Wednesday, June 17, 2020

Windows Update; Should I stay or should I Go.

Windows 10 Update 2004:  when to update.

Tuesday of this past week, 06/09/2020 was the second Tuesday of the month aka in the Microsoft realm as Patch Tuesday.  This update included patches for 129 vulnerabilities.  It was the largest Patch Tuesday ever.

Should you update?  As of June 9th, none of the bugs had been exploited in the "wild", only in lab testing.  However, malware writers are known to dissect Microsoft's monthly updates to select, find and exploit vulnerabilities that are most useful and profitable for them.

So yes it is a good idea to update your machines to keep them safe from the bad guys...  see link below for details about this update.



So, should you update to Windows 10 2004?

The latest version available is Windows 10 2004.  It has been delayed for 6 months due to extensive testing by Microsoft to attempt to avoid issues caused by the update.  In the Microsoft Universe, there are millions of combinations/permutations of hardware and software.  That's due to the ubiquitous installed base of Windows computers.

Also, manufacturers are always bringing new devices to the table and in many cases refuse to continue to write drivers or provide support for older devices.

After awhile even Microsoft can no longer support 10 year old processors and computers.  This is true in the Apple World as well.  I can't upgrade my old MAC to the latest version of Mac OS.  They stopped supporting it in 2014 with the Yosemite release, 10.10.

Thus far with Windows 10 Ver. 2004 there have been issues resulting in printer bugs, that stopped all print jobs on some printers.  


The out-of-band update should fix Ricoh, Canon, Panasonic, and Brother printers that Windows 10 admins reported stopped working after installing the security update. 

I have read about USB ports disappearing and reappearing, BlueTooth devices not working and now there seems to be issues with Chrome and Edge browsers.


In conclusion, I would recommend delaying the upgrade to Windows Ver. 2004 until next month's Patch Tuesday, July 14th, 2020.

You can delay updates for up to 35 days by going to Settings, (left click Start Button, and click on Gear Icon), Updates and Security, 


then select Advanced Options and look for Pause Updates



In the meanwhile stay tune to this blog and I will keep you updated as to when it is safe to go back in the water.

This is my current situation;




How to determine your Windows version

When Microsoft introduces a major feature release they use the last 2 digits of the year and 2 digits of the month to define the version, so version 1803 was March 2018 and the latest is April 2020.  This is known as the Version Number.  There is also the Build Number that more precisely defines updates and hotfixes that have been applied since you last upgraded the the latest Version.

You can find this information by using the WINVER command;

  • To open Run Command in Windows 10 use the shortcut key Win key+R
  • Type the keyword “ winver ” and click OK.
  • a Window with your Info will open.



Below is a link to a good article about Window versions and builds.




DForce Intel based Workstations

If you are running old equipment or an out of date OS, operating system, you could be putting your business and information at risk.  

Starting with the Intel 8th generation of processors, performance took a quantum leap forward, Core i3 processor cores increased from 2 to 4, Core i5 from 4 to 6 single thread cores and the Core i7 6 hyper threading cores.  In addition, SSDs are included in all DForce workstations.  Intel launched 9th generation Coffee Lake Refresh CPUs with up to eight cores.

Get up to speed today and safeguard your business and information.






Tuesday, March 24, 2020

Working from Home (WFH) - Remote Options to help you and your Business survive the Corona Crisis

I previously sent out an email to my client list with options for accessing their work computers remotely.  RemotePC still has a limited time offer of $6.95 for 10 computers for the first year available.  After deploying and using it for the past 2 weeks, I must say it works well and who can beat that price.

What about conducting business that requires face to face meetings?  Yesterday I set up a client with webcam and we deployed Zoom.  I had used Zoom in the past to attend online meetings schedule by Vendors and Microsoft training but had never used it to schedule a meeting.  I must say it is fairly easy to use.  You can either start a face to face meeting or schedule future meetings.  The best part of signing up for an account with Zoom is its Basic Plan is free.  There are limitations but you can conduct unlimited 1 to 1 meetings.



Here is a link to all Zoom plans.


A microphone and camera are necessary if you wish to have video along with voice-enabled meetings.  You can mute the audio and turn off the video if you wish.  Almost all notebook and portables have this capability built-in.  If you wish to use your desktop good luck finding a webcam.  Most webcams have a microphone built-in, however, due to the rush to work remotely, almost all stores are completely sold out.

Don't despair, I have links below that tell you how to use your iPhone or Android phone as your webcam.


iPhone as a webcam


Android as a webcam




Remote Access software for Working From Home.

Paid remote access:

In the advent of a virus related shutdown or other impediments to workplace access, you should have some preparedness plan in place.  Some of my clients already have remote access via LogMeIn or GoToMyPC.  These are just 2 of the possible ways you could access your workplace computer remotely.  However, some do not have enough licenses for all their workstations.  LogMeIn offers a 2 week Free Trial without a credit card.  be sure to use an email address that has not been previously used for a trial.  After the trial, LogMeIn and GoToMyPC are not cheap.

There is a new alternative, REmotePC by iDrive.  It has received a PCMag rating of Excellent.  Currently, they offer a 30-day free trial (No credit card required) and for a limited time, they have a 10 computer license for $6.95/first year.



Free remote (limited access) alternatives.

TeamViewer offers free access for personal use.  Google Remote Desktop is another free program, however, in the case of most free access software, you have to be given a code for the computer you want to access.  This limits unlimited access,  with TeamViewer you can install the software and record the access code before leaving, but if the computer restarts it will generate a new code that will prevent you from logging in again.  Google RemoteDesktop requires the user at the machine you wish to access to generate a code which the user will then provide you.



I will be writing in detail over the weekend in the Driving Force Blog.  Look for our email Monday.

Have a safe and healthy weekend.






Wednesday, February 19, 2020

Google Chrome Play Store Malware, Phishing and now Smishing, IDF Soldiers tricked and more Security News

Google Chrome Extensions.  500 plus extensions spreading dangerous Malware!

I like a lot of users have been using Google's Chrome browser in lieu of other browsers for the past few years.  It was faster and promised to be more secure.  That is not the case any longer.  Hackers have now infiltrated Google's Play Store with more than 116 new malicious apps offered for download.  More than 500 extensions containing malware have been discovered around the world.

Read more and how to check and remove offending extensions at;

https://www.komando.com/security-privacy/chrome-extensions-spread-malware/707273/


Israeli soldiers tricked into installing malware by Hamas agents posing as women

"Members of the Hamas Palestinian militant group have posed as young teenage girls to lure Israeli soldiers into installing malware-infected apps on their phones, a spokesperson for the Israeli Defence Force (IDF) said today."

https://www.zdnet.com/article/israeli-military-tricked-into-installing-malware-by-hamas-agents-posing-as-women/


Microsoft detects and tracks a daily average of around 77,000 active web shells, spread across 46,000 infected servers.

Email users receive numerous emails on a daily basis purporting to be voicemails, faxes or files.  The emails look to be from legit users or maybe from someone they know, either someone the hacker is spoofing or a compromised user.  Often times these emails allude to an invoice or payment, anything to entice the user to open or click on the link or attachment.  Many of these emails are simply tricks to fool the target into giving up their Microsoft Office, Social App or financial credentials.  These are easier to prevent from falling victim to, simply do not give up your credentials without verifying the legitimacy of the email's source.  Of more concern are emails that link to compromised servers hosting websites that are infected with web shells.

Microsoft has released info that it detects and tracks a daily average of 46,000 infected servers.  On these servers, they find 77,000 active web shells.

If you follow a link that lands you on an infected server/website. hackers use web shells to upload other hacking tools on a victim's systems, tools that are later used for reconnaissance operations and lateral movement across a victim's internal network, making simple web server hacks into much bigger security incidents.

If you aren't sure about an email, do not open.

To read more about this serious threat click on the following link;

https://www.zdnet.com/article/microsoft-says-it-detects-77000-active-web-shells-on-a-daily-average/?ftag=TRE49e8aa0&bhid=27630927001468733386426006914379


Phishing scams are costing us more than ever. This trick is most likely to catch you out.
Scammers are still getting big payouts from business email compromise attacks - but almost two-thirds of attacks involve a much simpler scheme.

Businesses are losing over $700m a month to cybercriminals because employees are falling victim to phishing attacks, business email compromise campaigns, and gift card scams – and the amount of money being lost is still on the rise.
Large wire transfers make a significant percentage of the successful attacks

https://www.zdnet.com/article/phishing-scams-are-costing-us-more-than-ever-this-trick-is-most-likely-to-catch-you-out/

This latest phishing scam is spreading fake invoices loaded with malware

Prolific malware turned botnet shows no signs of slowing down as campaigns are launched against financial institutions in the US and UK.

Emotet started life as a banking trojan but has also evolved into a botnet, with its criminal operators leasing out its capabilities to those who want to distribute their own malware to compromise machines.

https://www.zdnet.com/article/this-latest-phishing-scam-is-spreading-fake-invoices-loaded-with-malware/


Scammy, spammy texts have come to your phone. Here's how to avoid getting ripped off by scam artists who've added social engineering to their toolbox.

The computer is not the only device under attack by hackers and con men.  Nowadays, more users are conducting financial transactions using their mobile devices, smartphones.  With the advent of the mobile wallet and financial apps, the bad guys are targeting mobile users with SMS messages or what is called "Smishing" coined from the similar email Phishing term.

For more information and ways to protect yourself, click on the following link;

https://www.howtogeek.com/526115/what-is-smishing-and-how-do-you-protect-yourself/


Mac malware threats are now outpacing attacks on Windows PCs

https://www.zdnet.com/article/mac-malware-is-growing-fast-but-its-still-not-as-dangerous-as-the-attacks-on-windows/

Wednesday, February 12, 2020

Security Updates: Last night was Update Tuesday, Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

The second Tuesday of each month has become known as Patch Tuesday.  Microsoft released yesterday the February 2020 Patch Tuesday security updates. This month's updates include fixes for a whopping 99 vulnerabilities, making this Microsoft's biggest Patch Tuesday known to date.

With the possible combination and variety of installed programs not to mention a myriad of hardware configurations, issues are always a possibility.  Many users postpone updates, however, if possible install updates when available.  The internet is criminal infested and users and their info are under constant assault whether by Google, Alphabet, Facebook, and others gathering information discretely about you or criminals trying to steal your financial information.  There are many legit firms who collect your information and sell it to marketers and then they are hacked and your info is stolen along with millions of others.

On January 17, Microsoft disclosed ongoing attacks where hackers were using this IE zero-day, however, at the time, the OS maker could not provide a patch. This patch is now included with this month's cumulative security updates.

Read about this important update the following link;

https://www.zdnet.com/article/microsofts-february-2020-patch-tuesday-fixes-99-security-bugs/?ftag=TREc64629f&bhid=2219791


TEST