Blogs Archives - Page 22 of 63 - D1 Defend D1 Defend

Blogs Archives - Page 22 of 63 - D1 Defend D1 Defend

x

Threat Intelligence: The Ever-Present Danger of Supply Chain Attacks

Posted: December 8, 2023

The situation with the Citrix Bleed vulnerability has escalated.   

At least 60 credit unions across the U.S. have been knocked offline by a ransomware attack against their 3rd party cloud provider in the past few days. Citrix Bleed was the attacker’s way in, but this email isn’t just about another vulnerability.  

This email is about something far worse: supply chain attacks! We’re seeing case after case of devastating supply chain attacks that are crippling critical infrastructure, leaving everyday businesses as victims. 

One of the largest examples of this unfolded on July 2, 2021 against Kaseya, a Miami-based software company, a case that brings into focus the level of damage that can be inflicted by a supply-chain attack.  That attack against Kaseya disrupted nurseries, schools, pharmacies, and supermarkets in 17 countries.  Millions of people were impacted. 

Supply chain attacks are tricky because they work through existing relationships, and you can’t simply block them. Your MSP’s reputation is on the line, and guess what?  If hackers use you to get to your clients, your clients are in danger because of you. So, if you don’t take proactive steps, you’ve unknowingly added trojan horse software to your whitelists. 

Throughout 2023 we’ve seen attack after attack.  You may remember some of the major ones: 

  • February 2023 – Applied Materials Supply Chain Attack: A key partner of Applied Materials was targeted, causing a staggering $250 million loss in Q1 2023. This caused significant shipment delays and financial turmoil! 
  • February 2023 – University of San Francisco Attack: Imagine a doctor not being able to operate because of a system being offline for several days. Staff members were unable to access records or schedule surgeries and personal information belonging to clinical trial participants was stolen.  
  • March 2023 – 3CX Supply Chain Attack: Malware was silently delivered to and hidden in a number of client organizations. It acted as a ticking time bomb, with the hackers in control of the detonator switch.
  • June 2023 – MOVEit Supply Chain Attack: Personal data and flight safety was compromised in a massive breach, compromising travel security for thousands. 

Supply Chain Attacks are no joke. We anticipate more issues around supply chain attacks with entry ways such as the Citrix Bleed vulnerability. 

Once you deploy a product, your vendor is given unchecked access to your network. You need to commit to becoming vigilant and increasing the readiness of your MSP and your clients. 

What’s the solution? Start by using a Level 1 pen test to see if you find any vulnerabilities in your client’s environment. 

Then, meet with the client to establish a recurring cadence with comprehensive, Level 3 pen tests that demonstrate supply chain attack vectors. One weak link can totally devastate your reputation, and it’s important that you’re not blindsided by that reality. 

Having a comprehensive test done regularly is the major line of defense to stop a supply chain compromise. You can use your quarterly meetings to guide clients to go from basic defense to a powerful shield of defense in layers

As you continue to prepare your clients to survive a supply chain risk in the New Year, we want you to know that we’ve got your back. We’ll be adding additional details related to supply chain attacks in our pen test findings to ensure you don’t become a victim of a hacker with unchecked control over your clients. 

Please, don’t ignore this invisible threat, reach out to your PSM about recurring Level 3 pen tests for you and your clients today before a mistake that some other company made becomes your problem. 

Contact Us Today!

Patched Microsoft Outlook Vulnerability

Microsoft recently fixed a serious security flaw in Outlook that scored a 9.8 on the Common Vulnerability Scoring System.

This flaw, CVE-2023-2339, is a zero-click vulnerability. It could let hackers steal sensitive information from user accounts and send malicious emails as if they were the user.

The CVE-2023-2339 flaw affects all supported Windows Outlook versions. However, Outlook on the web, Android, iOS, Mac, and Microsoft 365 services are unaffected.

How the Security Flaw Works

The flaw comes from a Microsoft Outlook feature that allows users to customize their
notification sounds. The problem is that the audio file is on a remote server.

Cybercriminals can send malicious emails posing as calendar invites. The victim’s computer then loads the notification sound from a server controlled by the threat actor.

This can expose login credentials, which the hacker can use for unauthorized access.

The victim doesn’t even have to do anything for this to happen. When Outlook gets the
malicious email, it automatically starts the process remotely.

Protecting Your Business

The first step is to install the latest security update for Microsoft Outlook. For now, you should also limit using the New Technology LAN Manager (NTLM).

Companies can also block outbound SMB traffic over port 445. This will help prevent
unauthorized access.

Microsoft has also released an audit tool to help businesses determine if there was a breach.

Actionable Steps for Business Owners

To protect your business and customers from this Microsoft Outlook security flaw, consider these proactive steps:

1. Educate staff about the importance of security updates.
2. Keep Microsoft Outlook installations updated with the latest patches.
3. Monitor network traffic and block unauthorized connections.
4. Encourage strong, unique passwords and install multi-factor authentication (MFA).
5. Regularly review and update cybersecurity policies and practices.

These strategies help address potential cyber threats and keep your business data secure.

Cybercriminals can use the weakness in Microsoft Outlook to steal sensitive information and pose as users. This is a big risk for businesses.

Owners must act quickly to secure their systems and protect their customers. Use the steps above to avoid potential threats and keep your computer system safe.

Used with permission from Article Aggregator

How Cybercriminals are Exploiting the Silicon Valley Bank Shutdown

Recently, there was a rise in cybercrimes related to the closing of Silicon Valley Bank (SVB). Threat actors go after businesses and sometimes use them in their illegal activities.

SVB was the 16th largest bank in the U.S. The bank worked with tech giants like Buzzfeed, Roblox, and Roku. However, global inflation and a deposit run caused regulators to close the bank on Friday, March 10, 2023.

Hackers are using SVB-related content to manipulate people’s emotions. Analysts are finding more phishing attacks connected to the SVB closure, and new threats appear daily.

How Hackers Set Up SVB-related Attacks

Cybercriminals started buying fake SVB domains shortly after SVB closed. This is how they set up their SVB-related attacks. The attackers then made and tested phishing flows before starting their campaigns.

More than 62 new domains were set up for SVB-related attacks, and there were 200 phishing scams, most of which targeted businesses in the U.S.

The Public Response Helped Hackers

Unfortunately, the public’s response to the SVB crisis may have been unwittingly aiding cybercriminals. Attackers used websites that listed affected SVB customers to find targets.

Also, emails from companies switching to new banks can look like phishing emails, which can cause confusion and make the risks higher.

Getting Ready for the Wave of SVB Fraud

To counter SVB-related attacks and protect your business, you should:

1. Raise employee awareness about phishing and cyber threats.
2. Provide regular security training.
3. Implement email security solutions with anti-phishing features.
4. Use multi-factor authentication.
5. Keep software updated to prevent vulnerabilities.
6. Encourage strong, unique passwords and start using password managers.
7. Monitor the company’s online presence for fake domains or websites.
8. Develop and maintain an incident response plan.
9. Periodically review and update security processes.
10. Collaborate with cybersecurity experts for audits and vulnerability assessments.

The recent failure of SVB has given cybercriminals a chance to take advantage of businesses and individuals. To protect yourself from SVB-related attacks and other cyber threats, you need to put cybersecurity at the top of your list of priorities.

You can shield your company from these attacks by being proactive, improving security infrastructure, and using your resources wisely.

Used with permission from Article Aggregator

Using Technology to Improve Employee Productivity

It is crucial to make the most of available technology to stay ahead of the competition in today’s fast-paced business environment. As a result, business owners are always searching for ways to increase efficiency and employee productivity. Here are some tips and strategies for using technology to boost employee productivity.

Project Management Tools
Project management tools provide a clear and organized view of tasks and progress. Using a project management tool, teams can stay on schedule and meet deadlines while maintaining efficient communication between team members. In addition, employees can share updates, feedback, and files quickly and easily.

Virtual Assistants
With virtual assistants, routine tasks can be automated, allowing employees to devote more time to other critical tasks. As a result, employees can focus on high-value work when a virtual assistant schedules appointments, sends reminders and responds to emails.

Collaboration Tools
Collaboration tools allow employees to communicate and collaborate in real-time, regardless of location. In addition to reducing the time required to complete tasks, collaboration tools enable teams to share information and updates in one centralized location.

Time-Tracking Software
With time-tracking software, employees can track how much time they spend on various projects and tasks. By analyzing this information, managers can identify areas where they increase productivity.

Cloud Computing
A cloud computing solution allows employees to access their work files from any location and device, allowing them to work at home or on the go. In addition, cloud computing allows teams to collaborate and share files regardless of location, facilitating a more efficient work-life balance.

Technology is critical to increasing employee productivity. By leveraging technology, business owners can maximize employee productivity while collaborating with customers. In addition, by taking advantage of modern technological advances, business owners can gain an edge over their competitors.

Used with permission from Article Aggregator

Firefox 111 Boosts Security, Fixes Bugs, and Adds New Features

Mozilla has released a new version of Firefox for Android, equipping it with a built-in PDF viewer. Firefox 111 also provides a more secure experience for users through its Total Cookie Protection feature. In addition, the upgrade addresses the security issues and unusual bugs in the last version.

Android Users Finally Have Total Cookie Protection on Firefox

In 2021, Mozilla launched Total Cookie Protection for incognito Windows. It was an optional feature that users could turn on. In 2022, the company rolled it out to all Mac and Windows users. It enabled the security feature by default for all Windows. A year later, Mozilla finally debuted it for Android users.

Total Cookie Protection acts as a “cookie jar” for each website you visit. It contains cookies within their respective sites to prevent cross-site tracking. It is an extra layer of protection for your online data. It also gives you a break from intrusive ads, deterring companies from gathering information about you.

Mozilla Releases Additional Features for Android Users

Another highlight of the new Firefox 111 is its built-in PDF viewer. It eliminates the need for third-party apps when viewing PDF documents on your Android phone. There is also an exclusive feature for Pixel phone users with Android 12 or 13. You can now share links to recently viewed pages from the recent screen.

Aside from these new features, Firefox 111 has bug fixes for Android. It resolves the compatibility issue with Android 13 that was causing problems with copying saved passwords. Mozilla has also fixed the crashing that users were experiencing with the media playback notification.

Firefox 111 Has Browser Improvements for macOS and PC

Android users aren’t the only ones to benefit from the Firefox 111 upgrades. Mozilla has also addressed Windows 11 and macOS issues. It fixed the bug that was causing Firefox to freeze during start-up. It also resolved the issue that made Firefox crash when users pinch-zoomed.

Update to Minimize Your Risks 

No matter what browser you use in the office, encourage all your team members to upgrade to the latest version. Outdated versions are open to more security vulnerabilities. Once your browser is compromised, threat actors can steal sensitive information and install malware. Aside from improving security, upgrading your browser will also speed up the browsing experience and boost your team’s efficiency.

Used with permission from Article Aggregator

Schedule a Call