Wednesday, August 23, 2017

Email and Browser Health. Windows security: Cryptocurrency miner malware is enslaving PCs with EternalBlue.

http://searchsecurity.techtarget.com/definition/email-spoofing


Lately I have been fielding a lot of questions about the legitimacy of emails.  Some of the emails were from users who wondered if their PC was infected by a virus or malware.  These turned out to be nothing more than their email was used to spoof a mass spam mailing.  It used to be spoofing was used because a spammer was sending millions of emails and was not concerned if their list had bad or extinct email addresses.  They simply did not want to be bothered by the returned emails.  They only hoped for at least a 1% positive bites out of the millions sent.

However, with the rise in Malware the trick is to try and appear to be from a legitimate source so that the recipients will click on the links contained within and download the malicious payload.

There has also been a wave of emails purporting to be from Microsoft Office 365 claiming that a deactivation request has been received or that your mailbox has reached the limit and action is required now to resolve this.  Microsoft does not send emails to individual subscriber mailboxes.  There are admin and alternate emails that Microsoft uses to control subscriptions.  Don't confirm your email to these hackers by attempting to use the links provided.  You will only provide them with your login credentials and possibly download some bad stuff on your PC.

Windows security:  Cryptocurrency miner malware is enslaving PCs with EternalBlue.

Stealthy and persistent cryptocurrency-mining malware is hitting Windows machines.

Now there is "fileless" malware that runs in memory, hijacking PCs to work at mining cryptocurrency.

Researchers at Trend Micro describe the malware known as CoinMiner as "extremely stealthy and persistent".

To infect Windows machine, it's using the so-called EternalBlue vulnerability employed by WannaCry and NotPetya as a spreading mechanism. Microsoft released a patch for the flaw in March but a spate of infections in Asia, mostly in Japan, suggest some systems have not been updated.

Please be sure to patch your machine and be vigilant about emails you open & links you click on.

Add-ins and Extensions.  Browser health.

It used to be that Chrome and Firefox provided safe alternatives to the contact attacks and ravages on Microsoft's Internet Explorer Browser.  That is no longer the case.  Google's Chrome has been the target of phony extensions designed to spread malicious ads.  These extensions are delivered more often than not by users who google a legit software but don't pay attention to the sites found by the search.  Be sure the download you seek is from the site of it's maker and not a 3rd party who will slip you unneeded toolbars, extensions and malware.

The main intent of the attack on Chrome extension developers is to divert Chrome users to affiliate programs and switch out legitimate ads with malicious ones, ultimately to generate money for the attacker through referrals

Windows support scams:  Microsoft taking down Fraud Kingpins



Monday, June 19, 2017

Largest ever Voter Records Leak, Windows 10 Creators Update.

Nearly 200 million US voter records leaked
Personal details of American voters were stored on an unsecured and exposed server.

Just in time for tomorrow's June 20th, 2017 special election in the 6th District of Georgia comes news of the largest leak every of voter records.  Personal data of 198 million voters which was stored on an unsecured Amazon server.

The information included personal information such as name, DOB, home address, phone number and voter registration information.

"The various databases containing 198 million records on American voters from all political parties were found stored on an open Amazon S3 storage server owned by a Republican data analytics firm, Deep Root Analytics."

What is an Amazon S3 storage server?  Another component of the Cloud, https://aws.amazon.com/s3/

To read the full story, please use the link below.

http://www.zdnet.com/article/security-lapse-exposes-198-million-united-states-voter-records/?loc=newsletter_large_thumb_related&ftag=TREc64629f&bhid=2219791

http://www.bbc.com/news/technology-40331215


Microsoft's Windows 10 Creators Update.

The journey of Windows as a Subscription continues, the latest iteration is Windows 10, Creators Update.  For a list of new features click HERE

If your computer is updating automatically, you may already have it installed, it is Version 1703.  To update or check your current version of Windows use the link below;

https://support.microsoft.com/en-us/instantanswers/d4efb316-79f0-1aa1-9ef3-dcada78f3fa0/get-the-windows-10-creators-update

www.drivingforce.net

Sunday, May 14, 2017

World’s biggest cyberattack hits 150 countries and the threat is ‘escalating’

If you have not heard of the latest Malware threat that first appeared this past Thursday, then please take heed now.  It's a malware type known as ransomeware and is called WannaCry.  Cybersecurity experts say the initial targets were Russia, Ukraine and Taiwan but hospitals in the U.K., universities in China and global firms like FedEx were also under attack.

The malware is spreading by taking advantage of a vulnerability in Windows.  Microsoft release a patch in March but computers and networks that have not updated are at risk.  Microsoft has even released patches for unsupported older operating systems  including Server 2003 and Windows XP.  Computer already infected will not be helped by patching.

The ransomware attempts to seize control of an infected computer, encrypt files and then demand a ransom be paid before releasing control of the computer.

Cyberattack’s Impact Could Worsen in ‘Second Wave’ of Ransomware


On Friday an estimated 74 countries had reported infected computers.  Today that number has grown to 200,000 known victims in at least 150 countries.  Authorities are fearful that the numbers could spike with the start of the workweek on Monday when employees return and start using computers were the malware already is in hiding.



To read more; visit the links below.



Thursday, May 4, 2017

Beware of Google Docs Phishing Attempt!

Heads up everyone.  There is a nasty email circulating that invites you to click on a Google Docs link.  It will appear to be from someone you know and is a phishing attempt that can open up a whole bunch of trouble for you if you click on the enclosed link.  Please don't do that, just delete the email.

The payload of the email is that the deception will give the keys to your GMail account to the bad guy who sent you the email.  Remember it was a phishing attempt that DNC head John Podesta fell for leading to his email correspondence being leaked.

"The counter-measures Google described are likely to stop the spread of the phishing attack but, as one security expert points out, the attacker has already had time to harvest millions of email addresses via victims' Gmail contact lists.

It seems such scams targeting Google accounts are becoming more common in recent months. As my colleague Robert Hackett reported in January in the article Everyone is falling for this frighteningly effective Gmail scam, hackers (usually posing as a trusted contact) have been sending around booby-trapped documents that look like ordinary PDFs."


To read more please see the links below on Fortune's website.

A Massive Google Docs Phish Might Have Stolen A Load Of Gmail Accounts - UPDATED

https://www.forbes.com/sites/thomasbrewster/2017/05/03/massive-google-gmail-phish-many-victims/#1bbaa89b42a1

http://fortune.com/2017/05/03/google-docs-scam/


What to do (from the first article link)

"For anyone who remains concerned, there are steps they can take. First, it's possible to note the phishing attempt by just looking at the message. It'll typically say something like: "Mr. Attacker has invited you to view the following document." And the recipient will be in the BCC field. That's the first clue something phishy is going on, added to the fact that the only other visible email address in the to field is hhhhhhhhhhhhhhhh@mailinator[.]com, a temporary account on Mailinator.

Then, go to https://myaccount.google.com/permissions and revoke any permissions given to an app called Google Docs. This should prevent any problems, just in case Google hasn't managed to get rid of the app already.

And in the future, if you're not expecting a Google Doc and a link looks suspicious, don't click through before validating with the sender that it's legitimate.

There is, sadly, one big problem for victims who clicked through: the attacker could have automated their scam (likely, given how they carried out the illicit operation) and hoovered up all their Gmail already. In this case, there's not much to be done other than hope nothing sensitive was stolen or that proactive measures are being taken against those who perpetrated the hack."

Monday, March 27, 2017

3 things you should do right now to protect your Apple iCloud account

3 things you should do right now to protect your Apple iCloud account.

This is a followup to my Friday post about hackers possessing passwords to 250 million Apple iCloud accounts.

Apple users really should heed the advice of the experts and pay attention to the threat to their data posed by the hacker group, "Turkish Crime Family".  The London based hacker group may or may not have access to 250 million Apple iCloud accounts but they have proven they have access to an indeterminate number of accounts.  That is more than reason enough to protect your account and data by changing your password today.

from ZDNet article, change your password!

Since Apple isn't doing this, it's up to you.


Apple talks as if your Apple ID and iCloud ID are different. They're not. They're the same, and they use the same password.

To change your Apple ID password, sign in to your Apple ID account page with any web browser and follow the instructions to reset your password. I changed mine using Google Chrome from a Mint Linux system.

http://www.zdnet.com/article/how-to-protect-your-apple-icloud-account/?loc=newsletter_small_thumb&ftag=TRE17cfd61&bhid=2219791

I know ignorance is bliss, especially for Apple users.


DFS - 7th Generation Intel based workstations.


Friday, March 24, 2017

Apple iCloud Ransom target date April 7, 2017, New iPad

Happy Friday Quickie Blog - a couple of Apple facts.


Apple iCloud ransom demands: The facts you need to know

If you have an iCloud account you should seriously consider changing your password in light of a new threat by a hacker group called the Turkish Crime Family.  The group claims to have access to 250 million iCloud accounts.

If Apple doesn't pay a ransom in Bitcoin by April 7 the hackers are threatening to reset the passwords of the accounts and remotely wipe iPhones.

Read all about this latest Apple Hack at:

http://www.zdnet.com/article/apple-icloud-ransom-what-you-need-to-know/?loc=newsletter_large_thumb_featured&ftag=TRE17cfd61&bhid=2219791

Apple hope new cheap iPad will turn around sales

There is a new iPad available starting today 03/24/17.  The most exciting feature of this newest tablet from Apple is it's price, $329 for 9.7" 32 GB WiFi model.

It replaces the iPad Air 2 and is simply called the iPad.  In addition to the lower cost, the iPad sees a spec update, with the old A8X chip getting replaced with the 64-bit A9 processor.  Despite the more powerful processor there are compromises to hit that low price.  Apple is betting that it has hit the sweet spot to turn around flagging sales.

Also, a new red  iPhone.

Read about this new iPad at:

https://www.engadget.com/2017/03/22/apple-new-ipad-cheap-not-powerful/

https://betanews.com/2017/03/21/low-cost-9-7-inch-apple-ipad/

Thats it!  Happy Friday!  Buy a PC!


DFS-Driving Force Software Intel 7th Generation workstations.



Monday, March 13, 2017

WikiLeaks dump, CIA capabilities, your security and Best Buys assist FBI

Many things were revealed last week after the WikiLeaks dump.  Cybersecurity experts have been focusing on the "zero-day" vulnerabilities detailed in the documents.  These are holes in the code that can be used to infect a device with spyware/malware or to steal personal information.  The CIA has been criticized because they did not attempt to notify tech companies of the security flaws so they could be addressed but instead left Americans vulnerable to potential cyber criminals.

According to documents released in the dump, the CIA has the ability to hack into and control iPhone, Android and Samsung TVs.  It doesn't stop there, Skype, Wi-Fi networks and anti-virus programs can be manipulated as well.  If the CIA can hack these devices so can others.

The dump unveiled the agency's ability to hack into devices remotely and turn on cameras, microphones for tracking a person's location and messages.  The CIA along with intelligence services in the UK developed a hack targeting Samsung Smart TVs that enabled them to record surroundings while the TV appeared to be off.

In addition to the WikiLeaks dump, new federal court filings revealed a close relationship between the FBI and Best Buy’s Geek Squad.  The FBI was using Best Buy's Geek Squad to monitor and gather data on individuals.  Now I'm all for the capture of info that assists in getting child pornographers, criminals and other scumbags but I was still surprised to learn of the training and management of Geek Squad staff as FBI informants.


After CIA leaks, tech giants scramble to patch security flaws

Apple, Microsoft, and Google are analyzing leaked CIA documents to see if their products are affected, but security researchers say that most of the flaws have long been fixed.
http://www.zdnet.com/article/tech-giants-scramble-for-cia-hacking-fixes-most-flaws-patched/?loc=newsletter_large_thumb_featured&ftag=TRE17cfd61&bhid=2219791

FBI Used Best Buy’s Geek Squad To Increase Secret Public Surveillance

http://fortune.com/2017/03/12/rbi-best-buy-geek-squad/


The battle for online privacy:  What you need to know

https://www.cnet.com/news/online-privacy-what-you-need-to-know-faq/?ftag=CAD1acfa04&bhid=21042726186831923270015874178287


DFS-Driving Force Software Intel Generation 7 workstations






Monday, February 20, 2017

Most US firms would pay to avoid data breach shame going public

In the last week I have noticed a spike in attempted phishing attempts designed to entice me into downloading malware to my computer.  Here are some examples;

From Subject Received Size Categories
Cadwalader, Wickersham and Taft LLP fraudulent card charge  3:55 PM 41 KB

From Subject Received Size Categories
Navy Federal Suspicious Sign In Attempts Noticed Tue 5:21 PM 37 KB

From Subject Received Size Categories
USPS Shipping information for parcel 080483268 Mon 4:30 PM 33 KB

From Subject Received Size Categories USPS Shipping information for parcel 236217161 Mon 10:38 AM 43 KB

They are getting quite clever in their attempts.  The first one purported to be from a real international law firm and the email went like this,


Who the f**k are you and why is there a charge from drivingforce.net on my card?
Here you can view my statement , get back to me asap.

Well to say the least it did get my attention!

It contained a link that was supposed to provide me details about a Bank of  America Statement.  Instead it contained a link to a Japanese website that upon investigating the home page on a honeypot computer (ask me if you want to know), displayed this.

株式会社ウノトレーディング

現在ウェブサイトを準備中です。

日本の食を考える、食肉総合商社として


お問い合わせ TEL 03-5753-4720(受付 9:00〜18:00)

which translated to:


Uno trading Co., Ltd.

I am preparing my website now.

As a meat general trading company thinking about Japanese food

Inquiries TEL 03-5753-4720 (Reception 9: 00 ~ 18: 00)

Now I only lifted the home page from the link and did not explore the full link which would have taken me to the payload.  Many times the actual website is legit but has been hacked and malicious code placed on a page within the website.


Some clients have called me to report that a pop up from Microsoft saying their computer is infected and to call a 1-800 number.  This happened while visiting a legit site that obviously has been hacked and a malicious script placed on that website.  Of course this is a scam and if it happens to you do not call.  The best course of action to take is start TaskMgr and kill the browser process.


It is imperative that you practice good safe computing and deploy an anti-virus/malware strategy that includes both software and backup procedures.  Redundant backups both onsite and cloud can help avert a disaster in both data loss and financially.   Carbonite provides excellent backup protection in the event of an encryption attack.  I have clients that it saved from data loss by keeping up to 30 days of protection online.  One example is a client who did not realize for 2 days that a workstation had been compromised.  In that time the malware encrypted all their MS Office docs, PDFs and picture files rendering them unuseable.  Each file contained instructions on how to pay a ransom to receive an encryption key to recover the file.  Fortunately they were able to contact Carbonite and restore a 2 day old backup and recover their files with minimal loss.  You can find out more about Carbonite here http://partners.carbonite.com/freeradicalltd

Most US firms would pay to avoid data breach shame going public

According to research done by Bitdefender, most enterprise size firms would pay up to $124,000 to avoid public knowledge of a data breach.  Some IT decision makers say the would pay as much as $500,000.  Many have already set up Bitcoin accounts to be prepared in the event of such an occurrence.  Bitcoin is a cryptocurrency and a payment system.  It is the preferred payment used by many hackers and is hard to track.

In fact the results of the survey conducted for Bitdefender suggests that up to 34 percent of companies in the US may have been breached in the past year and that most do not know how it happened.  Read the complete article at the link below.

http://www.zdnet.com/article/most-us-firms-would-pay-to-avoid-data-breach-shame-going-public/?loc=newsletter_large_thumb_related&ftag=TREc64629f&bhid=2219791


Ad-DFS-Driving Force Software Intel based workstations






Monday, February 13, 2017

Is it time for a Chromebook? The new Chromebook Pro now available.

The new Chromebook Pro is available now for $449.  Is it ready for prime time?

I have used a Chromebook for over a year now and find it to be far more acceptable to use as a portable device than my iPad.  The battery life is a full day, start up is quick and with my Office 365 subscription I am able to perform much of what I need to accomplish in word processing, spreadsheets and of course email.  Although I have a couple of paid for MS Office 365 subscriptions, you don't have to pay for the Office Online subscriptions to use the online MS Office apps.  I signed up for a free Outlook.com email account and I am able to use the free online MS apps with that account.

The Chromebook I have is a HP 11 G4.  It has 32 GB SSD, 4 GB RAM and an Intel Celeron processor.  The only problems I have encountered is sometimes with streaming online content.  Often times I cast my screen to my 50" Sony TV and when I try to simultaneously send the audio to Bluetooth speaker it fails to sync the video and audio together resulting in a lag.  Have you tried wireless casting to your TV from your computer yet?  Awesome stuff.

In defense of my Chromebook it was only $169, a bargain for the price and a factor in why a lot of school districts are moving to Chromebooks as the preferred lesson delivery device for their students.  The Chromebook is tied to Internet accessibility but with access to the Internet being ubiquitous that is no longer a factor except in the most remote locales.

The Chromebook is evolving and a new model, the Chromebook Pro is available with the more powerful Intel Core processors.  Many of the Android Apps available on your Android phone are now coming to the Chromebook with more being ported over.

Below are links with different approaches to assessing the Chromebook Pro.  I hope they enlighten and inform you as to what to expect with a Chromebook, enjoy!

https://www.cnet.com/news/the-five-stages-of-chromebook-acceptance/


http://www.theverge.com/2017/2/10/14570480/samsung-chromebook-plus-laptop-review

http://www.theverge.com/2017/2/10/14571332/not-a-chromebook-pro-review-samsung-chrome-os-android-convertible










Tuesday, January 31, 2017

LogMeIn Increases Prices 70% Year over Year, Alternative Remote Access


LogMeIn Rate increase of 70%

Does your firm use LogMeIn for remote access?  Many of my clients do based upon my recommendations in the past.  It was an affordable alternative to GoToMyPC and provided a very good service.  It along with WebEx (Citrix) began as a free service before starting to charge for it's products.

I provide this information to give you time to weigh the benefits of continuing your current subscription, scaling down the number of seats you have or looking at alternatives.

Below is a chart that details the increase in the 2, 5 and 10 seat subscription.

# Seats           2017           2016       $ increase      % increase
10 Users $1,099.99 $649.00 $450.99 69.4900
5 Users $599.99 $349.00 $250.99 71.9169
2 Users $249.99 $149.00 $100.99 67.7785

If your subscription has already been renewed and you haven't checked your credit card statement you will want to check.  If you haven't been billed in 2017 yet, login to your account, go to Settings and then select Subscription to see when it renews and the new rate.  You can also check your Billing History under Settings, Billing and Billing History.

LogMeIn's new Rates





Alternative Remote Access Options

In my blog post of November 18th, 2016, I wrote about 15 free remote access services.  One such service in particular offers a viable alternative to LogMeIn.  Team Viewer is free for personal use.  It is a stable platform and works very well.



I'm not against LogMeIn per se, GoToMyPC has been charging at these levels for years.  LogMeIn has added 1 TB of cloud storage per seat as an additional service.  This was a replacement to their former pay for Cloud Service, Cubby.  However many of my clients are using Office 365 which provides 1 TB of OneDrive space per user and the ability to sync the desktop to the cloud.  LogMeIn's cloud space does not allow syncing nor does it allow you to map a network drive to set up a sync using software such as Syncovery.  I do not want to pay for services I don't use or need.

Finally the thing I never liked about LogMeIn is that they auto charge your credit card without notification and without providing a receipt.  I had a lot of my clients on my AMX card and it was a hassle to determine whose account I was being charged for.  In my opinion, a 70% increase in cost is worthy of a notification.

DFS-New Intel Generation 7 Workstations


TEST