Monday, November 22, 2021

Understanding Firewall Protection And What It Can Do For You



Firewall protection can help keep your computer safe from intruders like hackers whenever it is connected to the internet. It does this by checking the electronic data that comes in and out of your computer.  A good firewall offers protection from all those prying eyes. It prevents thieves as well as intruders from gaining access to your laptop, computer, server, or workstation. An excellent firewall can also offer protection to your computer against malicious worms.

Firewall Protection Against Identity Theft

A good firewall can help protect you from identity thieves. They are computer hackers who can find their way into vulnerable computers where they steal important files, tax records, credit card information, passwords, and reference or identification numbers. Remote thieves also exist and they are the ones who can hijack your computer system and send spam messages, or even plant computer viruses in your units.

What Can a Firewall Do?

To put it simply, a firewall can protect your computer from attack, scanning, or other similar types of intrusion made by hackers while they are connected to the internet. A firewall will check electronic data that comes in or out of a computer unit or a network and will compare it to the regulations that it has been provided. When the data matches the set rules, it will be allowed to pass. However, if it does not then the electronic data will be blocked. You may consider a firewall as a piece of software that can keep bad guys out of your unit or network and allow the good ones to get access.

According to research, a computer system that is not protected can be attacked in just a matter of minutes after starting to use the internet. That’s why it is very important to have a security software installed on your computer before you connect to the internet. If your computer is brand new and there is no internet security installed, it is suggested that you download and install one first along with the latest Windows updates and patches required for your computer to be secured before you start browsing the internet.

Is there anything that a firewall cannot do?

A firewall won’t give you the full security you need to make you completely safe when you are connected to the internet. It is one of the first lines of defense but it cannot protect you 100% on its own. That is why an internet security suite has other pieces of software too. A firewall cannot protect you from most viruses, spam messages, insufficiently configured Wireless Network, and installation of malware software.

SpartanTec Inc. understands that businesses rely on the internet to run their operations. With their managed firewall services, your business network and systems can be protected so you can be worry free and simply let the experts manage these things for you. Our managed firewall solutions include web content filtering, total security from online dangers, hardware & software, and simplified management.

Don’t put your business at risk. Contact SpartanTec Inc. and let our experts help you protect your business from online threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Thursday, November 18, 2021

The Hidden Dangers Of “Shadow IT” To Your Business



We all know that using information technology — programs, apps, or internet browsing — carries a certain amount of cybersecurity risk.

Nobody wants to have their secure data compromised, but technology brings enough benefits that the risk is worth it. So, you vet certain systems, you establish protocols, you update and patch your software, hire IT support experts, and you keep track of the technology used at work.

But what about the technology your employees are using that isn’t part of your official plan? We’re talking about messaging apps, Excel macros, cloud data storage, collaboration spaces, and even hardware like USB drives, smartphone storage, and personal laptops that you don’t control.

We call this “shadow IT,” and that’s a whole lot of potential holes to cover!

What is Shadow IT?

Even if you ignore the dangers of having accounts hacked, data stolen, and websites vandalized, shadow IT can be very inefficient. You don’t control it, so you don’t know where important information is or what work is being done. It makes it hard to avoid duplication of efforts and even harder to manage employee productivity. What are you to do? If you're not sure, seek out the help of IT support professionals.

Well, your gut reflex might be to “crack down” on using unauthorized technology for work purposes. Swallow that reaction, though — you can’t stop it, and you’ll just harm morale. You’ll also drive usage even further underground; your people won’t be honest with you for fear of reprisal. That means that if a compromise occurs, you’ll be the last to know.

Instead, keep an eye on the situation. Make it clear that you support employees using the tools they need to get the job done, as long as they let you know what those tools are. If your people start using cloud storage apps, that’s fine — but have them explain how they’ll keep that data secure. Just as you empower them to find their own tools, empower them to keep things secure.

You probably can’t come up with a list of all the shadow IT that’s being used at your work, but you can keep an eye on the trends as they develop. Research the technology that’s being used and watch the headlines for data breaches or other compromises.

In some cases, you will have to crack down on specific apps, programs, or devices being used at your work; they’re just too risky. If you’ve worked with employees and fostered good communication, this shouldn’t be an issue. Remember to avoid blaming employees when shadow IT becomes a problem — especially if they bring the issue to your attention themselves. There’s nothing wrong with asking your people to stop using a specific program or device, as long as you’re transparent and have good reasons.

Last, but not least, try to look on the bright side. Shadow IT may be a little risky, but it also presents opportunities for employees to drive productivity and try out new best practices. If they’re using a piece of technology, it’s probably doing something that the currently “approved” tech is not. They’re also showing self-starter tendencies and trying to do their job better. And that’s always something you should support!

Call SpartanTec, Inc. now and let us help you get rid of the hidden dangers of Shadow IT to your business.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Monday, November 15, 2021

New Android Malware Wreaks Havoc For Some Users



There's a nasty new strain of malware you need to be aware of that targets Android devices. Don't let the funny name fool you because AbstractEmu is a serious threat.

Not only will it root an infected device but it will allow the controller of the malware to take total control of the device. It will alter its settings and attempt to evade detection via a combination of anti-emulation checks and code abstraction.

The new strain was discovered by cybersecurity researchers at Lookout Threat Labs. They discovered it bundled with a collection of legitimate utility apps distributed via the Google Play Store and other third-party app repositories.

Google has removed the malware from the Play Store at this point but not before several thousand people had already downloaded it. The malware remains available on a few different third-party repositories. If you're in the habit of picking up apps outside of the Play Store an extra measure of caution is prudent.

The team that discovered the new strain had this to say about it:

"AbstractEmu does not have any sophisticated zero-click remote exploit functionality used in advanced APT-style threats, it is activated simply by the user having opened the app. As the malware is disguised as functional apps, most users will likely interact with them shortly after downloading.

By using the rooting process to gain privileged access to the Android operating system, the threat actor can silently grant themselves dangerous permissions or install additional malware -- steps that would normally require user interaction."

Needless to say the group behind AbstractEmu has some skill and some serious coding chops. Although the malware strain's removal from the Google Play Store has limited the rate of its spread you can bet the threat group will be on the lookout for other opportunities.

SpartanTec, Inc. now if you want to protect your business against malware and other cybersecurity threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Wednesday, November 10, 2021

Hackers Turn To New Trick Called SEO Poisoning



Hackers have a new tool in their toolbox you should be aware of. Called SEO Poisoning or sometimes "search poisoning" the attack relies on Black Hat SEO techniques to optimize web content.

Researchers from Menlo Security have spotted two separate campaigns one linked to the SolarMarker backdoor and the other leveraging REvil ransomware to infect unsuspecting netizins.

Here's how the attacks work:

The hackers gain access to legitimate sites that rank well on Google and inject them with a variety of specific search terms.

Because the site is respected and ranks highly on its own surfers who find their way onto the site are more likely to accept that anything on the site is legitimate. The hackers leverage this trust by adding poisoned content to the site. This poisoned content appears in search results to be a PDF file requiring a download in order to view it.

When a user clicks on a download link they seal their fate. Behind the scenes they are redirected multiple times ultimately winding up at a poisoned site controlled by the hackers where a malicious payload is dropped onto the visitor's device.

Both of these campaigns have leveraged respected WordPress sites taking advantage of an undisclosed flaw in a plugin called 'Formidable Forms.' The hackers install their malicious PDFs in the wp-content/uploads/formidable/ folder.

Most cybercriminals who deploy ransomware demand exorbitant fees to regain access to your files. These two campaigns are notable for making much smaller demands ranging between $1,500 and $7,500.

If you have a WordPress site and you use the Formidable Forms plugin download the latest version as soon as possible. The plugin's developers moved quickly to address the issue and a fix is available. As long as you are running version 5.0.10 or later you should be fine.

Call SpartanTec, Inc. now if you need help in protecting your business against various cybersecurity threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Tuesday, November 9, 2021

New TodayZoo Phishing Campaign Is Going After Passwords



Microsoft recently reported on the existence of an unusual phishing campaign designed primarily to harvest the passwords of unsuspecting victims.

One of the things that makes the campaign so unusual is the fact that it appears to be built by using bits of code copied and pasted from the work of other hackers. Call it a "FrankenPhishing Campaign" if you will.

Microsoft borrowed from the story of The Island of Doctor Moreau and has dubbed this campaign "TodayZoo". While it may be crude and cobbled together from the work of other it has been both large and successful enough to gain attention.

The campaign does a surprisingly admirable job of impersonating Microsoft's own brand. The campaign makes use of a technique called "zero point obfuscation" which makes use of HTML text written in a font size of zero designed to evade human detection.

This tool is a simple and almost crude plan and yet it has proved to be surprisingly successful. Users get an email that appears to be from Microsoft. The body of the email indicates that the user's Microsoft 365 account has been compromised and the user's password must be reset.

The email contains a link but of course, the link only points to a dummy version of the password reset page. The moment the user enters his or her login credentials all they're doing is handing them over to the people who orchestrated the phishing campaign or the cybersecurity threat.

Note that most phishing campaigns that work this way collect the login credentials on one site then forward them onto some other. In this case, the people behind the campaign are simply storing the credentials on the site that collects them.

All of this points to a group of enthusiastic amateurs. It's an audacious campaign and they will undoubtedly learn from it and improve. Odds are excellent that this is not the last we've heard from this group.

Call SpartanTec, Inc. now if you need the help of professional experts in keeping your information safe from hackers, phishing campaigns, and other online threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

New TodayZoo Phishing Campaign Is Going After Passwords



Microsoft recently reported on the existence of an unusual phishing campaign designed primarily to harvest the passwords of unsuspecting victims.

One of the things that makes the campaign so unusual is the fact that it appears to be built by using bits of code copied and pasted from the work of other hackers. Call it a "FrankenPhishing Campaign" if you will.

Microsoft borrowed from the story of The Island of Doctor Moreau and has dubbed this campaign "TodayZoo". While it may be crude and cobbled together from the work of other it has been both large and successful enough to gain attention.

The campaign does a surprisingly admirable job of impersonating Microsoft's own brand. The campaign makes use of a technique called "zero point obfuscation" which makes use of HTML text written in a font size of zero designed to evade human detection.

This tool is a simple and almost crude plan and yet it has proved to be surprisingly successful. Users get an email that appears to be from Microsoft. The body of the email indicates that the user's Microsoft 365 account has been compromised and the user's password must be reset.

The email contains a link but of course, the link only points to a dummy version of the password reset page. The moment the user enters his or her login credentials all they're doing is handing them over to the people who orchestrated the phishing campaign or the cybersecurity threat.

Note that most phishing campaigns that work this way collect the login credentials on one site then forward them onto some other. In this case, the people behind the campaign are simply storing the credentials on the site that collects them.

All of this points to a group of enthusiastic amateurs. It's an audacious campaign and they will undoubtedly learn from it and improve. Odds are excellent that this is not the last we've heard from this group.

Call SpartanTec, Inc. now if you need the help of professional experts in keeping your information safe from hackers, phishing campaigns, and other online threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence, Charleston

Monday, November 8, 2021

This Mac Malware Should Have Users Worried



Researchers from Microsoft have reported the discovery of a new variant of macOS malware called WizardUpdate.

The new version should worry all Mac users because it has been upgraded to incorporate enhanced evasion and persistence tactics that will make it more difficult to track, locate and ultimately stop.

WizardUpdate is also known as UpdateAgent and it is based on code that is distributed via download repositories. That is where it masquerades as a legitimate and safe software. Although the researchers found no direct indication of how this new variant is distributed it follows that the group behind the code would use similar if not outright identical techniques.

WizardUpdate has had a short but interesting history when it comes to cybersecurity breaches. It was first discovered in November 2020. In its earliest incarnation the code could do little more than collecting and exfiltrating basic system information. That proved to be but a simple test. Since its initial release WizardUpdate has seen numerous upgrades.

The latest build includes the following capabilities:

  • To grant admin permissions to regular users
  • To leverage existing user profiles to execute commands
  • To modify PLIST files using PlistBuddy
  • To bypass Gatekeeper by removing quarantine attributes from downloaded payloads
  • To grab the full download history for infected Macs by enumerating LSQuarantineDataURL String using SQLite
  • And to deploy secondary payloads downloaded from cloud infrastructure

Microsoft had this to say about the newly discovered strain:

"UpdateAgent abuses public cloud infrastructure to host additional payloads and attempts to bypass Gatekeeper, which is designed to ensure that only trusted apps run on Mac devices, by removing the downloaded file's quarantine attribute."

"It also leverages existing user permissions to create folders on the affected device. It uses PlistBuddy to create and modify Plists in LaunchAgent/ LaunchDeamon for persistence."

WizardUpdate by any name is a scarily capable malware strain and Mac users should be on high alert.

Call SpartanTec, Inc. now and let our team of IT support professionals help set up the most effective cybersecurity measures to protect you from malware and other types of online threats.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/