There are always evolving threats to your online security. Whether a phishing email, an email with a malware attachment/download or a compromised website, chances are you will experience at least one attempt each day. Security software, firewalls, and antivirus software can provide a high degree of protection but it is no guarantee that your credentials will not be compromised. You must be vigilant of phishing attempts and compromised websites.
A lot of attempts to steal your info is to spoof the email of someone you know to gain your confidence. It may include an attachment that when clicked on takes you to a filesharing site, DropBox, Microsoft Sharepoint or OneDrive and ask you to log in. It is easy to steal the source code of a website and mimic that site on a malicious web page. Once you log in, BAM, they have your info which they will use to compromise your authentic email or access your online account.
Another ploy I have seen recently are emails that include a compromised password that is a real password that the user has or still uses. The email states that they have private info about you that will be revealed publicly unless you pay a ransom to a Bitcoin wallet. These wallets are very real and untraceable, so do not fall for this extortion attempt.
I have been contacted by users wanting to know if these are real because the email contains a current or past used password. Again, they are only extortion attempts. The next question is how did they get the password. Below is a chart of information courtesy of "haveIbeenPawned.com". Your identity and information are all over the web. It is at your bank, LinkedIn, MySpace, Facebook etc. This chart lists the largest data breaches thus far of user data at major corporations and websites. And remember, these are just the largest, not nearly all.
Beneath the chart is links that you can use to check to see if your email has been pawned and your information was included in any of the compromised sites.
I have included the "haveIbeenPawned" website in a past blog post. If you don't practice good password security yet and your email has been pawned please start today. No one to blame but yourself.
https://haveibeenpwned.com/
https://www.lifelock.com/breach-detection?promocode=BreachEraser&nc=breachnortoneraser
Microsoft, Linux developers, and Apple are constantly releasing updates and patches to their operating systems to fix known and new exploits as they are found. If you are using Windows XP then you have not received a security update since April 8, 2014.
Web browsers are evolving and getting better at warning the user that a website is not safe. Google Chrome is good at warning you that a website is not safe and Mozilla Firefox will soon start alerting you to a breached site. These browser updates don't necessarily happen automatically. You should check if an update is available periodically and if so, install it.
If you are using Windows XP then you are using a way out of date, non-secure browser to navigate the internet. I would not advise using an XP machine for financial transactions.
Support for Windows 7 extended support ends January 14, 2020. Many software vendors will end support before that.
It isn't only the operating systems but recently flaws in Intel Processors have been exploited.
https://www.forbes.com/sites/davealtavilla/2018/01/03/intel-processor-bug-leaves-all-current-chips-vulnerable-and-its-fix-saps-performance/#74f5a918570a
One last thing, it's all software that you use whether Adobe Acrobat/Flash Player, Java, MS Office, or browsers. Hackers use exploits in all of these to gain access to your computer and info. It is imperative that you patch and update your systems to remain secure.
NEW INTEL GENERATION 8 & 9 based WORKSTATIONS
Showing posts with label Meltdown. Show all posts
Showing posts with label Meltdown. Show all posts
Thursday, November 15, 2018
Friday, January 5, 2018
Two new Security Vulnerabilities affect every Computer and Phone manufactured since 1995.
Two new vulnerabilities, "Meltdown" and "Spectre" can let an attacker access whatever data is in an affected devices memory. Meltdown can access sensitive data and files by melting down security boundaries typically enforced by the hardware. The Spectre exploit tricks apps into leaking secrets.
Though there has been no known exploits at this time you can believe that the bad guys are already looking at ways to exploit these new flaws. There are many innocent websites that have been unwittingly compromised with malicious code that is downloaded and executed when that page is visited.
An example of a worst-case scenario is a low-privileged user on a vulnerable computer could run JavaScript code on an ordinary-looking web page, which could then gain access to the contents of protected memory.
http://www.zdnet.com/article/security-flaws-affect-every-intel-chip-since-1995-arm-processors-vulnerable/?loc=newsletter_large_thumb_featured&ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379
The vulnerabilities were discovered by Google's Project Zero team.
Last year, Google’s Project Zero team discovered serious security flaws caused by “speculative execution,” a technique used by most modern processors (CPUs) to optimize performance.
The Project Zero researcher, Jann Horn, demonstrated that malicious actors could take advantage of speculative execution to read system memory that should have been inaccessible. For example, an unauthorized party may read sensitive information in the system’s memory such as passwords, encryption keys, or sensitive information open in applications. Testing also showed that an attack running on one virtual machine was able to access the physical memory of the host machine, and through that, gain read-access to the memory of a different virtual machine on the same host.
These vulnerabilities affect many CPUs, including those from AMD, ARM, and Intel, as well as the devices and operating systems running on them.
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html
Meltdown and Spectre: Here’s what Intel, Apple, Microsoft, others are doing about it
https://arstechnica.com/gadgets/2018/01/meltdown-and-spectre-heres-what-intel-apple-microsoft-others-are-doing-about-it/
http://www.eweek.com/security/microsoft-delivers-emergency-windows-10-patch-for-meltdown-cpu-bug
Apple responds to Intel, ARM chip flaws: All Macs and iOS devices are vulnerable, but don’t panic
http://bgr.com/2018/01/05/apple-security-chip-flaws-iphone-ipad-all-macs/
Microsoft issues patch for Meltdown and Spectre Vulnerabilities
Microsoft has issued an emergency patch for Windows 10 users already. It can be downloaded and installed directly from the following link;
https://support.microsoft.com/en-us/help/4056892/windows-10-update-kb4056892
Some AVs may block you from installing the patch. If you are having difficulty check the following article.
Windows Meltdown-Spectre fix: How to check if your AV is blocking Microsoft patch
Antivirus firms play patch catch-up, as Microsoft releases Meltdown firmware updates for Surface devices.
http://www.zdnet.com/article/windows-meltdown-spectre-fix-how-to-check-if-your-av-is-blocking-microsoft-patch/?loc=newsletter_large_thumb_featured&ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379
Subscribe to:
Posts (Atom)
-
Acer C7 Chromebook from Google Play, $199 What can you get for $199? Dual-core Intel Celeron Processor 2 GB DDR3 RAM 320 GB hard d...
-
Microsoft's Patch Tuesday to end beginning with Windows 10. This change goes for both security updates and non-security updates. htt...
-
The term Pig Butchering refers to the victims of scammers. The scammers nurture relationships with their targets before luring them in for t...
