Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Monday, March 2, 2020

Data Breach: Top Reasons Why It Happens


It seems like every day, there’s something in the news about a company experiencing a data breach, putting the organization, as well as its partners and customers, at risk. If you don’t want your business to be one of them, you have to know the most common causes of data breaches and what you can do to improve your information security.

Weak Passwords, Stolen Credentials


Hacking attacks is one of the most common cause of data breaches. But the vulnerability that hackers exploit is generally a lost or weak password. Statistics showed that four out of five breaches have been classified as a hack were in part due to stolen or weak passwords. There’s an easy way to deal with this and that is to use complex passwords and to never share them to anyone.

Application Vulnerabilities


There’s no need for you to open the door if it’s already open. Hackers like to exploit poorly implemented or designed because they leave openings that they can use to access your data. One simple solution is to make sure that all your hardware and software solutions are updated and functioning properly.

Malware


There is a rising trend in the use of in-direct and direct malware. Generally speaking, malware is a malicious software that is installed unknowingly and provides access for a hacker to a system and other connected systems. Be careful when accessing websites or when opening emails especially if you think they look suspicious.

Social Engineering


Hackers don’t need to go through the hassle of finding a way to access a system if they can let others with a more legitimate claim to the data they need do it for them instead. So, if it is too good to be true then don’t go for it. Chances are, hackers are waiting on you to grant them access to your system.

Too Many Permissions


Hackers love access permissions that are way too complex. Companies that fail to keep a tight rein on who has access to what within their company are more likely to have provided the wrong permission to the wrong individual or perhaps have neglected outdated permissions, which hackers will exploit. You don’t have to complicate things. When it comes to securing your information, simple is better.

Insider Threats


When it comes to information security Wilmington, the adage keep your friends close and your enemies closer is relevant. The disgruntled contractor, rogue employee, or those people who don’t know any better have been provided with the permission to access your company data. So what’s preventing them from altering, copying, or stealing information?

You should know who you are dealing with and act right away when there is an indication of a problem and make sure that everything is covered with produced and process that are backed up with the right training.

Physical Attacks


Is your building secure or safe? Hackers do not just sit around in a bedroom located in a far away land. They’ve got high visibility jackets along with a strong line in plausible patter to allow them to work their way into your building and inside your systems and network. You have to remain vigilant and watch out for anything that looks suspicious and make sure to report it.

Incorrect Configuration, User Mistakes


Errors happen and mistakes are made. Hire the right IT expert to be in charge in making sure that your data is secured.

IT professionals at SpartanTec, Inc. in Wilmington will set in place robust and relevant procedures and processes to prevent user error, then mistakes could be kept to the bare minimum and limited only to areas where they are much less likely to result into a major data breach.

Call SpartanTec, Inc. if you want to know how to amp up your information security and safeguard your business from all kinds of online threats.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255
https://spartantec-wilmingtonnc.business.site/

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Monday, September 2, 2019

Choice Hotel Data Breach Affects up To 700,000 Customers

Recently, an independent researcher named Bob Diachenko worked collaboratively with Comparitech. They discovered an unsecured database containing nearly 700,000 hotel records belonging to Choice Hotels.  Unfortunately, although Diachenko reported his finding to the company, hackers had beaten him to the punch and had already downloaded the file. They are now demanding a ransom for its return.

An investigation into the matter is ongoing. A spokesman for Choice Hotels reported that the bulk of the file consisted of test information, including dummy payment card numbers, passwords and populated reservation fields.  They did confirm, however, the presence of some 700,000 genuine guest records and included names, addresses and phone numbers.

The hackers left a ransom note in the database, demanding 0.4 Bitcoin for the safe return of the data.  Based on recent prices, that amounts to about $4,000. Assuming the company decides to pay and assuming the hackers keep their word, that is a small price to pay given the number of compromised records.

Choice Hotels reported that the database was exposed when a third-party vendor accessed it as part of a proposal to provide a tool.  Due to the lapse in security, Choice Hotels has decided not to work with that vendor again.

Their announcement about the incident reads, in part, as follows:

"We are evaluating other vendor relationships and working to put additional controls in place to prevent any future occurrences of this nature... We are also establishing a Responsible Disclosure Program and we welcome Mr. Diachenko's assistance in helping us identify any gaps."
This lukewarm response to the incident has done little to ease the concerns of Choice Hotels' customers. To this point, no notifications have been sent out to customers whose data has been compromised.  If you stay at Choice Hotels when you travel, be mindful that you may be receiving targeted phishing emails and that your payment card information may have been compromised.

Don't wait for a data breach to happen before you realize the importance of information security. Call SpartanTec, Inc. in Wilmington for a thorough review of your network. Our team will help identify potential vulnerabilities and help set in place security measures to protect your network and your client's information. 


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Tuesday, August 27, 2019

BlueKeep Virus Continues To Be An Issue For Microsoft

Wormable bugs are an ongoing concern for Microsoft.  Recently, the company released a set of patches for two newly discovered 'BlueKeep-Like vulnerabilities" that impact a wide range of Windows Operating Systems.

These bugs plague the company's remote desktop services and permit malware to spread rapidly from one device to another.

Remote Desktop Services is an older technology that's been an integral part of the Microsoft Windows environment for decades.  It's a good idea and a widely used technology that allows Windows users to remotely access another computer over a network.  Unfortunately, flaws in the system allow malicious third parties to gain control over the system and spread malware via remote code execution.

The two most recently discovered bugs are being tracked as CVE-2019-1181 and CVE-2019-1182.  They were discovered by Microsoft during one of the company's routine security checks. Patches were released for both as part of the company's August Patch Tuesday.

As the company explained in a recent blog post related to the issues:

"These two vulnerabilities are also 'wormable,' meaning that any future malware that exploits these could propagate from vulnerable computer to vulnerable computer without user interaction."

The operating systems vulnerable to the newly discovered bugs are:
  • Windows 7, Service Pack 1
  • Windows Server 2008 R2, Service Pack 1
  • Windows Server 2012
  • Windows 8.1
  • Windows Server 2012 R2
  • Windows 10, including server versions
At present, Microsoft has no statistics about how many machines in the Windows ecosystem are vulnerable to the two new bugs. The company has detected no third-party manipulations of the vulnerabilities to this point, but they recommend immediately applying the relevant patches in order to mitigate risk.

Unfortunately, recent reports have revealed that many businesses have been slow to respond to the threat that BlueKeep vulnerabilities represent.  If your company is among them, the time to act is now.

Call SpartanTec, Inc. if you want to make sure that your operating systems are secured from the most common online threats today. Let our team help you in keeping your network and business safe and secure from various types of risks and vulnerabilities.

SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Monday, August 19, 2019

Update Your iPhone To Avoid Latest iMessage Security Vulnerability

If you own an iPhone, be aware that a new iMessage vulnerability has been recently found and patched by Apple. This was part of the iOS 12.4 update.

The flaw allowed hackers to access and read the contents of files stored on iOS devices remotely. They could access files the same way as the device owner with no sandbox, and with no user interaction needed.

The issue was discovered by Natalie Silvanovich, who is a security research with Google's Project Zero.  As a proof of concept, she created a demo that only works on devices running iOS 12 or later. She describes it as "a simple example to demonstrate the reach-ability of the class in Springboard. The actual consequences of the bug are likely more serious."

In describing the issue itself, Silvanovich had this to say:

"First, it could potentially allow undesired access to local files if the code deserializing the buffer ever shares it (this is more likely to cause problems in components that use serialized objects to communicate locally than in iMessage).  Second, it allows an NSData object to be created with a length that is different than the length of its byte array.  This violates a very basic property that should always be true of NSData objects.  This can allow out of bounds reads, and could also potentially lead to out-of-bounds writes, as it is now possible to create NSData objects with very large sizes that would not be possible if the buffer was backed."

As mentioned, this bug has already been patched, along with two other iMessage vulnerabilities that Silvanovich recently discovered. All of them were addressed in Apple's most recent (12.4) update. If you're not in the habit of installing security updates automatically, then you'll need to grab this one and install it manually at your earliest convenience.

Smart gadgets and devices are everywhere. Regardless of the brand, a prudent owner will find ways to make sure that all their smartphones, computers, laptops, and network in general is safe against potential vulnerabilities that could put their pertinent information at risk. Call SpartanTec, Inc. in Wilmington NC to make sure that efficient security measures are in place to protect your personal information, business, and clients from the many different online threats today. 


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Thursday, August 15, 2019

Security Issue Found In Multiple Devices Is Called ‘Urgent 11’

Let's take a little time to talk about the vast numbers of smart devices in use around the world. You probably have several in your home or office. Smart devices need operating systems, just like your phone and your PC. Of course, mobile device operating systems must be much smaller and more compact. After all, they don't really need to do a lot of computing, and they don't need a GUI, so the code tends to be on the lean side.

The odds are excellent that you've never even heard of most of the IoT's operating systems, nor the companies that make them. Take VxWorks by a company called Wind River, for example.  It's the most popular Real Time Operating System (RTOS), used in a wide range of smart devices today.  They don't get a lot of attention or oversight because almost nobody has heard of them.

That's beginning to change, however.  Recently, security researchers disclosed the details of the "Urgent 11", which are 11 vulnerabilities found in VxWorks that can be used by hackers to take control of a variety of devices. These devices range from medical systems to printers, industrial equipment, routers, and more.

The company has been in existence for 32 years. Yet, in that time, only 13 security flaws with a MITRE-assigned CVE have been found in the VxWorks RTOS, because again, nobody's paying attention.

The good news is that when someone finally started paying attention, Wind River responded quickly and resolved all eleven of the security flaws, issuing a patch to correct them.  There's just one rather significant catch, however.

The company is claiming that the vulnerabilities are not unique to Wind River software and that the IPnet stack (where the vulnerabilities were found) was acquired by the company back in 2006.  Prior to Wind River's acquisition of it, it was deployed in a wide range of other RTOS'.

All that to say, while Wind River is acting responsibly, there are an unknown number of other RTOS' out there that are vulnerable. The companies behind them may be doing little or nothing about it.  In many ways, the OS ecosystem of the IoT is still very much a black box, and that's troublesome.

As a company, are you doing your part in securing your smart devices and your network? Or are you left in the dark about their vulnerabilities? Let SpartanTec, Inc. Wilmington help you find out if your business is at risk. Call now and learn more about their complimentary, one-time scan with Dark Web ID™ Credential Monitoring.

SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Tuesday, June 4, 2019

New Ransomware Looks Like An Anti-Virus Installation

Dharma is a highly successful ransomware strain.

It recently has been made even more successful by a change in the way the hackers controlling it are deploying it.

The first part of their latest campaign remains unchanged.  They rely on well-crafted phishing emails to lure employees in.

The key difference, however, lies in the particulars of the newly crafted emails.

In a nutshell, the group has begun imploring email recipients to protect their systems by installing the latest antivirus software.  The emails include a helpful link to the antivirus, which of course doesn't point to antivirus software at all. Rather, it is the ransomware they're trying to deploy inside corporate networks.

Worst of all, the emails claim to be from Microsoft, one of the biggest, most recognizable and most trusted names in the industry. So, there's a good chance that at least one of your employees will take the bait. In a bid to be good, proactive employees, they will seek to install what they think is antivirus software.

Once they start the installation, the damage is done.  It will lock every file on the victim's system, demand ransom, and seek to spread itself to as many other systems inside your network as it can reach.

Raphael Centeno, a security researcher at Trend Micro had this to say about the new twist on the malware strain:

"As proven by the new samples of Dharma, many malicious actors are still trying to upgrade old threats and use new techniques.  Ransomware remains a costly and versatile threat."
As ever, the best way to guard against this type of threat starts with employee education.  Employees should not be in the habit of installing their own antivirus software in the first place, so a gentle reminder to that effect should go a long way toward limiting the threat, but it still pays to be very much on your guard.

Secure your email and your system with the help of an expert IT consultant from SpartanTec, Inc.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255
https://spartantecwilmington.business.site

Thursday, April 25, 2019

Millions Of Toyota Customers Possibly Affected By Data Breach


In recent months, Japan is a nation under cyber-siege, with several high-profile attacks having been made against the country.  The most recent attack targeted Toyota.  If you own a Toyota or Lexus, it's possible that at least some of the information you gave to the company has been compromised. A data breach on such a huge company signals the need for businesses to have managed IT services looking over their data, ensuring no critical information leaks out.


Although an investigation into the matter is ongoing, Toyota wasted no time letting its massive customer base know.

Their official statement reads in part, as follows:

"We have not confirmed the fact that customer information has been leaked at this time, but we will continue to conduct detailed surveys, placing top priority on customer safety and security."

Later in the statement the company stressed that if customer information was, in fact compromised, that information did not contain credit card or other payment numbers. Although no sensitive information was stolen, it is always a good thing for companies to ensure that managed IT services Wilmington are in place.
Early indications point to a well-organized hacking group calling themselves the OceanLotus Group. Although even this cannot be confirmed at this point.

The details surrounding the attack are murky at this point. What we do know with certainty is that on March 21st, the company detected an unauthorized intrusion into its corporate networks across a staggering 8 company divisions, marking it as an extremely well organized and sophisticated attack. With this in hand, information security has never been more important.

Considering the other attacks made against Japanese companies and government agencies, it seems that for reasons that are not yet clear, one or more big hacker organizations filled with top-tier talent has decided to put the nation under the virtual gun.

Only time will tell exactly who's behind the attacks and what their ultimate purpose might be. For now, the key thing to know is that if you own a Toyota or Lexus, it's possible that at least some of your personally identifiable information was compromised.  Be on the lookout for additional information from Toyota as it becomes available.

Call SpartanTec, Inc. if you are looking for a reliable and reputable IT consultant to help make sure that your computers are safe and secure.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255


Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Monday, April 15, 2019

Developer Of Popular Kids App Slapped With Hefty Fine


The FTC or Federal Trade Commission has recently slapped a hefty fine on a popular app developer for violating the privacy of its users. The Chinese app developer who created Tik Tok, a popular mobile app, was handed a $5.7 million fine when the FTC filed a complaint against it after it was found to have violated the COPPA or Children's Online Privacy Protection Act. When it comes to privacy, private individuals must always take some time to understand the nature of the apps they are installing. As for businesses, it is a must to have managed IT services in place for better data protection.

The main problem with the app was that it did not require parental consent for users below the age of 13, which should be a must for apps that target such an audience. A wide range of data was recorded from user names to biographical information and more. What’s even more alarming was that user account details of the app users were available to the general public. This meant that anyone who can gain access to the apps can get hold of as much information they want on other users. The apparent mistake on the developer’s side has certainly put user’s information security at risk.

McAfee Cyber Investigations head, John Fokker, commended the move by the FTC. However, he cautioned that parents must also be active in ensuring that their kids are only using the apps designed for certain age brackets. While it holds true that parents should own up and do their part, apps must also come clean with their practices and turn a new leaf. Regardless, companies must always have managed IT services Wilmington to ensure that employee data are kept safe and that no company data will be compromised.

Are you looking for a complete technology solution provider? Call SpartanTec, Inc. today.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Tuesday, April 2, 2019

FTC Issues Fine To Developer Of Popular Kids App Over Privacy Violations


The developer of popular Chinese app, Tik Tok, was slapped with a huge fine by the Federal Trade Commission over privacy issues. The developer was found to have gathered personal data of the children who used their application. This is a serious blow to the developers of the app, but could be potentially problematic for the users as well. This is the reason why companies must have proper IT management to prevent any data loss from such cases.

The FTC filed a complaint and handed the company a $5.7 million fine over violations of the Children's Online Privacy Protection Act. The FTC cited the data gathering practices of the company which did not require parental consent from users ages 13 and below. User credential including names, e-mail addresses, profile pictures, and other information were gathered. To add more to their violations, the company’s development team failed to keep the said data away from public viewing. Failure to keep the data private has clearly exacerbated the already sorry state of their practices.

What’s even more disturbing is the fact that in the FTC filing, it was highlighted that there were numerous attempts where adults contacted children through the app. The complaint also noted the fact that users were able to view other people’s accounts within a 50-mile radius prior to the release of their 2016 update. With this in hand, it is highly important for businesses to have IT management Wilmington to protect data of employees and the company as well.

With the FTC pounding hard on the makers of Tik Tok, it sends a message to all developers to put more time and effort into producing better security and permissions for their applications. After all, information security and preventing untoward incidents is a prime reason for such measures.

Do you require IT services for your company? Call SpartanTec, Inc. today for complete technology solutions.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Tuesday, March 26, 2019

Retails Sites Hit With Large-Scale Bot Attacks


Retails businesses that have established their online presence are in for another wave of attacks. As indicated in this year’s State of the Internet, attacks on retails sites have ramped up. According to the report, large-scale bot attacks are out targeting businesses, with retails sites being hit the hardest. This attacks are known as “credential stuffing” and is nothing new. However, due to the scale of the attacks, businesses should be on the defensive. It is suggested that businesses deploy reliable IT management protocols either in-house or through a reputable service provider.

In fact, the attacks made from May up until December of 2018, a total of 28 billion attempts at credential stuffing was made. One retail site reported to have been attacked by more than 115 million times in a single day. All of the attacks were bot-driven.

The report also indicated that the bots have the ability to target in excess of 120 retails in a single attack. With the use of certain techniques, the bots were able to evade detection and continue with the attacks.

What’s more problematic is that successful bot attacks could be undetected by the retailer. This means that retailers could see normal data but in the back end, they were already facing some serious attacks. This could deal a huge blow to customers’ information security entirely. Not only will it compromise the retailer, but it will ultimately have a bigger impact on its customers. Overall, impact of these attacks are limited compared to other schemes deployed by hackers.

Although damage dealt by such attacks are limited, it is still significant and can pose as threat to both retailer and consumer alike. With this in hand, retailers should always be vigilant in preserving their security, which would later entail to better relations with customers. With that being said, businesses must have a reliable IT management Wilmington team to aid in such situations and prevent issues from escalating.

Want to secure your business online? Call SpartanTec, Inc. today for reputable IT services.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro


Tuesday, March 19, 2019

Hackers Steal User Credentials At Alarming Rates With Malware


It is a known fact that malware has infected more online users over the last few years. It’s also good to note the increasing complexity of malware code that hackers deploy over the internet. However, complex malware code isn’t the only thing that users need to worry about. Some malware are hiding in plain sight and are deceivingly simple. And it’s even simple enough that most users won’t be able to detect that it is a piece of malicious software. That’s where managed IT Services come into play. It’s just safer to do business online if you and your business’ information is protected.

For instance, Separ, the credential-siphoning malware that was detected more than a year ago. And unlike other malware that evolves into a more complex malicious code, Separ is the exact opposite. Simplicity in its code was part of its success.

Surprisingly, Separ was quite slick at avoiding detection. It utilized a bunch of code and executable files that are commonly used and are deemed safe. This allows it to simply blend in and avoid detection.

The most recent version of the malware was embedded in a PDF that triggers a chain of other apps when users clicked on them. The initial user interaction runs a simple script then escalates into a batch file that issues other commands into the computer that hijacks the protection protocol of the system. This is one of the many reasons why businesses should take advantage of managed IT Services Wilmington to secure the data of their business.  

According to experts, despite the simplicity of these malware, they can still wreak havoc and can equally be capable of stealing information. This is why experts insist that companies use at least one type of security protocol to increase their information security.

Keep your data protected with professional IT services. Call SpartanTec, Inc. today.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Monday, February 18, 2019

Page Caches May Be Vulnerable To Attack



There is another side channel attack that you have to be concerned about. This threat is going after the target’s system’s operating system page cache, where different kinds of sensitive data that’s been accessed by the owner of the device is kept for faster retrieval. Maybe the most ominous aspect and worst part of this newly recognized security threat is that it is not restricted by hardware architecture, and has been discovered to work not only on machines run on Windows but those on Linux as well.

This lets attackers to bypass security protocols and sandboxes.

The research team is a diverse group of IT professionals coming from CrowdStrike, NetApp, Intel, Boston University, and Graz University of Technology. They discovered a few possible methods a hacker may be able to utilize the newly determined attack vector and were even also, in some situations, to send data gathered from the target system to a remote server.

The team emphasized that even though they conducted their tests on Linux and Windows machines, there’s no possible reason their methods will not be successful on other operating systems that are currently being used. This threat can potentially affect the whole computing system. Although many of the experiments of the teams need the would-be hacker to be able to physically access the device, they managed to show that in some cases, a remote attack can also be done.

According to the team, "Our remote attack leverages timing differences between memory and disk access, measured on a remote system, as a proxy for the required local information."

They continued to explain that this can be done by measuring soft pages faults, which take place whenever a page is incorrectly mapped. Additionally, the team managed to send data between the remote web server and target system.


It should also be noted that this kind of attack hasn’t been seen in the wild, however, Microsoft, for one, is wasting no time dealing with it. Window Insider build 18305 already has a mitigation routine set in place. Plus, it is expected to be rolled out to its users in the coming months. Although it is not as devastating, it is still dangerous and well worth to keep on your radar.




Call SpartanTec, Inc. if you want to make sure that all your systems are protected against such a threat. 


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255


Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro