evolution of a zero-day working its way down to crimeware attack [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=58&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I just finished reading a pretty good article from Kaspersky&#8217;s ThreatPost.com website. The article was about how Nation State Attackers target Adobe products (PDF reader, flash, shockwave, etc). I especially liked the part about the article where Dennis Fisher, the article writer describes the evolution of a zero-day working its way down to crimeware attack packs (note &#8211; where Arkin is mentioned below &#8211; the author is referring to Brad Arkin, the senior director of product security and privacy at Adobe):</p>
<blockquote><p>=-=-=-=-=-=-=-=-=-=-=-=-=-<br />
&#8220;..when a new attack involving a zero-day bug in one of Adobe&#8217;s products starts, it typically will begin with attacks against a select group of high-profile organizations. That usually means defense contractors, government agencies or large financial services companies. Once the security teams at those organizations find and analyze the threat, Arkin said his team will begin getting a flurry of calls within an hour or two as the campaign hits.</p>
<p>From there, the attack will often then move down the ladder to other large enterprises and then smaller ones as the new exploit shows up in crimeware packs and automated attack tools. By that time, it&#8217;s likely an entirely different set of attackers using the exploit. But it&#8217;s the well-funded and highly skilled attackers who are doing the real heavy lifting in terms of finding new bugs and designing methods to exploit them.</p>
<p>&#8220;These samples trickle downhill really quickly and show up in crime packs,&#8221; Arkin said. &#8220;The actual exploits it turns out are very, very expensive and difficult to build. Finding the flaw is a lot easier than writing the exploit.</p>
<p>=-=-=-=-=-=-=-=-=-=-=-=-=-</p></blockquote>
<p>This is really good, and it is something that isn&#8217;t very well understood in my opinion. I do however think that there is another wrinkle here and that is the actual sale of zero-day exploits. A good PDF zero-day exploit for example can be worth over $50,000 dollars.</p>
<p><a title="Charlie Miller" href="http://twitter.com/0xcharlie">Charlie Miller</a> wrote a good <a title="The legitimate vulnerability market: the secretive world of 0-day exploit sales" href="http://securityevaluators.com/files/papers/0daymarket.pdf">whitepaper</a> about the legitimate buying and selling of exploits while he was working at Independent Security Evaluators.In one of Charlie&#8217;s presentations at AuCert2008 security conference his presentation had a chart with a price breakdown for the various exploit types commonly sold. Although the presentation was given in 2008, the pricing still holds fairly well today as a reference. Note everywhere in the chart that you see Vista, just mentally replaace it with Windows 7.</p>
<p><a href="http://advancedpersistentthreat.files.wordpress.com/2011/09/exploit-cost-breakdown.png"><img class="alignnone size-full wp-image-64" title="Exploit Cost Breakdown" src="http://advancedpersistentthreat.files.wordpress.com/2011/09/exploit-cost-breakdown.png?w=497&#038;h=327" alt="" width="497" height="327" /></a></p>
<p>&nbsp;</p>
<p>Security.StackExchange.com has the question <a title="Which companies facilitate payment in return for vulnerability disclosure?" href="http://security.stackexchange.com/questions/4086/which-companies-facilitate-payment-in-return-for-vulnerability-disclosure">&#8220;Which companies facilitate payment in return for vulnerability disclosure?&#8221;</a> answered and they provide a very good list of companies that actually purchase zero-day exploits from security researchers and exploit developers.</p>
<ul>
<li><a title="Zero Day Initiative (ZDI)" href="http://www.zerodayinitiative.com/">Zero Day Initiative (ZDI) by TippingPoint</a></li>
<li><a title="iDefense" href="http://labs.idefense.com/vcp/">iDefense</a></li>
<li><a title="iSight Partners" href="https://gvp.isightpartners.com">iSight</a></li>
<li><a title="SecureiTeam" href="http://www.beyondsecurity.com/ssd.html">SecuriTeam</a></li>
<li><a title="Netragard" href="http://snosoft.blogspot.com/2010/03/recent-news-on-forbes-about-our-exploit.htm">Netragard</a></li>
<li><a title="COSEINC" href="http://www.coseinc.com/" rel="nofollow">COSEINC</a></li>
<li><a title="Immunity Security" href="http://www.immunitysec.com/" rel="nofollow">Immunity</a></li>
</ul>
<p>Certain companies like Mozilla and Google have established bug bounty programs &#8211; they buy vulnerabilities of their software themselves. These bug bounty programs are generally paying anywhere from few hundred to a few thousand dollars.</p>
<p>A ripple in the pond of exploits for sale is the buying and selling of non-zero day exploits. Now off hand you&#8217;d probably think these types of exploits don&#8217;t have any real value because there is already a known fix for them, but au contraire mon frere, check out <a title="Exploit Hub" href="https://www.exploithub.com/">ExploitHub</a>. They&#8217;ve even gotten some decent press as well:</p>
<ul>
<li><a title="Forbes" href="http://www.forbes.com/forbes/2010/0927/technology-internet-hackers-nasdaq-nss-digital-arms-dealer.html">Forbes</a></li>
<li><a title="eWeek" href="http://www.eweek.com/c/a/Security/NSS-Labs-to-Open-Exploit-Marketplace-for-Security-Community-807562/">eWeek</a></li>
<li><a title="Dark Reading" href="http://www.darkreading.com/vulnerability_management/security/vulnerabilities/showArticle.jhtml?articleID=227400090">Dark Reading</a></li>
<li><a title="Softpedia" href="http://news.softpedia.com/news/NSS-Labs-Plans-to-Launch-Online-Exploit-Market-155863.shtml">Softpedia</a></li>
</ul>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=58&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/26/state-sponsored-hackers-and-the-above-ground-exploit-market/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>

		<media:content url="http://advancedpersistentthreat.files.wordpress.com/2011/09/exploit-cost-breakdown.png" medium="image">
			<media:title type="html">Exploit Cost Breakdown</media:title>
		</media:content>
	</item>
		<item>
		<title>Technical details about the RSA hack</title>
		<link>http://advanced-persistent-threat.com/2011/09/19/technical-details-about-the-rsa-hack/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/19/technical-details-about-the-rsa-hack/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 06:30:16 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[APT in the news]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[rsa attack]]></category>
		<category><![CDATA[rsa secureID]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=52</guid>
		<description><![CDATA[I really like this blog post about the RSA attack by F-Secure. Take a look at this &#8211; I think you&#8217;ll really like it: http://www.f-secure.com/weblog/archives/00002226.html Here are a few more references you can take a look at: I know this video is an overly simplified explanation of the attack, but hey man you gotta start [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=52&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I really like this blog post about the RSA attack by F-Secure. Take a look at this &#8211; I think you&#8217;ll really like it:</p>
<p>http://www.f-secure.com/weblog/archives/00002226.html</p>
<p>Here are a few more references you can take a look at:</p>
<p>I know this video is an overly simplified explanation of the attack, but hey man you gotta start somewhere.<br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='497' height='310' src='http://www.youtube.com/embed/UZNF1-1Hk1Y?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>&nbsp;</p>
<p>Here is a little more of a technical walk-through about the RSA attack:</p>
<p>&nbsp;</p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/52yvjLHGnC8?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/52/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=52&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/19/technical-details-about-the-rsa-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of Stuxnet</title>
		<link>http://advanced-persistent-threat.com/2011/09/19/analysis-of-stuxnet/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/19/analysis-of-stuxnet/#comments</comments>
		<pubDate>Mon, 19 Sep 2011 05:00:45 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[APT in the news]]></category>
		<category><![CDATA[CyberWar]]></category>
		<category><![CDATA[Tactics & Techniques]]></category>
		<category><![CDATA[Advanced Persistent Threat]]></category>
		<category><![CDATA[scada]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[zero-day exploit]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=54</guid>
		<description><![CDATA[Quite frankly I&#8217;m tired of talking about Stuxnet, but I have to admit that for as tired as I am of I really don&#8217;t like when people get their facts wrong about it. I decided to put together a list of resources Stuxnet related info. News articles: Security Researcher Presentations: http://media.blackhat.com/bh-dc-11/Parker/BlackHat_DC_2011_Parker_Finger%20Pointing-Slides.pdf Whitepapers: http://www.eset.com/resources/white-papers/Stuxnet_Under_the_Microscope.pdf http://abterra.ca/papers/How-Stuxnet-Spreads.pdf http://www.aisec.fraunhofer.de/content/dam/sitmuc/en/pdf/studien/studie_stuxnet.pdf [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=54&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Quite frankly I&#8217;m tired of talking about Stuxnet, but I have to admit that for as tired as I am of I really don&#8217;t like when people get their facts wrong about it. I decided to put together a list of resources Stuxnet related info.</p>
<p>News articles:</p>
<p>Security Researcher Presentations:</p>
<p>http://media.blackhat.com/bh-dc-11/Parker/BlackHat_DC_2011_Parker_Finger%20Pointing-Slides.pdf</p>
<p>Whitepapers:</p>
<p>http://www.eset.com/resources/white-papers/Stuxnet_Under_the_Microscope.pdf</p>
<p>http://abterra.ca/papers/How-Stuxnet-Spreads.pdf</p>
<p>http://www.aisec.fraunhofer.de/content/dam/sitmuc/en/pdf/studien/studie_stuxnet.pdf</p>
<p>http://www.fas.org/sgp/crs/natsec/R41524.pdf</p>
<p>http://www.xmco.fr/actu-secu/XMCO-ActuSecu-27-STUXNET_EN.pdf</p>
<p>Videos:<br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/cf0jlzVCyOI?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span><br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/lRwYFYxIgeo?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span><br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/DBLuLQ7EHpk?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span><br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='420' height='345' src='http://www.youtube.com/embed/OGQ5WqSvdrU?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>More technical information:</p>
<p>LNK vulnerabilities/Stuxnet<br />
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/eFLNG5zHaVA?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=54&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/19/analysis-of-stuxnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>60 minutes special &#8211; Hacking DoD</title>
		<link>http://advanced-persistent-threat.com/2011/09/12/60-minutes-special-hacking-dod/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/12/60-minutes-special-hacking-dod/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 06:30:29 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[APT in the news]]></category>
		<category><![CDATA[CyberWar]]></category>
		<category><![CDATA[Videos]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=47</guid>
		<description><![CDATA[This is the news blurp some people have asked me about that referenced how CENTCOM was hacked into. One of the things that is and will continue to be difficult about this site is that I can only post information that is in the public domain. There are very few public details about how bad [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=47&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This is the news blurp some people have asked me about that referenced how CENTCOM was hacked into. One of the things that is and will continue to be difficult about this site is that I can only post information that is in the public domain.</p>
<p>There are very few public details about how bad this attack really was. Those of us that work in or with the DoD have an idea of how critical the attack must have been because of the defensive measures that have been put in place since the attack.</p>
<p><a href="http://cnettv.cnet.com/av/video/cbsnews/atlantis2/cbsnews_player_embed.swf">http://cnettv.cnet.com/av/video/cbsnews/atlantis2/cbsnews_player_embed.swf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/47/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=47&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/12/60-minutes-special-hacking-dod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>Video Proof of State-Sponsored Hackers in China</title>
		<link>http://advanced-persistent-threat.com/2011/09/12/video-proof-of-state-sponsored-hackers-in-china/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/12/video-proof-of-state-sponsored-hackers-in-china/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 06:30:09 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[CyberWar]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[state sponsored attackers]]></category>
		<category><![CDATA[state sponsored hackers]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=50</guid>
		<description><![CDATA[Amazing &#8211; we finally have documented proof! I wouldn&#8217;t call this specific incident APT, but I do think it&#8217;s a good thing for the public to see that there finally is a documented case of state-sponsored attackers. Here is opening quote from the blog post: &#8220;China is often blamed for launching online attacks, but the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=50&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Amazing &#8211; we finally have documented proof! I wouldn&#8217;t call this specific incident APT, but I do think it&#8217;s a good thing for the public to see that there finally is a documented case of state-sponsored attackers.</p>
<p>Here is opening quote from the <a title="Video Proof of State Sponsored Hacking in China" href="http://www.f-secure.com/weblog/archives/00002221.html">blog post</a>:</p>
<p>&#8220;China is often blamed for launching online attacks, but the evidence is almost always circumstantial. Many of the targeted espionage trojans seem to come from China, but we can&#8217;t actually prove it.</p>
<p>However, some new evidence has just surfaced.&#8221;</p>
<p>Source:</p>
<p>http://www.f-secure.com/weblog/archives/00002221.html</p>
<p>&nbsp;</p>
<p>The <a title="Video Proof of State Sponsored Hacking in China - removed" href="http://www.f-secure.com/weblog/archives/00002224.html">follow-on blog post</a> shows how the video proof was removed:</p>
<p>http://www.f-secure.com/weblog/archives/00002224.html</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=50&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/12/video-proof-of-state-sponsored-hackers-in-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
		<item>
		<title>CyberWar: 60 minutes special from 2010</title>
		<link>http://advanced-persistent-threat.com/2011/09/12/cyberwar-60-minutes-special-from-2010/</link>
		<comments>http://advanced-persistent-threat.com/2011/09/12/cyberwar-60-minutes-special-from-2010/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 06:00:06 +0000</pubDate>
		<dc:creator>Joseph McCray Jr.</dc:creator>
				<category><![CDATA[APT in the news]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[cyber command]]></category>
		<category><![CDATA[cyberwar]]></category>
		<category><![CDATA[nsa]]></category>

		<guid isPermaLink="false">http://advanced-persistent-threat.com/?p=44</guid>
		<description><![CDATA[This is important. CyberWar is a very real threat, but there are so many people in the industry (e.g. media/vendors) that are just Fear Uncertainty and Doubt (FUD) spreaders. The old quote &#8220;Paranoia is billable&#8221; comes to mind when I see this FUD spreading by media and vendors. It&#8217;s hard to have a real conversation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=44&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This is important. CyberWar is a very real threat, but there are so many people in the industry (e.g. media/vendors) that are just Fear Uncertainty and Doubt (FUD) spreaders. The old quote &#8220;Paranoia is billable&#8221; comes to mind when I see this FUD spreading by media and vendors.</p>
<p>It&#8217;s hard to have a real conversation about CyberWar that&#8217;s not FUD, and I think this 60 minutes special is pretty good, but it&#8217;s a little on the FUD side in my opinion.</p>
<p>&nbsp;</p>
<p>I do love the point made that we (meaning the USA) do this stuff too.</p>
<p>&nbsp;</p>
<p><a href="http://cnettv.cnet.com/av/video/cbsnews/atlantis2/cbsnews_player_embed.swf">http://cnettv.cnet.com/av/video/cbsnews/atlantis2/cbsnews_player_embed.swf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/advancedpersistentthreat.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/advancedpersistentthreat.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=advanced-persistent-threat.com&#038;blog=24484433&#038;post=44&#038;subd=advancedpersistentthreat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://advanced-persistent-threat.com/2011/09/12/cyberwar-60-minutes-special-from-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/2b3ea7bd7fad6498069b31a6065f439c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joemccray</media:title>
		</media:content>
	</item>
	</channel>
</rss>