Friday, September 27, 2019

Your Google Calendar Settings May Be Sharing Your Info

Twelve years ago, Google introduced a new feature to Google Calendar that allowed users to share their calendars with others.  It's a great feature and invaluable in a corporate environment because it gives teams an easy way to collaborate.  Google itself even touted the "make it pubic" feature of their calendar as being a cool way to use their search engine to discover upcoming events.

Unfortunately, as with most things, there's a potential downside.  Recently, a security researcher named Avinash Jain discovered more than 8,000 publicly accessible Google Calendars, searchable via Google's own search engine.  Many of these calendars contain sensitive information (which is bad enough), but worse, they allow any user to add new events that can cause real harm to the system hosting the calendar. This is done via maliciously crafted events or poisoned links.

As Avinash Jain reports:

"I was able to access public calendars of various organizations leaking out sensitive details like their email IDs, their event name, event details, location, meeting links, zoom meeting links, google hangout links, and much, much more.

This is more of an intended setting by the users and intended behavior of the service. The main issue however, is that anyone can view anyone's public calendar, add anything on it - just by a single search query without being shared the calendar link.

Jain goes onto say that several calendars belonging to many of the top 500 Alexa company's employees were made public, which is certainly cause for concern.

This most recent finding adds to the chorus already warning of the dangers of calendar sharing.  Just a few months ago, researchers from Kaspersky Lab discovered scammers abusing Google Calendar in a variety of ways. For example, there were phishing scams that contained poisoned links masquerading as google calendar event links.

Stay vigilant and be sure you have all employees check their Google Calendar security settings so you're not revealing more than you intended to.

It is also crucial to make sure that your computers or the entire business network is not in any way at risk of any kind of online breach. Call SpartanTec, Inc. in Greenville now and let our team set up and efficient strategy to protect your business.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Saturday, September 14, 2019

Hackers Are Using Resumes To Deliver Malicious Software


Hackers have used poisoned documents to deliver malware payloads for years. Recently though, researchers at the security company Cofense have spotted a new twist to the ploy, aimed squarely at HR departments. The recently detected campaign uses fake resume attachments to deliver Quasar Remote Administration Tool. It is affectionately known as RAT to any unsuspecting Windows user who can be tricked into jumping through a few hoops.

Here's how it works:

An email containing a document that appears to be a resume is sent to someone in a given company.  The document is password protected, but the password is politely included in the body of the email, and is usually something simple like '123.' If the user enters the password, a popup box will appear, asking the user if he/she wants to enable macros.

Up to this point, the attack is fairly standard, but here's where it gets interesting:

If the macros are allowed to run, they'll display a series of images and a message announcing that content is loading.  What it's actually doing is throwing out garbage code that's designed to crash analysis and detection tools while RAT is installed quietly in the background.

At that point, the system is compromised. RAT's capabilities give the hackers the ability to open remote desktop connections, log keystrokes and steal passwords, record any webcams in use, download files, and capture screenshots of the infected machine.

Worst of all, the first part of the infection process knocks out most detection programs. So, the hackers generally have a large window of time to take advantage of the newly created beach head. That can cause all manner of havoc in your network or simply choose to quietly siphon proprietary data from your systems.

Be on the alert and make sure your HR staff is aware.  This is a nasty campaign and it's just hitting stride.

These kind of attacks can be prevented. The IT Management Services of SpartanTec, Inc. will work with your HR department to ensure the resumes they are receiving are free of any harmful malware. Contact us today for a consultation.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Friday, August 16, 2019

How Can You Secure Your Computer From Hackers?


Back in the 1990’s, computer users have started to notice the disadvantages of the internet and many of them didn’t like what they saw. Email accounts were bombarded with tons of spam while business networks were plagued with various computer viruses. A scary criminal component came about that widened the definition of robbery to a whole new level. It now includes infiltrating the computer, stealing personal details, duping you to revealing personal details, as well as using that information to extort and steal everything from your bank account, identity, and down to your business secrets.

Despite all that, small and large businesses depend on the internet to monitor their orders, financials, and their inventory as well as perform PR campaigns and marketing, connect with clients, participate in social media, and conduct other important business operations. However, there’s been a lot of reports about computer breaches in different companies including those that are already at the top of the ladder. Small companies are responsible when it comes to the prevention of such crimes so that company property is not harmed and consumer information is not stolen. A few steps to ensure computersecurity and protect your integrity are listed below.

Use a Firewall

Two of the biggest computer operating systems come with built in firewalls, software that were made to develop a barrier between the outside world and your information. They prevent unauthorized access to your company’s network and notify you of any attempt of intrusion.

Install Anti-Virus

Trojans, keyloggers, and computer viruses are all around. Anti-virus programs like Avast and Malwarebytes work by immunizing your computer against any software that will threaten the operating system or any unauthorized code. Viruses can have different effects that might be quite easy to identify. They may slow down your computer or in some cases delete or halt key files.

Install Anti-Spyware Package

Spyware is a specialized type of software that will collect and monitor your organizational or personal information secretly. It is designed to be difficult to detect and remove. It also tends to serve up undesired adverts or search results that will direct you to malicious websites.

Use Complex Passwords

One important way of preventing illegal intrusions onto your computer and your network is to use secure and complex passwords. It will be harder for a hacker to invade your computer if you use more secure passwords. It is not a good idea to use obvious combinations or words that will represent common things like your birthday or any basic information that could be easily connected to you.

Update Your OS, Browser, and Apps

You should always install updates to your computer’s operating system. The majority of updates include security patches that will stop hackers from gaining access and exploiting your personal or business information. This also applies to your favorite apps.

Ignore Spam

You should be careful of emails that come from unknown parties and don’t click on the links or even open attachments that on the email. Over the years, spam catchers have upped their game and have become extremely effective at catching spam. But you still need to be very careful.

The threats to your computer, personal and business information are everywhere. Never let your guard down and always make sure that effective security measures are in place to protect your network and company in general. Call SpartanTec, Inc. now and let our team determine if your network is at risk and what measures can be taken to protect your company.



SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Wednesday, August 7, 2019

Equifax Breach Victims Could Be Entitled To Settlement Claims

Equifax is one of the three credit reporting firms in the US that suffered a massive data breach in 2017 that exposed the personal and financial state of literally half the country (more than 150 million people). As a result, Equifax was ordered to pay a hefty $700 million fine to settle a series of Federal and State investigations. While the size of the fine sounds impressive, digging a bit deeper reveals it to be a bit underwhelming.

Only $425 million of that fine will go into a fund designed to actually reimburse impacted customers. However, Equifax will be allowed to earmark an unspecified portion of that to provide free credit monitoring services to anyone who was impacted by the breach.

Here's the problem:  Free Credit Monitoring is actually a money-maker for Equifax because of the way the "free" service is offered.  It's free for a year, and then automatically converts to a paid service.  Given that most people don't pay close attention to that sort of thing, a significant percentage of customers will continue paying Equifax for their credit monitoring service, which essentially sees the company profiting from their own data breach.

In any case, impacted customers will be eligible for a small amount of money from Equifax if their data was compromised. The company is on the hook for paying some $300 million in fines and civil penalties across 50 states and to the Consumer Financial Protection Bureau.

On top of that, the company has been ordered to provide all American consumers, (whether they were impacted by the breach or not), six free credit reports each for the next seven years. This is in addition to the one free annual credit report they already get beginning in January 2020.

It's a decent settlement, but it lets Equifax off the hook too easily. That is especially true given that they can turn one of the largest data breaches in American history into a profit center.  The CFPB could have and should have demanded more.

Call SpartanTec, Inc. if you want to make sure that your network is secured against potential online breach.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914

Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Tuesday, July 30, 2019

Android Malware Can Replace Real Apps With Fake Apps

Security researchers at Check Point have discovered a disturbing new strain of Android malware that's as ingenious as it is disturbing. It is effective because it is designed to replace a rapidly expanding number of apps with poisoned copies.

The app copies still retain their core functionality, making the malware notoriously difficult to detect.

After all, if you downloaded JioTV, a photo editing app of some kind, or a game, and the app works as you expect it to, why would you even suspect that it was malware?  Unfortunately, that's exactly what this new malware strain does.

Dubbed 'Agent Smith,' the malware takes advantage of different android vulnerabilities and injects malicious code into the APK files of targeted apps defined by a list inside the code. They then automatically update and re-install them without the device owner's knowledge or consent.

The Check Point researchers had this to say about the new strain:

"It's not enough for this malware family to swap just one innocent application with an infected double.  It does so for each and every app on the device, as long as the package names are on its prey list.

Over time, this campaign will also infect the same device repeatedly, with the latest malicious patches.  This leads us to estimate there are to be over 2.8 billion infections in total, on around 25 million unique devices, meaning that on average, each victim would have suffered roughly 112 swaps of innocent applications."

Of course, the last thing the malware's creators want is for the app to be legitimately updated. So part of the strain's design is to disable that functionality from inside the app so the hackers can control the updates.

If there's a silver lining, it is that to date, the malware doesn't contain any data siphoning or data destroying code.  All it does is display ads.  Unfortunately, the malware strain's owners can easily shift gears any time they want to.

Call SpartanTec, Inc. for details on how to keep your information safe.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914

Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Friday, July 26, 2019

How To Protect the Data Of Your Clients and Company


Having sensitive information regarding customers and clients is crucial, however ensuring that private details stays secure may be just as important to the health of a small business. Several small businesses aren’t that ready for the tricks hackers use to get data from information units or to handle the fallout from such as event. As a matter of fact, hackers consider small businesses as attractive targets compared to bigger companies since they do not invest as many resources in their information security. This holds true for those companies that provide services to bigger firms. So how do you protect the data of your clients, employees, and company as well?

Data protection Tips For Better Information Security


In case you collect it, you should protect it.

You need set in place and adhere to security measures to make sure that the personal information of employees and customers are protection from unauthorized and inappropriate access.

Set up a strong privacy policy.

Clients have to know that you are doing your best to protect their information. Be sure that you have a privacy policy set in place so they have something to refer to if they want to know how you are keeping their personal details safe and secure. Don’t forget to be straightforward with clients regarding their consumer data that you collect and whatever it is that you are doing with their information. By being honest, you will be able to build trust and you will show your clients that their data is important to you and that you are doing all that you can to protect it.

You need to know what you are trying to protect.

You have to know what information you have, where it is stored, how it is used, and who can access it. Know the type of assets you may have and the reasons hackers may have to want to get them.
Never underestimate the threat.

Most small business owners think that only larger enterprises are at risk. But the truth is, there have been instances when small businesses lost thousands because of cyber criminals.

Don’t keep what you don’t need.

The more sensitive information you keep, the more at risk your company will be. Don’t use social security numbers as well as other crucial information to identify your clients. Instead of using these info, why don’t you go for log in identifications as well as passwords? You can prevent attackers from simulating users if you have several layers of identification. Delete any other information that you don’t need.

Keep your machine clean.

Be sure that you have installed the latest anti-virus program, web browser, as well as operating system. These are among the most effective defences against malware, viruses, and other kinds of online threats. Several software will connect and update automatically to protect your system against known risks. Switch on automatic updates if ever you have that option.

Install multiple security layers.

Spam filters and email protection can weed out phishing scams and malware, which are mostly aimed directly at companies, regardless of the size.

Do you want to know if your information, computers, and networks are at risk? Let our team at SpartanTec, Inc. help you. Call us now for more details. 

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer

Wednesday, July 17, 2019

Stop Ransomware Attacks With Network Segregation, Segmentation


There has been lots of ransomware attacks against organizations in the healthcare industry over the past years. In some cases, there have been devastating consequences. Fortunately, network segmentation and segregation can help.

From patient data that have been compromised to EHR downtime, such cyberattacks could disrupt the facility’s operation significantly. Network segmentation and network segregation are measures that can assist in mitigating the risks from such typical attacks. The separation of important networks from internal network, less sensitive networks, or from the internet is referred to as network segregation. Meanwhile, network segmentation, involves dividing the bigger network to smaller ones. This can be achieved through virtual local area networks, firewalls, as well as other separation methods.

Both of these approaches can stop ransomware attacks that will encrypt files on your network, restrict access to those files, and bring the victim to a web page and given instructions on how they can pay a ransom using bitcoin so they can unlock their files. How can healthcare firms and organizations create and implement such measures to protect their data and infrastructure from such attacks?

Network Segregation and Network Segregation

One effective way of prevent ransomware attacks is air gapping, which involves separating the network from internal networks that may be unsecured and from the internet. This measure could create usability problems within the firm.

Network segmentation is another solution that is network based. It involves dividing bigger networks into smaller segments using separation techniques such as VLANs or virtual local area networks. Function can be used as a basis when segmenting networks like splitting human resources from finance. It can also be done by data like separating non regulated data from PHI. Segmentation will lay down the ground work for controls that offer protection from lateral movement on the network by hackers or ransomware, thus preventing compromise or infection from being spread across your organization’s network.

Organizations have to make sure that they perform patches to lessen their vulnerability, install antivirus software, and follow only the best practices when it comes to cybersecurity hygiene. They should also train their workforce, use email protection, and updated antivirus software. Ransomware will continue to be a threat to the healthcare industry into the near future. There are things organizations can take to prevent ransomware from infecting their network and decrease the damage in case a ransomware attack succeeds at first. Network segmentation and network segregation are two methods that healthcare organizations can take to mitigate the risk of encountering ransomware. They may be costly or complex but they can save organizations from the damage in their system, finances, and reputation as well as patient risk that a ransomware attack will result in.

Call SpartanTec, Inc. if you need help in making sure that your organization and network is safe against ransomware attacks.

SpartanTec, Inc.
Greenville, SC  29601
(864) 326-5914


Cities Served
Greenville, Spartansburg, Mauldin, East Park, Overbrook, West Greenville, Greer