- News & Resources: Listings >
- Blog
- How to Improve Safety and Security in Schools – Cloud Manage Network
- Top 10 Cybersecurity Threats in 2024
- Microsegmentation: Protecting Data from Cyber Threats
- Retail shoplifting and loss prevention: How to protect your business
- Generative AI Cost Optimization Strategies
- Why Do I Need to Protect My Cloud?
- 10 Reasons for Engaging Outside Experts to Manage Your Cybersecurity
- Why Hiring a 3rd Party MSP Expert Makes Sense and – and Cents (MANY cents!)
- Brand and Network Considerations When Adopting AI Corporately
- Integrating XDR, SIEM, and SOAR
- 3-2-1 –Go? Not so quick, this time.
- 5 Things a CISO Shoud Know
- 10-Step Patch Management Checklist
- Penetration Testing vs. Breach Attack Simulation
- Current big cyber breaches and impact on businesses
- Smart Infrastructure Gets Lit Up!
- Securing Industrial IoT: The Missing Puzzle Piece
- 7 Common Cybersecurity Mistakes Made by SMBs
- The Future of Physical Security: Cloud-Based Systems
- Autonomous and Sensor Technology Use Surging
- 2024 Facilities Trends Will Require Facilities and IT Teams to Work in Tandem
- NGFW vs. WAF. What’s the Right Firewall for You?
- Chris Hadfield’s Words To Live By
- Industrial Revolution 4.0 + IIoT
- Digital Fluency Drives Innovation
- Your Cloud Needs Protecting, Too
- Your building alarm systems could become obsolete. In 2024!
- Zero Trust 2.0: Zero Trust Data Resilience (ZTDR)
- We just got, or got used to, Wi-Fi 6. What is Wi-Fi 7?
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – 4th and Last in a Four-Part Series
- Why 2024 is the Year for AI Networking
- International Women’s Day is Tomorrow – Great Time to Think About…
- Data-Centric Security Step One: Classifying Your Data
- The Network – Unsung Hero of Super Bowl LVIII
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – Third in a Four-Part Series
- Boosting IT Team Performance by Fostering Intuition, Curiosity and Creativity
- Breach Remediation Costs Can Wipeout Bottom Line and Business
- Hoodied Hackers Now Favour Hugo Boss
- What Do You Need to Tell the Board? Business Metrics that CISOs Should Share – Second in a Four-Part Series
- How to Get People to Re-Engage After the Holidays
- What Does the Board Need to Know? Business Metrics that CISOs Should Share – First in a Four-Part Series
- Android Devices MUST be Updated + IT Departments Being Cut as Privilege Escalation Escalates
- Today’s Common Cloud Migration and Management Concerns
- Protect Your Healthcare Network from Cyberattack – Lives are at Stake
- Happy Halloween: Black Cats Lead to Boo….Hoo.
- Insurance Underwriters are Protecting Their Flanks
- Insurance Companies Cracking Down as Cybercriminals Become Better Business Builders
- Scary Cyberattacks Stats
- Parents, Profs and IT Professionals Perceive Back-to-School Through Different Lens
- Zscaler’s new IDTR and other tools that leverage generative AI
- Vanquish Vaping, Vandalism and Villainy
- Fabric for Fast-Paced Environments
- Changes to Cyber Insurance Requirements – What you Need to Know
- Cybersecurity Readiness – Newly Released Report
- Passwords Leaked…Again
- 10-Step Patch Management Checklist
- Remote – Again – For Now… and Still Maintaining Engagement
- Protecting Pocketbooks, Passwords and Property from Pilfering
- Raspberry Robin: Highly Evasive Worm Spreads over External Disks
- Cisco Introduces Responsible AI – Enhancing Technology, Transparency and Customer Trust
- Managing Customer Trust in Uncertain Supply Chain Conditions
- Hope on the Horizon
- Toys of Tomorrow… What will spark your imagination? Fuel your imagination?
- Protecting Purses and Digital Wallets
- The Password that Felled the Kingdom + MFA vs 2FA
- The MOE’s RA 3.0 and Zscaler
- 7 Critical Reasons for MS Office 365 Backup
- Penetration Testing Important, but…
- Social Engineering and Poor Patching Responsible for Over 90% of Cybersecurity Problems
- Breach Incidence and Costs On the Rise Again + 5 Ways to Reduce Your Risk
- Cybersecurity Insurance Policies Require Security Audits and Pen Testing
- Wireless strategies for business continuity gain importance as enterprise expand IoT, cloud, and other technologies
- How Cybercrooks are Targeting YOU
- Enabling Digital Transformation with Cisco SD-WAN
- WFH Post Pandemic – What It Will Look Like. What You’ll Need.
- Leaders to looking to the IoT to improve efficiency and resiliency
- Cyber Security Vernacular – Well, some of it, for now
- Why You Need Disaster Recovery, NOT Just Back-Ups
- 10 Reasons Why Having an Expert Manage Your Cybersecurity Makes Sense and Saves Dollars
- Converting CapEx IT Investments into Manageable OpEx
- The Hybrid Workplace – Planning the Next Phase
- Cisco Cloud Calling: Empowering Customers to Thrive with Hybrid Work
- When You Can’t Access the Cloud
- How to Keep On Keeping On
- New Cisco Research Reveals Collaboration, Cloud and Security are IT’s Top Challenges
- Threats from Within on the Rise
- Cloud Covered? If Not, Take Cover!
- Zero Trust and Forrester Wave Report
- Password Based Cyber Attack: Like Leaving Keys Under Doormats
- So, What’s Up With Sensors?
- Sensors and Systems Create a Digital “Last Mile” and Help Skyrocketing Costs
- Scanners Provide Peace of Mind for Returning Students and Workers
- Sensors Improve Operations and Bottom Line… Easily and Cost-Affordably.
- Cisco Meraki Looks at 2021
- 2020 Holiday Shopping: Cybersecurity and Other Tips to Safeguard Wallets and Systems
- How to make the most of the technology you have
- Personnel, Planet and Business Progress: More Interdependent Than Ever Before
- Sure… you can get them all in the boat – but can you get them to work well together?
- Pushing the Zero Trust Envelope – Cisco is Named a Leader in the 2020 Forrester Zero Trust Wave
- Cloud Data Must be Protected, Too!
- Don’t Let Anyone Get the Dirt on You – Make It Instead!
- How IoT Devices Can Help You and Your business
- WebEx – A World of Possibility
- Creating Your Breach Response Plan Now Will Save You Thousands Down The Road
- Been hacked? Here’s what you must do next.
- The Need for Pen Testing is At an All-Time High
- 5 Ways an IT Reseller Improves Your Performance and Peace-of-Mind
- 5G and Wi-Fi 6: Faster, more flexible, and future ready. Are you?
- Network and Data Security for Returning and Remote Workers + Disaster Recovery Symposium
- Collaboration and Cisco WebEx: Protecting Your Data
- Thursday’s Virtual Conference Tackles Today’s Supply Chain Trials and Tribulations
- 10 Tips to Reduce Cloud Storage Risk
- COVID-19 Crisis Fuelling IT Spending
- Supply Chain/Logistics Experts Share Their Expertise
- Cisco Breach Defence Overview
- Announcing Our New Website and Blog
The ghostly night that ghouls relish is now upon us. Goblins will gobble up tasty treats. Little kids will scamper in the streets. Teens will jump out of the bushes yelling, “Boo!”, while black cats cross your path. It has been a spooky month, indeed.
On Friday the 13th we issued a warning about increasing threat vectors that, unfortunately, proved necessary. Then along came the Scattered Spider, along with a black cat that can leap onto your unpatched FTP server, creating massive damage.
First, the Spider
Although it was not their first rodeo, Scattered Spider gain fame (though ‘infamy’ may be more accurate) by digitally infiltrating MGM Resorts and Caesars Entertainment, last month. Total losses: +$100 Million.
What makes this notable is that, according to CyberArk Offensive Tech Researcher Andy Thompson, the threat vectors didn’t get into the system through malware. Instead, the attackers used the bona fide users’ credentials to gain remote access. How?
The process I’m about to describe applies to attacks that have been made on telecommunications firms, municipalities, manufacturers, educational institutions and others. First, they teach young video gamers in the UK and North America how to scour social media platforms to acquire the information needed to impersonate an actual employee.
Then they show them how to use this information to convince a company’s IT Help Desk personnel that they are a legit stakeholder, often getting the IT person to bypass Multi-Factor Authentication. One moment of compassion for a young, innocent sounding voice with a compelling story and the damage is done.
But… These bad actors, some of whom are as young as 15 or 16, then hand off the credentials to access brokers or larger groups that specialize in ransomware and other malware.
This is scary enough, but these organized hackers aren’t just looking for identities and proprietary data. According to Jenkins, they are also searching for your AWS panel root account The goal: to gain access to your Jenkins stacks so they can use your cloud platform crypto mining. Imagine what that would do your operations!
If you listened to our September video interview, you heard how cybercrime has become a well-organised, well-oiled industry, and can see how access brokers (and ChatGPT) are changing the cybercrime landscape. For now, one of the deterrents is still having a robust Multi-Factor Authentication (MFA) in place as an important line of defence. Many people recognize the importance of having MFA on their endpoints, but it is also needed within the cloud, and it each access stage as users go deeper into your network.
What does this mean for you, and what should you do?
-
Organisations need to recognize that students and young low-income earners are vulnerable and susceptible to being lure to the dark side (i.e. the dark web). As a result, employee onboarding and ongoing training must include a serious discussion on the topic – and a warning that hacking is a crime for which jail time can be severe.
-
Review and, as necessary, revamp your hiring and onboarding practices, as well as your IT protocols and training.
-
Orphaned assets present great risks. Not surprisingly, there are cyber criminals who specialize in turning employees into bad actors. So, make sure your patches are always up to date and that you have inventoried every device and/or application on the network.
-
Ensure you are using a good MFA solution. Our partners have created special bundles for various cybersecurity products. There are packages for large enterprises as well as SMBs. Please call us to learn if there is a bundle that’s right for your needs.
And now the Black Cats
Unfortunately, some black cats are not the sweet furry ones, but are the kind packing pernicious payloads.
The BlackCat ransomware, also known as ALPHV, is virulent and, unfortunately, an excellent example of the type of trouble being unleashed by criminals profiting from the growing Ransomware as a Service (RaaS) industry.
We’ve been talking about this relatively new entrant to the gig economy for some time – and the access brokers spearheading RaaS operations have been talking about BlackCat since it arrived on the scene in November 2021.
BlackCat, which is the first sophisticated malware written in RUST, rapidly became the darling of the dark web delinquents because of its high performance and memory safety. The other problem is that it can also compromise Windows- and Linux-based operating systems.
As a result, it was the vehicle used for many of the headline-grabbing breaches for about a year after it was released. Then, towards the end of 2022, it seemed to be slinking away, as BlackCat attacks drop by approximately 20% from November 2022 to the end of Augus.
Unfortunately, as was so often heard in the movie Dinosaur Story, “They’re Baaack!”
So, please remind your teams about double-checking the provenance of emails – and warn them not to click on any cool Halloween photos today, because experts expect there to be a five-fold increase in socially-engineered attacks. You don’t want the headache, and we certainly don’t want you crying “Boo Hoo”.
So, here’s to furry black cats, decorative spiders only, and a very Happy and treat-filled Halloween for us all!