Twelve years ago, Google introduced a new feature to Google Calendar that allowed users to share their calendars with others. It's a great feature and invaluable in a corporate environment because it gives teams an easy way to collaborate. Google itself even touted the "make it pubic" feature of their calendar as being a cool way to use their search engine to discover upcoming events.
Unfortunately, as with most things, there's a potential downside. Recently, a security researcher named Avinash Jain discovered more than 8,000 publicly accessible Google Calendars, searchable via Google's own search engine. Many of these calendars contain sensitive information (which is bad enough), but worse, they allow any user to add new events that can cause real harm to the system hosting the calendar. This is done via maliciously crafted events or poisoned links.
As Avinash Jain reports:
"I was able to access public calendars of various organizations leaking out sensitive details like their email IDs, their event name, event details, location, meeting links, zoom meeting links, google hangout links, and much, much more.
This is more of an intended setting by the users and intended behavior of the service. The main issue however, is that anyone can view anyone's public calendar, add anything on it - just by a single search query without being shared the calendar link.
Jain goes onto say that several calendars belonging to many of the top 500 Alexa company's employees were made public, which is certainly cause for concern.
This most recent finding adds to the chorus already warning of the dangers of calendar sharing. Just a few months ago, researchers from Kaspersky Lab discovered scammers abusing Google Calendar in a variety of ways. For example, there were phishing scams that contained poisoned links masquerading as google calendar event links.
Stay vigilant and be sure you have all employees check their Google Calendar security settings so you're not revealing more than you intended to.
It is also crucial to make sure that your computers or the entire business network is not in any way at risk of any kind of online breach. Call SpartanTec, Inc. in Greenville now and let our team set up and efficient strategy to protect your business.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Friday, September 27, 2019
Saturday, September 14, 2019
Hackers Are Using Resumes To Deliver Malicious Software
Hackers have used poisoned documents to deliver malware payloads for years. Recently though, researchers at the security company Cofense have spotted a new twist to the ploy, aimed squarely at HR departments. The recently detected campaign uses fake resume attachments to deliver Quasar Remote Administration Tool. It is affectionately known as RAT to any unsuspecting Windows user who can be tricked into jumping through a few hoops.
Here's how it works:
An email containing a document that appears to be a resume is sent to someone in a given company. The document is password protected, but the password is politely included in the body of the email, and is usually something simple like '123.' If the user enters the password, a popup box will appear, asking the user if he/she wants to enable macros.
Up to this point, the attack is fairly standard, but here's where it gets interesting:
If the macros are allowed to run, they'll display a series of images and a message announcing that content is loading. What it's actually doing is throwing out garbage code that's designed to crash analysis and detection tools while RAT is installed quietly in the background.
At that point, the system is compromised. RAT's capabilities give the hackers the ability to open remote desktop connections, log keystrokes and steal passwords, record any webcams in use, download files, and capture screenshots of the infected machine.
Worst of all, the first part of the infection process knocks out most detection programs. So, the hackers generally have a large window of time to take advantage of the newly created beach head. That can cause all manner of havoc in your network or simply choose to quietly siphon proprietary data from your systems.
Be on the alert and make sure your HR staff is aware. This is a nasty campaign and it's just hitting stride.
These kind of attacks can be prevented. The IT Management Services of SpartanTec, Inc. will work with your HR department to ensure the resumes they are receiving are free of any harmful malware. Contact us today for a consultation.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Friday, August 16, 2019
How Can You Secure Your Computer From Hackers?
Back in the 1990’s, computer users have started to notice
the disadvantages of the internet and many of them didn’t like what they saw. Email
accounts were bombarded with tons of spam while business networks were plagued
with various computer viruses. A scary criminal component came about that
widened the definition of robbery to a whole new level. It now includes
infiltrating the computer, stealing personal details, duping you to revealing
personal details, as well as using that information to extort and steal
everything from your bank account, identity, and down to your business secrets.
Despite all that, small and large businesses depend on the
internet to monitor their orders, financials, and their inventory as well as
perform PR campaigns and marketing, connect with clients, participate in social
media, and conduct other important business operations. However, there’s been a
lot of reports about computer breaches in different companies including those
that are already at the top of the ladder. Small companies are responsible when
it comes to the prevention of such crimes so that company property is not
harmed and consumer information is not stolen. A few steps to ensure computersecurity and protect your integrity are listed below.
Use a Firewall
Two of the biggest computer operating systems come with
built in firewalls,
software that were made to develop a barrier between the outside world and your
information. They prevent unauthorized access to your company’s network and
notify you of any attempt of intrusion.
Install Anti-Virus
Trojans, keyloggers, and computer
viruses are all around. Anti-virus
programs like Avast and Malwarebytes work by immunizing your computer against
any software that will threaten the operating system or any unauthorized code.
Viruses can have different effects that might be quite easy to identify. They
may slow down your computer or in some cases delete or halt key files.
Install Anti-Spyware Package
Spyware is a specialized type of software that will collect
and monitor your organizational or personal information secretly. It is
designed to be difficult to detect and remove. It also tends to serve up
undesired adverts or search results that will direct you to malicious websites.
Use Complex Passwords
One important way of preventing illegal intrusions onto your
computer and your network is to use secure and complex passwords. It will be
harder for a hacker to invade your computer if you use more secure passwords. It
is not a good idea to use obvious combinations or words that will represent
common things like your birthday or any basic information that could be easily connected
to you.
Update Your OS, Browser, and Apps
You should always install updates to your computer’s
operating system. The majority of updates include security
patches that will stop hackers from gaining access and exploiting your personal
or business information. This also applies to your favorite apps.
Ignore Spam
You should be careful of emails that come from unknown
parties and don’t click on the links or even open attachments that on the
email. Over the years, spam catchers have upped their game and have become
extremely effective at catching spam. But you still need to be very careful.
The threats to your computer, personal and business information are everywhere. Never let your guard down and always make sure that effective security measures are in place to protect your network and company in general. Call SpartanTec, Inc. now and let our team determine if your network is at risk and what measures can be taken to protect your company.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Wednesday, August 7, 2019
Equifax Breach Victims Could Be Entitled To Settlement Claims
Equifax is one of the three credit reporting firms in the US that suffered a massive data breach in 2017 that exposed the personal and financial state of literally half the country (more than 150 million people). As a result, Equifax was ordered to pay a hefty $700 million fine to settle a series of Federal and State investigations. While the size of the fine sounds impressive, digging a bit deeper reveals it to be a bit underwhelming.
Only $425 million of that fine will go into a fund designed to actually reimburse impacted customers. However, Equifax will be allowed to earmark an unspecified portion of that to provide free credit monitoring services to anyone who was impacted by the breach.
Here's the problem: Free Credit Monitoring is actually a money-maker for Equifax because of the way the "free" service is offered. It's free for a year, and then automatically converts to a paid service. Given that most people don't pay close attention to that sort of thing, a significant percentage of customers will continue paying Equifax for their credit monitoring service, which essentially sees the company profiting from their own data breach.
In any case, impacted customers will be eligible for a small amount of money from Equifax if their data was compromised. The company is on the hook for paying some $300 million in fines and civil penalties across 50 states and to the Consumer Financial Protection Bureau.
On top of that, the company has been ordered to provide all American consumers, (whether they were impacted by the breach or not), six free credit reports each for the next seven years. This is in addition to the one free annual credit report they already get beginning in January 2020.
It's a decent settlement, but it lets Equifax off the hook too easily. That is especially true given that they can turn one of the largest data breaches in American history into a profit center. The CFPB could have and should have demanded more.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Only $425 million of that fine will go into a fund designed to actually reimburse impacted customers. However, Equifax will be allowed to earmark an unspecified portion of that to provide free credit monitoring services to anyone who was impacted by the breach.
Here's the problem: Free Credit Monitoring is actually a money-maker for Equifax because of the way the "free" service is offered. It's free for a year, and then automatically converts to a paid service. Given that most people don't pay close attention to that sort of thing, a significant percentage of customers will continue paying Equifax for their credit monitoring service, which essentially sees the company profiting from their own data breach.
In any case, impacted customers will be eligible for a small amount of money from Equifax if their data was compromised. The company is on the hook for paying some $300 million in fines and civil penalties across 50 states and to the Consumer Financial Protection Bureau.
On top of that, the company has been ordered to provide all American consumers, (whether they were impacted by the breach or not), six free credit reports each for the next seven years. This is in addition to the one free annual credit report they already get beginning in January 2020.
It's a decent settlement, but it lets Equifax off the hook too easily. That is especially true given that they can turn one of the largest data breaches in American history into a profit center. The CFPB could have and should have demanded more.
Call SpartanTec, Inc. if you want to make sure that your network is secured against potential online breach.
SpartanTec, Inc.Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Tuesday, July 30, 2019
Android Malware Can Replace Real Apps With Fake Apps
Security researchers at Check Point have discovered a disturbing new strain of Android malware that's as ingenious as it is disturbing. It is effective because it is designed to replace a rapidly expanding number of apps with poisoned copies.
The app copies still retain their core functionality, making the malware notoriously difficult to detect.
After all, if you downloaded JioTV, a photo editing app of some kind, or a game, and the app works as you expect it to, why would you even suspect that it was malware? Unfortunately, that's exactly what this new malware strain does.
Dubbed 'Agent Smith,' the malware takes advantage of different android vulnerabilities and injects malicious code into the APK files of targeted apps defined by a list inside the code. They then automatically update and re-install them without the device owner's knowledge or consent.
The Check Point researchers had this to say about the new strain:
"It's not enough for this malware family to swap just one innocent application with an infected double. It does so for each and every app on the device, as long as the package names are on its prey list.
Over time, this campaign will also infect the same device repeatedly, with the latest malicious patches. This leads us to estimate there are to be over 2.8 billion infections in total, on around 25 million unique devices, meaning that on average, each victim would have suffered roughly 112 swaps of innocent applications."
Of course, the last thing the malware's creators want is for the app to be legitimately updated. So part of the strain's design is to disable that functionality from inside the app so the hackers can control the updates.
If there's a silver lining, it is that to date, the malware doesn't contain any data siphoning or data destroying code. All it does is display ads. Unfortunately, the malware strain's owners can easily shift gears any time they want to.
Call SpartanTec, Inc. for details on how to keep your information safe.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
The app copies still retain their core functionality, making the malware notoriously difficult to detect.
After all, if you downloaded JioTV, a photo editing app of some kind, or a game, and the app works as you expect it to, why would you even suspect that it was malware? Unfortunately, that's exactly what this new malware strain does.
Dubbed 'Agent Smith,' the malware takes advantage of different android vulnerabilities and injects malicious code into the APK files of targeted apps defined by a list inside the code. They then automatically update and re-install them without the device owner's knowledge or consent.
The Check Point researchers had this to say about the new strain:
"It's not enough for this malware family to swap just one innocent application with an infected double. It does so for each and every app on the device, as long as the package names are on its prey list.
Over time, this campaign will also infect the same device repeatedly, with the latest malicious patches. This leads us to estimate there are to be over 2.8 billion infections in total, on around 25 million unique devices, meaning that on average, each victim would have suffered roughly 112 swaps of innocent applications."
Of course, the last thing the malware's creators want is for the app to be legitimately updated. So part of the strain's design is to disable that functionality from inside the app so the hackers can control the updates.
If there's a silver lining, it is that to date, the malware doesn't contain any data siphoning or data destroying code. All it does is display ads. Unfortunately, the malware strain's owners can easily shift gears any time they want to.
Call SpartanTec, Inc. for details on how to keep your information safe.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Friday, July 26, 2019
How To Protect the Data Of Your Clients and Company
Having sensitive information regarding customers and clients
is crucial, however ensuring that private details stays secure may be just as
important to the health of a small business. Several small businesses aren’t
that ready for the tricks hackers use to get data from information units or to
handle the fallout from such as event. As a matter of fact, hackers consider
small businesses as attractive targets compared to bigger companies since they
do not invest as many resources in their information security.
This holds true for those companies that provide services to bigger firms. So
how do you protect the data of your clients, employees, and company as well?
Data protection Tips For Better Information Security
In case you collect
it, you should protect it.
You need set in place and adhere to security measures to
make sure that the personal information of employees and customers are protection
from unauthorized and inappropriate access.
Set up a strong
privacy policy.
Clients have to know that you are doing your best to protect
their information. Be sure that you have a privacy policy set in
place so they have something to refer to if they want to know how you are
keeping their personal details safe and secure. Don’t forget to be
straightforward with clients regarding their consumer data that you collect and
whatever it is that you are doing with their information. By being honest, you
will be able to build trust and you will show your clients that their data is
important to you and that you are doing all that you can to protect it.
You need to know what
you are trying to protect.
You have to know what information you have, where it is
stored, how it is used, and who can access it. Know the type of assets you may
have and the reasons hackers may have to want to get them.
Never underestimate
the threat.
Most small business owners think that only larger
enterprises are at risk. But the truth is, there have been instances when small
businesses lost thousands because of cyber criminals.
Don’t keep what you
don’t need.
The more sensitive information you keep, the more at risk
your company will be. Don’t use social security numbers as well as other
crucial information to identify your clients. Instead of using these info, why
don’t you go for log in identifications as well as passwords? You can prevent
attackers from simulating users if you have several layers of identification.
Delete any other information that you don’t need.
Keep your machine
clean.
Be sure that you have installed the latest anti-virus
program, web browser, as well as operating system. These are among the most
effective defences against malware, viruses, and other kinds of online threats.
Several software will connect and update automatically to protect your system
against known risks. Switch on automatic updates if ever you have that option.
Install multiple security
layers.
Spam filters and email
protection can weed out phishing scams and malware, which are mostly aimed
directly at companies, regardless of the size.
Do you want to know if your information, computers, and networks are at risk? Let our team at SpartanTec, Inc. help you. Call us now for more details.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Wednesday, July 17, 2019
Stop Ransomware Attacks With Network Segregation, Segmentation
There has been lots of ransomware attacks against
organizations in the healthcare industry over the past years. In some cases,
there have been devastating consequences. Fortunately, network segmentation and
segregation can help.
From patient data that have been compromised to EHR
downtime, such cyberattacks could disrupt the facility’s operation
significantly. Network segmentation and network segregation are measures that
can assist in mitigating the risks from such typical attacks. The separation of
important networks from internal network, less sensitive networks, or from the
internet is referred to as network segregation. Meanwhile, network
segmentation, involves dividing the bigger network to smaller ones. This can be
achieved through virtual local area networks, firewalls,
as well as other separation methods.
Both of these approaches can stop ransomware attacks that
will encrypt files on your network, restrict access to those files, and bring
the victim to a web page and given instructions on how they can pay a ransom
using bitcoin so they can unlock their files. How can healthcare firms and
organizations create and implement such measures to protect their data and
infrastructure from such attacks?
Network Segregation
and Network Segregation
One effective way of prevent ransomware attacks is air
gapping, which involves separating the network from internal networks that may
be unsecured and from the internet. This measure could create usability problems
within the firm.
Network segmentation is another solution that is network based.
It involves dividing bigger networks into smaller segments using separation
techniques such as VLANs or virtual
local area networks. Function can be used as a basis when segmenting
networks like splitting human resources from finance. It can also be done by
data like separating non regulated data from PHI. Segmentation will lay down
the ground work for controls that offer protection from lateral movement on the
network by hackers or ransomware, thus preventing compromise or infection from
being spread across your organization’s network.
Organizations have to make sure that they perform patches to
lessen their vulnerability, install antivirus software, and follow only the
best practices when it comes to cybersecurity hygiene. They should also train
their workforce, use email
protection, and updated antivirus
software. Ransomware will continue to be a threat to the healthcare
industry into the near future. There are things organizations can take to
prevent ransomware from infecting their network and decrease the damage in case
a ransomware attack succeeds at first. Network segmentation and network
segregation are two methods that healthcare organizations can take to mitigate
the risk of encountering ransomware. They may be costly or complex but they can
save organizations from the damage in their system, finances, and reputation as
well as patient risk that a ransomware attack will result in.
Call SpartanTec, Inc. if you need help in making sure that your organization and network is safe against ransomware attacks.
SpartanTec, Inc.
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Greenville, SC 29601
(864) 326-5914
Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer
Subscribe to:
Posts (Atom)






