cyber attack image concept
Cybersecurity

Unmasking Double-Clickjacking: How This Cyber Attack Exploits Users

Every cyber attack evolves, but few are as deceptive as double-clickjacking. This insidious online threat manipulates users into unintentionally performing actions on websites, potentially exposing personal data or granting unauthorized access. As cybersecurity risks grow, businesses and individuals alike must understand how double-clickjacking operates and why it’s becoming a significant concern in 2025.


What Is Double-Clickjacking and Why Should You Care?

Double-clickjacking is a refined version of clickjacking, a cyber attack that tricks users into interacting with hidden or malicious elements on a webpage. Unlike standard clickjacking, this method requires two deliberate clicks, exploiting users’ trust and creating a false sense of security.

The implications are alarming: attackers could initiate financial transactions, change security settings, or steal sensitive data—all without the user’s awareness. With the increasing reliance on digital platforms, understanding this threat is critical to safeguarding personal and professional digital spaces.


The Mechanics of Double-Clickjacking: How Hackers Exploits Users

At its core, double-clickjacking relies on overlaying invisible elements, such as buttons or forms, onto legitimate web pages. Users are prompted to interact with these elements through misleading instructions like “Click here to verify.” The first click sets the stage, while the second completes the malicious action.

What makes this attack particularly dangerous is its subtlety. Unlike phishing emails or obvious malware, double-clickjacking blends seamlessly into everyday browsing activities, making it harder to detect and prevent.


A Growing Threat: How This Cyber Attack Is Targeting Users

Recent reports indicate a rise in sophisticated double-clickjacking campaigns targeting both individuals and organizations. This increase is tied to the growing use of interactive web applications, where clicks are integral to functionality.

As attackers refine their methods and develop more deceptive tactics, organizations must stay ahead with proactive defense strategies.


How to Protect Yourself from This Cyber Attack

Awareness and proactive measures are key to mitigating the risks of double-clickjacking. Here are some actionable steps:

  1. Enable Browser Security Features: Modern browsers offer protections against malicious scripts and overlays.
  2. Use Content Security Policies (CSPs): These can prevent attackers from embedding unauthorized elements on your site.
  3. Educate Employees and Users: Teach users to verify web interactions and avoid unfamiliar prompts.
  4. Invest in Cybersecurity Tools: Tools that detect and block clickjacking attempts can add an essential layer of protection.

By staying vigilant, you can significantly reduce your exposure to these attacks.


Staying One Step Ahead

Double-clickjacking is a rising cyber attack that thrives on deception and user trust. Its growing sophistication highlights the importance of staying informed and taking preventive measures. Whether you’re an individual or a business leader, understanding the mechanics of this threat is the first step toward stronger cybersecurity.

Contact us for more info about protecting your business from double-clickjacking and other cyber attacks.

For more technology articles like this, visit our Content Hub at Tech Scope Connect.

Read More
cybersecurity
Cybersecurity

Patch Management in Cybersecurity: More than Just Routine Updates

In the rapidly evolving world of digital transformation, one constant remains: the unrelenting necessity of keeping systems and applications current and secure. While software updates often bring the allure of new features, their most crucial function is far more defensive. Enter: Patch Management.


Delving Deeper into Patch Management

Patch management isn't just a series of steps for system upkeep; it's the frontline defense against potential cyber threats. At its core, patch management involves identifying, acquiring, installing, and verifying updates known as "patches" for various software and systems. These patches, whether they address small bugs or critical vulnerabilities, can significantly dictate a business's security posture.


Unpacking the Critical Role of Patch Management in Cybersecurity

  1. Enhancing Security: Cyber threats are ever-evolving, with attackers frequently seeking out and exploiting vulnerabilities in software. These vulnerabilities can be gateways for malware infections, data breaches, and other malicious activities. Patching helps seal these gateways, denying cybercriminals an easy point of entry.
  2. Guaranteeing System Stability: Beyond security, patches correct glitches and bugs that can lead to system crashes or reduced functionality. By addressing these, companies ensure that their operations remain fluid, efficient, and uninterrupted.
  3. Upholding Compliance Standards: Regulatory bodies recognize the importance of timely patching. Many industries face stringent guidelines necessitating updated and secure IT systems. Adherence to patch management can mean the difference between passing or failing a critical audit.
  4. Optimizing System Performance: Contrary to the belief that updates may slow down systems, many patches enhance software's performance metrics, making programs run faster and use resources more efficiently.


What are Zero-Day Exploits?

A "zero-day exploit" refers to an attack that targets a software vulnerability unknown to the software vendor, and for which no official fix or "patch" exists. The term "zero-day" denotes that the software's developers have "zero days" to fix the problem before the exploit can potentially harm users.

Zero-day vulnerabilities are valuable to malicious actors because they target gaps in software defenses that are unaddressed, making them particularly effective and damaging. Typically, when such a vulnerability is discovered, there's a race against time: hackers try to exploit it as much as possible before it gets fixed, while software developers scramble to release a patch to address the flaw.

Given the threat of zero-day vulnerabilities, how does patch management play a role?


The Role of Patch Management

The role of patch management in the context of zero-day exploits is two-fold:

  1. Reactive Approach: When a zero-day vulnerability becomes known to the public or the software vendor, the software developers rush to create a patch. Once the patch is available, organizations must apply it swiftly to minimize the exposure window. Effective patch management ensures that these patches are deployed consistently and promptly, reducing the risk of successful exploitation.
  2. Proactive Approach: Regular and effective patch management can indirectly help protect against some zero-day exploits. By ensuring that all other known vulnerabilities are patched, organizations reduce the number of potential entry points for attackers. When attackers gain entry through a known vulnerability due to a missing patch, they might discover and exploit zero-day vulnerabilities in the system. Keeping the system up-to-date makes it harder for attackers to find an initial entry point.


Enhancing Patch Management with Dedicated Software

Acknowledging the significance of patch management, the tech industry has developed a suite of tools aimed at streamlining the process. These aren’t mere conveniences; they're force multipliers in the battle against cyber threats.

  • Automated Discovery: A single missed update can be a potential Achilles heel. Automated tools ensure nothing slips through by pinpointing systems lacking critical patches.
  • Centralized Oversight: With myriad systems running simultaneously, centralized patch management software provides a unified, coherent approach, eliminating inconsistencies and redundancies.
  • Strategic Deployment: Timing is everything. By deploying patches during periods of low activity, businesses can avoid disruptions during peak operational hours.
  • Safe Testing Grounds: Rolling out a patch organization-wide without testing can be risky. Advanced tools offer controlled environments to test patches, safeguarding against potential conflicts or issues.
  • Audit-ready Reporting: In the era of accountability, maintaining a meticulous record of all patch deployments is paramount, especially for compliance and regulatory purposes.
  • Versatility Across Platforms: The diverse software ecosystem demands tools that can seamlessly cater to various operating systems and applications. The best patch management solutions are versatile and adaptable.


Final Words

Though patch management might seem like a mundane IT task, its repercussions in the cybersecurity landscape are monumental. It's the unsung hero that works silently in the background, ensuring business continuity, safeguarding data, and maintaining system integrity.

Don't wait for a breach to realize the significance of routine updates. Evaluate your patch management strategies today. Remember, in the realm of cybersecurity, vigilance, and regular updates aren't just best practices—they're your first line of defense. Be proactive, stay updated, and ensure that your digital realms remain uncompromised.


Experience the Future of Technology Today!

Take your knowledge and passion for technology to the next level! Watch our Summit of Things 2023 On-Demand videos for 30 days and experience a premier tech event that will let you enter the dynamic world of IoT and gain insights into the future of technology.

This summit is your gateway to connect with industry leaders, explore cutting-edge innovations, and start a journey for a tech-driven future. You can still catch up and learn from our 30+ experts from all over the world! Buy your tickets at https://iotmktg.com/summit-of-things-2023/.


Read More
ransomware
Cybersecurity

The Peril of Zero-Day Attacks and the Changing Face of Ransomware: Insights from Akamai

A "zero-day attack" refers to the exploitation of a software vulnerability that is unknown to the software vendor or, in some cases, the vulnerability is known but a fix or patch has not been released yet. The term "zero-day" essentially means that developers have "zero days" to fix the problem because it's already being exploited in the wild.

Here's a more detailed breakdown:

  1. Vulnerability Discovery: A hacker or researcher finds a security flaw in a software, which isn't known to the public or the software's developers.
  2. Zero-Day Exploit Creation: The hacker creates an exploit—a method to take advantage of the vulnerability—to compromise the software or system.
  3. Undetected Phase: The exploit is used against targets without the knowledge of the public, software developers, or antivirus firms. This period can last from days to even years, during which the hacker can use the exploit without any detection.
  4. Public Disclosure: The vulnerability becomes known to the software vendor or the public, often due to detection by security researchers or when it becomes widely used by hackers.
  5. Patch Development: Once the software vendor knows about the vulnerability, they will usually start to work on a fix or patch for it.
  6. Patch Deployment: The software vendor releases the patch to the public. Systems that update with this patch become protected against the vulnerability.

Zero-day attacks are especially concerning because they target vulnerabilities for which there are no current defenses. This makes them very effective and potentially damaging. As a result, there's a black market where zero-day vulnerabilities and their exploits are bought and sold for significant amounts of money. The buyers can range from governments to criminal organizations.


Rampant Abuse of Zero-Day and One-Day Vulnerabilities

Diving deeper into the impact of these vulnerabilities, a recent report by Akamai Technologies Inc., titled "Ransomware on the Move: Exploitation Techniques and the Active Pursuit of Zero-Days", shines a spotlight on the evolving threats within the ransomware domain. The findings are alarming: there has been a 143% spike in the number of ransomware victims between Q1 2022 and Q1 2023, attributed to the rampant misuse of Zero-Day and One-Day vulnerabilities.

The report further unveils a concerning evolution in ransomware strategies. Perpetrators are increasingly turning to file exfiltration—unauthorized extraction or transfer of sensitive data—as their main mode of extortion. This development underscores the point that merely backing up files isn't enough to secure against contemporary ransomware threats.

In the ever-shifting world of cyber-threats, LockBit ransomware has emerged as the dominant force, claiming responsibility for 39% of all victims from Q4 2021 to Q2 2023. This figure dwarfs the number affected by the next most prolific ransomware group, which is over four times smaller. Additionally, the CL0P ransomware group has been actively developing zero-day vulnerabilities, marking a 9x surge in its victims year-on-year.

Manufacturing, an industry vital to global supply chains, saw a 42% escalation in victims between Q4 2021 and Q4 2022, with LockBit behind a significant 41% of these attacks. The healthcare sector wasn't spared either, observing a 39% uptick in victims, primarily at the hands of ALPHV (or BlackCat) and LockBit ransomware factions.

Some more salient points from the report include:

  • Firms reporting revenues up to $50 million faced the highest threat, accounting for 65% of targets.
  • Those victimized more than once by ransomware had a staggering 6-fold likelihood of experiencing another attack within three months of the initial breach.
  • Financial institutions witnessed a 50% rise in the total number of affected organizations year-on-year. Meanwhile, the retail sector took the third spot in terms of industry-specific ransomware victims, seeing a 9% increase.

Commenting on the gravity of the situation, Pavel Gurvich, Senior Vice President and General Manager, Enterprise Security at Akamai, stated, "Adversaries behind ransomware attacks continue to evolve their techniques and strategies striking at the heart of organizations by exfiltrating their critical and sensitive information." He emphasized the importance for organizations to stay abreast of these evolving threats to ensure their ongoing security and resilience.

For a more comprehensive understanding of these findings and to connect with Akamai's threat research team, interested individuals and organizations can visit the Akamai Security Hub and follow them on Twitter at @Akamai_Research.


Conclusion

The recent findings from Akamai Technologies highlight an alarming trend in the cyber threat landscape. Zero-day and one-day vulnerabilities, once just a niche concern in the cybersecurity world, have now escalated ransomware attacks to unprecedented levels. With ransomware groups like LockBit leading the charge and a drastic shift towards file exfiltration as a primary extortion method, organizations across all sectors find themselves at heightened risk.

It's clear that traditional defensive measures, such as mere file backups, are no longer adequate in this evolved threat scenario. As cyber adversaries become increasingly sophisticated, organizations must proactively update their defensive strategies and remain ever-vigilant. The onus is not just on enterprises but also on cybersecurity solution providers to innovate, educate, and prepare for the continually morphing challenges ahead.


Experience the Future of Technology Today!

Take your knowledge and passion for technology to the next level! Watch our Summit of Things 2023 On-Demand videos for 30 days and experience a premier tech event that will let you enter the dynamic world of IoT and gain insights into the future of technology.

This summit is your gateway to connect with industry leaders, explore cutting-edge innovations, and start a journey for a tech-driven future. You can still catch up and learn from our 30+ experts from all over the world! Buy your tickets at https://iotmktg.com/summit-of-things-2023/.


Read More
IoT Secure Passwords
Cybersecurity

Best Practices in Securing Passwords for IoT Devices

In an era dominated by digital connectivity, robust password security becomes a necessity for all users. Today's digital world requires strong password security, extending beyond online accounts to a growing range of IoT devices like smart thermostats and cameras. Basic password rules apply universally, but IoT devices bring their own unique security challenges. These devices not only widen the scope of our digital footprint but also expose our physical spaces to cyber risks.

The increasing number of attacks on IoT devices highlights the need for enhanced password security strategies for these specific assets. Whether securing your email or your smart home, effective password management is key to protecting against cyber-attacks. This guide will cover essential and IoT-specific password best practices to help you enhance your overall digital and connected security. Don’t forget to check out our comprehensive guide for password security for the basic password rules.

Password Do's for IoT Devices

1. Default Passwords

Change the DefaultIoT devices often come with default usernames and passwords that are easy for attackers to guess. Always change these as soon as you set up the device.

2. Device-Specific Passwords

Unique Credentials: Given that IoT devices are often linked to control centers or even your smartphone, use different passwords for the device and the control account.

3. Complexity Matters

Strong Passwords: Even if the device seems trivial, like a lightbulb, ensure that the password is strong. Attackers can use less secure devices as entry points into your network.

4. Two-Factor Authentication (2FA)

Enable if Possible: Some advanced IoT devices may offer 2FA. Make use of this feature when available.

5. Network Segmentation

Different Network: If possible, place your IoT devices on a separate network from your main computing devices. This adds an extra layer of security in case the IoT device is compromised.

6. Periodic Updates

Change Passwords Regularly: Just like your other accounts, the passwords for IoT devices should be updated periodically.

7. Recovery Methods

Secure and Up-to-Date: Make sure that the recovery methods are not only secure but also up-to-date. If you lose access to the device, a secure recovery process is essential.


Password Don'ts for IoT Devices

1. No Defaults

  • Don't Keep Default Credentials: This can't be emphasized enough. Attackers often have lists of default credentials for various IoT devices.

2. No Shared Passwords

  • Don't Use Common Passwords: Your IoT devices should not share passwords with each other or with any of your other accounts.

3. Avoid Public Networks

  • Don't Connect to Insecure Networks: Whenever possible, don't connect your IoT devices to public or unsecured Wi-Fi networks.

4. No Open Controls

  • Don't Leave Admin Panels Open: Always logout of admin panels and control centers for IoT devices and smart appliances when you're done configuring them.

5. Ignore Security Alerts

  • Don’t Neglect Warnings: IoT devices may not have as sophisticated alert systems as other platforms, but if you do receive a security alert, take it seriously.

6. No Easy Recovery

  • Don’t Use Easy Recovery Questions: If the device allows for recovery questions, make sure they are not easily guessable or searchable.

7. Overlook Software Updates

  • Don't Ignore Updates: IoT devices often receive firmware updates that may include security patches. Make sure to apply these updates promptly.


Conclusion

Overall, the surge in IoT-related cyber-attacks serves as a stark reminder of the importance of robust password security for these assets. Whether it's securing your email or fortifying your smart home, effective password management remains the linchpin of defense against cyber threats.

While many of the core principles of password security remain the same, IoT devices introduce unique challenges and risks that warrant special considerations. Always read the security guidelines provided by the manufacturer and remain vigilant to protect your connected devices.


Read More
Password Security
Cybersecurity

The Do’s and Don’ts of Password Security: A Comprehensive Guide

In today's digital age, safeguarding your personal information is more critical than ever. From online banking to social media accounts, almost every digital platform requires a password for authentication. Unfortunately, password breaches are becoming increasingly common, placing your personal and financial data at risk.

Understanding how to create and manage secure passwords can be the difference between protecting your data and falling victim to cyber-attacks. Here, we explore the do's and don'ts of password security to guide you in maintaining a bulletproof digital presence.

Do's of Password Security

1. Craft a Strong, Unique Password for Every Account

  • Combine Upper and Lower-Case Letters: Use a mix of upper-case and lower-case letters to add complexity to your passwords.
  • Integrate Numbers and Special Characters: Include numbers and special characters in your password. The more randomly these are placed, the better.
  • Ensure Uniqueness: Make sure each password is unique to each account or application you use.

2. Consider Using Passphrases and Memorable Phrases

  • Employ Passphrases: A passphrase—a sequence of words or a sentence—is generally easier to remember than a random string of characters but can be just as secure.
  • Utilize Song Titles or Phrases: Convert familiar song titles or phrases into a more complicated string by incorporating numbers and special characters. (e.g., "Somewhere Over the Rainbow" becomes "Sw0tR8nBO")

3. Leverage Two-Factor Authentication (2FA

Whenever possible, enable 2FA on your accounts for an added layer of security, typically via a mobile device.

4. Utilize a Reputable Password Manager

A password manager can securely store and manage your various passwords, making it easier to maintain strong, unique passwords for each account.

5. Periodically Update Your Passwords

Change your passwords every few months to reduce the risks associated with password leaks or hacks. This aligns with advice from both lists.

6. Maintain Privacy and Control

  • Monitor Account Activity: Regularly check your accounts for any suspicious activity. Change your password immediately if you notice something amiss.
  • Keep Passwords Private: Never share your passwords with anyone. Once it’s out of your control, so is your security.

7. Secure Your Account Recovery Methods

Ensure that the email address or phone number associated with your password recovery options is also secure. In the event that hackers gain access to your recovery email, they could reset passwords for multiple accounts.


Don'ts of Password Security

1. Avoid Using Personal Information

  • Skip Using Identifiable Information: Do not use your name, birth date, social security number, or other personal identifiers, including names of pets, friends, or family.
  • Don't Use Usernames: Never create a password using your username in any form, whether reversed, capitalized, or doubled.

2. Never Reuse Passwords

  • Avoid Multi-Account Risk: Do not use the same password for different accounts. If one account is compromised, all others could be at risk.
  • Don't Reuse Old Passwords: Refrain from reusing any of your last 10 passwords.

3. Safeguard Your Password

  • No Written Records: Don't write down your passwords or store them in text files on your computer.
  • No Easy Storage: Avoid using the "Save Password" option if prompted and don't store passwords near your computer.

4. Don't Share Your Password

  • Maintain Privacy: Never share your password with friends, family, or coworkers.

5. Evade Dictionary Attacks

  • Avoid Dictionary Words: Don't use words found in dictionaries or common phrases, even if spelled backward.
  • No Short Passwords: Use passwords that are at least 12 characters long to minimize the risks.

6. Be Mindful of Predictable Patterns

  • Avoid Keyboard Sequences: Don't use sequences of keys next to each other on the keyboard (e.g., "asdfghjkl").
  • Avoid Dates: Don't use dates to create passwords, such as birth dates or significant events.
  • No Number Substitutions: Don't use numbers in place of letters in an obvious manner, like "Pa55w0rd."

7. Act on Security Alerts

If you receive a security alert about a possible unauthorized login or a data breach involving a service you use, act immediately by changing your password.

8. Maintain Physical Security

  • Log Off from Shared Computers: Don't walk away from a shared computer without logging off to ensure no other users can access your accounts.

9. Be Cautious of Online Guidance

  • Don't Use Sample Passwords: Avoid using sample passwords provided on different websites, as they're often not secure.

This guide offers a comprehensive approach to maintaining robust password security. Staying vigilant and adhering to these guidelines can go a long way in protecting your digital assets and will significantly mitigate the risks associated with various cyber threats.


Conclusion

Password security is a critical component of your overall digital safety. By adhering to the do's and avoiding the don'ts, you can significantly mitigate the risks associated with cyber threats. It's a small investment of time and attention that can provide significant benefits in protecting your online presence.

Remember, the time and attention invested in password security today can yield immeasurable benefits in safeguarding your online presence against the evolving world of cyber threats. Stay secure, stay vigilant, and protect your digital legacy.


Read More
ransomware attack
Cybersecurity

Kaseya Launches Patches to Address Security Loopholes

A ransomware attack prompted Kaseya to roll out new patches as a means of securing customers. Specifically, the Virtual System Administrator, or VSA, was exploited by cybercriminals. Potentially, 1,500 or more businesses worldwide were affected by ransomware owing to holes in associated security.

Kaseya told customers that were suspected of being infected with this ransomware to deactivate servers ahead of the coming patch. It took about ten days, but now a patch has arrived. Specifically, this patch rectifies a number of notable security flaws. These include the following:

  • Fixing a bypass in two-factor authentication
  • Logic flaw and credential leaks
  • Vulnerabilities in cross-site scripting


Understanding What Happened to Secure Your Business

Since Kaseya’s software is primarily of the Software as a Service (SaaS) variety, infection at the core of Kaseya ultimately affects a diversity of users. It’s like poisoning a river while it’s a creek up the mountain: the waters keep flowing, and many downstream get poisoned.

Well, in this case, the “downstream” folks were those using endpoints, of which current estimates put the number impacted in the neighborhood of a million. At least, that was the claim of the hackers. It’s a plausible claim. If each affected business had 1,000 endpoints, then 1,500 affected businesses would average a little under 700 endpoints per operation.


The Timeline of the Attack

Initial instances of contamination were observed around July 2nd, and as of July 13th, things had been curbed. REvil and Sodinikibi were first realized to be the ransomware culprits. By July 4th, a detection tool was launched to help businesses know if they were compromised.

Damages from the ransomware were only lightly covered by media outlets and the full extent of the cyberattack was not explored in depth. By July 5th, a $70,000,000 demand was issued by hackers to Kaseya. By the 6th, a patch was supposed to be online, but delays knocked it back. The delay continued through July 7th. By the following day, fake email warnings were going out, further compromising affected parties.

On the 10th of July, it was revealed key leaders among Kaseya knew about the vulnerability exploited by hackers, but said nothing; or at least not enough–whistleblowers revealed this. By the 11th, real patches began to be implemented. Progress was made by the 12th, by the 13th, IT Glue Integration was able to be reactivated.


What Can Be Learned?

This was a “zero day attack”, and more details are explained in The Washington Post. Essentially, the cybercriminals exploited an attack even sophisticated higher-level IT officials were unaware of–but for those exposed by the whistleblower, of course. Call what happened to Kaseya a sort of canary in the coal mine. An attack like this will happen again, and to another large company providing services via cloud-based technology.

Certainly, there will be increases in security. Patches will be disseminated. However, zero day attacks incorporating “streams” of data at cloud-based “nodes” will continue to affect a wide variety of customers going forward. That’s just the unattractive reality of the situation. Also, this is a sort of hack attack that has government influence–the Post article seems to believe the Kremlin could have halted the attack.

Well, it’s hard to know whether the Post is playing politics or not these days. What’s easy to know is that patching solutions for security are perhaps more fundamental than ever. When new security options become available, you need to tap into them right away. Also, it’s important to have failover protections in place that can cover several weeks of operating without core tech functionality.


What To Do

Cybercrime is nothing new, but sometimes the way in which it is pursued is novel. Therefore, it would be best to have all the latest security, and partner your business with cybersecurity professionals who make top-tier security a primary prerogative. Also, it is wise to compartmentalize sensitive data so that ransomware attacks like this won’t impact your business operations. Lastly, keep employees well-trained on the latest best practices to ensure they’re always up to date on how to conduct themselves amid shifty digital waters safely.


Read More
ransomware attack
Cybersecurity

Kaseya Ransomware Attack: What You Need to Know So Far

What Happened?

Recently, there was a ransomware attack on Kaseya, a tech company out of Miami whose primary services involve providing a worldwide customer base with tech management solutions. The group that did the attack is called REvil, and they’re reputed to have been responsible for shutting down both a major meat processor and the colonial pipeline attack earlier this year.


What’s The Impact?

The fallout from this latest developing ransomware attack has impacted hundreds of Kaseya’s customers. In Sweden, there were grocery and pharmacy chains impacted, as well as a railway. These customers of Kaseya suffered direct impact from the ransomware.

The attack was noticed and addressed publicly as of July 2nd. Presently, it’s expected that approximately 36k companies have been in one way or another impacted by the attack on Kaseya.

As of July 7th Kaseya is advising customers with on-premise VSA servers to remain offline until they receive the patch along with futher security recommendations. On Sunday, July 4, Kaseya began advising some SaaS customers in Europe, Asia, and the UK to begin reactivating servers. Monday saw Kaseya begin advising the same in the United States for certain clients. Unfortunately on July 6th they discovered an issue and will be delaying restoration of SaaS services until the evening of July 8th. Presently, the totality of the issue has not yet been resolved.


Preventative Measures

A detection tool was released to some 900 customers which reveals whether or not some sort of compromise has taken place in terms of security. This ransomware attack is presently being investigated by the FBI and the US Cybersecurity and Infrastructure Agency. For the majority of clients, returns in stages are being perscribed–at least in regards Software as a Service (SaaS) server arrays whose functionality was diminished by associated precautions.

In order to avoid compromise if your company is involved with Kaseya tech solutions, look into any products related to VSA either directly or indirectly. This is where the ransomware is “centered” so avoid using endpoint options related to VSA until Kaseya gives your company the go-ahead. The crux is, VSA is aimed at small to medium-sized businesses and is designed for remote monitoring solutions, as well as routine maintenance such as updates in security software.

The good news is, Kaseya has told the press that they are completely positive with regards to the genesis of this ransomware attack, and they’ve taken the proper steps to fix the issue. However, given how recent the event is at the time of this writing, it’s wise to be as cautious for a few more days at least. Ransomware, adware, and Trojan malware can hide until hackers activate it.


Safeguarding Operations

The threat of a ransomware attack won’t go away; at least that’s the expectation of those who make IT pursuits their professional business. The attacks will simply shift over time. Even large companies can be impacted. Why is this the case? Well, as new tech develops, so also do new ways of misusing that tech in an illegal manner. Accordingly, new threats follow new innovations. So to recap:

  • Kaseya has addressed the issue and is beginning to restore services
  • Presently, it’s wise to be cautious, given how recent the attack was
  • Outsourcing tech security to cybersecurity experts is advisable


Improving Operational Security

Though Kaseya has addressed the REvil attack, you will want to remain cautious, and locally outsourcing tech security is wise. Also, you should train staff with regards to best practices, and assure all your data is properly backed up in a way that allows a secure reboot.

Read More
Learning from Top Data Breaches
Cybersecurity

Learning from Top Data Breaches in History

Even though you may not hear much about the top data breaches in the news unless you read tech publications, several horrific examples have occurred in the past few decades. These cybersecurity meltdowns can cost millions of dollars to fix the damages on top of litigation and reputation issues. Here’s a look at some of the worst online data disasters of all time.

Related: Why You Need to Strengthen Your IIoT Security


Adobe, October 2013

Over 150 million user records were breached as Adobe reported cybercriminals gained access to nearly 3 million credit card records. The hackers were also able to crack encryption and steal login data for an initially unannounced number of accounts. Later in the month, Adobe added that IDs and passwords were breached for 38 million active users.

Many cybersecurity experts considered this event one of the top data breaches at the time. Adobe paid over $1 million in legal fees and an undisclosed amount to victims who filed claims against the graphic design provider for violating the Customer Records Act. Yet bigger breaches affecting other big players would follow.


MySpace, 2013 and Yahoo, 2013-2014

At one time, MySpace was the biggest social network while Facebook was the newcomer until it dominated social media in 2009. By 2013 MySpace was becoming a fading website, overshadowed by several social networks. What brought the original king of social media back into tech industry news in 2016 was the company’s announcement of a breach impacting 360 million user accounts three years earlier.

The data became available for sale on LeakedSource, a searchable database of stolen passwords used by hackers on the dark web. As bad as that breach sounds, it wasn’t nearly as shocking as Yahoo’s 2013-2014 breach of 3 billion user accounts. Technically, that’s actually the biggest breach ever if you count the victims.

First, Yahoo said in 2016 the disaster affected 500 million users, then revised it to the 3 billion figure the following year. These attacks eventually cost Yahoo’s later parent company Verizon about $350 million.

Keep reading: 5 Ways to Keep Smart Appliances Safe from Security Threats


eBay, May 2014

This cybersecurity breach exposed the online marketplace provider’s entire list of user accounts, which added up to 145 million. Hackers broke through encrypted passwords to breach confidential information such as names, addresses, and birthdates. Fortunately, credit card numbers were stored in another location and weren’t compromised.


Equifax, July 2017

One of the most widely-reported data breaches affected one of the three major credit bureaus. It exposed around 143 million customer accounts. It proved that no one is too big to be immune to a cyberattack. Even though the company originally thought the breach occurred on July 29, it later announced the attack probably began in May.

Exposed in the breach were consumer credit card numbers, social security numbers, drivers’ license numbers, and other confidential data. An unpatched application vulnerability allowed the attackers to penetrate the system. Not only was the network not well segmented, Equafix did not report the incident to the public immediately.


Canva, May 2019

The Australian graphic design cloud service was hit with a cyberattack that compromised email addresses, usernames, and other sensitive information, which impacted about 61 million users. Canva initially stated the attack was limited to the intruders viewing data without stealing it. Known as Gnosticplayers, the perpetrators notified ZDNet to take credit for the attack.

Later the story got worse when Canva revealed about 4 million user accounts with hacked passwords were discovered by the company. More shockwaves were felt when the company announced these passwords had been decrypted and shared online.

Read more: All You Need to Know About Ransomware and Ways to Prevent It


Conclusion

What can we learn from the top data breaches of all time? One thing is that organizations of all sizes – even tech or financial giants – can be breached. Another revelation is we usually don’t find out about the worst breaches until years later. So, it’s best to take cybersecurity seriously and implement the strongest cybersecurity strategies available for both personal and business related data.

Read More