Saturday, August 17, 2019

New post about email security


Emails are one of the most common and widely used media to exchange information for official and personal needs. According to new studies by Keone Software around 205 billion emails were exchanged by individuals in the year 2015, and this count increased to 246 billion in 2019.
With the increasing popularity of digital media and the internet, business owners have moved online. Even the financial institutes, insurance companies, and other service providers also offer electronic access to the system. In such situations, hackers avail more opportunities to lead phishing attacks on your emails. It is important to learn a few trusted methods and tactics to protect your email box from harmful phishing attacks.

How hackers could attack your email

In today’s advanced world, it is possible to do so many things via online systems. That is why your usernames, passwords, and other credentials are very important to hackers. Once they gain access to such sensitive information, they may log in to your personal accounts and steal all your hard-earned money.
As a common scenario, hackers often try to steal such credentials by sending some urgent emails to the victims, and the surprising fact is that the source of such emails appears legitimate to the viewers. Such fake emails may appear like they are originated from your bank or insurance company. But once you try to enter your details to the link provided by them; the username and password are captured by attackers, and your account is immediately hacked. Read full post here:
https://linustechtips.com/main/blogs/entry/1666-how-to-protect-your-email-box-from-phishing-attacks/

New Post About Rootkits



A clandestine computer program – rootkit allows hackers to have non-stop access to the vulnerable computer by hiding itself under the veil of an application that is not at all suspicious or dubious. When you accept to grant permission to the applications to install or update themselves, the rootkit is introduced to the device along with these apps and waits for the hacker to activate it so that it can start its surveillance. According to Keone Software, Rootkits can be associated with key loggers and malware like worms, viruses, Trojans and other malware that usually initiate their malfunction by hiding themselves in such a way that the user doesn’t realize their presence for quite some time. Read the entire post here: http://secureweb.altervista.org/what-is-a-rootkit/

Article About Advanced Persistent Threat



The Advanced Persistent Threat (APT) is a special type of attack where some unauthorized user avail access to certain network or system and stays there for a long run without even being detected. Such attacks are more dangerous for organizations as hackers may manipulate or steal sensitive data. Note that, APT attacks usually do not cause any harm to the local machines or network; rather, the main motive of the attacker use to steal data.
Such attacks are usually completed in several phases. It may include hacking the system or network, preventing detection, developing a plan for the attack, mapping the sensitive data, and filtering the accessible information. Read more: https://adwarehelp.svbtle.com/what-is-an-apt-advanced-persistent-threat


Wednesday, August 14, 2019

POST ABOUT LOCKY VIRUS

Locky file virus makes users desperate as their most important files get locked with a sophisticated encryption system. IT experts are making their best to come up with an ultimate recovery solution. The encryption is strong enough, though. Any decoding attempts of the white hat hackers have not yielded a satisfactory result – so far. While the users still reasonably place their hopes on the release of decryption method, there are some smart techniques enabling quite efficient data recovery that often meets user’s needs.

Let us gain some insight into how the infection works and what it actually is. That would facilitate the use of anti-ransomware methods referred to above.

The IT industry tends to classify the infection as a piece of ransomware. The Locky virus holds your data out of your access as a hostage. To restore the access, a victim is prompted to pay the amount specified by the invader. The sum is payable in bitcoins and via dedicated TOR channel.

More: https://pc-protect.weebly.com/blog/locky-virus-targets-all-of-us

ARTICLE ABOUT FRAUDULENT ATTACKS ASSOCIATED WITH ITUNES GIFT CARDS



Currently, cybercriminals often resort to a strategy of making telephone calls with the requirement to transfer funds for paying taxes, medical bills, utility bills, etc. Fraud attacks are carried out in many ways, often using gift cards. Since some attackers use iTunes gift cards, we feel it necessary to warn Apple customers about the likelihood of encountering such an attack.
All fraudulent attacks (regardless of the purpose of payment) are conducted according to a certain formula: the attacker calls the victim in order to sow panic and convince him of the need to urgently pay something using the iTunes gift card, which can be purchased at the nearest retail store. After purchasing the card, the victim is asked to make a payment by dictating a 16-digit code on the back of the card by phone.
Remember that iTunes gift cards can only be used to purchase products and services from the iTunes Store, the App Store and the iBooks Store, or to pay for a subscription to Apple Music. If you are required to use a card to make a payment that is not associated with the iTunes Store, App Store, iBooks Store or Apple Music, you are likely to have become the target of a fraudulent attack. Immediately report this to the local law enforcement agencies (police department, trade commission, etc.).

Article on how to stay safe while using public Wi-Fi

Free Wi-Fi at the airport, at the mall or in coffee shops help us when we are running a little low on our data pack but they come with threats to your security. Public Wi-Fi even those offered by hotels do not come with necessary security, using them could put your data at risk. These servers are easy to hack into, without your knowing all your browsing activity and other personal information could be accessed by a third party. Read more here:
https://antivirusspace.wordpress.com/2019/08/14/how-to-stay-safe-while-using-public-wi-fi/

Tuesday, December 18, 2018

Information security

Information security is the state of preservation of information and the protection of the legal rights of an individual and society in digital space.

Information security is the process of ensuring the confidentiality, integrity and availability of information.

Privacy and Confidentiality: Providing access to information only to authorized users.

Integrity: Ensuring the reliability and completeness of information and methods for its processing.

Accessibility: Providing access to information and related assets of authorized users as needed.

Information security - all aspects related to determining, achieving and maintaining confidentiality, integrity, availability, non-repudiation, accountability, authenticity and reliability of information or means of its processing.

Information security - the state of data security, which ensures their confidentiality, availability and integrity.

Information security is determined by the absence of unacceptable risk associated with the leakage of information through technical channels, unauthorized and unintended effects on data and (or) on other resources of the automated information system used in an automated system.


Here are several interesting security articles:

http://scalar.usc.edu/works/new-daily-article/how-to-check-the-macbook-virus


https://privacy-security.shorthandstories.com/globeimposter/index.html


http://antonlucanus.web.ugm.ac.id/2018/10/30/the-pros-and-cons-of-the-cyber-reality-in-our-lives-technology-its-differing-aspects-and-demanding-impositions/


http://www.imfaceplate.com/infosec/strange-cryptocurrency-industry-jobs


https://cybersmith.exposure.co/similar-photo-cleaner/


https://dailygram.com/index.php/blog/492275/mining-crypto-at-work/


https://busy.org/@davesure/how-apple-s-self-proclaimed-employees-cheat-on-mac-users


http://sharingknowledge.world.edu/are-there-viruses-for-mac-computers/



Tuesday, October 25, 2016

Locky ransomware has been updated again: now uses .thor file extension



Seems like Locky creators have returned from vacation, after several weeks of slow distribution of their earlier version called Odin, they released two more variants this week. First one adds .shit extension and the second one adds .thor extension. Two variants differ in a way that one may work offline without contacting Command and Control servers. Seems like cyber criminals want to launch two variants simultaneously and see which one goes better in terms of rogue ROI.

Like with many previous versions, new .thor file virus usually arrives with malicious email attachments or hyper links within the body of the email message or instant message. Do not click on such links and do not open attachment sent by unfamiliar users. 

If your files got encrypted with .thor version of the virus, try restoring Windows from previous restore point or utilize backups. For more tips read here.

To be protected, make regular backups and keep you security software up-to-date.

Tuesday, April 5, 2016

Locky Ransomware Virus Is on the Rise




The easy availability of Locky malware attracts a number of distributors. Those propagators are unrelated to each other. They make use of any possible method of introduction. Naturally, some of them have already been caught at spreading the malware. The point is, they are not much closer to the arch villain than anyone.
The ransoming virus installation details vary from case to case. The prevailing infection vector is known. Most of the infiltration cases are due to opening spam mail attachments.
The introduction is to be followed by installation of the Locky ranowmare. The latter requires an affected system to reboot. One can prevent the encryption already at that stage. If a sudden reboot is happening, it is worth switching your computer to Safe Mode: the malware is not able to complete its installation.
If it succeeds in its encrypting attempts, the victims are presented with a relevant ransom note. The note is available at each folder with affected files. Several formats convey the same notification to ensure the users would read it.
The removal of Locky encryption shall include the ransomware elimination and data recovery. Whenever possible, the victims shall abstain from purchasing the key as prompted by the scammers. Relevant instructions on how to handle and prevent Locky invasion follow: http://myspybot.com/decrypt-locky-files/

Friday, December 11, 2015

An update of TeslaCrypt came out this week




It incorporates minimal adjustments to the previous version of TeslaCrypt. In particular, the file name of the ransom note is now called Howto_RESTORE_FILES.txt, it can be also .html and .bmp. With the exception of the change of the name, the wording of the ransom note is similar to the previous version.

Another change is a different name for autorun entry.

Finally, a modest modification of the way ransomware cleans the Shadow Volume Copies. In terms of removing Shadow Volume Copies, new version of TeslaCrypt is now executing vssadmin.exe until the ransomware identifies that the user of the infected machine did not terminate the request to run vssadmin.exe.

More details about TeslaCrypt ransomware as well as removal instructions can be found here: http://soft2secure.com/knowledgebase/teslacrypt