Friday, August 6, 2021

New Malware Called MosaicLoader Is Being Delivered Via Ads



Security company BitDefender has recently discovered a new strain of malware you should be aware of. They have dubbed the new threat MosaicLoader.

According to the company it is currently being distributed via ads displayed in search results when an internet user searches for links to cracked versions of popular software.

It is designed to steal passwords, deliver other forms of malware, and install cryptocurrency miners. This means that if it winds up on your system it can cause all manner of problems for you.

Most malware we see today is delivered via phishing attacks or by exploiting unpatched software. MosaicLoader's method of delivery makes it markedly different and thus noteworthy.

Bogdan Botezatu of BitDefender had this to say about the recent discovery:

"Most likely, attackers are purchasing adverts with downstream ad networks - small ad networks that funnel ad traffic to larger and larger providers. They usually do this over the weekend when manual ad vetting is impacted by the limited staff on call."

 

Call Now

 

Most up to date antivirus software would spot and prevent the installation of MosaicLoader. Unfortunately many people who are looking for cracked versions of popular software turn their antivirus software off. Hackers around the world are well aware of this and are seeking to take advantage.

Bogdan Botezatu continues:

"From what we can tell, this new MosaicLoader attempts to infect as many devices as possible, likely to build up market share and then sell access to infected computers to other threat actors. We advise users to never turn off their security solution when it blocks the installation of software downloaded from the internet, as attackers have become adept at bundling legitimate apps with malware."

It's good advice. Make sure all of your employees are aware and on their guard. That's not a perfect cybersecurity solution but it is a very good start.

 

Call SpartanTec, Inc. now and let our team of IT experts protect your network against malware and other online threats.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Tuesday, August 3, 2021

DNS Issue Caused Major Website Outage



The Akamai Corporation reported a major outage on Thursday (7/22/2021) that caused major disruptions on the internet in the United States for a period of several hours. A tweet from the company confirmed that the outage was caused by a software update. The update triggered a bug in the DNS system which caused the outage.

The good news is that the outage was not the result of a hack as had initially been feared.

The outage impacted a number of high-profile companies in the US, including:

  • AT&T
  • Costco
  • Capital One
  • And Delta Airlines

The websites owned by these companies simply displayed "DNS error" messages during the course of the outage. This prevented customers who rely on those sites from being able to access needed data.

 

Call Now

 

The bug was tracked back to its source and the issue corrected. All of the companies that had been impacted now report that their sites are working properly.

This latest incident only serves to underscore how fragile the internet is. There have been a number of high-profile attacks so far this year that have targeted critical infrastructure like the main gas pipeline that serves the Southeastern United States.

Given that information it is understandable that many who witnessed the outage in real time were concerned that it may have been caused by hackers seeking to bring down large portions of the web. Fortunately that proved not to be the case in this instance. We may not be so lucky next time.

This incident also underscores the importance of having robust backup plans prior to applying updates to critical infrastructure. Had that been done in this case the outage may well have been avoided.

Akamai has apologized for the scare and any inconvenience the outage may have caused and we can all now breathe a collective sigh of relief. At least for now.

Call SpartanTec, Inc. now and let our IT support team help you with all your IT needs and protect your company against cyber attacks.

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Thursday, July 29, 2021

Latest Data Breach Hits Guess Clothing Company



American fashion retailer Guess recently became the latest in a seemingly unending parade of big-name companies to suffer a data breach.

The company's breach notification letter was mailed to all customers whose data was compromised. The letter states that an unidentified party gained access to Guess' systems between February 2nd and February 23rd of this year (2021).

The company discovered evidence of the breach on May 26th and determined that the personal information of some Guess customers had been accessed. By the 3rd of June, the company, a third party security vendor, and law enforcement officials had finished a review of the data that was accessed. They then began contacting all individuals impacted by the breach as of June 9th.

The company is offering a year of free credit monitoring to all impacted individuals as is often the case in data breaches.

 

Call Now

 

The letter being sent to impacted individuals reads in part as follows:

"On May 26, 2021, the investigation determined that personal information related to certain individuals may have been accessed or acquired by an unauthorized actor. The investigation determined that Social Security numbers, driver's license numbers, passport numbers and/or financial account numbers may have been accessed or acquired."

The data security breach notification letters give no indication as to the scope and scale of the breach. The information filed with Main's Attorney General indicates that just over 1300 people had their data compromised during the attack.

Guess' breach notification gave no indication of who may have been behind the attack. However security researchers have found circumstantial evidence on the Dark Web that points to the DarkSide ransomware group.

If that name sounds familiar to you it's because they're the group behind the recent Colonial Pipeline attack that brought fuel deliveries to a standstill in the southeastern United States for the better part of two weeks. Not long after the Colonial attack the FBI seized significant portions of the group's infrastructure and they ceased all operations in late May. Now they seem to be back with a vengeance.

 

Call SpartanTec, Inc. now if you need expert help boosting your company's cybersecurity and protecting your business from data breaches.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Wednesday, July 28, 2021

2 Places You Should Never Cut Corners With IT



Today’s technology empowers business owners in ways that would have seemed incredible even 10 years ago. With a humming network connecting your team to the rest of the world, and with just a few simple keystrokes, your organization can complete tasks that used to take days. That's why you need to boost your cybersecurity measures.

However, the endless possibility that accompanies technological advancement comes with a catch: to be truly effective, IT requires investment – not just of capital, but of time and attention, resources all too dear to the harried entrepreneurs of the modern age. Perhaps this is why, everywhere you look, small to midsize business owners are not only failing to realize the full potential of their technology, but are unknowingly leaving massive gaps in their systems and processes for malicious entities to exploit. And so, budding companies that would otherwise dominate the market are prematurely stamped out by competitors with more tech savvy or are hamstrung by costly data breaches.

Even in the midst of this trend, we understand how easy it is to ignore your company’s glaring technological gaps. You imagine that you don’t have the time or money to address the issue, or that you’ll do it down the road once your business is better established. But no matter how big or small your business may be, there are two foundational tech concerns that you should never cut corners on.

 

Call Now

 

1 CYBERSECURITY

Pretty much every successful company today is intimately intertwined with the technology on which it depends. So it makes sense that your primary worry should be protecting what’s yours from those who want to snatch it. Think of it this way: would you hire a $5 locksmith to secure your office? Of course not. Then why do so many business owners put their livelihood behind a flimsy, $5 firewall – or, even worse, a free antivirus? In 2018, it is more likely that your business will fall victim to a cyber-attack than it is that thieves will arrive at your office in the dead of night, according to a 2017 report from Kroll.

In 2015, SEC Commissioner Luis A. Aguilar wrote, “Cyber security is clearly a concern that the entire business community shares, but it represents an especially pernicious threat to smaller businesses. The reason is simple: small and midsize businesses are not just targets of cybercrime; they are the principal targets.” With this in mind, cyber security should always be one of your top priorities.

2 TECH SUPPORT THAT GOES BEYOND THE “BREAK-FIX” APPROACH

It’s difficult to overestimate the money, time and stress it can cost you when your technology breaks down. Between server downtime, haywire software, connectivity issues and myriad other potential problems, when your stuff breaks, it can cause more than a massive headache – it can put you out of business.

Most business owners realize this, but many still opt for the classic “break-fix” strategy. Unfortunately, “If it ain’t broke…” is a dangerous maxim by which to steer a ship. If you wait to address a problem until after it becomes an issue, you’re inviting a crisis into the equation that could easily have been avoided with a keen, proactive eye. And when your server fails, or your firewall network experiences hiccups, or some other unforeseen issue rears its ugly head, an unfamiliar break-fix technician will take longer to fix the issue than an expert who’s been working with your specific network from start to finish and already knows it inside out. It’s just not worth it.

In addition, proactively managed service providers will consistently make recommendations to keep your company competitive. Whether it be a small upgrade to software here, a patch there or an overhaul of your server system, these moves can be invaluable in the breakneck marketplace. And, of course, since they’re keeping tabs on your tech at all times, any potential problems get addressed long before they hit your bottom line.

By leveraging technology, you and your business can do amazing things. Partner with a team of IT support professionals who are actively invested in your success and confidently push your company into 2019.

 

Call SpartanTec, Inc. now if you want to make sure that your business is secured by implementing the appropriate cybersecurity measures.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Monday, July 26, 2021

Difference Between a Data Breach and Security Incident?



If you think a data breach can’t happen to you, think again: According to the Ponemon Institute’s Fifth Annual Benchmark Study on Privacy and Security of Healthcare Data,criminal attacks are up 125 percent compared to five years ago. And that’s just in the healthcare sector.

Now more than ever, organizations need a primer on how to protect sensitive data. With cyber crime attacks on the rise, it’s critical to understand what a data breach is, how it differs from a security incident and how to plan a data breach response.

Incident vs. Breach

Think of a security incident as a pesky cold that may sideline you for a couple days, but clears up fairly quickly. It’s any event that violates an organization’s security or privacy policies around sensitive information like Social Security numbers or confidential medical records. This can be anything from a misplaced drive to missing paper files.

data breach Myrtle Beach, on the other hand, is like the nastiest flu bug ever — a whopper of a virus that will knock you off your feet.  The folks at ID Experts define it as a security incident that meets specific legal definitions per state and federal laws.

Specifically, data breaches require notification to the affected individuals, regulatory agencies, and sometimes credit reporting agencies and media.

 

Call Now

 

Security Incidents Are Status Quo

Security incidents are, sadly, part of the status quo — with 65 percent of healthcare organizations reporting having experienced electronic information-based security incidents over the past two years, according to the Ponemon study.

While not all security incidents escalate into data breaches, there’s a regulatory obligation to complete an incident risk assessment when PHI (protected health information) or PII (personally identifiable information) is compromised.

Responding Effectively

When an incident does escalate into a data breach, a quick and effective response is critical. This requires close collaboration across the company or organization, not just IT. Stakeholders in legal, marketing, public relations, the C-Suite and other functions have to be prepared to own a piece of the incident response and work together in a fairly seamless manner.

The first two, vital steps following a data breach are 1) Quantify the damage; and 2) Determine your response.

To address the first, quantifying damage, it helps to know at any point in time what information requires the most protection, where it’s stored and how it’s protected. At SpartanTec, Inc. we recommend performing periodic cyber threat assessments to develop this understanding.

In respect to step two, determining response, this is essential to managing enterprise risk and can quell fears, especially when the breach is more serious than initially thought, when credit monitoring isn’t enough and when media interest is high.

It requires data breach agility. Organizations with high data breach agility are more likely to have cybersecurity platforms that optimize visibility and the sharing of actionable threat intelligence between prevention and detection tools and across endpoints, data centers and the cloud.

 

This is among the advantages of the security fabric. Based on open APIs, it links together different security sensors and tools to collect real threat data, enabling technology and people to more effectively coordinate and respond to potential threats. Contact SpartanTec, Inc. to learn more.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Morgan Stanley Banking Latest To Get Hit By Data Breach



Data breach continue to evolve as the hackers themselves get increasingly sophisticated. One of the most recent victims is investment banking giant Morgan Stanley. Their network was breached after the attackers stole personal information belonging to their customers by hacking into an Accellion FTA server belonging to a third-party vendor, then using that information to breach Morgan Stanley's network.

The third-party vendor in question, Guidehouse, provides account maintenance service to Morgan Stanley. They notified the banking giant back in May that they had been breached and that some information belonging to Morgan Stanley customers had been compromised.

At this time it is unclear just how many of Morgan Stanley's customers have been impacted, but the company is in the process of reaching out to all who were impacted to let them know. Although the company has not indicated as much, it's fairly standard practice for firms to offer 1-2 years of credit protection to customers who have had their data compromised. Odds are excellent that this will be the case here. Although again, that has not been confirmed at this point.

 

Call Now

 

In any case, this is a serious cybersecurity breach, regardless of scope and scale, because the hackers were able to make off with both encrypted files and the decryption key to unlock them.

The stolen data includes:

  • Stock plan participants' name
  • Physical address
  • Date of birth
  • Social security number
  • And company name, where applicable

In other words, more than enough information to steal an individual's identity.

If you bank with Morgan Stanley, be on the lookout for a letter from the company and watch your credit statements like a hawk. If you want to take a more proactive stance, give them a call to verify whether or not you are among the impacted users.

 

Call SpartanTec, Inc. now if you want to protect your business against cyberthreats.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence

Wednesday, July 21, 2021

Is IT Outsourcing Right For Your Business?



For years, a lot of small businesses with 100 to 500 users have depended on in-house IT support to remain operational. When a user has a problem with an application or a device, they asked their IT staff to stop whatever they’re doing and fix the problem. Although inefficient, this method gave users a go-to option for their IT needs. But did you know that there’s a more effective option that’s beneficial to both the company and their users, it’s IT outsourcing?

The conventional shoulder tapping model used by IT support has been negatively affected by the COVID-19 pandemic. When companies shut down and moved to remote work, the in-house IT professional was nowhere in sight. Apart from that, user questions, incidents, and problems increased, and several employees were not used to home based work. The in-house teams which are working remotely could not keep up with the rise in demand, because they lacked the process discipline and monitoring tools. They also depended on ad hoc fixes.

 

  Call Now   

 

It also disrupted anti-virus updates, application lifecycle servicing, as well as routine hardware refreshes. Problems and incidents snowballed. Even though Zoom existed, collaboration tools were unable to reach their full potential, because user training programs were moved back to the back burner. Not only that, the risk profiles were heightened because of the neglect of the protocols involving cybersecurity. Cybercriminals have also upped their game during the coronavirus pandemic, which placed employees who handle sensitive data from their home offices at an increased risk.

IT Outsourcing Is The New Normal

These days, many companies are understanding that in-house IT support is no longer enough for the new normal where remote work takes on a more prominent role. While third-party outsourcing is a good option, looking for a model that will fit remains a challenge. Conventional enterprise outsourcing arrangements that are built on economies on the scale, as well as negotiated service agreements and T&Cs, are too costly for small clients and unprofitable for the providers. Meanwhile, the nerd-for-hire option lacked the resources, flexibility, and scalability required to deal with the complex technology needs of several small businesses.

An appropriate and effective IT outsourcing approach combines scalability, enterprise-level capabilities, and cost-effectiveness. It allows the maximizing of resource utilization while making sure that an IT team will respond to the requirements of a user. IT outsourcing strikes a balance by assigning an IT support team for a defined group of clients. It also offers you access to top-notch IT experts at affordable rates and provides the extra benefits of scalability and flexibility.

Effective IT outsourcing offered by companies like SpartanTec, Inc. for smaller companies will deliver on the basics of service governance and execution. They can get, configure, install, as well as service laptops, notebooks, and mobile devices. They will monitor your network security round the clock and deal with IT issues right away.

 

Call SpartanTec, Inc. now if you’re interested in outsourcing your IT tasks. Our team of IT experts is always ready to help.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence