Showing all posts tagged security:

Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor | FireEye Inc

Implement MFA people!



Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor | FireEye Inc
We have discovered a global intrusion campaign, and we are tracking the actors behind this campaign as UNC2452.

Suspected Russian hackers spied on U.S. Treasury emails - sources | Reuters


Suspected Russian hackers spied on U.S. Treasury emails - sources | Reuters
Hackers believed to be working for Russia have been monitoring internal email traffic at the U.S. Treasury and Commerce departments, according to people familiar with the matter, adding they feared the hacks uncovered so far may be the tip of the iceberg.

Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers



Widespread malware campaign seeks to silently inject ads into search results, affects multiple browsers - Microsoft Security


A persistent malware campaign has been actively distributing Adrozek, an evolved browser modifier malware at scale since at least May 2020. At its peak in August, the threat was observed on over 30,000 devices every day. The malware is designed to inject ads into search engine results pages and affects multiple browsers.

Security Affairs - Apache Software Foundation fixes code execution flaw in Apache Struts 2



Apache Software Foundation fixes code execution flaw in Apache Struts 2


The Apache Software Foundation addressed a possible remote code execution vulnerability in Struts 2 related to the OGNL technology. The Apache Software Foundation has released a security update to address a "possible remote code execution" flaw in Struts 2 that is related to the OGNL technology. The remote code execution flaw, tracked as CVE-2020-17530, resides in […]

Security Affairs - WordPress Easy WP SMTP zero-day potentially exposes hundreds of thousands of sites to hack



WordPress Easy WP SMTP zero-day potentially exposes hundreds of thousands of sites to hack


Threat actors are actively exploiting a zero-day vulnerability in the popular Easy WP SMTP WordPress plugin installed on more than 500,000 sites. Hackers are actively exploiting a zero-day vulnerability in the popular Easy WP SMTP WordPress plugin to reset passwords for admin accounts. The SMTP WordPress plugin is installed on more than 500,000 sites, but […]

Security Affairs - Spotify reset user passwords after personal information exposure



Spotify reset user passwords after personal information exposure


Spotify is informing users that their personal information might have been accidentally shared with some of its business partners. Spotify is informing users that their personal information might have been inadvertently shared with some of its business partners for several months. The company filed a notice of breach notice with the California Attorney General. "We deeply regret […]

Verkada - Hybrid Cloud Video Security

Tired of your existing video security system that is probably made up of a combination of different DVRs/NVRs and an assortment of cameras that you need multiple consoles to manage and of course, search for video?

Take a look at the Verkada solution - no on-premise DVR/NVR - 10 year warranty on all cameras, the ability to manage all cameras from a single web portal or mobile application. Many more features as well released on a continuous basis that you will automatically be provisioned for!

Check out their weekly webinar (link below) or reach out to me directly and I will coordinate an intro and demo for you.




Organizations are rapidly moving to the cloud to enable remote access, support greater scale, and improve usability of video surveillance systems. In this webinar, we’ll show how to deploy smart, cloud-based video surveillance so simple and scalable that it works for everyone at your organization.

verkada.com

Cloudflare

So, one of the many things I enjoy about my job is getting the exposure to all sort of new technology for IT, cloud and security. I've been spending some more time getting more up to speed on Cloudflare and realizing that it is more than a CDN, more than a WAF, more than DNS and more than ZTA - in fact, it can be used for all of them.

Get faster DNS and privacy on your phone by installing the 1.1.1.1 app. It's free!


More to come on this topic, but I did mange to do this today:



Another Equifax Issue

They can't seem to catch a break. The entire credit bureau industry needs a reboot. A great potential use-case for blockchain!


Look Who Is On TV

My employer (@BECU) and I wanted to get some messages out this year for CyberSecurity Awareness month and I had the priviledge of filming a couple of spots with KOMO TV's Connie Thompson. It was a great experience and I look forward to doing more of this in the future.



How to Get Hacked

Cyber-security sounds like something straight out of a cheesy ‘90s movie. BUT. The fact of the matter is, the Internet is here to stay, and more and more of our lives are being lived online. And no one likes getting hacked.

Hackers can wreak havoc on your personal lives (and your credit scores). It can take years to untangle the mess of identity theft or fraud. Who needs it? That's why the Department of Homeland Security has declared October Cyber-Security month. 

So let's all pretend we're living in the movie Hackers, and take a few minutes to defeat the bad guys. 

We interviewed Kyle Welsh, Chief Information Security Officer, to brief us on what we need to do to keep safe online. If you want to get hacked…just don't follow this advice.

1.  Passwords. Do they really matter? Can't hackers find a way around them?

Passwords matter more than anything else – and usernames. Don't underestimate the power of a good password! 

Think of your passwords like toothbrushes:

  • Change them frequently
  • Don't share them
  • Don't leave them lying around
  • The longer you brush, the better 

Use a combination of numbers, special characters, lowercase and capital letters to create passwords that are at least 12 characters long. I recommend using pass phrases – a string of words that have meaning to you but will create a long password (such as Hackers1sUnder@ppreci@ted). 

Don't use your email address for your username – it's too easy to find your email on the Internet, and then hackers have half the equation. 

Try to use separate passwords for every account. 

While you're updating passwords and usernames, make sure your addresses, email addresses and phone numbers are up-to-date and accurate.

2. I know using different passwords is important, but how the heck are we supposed to remember super long passwords for every account?

Yeah, that's tough. I personally use a password manager. All you have to do is remember one password. The manager remembers the rest for you and stores them securely in the cloud. I like LastPass and Dashlane. Both have good security measures in place. 

3. How do I know if I've been hacked?

Go to the website haveibeenpwned.com and enter your email address and any usernames you use. This free service will tell you if you've been hacked. It's a good source. We recommend it to our employees here at BECU.

Note: “Pwned" is internet slang for “owned," “dominated" or “beaten." It can be pronounced as owned or as poned.

Some signs that you may have been hacked:

  • You have programs that suddenly don't work

  • New files have appeared or files you didn't delete are now missing.

  • You have new programs or internet browser toolbars.

  • Random, frequent pop-ups appear

  • People in your email contacts are getting fake messages from you.

  • Money is missing from your bank account or you're getting bills to pay for online purchases you didn't make.

4. What do I do if I've been hacked?! Should I throw my computer across the room, or....?

  1. Disconnect from the internet.

  2. Get a computer savvy friend to assist if needed.

  3. Run a complete scan with an anti-virus/spyware scanner you trust.

  4. Contact your financial institution and credit card companies to alert them to a potential issue.

5. I hear social media can be risky, but...I just can't quit.

Just be careful with what you share. Check your settings to make sure only friends can see what you post, or at most friends of friends. 

Don't post when you're going to be traveling. Don't share your address. Don't make your email public. Don't take pictures with sensitive information in them. And set good passwords! Social media has made it much easier to steal people's identities. 

6. Why do hacking scenes always take place in coffee shops and airports?

Because public Wi-Fi makes it easier on the hackers. Assume that everything you do on public or free Wi-Fi can be seen by other people. Refrain from conducting sensitive activities such as online banking or shopping. If you are browsing, make sure the websites you're using are encrypted. Encrypted sites have URLs that begin with https ¬¬– the “s" stands for secure.

7. Is mobile banking safe?

It is if you're using a legitimate app provided by your financial institution. Anyone can develop an app with no safety evaluation and many are malicious. The Apple store verifies apps and eliminates ones that aren't legitimate. But Android and Windows don't have the same system in place. 

I always check to see how many reviews an app has. Not what the rating is – how many people have reviewed it. The more, the better. 

There are some things that you can do to make your phone more secure.

  • Create a complex password to unlock your device or use fingerprint authentication if you have it.

  • Enable encryption

  • Enable remote wipe capabilities

And when it comes to our mobile app, have a little patience, grasshopper. The reason your accounts take a few seconds to load when you first open the app is because we wipe all your information from your phone every time you log out. So when you log back in, your app has to pull all that data in from the remote server, where we're guarding it securely with a ring of fierce dragons (well...not really. But we are working to keep your information safe!). 

Links to our official, safe-to-use app:

iTunes Store
Google Play
Windows

https://www.becu.org/news/2016/Oct/latest-news/how-to-get-hacked