world of internet security, latest cyber security news,information,updates on technology,it job vacancies,internet security,breaches,and safeguards

Showing posts with label THREATS-WINDOWS. Show all posts
Showing posts with label THREATS-WINDOWS. Show all posts

Monday, 7 January 2019

How to protect your Facebook account

with 0 Comment

Here we walk you through the important settings you can change and behaviors you can implement to lock down your privacy on the social network.

Note: To change many of the settings below, Facebook will ask you to input your password. It’s a good reminder that if your password isn’t strong or unique to the site, now is the perfect time to change it!

Enable 2FA

If you only do one thing on the list in this article, do this: enable two-factor authentication (2FA). This means someone trying to break into your Facebook account needs more than just your password, they also need a second token that you own, be it a code or a physical key. The chances of someone having this in their possession are pretty small, so this step will stop most intruders in their tracks.

Facebook will walk you through the steps to enable 2FA on your account to help you get set up. You have a few options available to you for how you want to authenticate: you can choose to use a code sent to you by text message, which is easiest but not completely secure, or to use a code generated by an authenticator app on your phone, which takes a little more setup work.

If you’re really savvy and browsing using the website on a computer, Facebook also supports U2F keys like YubiKey, which is a physical key you plug into your computer’s USB port as your authentication token.

How to do it on your desktop: Go to your Facebook Settings and select Security and Login from the menu on the left. Next to Two-Factor Authentication click Edit and then Get Started.

How to do it in the app: Open Privacy shortcuts from the hamburger menu in the bottom left. Scroll down to the Account Security section and tap Use two-factor authentication. Choose whether you want to set up SMS 2FA or use an authenticator app.

You can turn on 2FA for your account from either the website or the app, you don’t have to do it in both places.

Get login alerts

If someone does manage to get into your Facebook account, you’ll want to know about it as soon as possible. If requested, Facebook can alert you to any strange-seeming logins to your account. You can be alerted via email, text message, Facebook message or even a Facebook in-app notification. It’s a little peace of mind and a very simple measure to set up.

How to do it on your desktop: In your Facebook settings, select Security and Login and scroll down to Setting up Extra Security. Hit the Edit button on Get alerts about unrecognized logins and customize how you’d like to be notified.

How to do it in the app: Open Privacy Shortcuts from the hamburger menu in the bottom left. Scroll down to the Account Security section and tap Receive alerts about unrecognised logins.

Check your connected apps

That quiz you took years ago about your star sign that you promptly posted and forgot about? All these years it’s had permission to see your profile, posts, and friends’ posts into perpetuity, so why does it still have this access?

You could have any number of apps like this quietly sniffing your information in the background. There’s an easy way to check what apps you might still have enabled, and disable them if you like. It’s best to have as few apps enabled as possible – and definitely remove permissions for any apps that you don’t recognize or remember using.

How to do it on your desktop: In your settings, go to Apps and Websites. Check the apps in your Active and Expired categories and remove any or all of them.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to the Security section and tap Apps and Websites. Open Logged in using Facebook and check the apps in your “Active” and “Expired” categories and remove any or all of them.

Note, there is also a Business Integrations section, separate to Apps and Websites, that you might want to check for connected services too.

Be discriminating in how people find and contact you

The whole idea of Facebook is to reach out to friends and family and grow your network, but spammers and fake profiles seem to be some of the most enthusiastic users of the platform lately.

If you’re tired of getting suspicious Facebook friend invitations, or would rather not invite the risk of getting a phishy or malicious link on your Facebook wall, be discriminating in who you befriend. We suggest limiting who can contact and find you on the platform to “Friends of friends,” and to limit email and phone lookups to “Friends of friends” as well.

How to do it on your desktop: In settings, select Privacy. Modify your preferences for how you can be found on Facebook under the How people can find and contact you section.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to the Privacy section and hit Privacy settings. Scroll down to How people can find and contact you. 

Call for backup: Choose friends to help if you’re locked out

If you’ve had issues in the past with your account being compromised – say if you’re a public figure or just very unlucky – Facebook has an option to let you select three to five people in your friends list who you can call on to help you gain control over your account if you’re ever unable to log in (say, because someone else has locked you out.)

This is not a feature that everyone will need, so if you don’t think it’s going to be that big a deal if you’re locked out of your account, feel free to skip this one. But if Facebook is your primary means for earning a living, or communicating with customers or your fanbase, this setting is worth your consideration.


The people you choose to be your backup – which Facebook calls your “trusted contacts” – should be people you know will be tech-savvy enough to know how to help you quickly (so, ideally someone who knows how to use a smartphone), and they should also know ahead of time that you’re choosing them to be a trusted contact, as Facebook will notify them that you’ve tapped them for this ‘honor’.

At no point will any of your trusted contacts have access to your Facebook account personally, nor will they be able to commandeer it at any time – they will be able to send you a code and a URL to help you log back into your account in case of an emergency.

How to do it: In Settings, go to Security and Login and scroll down to Setting up extra security. Hit edit on Choose 3 to 5 friends to contact if you get locked out and follow the instructions.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Under Security, tap Security and login and scroll down to Setting up Extra Security. Hit Choose 3 to 5 friends to contact if you are locked out.

Face recognition and tag privacy

Facebook maintains that it has face recognition capabilities for our own benefit – so we can know if we’re in a photo but haven’t been tagged, and someone can’t impersonate us by using our profile photo (we’re wise to your tricks, spambots!). But many of us also find this kind of tech creepy and intrusive. If you don’t want Facebook to proactively find you and identify you in photos, you can disable face recognition.

How to do it on your desktop: In Settings, select Face Recognition and then choose No.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Face recognition. Select No.

Note that face recognition isn’t the same as when people you know tag you in photos. If you don’t want people to tag you in photos or posts without your approval first, there’s another setting you’ll want to enable.

How to do it on your desktop: In Settings, go to Timeline and tagging and then choose On for both options in the Review section.


How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Timeline and tagging. Scroll down to Review and ensure both are set to On.

Keep your posts friends-only

You wouldn’t leave your front door open all the time. Why make the details of your personal life open and public for all the cybercriminals in the world to mine? Leaving your posts all public-facing is a gold-mine for criminals looking for details to try and guess security questions, or impersonate you to scam friends or family.

There’s a really easy solution here: Keep your Facebook posts out of the public eye and make the default privacy level friends-only. That way only the people you have approved and friended can see what you’re up to.

How to do it on your desktop: In settings, select Privacy. Under Your Activity set Who can see your future activity? to Friends, and click Limit past posts to retroactively make all your previous posts Friends-only as well.

How to do it in the app: Open Settings from the hamburger menu in the bottom left. Scroll down to Privacy and open Privacy settings. Under Your Activity set Who can see your future activity? to Friends, and also go back a step and turn on Limit who can see past posts too.

Be discriminating in what you do

Unfortunately, the risks to Facebook users are no longer just from external forces trying to break their way into your account. Unfortunately, we’ve learned in the last year or so that there have been a few Facebook-approved data miners, like Cambridge Analytica, that were given unfettered access to what Facebook users were up to behind the garden walls.

So the steadfast internet advice applies here as anywhere: Mind what you post, and remember that the internet is forever. Even content you post behind the friends-only filter on Facebook is not an ironclad guarantee of privacy, so use discretion and if your gut is telling you to not hit that “post” button, it’s best to listen.

Thursday, 12 October 2017

CYBER SECURITY AWARENESS MONTH: 5 security mistakes your IT team wish you wouldn’t make

with 0 Comment
https://www.goldenfrog.com/blog/wp-content/uploads/2016/10/ncsam_2016_blog.png
 
It’s National Cybersecurity Awareness Month (NCSAM) and this week’s theme is Cybersecurity in the workplace is everyone’s business. Here we will be sending you some tips on how to make your computer save.

1. Lock your computer 

Your screen isn’t meant for anyone's  eyes so if you’re not looking at it, nobody else should be looking at it either. Nobody else should be using your login either, no matter if it’s a colleague sending an email in your name when you go for a coffee or a rogue employee searching through your stuff for confidential information.

To lock your Windows computer use CTRL+ALT+DEL and select Lock, or press ⊞+L. (That square character is the key with the Windows logo on it.)

On a Mac press CTRL+⌘+Q (the four-leafed clover key is also labelled “command” ), or press the power button briefly.

2. Loose lips sink ships

The expression “loose lips sink ships” is a phrase used in World War 2 to warn of the dangers of unguarded talk. It works in cyber security too.

It’s easy to leak information by accidentally sending things to the wrong people, saying the wrong thing in the wrong place, mislaying printed documents or leaving meeting rooms without erasing whiteboards. So, re-read what you’re about to sending in emails, instant messages or texts, and make sure that what you’re about to send will go to your intended recipients.

Review files before attaching them – it’s easy to leak sensitive information if it’s in a small section of a much bigger spreadsheet or document. When you’re talking, be aware of where you’re standing and who is around you. Ask yourself if it’s appropriate to share what you’re saying about sales figures, targets, staffing or whatever else you’re talking about with the people in earshot.

And erase the whiteboard before you leave a meeting room. It’s not just a courtesy for the next users of the room, but a routine precaution that ensures nothing confidential will find its way onto the mobile phone of a camera-happy passer-by.

3. Save regularly

I’m aware of how easy it is to get sucked into whatever it is you’re doing but we can’t protect things that you haven’t saved. Saving things regularly, to the appropriate place – such as network drives – ensures that the data you have is secure in the event that your laptop is stolen.

We’ll make sure your work laptop is encrypted so that your data won’t end up in the wrong hands if your laptop is lost or stolen, but we can’t recover your data if you haven’t saved it somewhere safe and secure where we can keep an eye on it for you.

4. Separate personal and professional

If you use your home email, personal Whats App account – or anything else outside the reach of your Its policies. for work then we can’t protect you and you’ll be answerable for the consequences. If you use your work computer, email or phone for personal stuff, for eBay, PayPal, adult websites (it happens), pictures of your kids and pets, or anything else, it won’t be there if you leave the company. As an IT professional the first thing I’ll do after revoking your access is to wipe your stuff, poof, gone!

And, whilst I can assure you that almost all of us in IT are lovely and would never take advantage of the information you’ve left behind there will always be some bad apples. The principle of least privilege applies – we don’t need access to your personal stuff so we shouldn’t have it.

5. Tell us what happened (seriously, tell us everything)

Finally, if you have to report something to your IT department please, please don’t cut down or amend your story. We want to know everything. Something small and insignificant can drastically change the troubleshooting steps we need to go through and even a small detail missed can reduce our efficiency and effectiveness.

We want to know literally everything you can remember before and after an event to build a better picture of what happened. (We will find it eventually and be annoyed you didn’t share!). We’re on your side, and we’d love to have you on ours – we’re all in this together.

Friday, 4 August 2017

Security Awareness for IT Employees

with 0 Comment
Image result for hd picture security awareness for it employees

It is very important for IT team members to participate in security awareness and education and most of all comply with the corporate guidelines for IT security. It may be mandatory in some organization but even if it’s not so, it is paramount to understand that security requirement, guidelines, policies, and procedure will vary between organizations and it is important for the management to ensure that any employee will understand, accept and follow the corporate security rules and be updated with prevailing threats in the course of a periodic training.

Studies have showed that IT employees who are supposed to enforce security are fond of breaking the rules, and most of the time circumvent the rules, for instance, if the USB devices are blocked, a website is forbidden, or rather a specific application is not installed. For a typical user, that would be it, but an IT user may decide to mess around with the system settings, changing a registry entry, or using a portable proxy avoidance tool.
Since standard security controls may not be that effective with IT employees, the only option is make sure they are aware of the risks of not following rules; this should include both the threats to the company and the consequences violators will face.

Most security related incidents related to IT employees are caused by simple mistakes like using a very simple password against company policy of enforcing complex passwords, or even writing them down in easily found places.
Software developers are another group that can create security flaws. It is common for someone having trouble with a syntax error to download sample source code and use it without considering the security implications.  Some may even share a piece of sensitive code on a public online forum in search for help.

 The fact is, while IT employees may be more comfortable with technology, they are not invulnerable to simple mistakes, and that includes falling victim to social engineering, opening attachments from unknown sources, downloading software from outside the official stores, clicking on links in social media sites, etc. Again, even though IT employees are expected to know that this is a risky behavior, incidents are bound to happen without proper security awareness training.
IT personnel are mostly a prime target for cyber criminals because of their access to sensitive information. Some have source code access, administrative rights, physical access to restricted areas, unrestricted network access. If any IT user fall victim to a phishing attack, he automatically compromises the organization’s secrets

Security Awareness: How to Educate IT Employees

The best approach to prevent both unintentional and deliberate security incidents form IT personnel is to create an awareness program that reflects the level of harm an employee may cause to a business.
This will require a proper understanding of the audience and developing awareness pieces accordingly, while a part of the awareness material will be designed for the employees as a whole, some of it must be created specifically for key areas such as IT or even other areas of IT such as coders, database administrators, and network administrators).

Here are some tips that can be quite useful in bringing your awareness program up to speed

Since we are talking about IT employees, it is reasonable to assume that they already have a good understanding of technology, otherwise you would not have hired them. As with any audience, speaking in a language they fell comfortable is of key importance if you wish to get your message through. With a general employee group, using technobabble may not be the best idea, but since we are talking about IT geeks, this approach can be of great value to get their attention going.

The basics of information security: Now, understanding technology and even being an expert in some related areas may not require a profound knowledge of information security, so it is always best to not assume IT employees are already proficient with information security. There is no harm in starting from the basis, so some effort should be made to ensure that things like basic concepts, terminology, procedures, guidelines, and policies are well understood. This can be accomplished real easily by creating a security handbook (that can also be used with non-IT employees) and having quick presentation sessions.

Be specific: IT employees can work in several different areas that are subject to specific risks. While it is important to have your entire team aligned on the general terms, there is little to be gained from spending resources and time educating an employee about a subject that does not involve his line of work. For instance, server admins may not be required to know more than the basic concerns of coding vulnerabilities and your development team does not need to be concerned with the operational system’s security settings. Again, it is all dependent on knowing and understanding your audience.

Whenever possible, use real examples: More often than not, IT personnel will be directly involved in dealing with security incidents. While it is important to avoid over-exposition of past issues, having practical examples pertinent to the company’s risk scenario is one of the best approaches to accomplish awareness. For example, if a company has a history of malware infection or, even worse, suffered a ransomware attack, it is always good to discuss it with the tech team and point out whatever security controls were missing and, if there was malicious intent, what the consequences were and what has improved to help avoid further occurrences.

Concluding Thoughts

The human factor has been and will remain a major part of most data breaches or any other type of security incident. IT employees can either be a source of vulnerability or one of the most resilient combatants in a company’s information security efforts; it is all a matter of being aware and adequately trained.


While IT people in general have more experience and are even easier to educate on security matters, it is important not to underestimate the level of exposition that may arise if IT employees are not part of security aware efforts. Simple unintentional mistakes can become major incidents that may impact operations, financial results, and even the image/reputation of any business.

Wednesday, 28 June 2017

How To Protect Yourself Against Petya Ransomware

with 0 Comment

The latest attack the world has seen recently is a variant of the Petya ransomware virus. As of this writing, it appears a new variant of Petya has been released with EternalBlue exploit code built in, which WannaCry utilised to propagate around organisations.

Unlike WannaCry, Petya is a different kind of ransomware. Common delivery methods are via phishing emails, or scams. The payload requires local administrator access.

Prevention Tip #1: The malware requires administrator rights to the local computer. Standard users should not have this in permission. Consider restricting who has local admin rights to prevent execution of exploit code within organisations. Home users should also consider using a Standard User Account for day-to-day operations.

Once executed, the system’s master boot record (MBR) is overwritten by the custom boot loader, which loads a malicious kernel containing code that starts the encryption process.

Once the MBR has been altered, the malware will cause the system to crash. When the computer reboots, the malicious kernel is loaded, and a screen will appear showing a fake Check disk process.

This is where the malware is encrypting the Master File Table (MFT) that is found on NTFS disk partitions, commonly found in most Windows operating systems.

It is when the machine is rebooted to encrypt the MFT that the real damage is done.

Prevention Tip #2: Some Windows systems are configured to automatically reboot if it crashes. You can disable this feature in Windows. If you can prevent the MFT from being encrypted, you can still recover your data from your local disk. Click here to learn how to do this.


Once the fake Check Disk is complete, the end user is presented with a ransomware page to find out how to go about recovering their data by paying an amount of money.

In addition to the prevention tips listed above, below are some recommendations that will help protect you from such an attack, and how to minimise the impact:

RECOMMENDATIONS FOR COMPANIES

  1. Deploy the latest Microsoft patches, including MS17-010 which patches the SMB vulnerability
  2. Consider disabling SMBv1 to prevent spreading of malware
  3. Educate end-users to remain vigilant when opening attachments or clicking on links from senders they do not know
  4. Ensure you have the latest updates installed for your anti-virus software, vendors are releasing updates to cover this exploit as samples are being analysed
  5. Ensure you have backup copies of your files stored on local disks. Generally, user files on local drives are replicated from a network share
  6. Prevent users from writing data outside of designated areas on the local hard disk to prevent data loss if attack occurs
  7. Operate a least privileged access model with employees. Restrict who has local administration access

RECOMMENDATIONS FOR END-USERS OR HOME USERS

  1. Ensure automatic updates are turned on and the latest security patches are applied
  2. Update your Antivirus software to the latest version and the signatures are up-to-date
  3. Ensure you have enabled User Access Control on the endpoint and consider operating as a standard user and not a user with administrative privileges
  4. As a home user, consider using a cloud backup or online storage provider, such as DropBox, Google Drive and Microsoft OneDrive. As files are changed, they are updated in the cloud
Petya does not encrypt the files themselves, it encrypts the Master File Table, which is an index of where all the files are stored on a hard disk drive. Without the index, it makes it incredibly difficult to identify where the files are on the disk.




Tuesday, 27 June 2017

WARNING!! Global ransomware outbreak hits organisations

with 0 Comment

There are multiple reports from countries around the world that their computers have been hit by ransomware. Part of the ransom reads as shown in the image above.

Security experts have confirmed that the ransomware, believed to be a variant of Petya or Petrwap, is spreading by exploiting an NSA-built Windows exploit known as "Eternal Blue".

Eternal Blue was developed by the United States' National Security Agency for the purpose of infecting the computers of those it wished to spy upon. As a consequence, the NSA didn't tell Microsoft about the vulnerability it had discovered in Windows *until* details were stolen from the agency by a mysterious group of hackers known as the Shadow Brokers.

The fact that the NSA initially hoarded details of the security holes in Microsoft's code has put organisations around the world at risk.

Eternal Blue was a key part of how the WannaCry ransomware spread so quickly earlier this year, and *has* now been patched by Microsoft for some months. Clearly, however, many organisations have still failed to put those security patches in place.

Some of the earliest reports of affected computers came from government offices and energy companies in Ukraine, as well as the airport of the country's capital Kiev where BBC News reports that flights may be delayed as a consequence.

Rozenko Pavlo, deputy prime minister of Ukraine, tweeted a photograph of his computer - seemingly mid-way through being encrypted by the ransomware.



However, the attack does not appear to have limited itself to Ukraine.

For instance, there have been additional reports that the Spanish offices of multinational companies such as law firm DLA Piper have been hit by a malware attack that is encrypting files on their computers and demanding a ransom of US $300 in Bitcoin be paid to the extortionists.

Meanwhile marketing giant WPP says that several of its companies have suffered as a result of a "suspected cyber attack".

Other victims include Maersk, the international shipping logistics company, which confirmed via Twitter that it had fallen victim to a cyber attack.


There have also been reports of infections in Russia, India and the UK, and it seems unlikely that that will be the end of it.

I really hope you learnt a lesson from the WannaCry ransomware outbreak and put some secure backup systems in place...

Subscribe to our newsletter for updates on how to secure your systems



Wednesday, 7 June 2017

JUDY MALWARE affects millions of andriod device

with 0 Comment


It has happened again; security experts have discovered a malicious application inside the official Google Play store. The new malware, dubbed “Judy,” is designed to infect Android devices and generate false clicks on advertisements. According to malware researchers at Checkpoint Software, Judy malware was used by crooks to generate revenue on the false advertising clicks.

The new malicious app bypassed Google checks, and according to the experts, it may be present in 41 popular games deployed on the Play store for years if confirmed more than 36 million users may have been infected with Judy adware.

“Check Point researchers discovered another widespread malware campaign on Google Play, Google’s official app store. The malware, dubbed “Judy,” is an auto-clicking adware which was found on 41 apps developed by a Korean company. ” states the analysis published by CheckPoint. “The malicious apps reached an astonishing spread between 4.5 million and 18.5 million downloads. We also found several apps containing the malware, which were developed by other developers on Google Play. These apps also had a large amount of downloads between 4 and 18 million, meaning the total spread of the malware may have reached between 8.5 and 36.5 million users.”

The affected apps containing the malicious code were developed by a Korean company and had all been pulled from the Google Play Store. The experts also found other applications developed by other vendors into the Play Store that contained the same malware. It is not clear if these infected apps were intentionally designed with the Judy adware or simply were compromised because of sharing of portions of code.

“We also found several apps containing the malware, which were developed by other developers on Google Play. The connection between the two campaigns remains unclear, and it is possible that one borrowed code from the other, knowingly or unknowingly.” reads the report published by CheckPoint security.

Figure 1 – Mobile app in the Google Play Store infected with Judy Adware

The researchers noticed similarities with other two malware apps, “Falseguide” and “Skinner,” which bypassed Google’s safety and check system. All the malicious apps designs appear to be similar in that they used communications links with a Command and Control server for operation. Once the link was established, the Command Server would then download the malicious software on the unsuspecting user.

How does the malicious app by pass Google checks?

The malware developers first would design and upload a baiting program to the Google Play Store; it appears to be games or simulated doll dress designs aimed at children. The bait applications can bypass the Google checking system since they contained no malicious code. The apps apparently look valid because they are designed to communicate with a specific URL for additional user game data such as updated dress designs for children’s dolls. The URL is the address of the Command server from which the applications download the malicious payloads.

“To bypass Bouncer, Google Play’s protection, the hackers create a seemingly benign bridgehead app, meant to establish a connection to the victim’s device, and insert it into the app store. Once a user downloads a malicious app, it silently registers receivers which establish a connection with the C&C server. The server replies with the actual malicious payload, which includes JavaScript code, a user-agent string, and URLs controlled by the malware author.” reads the experts.

One a user will start a malicious app; the command server would provide the malicious payload that infects the unknowing user with a silent and invisible web browser using JavaScript. The adware leverages the JavaScript code to locate and click on banners from Google ads once the user visits one of the websites for which it was designed. The silent browser would then simulate a user clicking on the paying ads and banners. Each infected user would then unknowingly be clicking thousands of times a day against advertisements generating revenue for the malware developer cheating the paying advertisers.

In addition to the clicking activity, Judy also displays a large amount of advertisements. In many cases the advertisements displayed by Judy oblige users to click on the ad to close it. This behavior was noticed by users that reported it in the feedback session of the app in the official store.

According to Checkpoint, the malware apps were all developed by a single Korean company named Kiniwini, registered on Google Play as ENISTUDIO corp.

“The company develops mobile apps for both Android and iOS platform,” states the Checkpoint bulletin.

“It is quite unusual to find an actual organization behind mobile malware, as most of them are developed by purely malicious actors. It is important to note that the activity conducted by the malware is not borderline advertising, but definitely an illegitimate use of the users’ mobile devices for generating fraudulent clicks, benefiting the attackers.”

Google is aware of the techniques adopted by crooks to bypass its; it is releasing new privacy and security guidelines to developers and increasing checks against fraudulent activities. The use of a secondary communications system is still able to bypass security checks implemented by Google; the IT giant is not able to analyze malware stored on a separate Command server during the upload and activation process for developers.

It is not unusual for app developers to utilize a communications link to specific URLs. Many games and user applications require a link to update common data, generate game revenue and add additional features. The design of using a malicious Command server to install functioning malware is something that previously had been reserved for intelligence agencies and criminal hacker organizations.

The efficiency of threats like the Judy malware is pushing IT giants to adopt new solutions to prevent their spreading.

Google has recently announced the deployment of another security defense system, called Google Play Protect, that was designed to protect the devices running Android mobile OS.

Google already uses several security measures to protect the mobile devices, Verify Apps and the Bouncer service are the most important defense measured implemented by the company. Unfortunately, once the apps are uploaded to the Play Store and installed on the user device, Google is not able to monitor the behavior of the apps and detect the malicious ones.

Figure 2 – Google Play Protect


Google Play Protect implements a machine learning and app usage analysis to identify any malicious activity on the mobile device.

The new system is integrated into the Google Play Store app; this means that its usage is transparent to the end user that doesn’t need to install or enable it on his device.

“Google Play Protect continuously works to keep your device, data, and apps safe. It actively scans your device and is constantly improving to make sure you have the latest in mobile security. Your device is automatically scanned around the clock, so you can rest easy.” reads the description published by Google.

Google Play Protect for implements the following features:

  1. App scanning
  2. Anti-Theft Measures
  3. Browser Protection

The new protection service will be rolling out to all the Android mobile devices over the coming weeks.

The performance announced by Google are impressive, the app scanning is an always-on service on devices, it can scan 50 billion apps each day across a billion Android mobile devices to detect malicious applications.

The Google Play Protect also monitors mobile apps that have been installed by users from third-party stores, a circumstance that is very frequent. In many cases, Android users download mobile applications from unofficial stores, recently I bought a drone that allows the user to access the built-in camera through a mobile app that is available for download from a server located in China, and many other IoT devices are controlled by similar apps hosted in third-party stores.

The key components of the new service implemented by Google are the machine learning algorithms that compare app behavior and can identify any behavior that matches malicious patterns.

The machine learning system regularly updates to identify and mitigate new cyber threats, every time a malicious app is detected, the Google Play Protect service warns the user or even disables the app.

“With more than 50 billion apps scanned every day, our machine learning systems are always on the lookout for new risks, identifying potentially harmful apps and keeping them off your device or removing them. All Google Play apps go through a rigorous security analysis even before they’re published on the Play Store—and Play Protect warns you about bad apps that are downloaded from other sources too.” states a blog post published by Google. “Play Protect watches out for any app that might step out of line on your device, keeping you and every other Android user safe.”

The news system implemented by Google also offers Anti-Theft Measures, the Android Device Manager has been replaced with Find My Device, that allows users to locate lost and misplaced devices. The new feature is available through user’s browser or any other mobile device. The service also allows to wipe data on the lost device remotely.

Another interesting feature implemented by Google is the Safe Browsing feature in Chrome, the Google Play Protect protects users while browsing.

The feature will block malicious websites that were designed to deliver malicious code on the mobile devices.

Let me close with consideration, despite the effort of security firms and IT giants, it is important users will adopt best practices to protect their mobile devices, such as installing protection solutions and installing only the necessary applications.




Monday, 29 February 2016

The “HawkEye” attack by cyber criminals

with 0 Comment

Even if you’ve heard of it before, it’s still worth reminding yourself how the scam works, which is something like this:

1. Buy booby-trapped documents that use the Microsoft Word Intruder (MWI) exploit tool. If opened on an unpatched version of Windows, these documents automatically install chosen malware on the victim’s computer, with no user clicks required.

2. Buy a commercially-available keylogger and configure the booby-trapped files to download and install it. (This case used the now-defunct Hawkeye keylogger.)


3. Pick a broad industry sector, e.g. leather and leather products.

4. Send a small number of scam emails (typically a few thousand in total) pretending to be quotation requests or payment information, each containing a booby-trapped MWI document.


5. Infect victims with the keylogger and wait until they type in their email passwords.

6. Use the stolen email passwords to watch their inboxes, until you see that a customer has been invoiced and is about to pay.


7. Email the customer from the hijacked account, instructing the customer to use a new account number for future payments.

8. Take the money yourself and quickly move it where it can’t easily be found or recovered.

Just one or two criminals, working unaided, and with enough patience to go after a small number of high-value victims, could easily operate a scam of this sort.

What to do?

1. Patch promptly. The booby-trapped documents in this attack relied on a security hole that had been patched years before.

2. Keep your security software up-to-date. A good anti-virus can block attacks like this at several points, and you win if you can stop any one of them, starting with the original inbound email.

3. Beware of unsolicited attachments. This can be hard if your job is business development and the email is a Request For Quotation, but avoid opening just any old document.

4. Consider using a stripped-down document viewer. Microsoft’s own Word Viewer, for example, is usually much less vulnerable than Word itelf because it’s much simpler. (It doesn’t support macros, either, which protects against Locky-type attacks, too.)

5. If your email software supports it, use 2FA. That’s short for two-factor authentication, those one-time codes that come up on your phone on a special security token. With 2FA, just stealing your email password isn’t enough on its own.

6. Have a two-person process for important transactions. Paying large invoices and changing remittance advice shouldn’t be too easy. Require separate approval from a supervisor, so you always get a second opinion when large sums are at stake.

Friday, 8 January 2016

Internet Explorer 8, 9 and 10 to reach 'end of life' next Tuesday

with 0 Comment
Image result for windows logo
If you intend to keep using internet explorer for ever, you need to stop using the version you now have and upgrade to the latest internet explorer 11.
the specification for desktop version include the following:

Version of windows: Official internet version are:

windows 7 internet explorer 8,9,10,11

windows 8.1 internet explorer 11

windows 10 internet explorer 11

Therefore, make sure you determine exactly which version of internet explorer you've got and we also suggest that you verify to make sure rather than choosing what you you consider might be the better choice. And you need to ask yourself a question.

Are you aware of when you version of IE will receive it's security update?

if you are already on using the IE version 11, i must say you are already on a safe side.

However if you are already on windows 7 and haven't updated to the latest internet explorer 11, then by Tuesday 12 January 2016, you will stop receiving  security updates and fixes from Microsoft.

if you consider doing absolutely nothing, then any security vulnerability that arise on the your existing internet explorer version will not be patched and will never be patched. 

Therefore, after January 12 2016, if you haven't updated to the IE version 11, your windows 7 computer will start issuing “End of Life notifications“