Blog

URGENT! Google Chrome “HTTPS By Default D-Day” Is Today! (July 24, 2018)

Why the big hubbub over HTTPS?…

Because from now on, users who visit HTTP sites will be hit with a BIG WARNING from Google. This will happen to anyone using Google Chrome version 68.

HTTPS Websites

Google warns that you should have been protecting your websites with HTTPS for a while now. And this isn’t just for confidential communications. You need HTTPS on all your sites.

Why?…

HTTPS Prevents Intruders And Security Vulnerabilities

You certainly don’t want people (criminals or otherwise) tampering with the communications between your site and your users’ browsers. These intruders can be hackers or legitimate companies like Internet Service Providers (ISPs) that inject ads into your web pages. Did you know that some of these advertisements can block the user and create security vulnerabilities on your site?

HTTPS Protects Your Users’ Privacy

Every unprotected HTTP request to your website can potentially reveal your visitors’ private information, such as their browsing behaviors and even their identities. Some intruders gather bits of information and compile it into user “profiles” to steal their identities.

HTTPS also keeps intruders from listening to communications between your website and your visitors. This means if you don’t use HTTPS and you have an online help desk service with VoIP, someone else other than your rep and your client may be listening.

Intruders can trick your visitors into providing their confidential information or installing malware into your website.  They can access and exploit unprotected images, cookies, scripts, HTML … and they can do this at any point along the network.

This means that your users’ machines, a clients’ Wi-Fi hotspot, etc., could be exploited and you’ll be to blame.

HTTPS Is Required For Progressive Web Applications (PWAs)

What are PWAs?  They use modern website capabilities to deliver app-like experiences to your users.

Google likes PWAs because they: 

  • Load instantly, even when your visitors use uncertain network conditions. This is because they “live” on the user’s home screen. They don’t need to go to an app store for them. PWAs can also re-engage your users with push notifications. You can control how the app is launched and appear on your site.
  • Respond fast and smoothly. Did you know that 53% of users leave a site if it takes longer than 3 seconds to load?
  • Are engaging and provide an immersive user experience. You can pre-cache resources so you’re not so dependent upon the network.  It gives your users a more reliable experience when browsing your site.

Google Says That HTTPS Is The Future

In addition to the security benefits of using HTTPS, there are commercial benefits as well.  Browsers and search bots prefer HTTPS sites. Your site will be easier for visitors to find.

Today’s new web platform features allow things like taking pictures, recording audio and new geolocation APIs (Application Program Interfaces). They essentially provide offline app experiences. HTTPS is a key component to the permission workflows for both new features and updating APIs.

And take note! Watch for HTTPS warnings from Microsoft, Apple and Mozilla. They’ll be coming soon.

Keep Google happy and your users safe. It’s not expensive to switch to HTTPS and it’s certainly worth doing!

 

URGENT! Google Chrome “HTTPS By Default D-Day” Is Today! (July 24, 2018) Read More »

Simplify Your Workday With These Office 365 Updates for July 2018

Microsoft is always looking for great ways to make your workflow easier. That’s why they continuously update their products. The July 2018 updates to Office 365 are especially unique and should prove to be very helpful to users.

Upgrades To The Ribbon

Microsoft introduced the ribbon in its Office 2007 software. It replaced those traditional menus and toolbars that users were so familiar with. Though the changes did cause somewhat of a stir in the community of users, soon everyone came to appreciate the ribbon. It went over so well that Microsoft continued to update the ribbon each year to include greater functionalities.

Today, no one can imagine Office 365 without the ribbon. With that said, the new updates for Office 365 July 2018 include larger graphical controls on the ribbon that are more visible and grouped in a logical manner. Ribbon functions are more accessible and easier to use. Microsoft’s goal with this update was to make it easier for users to collaborate and connect with others.

The ribbon is also more intuitive now. It puts those commands you’re currently using front and center so they’re available when you need them.

Now there’s only one row of buttons instead of two, which helps to keep the commands you use at the forefront of what you’re working on. This allows more space for your document content. If you’re a big fan of the old ribbon that had two rows of commands, you can easily restore that look with the toggle of a button. Restoring the classic view has been made simple.

The new simplified ribbon is scheduled to be released first in the web version of Word. It will be rolled out to a special group of Office insiders in July. Microsoft will take the feedback from these users, then adjust their updates before rolling out the new Office applications to all users.

Sharepoint Integration

Integration has always been a big thing for Office 365 applications. The Office team has gone one step further with new ways to embed Planner into SharePoint sites. Now the Office 365 productivity solutions that everyone loves are even easier to access. For instance, the SharePoint navigation bar gives all team members the ability to manage tasks directly from SharePoint. Outlook, Calendars, and Microsoft Teams are still available from most applications.

A new button on the SharePoint page allows users to add a plan from Planner. Designing a SharePoint page that has plan details is a breeze. Simply head over to the SharePoint page with the plan details, then click on the Edit button. Locate the area where you want your plan displayed, then click the Plus sign, and select the new Planner web part.

Microsoft Teams Updates

SharePoint integration for Microsoft Teams has been greatly simplified as well. Users can add files directly into the Teams interface right from SharePoint. They can also link an entire SharePoint document library in Microsoft Teams.

Teams have become a favorite meeting application with all the Microsoft apps accessible from the Teams interface. This app took a huge leap forward when Teams was recently updated to allow for links to an entire SharePoint document library. This offers fast, convenient ways to share the SharePoint document library with your whole team. Expect to see more exclusive updates to Microsoft Teams in the future, as it has now become an indispensable part of everyone’s workday. It’s revolutionizing the way people communicate.

New Chat Functions

The Team’s chat experience has been improved to add more flexibility to participants. For instance, if you are involved in a chat that is no longer relevant, you can easily duck out of the meeting. You can also hide a chat if you need to do so or mute a chat if you need to focus on some other task at the moment.

Sway for iOS

Microsoft announced its most extensive update in history on May 30th to Sway for iOS. Now users will find it easier than ever to create a Sway from beginning to end on their iPhone or iPad. Users can quickly toggle between Edit and Preview modes. Add and reorganize text and media in the Edit mode.

Preview lets you see your Sway as others will see it. You can also make easy and fast changes to your Design with the toggle of a button. Edit mode has been simplified to an all-white canvas where users can add photos and videos from the camera or take a new photo. Tap on an image to resize it or add a caption. Photo grouping has been simplified as well. Drag and drop one image onto another to create a new image group.

Sway on iOS allows for the addition of lists, bullets, links, blockquotes, and more with the single tap of a button. Once you have your Sway completed, it’s easy to share or you can invite friends to collaborate. The Sway app for iOS is available from the Apple Store and it’s more fun than ever to use.

Microsoft Office 365

Wrap Up

The Office 365 Updates for July 2018 all about ease and convenience. You can do more in less time. It’s well worth it to learn these easy new ways to use Office 365 so you can shave time off your workday and get more done each day.

Simplify Your Workday With These Office 365 Updates for July 2018 Read More »

A New Way That Password Stealing Malware Infects Your PC

The acquisition of user IDs has become much easier for cybercriminals in the globalization era. A variety of methods can be used to steal passwords, including spyware, keyloggers, and phishing attacks. This can lead to the total loss of essential data held in company or private databases. Most of the methods used by these cyber criminals involve the use of malware that has been designed to steal user credentials. Based on the objectives of a particular cybercriminal, a variety of malware methods are applied to fulfill those goals.

Password Stealing Malware

A significant proportion of methods used to steal user credentials consider the use of malware. Additionally, phishing attacks use malicious attacks through communication channels such as emails where malware-loaded websites are disguised as genuine ones to trap unsuspecting users. Other types of attacks include spyware and keylogging which, for a variety of incidences, has been observed to continually grow in both complexity and frequency of attacks.

Signs of a Malware Infected PC

One of the diagnosis methods of identifying whether a computer is infected with a virus is through the observation of random pop-ups and significantly increased booting time. Instances like these are associated with spyware configured to steal essential data from users without them noticing.

The objective of using spyware on user PCs is to ensure that information stored in browsers and other sensitive areas is well camouflaged. This includes communication channels such as email. Cyber crooks will attempt to acquire your passwords without you noticing that anything is wrong. Though this seems like a flawed technique that wouldn’t work all the time, the truth is that it works exceptionally well. For instance, 158 million social security numbers were stolen in 2017. That doesn’t include all the other types of records and data stolen from individuals and companies.

Malware Injection Technique

For reliable security dodging methods, process injection is a method of integrating malware and lifeless adversary strategy in trade-crafting accounting for the integration of custom codes within the address bars of other processes. The variety of injection techniques includes the following methods.

Portable Executable Injection

Shellcodes and Create Remote Threads are among strategies used in malware injection where malicious codes are copied into accessible active processes commanding them to execute as the originals. Through this strategy of attack, the malware does not require writing malicious code on a disk. Instead, it does so by calling Write Process Memory on the host procedure. The impact of this procedure is that the injected code copies its PE to another process with an unidentifiable base address commanding it to re-compute the original addresses of its PE.

Process Hollowing

Process hollowing is a technique that malware applies to take into account the mapping or hollowing out of the primary code from within the memory of the target’s procedure while overwriting the memory target process with an executable malicious code. The function of the malware is to create a new process designed to host the malicious code presenting it in a hanging form awaiting for the Resume Thread Function to be called in order to execute.

This process leads to the switching of the original file contents with the malicious payload. Processes used for mapping the memory include two API examples, the ZwUnmap and the NtUnmap Views of Section. In order to succeed in assigning new memory for the malware, this procedure takes advantage of the malware’s unmapping of the memory and proceeds to execute the loader, VirtualAllocEx that facilitates the application of the malware to the Write Process Memory on the identified vulnerable target.

Classic DLL Injection Through Create Remote Thread And Load Library

This technique is among the most popular method used in malware injection into other processes. By commanding the implicit address space to process the malware code using the dynamic-bond library, the approach facilitates the creation of Remote Threads in the target process through process loading.

The primary objective of the malware is to target a process for injection. This procedure is generally performed through a search of the processes to call a trio of APIs that include CreateToolHelp32Snapshot, Process32 1st, and 2nd. The specific functions of each of these APIs include the cataloging of heaps and returning a snapshot, retrieval of the first process, and the iteration through the previous two processes respectively. After successfully allocating the target process, the malware is able to execute through Open Process calling.

Conclusion

This article reported on a number of techniques used by malware attackers in concealing unauthenticated activities in other processes. Two procedures are observed to facilitate the functionality of malware and include open injection of a shellcode on another processor or the command of other processes to load malicious libraries on behalf of the malware. Cyber thieves are constantly updating their attack procedures to stay one step ahead of IT professionals. That makes locating and eliminating malware threats a full-time job.

A New Way That Password Stealing Malware Infects Your PC Read More »

iPhone Users: Don’t Run 11.4.1 Update

Are you using an iPhone or iPad?  It may be worth it to hold off a few days before hitting that update button.

iPhone IOS Updates

Why?

Reports are surfacing that after updating to #IOS 11.4.1 there are issues with app updates. The App store shows many apps that need to be updated, but when you press ‘update‘ or ‘update all’ the apps updates are failing.

Click Here To Learn More

We recommended holding off until Apple fixes these update issues.

Have any questions regarding the recent iPhone/iPad update?  We welcome you to reach out to us at {phone} or {email}.

iPhone Users: Don’t Run 11.4.1 Update Read More »

Exactis Data Leak (Questions/Answers)

Exactis Data Leak Reveals the Dangers of Less Efficient Security Measures around People’s Data

The new data leak at Exactis, a marketing and data-aggregation firm based in Florida, presents a great many opportunities for cybercriminals to launch any number of attacks on unsuspecting victims over the next several months.

Data Leak

Exactis, which collects loads of personal data on nearly every U.S. adult, recently leaked detailed information on both people and businesses in the country, according to an exposé by a security researcher.

The exact number of people that this breach has affected remains unknown, but reports indicate that about 340 million records were involved in the leak on the company’s publicly available server.

The Florida-based data aggregation company claims to be in possession of data on a whopping 218 million U.S. adults, including some 110 million households. It further has some 3.5 billion records (digital, consumer, and business records).

Exactis data leak a lesser threat?

Many potential victims may take comfort in the fact that Exactis does not collect people’s payment information such as credit or debit card data, nor their Social Security Numbers. The marketing firm is largely interested in personal information – including names, addresses, and other very basic and specific details about people’s private lives such as hobbies, religion, and individual preferences.

Additionally, unlike the Equifax data breach that involved massive loss of people’s payment information into the hands of cybercriminals, no evidence has come to light yet indicating that the leaked data on the Exactis server actually fell in the hands of anyone with malicious intent.

According to the individual who discovered the breach, Exactis has since taken protective measures to secure the data.

However, this is not a guarantee that there’s no need for alarm. There is no way to tell just how long the individuals who infiltrated the server might have stayed there undetected. Neither does anyone know the details of their exact intent nor the kind of information they might be interested in.

What is now public knowledge, however, is that the exposed information also included home addresses, email addresses, and phone numbers – which can be a time bomb in the hands of a bad actor.

What was the mistake that led to the Exactis server leak?

The data leak at Exactis was possible because the company left the information up on a public server without any protection around it. This way of storing information in the company left the massive collection exposed for anyone who cared to access and use it. There’s no denying how tempting something like this would be for a data thief, as the database had information about “pretty much every U.S. citizen in it.”

While Vinny Troia, the security expert who exposed this leak admits to not knowing where Exactis obtains all their data, he confirms that the database is truly one of the most comprehensive information resources available of its kind.

Should this data security breach and the numbers associated with it be anything to go by, it would be one of the most detrimental to hit the U.S. in a while. This data leak would beat 2017’s Equifax breach hands down. The Equifax breach has held the record as being one of the most devastating security data breaches to date. It affected the highest number of consumers – up to an estimated total of 145.5 million individuals.

What potential risks are victims of this breach are facing?

The damage is done, so what are the repercussions? What does this mean to the individuals and businesses whose details have been breached? What possible solutions do they have at their disposal?

Spam emails

Persons whose personal details are now out there can expect to receive streams of annoying spam emails in their inboxes.

If spammers got hold of someone’s personal information from the Exactis data leak, this would mean a fresh new list of email addresses to send unsolicited offers to. This class of cybercriminals makes money off signals such as website pop-up ad impressions or email response rates. Clicking on their unsolicited emails would be generating money for them without intending to.

Phishing attacks

A direr possibility, the data might fall into the hands of identity thieves. These criminals could use the email addresses obtained from the leaked collection to create any number of phishing schemes.

The consumers who have lost their personal information, therefore, run the risk of being targeted by phishing attack emails, which involve criminals impersonating legitimate senders attempting to trick them (unsuspecting recipients) into clicking malicious links in these emails. Clicking such malicious links would trigger the download of malware onto these victims’ computers.

Attackers may also trick these victims whose emails they (attackers) have gathered, into giving out some confidential and more valuable information such as usernames and passwords, credit card data, and even Social Security numbers.

Wrap up

Knowing what to expect is the first step in preparing for the consequences of this breach. At the end of the day, you must protect yourself. It is utterly important that you do not open any email that originates from an untrusted source. Better still, consider using a suitable email authentication service to protect you from interacting with malicious emails. Watch for phishing schemes—expect them to come to your inbox and be prepared. Don’t be fooled by emails that seem a bit too urgent. Cybercriminals always use fear to get you to click on their bad links.

Exactis Data Leak (Questions/Answers) Read More »

Talk to our Team