In light of recent events in Europe, the imposition of sanctions and possibly offensive cyber operations on the Russian Federation, the possibility for increased online attacks from Russia and other entities will be increasing. (See the latest alert from CISA https://www.cisa.gov/shields-up ) While it is a common belief that hackers only focus on large businesses (due to potential value/extortion), they go after smaller businesses as well, even if just to build more launching ports to attack bigger targets. In one 4 minute window today, our office's security gateway showed dozens of probes - most from foreign networks. The threats are constant. So we wanted to share some tips, steps, and insights that can help you protect your infrastructure, along with some new advanced security options that have recently become available.
Online security is a complex and multifaceted challenge. Threats come in from many sources - email, web, firewall compromises, rogue attachments, even phone calls/social engineering. So while the anti-malware/security suites and enhanced network security gateways many of you have can help repel many attacks, the best defense is being vigilant when working online.
The most common avenue for threat actors to gain access to your networks is via email - mainly through embedded links or attachments with links to command and control servers. Below are some resources to share with your employees to help recognize suspect emails, attachments, and web properties:
- How To Recognize and Avoid Phishing Scams (https://www.consumer.ftc.gov/
articles/how-recognize-and- )avoid-phishing-scams - Handling Unexpected or Suspicious Email Attachments (https://it.stonybrook.edu/
help/kb/handling-unexpected- )or-suspicious-email- attachments - A common checklist from IT Xpress:
- If you are prompted to allow something to make changes to your computer - be SURE it's something you are actively doing (installing software, applying a verified and trusted update, etc). If in doubt, CLICK NO.
- Look at the From email address. You can often see it by hovering over the sender. Does the domain match the organization it came from? Or is it an online service (secure documents, finance, etc) that you've gotten emails from for this person before?
- Is the email sent directly to you or is the To list empty with everyone Bcc'ed? This may be OK, but it's a warning. If it's sent to some random userid, that's even more of a warning.
- Is the language in the email sensible?
- Before you click a link, hover over it and the actual link should appear in a tooltip or in the status bar at the bottom of the window. Does the domain part (www.companyname.com) match up with the company sending the email? Many will direct you to 3rd party services the sender's company uses - so try to keep a list of common ones they use. Be *very* careful of links to files from Google Drive/OneDrive - most are fine, but many attacks utilize these services to give the links the appearance of legitimacy.
- For common attachment types:
- DOC/XLS/PPT (Office): The main attack method here is to use macros - small scripts embedded inside a document. Office suites have taken steps to prevent this. You may have noticed an 'Enable Editing' button is frequently displayed - that's good. Most office documents opened, are opened for reading, not changing. So only click enable if you trust the document and need to make changes. If you are prompted to Enable Content - this will enabled macros. Only do this if you can 100% verify the source of the file, the sender knows there are macros in it, and you need to enable them for the document to function properly. *This is rare*
- PDF (Adobe): PDF files are the most common method to send printed documents. However, they also support powerful features that can be abused. PDF viewers will display PDFs in 'Protected View', which should be used to limit the attack surface for a PDF document. Only disable Protected mode if you need to activate a PDF document feature (vs just print it off)
- EXE (Programs): Simple - do not open. Most email system ban this file type anyway, but they are programs and will 'run' code on your computer, potentially compromising it.
- ZIP (Archives): Proceed with caution. They're a great way to send a collection of files, but they can also be used to try and 'hide' malicious files from anti-malware/security systems, *especially* if they are protected with a password. Extracting an archive is rarely a danger, but manipulating the files it contains can expose you to significant risk. So verify if at all possible before extracting.
- WAV/MP3/AAC/MP4/WMV (Audio/Video): Generally safe, though there have occasionally been some designed to trigger exploits in old versions of audio/video players. Keep your software up to date to protect here.
- HTM/HTML (Web Pages): These are commonly used to save web generated reports (use PDF instead if you can), but can contain all sorts of content and code that can attempt to exploit a system, just by opening them. However, some legitimate document encryption systems use attached web scripts to function, so it's like most - be wary and only open those from trusted verified sources.
- TXT/RFT (Text): Almost always safe - unless you get told it can't be opened - then it's likely a more dangerous file hoping you'll change .txt to something else so it can execute and attempt a compromise.
- JPG/PNG/TIFF/BMP (Images): Like audio/video - generally safe, though they can attempt to exploit vulnerabilities in old out of date image viewers. Keep your software up to date.
- When calling 3rd party vendors for support, verify you're actually calling the intended company. Bad actors like to return ads to common vendor searches with their own phone number, hoping you'll let them login to your system and accounts to 'help'. *NEVER* give your login to a 3rd party except for trusted IT personnel like us. Big name tech vendors like Google, Microsoft, Computer Vendors, etc will *never* ask for them, instead having you enter them.
- When in doubt - ask us! A brief email, phone call, or text could be the difference between a simple validation and a massive ransomware attack. Trust your instincts - we've all used computers long enough to notice unusual actions/behaviors.
Businesses are facing constantly evolving threats to their IT systems from a wide array of sources, so IT solutions are continually evolving and expanding to defend against them. Our system security vendor is always evolving their platform to address these new threats. Enhancements include:
- Ransomware Mitigation to help reduce the recovery time for a Ransomware attack
- Advanced Anti-Exploit Protection to help protect against new style 'persistent' threats like Fileless attacks
- Network Attack Defense to help stop attacks before they reach the system
- and a new Risk Management feature that analyzes all your systems to highlight weaknesses in their configuration and defenses
All of these new features are included in IT Xpert plans at no additional charge! But if you're looking to further enhance the security of your IT infrastructure, IT Xpress has accelerated the availability of some new optional enhancements to our existing services:
- Bitdefender Advanced Threat Security (ATS) - Added to your existing Bitdefender suite, ATS adds an advanced Hyper Detect engine that continually monitors internal computer operations, looking for sequences of events that are common during attacks. It also adds a 'pre-launch' threat model to identify and block attack code before it's executed. Finally, it adds an advanced realtime sandbox analyzer to launch attachments and downloads in a secure 'sandbox', looking for malicious behavior, before delivering them to the user. ATS can be added for an additional $3/system/month
- Endpoint Detection and Response (EDR) - Despite the best defenses and efforts, attacks can occasionally slip through. When they do, it is paramount to be able to quickly identify what happened, where it happened, and what it affected. This helps with eradication, mitigation, and recovery. EDR provides advanced visualization of a detected attack's history in your environment and detailed tracking of everything that executed and changed. Our IT Xperts can see exactly where an attack came from, how it executed, what it touched, and where it went. This allows for much faster response to advanced attacks. EDR is available for an additional $2/system/month
- Advanced Email Security - One of the largest threat exposures for a business is email. Attackers are getting very good at crafting believable emails trying to harvest account credentials, launch foothold attacks in a network, and compromise systems. Our new Advanced Email Security service provides realtime threat filtering of incoming and outgoing email and data privacy filters to detect and prevent sending of protected data (HIPAA, FINRA, Legal, etc). It also adds advanced URL threat filtering to preemptively check all links in an email for threats before a user clicks it, warning them if a link leads to an unsafe site or performs unsafe operations. Advanced Email Security is available for $4/email account/month
Contact us today to add any of these exciting new offerings to your plan or if you have questions about them.
Thanks and stay safe!
IT Xpress
Comments
0 comments
Please sign in to leave a comment.