Showing posts with label cyber-security. Show all posts
Showing posts with label cyber-security. Show all posts

Tuesday, September 15, 2020

Apple Product reveal day is today, Windows Server severe bug patch, Emotet and Hackers on the rise.

 It's a big day in Tech world with the annual Apple new Device release event set for today.  Expect emphasis on new Apple watch 6 and iPad Air to take center stage.  But first let's deal with a huge security issue.

"Unbeknownst to many, last month Microsoft patched one of the most severe bugs ever reported to the company, an issue that could be abused to easily take over Windows Servers running as domain controllers in enterprise networks."

 If your organization runs Windows server there is an update that is imperative your IT support techs apply to your servers.  A flaw in the Netlogon authentication process allows an attacker to exploit the cryptographic algorithm used to verify identity of a computer on a domain network.

The update has been available since Patch Tuesday of August 2020, it is known as CVD-2020-1472 and if your server is behind in updates then you are vulnerable.  The flaw has received a severity rating of 10, the details are only coming out now more than a month after the update was released because the vulnerability was too dangerous to make public.

"But in a blog post today, the team at Secura B.V., a Dutch security firm, has finally lifted the veil from this mysterious bug and published a technical report describing CVE-2020-1472 in greater depth.

And per the report, the bug is truly worthy of its 10/10 CVSSv3 severity score."

For more info, please follow this link.

https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/?ftag=TREc64629f&bhid=2219791&mid=13047656&cid=716603217

Apple Event.  Because of Covid-19, the 2020 Apple event will be held virtually at 10 a.m. PDT from Apple Park.  

You can add the event to your calendar and obtain a link to the event by going to;

https://www.apple.com/apple-events/

For insight into the new products and features, please visit the links below.

https://9to5mac.com/2020/09/14/apple-september-event-what-to-expect/

https://9to5mac.com/2020/09/14/heres-how-apples-fall-2020-ipad-ipad-air-and-iphone-12-features-will-compare/


COVID cybercrime: 10 disturbing statistics to keep you awake tonight

Not everyone has been sidelined by the Corona virus.  Hackers are out in force trying to steal your info/credentials and ultimately, finances.  9 out of 10 coronavirus related domains are scams and a half a million Zoom accounts have been compromised and are available on the Dark Web.

With so many new remote workers there has been a huge increase in desktop connections using RDP (remote desktop protocol) which has created a huge number of new targets for the bad guys.  The speed at which all these new connections have been created has led to mistakes in implementation and many remote devices are not secured.  This has led to a 400% increase in brute-force attacks.

In addition email scams related to Covid-19 were up 667% in March, 2020 alone.

The following is amazing to me but with so many people getting their news from social media, I guess I shouldn't be surprised;

In a test performed in late March, researchers found that users are three times more likely to click on a phishing link and then enter their credentials than they were pre-COVID. Of course, it doesn't hurt that those phishing emails often used words like "COVID" or "coronavirus, "masks", "test", "quarantine" and "vaccine."

Be careful;  for more details follow the link  below,

https://www.zdnet.com/article/ten-disturbing-coronavirus-related-cybercrime-statistics-to-keep-you-awake-tonight/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379&mid=13046731&cid=1862926557







Monday, April 29, 2019

Implantable Medical Devices - keeping them safe from Hackers, also Facebook will be taken over by the Dead in 50 years!

The future of cybersecurity: Your body as a hacker-proof network

Could a 'body area network' be the key to keeping medical devices safe or transferring data between individuals?

Modern medicine is making use of the internet with more devices having internet connectivity.  Insulin pumps, pacemakers, and more implantable devices are being fitted with wireless internet connectivity that allows doctors to monitor your health remotely.

The issue with being connected to the internet is that the devices can be hacked.  Already proof of concept attacks has illustrated the risk exists.  Fortunately, there have been no attacks so far but cybercriminals have demonstrated a lack of morality and tampering with these devices will no doubt happen.  In the past, they have extorted hospitals putting patients at risk.

The wireless technology used to share data can be read many feet away.  Recently implantable defibrillators were given a severity rating of 9.3 out of 10 for a flaw that allowed them to be hacked 20 feet away by the Department of Homeland security.

Scary stuff but new research using the human body as the signal carrier restricts the signal to a few centimeters outside the patient.  Researchers at Purdue University have created Electro-Quasistatic Human Body Communication (EQS-HBC) which uses low-frequency, carrier-less broadband transmission.

To read the full article click on the link below.

https://www.zdnet.com/article/the-future-of-cyber-security-your-body-as-a-hacker-proof-network/?ftag=TRE49e8aa0&bhid=27630927001468733386426006914379

The dead will take over Facebook in the next 50 years
Analysis suggests that the deceased will soon outnumber the living on the network.

and I thought it was me the reason no one responded to my posts.  :-)

A time is coming in which you may see more memorial accounts on Facebook than active users, with academics estimating that accounts belonging to the deceased will outnumber the living within 50 years.

https://www.zdnet.com/article/the-dead-will-take-over-facebook-in-the-next-50-years/?ftag=TRE-03-10aaa6b&bhid=2219791


TEST