Wednesday, May 22, 2019

Password Policies Getting Update From Microsoft

Industry experts have been predicting the death of the humble password for decades.  To date, those predictions have amounted to nothing.

Passwords are still with us, and still serve as the cornerstone of security, even as other measures have arisen alongside them to help better secure your all-important data.

Even though passwords aren't gone, the security landscape is changing. Recently, Microsoft has announced another step down that path of change.  They're doing away with the notion of forced password changes.

The logic is hard to argue with.  The policy of forced password changes really doesn't offer all that much in the way of protection. It often creates as many headaches and problems as it solves, because users tend to make small, virtually meaningless and easy to predict changes to their passwords. Or, they often forget their new ones anyway.

While Microsoft is no longer forcing password changes at periodic intervals, they are leaving the option available for Enterprise users to establish their own forced password change thresholds if they choose to do so.  In tandem with the coming change, they're also recommending that security professionals perform a periodic review of passwords to ensure that the passwords in use aren't on the list of the UK National Cyber Security Centre's list of the 100,000 worst passwords.

One important thing to note is the fact that the company isn't making any changes to its requirements for minimum password length, complexity, or history. That is essential in terms of keeping users from simply recycling the same two or three passwords, switching endlessly back and forth between them.
It's also worth mentioning that these changes could benefit companies that are currently under audit. That is if the auditing agency is using Microsoft's security baseline as a guideline. That makes this seem like a small , but it is more significant than it may first appear.

Call SpartanTec, Inc. if you wish to know how to secure your online information.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Tuesday, May 14, 2019

Persistent Banking Trojan Virus Launches New Phishing Scam


The venerable banking Trojan known as Q-bot is back in the news, having recently been spotted in the wild as part of a sophisticated new phishing campaign designed to claim a new generation of victims.

Q-bot is one of the oldest banking Trojans still in use, and has a history that stretches back more than a decade.

In this most recent incarnation, the malware is being delivered via an email which appears to be a reply to an existing email chain.  The body of the email contains a poisoned link which, if clicked will install the malware in the background.

Once in place, it creates a backdoor to the compromised machine in question, allowing hackers access any time they like.  It also serves as a key logger and general spy. It can steal financial data, banking data, other logins, credentials, and of course, makes it possible for the hackers to install additional malware as they see fit.

The reason Q-bot is still enjoying use of stolen data is that it's very good at what it does, and the developers of the code have taken steps to keep it up to date.  This, combined with finding new and innovative ways of introducing the Trojan onto target systems has made it as close to a persistent threat as we've seen when it comes to malicious code.

The latest campaign appears to borrow from the success of a similar campaign launched last year involving a Trojan with comparable functionality called Emotet.

This serves as confirmation that different hacking groups around the world are learning from one another, comparing notes, and developing an increasingly robust set of best practices. All this makes it increasingly more difficult to effectively defend against such threats.  Stay vigilant and be sure to remind your employees never to open emails or click links inside emails, even if they appear to be from a trusted source.

SpartanTec, Inc. can provide training for your employees to ensure they are not inadvertently allowing this malware into your computer systems via their email practices. We are located in Wilmington and provide managed IT services including a free dark web scan and employee awareness training. Contact us today to ensure the safety of your data. 

SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255


Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro


Monday, May 6, 2019

Issue With Internet Explorer Could Affect Most PC Users


Are you still surfing the web with Internet Explorer?  If so, you're not alone.  Four years after Microsoft announced Edge as its successor, the company's old browser still has a few stubborn holdouts who continue to use it for various reasons.
Unfortunately, security experts keep finding critical security flaws in the code that make it something of a ticking time bomb.

The most recent of these was unearthed by an independent researcher named John Page. He published a proof of concept that demonstrates a flaw in the way the old browser handles MHT files, which are used by Internet Explorer for archival purposes.

If any computer running Windows 7, Windows 10, or Windows Server 2012 encounters an MHT file, it will attempt to open it using Internet Explorer.  This fact represents a tremendous opportunity for a savvy hacker.  All he has to do is present a specially crafted MHT file containing malicious code to a user and use a bit of social engineering to open it.  Using history as a guide, convincing users to open files from untrusted sources is not especially difficult to do.

Even if you don't currently use Internet Explorer, your system is still very much at risk from this type of attack, because IE 11 still ships with every Windows-based PC, including the latest Windows 10 machines.  The only potential saving grace here is that on Windows 10 machines, Internet Explorer is not enabled by default and needs to go through a user-initiated setup process before it could be used.
The solution then, at least if you've got a Windows 10 machine, is simply to avoid enabling Internet Explorer or, even better, simply uninstall it from the Control Panel altogether.

Mr. Page reported the issue to Microsoft on March 27, and received the following reply:
"We determined that a fix for this issue will be considered in a future version of this product or service.  At this time, we will not be providing ongoing updates of the status of the fix for this issue and we have closed the case."

Unfortunately, that's a canned response that amounts to a dismissal. So for the foreseeable future, you should operate under the assumption that no help will be forthcoming from Microsoft on this issue.  Make sure your IT staff is aware.

SpartanTec, Inc. serves small to medium size business with outstanding IT support in both North and South Carolina. Call us today to ensure your data is safe.

SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255


Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro





Thursday, April 25, 2019

Millions Of Toyota Customers Possibly Affected By Data Breach


In recent months, Japan is a nation under cyber-siege, with several high-profile attacks having been made against the country.  The most recent attack targeted Toyota.  If you own a Toyota or Lexus, it's possible that at least some of the information you gave to the company has been compromised. A data breach on such a huge company signals the need for businesses to have managed IT services looking over their data, ensuring no critical information leaks out.


Although an investigation into the matter is ongoing, Toyota wasted no time letting its massive customer base know.

Their official statement reads in part, as follows:

"We have not confirmed the fact that customer information has been leaked at this time, but we will continue to conduct detailed surveys, placing top priority on customer safety and security."

Later in the statement the company stressed that if customer information was, in fact compromised, that information did not contain credit card or other payment numbers. Although no sensitive information was stolen, it is always a good thing for companies to ensure that managed IT services Wilmington are in place.
Early indications point to a well-organized hacking group calling themselves the OceanLotus Group. Although even this cannot be confirmed at this point.

The details surrounding the attack are murky at this point. What we do know with certainty is that on March 21st, the company detected an unauthorized intrusion into its corporate networks across a staggering 8 company divisions, marking it as an extremely well organized and sophisticated attack. With this in hand, information security has never been more important.

Considering the other attacks made against Japanese companies and government agencies, it seems that for reasons that are not yet clear, one or more big hacker organizations filled with top-tier talent has decided to put the nation under the virtual gun.

Only time will tell exactly who's behind the attacks and what their ultimate purpose might be. For now, the key thing to know is that if you own a Toyota or Lexus, it's possible that at least some of your personally identifiable information was compromised.  Be on the lookout for additional information from Toyota as it becomes available.

Call SpartanTec, Inc. if you are looking for a reliable and reputable IT consultant to help make sure that your computers are safe and secure.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255


Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Monday, April 15, 2019

Developer Of Popular Kids App Slapped With Hefty Fine


The FTC or Federal Trade Commission has recently slapped a hefty fine on a popular app developer for violating the privacy of its users. The Chinese app developer who created Tik Tok, a popular mobile app, was handed a $5.7 million fine when the FTC filed a complaint against it after it was found to have violated the COPPA or Children's Online Privacy Protection Act. When it comes to privacy, private individuals must always take some time to understand the nature of the apps they are installing. As for businesses, it is a must to have managed IT services in place for better data protection.

The main problem with the app was that it did not require parental consent for users below the age of 13, which should be a must for apps that target such an audience. A wide range of data was recorded from user names to biographical information and more. What’s even more alarming was that user account details of the app users were available to the general public. This meant that anyone who can gain access to the apps can get hold of as much information they want on other users. The apparent mistake on the developer’s side has certainly put user’s information security at risk.

McAfee Cyber Investigations head, John Fokker, commended the move by the FTC. However, he cautioned that parents must also be active in ensuring that their kids are only using the apps designed for certain age brackets. While it holds true that parents should own up and do their part, apps must also come clean with their practices and turn a new leaf. Regardless, companies must always have managed IT services Wilmington to ensure that employee data are kept safe and that no company data will be compromised.

Are you looking for a complete technology solution provider? Call SpartanTec, Inc. today.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro

Monday, April 8, 2019

Information Technology And How It Benefits Businesses


Information technology in general is a diverse collective of technologies used to store, exchange, and create information. There are a lot of trends nowadays that further improve the tech within the scope of IT. The good thing about all this innovation is that everyone can benefit from it. Private individuals can reap the benefits of IT services. Businesses are also the primary beneficiaries of such advances in IT. But what are exactly the benefits that businesses can gain from information technology? Here are a few business benefits of IT:

Better forms of communication


Better communication means increased productivity. Within businesses, clear communication is everything and all of this needs to happen fast. Information technology can make communication better by speeding up the process. Internal chat and e-mail services, VOIP, and other services are all critical. Of course, all of these services wouldn’t be possible if not for proper communication systems as well as innovative IT equipment. With a combination of services, systems, and IT equipment, employees and other executives in the hierarchy can respond quickly to partners and customers alike.

Increased efficiency in the workplace


With the aid of information technology workflow systems have become more streamlined to increase the efficiency within the workplace. Routine tasks can be automated, making data analysis and storage far easier and faster. Customer queries are also handled faster and in a timely manner. Real-time chat is also made possible through, which equates to better customer services down the line. Computer security is also improved at the same time.

An edge over rival businesses


One goals that businesses have in common is to gain a competitive edge over rivals. This is where IT services Wilmington come into play. The adoption of well-developed IT services and equipment, companies can create newer services, build new products that make it harder for customers to shift towards other providers.

Overall cost reduction


Cost is a primary factor in that could dictate the operation of an entire business.    With a properly setup IT infrastructure, redundant tasks such as payroll processing can be sped up and done accurately each time, ultimately reducing the costs of performing such tasks.

Call SpartanTec, Inc. today and discover how they can assist your company with a complete IT Managed Solution. 


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro


Tuesday, April 2, 2019

FTC Issues Fine To Developer Of Popular Kids App Over Privacy Violations


The developer of popular Chinese app, Tik Tok, was slapped with a huge fine by the Federal Trade Commission over privacy issues. The developer was found to have gathered personal data of the children who used their application. This is a serious blow to the developers of the app, but could be potentially problematic for the users as well. This is the reason why companies must have proper IT management to prevent any data loss from such cases.

The FTC filed a complaint and handed the company a $5.7 million fine over violations of the Children's Online Privacy Protection Act. The FTC cited the data gathering practices of the company which did not require parental consent from users ages 13 and below. User credential including names, e-mail addresses, profile pictures, and other information were gathered. To add more to their violations, the company’s development team failed to keep the said data away from public viewing. Failure to keep the data private has clearly exacerbated the already sorry state of their practices.

What’s even more disturbing is the fact that in the FTC filing, it was highlighted that there were numerous attempts where adults contacted children through the app. The complaint also noted the fact that users were able to view other people’s accounts within a 50-mile radius prior to the release of their 2016 update. With this in hand, it is highly important for businesses to have IT management Wilmington to protect data of employees and the company as well.

With the FTC pounding hard on the makers of Tik Tok, it sends a message to all developers to put more time and effort into producing better security and permissions for their applications. After all, information security and preventing untoward incidents is a prime reason for such measures.

Do you require IT services for your company? Call SpartanTec, Inc. today for complete technology solutions.


SpartanTec, Inc.
Wilmington, NC 28412
(910) 218-9255

Cities Served:
Wilmington, Silver Lake, Sea Breeze, Carolina Beach, Eagle Island, Leland, Wrightsboro