Tuesday, May 21, 2019

Microsoft kicks off the rollout of the Windows 10 May Update/1903

Microsoft's Windows 10 May Update/1903 is available to consumers and business customers as of today, May 21. It's available through WSUS, Windows Update for Business and VLSC starting today, too.

Starting today May 21, 2019, consumers and businesses can upgrade to the version 1903, the first feature update to Windows 10 in 2019.  The update is available via download on WSUS, Windows Update for Business.

The latest version available prior to 1903 was version 1809.  You can check which version you are on by using the Windows key + R, the type "Winver" and press the key.  If you are not on version 1809, you can download and install version 1903 without doing the intermediary updates since Windows updates are cumulative.

Users can still delay by 35 days the update however Microsoft is not pushing it on users currently.  Microsoft indicated in April that it was changing the way it rolls out updates to users after the troubles caused by the October 2018/1809 update that caused data loss for some users.

The new update has many new features including "SandBox" which allows Windows Pro, Enterprise and Education users to run potential risky software isolated helping to keep your system safe and secure.

https://www.zdnet.com/pictures/windows-10-update-the-new-features-that-matter-most/16/

I will be updating my system tonight and let you know how it goes.

For the entire story click on the link below;

https://www.zdnet.com/article/microsoft-kicks-off-the-rollout-of-the-windows-10-may-update-1903/?ftag=TREc64629f&bhid=2219791


Wednesday, May 15, 2019

Warning! If You Save your Passwords in a Browser, Don't miss this Blog Post

If you use your favorite internet browsing program to save passwords for websites, you might want to rethink this policy.  This includes all browser programs, Chrome, Firefox, IE and Safari.  In 3 of these, I found the saved passwords were only protected by a user's password or in the case of Safari, the Admin password.  The other major browser has a default policy of no password and will expose passwords with a few clicks of the mouse, however, it does allow you to set a Master password separate from a user password.

If you continue to use this method to save passwords please use a strong password and not one you use for all your protection including websites.  However, if your browser uses a User or Admin password to protect saved website passwords, I have programs that can crack a forgotten password or generate a new password for a user.  In the event your computer is stolen or accessed by a hacker or criminal, they can simply change your password and then proceed to steal your financial website's user name and password.

Lastly, beware this information is readily available using a Googe search.

Google Chrome

I knew about the Password list under settings of Google Chrome but I had never paid any attention to the settings and details of the list.  Last week a client needed to be able to log in to a company web publishing account that was created by a user who had left the company.  I suggested checking if they had saved the account password in Chrome.  Then we could use Chrome to auto login and change the password.  I checked the password list to see if the password was saved.  What I found was that Chrome will easily spill all its content about passwords, Banks, Stocks, Credit Cards, Facebook, any password that is in the saved password list.

By default, passwords in Chrome's password list are masked by dots to prevent one from seeing the actual password, however by simply clicking on the eye icon next to a password Windows will prompt you for your user login password or pin and voila, all passwords can be viewed by clicking on the eye icon to the right of a saved password.

If you have ever shared your password with a family member, co-worker or haphazardly use easy passwords for protection then any financial, confidential or social media sites you visit that have a saved password can be viewed and compromised.  And let me add this, if I know this then hackers and criminals know this and if your computer is compromised by a trojan or malware then they know where to look to get access to your confidential Financial and Personal information.  These steps are easily found by Googling for the information.

To illustrate how to expose your password info under Chrome, click on the 3 dots in a line, upper right corner of Chrome browser, then select Settings from the drop-down.


Next click on Passwords,



When you do this the saved and not saved Password list appears



Once the list appears, all I have to do is click on the eye icon and the system will respond with the following Window asking for the computer password/pin.


Once you have provided the computer with the correct password/pin, Chrome will then allow you to reveal the hidden password for every saved account.

Below is my IBJJF password exposed (since changed)...


You might think all this is bad enough but no, there's more.

I have a Chromebook and Android phones.  If you have provided your Gmail account to these devices and have Sync and personalize Chrome across your devices turned on, you can go to My Google and find all saved passwords from your Chrome and Android based devices.



Mozilla Firefox and Microsoft Internet Explorer

You may think I'm saying not to use Google Chrome or I am picking on Chrome.  I started with Chrome because it is the most popular Windows Browser now.  However, FireFox and IE both have the same issue.

The default setting for Firefox doesn't require you to provide a password/pin to show passwords.  All you have to do in Firefox is click on the settings icon in the upper right of the Firefox browser, select options,


choose Privacy & Security,


next click on Login & Passwords, Saved Logins.  


click on Saved Logins and you are 1 step away for revealing all saved passwords.

Note:  Mozilla does allow you to "Use a master password" which you will want to do.  This is a better option in my opinion than using the user password for a computer, however as stated this is not the default and Mozilla is wide open otherwise.

Internet Explorer

To accomplish the same feat in IE, go to Internet Tools.  If your browser has the Menu Bar option on simply click on Tools and then select Internet Tools from the dropdown, if you don't see the Menu Bar you can access Internet Tools from the Control Panel.






Next click on the Content Tab and select Settings under AutoComplete



Click on Manage Passwords



To expose a password click on the carat symbol to the right of the password.




As you can see the user ID is already there, you will be asked to provide the user password/pin to reveal the password.


Safari

Apple's Safari browser protects Macs behind the Admin password.  This is only as secure as the password is strong and breakable using 3rd party hacker software.










Tuesday, May 7, 2019

Ransomware, Malware attacks - Protection is important but a Recovery Plan is equally important, Israel responds to Hamas hackers with Air Strike

Ransomware: The key lesson Maersk learned from battling the NotPetya attack

In 2017 Maersk the shipping giant based in Denmark was hit by the NotPetya Ransomware.  Maersk was not an intended target by the developers.  NotPetya was developed by the Russian military and assisted by a leaked version of the NSA EternalBlue Hacking tool which helped to spread the WannaCry ransomware outbreak.  NotPetya's intended target was businesses located in Ukraine, however, it was soon out of control and spreading and causing damage around the world costing billions of dollars in lost revenue and IT costs.

Ransomware and malware require constant vigilance and protection to prevent it from affecting your organization.  With many nation states and their intelligence agencies focussed on cyberwarfare against one another, it is a daunting task.  It was a worm developed by the NSA "Stuxnet" that brought down the Iranian centrifuges in their nuclear laboratories in 2010.  Stuxnet like NotPetya was not contained and soon in the hands of criminal hackers wreaking havoc in businesses around the world.

But while protecting networks and critical systems is the ultimate goal, a data recovery plan must also be in place, so in the event of the worst happening and critical services being knocked out, you can still operate.

A significant part of this, said Woodcock, is "that ability to really understand the core business processes" and know everything about the systems and applications which run the operation.

I personally use redundant backup devices and software at my business clients.  It is imperative that there is also backups kept offline in the event of the malware spreading to the backup devices.

To read more about what happened at Maersk;

https://www.zdnet.com/article/ransomware-the-key-lesson-maersk-learned-from-battling-the-notpetya-attack/

Windows Update:  why it is important to update your systems and computers.  

As new security holes are discovered and exploited, Microsoft releases updates patching these security risks.  Computers that have not been patched or are using an old operating system are targeted by criminal hackers.

NSA's arsenal of Windows hacking tools has leaked

The NSA and other intelligence agencies are also targeting computers around the world.  The NSA used Windows hacking tools to target several banks.

A new trove of alleged surveillance tools and exploits from the National Security Agency's elite hacking team have been released by the Shadow Brokers' hacking group.

The group Friday appeared to release tools designed to target Windows PCs and servers, along with presentations and files purporting to detail the agency's methods of carrying out clandestine surveillance.

https://www.zdnet.com/article/shadow-brokers-latest-file-drop-shows-nsa-targeted-windows-pcs-banks/

In a first, Israel responds to Hamas hackers with an air strike

Three years ago,  NATO proclaimed "cyber" as a target in the modern era creating a new battlefield.  Israel has now been the first to use military force to strike against a foe for using cyber warfare.  Hamas had been engaging in attacks on Israel's cyberspace.  In response, Israel launched an airstrike against as building in the Gaza strip housing Hamas cyber operatives.

"After dealing with the cyber dimension, the Air Force dealt with it in the physical dimension," said IDF spokesperson, Brig. Gen. Ronen Manlis. "At this point in time, Hamas has no cyber operational capabilities."

You don't want to miss this; read more at;

https://www.zdnet.com/article/in-a-first-israel-responds-to-hamas-hackers-with-an-air-strike/

If you are still running Windows XP and Windows 7, look to upgrade today to a new computer.

New DForce Intel 8th and 9th Generations Workstations.



Say it's not so! Windows 12 is coming in 2024. Apple iPhone malware/exploits.

Windows 12 is coming soon in 2024 I've read too many emails and articles hinting at a new Windows in the months leading up to 2024 and n...