Showing posts with label Security Topics. Show all posts
Showing posts with label Security Topics. Show all posts

Thursday, April 11, 2019

Security Round Up: Amazon, Facebook & Ransomware

If you are interested or looking for them you can find near daily news articles discussing some form of risk to the security of our private data. This can come in many forms including, but not limited to:
  • Company data breaches
  • Ransomware attacks
  • Phishing schemes
  • Malware
  • Companies storing files in plain text
  • Servers that did not receive critical updates
  • Social engineering and more
The point of this list is to show all the ways we need to be vigilant. While we do not want to waste all our time worrying about our data, the more present we are while online and the more cautious we are when sharing information, the better protected we will be. There will always be examples of issues out of our hands, for instance when a company gets hacked, but if we protect ourselves by not reusing user id's and passwords we can control how badly we are affected.

Thursday, March 07, 2019

It's Consumer Protection Week - Here's 4 Ways to be Safer Online

This week is National Consumer Protection week and as while there are many threats to our user data and personal information, there are also a multitude of ways we can protect ourselves. Some examples of best practices are:
  • Using a credit card rather than debit card - this prevents you from needing to enter a pin in public where people can visually capture your input.
  • Using Apple or Google Pay - these applications store your credit card so you do not need to physically access the card to use it.
  • Using a unique PIN for debit cards - not reusing this pin for unlocking cell phones or as voicemail codes, etc.
  • Never sharing passwords, account access, and credit or debit cards with others.
There are other, more advanced threats to the security of your devices. It is important to be aware of them as this increases your ability to protect yourself from them. 


It's Consumer Protection Week - Here's 4 Ways to be Safer Online

There are far more than four approaches to staying safe in an online environment, but these ideas can be implemented immediately. Most importantly, remember to slow down when you are feeling pressured. Hackers often use scare tactics to appeal to your emotional, and less rational, feelings to get you to act without thinking. If you stop and think about what is going on before reacting, you will be less likely to make a big mistake.


Reduce the amount you rely upon search

Thursday, January 31, 2019

Security Round Up: Email, Voicemail and Paycheck Phishing

We are barely a month into 2019 but attacks on our data are as prevalent as ever. Threats can come in many forms, including but not limited to:
  • Company data breaches (which you have no control over)
  • Hacked user accounts often stemming from weak or commonly used passwords (which we can control)
  • Phishing attacks via email, phone calls and more
  • Email attacks
  • Malware embedded images
  • Unsecured wireless networks
  • Unencrypted online forms
  • Man-in-the-middle attacks

This post covers what we need to know and what we can do to protect our data in relation to some of the most recent threats.

Thursday, January 03, 2019

Security Round Up: What Recent Breaches You Should Know

It is the start of a new year which means new goals for most people and a fresh way of looking at things. Unfortunately, one thing that did not change with the start of the new year is the threat to your personal information and data. During the last few months some substantial new threats were released. These threats are in addition to the millions of users' data leaked via companies like Marriott and others and are of particular importance as they affect hardware items people commonly have in their home.

Security Round Up: What Recent Breaches You Should Know


Guardzilla indoor wireless security systems - GZ501W

A vulnerability in some of Guardzilla's indoor wireless security systems allow hard coded security keys to be easily cracked. This vulnerability exists primarily because the keys utilize an outdated algorithm. Once cracked, those keys can be used to access customer data uploaded to Amazon web services where Guardzilla's storage servers reside. 


Thursday, November 15, 2018

4 Reasons you need to be Hyper-Vigilant Clicking Ads

During the last few months of the year the variety and number of ads and emails increases exponentially. Consumer spending is traditionally higher during this time which helps retailers clear out product and bolster company profits. As consumers spend more during this time of year, they are also looking for purchases that make the best use of their money. 

Unfortunately, with more purchases being made, hackers proportionally increase the number of scam emails and infected ads. The end result is that end users are at a consistently higher risk of running across one. In addition to an increase in infected ads and emails, this time of year is fraught with events, commitments and more limited time. If we allow ourselves to be rushed, we are more likely to make less informed decisions. This can end up costing us time to remedy, money to fix and a great deal of frustration.


4 Reasons you Need to be Hyper-Vigilant Clicking Ads


Listed below are four things to consider before opening emails or clicking ads during the holiday season.

1. Consider the source

Thursday, November 01, 2018

Beware: IoT Devices Bring Features AND Security Risks

IoT or Internet of Things devices provide capabilities and functionality that once seemed improbable. From things as simple as making phone calls to more complicated tasks like adding items to a grocery list, ordering food, managing the temperature of rooms and turning lights on, internet connected devices provide a vast array of features. 

IoT devices access the internet to accomplish many of their features. For example, the internet allows them to:
  • Connect with servers that manage their software
  • Connect with other devices and third-party applications
  • Sync with other devices and applications
  • Install security and feature updates
  • Add new features
  • Much more
Unfortunately, like anything connected to the internet, an inherent security risk is introduced by having this capability. A Consumer Reports investigation from earlier this year reported that millions of televisions could potentially be controlled by hackers exploiting security flaws in these devices. You might not be concerned about a hacked television, but other devices that control temperatures and more, present a much larger risk.


Monday, October 15, 2018

How to Postpone Windows Updates After Recent File Loss

To see this process in action, watch the video that accompanies this post.

This month the Windows 10 update, dubbed update 1809, caused a loss of files on some user devices. After identifying the cause, the update rollout was halted. Unfortunately, some users lost their user profiles and everything including their documents contained within their profile. Currently, there is no guarantee these files can be recovered. Last week the rollout was restarted after the bugs in this update were reportedly fixed.

An issue like this brings many people to wonder how this could happen, and how they can protect themselves in the future when updates are deployed automatically. The answer is you can't opt out of updates, but you can postpone them which might be enough to protect you from an issue like this.


How to Postpone Windows 10 Updates After Recent File Loss

First, it is important to note this update which deleted files is just one of many reasons why it is always important to have an active backup solution. File loss is unpredictable and typically happens without warning. The time to worry about file loss is before anything happens, when file loss seems improbable. For more information about cloud backup solutions, visit our website business continuity page and our cloud backups page.


Thursday, October 04, 2018

When you Should Use Firewalls, Content Filters & Anti-Malware Software

Firewalls, content filters and anti-malware software are all items implemented to protect hardware devices and the data on them. To understand when you should implement any of these types of protections, it is important to understand how they work. Like a bicycle, car and a bus which fulfill similar purposes, these devices have similar goals but accomplish them in very different ways.

By better understanding how each device works, it is easier to decide which are best to implement to meet your particular needs.


When you Should Use Firewalls, Content Filters & Anti-Malware Software


Firewalls

Thursday, July 26, 2018

Security Vulnerabilities: LabCorp, Voter Data, & ComplyRight HR

In the previous security vulnerabilities post we discussed recent issues with Bluetooth, Macy's and Emotet. This post provides information about additional security vulnerabilities that have recently occurred including:
  • LabCorp's Ransomware infection
  • Voter data breach
  • ComplyRight breach
The information about these recent security vulnerabilities include how they might affect you and what you should do to protect yourself. The title of each breach type listed below is a link to an external news source with additional information about that particular security vulnerability.

Security Vulnerabilities: LabCorp, Voter Data, & ComplyRight



LabCorp is one of the largest clinical labs in the U.S. and was the unfortunate victim of a SamSam Ransomware attack on July 13. Luckily, the attack was quickly noticed and immediate measures were taken to stop the spread of the attack. Still, in the 50 minutes it took to stop the attack, 7,000 systems and 1,900 servers were affected. This shows the power and chaos a Ransomware attack can cause, even when client information is not compromised, as in this situation.

Wednesday, July 25, 2018

Security Vulnerabilities: Bluetooth, Macy's, Emotet & More

Dozens of new security vulnerabilities have been discovered in the last few weeks. Some target hospitals, others banking software and still others regular everyday website users. These attacks have come in many different forms including:
  • Bluetooth vulnerability
  • Banking malware
  • Ransomware via brute force RDP (remote desktop protocol)
  • Accessing user accounts via breached websites and unprotected files
This post provides information about the most recent security vulnerabilities including how they might affect you and what you should do to protect yourself. The title of each breach type listed below is a link to an external news source with additional information about that particular security vulnerability.

Security Vulnerabilities: Bluetooth, Macy's, Emotet & More


Bluetooth is used by desktops, laptops, tablets, mobile devices, headphones, speakers, cars and much more. This recent Bluetooth vulnerability affects part of the process Bluetooth devices use to pair and authenticate with one another. The threat involves one aspect of the validation process being skipped which introduces the risk of a man-in-the-middle attack. When taking advantage of this vulnerability, attackers can intercept and decrypt, or forge and inject messages between devices. 

Thursday, July 12, 2018

Why USB Drives are Effective but also Dangerous

External USB drives are convenient and extremely affordable, which makes them the perfect solution for many uses. Consider the following applications:
  • Moving files from one computer to another
  • Keeping a secondary copy of important files
  • Holding software executables, like anti-malware or internet browsers, to install on computers with malware or other issues that make it challenging to install software in traditional ways
  • Sharing large files with others that email filters traditionally block
When USB drives are connected to a device, the device automatically detects it and installs software as necessary. This process takes less than a few minutes and once finished, the device is ready to use. Unfortunately, like many items that make our lives easier, they also bring risk. For example, Internet of Things, or IoT, devices can be controlled via apps and online applications. This also makes them a target to hackers and the easiness of using USB flash drives makes them a target. 


Example of an external USB flash drive. This particular drive has a rotating cover to protect the USB connector.

Wednesday, June 13, 2018

What to Do When Browser Pop-Ups Warn a Device is at Risk

Websites contain far more than just text, they often include images, videos, ads, pop-ups, banners and more. Some features are more intrusive than others. Almost everyone has been to a site where an ad began playing in the background and you were forced to hunt it down to pause it. Unfortunately, because these ads load automatically and are constantly changing, they are often targeted by hackers. 

There is a history of ads being injected with malicious code before being presented to the visitor and every so often articles are released about this issue. Phishing browser pop-ups are presented in different ways including those:
  • Stating your device may have been infected by malware and to call a number for assistance. This attack often claims to be coming from Microsoft which it is not!
  • Stating there has been a problem with your computer and to call a number for assistance. The number typically claims to be tech support.
  • With a warning message and an accompanying audio message. The audio typically loops for dramatic effect and follows the script of the pop-up.
An example of a browser pop-up.

Wednesday, June 06, 2018

Managing Mobile Devices - 3 Controls you Need to Know

From smartphones to tablets to laptops, these devices connect us to mail, social media, business documents, photos and videos, and more. Whether for work or for personal reasons, the purpose of these devices is to make our lives easier, and to provide timely information in a convenient way. The drawback to easy and quick access to information is the potential for unknown individuals to gain unauthorized access to that data.

Personal devices typically have less important information than business devices, but security threats can be detrimental to both. For a business the threat is constant and measurable. Loss of client personally identifiable information, or PII, can lead to financial penalties, loss of reputation and much more. Mobile devices present greater management issues than those in main office buildings managed by firewall and content filter rules. Mobile devices are often targeted more actively while having less protections. Luckily, there is software that provides management tools which has been created specifically for assisting in managing mobile devices and the security threats that target them.

Managing Mobile Devices - 3 Controls you Need to Know


Consider the following:
  • An employee traveling for work has their laptop stolen and an unknown individual may gain access to the files on that device
  • A family member leaves a device behind in a coffee shop
  • Someone who is no longer an employee fails to return a device provided to them

Thursday, May 31, 2018

The Security Risks Presented when Using Public WiFi

Connecting computers and laptops to WiFi provides the ability to browse the internet. Connecting smart phones to WiFi allows them to browse the internet without the data being transferred counting against a data plan. Additionally, local WiFi can often provide faster transfer rates than using a smartphone's built-in cellular connection because of the close proximity.

Taking advantage of the many benefits provided by utilizing WiFi seems like a win-win! Unfortunately, there is a big difference between using secure WiFi at your home or office and connecting to public WiFi.



The Security Risks Presented when Using Public WiFi


Connecting to your wireless network at home should not provide security risks when the network is secured with a unique password that is changed at least 1-2 times per year. When your wireless router supports it, create two wireless networks and implement them like this:
  • Use one to connect computers, laptops, shared storage devices, and printers. 
  • Use the other to connect smart phones and all IoT items like fans and thermostats, streaming devices like Roku and Chromecast, and for guest devices.

Wednesday, April 25, 2018

Recent Hacks & Breaches - What you Need to Know

From Ransomware to leaked user accounts, there have been some massive hacks and breaches in 2018 already. These security incidents remind us once again how important it is to:
  • Use multiple user id's and password combinations
  • Regularly change passwords
  • Create lengthy and complex passwords
  • Check credit and bank accounts often for fraudulent charges
  • Be careful when clicking links and opening emails
  • When using free WiFi refrain from entering credentials to log into accounts 
This post covers some of the larger, more recent hacks and breaches and what you need to know about them.


Tuesday, January 09, 2018

Security Round Up: Meltdown & Spectre Patch Scams

It is likely you have heard of the security threats labeled Meltdown and Spectre. These vulnerabilities exist on Intel processors but must be addressed by the current operating system they are running to patch the issue. Patches are being released, although some are being blocked by anti-virus software. Machines that have not been running can also miss these patches. 

Worse yet, there are new phishing email scams being sent that pretend to have information about patches. This security round up covers some basic information about the Meltdown and Spectre threats as well as patch scams.


Security Round Up: Meltdown & Spectre Patch Scams

Both Meltdown and Spectre are security flaws that exist at the architectural level of processors. This means the operating system running on your device hardware, and the software running on top of that operating system, are all vulnerable. Unfortunately, the patches that will thwart the exploit must come from the operating system manufacturers. As security updates are released, it is important to apply them.



Thursday, December 21, 2017

Helpful Technology Information Throughout the Holidays

Whether you love or hate technology, or fall somewhere in between these extremes, technology is ingrained in our daily lives. In some ways technology makes our lives easier, more efficient and we are more connected. In other ways it is easier for people to take advantage of the fact that we are always online and that information can be procured from a distance. 

Since this is often a very busy time of year for people, we cultivated a list of timely posts published over the last year. These posts have helpful information about protecting devices, data, purchasing new devices, and much more!




Helpful Technology Information Throughout the Holidays


Wednesday, December 06, 2017

Managing the Password Policy for Microsoft O365 Accounts

Changing an account password every 90 days is more often than most users would prefer if given a choice. So what happens when we are forced to change account passwords too often? Typically some or all of the following will occur:
  • User passwords get simpler rather than more complex so users can remember them.
  • Only one character of a password is changed. For instance, a number might progress to the next highest iteration.
  • New passwords are written down because it can be difficult to remember them when they are changed often.
By default, Microsoft O365 accounts force users to change their password every 90 days. This can be tedious and frustrating as email on phones and in mail applications will stop working when the password policy has been exceeded. As a user, it can be difficult to know what has happened because these applications do not tell you that a password change is required, it simply stops working. Luckily, an O365 administrator can access the management interface and change the password policy to something that works for everyone.

Wednesday, November 15, 2017

3 Tech Tips for Staying Safe this Holiday Season

Staying safe during the holiday season means many things, but we also need to consider the security of our identity and protecting our credit. Most people use their credit cards more often during this time of year whether it be in person, transactions over the phone, or submitting the information for online orders. Regardless of how you spend during the holiday season, these tips can help keep you safe from those who are otherwise looking to access your information and use it to their advantage.




3 Tech Tips for Staying Safe this Holiday Season

Leave the credit cards in your wallet

Wednesday, October 18, 2017

Security Round-Up: WPA2 Vulnerability, Ransomware & More

Among the news of hurricanes, wildfires and flooding, there are many virtual threats  occurring that are important to know about. New threats are released every day, attacking physical hardware, operating systems, protocols, types of users, companies, and more. Some are annoying, some are malicious, while others lie in wait for the best opportunity to use the information they gathered. 

Occasionally a security issue is released that affects the majority of devices, applications or protocols that the majority of people use. The following threats affect items you are likely using every day.


Security Round-Up: WPA2 Vulnerability, Ransomware & More

WPA2 Vulnerability

A brand new threat to the use of wireless was recently exposed. Key Reinstallation Attack, aka KRACK, is a widespread vulnerability that can affect every device using Wi-Fi. This attack undermines the most common wireless encryption used, Wireless Protected Access 2, or WPA2. WPA2 is used to protect users' information when data is exchanged with websites on the Internet and other computer networks.