Friday, May 28, 2021

SolarWinds hackers are at it again, targeting 150 organizations, Microsoft warns

SolarWinds hackers are at it again, targeting 150 organizations, Microsoft warns

Microsoft has reported that the same group responsible for the SolarWinds attack "Nobellum" are at it again, this time distributing intrusion software via email purporting to be from USAID, US Aid organization.

This time they have compromised email systems linked to the State Department’s International aid agency to send spear phishing emails targeting agencies and individuals who have been identified as anti-Putin.  It is using a message purporting to be from former President Trump with a bait link about election fraud.

If clicked the link delivers malicious files to compromise your system.  

It is reported that the targets are agencies and individuals who are anti-Putin.  The email has a headline that proclaims, (see picture below, courtesy NY Times);

The hackers are linked to Russia's main intelligence agency and the emails are being sent via the email system used by the State Department's international aid agency.

Hackers linked to Russia’s main intelligence agency surreptitiously seized an email system used by the State Department’s international aid agency to burrow into the computer networks of human rights groups and other organizations of the sort that have been critical of President Vladimir V. Putin, Microsoft Corporation disclosed on Thursday.

To read more please visit the links below;

https://www.nytimes.com/2021/05/28/us/politics/russia-hack-usaid.html

https://www.nbcnews.com/tech/security/solarwinds-hackers-are-it-again-targeting-150-organizations-microsoft-warns-n1268893


If you don't have protection, please consider doing something,

https://www.malwarebytes.com/pricing/















Tuesday, May 18, 2021

Ransomware Attacks. Take advantage of all layers of protections afforded you.

Turn on anti-ransomware feature in Windows 10.

In light of the most recent high profile ransomware attack on the Colonial pipeline, what can you do to protect your organization from falling victim to a ransomware attack?

According to Firewall manufacturer SonicWall, Ransomware threats increased a massive 62 percent in 2020 compared to 2019 and it is showing no sign of slowing down.  How many attacks?... over 304 million ransomware attacks in 2020 with the average payout over $220,000.

Of course, those are mainly businesses forking over that kind of money to attackers who are holding their data hostage. Small businesses in particular are disproportionately targeted, but facilitators of ransomware do also go after individuals.

One may think that if they can hack through the protection manned by large corporations what can I do?  The large corporations have deep pockets that make them lucrative targets.  However as stated above, individuals are targeted as well.

Windows 10 as well as most Security software firms have protections that provide extra layers of security but you must enable or properly configure them to work effectively.

You should routinely back up any important data, and as always, following smart computing habits (like not clicking on links in unsolicited emails) to tip the odds in your favor.

Read about steps you can take below if you are running Windows 10 and if you own Kaspersky security software.

Monday, April 12, 2021

Criminals spread malware using website contact forms with Google URLs

 Criminals spread malware using website contact forms with Google URLs

Crooks are using social engineering to exploit workers' efforts to do their jobs.

If you are using a contact form on your company website please be aware that criminals are now using website contact forms to spread an info-stealing Trojan called IcedID.  The ploy the crooks are using is to include legitimate Google URLs, and then requiring users to supply their Google username and password.

IcedID is a banking trojan and information stealer and can be used as an entry point for subsequent attacks, such as manually operated ransomware for high-value targets. Human-operated ransomware attacks are increasingly common and require the attacker to sit at the keyboard and orchestrate the attack, in contrast to an automated attack.

In recent weeks, one of my clients experienced a rise in spam and phishing emails from their WordPress based website.  They implemented a CAPTCHA challenge to thwart the phishing and scam emails, however this new threat has the ability to bypass the CAPTCHA protection.

Microsoft considered the threat serious enough to report the attacks to Google's security teams to warn them that cyber criminals are using legitimate Google URLs to deliver malware. The Google URLs are useful to the attackers because they will bypass email security filters. The attackers appear to have also bypassed CAPTCHA challenges that are used to test whether the contact submission is from a human. 

The crooks are using social engineering to exploit workers' efforts to do their jobs, using language that applies pressure on the employee to respond.

One trick used is to falsely claim that the website is using copyrighted images.  We have already experienced this at one client.

This is an old ploy however with a new twist.  The email contains a link to a sites.google.com page.  If the link is followed a ZIP file containing a JavaScript file will automatically download and it in turn downloads the IcedID malware as a .DAT file.  A remote control component Cobalt Strike is installed as well which allows the attacker to control the device over the internet.


To read the full article at ZDNet click on the following link;

Criminals spread malware using website contact forms with Google URLs | ZDNet







Tuesday, April 6, 2021

Facebook Data Breach exposes 533 million users data on Dark Web, Elon Musk's StarLink satellite internet coming soon to an area near you.

Facebook data on 533 million users posted online

Data of 533 million Facebook users including phone numbers, Facebook IDs, full names, birth dates and other information have been posted online.

Of the 533 million users whose data was leaked, 32.3 million US users and 11.5 million in the UK are affected.

The data was posted on a Dark Web site for free.  User information posted included; 

"The information that was exposed includes profile information, Facebook identification numbers, emails, location data and more, according to a report in The Record, which is published by cyber-threat intelligence firm Recorded Future."

Facebook has reported that the information collected was done in 2019 and they have since found and patched the issue.  However as reported on ZDNet news, how many users have changed their associated email and phone numbers since 2019?... not many.  Fortunately, SSNs are not required on Facebook and credit card info is hopefully outdated by now.

This "regurgitation" of an old, massive hack shows how vulnerable data can be once it's stolen.

On the Dark Web there is a massive market for buying and selling personal information  You can expect this data to be used in future phishing and hack attacks.

For more info read;

https://www.zdnet.com/article/facebook-data-on-533-million-users-posted-online/?ftag=TRE-03-10aaa6b&bhid=2219791&mid=13323985&cid=716603217

https://www.thestreet.com/latest-news/facebook-data-for-half-billion-users-emerge-on-dark-web

How to Check if Your Phone Number Is in the Huge Facebook Data Leak

https://gizmodo.com/how-to-check-if-your-phone-number-is-in-the-huge-facebo-1846617849

Starlink - Internet alternative

The Starlink satellite communications network moves closer to being a viable alternative as an internet provider replacement with each launch of SpaceX.  On each SpaceX mission, up to 60 satellites are being launched.  Starlink currently has 1321 in orbit with 12,000 more already approved and 30,000 more licenses applied for but not yet approved.

Elon Musk is accomplishing his goal at a cost much less than conventional satellites and Starlink's satellites are located in an orbit 60 times closer than conventional satellites.

I have signed up for the service which is expected to be available in mid to late 2021.  It costs an initial $99.00 and will be available on a first come, first serve basis.

When signing up I had to find my location Plus Code which was something new to me.  Plus Codes are based on latitude and longitude, and displayed as numbers and letters. With a Plus Code, people can receive deliveries, access emergency and social services, or just help other people find them.  I have included a link to find your plus code below.

To read more;

With Starlink, Elon Musk Is Once Again Showing How To Make Economies Of Scale Work (forbes.com)

https://www.upi.com/News_Photos/view/upi/9561217701bca2fdc4eb07d2bceca2f6/SpaceX-Launches-Starlink-Satellites-From-the-Cape-Canaveral-Space-Force-Station-Florida/

https://maps.google.com/pluscodes/

Starlink

Shameful Plug DForce Intel based Workstations

SSD equipped, Generation 9, 10 and 11

PDF - View or Download









Monday, March 8, 2021

Microsoft Exchange zero-day attacks: 30,000 servers hit already, says report

Some clients have reported an increase of junk/spam emails in the last week.  If your organization still uses an onsite Exchange server then you need to be aware that it needs to be patched now or taken offline.

the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has issued an order to agencies to apply the patches for on-premise Exchange systems or to simply disconnect vulnerable servers after seeing "active exploitation" of the vulnerabilities. In other words, patch now or cut off a vital communications tool. 

So far 4 previously unknown vulnerabilities are being used in attacks against thousands of companies, perhaps tens of thousands organizations.

Microsoft released patches for a critical flaw last year and warned Exchange users to update their servers but said that months later tens of thousands of server remain unpatched despite attacks from nation-state hackers.

This latest attack is being carried out by a previously unknown group called Hafnium who the Department of Homeland Security's (CISA) Cybersecurity and Infrastructure Agency thinks is based in China.

The Hafnium hackers have accelerated attacks on vulnerable Exchange servers since Microsoft released the patches.

CISA's former directory thinks government agencies and small businesses will be more affected by these attacks than large enterprise. 

To read the full article please click on the following link;

https://www.zdnet.com/article/microsoft-exchange-zero-day-attacks-30000-servers-hit-already-says-report/?ftag=TRE-03-10aaa6b&bhid=2219791&mid=13291744&cid=716603217


If you haven't already seen an increase in spam activity, expect to and be careful that you don't open up your systems to an attack.  The following article details the most common ploys used to distribute malware and attacks.

Phishing: These are the most common techniques used to attack your PC

Microsoft Office macros, PowerShell and more are still proving to be popular with cyber criminals distributing attacks via phishing emails, warn researchers after analysing billions of attacks.

https://www.zdnet.com/article/phishing-these-are-the-most-common-techniques-used-to-attack-your-pc/

and it's not just  PCs being attacked.

30,000 Macs infected with new Silver Sparrow malware

Silver Sparrow can even run on systems with Apple's new M1 chip.

"According to data provided by Malwarebytes, Silver Sparrow had infected 29,139 macOS endpoints across 153 countries as of February 17, including high volumes of detection in the United States, the United Kingdom, Canada, France, and Germany," 

https://www.zdnet.com/article/30000-macs-infected-with-new-silver-sparrow-malware/


Wednesday, October 14, 2020

Microsoft October 2020 Patch Tuesday, Alexa IT Headache and new iPhones.

Microsoft October 2020 Patch Tuesday fixes 87 vulnerabilities

Fixes for 21 remote code execution (RCE) vulnerabilities included for products like Excel, Outlook, the Windows Graphics component, and the Windows TCP/IP stack.

Microsoft has released today its monthly batch of security updates known as Patch Tuesday, and this month the OS maker has patched 87 vulnerabilities across a wide range of Microsoft products.

 It's a monthly thing, sometimes no gain, only pain but with much of the U.S. and the world working remotely it is now more important to apply your OS updates than ever.  Hackers are concentrating their efforts on the RDP protocols.

https://www.zdnet.com/article/microsoft-october-2020-patch-tuesday-fixes-87-vulnerabilities/?ftag=TRE-03-10aaa6b&bhid=2219791&mid=13109479&cid=716603217


Amazon's Alexa is driving IT managers crazy

"The danger is that these devices aren't typically secured by design," Grimm told me. "They can basically be like an open door or window to the network that an attacker uses as a means to get on the network and look for more valuable resources -- intellectual property, personal information, and more."

https://www.zdnet.com/article/amazons-alexa-is-driving-it-managers-crazy/

See also: Amazon's Alexa gets a new brain on Echo |  Alexa, why should I upgrade my Echo?  | Which Echo to buy? How to pick the best Alexa device for your needs | Why Amazon needs to stop selling us new Echos


Apple just announced the iPhone 12 lineup, and it's packed full of features and new capabilities, at a range of price points.

I've been telling Verizon and AT&T clients for over a year now, just because your phone displays 5G in he upper right corner, if you don't have a 5G phone you are operating at 4G.  Well 5G iPhones are finally here.

All four iPhone 12 models are capable of connecting to 5G networks. In the US, that means they include Sub6 and mmWave compatibility. The phones will have a Smart Data Mode that will decide whether or not a 5G connection is required for a task, and when it's not, it will use a 4G LTE connection instead. Doing so will save battery life. 

New iPhone models and dates of availability:

iPhone 12 Mini: Nov. 6 preorders, Nov 13 availability

iPhone 12: Oct 16 preorders, Oct. 23 availability 

iPhone 12 Pro: Oct. 16 preorders, Oct. 23 availability 

iPhone 12 Pro Max: Nov. 6 preorders, Nov 13 availability

https://www.zdnet.com/article/iphone-12-all-the-models-launch-date-pricing-and-specs/


This article (link) has me thinking about keeping my iPhone 7 a little longer.

iPhone 12 has 5G, but Apple still has us questioning why we need it

For now, the biggest reason to buy a 5G phone is FOMO -- and future-proofing.

https://www.cnet.com/news/iphone-12-has-5g-but-apple-still-has-us-questinoing-why-we-need-it/













Thursday, October 1, 2020

Global Microsoft Outage, Apple Woes, Cybercrime, Nvidia RTX 30 series graphics cards.

Global Microsoft outage brings down Teams, Office 365 and Outlook

Microsoft says a recent update has affected the processing of authentication requests, making cloud-based services inaccessible.

Microsoft Blames Software ‘Code Issue’ For Office 365 Outage

“It’s amazing to me that a change in code could cause a platform as big as Azure to go down,” says a senior executive for one of Microsoft’s top partners, who did not want to be identified. “It sounds like someone wrote some code that was merged into a production environment and it broke authentication. That’s ridiculous. If you can’t get into email or documents for five hours it’s pretty bad.” CRN

The outage affected users between the hours of 5:25 pm EST to 10:25 pm EST.  I did not hear from a single user concerning any issues.  Fortunately for us the outage occurred after normal business hours and from what I read, users who had a session established were okay.  It was only those who tried to log in during that period of time who were affected.

Microsoft attributed the Azure service outage to a “recent configuration change impacted a backend storage layer, which caused latency to authentication requests.” CRN.

https://www.crn.com/news/cloud/microsoft-blames-software-code-issue-for-office-365-outage

https://www.theguardian.com/technology/2020/sep/29/major-microsoft-outage-brings-down-office-365-outlook-and-teams?ref=hvper.com

https://www.bing.com/news/search?q=Office+365+Outage&qpvt=office+365+outage&FORM=NWRFSH


Apple News

Who'd have thought... Apple makes mistakes too.  Read the link below, 

iOS 14.0.1: The battery and connectivity woes continue

iOS 14.0.1 fixes some things. Breaks other things.

The bottom line is that we're into that messy period at the beginning of an iOS launch where there will be a lot of bugs and fixes and new bugs. I suspect iOS 14.0.2 is not that far away, and that it won't be long until iOS 14.1 is released, likely to be the iOS version that ships on the new iPhones.

https://www.zdnet.com/article/ios-14-0-1-the-battery-and-connectivity-woes-continue/?ftag=TRE-03-10aaa6b&bhid=2219791&mid=13076371&cid=716603217

iPhone 12 64GB model incoming, says leaker, shipments start next week

A new report from serial Apple leaker Jon Prosser states the iPhone 12 will be getting a 64GB storage option, despite previous reports Apple was ditching the configuration.

https://www.imore.com/iphone-12-64gb-model-confirmed-shipments-start-next-week


Cyber Crime

Cyberattack hobbles major hospital chain's US facilities, staff forced to use paper records

https://www.foxbusiness.com/healthcare/cyberattack-hobbles-major-hospital-chains-us-facilities-staff-forced-to-use-paper-records

A computer outage at a major hospital chain thrust healthcare facilities across the U.S. into chaos Monday, with treatment impeded as doctors and nurses already burdened by the coronavirus pandemic were forced to rely on paper backup systems.

Universal Health Services Inc., which operates more than 250 hospitals and other clinical facilities in the U.S., blamed the outage on an unspecified IT “security issue” in a statement posted to its website Monday but provided no details about the incident, such as how many facilities were affected and whether patients had to be diverted to other hospitals.

Google removes 17 Android apps caught engaging in WAP billing fraud

The 17 apps were infected with the Joker (Bread) malware, which Google described in January 2020 as one of the most persistent threats it dealt with since 2017.

https://www.zdnet.com/article/google-removes-17-android-apps-doing-wap-billing-fraud-from-the-play-store/

The FBI's most wanted cybercriminals

https://www.zdnet.com/pictures/the-fbis-most-wanted-cyber-criminals/

NVIDIA GeForce RTX 30 Series Graphics Cards

Nvidia announced their new RTX 30 graphic cards on September 17th.  The GeForce RTX 3090 was released September 24th.  I was at the Marietta Micro Center store on the 23rd of September and saw this scene that I had to take a picture of;


I first thought it was the line to get in due to the Pandemic, (there usually is a line on weekends due to restrictions on the number of people allowed in at one time), but then I saw people going into the store bypassing the line.

Once inside I asked the lady what was going on, she replied "they are camping and waiting for the release of the Nvidia graphics card tomorrow."  WOW, not only are these people going to fork over $1500 for a video card but they can afford a whole day of their life devoted to this purpose, and they don't need to work, they have the money.  SMDH.

Read more about the new Nvidia cards and while at it, be sure to buy a DForce Gaming computer.

Thanks for reading!




DFORCE Gaming Rigs, Ultra-fast performance, Powerful and expandable!













Wednesday, September 16, 2020

A lot of Apple News from Yesterday, however still waiting on iPhone 12 and 5G. iPad Air 4 sounds great.

The Apple Watch and iPad launch event was typical Apple. Product upgrades that spur purchases, services to threaten multiple rivals and good price points across the portfolio.

The Apple event yesterday September 15th focused on the new Apple Watch 6, iPad Air and new service bundles including Apple TV, Apple Music and a new Fitness service to challenge Peloton's App.

Key fitness items include:

Blood oxygen measurements.

Background health metrics while you sleep.

Partnerships with academic institutions on studies.

Apple announced a new subscription model, Apple One that introduces various levels of service bundling which has already triggered responses from Spotify and other entertainment providers.

I have an Apple watch 3 and after reviewing details and what other reviewers are saying this a.m., I have no intention of upgrading my Apple Watch.  I'm waiting on the iPhone 12 with 5G.  

Yesterday's event was only a warm-up to spur sales prior to the iPhone 5G introduction which I'm sure will be available before Christmas.

I'm not going to lie though, I will purchase the new iPad Air 4 when available since I have kicked Comcast TV services out of my office and home.  I have a great IPTV service which runs on IOS.

Apple surprised iPhone users with a next-day iOS 14 release. App developers are pissed.

To read about all the product announcements from the Apple Event yesterday please click on the following link;

https://www.zdnet.com/article/everything-apple-announced-at-its-sept-15-event-apple-watch-series-6-se-apple-one-fitness-plus-and-ipad-ipad-air-lineup-updates/?ftag=TREc64629f&bhid=2219791&mid=13049704&cid=716603217








Tuesday, September 15, 2020

Apple Product reveal day is today, Windows Server severe bug patch, Emotet and Hackers on the rise.

 It's a big day in Tech world with the annual Apple new Device release event set for today.  Expect emphasis on new Apple watch 6 and iPad Air to take center stage.  But first let's deal with a huge security issue.

"Unbeknownst to many, last month Microsoft patched one of the most severe bugs ever reported to the company, an issue that could be abused to easily take over Windows Servers running as domain controllers in enterprise networks."

 If your organization runs Windows server there is an update that is imperative your IT support techs apply to your servers.  A flaw in the Netlogon authentication process allows an attacker to exploit the cryptographic algorithm used to verify identity of a computer on a domain network.

The update has been available since Patch Tuesday of August 2020, it is known as CVD-2020-1472 and if your server is behind in updates then you are vulnerable.  The flaw has received a severity rating of 10, the details are only coming out now more than a month after the update was released because the vulnerability was too dangerous to make public.

"But in a blog post today, the team at Secura B.V., a Dutch security firm, has finally lifted the veil from this mysterious bug and published a technical report describing CVE-2020-1472 in greater depth.

And per the report, the bug is truly worthy of its 10/10 CVSSv3 severity score."

For more info, please follow this link.

https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/?ftag=TREc64629f&bhid=2219791&mid=13047656&cid=716603217

Apple Event.  Because of Covid-19, the 2020 Apple event will be held virtually at 10 a.m. PDT from Apple Park.  

You can add the event to your calendar and obtain a link to the event by going to;

https://www.apple.com/apple-events/

For insight into the new products and features, please visit the links below.

https://9to5mac.com/2020/09/14/apple-september-event-what-to-expect/

https://9to5mac.com/2020/09/14/heres-how-apples-fall-2020-ipad-ipad-air-and-iphone-12-features-will-compare/


COVID cybercrime: 10 disturbing statistics to keep you awake tonight

Not everyone has been sidelined by the Corona virus.  Hackers are out in force trying to steal your info/credentials and ultimately, finances.  9 out of 10 coronavirus related domains are scams and a half a million Zoom accounts have been compromised and are available on the Dark Web.

With so many new remote workers there has been a huge increase in desktop connections using RDP (remote desktop protocol) which has created a huge number of new targets for the bad guys.  The speed at which all these new connections have been created has led to mistakes in implementation and many remote devices are not secured.  This has led to a 400% increase in brute-force attacks.

In addition email scams related to Covid-19 were up 667% in March, 2020 alone.

The following is amazing to me but with so many people getting their news from social media, I guess I shouldn't be surprised;

In a test performed in late March, researchers found that users are three times more likely to click on a phishing link and then enter their credentials than they were pre-COVID. Of course, it doesn't hurt that those phishing emails often used words like "COVID" or "coronavirus, "masks", "test", "quarantine" and "vaccine."

Be careful;  for more details follow the link  below,

https://www.zdnet.com/article/ten-disturbing-coronavirus-related-cybercrime-statistics-to-keep-you-awake-tonight/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379&mid=13046731&cid=1862926557







Tuesday, July 14, 2020

Watch out! Patch Tuesday is here, one day before Tax Day, 2020

Watch out!  Patch Tuesday is here, one day before Tax Day, 2020.

With a record number of people working from home hackers are busy trying to exploit weaknesses.  They have a narrowed target since they know who the remote access service providers are, the ports and protocols they use and the weaknesses of home routers.  See ZDNet links below


In the past 5 months Microsoft updates have contained an average of ninety fixes for CVEs, (common vulnerabilities and exposures (CVE)).  However, total updates are actually down from previous cycles with no new updates for Exchange and SQL products.

It is important to keep your systems updated so that security flaws are patched and your computer protected.  You can delay your updates for a default of 7 days to a maximum of 35 days if you wish but remember this can leave your system vulnerable to the latest attacks.

You need to be diligent about updating your system, Old vulnerabilities exist and new variants of ransomware are appearing one, example being Try2Cry.

If you are experiencing any particular issues as you roll out this new operating system you should check out the known issues page for the latest information. You may find a fix is already available or will soon be on the way.


To read more visit this link which is the source of much of this post.



July 2020 Patch Tuesday forecast

  • Expect to see a larger number of Microsoft updates this month. We are due for a new set of .NET updates and, as I mentioned above, we are overdue for a SQL server or Exchange server update.
  • Servicing stack updates (SSUs) and Extended Security Updates (ESUs) for Windows 7 and Server 2008/2008 R2 are expected in the group release as usual.
  • The Oracle Critical Product Update (CPU) aligns with patch Tuesday once again this quarter. Don’t forget your Java update and other OpenJDK-based products such as Amazon Correto, AdoptOpenJDK, and others which will follow close behind.
  • After the surprise Adobe Flash release last month, could we see another? Unlikely, but be on the lookout. The last major security update for Acrobat and Reader was in early May so look for a security release this week.
  • Apple released their security updates for iTunes and iCloud back in late May and have been releasing roughly every other month. We may not see a release on Tuesday but be on the lookout later this month.
  • Google released a security update for Chrome 84 this week.
  • Mozilla provided minor security updates this week for Firefox 78, and major updates for Firefox ESR 68 and Thunderbird 68 the last week of June. We may see a minor update for these applications next week.

TEST