|
Cyber Security Must-Haves
Happy October! This month we welcome the beauty of fall as we embrace cooler weather, warmer attire, and urgent patches to zero-day vulnerabilities that are being exploited in the wild. Not sure what that is? Keep reading to find out.
For this month’s newsletter, I want to share a few key cyber security “must-haves,” if you will. These tips are shared in light of breaches that TCE Strategy is currently helping to mitigate in the hope that you learn from and potentially prevent them for yourself and your business:
- Patching. Patch your firewalls. Check every month for new firewall patches. Don’t allow administrator accounts to VPN (Virtual Private Network) directly into your environment. Only everyday (non-administrator) accounts should be able to do that. Change your passwords occasionally, even if it’s only once a year.
- Employ Microsoft’s Local Administrator Password Solution (LAPS) to randomize the local admin accounts on your company’s PCs.
- Avoid logging in to computers with Domain Administrator Credentials. If you have to promote or demote domain controllers and do certain other things that require a login as a domain admin, change your passwords after every time you do so. For all other admin functions, log in as a normal user and perform a “run as” command to use admin privileges on the applications that you need them for.
- Check your websites for SQL injection issues and other serious vulnerabilities. Run external vulnerability scans on your websites. Have a full penetration test done on your websites if you really care about them (this is a service that TCE Strategy provides).
As always, my goal is to simply be a conduit of valuable information that will help you stay secure and avoid cyber criminals at all cost.
Cyber News In Review
On the cyber news front, hardly anyone escaped the virtual craze that was the widespread, six hour outages of Facebook, Instagram and WhatsApp on Monday, October 4th. While many speculated that cybercriminals were involved, it turned out that cybersecurity wasn’t a factor. The reason Facebook and its entities crashed essentially had everything to do with a service on the internet called DNS and just how easy it is to accidentally remove DNS entries for a company. Oops… Who knew you didn’t even need Facebook to spread rumors and misinformation?
Microsoft’s Patch Tuesday for the month happened this past Tuesday, October 12 with a shocking number of zero-day vulnerabilities: four. Three of these are being actively exploited in the wild. This is an urgent call to why patching matters, and how the frequency at which it is done is essential. All patching is necessary and encouraged, if not highly persuaded. Patching this month, however, is one that Windows users cannot afford to delay. Patch early, patch often.
Regarding “zero-day” vulnerabilities, here is a layperson’s definition: I found a way to take over your computer using a flaw in some software you have installed. No one else knows about it. I start using it until someone catches me doing something bad on your computer. Up until the point that I’m caught, my way of taking over your computer is a “zero-day” vulnerability. Soon after I’m caught, the software vendor normally develops and releases a patch. The day the patch comes out is “day one,” as it’s easy to reverse engineer a patch and see what it fixed. Now the race begins: people using the software need to patch it, and cybercriminals want to weaponize the vulnerability so that they can start using my “zero-day” vulnerability on computers that haven’t been patched. You want to be in the camp that patches their computers. The cybercriminals want you to be in the camp that doesn’t.
October is Cybersecurity Awareness Month. The Cybersecurity & Infrastructure Security Agency is releasing weekly reminders throughout the month with various ways we can stay on top of protecting ourselves from cyber crime with their #beCyberSmart campaign. Click here to learn more!
Until next month, stay safe!
|