On April 6th, Adobe released a critical patch for its Flash Player plugin for browsers. This came with an alert that the previous version of Flash Player has Zero-Day vulnerabilities, and could even allow hackers to take control of your computer. It is vital that you update Flash Player on all of your browsers, as the term "Zero-Day Vulnerability," means that cyber-criminals already know about this threat and are known to be actively exploiting it. A very special thanks to Brian Krebs of Krebs on Security for posting an update about this threat, and further spreading the word.
Astria Business Solutions highly recommends you verify that you are running the most current version of Flash, this can be checked on Adobe's website. If you use multiple browsers, such as Internet Explorer, Chrome, Firefox, or others, be sure to verify that Flash Player is updated in each of these. Some browsers may also require a manual restart to finalize the update: all that you need to do is close the browser and open it again.
Remember that this is a Zero-Day threat, and needs to be addressed immediately. Hackers have already exploited this on computers running Windows 10 and earlier platforms, but Adobe warns that Macintosh, Linux, and Chrome OS based operating systems are also vulnerable. Be certain to apply this patch as quickly as possible.
Friday, April 8, 2016
Department of Homeland Security Issues Ransomware Alert
As we’ve discussed in many previous blog posts, and as we
have seen continuously in the news, Ransomware is increasingly becoming an
issue that businesses and individuals should be prepared for. More and more
victims unfortunately seem to be paying the ransoms, which means that
Ransomware has become more and more profitable for cybercriminals, and
therefore it has become more common.
The issue has become so prevalent that the United States Department
of Homeland Security and the Canadian Cyber Incident Response Centre have
released a major warning about Ransomware and its effects. Specifically, the
joint alert aims to “provide further information on ransomware, specifically
its main characteristics, its prevalence, variants that may be proliferating,
and how users can prevent and mitigate against ransomware.”
This alert just signifies how serious this problem is
becoming, and how important it is for businesses and individuals to prepare
their systems and be aware of the ways Ransomware can get into systems. Email
is still one of the most common entryways for infections like these, particularly
through phishing attempts that try and trick the user into opening and running the
malicious files.
The alert put out on US-CERT mentions several things our
readers may be familiar with, discussing what Ransomware is and how it often
locks users out of their systems, but is also makes some additional points that
are worth highlighting.
First, they mention that paying the ransom demands is not
advised, as the attackers may or may not release your files, and you may even
end up targeted for a second attack later.
Second, they point out that when Ransomware is installed on
a system, it often is installed with other malware in the background. This
means even if you do get your files unlocked by paying the ransom, the
attackers may still be stealing private information off your system:
particularly banking information.
Third, they note that Ransomware infections often have
additional, hidden costs to businesses, such as loss of valuable data, loss of
time and productivity due to system downtime and repair, and even damage to
reputation.
Last, they highlight their recommendations to minimize the
risks of malware, first and foremost being having a proper backup in place that
is regularly updated. This is a good measure to defend against most infections,
but especially with Ransomware as it gives you a the option to rebuild the system
with only the cost of hours, rather than the $3.6 million demanded of aHospital in Hollywood.
This alert is very helpful and provides a good breakdown of
what Ransomware is, where it comes from and how to prevent it from infecting
your systems. Astria Business Solutions highly recommends you read it and share
with others as well. Awareness is key to information security.
If you would like assistance with Ransomware preparedness,
Astria Business Solutions can assist you. We can set up email filtering to help
prevent phishing attempts and can assist you in creating and implementing
backup and recovery plans. For more information, visit our website at
AstriaBiz.com
Wednesday, April 6, 2016
4/6/16 Weekly Security News: Law Firms and Cyberattacks, Trump Hotels Breached, FBI Cracks iPhone
This week the articles we found cover why law offices are becoming increasingly targeted by cyber-crime, another possible breach of Trump Hotel Collection customers, and what the FBI plans to do with it's methods for breaking into iPhones.
1. 4/1/2016 Security Week: "Why Are Law Firms Targeted by Cyberattacks?"
In this article, Security Week investigates cyber-attacks on
law firms, and what precisely makes them such ideal targets. Clearly with the
amount of personal data they would be high value targets, but other factors,
such as stock market information, could also be fueling attacks on these firms.
Knowing what was purchased by who and at what price could be valuable
information for cyber-thieves looking to play the stock market.
But, as the article says, “The biggest surprise about these
hacks, however, is that there is any surprise at all.” Unfortunately, it seems
law firms are often simply much easier targets to attack than others, as they
often do not invest enough into cyber-security. The author even cites examples
from white-hat hackers breaking into a prestigious law firm, and gaining access
to essentially everything within 48 hours. Being a relatively short time
compared to other possible targets (it took three weeks with a top ten
technology company), it is little wonder that law firms are becoming targets
for hackers.
2. 4/4/2016 Krebs on Security: "Sources: Trump Hotels Breached Again."
It appears that in less than the span of a year, the Trump Hotel Collection has been breached twice. Krebs on Security author Brian Krebs reported that his banking industry sources have noticed patterns indicative of breaches in some or even all of the credit card data of this group of hotels. Krebs was the first to report on the previous incident as well back in July of 2015: a breach that was only confirmed by the hotel management three months later. Hopefully, should this breach prove to be accurate, the Trump Hotel Collection administration will find the source faster and notify their customers of the incident quickly.
3. 4/1/2016 Mac World: "FBI takes heat for keeping iPhone hack under wraps."
Last week, the FBI, assisted by an unnamed party, was reportedly able to crack into the San Bernadino case iPhone, and now they may also be assisting other government branches in breaking into other criminals’ cell phones for use in evidence. The American Civil Liberties Union (ACLU) in particular is adamant that the FBI disclose the methodology to Apple, both to aid in Apple securing their products and to aid in the business’ relationship with the government in the future. The FBI has yet to determine if it will publicly disclose the flaw, disclose the flaw to Apple, or keep the technique to themselves for possible use in the future. At any rate, it shows once more that Apple security is far from perfect, and iPhone users still need to be cautious of what data they process on their phones. If one organization found a way in, other hackers may indeed follow.
2. 4/4/2016 Krebs on Security: "Sources: Trump Hotels Breached Again."
It appears that in less than the span of a year, the Trump Hotel Collection has been breached twice. Krebs on Security author Brian Krebs reported that his banking industry sources have noticed patterns indicative of breaches in some or even all of the credit card data of this group of hotels. Krebs was the first to report on the previous incident as well back in July of 2015: a breach that was only confirmed by the hotel management three months later. Hopefully, should this breach prove to be accurate, the Trump Hotel Collection administration will find the source faster and notify their customers of the incident quickly.
3. 4/1/2016 Mac World: "FBI takes heat for keeping iPhone hack under wraps."
Last week, the FBI, assisted by an unnamed party, was reportedly able to crack into the San Bernadino case iPhone, and now they may also be assisting other government branches in breaking into other criminals’ cell phones for use in evidence. The American Civil Liberties Union (ACLU) in particular is adamant that the FBI disclose the methodology to Apple, both to aid in Apple securing their products and to aid in the business’ relationship with the government in the future. The FBI has yet to determine if it will publicly disclose the flaw, disclose the flaw to Apple, or keep the technique to themselves for possible use in the future. At any rate, it shows once more that Apple security is far from perfect, and iPhone users still need to be cautious of what data they process on their phones. If one organization found a way in, other hackers may indeed follow.
That’s all for this week, check back next Tuesday for
further news from across the web, all here at Astria Horizon. If you want more
information on how Astria Business Solutions can assist you in your Information
Security goals, visit our website at AstriaBiz.com
Friday, April 1, 2016
Malvertising! The overlooked risks in Malicious Ads.
One form of attack that is fairly well known but
unfortunately often overlooked is actually fairly passive, until you engage it
of course. Malicious advertising, also known as “Malvertising,” seeks to trick
users into clicking interesting ads and accidentally allow bad websites to
download malware or spyware onto your system.
Although Malvertising is fairly well known, and many people are
cautious of clicking on just any link, the fact of the matter is that these
attacks still often succeed as they prey on people’s curiosity and
carelessness. Earlier this year, Forbes had an issue where their website was infiltrated by malicious ads, and Astria’s customers have also encountered bad
ads on good websites as recent as last week. So we thought it would be wise to discuss the
Malvertising issue further on Astria Horizon, to educate readers on things to
be aware of.
Malvertising attacks work in a couple different ways, but
one common tactic employed is creating catchy or interesting titles
to draw people in. Some of them are obvious to avoid, offering unrealistic
credit card offers or claiming your system is already infected with viruses.
But some are more subtle, preying on users being curious or genuinely interested
in the topic of discussion.
These generally ads target
individuals that are not aware of the dangers online. One such ad
encountered by Astria in recent weeks offered a slideshow of photographs of
WWII Aircraft, likely targeting older veterans with less online experience.
Young people could be targeted by surprising news about their favorite
celebrities, and other ads can be similarly targeted towards other people. Some
ads even try and blend in with other news or articles on websites in hopes of
users clicking them thinking they are a genuine part of a trusted website.
Once on the bad website, the attackers will try and trick
you into downloading and running malicious software. They could claim you need
a flash player update to view the promised images, or try and scare you into
accidentally downloading malware by claiming your system encountered critical
errors and needs to be repaired. However the ploy goes, once you download and
install a bad file, your system will be infected. TrendMicro has a useful infographic showing how malicious ads can gain a foothold that helps in visualizing these attacks.
It’s important to be aware of these tactics and the tricks
that Malvertisers use, because the more aware you are of them, the better you
can recognize their traps and avoid them. In general, remember that ads that
make promises that are too-good-to-be-true, usually are. And if pages claim you
need to update Java or Flash to use them, update them directly from Adobe or
Oracle. It is best to avoid downloads for these programs except from their
publishers.
The biggest aid in your defense against Malvertising is
really an air of caution. Weigh the risks: Is it worth finding out the latest
in celebrity gossip if it could mean rebuilding your computer? Consider these
things when you encounter suspicious ads and you’ll be much better off in the
long run. There are other, genuine sources for news and articles that interest
you, and it is better to find it there.
Astria Business Solutions also has tools to help prevent
Malvertising from attacking your system, and knows how to deal with infections
if they should occur. For more information on our services, visit our website
at AstriaBiz.com, or you can contact us here.
Subscribe to:
Posts (Atom)





