<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Security Breach Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/cyber-security-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/cyber-security-breach/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Sat, 01 Jun 2024 00:02:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Cyber Security Breach Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/cyber-security-breach/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</title>
		<link>https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sat, 25 May 2024 21:38:42 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[BEC]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Fraud]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5809</guid>

					<description><![CDATA[<p>Have you ever wondered if someone is eavesdropping on you through your phone? While it might sound like a scene from a spy movie, there are real concerns about privacy and security related to microphone access on your devices. A Real-World Example from the Workplace: Recently, a new employee at a company received a fraudulent [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/">Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Have you ever wondered if someone is eavesdropping on you through your phone? While it might sound like a scene from a spy movie, there are real concerns about privacy and security related to microphone access on your devices.</p>
<p><strong>A Real-World Example from the Workplace</strong>: Recently, a new employee at a company received a fraudulent text message on her personal phone, supposedly from the company&#8217;s president. The president had not sent any text, and the company had not stored her personal phone number. How did the threat actor know? It’s possible that a data broker linked the new employee’s private phone number with the president’s name at the new company by eavesdropping on a conversation, such as her telling a friend about her new job. Upon investigation, the employee found that some unexpected apps had access to her microphone.</p>
<p><strong>A Real-Word Family Example</strong>: Last week, a husband and wife discussed dental options for their child at the breakfast table with their phones nearby. They hadn&#8217;t typed anything into a computer or searched online, yet less than an hour later, one received a text message from a company offering dental aligners. How could this happen? An app on their phone might have accessed the microphone, listened to the conversation, and shared the information with a data broker. The data broker then provided this information to a company selling dental aligners, prompting them to send a targeted text message. Have you or someone you know had similar experiences?</p>
<p><strong>How It Happens</strong>: Some apps collect data, including audio data from a microphone, and sell it to data brokers, also known as Marketing Data Aggregation Warehouses. These brokers aggregate and sell data to various businesses, including marketing and advertising firms. These businesses then use the information to send targeted advertisements or, in the case of threat actors, perform sophisticated phishing attacks designed to extract sensitive information or commit fraud.</p>
<p><strong>Apps are supposed to request your permission</strong> to access your microphone. However, this &#8220;user&#8217;s consent&#8221; often comes from clicking &#8220;Do you agree to the privacy policy&#8221; during installation. Most users do not read these policies and agree just to use the app. Privacy policies can be vague, stating that the user allows the app to collect information and share data with third parties.</p>
<p>Several types of apps can gather information for sale to data brokers and request microphone access in their privacy policies. These include:</p>
<ul>
<li><strong>Social Media and Communication Apps:</strong> Use microphone access for features like voice messaging and video recording, sharing collected data for advertising.</li>
<li><strong>Virtual Assistants:</strong> Require microphone access for functionality, collecting voice queries and background noise for service improvement and advertising.</li>
<li><strong>Gaming Apps:</strong> Mobile games with voice chat request microphone access for communication, sharing user data for advertising.</li>
<li><strong>Productivity Apps:</strong> Note-taking and voice recorder apps request access for audio notes and transcriptions, collecting valuable user data.</li>
<li><strong>Health and Fitness Apps:</strong> Fitness trackers and health apps request microphone access for voice input, collecting sensitive health data.</li>
<li><strong>Utility Apps:</strong> Simple apps like flashlights and calculators sometimes request unnecessary permissions, including microphone access, to gather user data covertly.</li>
<li><strong>Marketing and Rewards Apps:</strong> Request location and microphone access to collect user data, which is then sold to data brokers.</li>
</ul>
<p>These apps often include clauses in their privacy policies that allow microphone data collection, which users might unknowingly grant, leading to targeted advertising and other uses by data brokers.</p>
<p>For further reading, refer to articles like &#8220;FTC Cracks Down on Mass Data Collectors&#8221; by the Federal Trade Commission.</p>
<p><strong>Protecting Your Privacy:</strong> To protect against such risks, Apple, Google, and Microsoft have all implemented ways to help ensure your microphone&#8217;s privacy even if users agree to the privacy policy. Instructions for disabling access to your mic are listed below. It’s crucial to regularly review and update app permissions on your devices, ensuring that only essential apps have access to sensitive data like the microphone.</p>
<p><strong>Beyond Annoying Ads</strong>: Threat actors can use similar tactics to perform targeted attacks and commit fraud against individuals and their companies. For instance, the fraudulent text message received by the new employee could lead to more sophisticated phishing attacks intended for extracting sensitive information, transferring money, or other financial fraud.</p>
<p><strong>Follow the instructions in the following draft memo you can send your workers and tell your family</strong>:</p>
<h3><strong>Memo to All Employees: Securing Your Microphone Privacy Settings</strong></h3>
<p>Dear Team,</p>
<p>We are committed to ensuring the privacy and security of our employees&#8217; personal and professional information. Recent reports have highlighted the risks associated with apps accessing device microphones without explicit consent, potentially leading to targeted fraud and privacy breaches.</p>
<p>To protect your privacy and our organization&#8217;s security, we ask all employees to take a few moments to review and update the microphone privacy settings on their devices. Below are step-by-step instructions for various platforms:</p>
<p><strong>For Apple Devices:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Privacy &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all applications that do not need access to your mic.</li>
</ol>
<p><strong>For Android Devices:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Type Microphone, Privacy, or Permission Manager in the search box. </strong>If you do not see the privacy settings, you might need to use a search engine or chatbot to find specific instructions for your device model and version of Android.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>For Windows:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Privacy &amp; Security &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>For Macs:</strong></p>
<ol>
<li>Click on the <strong>Apple symbol &gt; System Settings &gt; Privacy &amp; Security &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>Practical Steps:</strong></p>
<ul>
<li><strong>Revoke Unnecessary Access:</strong> Disable microphone access for all apps that do not need it. Allow exceptions for essential apps such as video conferencing tools and browsers if you use them for meetings. If you are uncertain, restrict access; the app will request permission if it needs access in the future.</li>
<li><strong>Test Essential Apps:</strong> Before your next meeting, verify that the apps you frequently use for video conferencing and other essential functions work correctly with the microphone settings you have configured.</li>
<li><strong>Restrict Other Permissions:</strong> While adjusting your microphone settings, you&#8217;ll see other settings. To further protect your privacy, consider restricting access to your camera, location, contacts, and other sensitive data.</li>
</ul>
<p>We live in a world where protecting our privacy is increasingly our responsibility. Threat actors are becoming more sophisticated, so it&#8217;s crucial to stay vigilant and proactive in securing our devices.</p>
<p>Thank you for your attention to this important matter. If you have any questions or need assistance, please ask.</p>
<p>(In the last sentence, you can give them more specific guidance on what to do if they have a question)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<h6></h6>
<p>The post <a href="https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/">Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Protecting Your Financial Interests in the Wake of a Major Data Breach</title>
		<link>https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sun, 21 Apr 2024 13:33:01 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Anti-virus]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Credit Freeze]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Fraud]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Restoration]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[Malicious Advertising]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Restoring]]></category>
		<category><![CDATA[Security Breach]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5779</guid>

					<description><![CDATA[<p>In today&#8217;s digital age, the security of your personal information is more than a convenience &#8211; it&#8217;s a crucial aspect of your financial strategy. Recently, a significant breach at a major phone provider has put the personal data of 73 million individuals at risk, including high-net-worth individuals like yourself. This exposed data includes not only [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/">Protecting Your Financial Interests in the Wake of a Major Data Breach</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In today&#8217;s digital age, the security of your personal information is more than a convenience &#8211; it&#8217;s a crucial aspect of your financial strategy. Recently, a significant breach at a major phone provider has put the personal data of 73 million individuals at risk, including high-net-worth individuals like yourself. This exposed data includes not only names and contact details but also sensitive information such as social security numbers, dates of birth, and account credentials. The potential financial repercussions are substantial, making it imperative to take action to safeguard your assets. Follow these guidelines to mitigate risks and ensure your financial security remains uncompromised.</p>
<h3>Credit Freeze</h3>
<p>If you haven’t already, consider freezing your credit to prevent new credit accounts from being opened in your name without your permission. Here are in-depth instructions and details: <a href="https://fosterinstitute.com/help-protect-your-financial-future-freeze-your-credit/" target="_blank" rel="noopener">Help Protect Your Financial Future: Freeze Your Credit &#8211; Foster Institute</a></p>
<h3>Monitor Financial Accounts</h3>
<p>Keep a close watch on your financial accounts for any unauthorized activity or transactions. Consider subscribing to an identity theft protection service, which can help monitor your information and alert you to potential misuse of your personal data. If you didn’t place the credit freeze mentioned above, doing so is essential.</p>
<h3>Beware of Fraud and Scams</h3>
<p>Beware of email, text, phone calls, or messages popping up on your computer that claim you are hacked and offer tech support help. Familiarize yourself and your family with the latest fraud techniques. Be skeptical of emails, phone calls, or messages that request personal information or direct you to websites asking for personal or financial data.</p>
<h3>Be Cautious with Search Engine Results that are Ads</h3>
<p>Threat actors can purchase ads so that, if you search for keywords such as &#8216;My phone provider database was hacked,&#8217; the ad, disguised as a helpful search result, will appear at the top. This can lead you to a page designed to defraud you or compromise your computer</p>
<p>To help protect yourself, when you search, scroll down and click on the organic search results rather than the ads. You are more likely to access safer websites.</p>
<p>Malicious advertising is not limited to search engines. Advertisements on websites can be just as dangerous. These attacks are called malvertising and trick millions of users each year.</p>
<h3>Change Passwords Immediately</h3>
<p>If you haven’t recently, change passwords for all your accounts including phone provider, social media, banking, and other sensitive accounts, especially if you’ve used the same password for multiple accounts.</p>
<h3>Use a Password Manager</h3>
<p>Consider using a password manager to manage your unique passwords on every website. Detailed information about using password managers: <a href="https://fosterinstitute.com/password-managers-speed-your-workflow/" target="_blank" rel="noopener">Password Managers Speed Your Workflow &#8211; Foster Institute</a></p>
<h3>Set Up Unique Security Questions</h3>
<p>When setting up security questions, avoid real answers that are easy for a bad actor to research. Instead, use fictional answers like, “The fourth crater on the moon.” Save your secret answers in a randomly named file such as “socks.docx,” and consider encrypting this file for added safety.</p>
<h3>Enable Two-Step Verification</h3>
<p>Enable two-step verification for accounts. Prioritize setting this up on sensitive websites and services where it&#8217;s available.</p>
<h3>Update Operating Systems and Software</h3>
<p>Ensure that all your devices have the latest security software, web browsers, and operating systems updates and patches. This is one of the best defenses against viruses, malware, and other online threats.</p>
<h3>Secure Your Tax Identity with an ID.me Account</h3>
<p>Given that social security numbers were compromised, there&#8217;s an elevated risk of someone attempting to file a fraudulent federal tax return in your name. To combat this, consider registering for an ID.me account which provides access to IRS services. With this account, you can also apply for an IRS Identity Protection PIN (IP PIN) that adds an extra layer of security to your tax filings by requiring this unique six-digit number on your tax return.</p>
<h3>Protect Your Property Records</h3>
<p>With personal details like your SSN in the wrong hands, even your home ownership documents could be targeted. It&#8217;s advisable to monitor and possibly register your property deeds with services that alert you to any unauthorized filings or changes. While a universal solution for this isn&#8217;t available yet, taking initial steps such as contacting your local county clerk&#8217;s office to inquire about protective measures can be beneficial.</p>
<h3>Awareness for Business Impact</h3>
<p>Businesses, particularly those utilizing services from the breached provider, should be acutely aware of the implications this breach can have on their operations. It&#8217;s crucial for business owners to assess their exposure and strengthen their internal security measures, including employee training on data privacy and regular security audits to prevent further damage.</p>
<h3>Register for Online Tax Accounts in All States</h3>
<p>To prevent the misuse of your personal information for fraudulent state tax filings, consider registering for an online tax account in each of the 50 states. This pre-emptive registration can block identity thieves from creating accounts in your name, a tactic increasingly used to commit tax fraud across state lines.</p>
<h3>Digital Footprint and Data Sharing</h3>
<p>Be vigilant about the information you share online and through mobile applications. It&#8217;s crucial to minimize data sharing and scrutinize the permissions you grant to apps, especially those that request access to sensitive personal information. Educate yourself and limit exposures to safeguard against unauthorized data usage. The less information threat actors can gather about you, the more difficult it will be for them to misuse your identity.</p>
<h3>Review and Update Privacy Settings</h3>
<p>Regularly review and update your privacy settings on social media and other online platforms to ensure minimal public exposure of personal information. This proactive measure can significantly deter fraudsters from using accessible data to facilitate identity theft or scams.</p>
<h3>Legal and Financial Consultation</h3>
<p>Consult with legal and financial advisors to explore additional protective measures tailored to your personal or business circumstances. Discuss setting up legal structures such as trusts to shield assets, or other strategies that may offer enhanced security against identity theft and financial fraud.</p>
<h3>Emergency Contacts and Protocols</h3>
<p>Prepare an emergency contact list and establish protocols for immediate action if you suspect identity theft or if a data breach occurs. Include the contact information for essential services such as credit bureaus, your bank, and legal advisers, to ensure a swift and organized response to security threats.</p>
<p>Forward this message to your friends so they can follow these steps can help mitigate the damage from the breach and protect their personal information.</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6>Disclaimer: The information provided in this blog is for general informational purposes only. Technology changes constantly, and some of this information might become obsolete or incorrect. We do not endorse or receive compensation for mentioning products, services, or brand names. Any outbound links provided are for your convenience and to get you started, but we cannot guarantee the security or safety of those external websites. Conducting your research and making an informed decision about any products or services mentioned here is essential. We shall not be held responsible for any actions taken based on the information provided.</h6>
<p>The post <a href="https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/">Protecting Your Financial Interests in the Wake of a Major Data Breach</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>If You Get Hacked, Do Not Email Anyone About It</title>
		<link>https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 15 Oct 2020 21:17:38 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Business Email Compromise]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Executives and IT]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[Keep Your Network Safe]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3329</guid>

					<description><![CDATA[<p>You&#8217;ve trained your users to be vigilant for symptoms of cybersecurity issues. Now teach them to share their concerns confidentially. Alert your users today: Tell them to, if they suspect something, avoid opening a support ticket or emailing your IT professionals about the concern. More often than ever before, bad actors infiltrate organizations in a [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/">If You Get Hacked, Do Not Email Anyone About It</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You&#8217;ve trained your users to be vigilant for symptoms of cybersecurity issues. Now teach them to share their concerns confidentially.<span id="more-3329"></span><br />
Alert your users today: Tell them to, if they suspect something, avoid opening a support ticket or emailing your IT professionals about the concern.</p>
<p>More often than ever before, bad actors infiltrate organizations in a slow, methodical way. They can remain undetected for weeks, months, even years. The FBI uses the term dwell time to designate the period from when attackers infiltrate systems until you discover them. The FBI warns businesses that attackers can cause significant damage during dwell time. Bad actors quickly establish backdoors to ensure access, even if you block their first point of entry. They deploy keyloggers on systems to record keystrokes. If your cyber assets are compromised, the bad actors can potentially monitor your messages to find out when you discover their presence in your network, computers, applications, cloud resources, websites, or anywhere else.</p>
<p>Once attackers know you&#8217;ve discovered their infiltration, that triggers them to move forward with their next phase, often contacting you to demand a ransom. Sometimes they threaten severe consequences if you attempt to recover your system in any other way than paying them. Since they are in your systems, you must take the threats seriously.</p>
<p>Establish a protocol for workers to communicate suspicions in some method other than email.</p>
<p>Even your IT department must avoid emailing each other questions such as, &#8220;I received an alert that someone is resetting an administrator password. That&#8217;s odd. Is that you?&#8221; Instead, they must communicate by mobile phone or radio.</p>
<p>If you suspect a breach and contact us, consider phoning. If you must email, use a personal account outside of your company account, and use a phone or some device other than a company computer&#8217;s keyboard to send the message.</p>
<p>I’m not talking about when users receive a phishing message. I’m talking about if they receive a phishing message that includes customer account information, if an important file is missing or won’t open, or if they receive an unexpected login request on a website or to open a file. IT needs to investigate these early-warning signs.</p>
<p>Please forward this to other executives who you care about to establish a mobile hotline number for users to reach the IT team to report suspicious activity. Help avoid triggering attackers’ responses before your IT team has time to react and, hopefully, mitigate a potential cybersecurity disaster.</p>
<p>The post <a href="https://fosterinstitute.com/if-you-get-hacked-do-not-email-anyone-about-it/">If You Get Hacked, Do Not Email Anyone About It</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your Work From Home Users are Like a Box of Chocolates</title>
		<link>https://fosterinstitute.com/your-work-from-home-users-are-like-a-box-of-chocolates/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 11 Sep 2020 16:37:51 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Coronavirus]]></category>
		<category><![CDATA[covid-19]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[Remote Worker Security]]></category>
		<category><![CDATA[Remote Workers]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[risk management]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=3293</guid>

					<description><![CDATA[<p>Because of so many work from home users, the Internet is like a box of chocolates for attackers. Step 1: Attackers compromise work-from-home users. Step 2: They gain access to their company. Step 3: They bite into the company to discover what&#8217;s inside. There are so many work from home users; this is a target-rich [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/your-work-from-home-users-are-like-a-box-of-chocolates/">Your Work From Home Users are Like a Box of Chocolates</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Because of so many work from home users, the Internet is like a box of chocolates for attackers.<span id="more-3293"></span></p>
<p>Step 1: Attackers compromise work-from-home users.<br />
Step 2: They gain access to their company.<br />
Step 3: They bite into the company to discover what&#8217;s inside.</p>
<p>There are so many work from home users; this is a target-rich environment.</p>
<p>1. You must harden remote users&#8217; systems against attacks. Secure their connections.<br />
2. When possible, issue laptops, so your IT team has more control over your remote users&#8217; security.<br />
3. Implement user training and phish testing. Please say if you&#8217;d like us to provide phish testing and online training for your users. We do all the work so your IT teams can focus on their other tasks.</p>
<p>Please forward this to your friends so they realize their remote users must be more secure than ever, and attackers target them indiscriminately.</p>
<p>The post <a href="https://fosterinstitute.com/your-work-from-home-users-are-like-a-box-of-chocolates/">Your Work From Home Users are Like a Box of Chocolates</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>773 Million Passwords Exposed &#8211; Were You Exposed?</title>
		<link>https://fosterinstitute.com/773-million-passwords-exposed-were-you-exposed/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 17 Jan 2019 23:22:23 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Password Manager]]></category>
		<category><![CDATA[Password Safety]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Cyber Security Awareness]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Cyber Threats]]></category>
		<category><![CDATA[Hardware Key]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Modlishka]]></category>
		<category><![CDATA[password code]]></category>
		<category><![CDATA[password manager]]></category>
		<category><![CDATA[two step verification]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2699</guid>

					<description><![CDATA[<p>Today Troy Hunt announced that a collection of 773 million usernames and passwords were released. This release of passwords, dubbed Collection #1, contains usernames and passwords that have shown up on the dark web over the past two or three years. Think of Collection #1 as being a value pack of bundled old password lists. [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/773-million-passwords-exposed-were-you-exposed/">773 Million Passwords Exposed &#8211; Were You Exposed?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Today Troy Hunt announced that a collection of 773 million usernames and passwords were released. This release of passwords, dubbed Collection #1, contains usernames and passwords<br />
<span id="more-2897"></span><br />
that have shown up on the dark web over the past two or three years. Think of Collection #1 as being a value pack of bundled old password lists.</p>
<p>If you want to find out if your passwords were released, visit his site called <a href="https://haveibeenpwned.com">https://haveibeenpwned.com</a>. If you elect to enter your email address, he will tell you if it is in the collection and give you more details.</p>
<p>What do you do if you are on the list? Reset your passwords. Use a password manager that will remember your passwords for you to make your life easier when you use a different password at each website from now on.</p>
<p>Now is a great time to enable two-step verification. A basic form of two-step verification is when you enter a username and password, and you receive a text message code to type in. Enable two-step verification on PayPal, LinkedIn, Dropbox, Facebook and every other web service you use. On each website, look for Settings &gt; Security. You may need to dig down, but more reputable sites now support two-step verification, but you must enable the feature.</p>
<p>Some bad news is that, about a week ago, a tool called Modlishka shows how to break two-step verification so it isn&#8217;t that secure, but two-step verification is still more secure than a simple username password combination. If it allows, have a website use some other method than texting you a password. Using an app on your phone or calling you via a voice call are options that are often more secure than the text message. Microsoft, Google, and a service called Duo offer these options and more. Having a hardware key is even better unless your laptop users leave the key stored in the laptop case, and their password written on the bottom of the laptop.</p>
<p>The post <a href="https://fosterinstitute.com/773-million-passwords-exposed-were-you-exposed/">773 Million Passwords Exposed &#8211; Were You Exposed?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Stealing Tesla Cars, and Stealing Your Network with Agent Tesla</title>
		<link>https://fosterinstitute.com/stealing-tesla-cars-and-stealing-your-network-with-agent-tesla/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 25 Oct 2018 20:16:24 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacker Insight]]></category>
		<category><![CDATA[Preventative IT Security Breach]]></category>
		<category><![CDATA[Agent Tesla]]></category>
		<category><![CDATA[Breaking Passwords]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Disgruntled Employee Security]]></category>
		<category><![CDATA[GoToMyPC]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[LogMeIn]]></category>
		<category><![CDATA[Stealing Keystroks]]></category>
		<category><![CDATA[Tesla Hackers]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2678</guid>

					<description><![CDATA[<p>The 3 minute Tesla car stealing video is fun, and keep reading the next paragraph about your organization&#8217;s security too.First the theft. Wired magazine published an article you can find by searching the title: Hackers Can Steal a Tesla Model S in Seconds by Cloning Its Key Fob. Then, you can watch a security cam [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/stealing-tesla-cars-and-stealing-your-network-with-agent-tesla/">Stealing Tesla Cars, and Stealing Your Network with Agent Tesla</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The 3 minute Tesla car stealing video is fun, and keep reading the next paragraph about your organization&#8217;s security too.<span id="more-2893"></span>First the theft. Wired magazine published an article you can find by searching the title: Hackers Can Steal a Tesla Model S in Seconds by Cloning Its Key Fob. Then, you can watch a security cam video of two men stealing a Model S in real life on YouTube. The thieves had to use Google to find out how to unplug the car. To see the short video, search: Tesla Model S Being Stolen Antony Kennedy or click <a href="https://www.youtube.com/watch?v=odG2GX4_cUQ&amp;feature=youtu.be" target="_blank" rel="noopener noreferrer">here</a>.</p>
<p>Now, what affects you directly whether you own a Tesla or not. Many IT Professionals, consultants, and outsourced IT firms access your network remotely using tools designed to help them help your users solve technical issues. Example programs include GoToMyPC, TeamViewer, LogMeIn, VNC, and Splashtop. Some outsourced companies use a product called Agent Tesla to support their customers. If you visit the website agent tesla dot com, you will see that the product has additional features including stealing keystrokes, breaking passwords, and spreading itself like a virus through a network. It appears that some bad actors have been using this tool to infect computers at companies without the company&#8217;s permission. And the tech support representatives at Agent Tesla were more than willing to assist the bad actors.</p>
<p>A key takeaway is that user-friendly tools can permit non-technical people to hack your network without needing any technical know-how.</p>
<p>What if a disgruntled or unscrupulous worker in your company installs GoToMyPC, LogMeIn, or similar easy-to-use software on computers in your private offices? They could overhear private conversations without anyone knowing. One of our clients experienced millions of dollars of embezzlement because a trusted worker used one of those programs on the computer that was in the conference room. The embezzler was not technically savvy at all, and he heard enough confidential information to embezzle millions and wreak all kinds of havoc. He did not need to use the additional user-friendly features that Agent Tesla provides including password cracking and automatic infection of other computers, but he could have.</p>
<p>Visit with your IT professionals. What are you, as an organization, doing to protect yourself from someone intentionally utilizing a readily available program, such as Agent Tesla, to infect your network, spy on your workers, steal information, and break your passwords?</p>
<p>The CEO, Owner, President, and other chief executives suffer the most when an attack devastates an organization. Most of them wish they&#8217;d have taken more of an active role in security. Learn from their mistakes, before it is too late.</p>
<p>The post <a href="https://fosterinstitute.com/stealing-tesla-cars-and-stealing-your-network-with-agent-tesla/">Stealing Tesla Cars, and Stealing Your Network with Agent Tesla</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Insanity of Your Network – Storing Keys in the Same Place as Everyone Else</title>
		<link>https://fosterinstitute.com/the-insanity-of-your-network-storing-keys-in-the-same-place-as-everyone-else/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 10 Sep 2018 16:07:03 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Pro Tips]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Password Safety]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[master passwords]]></category>
		<category><![CDATA[password access]]></category>
		<category><![CDATA[password location]]></category>
		<category><![CDATA[password safety]]></category>
		<category><![CDATA[safely storing passwords]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2666</guid>

					<description><![CDATA[<p>Imagine that you have a fleet of dozens of expensive vehicles, and you keep all of their keys in a locked cabinet. There is a master key that opens the cabinet. You assign your IT team the responsibility to secure and manage the keys to the vehicles, so you give each member of your IT [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/the-insanity-of-your-network-storing-keys-in-the-same-place-as-everyone-else/">The Insanity of Your Network – Storing Keys in the Same Place as Everyone Else</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Imagine that you have a fleet of dozens of expensive vehicles, and you keep all of their keys in a locked cabinet. There is a master key that opens the cabinet.</p>
<p>You assign your IT team <span id="more-2666"></span>the responsibility to secure and manage the keys to the vehicles, so you give each member of your IT team a copy of the master key.</p>
<p>Here is where it gets crazy: Suppose that there is a well-known tradition, in all companies, for IT professionals to store their master keys in the top drawer of their desks. Unfortunately, if someone wants to steal a vehicle, they know right where to find a master key. They can take all the cars once they gain access to the master, and they know exactly where to find it.</p>
<p>In the real world, your IT team has the responsibility to secure and manage your most sensitive data. In doing so, they have the master keys that unlock all the other keys. It is a tradition to give all IT professionals, and even outside consultants, keys to the master lockbox. The shocking part is that all IT professionals are encouraged to store the master keys in the same place, in the default well-known security groups named schema, enterprise, and domain admins.</p>
<p>Your IT team must create new security groups, with different names, in which to store the master keys. It is crucial that the new groups only provide specific privileges to member users on a need to know basis. It is ok if this strategy is new to them.</p>
<p>To measure this, ask your IT professionals to show you what users are members of those default security groups. Discuss moving those users into specific groups that provide the least amount of access they need to perform their work. Depending on the complexity of your system, this may take more time. IT professionals are always busy, so discuss with them their current projects, then prioritize this essential security improvement accordingly.</p>
<p>Storing master keys in a well-known location is absurd, and it is likely that you are doing that now.</p>
<p>The post <a href="https://fosterinstitute.com/the-insanity-of-your-network-storing-keys-in-the-same-place-as-everyone-else/">The Insanity of Your Network – Storing Keys in the Same Place as Everyone Else</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Three Biggest Cyber Security Trends Right Now</title>
		<link>https://fosterinstitute.com/the-three-biggest-cyber-security-trends-right-now/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 21 Dec 2017 13:00:56 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Executive Tips]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Service Provider Breach]]></category>
		<category><![CDATA[Breach Audit]]></category>
		<category><![CDATA[Contractor Breaches]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[Cyber Security Trends]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[security awareness training]]></category>
		<category><![CDATA[Service Provider Breaches]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Third Party Audit]]></category>
		<category><![CDATA[Vendor Security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2589</guid>

					<description><![CDATA[<p>First, the attacker population is outpacing the ability to control them. Attacks are trending higher at an ever-increasing rate. Be extra security-diligent. Second, ransomware, software that prevents you from accessing your information until you pay a ransom, incidences are accelerating. People still blame attackers for ransomware. Mostly thats an excuse. The solution is to be [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/the-three-biggest-cyber-security-trends-right-now/">The Three Biggest Cyber Security Trends Right Now</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>First, the attacker population is outpacing the ability to control them. Attacks are trending higher at an ever-increasing rate. Be extra security-diligent.<span id="more-2589"></span></p>
<p>Second, ransomware, software that prevents you from accessing your information until you pay a ransom, incidences are accelerating. People still blame attackers for ransomware. Mostly thats an excuse. The solution is to be more proactive and increase security before the ransomware can attack. And test your speedy restore capability regularly, just in case.</p>
<p>Last, about half of the breaches we see started with some service provider. All companies that provide you with goods and services might have infections on their networks that lead to a breach of data or an interruption in their ability to serve you, which may interfere with your ability to serve your customers. If they have a connection to your network, or exchange data with you in any way, they may unwittingly do something that compromises your organizations security. Be sure your vendors and service providers are security minded and have audits by qualified independent auditors.</p>
<p>Forward this to all the executives you know. Together we can make the world a safer place.</p>
<p>The post <a href="https://fosterinstitute.com/the-three-biggest-cyber-security-trends-right-now/">The Three Biggest Cyber Security Trends Right Now</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>About Half of All Breaches are Caused by a Contractor or Service Provider</title>
		<link>https://fosterinstitute.com/about-half-of-all-breaches-are-caused-by-a-contractor-or-service-provider/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 14 Dec 2017 18:48:31 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Training]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Preventative IT Security Breach]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Breach Audit]]></category>
		<category><![CDATA[Contractor Breaches]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[security awareness training]]></category>
		<category><![CDATA[Service Provider Breaches]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Third Party Audit]]></category>
		<category><![CDATA[Vendor Security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2585</guid>

					<description><![CDATA[<p>In our experience of auditing after breaches have happened, about half were caused by a service provider working for the company that gets breached. Almost always, the vendor or contractor had no malicious intent. Their organization’s own IT systems were not secure, and/or their team members performed actions in a non-secure way. Be sure the [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/about-half-of-all-breaches-are-caused-by-a-contractor-or-service-provider/">About Half of All Breaches are Caused by a Contractor or Service Provider</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In our experience of auditing after breaches have happened, about half were caused by a service provider working for the company that gets breached.<span id="more-2585"></span></p>
<p>Almost always, the vendor or contractor had no malicious intent. Their organization’s own IT systems were not secure, and/or their team members performed actions in a non-secure way.</p>
<p>Be sure the service providers you use are working every day to be more secure too. Ask them about their security awareness training program. Ask them how often they are audited by independent third party firms that are interested in helping them increase their own security. If you want to, encourage them to sign up for our newsletter.</p>
<p>Remember, your IT security relies on their IT security too.</p>
<p>The post <a href="https://fosterinstitute.com/about-half-of-all-breaches-are-caused-by-a-contractor-or-service-provider/">About Half of All Breaches are Caused by a Contractor or Service Provider</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Wireless Security is Broken &#038; What You Need to Do</title>
		<link>https://fosterinstitute.com/wireless-security-is-broken-what-you-need-to-do/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 17 Oct 2017 13:33:29 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[KRACK]]></category>
		<category><![CDATA[wi-fi best practices]]></category>
		<category><![CDATA[wi-fi safety]]></category>
		<category><![CDATA[wi-fi security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[firmware updates]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Microsoft patch]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[Security Patches]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Wi-fi security]]></category>
		<category><![CDATA[wireless network]]></category>
		<category><![CDATA[WPA2]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2558</guid>

					<description><![CDATA[<p>Many organizations rely on a wireless password to protect their Wi-Fi networks. Behind the scenes, that password is used as part of a security protocol called WPA2. An attack, dubbed KRACK, has been announced that breaks that security. The attack can permit attackers to potentially eavesdrop on your network traffic and your communications, change information, [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/wireless-security-is-broken-what-you-need-to-do/">Wireless Security is Broken &#038; What You Need to Do</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Many organizations rely on a wireless password to protect their Wi-Fi networks. Behind the scenes, that password is used as part of a security protocol called WPA2. An attack, dubbed KRACK, has been announced that breaks that security.<span id="more-2558"></span></p>
<p>The attack can permit attackers to potentially eavesdrop on your network traffic and your communications, change information, delete information, and insert information, all to cause problems and cost you money.</p>
<p>The good news is that the attacker needs to be within range of your Wi-Fi network. They could be some distance away if they use a strong antenna or if they plant a remotely controlled device nearby.</p>
<p>Do two things to mitigate this danger:</p>
<p>First: Apply the new patches that address this issue. That can prevent the attack.</p>
<p>Second: Isolate your wireless network from the rest of your network. That can help reduce the damage.</p>
<p>Related to the first step: Apply the most recent critical security patches, often called firmware updates, to your wireless devices. The company brands of your devices should release patches. Additionally, apply patches to your operating systems and applications that use Wi-Fi networking.</p>
<p>Microsoft released a patch a few days ago, on October 10, as part of the expected second Tuesday of every month patches, that solves this problem on their side of the products. At home, your automatic update should have patched your Windows workstations. But you will still need to patch your wireless access point. At the office, your IT team will need to patch the computers and devices. Please give them time to do so – it can take some time. Information about the attack in general, and some of the patches, can be found at: <a href="http://kb.cert.org/vuls/id/228519">kb.cert.org/vuls/id/228519</a> If the manufacturer of your devices does not produce updates, your next step might be to replace the devices with new ones.</p>
<p>For the second step: It is an IT Security best practice to isolate all wireless devices on your network to be away from the wired devices. For years, organizations would add wireless capabilities to their network by connecting wireless access points to the same network as your workstations and servers. That is a very dangerous practice since it can permit wireless devices, perhaps belonging to an attacker in the van outside your building, to access the wired resources on your network. In the case of this specific attack, it makes it easier for the attacker to access the data on the most protected parts of your organization’s network. Isolate all wireless devices on their own, what your IT professionals call a, filtered subnet.</p>
<p>As is often the case with IT Security, this will be a risk vs. expense decision. It is important that the executives of a company make the final decision about whether or not to ask IT to implement the mitigation steps. Your IT Team will appreciate your deciding, and the choice is yours since, if there is a successful cyber-attack, the executives, especially the president, CEO, and owner will suffer the most.</p>
<p>Please forward this to everyone you know who uses wireless networks.</p>
<p>The post <a href="https://fosterinstitute.com/wireless-security-is-broken-what-you-need-to-do/">Wireless Security is Broken &#038; What You Need to Do</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
