<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hacking Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/hacking/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Sat, 01 Jun 2024 00:02:18 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Hacking Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/hacking/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</title>
		<link>https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sat, 25 May 2024 21:38:42 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[BEC]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Fraud]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5809</guid>

					<description><![CDATA[<p>Have you ever wondered if someone is eavesdropping on you through your phone? While it might sound like a scene from a spy movie, there are real concerns about privacy and security related to microphone access on your devices. A Real-World Example from the Workplace: Recently, a new employee at a company received a fraudulent [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/">Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Have you ever wondered if someone is eavesdropping on you through your phone? While it might sound like a scene from a spy movie, there are real concerns about privacy and security related to microphone access on your devices.</p>
<p><strong>A Real-World Example from the Workplace</strong>: Recently, a new employee at a company received a fraudulent text message on her personal phone, supposedly from the company&#8217;s president. The president had not sent any text, and the company had not stored her personal phone number. How did the threat actor know? It’s possible that a data broker linked the new employee’s private phone number with the president’s name at the new company by eavesdropping on a conversation, such as her telling a friend about her new job. Upon investigation, the employee found that some unexpected apps had access to her microphone.</p>
<p><strong>A Real-Word Family Example</strong>: Last week, a husband and wife discussed dental options for their child at the breakfast table with their phones nearby. They hadn&#8217;t typed anything into a computer or searched online, yet less than an hour later, one received a text message from a company offering dental aligners. How could this happen? An app on their phone might have accessed the microphone, listened to the conversation, and shared the information with a data broker. The data broker then provided this information to a company selling dental aligners, prompting them to send a targeted text message. Have you or someone you know had similar experiences?</p>
<p><strong>How It Happens</strong>: Some apps collect data, including audio data from a microphone, and sell it to data brokers, also known as Marketing Data Aggregation Warehouses. These brokers aggregate and sell data to various businesses, including marketing and advertising firms. These businesses then use the information to send targeted advertisements or, in the case of threat actors, perform sophisticated phishing attacks designed to extract sensitive information or commit fraud.</p>
<p><strong>Apps are supposed to request your permission</strong> to access your microphone. However, this &#8220;user&#8217;s consent&#8221; often comes from clicking &#8220;Do you agree to the privacy policy&#8221; during installation. Most users do not read these policies and agree just to use the app. Privacy policies can be vague, stating that the user allows the app to collect information and share data with third parties.</p>
<p>Several types of apps can gather information for sale to data brokers and request microphone access in their privacy policies. These include:</p>
<ul>
<li><strong>Social Media and Communication Apps:</strong> Use microphone access for features like voice messaging and video recording, sharing collected data for advertising.</li>
<li><strong>Virtual Assistants:</strong> Require microphone access for functionality, collecting voice queries and background noise for service improvement and advertising.</li>
<li><strong>Gaming Apps:</strong> Mobile games with voice chat request microphone access for communication, sharing user data for advertising.</li>
<li><strong>Productivity Apps:</strong> Note-taking and voice recorder apps request access for audio notes and transcriptions, collecting valuable user data.</li>
<li><strong>Health and Fitness Apps:</strong> Fitness trackers and health apps request microphone access for voice input, collecting sensitive health data.</li>
<li><strong>Utility Apps:</strong> Simple apps like flashlights and calculators sometimes request unnecessary permissions, including microphone access, to gather user data covertly.</li>
<li><strong>Marketing and Rewards Apps:</strong> Request location and microphone access to collect user data, which is then sold to data brokers.</li>
</ul>
<p>These apps often include clauses in their privacy policies that allow microphone data collection, which users might unknowingly grant, leading to targeted advertising and other uses by data brokers.</p>
<p>For further reading, refer to articles like &#8220;FTC Cracks Down on Mass Data Collectors&#8221; by the Federal Trade Commission.</p>
<p><strong>Protecting Your Privacy:</strong> To protect against such risks, Apple, Google, and Microsoft have all implemented ways to help ensure your microphone&#8217;s privacy even if users agree to the privacy policy. Instructions for disabling access to your mic are listed below. It’s crucial to regularly review and update app permissions on your devices, ensuring that only essential apps have access to sensitive data like the microphone.</p>
<p><strong>Beyond Annoying Ads</strong>: Threat actors can use similar tactics to perform targeted attacks and commit fraud against individuals and their companies. For instance, the fraudulent text message received by the new employee could lead to more sophisticated phishing attacks intended for extracting sensitive information, transferring money, or other financial fraud.</p>
<p><strong>Follow the instructions in the following draft memo you can send your workers and tell your family</strong>:</p>
<h3><strong>Memo to All Employees: Securing Your Microphone Privacy Settings</strong></h3>
<p>Dear Team,</p>
<p>We are committed to ensuring the privacy and security of our employees&#8217; personal and professional information. Recent reports have highlighted the risks associated with apps accessing device microphones without explicit consent, potentially leading to targeted fraud and privacy breaches.</p>
<p>To protect your privacy and our organization&#8217;s security, we ask all employees to take a few moments to review and update the microphone privacy settings on their devices. Below are step-by-step instructions for various platforms:</p>
<p><strong>For Apple Devices:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Privacy &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all applications that do not need access to your mic.</li>
</ol>
<p><strong>For Android Devices:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Type Microphone, Privacy, or Permission Manager in the search box. </strong>If you do not see the privacy settings, you might need to use a search engine or chatbot to find specific instructions for your device model and version of Android.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>For Windows:</strong></p>
<ol>
<li>Go to <strong>Settings &gt; Privacy &amp; Security &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>For Macs:</strong></p>
<ol>
<li>Click on the <strong>Apple symbol &gt; System Settings &gt; Privacy &amp; Security &gt; Microphone</strong>.</li>
<li>Turn off the microphone for all apps that do not need access to your mic.</li>
</ol>
<p><strong>Practical Steps:</strong></p>
<ul>
<li><strong>Revoke Unnecessary Access:</strong> Disable microphone access for all apps that do not need it. Allow exceptions for essential apps such as video conferencing tools and browsers if you use them for meetings. If you are uncertain, restrict access; the app will request permission if it needs access in the future.</li>
<li><strong>Test Essential Apps:</strong> Before your next meeting, verify that the apps you frequently use for video conferencing and other essential functions work correctly with the microphone settings you have configured.</li>
<li><strong>Restrict Other Permissions:</strong> While adjusting your microphone settings, you&#8217;ll see other settings. To further protect your privacy, consider restricting access to your camera, location, contacts, and other sensitive data.</li>
</ul>
<p>We live in a world where protecting our privacy is increasingly our responsibility. Threat actors are becoming more sophisticated, so it&#8217;s crucial to stay vigilant and proactive in securing our devices.</p>
<p>Thank you for your attention to this important matter. If you have any questions or need assistance, please ask.</p>
<p>(In the last sentence, you can give them more specific guidance on what to do if they have a question)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<h6></h6>
<p>The post <a href="https://fosterinstitute.com/are-threat-actors-listening-to-your-phone-secure-your-mic-to-reduce-risks/">Are Threat Actors Listening to Your Phone? Secure Your Mic to Reduce Security Risks and Protect Your Privacy</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Concerns and Fun with ChatGPT</title>
		<link>https://fosterinstitute.com/cybersecurity-concerns-and-fun-with-chatgpt/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 23:13:06 +0000</pubDate>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5368</guid>

					<description><![CDATA[<p>If you’ve not tried Open AI ChatGPT yet, you must. It has changed the world forever and the sooner you try it, the better. You can go to the web address: chat.openai.com/chat. Read the privacy warnings and, if you agree, sign up. When you start having conversations, prepare to be amazed. Most people I encounter [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/cybersecurity-concerns-and-fun-with-chatgpt/">Cybersecurity Concerns and Fun with ChatGPT</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you’ve not tried Open AI ChatGPT yet, you must. It has changed the world forever and the sooner you try it, the better. You can go to the web address: <a href="http://chat.openai.com/chat" target="_blank" rel="noopener">chat.openai.com/chat</a>. Read the privacy warnings and, if you agree, sign up. When you start having conversations, prepare to be amazed.</p>
<p>Most people I encounter talk about their fun with ChatGPT, and I can relate. Type “Write a Valentine’s day note to my lover who likes (activities). I’m attracted to their (attractions) and want them to know (details).” Keep adding details. And, of course, you can say, “Make it rhyme” or “write it like Shakespeare.” You’ll have a smile on your face.</p>
<p>Be sure to select “New chat” whenever you change topics. After you get a surprisingly fun Valentine’s message, open a new chat to ask, “Remind me of the Excel formula to return the first twenty characters of a string.” ChatGPT remembers conversations in chat segments, so avoid mixing topics to get the best results.</p>
<p>AI has given a new meaning to the term Virtual Assistant. Sometimes I compose long email messages and want to shorten them. I first compose the message with no sensitive information, give it to ChatGPT, and say, “Write this shorter.” It is stunning how capable it is at combining sentences and summarizing ideas while mostly keeping the whole meaning. Sometimes it elaborates and incorporates new ideas into the message. I find that amusing and occasionally helpful. I must re-read the output carefully and often make changes since ChatGPT is not perfect at knowing precisely what I mean, but for long messages, it sometimes helps me make them concise, saving the recipient time.</p>
<p>Do not be duped – AI does not know everything and can accidentally produce inaccurate information that sounds very convincing.</p>
<p>When I hear people discussing the risks of ChatGPT, they usually focus on students using it to write their essay assignments for them. They have not considered more severe concerns. If you are interested, search the web for: chatbot ai can be used to create ransomware video.</p>
<p>Fortunately, ChatGPT is implementing safeguards to help prevent malicious use, and there are ways to trick it. Values and ethics vary from person to person, and some people, or governments, might feel justified in using AI to help create weapons, influence elections, or help them with strategies to harm.</p>
<p>Before his death, the famous physicist Stephen Hawking warned that AI could “end mankind.” Elon Musk has donated millions of dollars to OpenAI but intensely voiced concerns about the dangers of AI.</p>
<p>Some of our clients now block access to ChatGPT on company networks and devices. Some won’t.</p>
<p>Please forward this to your friends so they will consider the risks and enjoy AI-related fun. ChatGPT is impressive, and the business world will never be the same.</p>
<p>The post <a href="https://fosterinstitute.com/cybersecurity-concerns-and-fun-with-chatgpt/">Cybersecurity Concerns and Fun with ChatGPT</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Short List of Essential Cybersecurity Statistics Exposes Attackers and Can Help You Secure Your Systems</title>
		<link>https://fosterinstitute.com/short-list-of-essential-cybersecurity-statistics-exposes-attackers-and-can-help-you-secure-your-systems/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 10 Jan 2023 16:52:41 +0000</pubDate>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Supporting IT Professionals]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5361</guid>

					<description><![CDATA[<p>Verizon&#8217;s 2022 Data Breach Investigation Report reveals some interesting information from extensive worldwide research. In North America, System Intrusion (Now up to 80%) attacks surpass Social Engineering (down to 20%). System Intrusion is when attackers gain access to networks, plant ransomware, establish remote access, and otherwise compromise data and processes in a network. 90% of [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/short-list-of-essential-cybersecurity-statistics-exposes-attackers-and-can-help-you-secure-your-systems/">Short List of Essential Cybersecurity Statistics Exposes Attackers and Can Help You Secure Your Systems</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Verizon&#8217;s 2022 Data Breach Investigation Report reveals some interesting information from extensive worldwide research.</p>
<p>In North America, System Intrusion (Now up to 80%) attacks surpass Social Engineering (down to 20%). System Intrusion is when attackers gain access to networks, plant ransomware, establish remote access, and otherwise compromise data and processes in a network.</p>
<p>90% of system intrusion attacks in North America were performed by threat actors external to the company. But the 10% of internal attacks highlights the concern of insider threats. Insider threat is when someone working for an organization accidentally or intentionally gives attackers access.</p>
<p>In North America, the motivation for attacks are:<br />
For financial gain: 96%<br />
Espionage and spying: 3%<br />
Grudges and anger: 1%</p>
<p>Of attacks in North America, 14% were caused Primarily by Cloud Security Misconfigurations, highlighting the need to ensure IT professionals are familiar with the complex security settings related to cloud services. An excellent resource for Microsoft Cloud Security is <a href="https://learn.microsoft.com/en-us/microsoft-365/solutions/setup-secure-collaboration-with-teams?view=o365-worldwide#securing-teams-for-sensitive-and-highly-sensitive-data" target="_blank" rel="noopener">https://learn.microsoft.com/en-us/microsoft-365/solutions/setup-secure-collaboration-with-teams?view=o365-worldwide#securing-teams-for-sensitive-and-highly-sensitive-data</a></p>
<p>To see statistics in other parts of the world and overall, you can find the report at <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener">https://www.verizon.com/business/resources/reports/dbir/</a></p>
<p>The post <a href="https://fosterinstitute.com/short-list-of-essential-cybersecurity-statistics-exposes-attackers-and-can-help-you-secure-your-systems/">Short List of Essential Cybersecurity Statistics Exposes Attackers and Can Help You Secure Your Systems</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Know Why Web Application Providers Show Dots when You Type Your Passwords</title>
		<link>https://fosterinstitute.com/know-why-web-application-providers-show-dots-when-you-type-your-passwords/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Tue, 13 Dec 2022 21:15:56 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5356</guid>

					<description><![CDATA[<p>Dalmatians have dots, and so should your screen when you enter your password. Those dots help prevent screen recordings from capturing your passwords. If you have malware on your phone, tablet, or computer, it could be recording images of your screen as you type. If the malware can only see dots, your password is safe [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/know-why-web-application-providers-show-dots-when-you-type-your-passwords/">Know Why Web Application Providers Show Dots when You Type Your Passwords</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Dalmatians have dots, and so should your screen when you enter your password. Those dots help prevent screen recordings from capturing your passwords.</p>
<p>If you have malware on your phone, tablet, or computer, it could be recording images of your screen as you type. If the malware can only see dots, your password is safe from “shoulder surfers” looking at your screen from thousands of miles away.</p>
<p>Additionally, if you use language translation or other browser plug-ins that read your screen, your browsers could be “reading” the text on your screen. If web applications or websites display your actual password, it might get transmitted to strangers without you realizing it.</p>
<p>It can be frustrating not to see your password as you type, but there is a good reason beyond knowing the person next to you isn’t watching your screen.</p>
<p>For information about preventing malware on your systems, please visit the Foster Institute Blog at <a href="https://fosterinstitute.com/blog" target="_blank" rel="noopener">fosterinstitute.com/blog</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://fosterinstitute.com/know-why-web-application-providers-show-dots-when-you-type-your-passwords/">Know Why Web Application Providers Show Dots when You Type Your Passwords</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Avoid Receiving Disturbing Photos via Apple AirDrop and Android Nearby</title>
		<link>https://fosterinstitute.com/how-to-avoid-receiving-disturbing-photos-via-apple-airdrop-and-android-near/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 26 Sep 2022 17:59:05 +0000</pubDate>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Wireless Security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5334</guid>

					<description><![CDATA[<p>You’ve likely seen the video or at least heard the story of how a Southwest Airlines pilot responded to complaints from passengers that they received images of an unclothed person on their phone. The captain used the intercom system to scold the unknown passenger and threatened to return to the gate. This so-called cyber-flashing is [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/how-to-avoid-receiving-disturbing-photos-via-apple-airdrop-and-android-near/">How to Avoid Receiving Disturbing Photos via Apple AirDrop and Android Nearby</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You’ve likely seen the video or at least heard the story of how a Southwest Airlines pilot responded to complaints from passengers that they received images of an unclothed person on their phone. The captain used the intercom system to scold the unknown passenger and threatened to return to the gate.</p>
<p>This so-called cyber-flashing is a growing problem with Apple’s AirDrop feature and Android’s Nearby Share feature that allow you to send and receive images, videos, and files from other users nearby.</p>
<p>Yes, you get prompted to decline or accept the image, but you cannot unsee the preview image in the prompt.</p>
<p>To protect yourself on your Apple device, Click on Settings, General, and AirDrop to choose Receiving Off, Contacts Only, or Everyone. I recommend you select Receiving Off. Temporarily enable receiving when you wish to exchange photos. Apple provides a detailed explanation of AirDrop at <a href="https://support.apple.com/en-us/HT204144" target="_blank" rel="noopener">https://support.apple.com/en-us/HT204144</a></p>
<p>To protect yourself on an Android device, choose Hidden your Nearby Share settings. The steps will differ depending on your device and version: Settings, Connected Devices, Connection preferences, Nearby Share, and choose Hidden. Or your device might have you go to Settings, Google, Devices &amp; Sharing, Nearby Share, and set Use Nearby Share to Off. You can learn more about Nearby Share at <a href="https://support.google.com/android/answer/9286773?hl=en" target="_blank" rel="noopener">https://support.google.com/android/answer/9286773?hl=en</a></p>
<p>Bad actors strive to find ways to affect users of any brand and type of device and service. Please forward this to your friends, so they don’t receive shocking images via AirDrop or Nearby Share!</p>
<p>The post <a href="https://fosterinstitute.com/how-to-avoid-receiving-disturbing-photos-via-apple-airdrop-and-android-near/">How to Avoid Receiving Disturbing Photos via Apple AirDrop and Android Nearby</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Anatomy of a Password Attack, and How to Prevent Them</title>
		<link>https://fosterinstitute.com/anatomy-of-a-password-attack-and-how-to-prevent-them/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 09 Jun 2022 22:13:47 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Password Security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5260</guid>

					<description><![CDATA[<p>Password attacks against businesses happen all the time. You can protect your organization. Imagine that your firewall has doors to allow connections into your network. Usernames and passwords are the keys to unlocking the doors. An effective cybersecurity control is to remove the doors. When there is no door, there is no keyhole for an [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/anatomy-of-a-password-attack-and-how-to-prevent-them/">Anatomy of a Password Attack, and How to Prevent Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Password attacks against businesses happen all the time. You can protect your organization.</p>
<p>Imagine that your firewall has doors to allow connections into your network. Usernames and passwords are the keys to unlocking the doors. An effective cybersecurity control is to remove the doors. When there is no door, there is no keyhole for an attacker to try to guess the keys.</p>
<p>Many organizations have too many open doors exposed to the world. An essential cybersecurity control is to remove the entries. Alternatively, if you must have the door, your IT team can configure the firewall with a cloaking strategy so that only specific sources can see the door. Most people would never know there is a door.</p>
<p>Ask your IT team to close external ports that are not essential to doing business. If they must leave ports open, ask them to create rules to limit access to specific source addresses if possible.</p>
<p>Below is information from the security log file on a server tracking failed login attempts. For a brute-force password guessing attack, the attackers must also guess usernames. They can predict usernames such as Administrator, so they try many passwords, 1398 in the example below, for predictable names.</p>
<p>If your IT team shows you a list of guessed names, and the guessed usernames match workers in your organization, that is a severe concern. It means that the attackers have done their research or already have access. You are a specific target. Remember, if there is no door, then these attacks cannot happen:</p>
<p>1398 different passwords attempted with this guessed username: Administrator<br />
836 different passwords attempted with this guessed username: Admin<br />
554 different passwords attempted with this guessed username: user<br />
314 different passwords attempted with this guessed username: test<br />
314 different passwords attempted with this guessed username: user1<br />
160 different passwords attempted with this guessed username: user2<br />
156 different passwords attempted with this guessed username: user3<br />
156 different passwords attempted with this guessed username: admin1<br />
155 different passwords attempted with this guessed username: test1<br />
111 different passwords attempted with this guessed username: guest<br />
91 different passwords attempted with this guessed username: sql<br />
89 different passwords attempted with this guessed username: aspnet<br />
87 different passwords attempted with this guessed username: support_388945a0<br />
84 different passwords attempted with this guessed username: david<br />
83 different passwords attempted with this guessed username: root<br />
82 different passwords attempted with this guessed username: backup<br />
80 different passwords attempted with this guessed username: sys<br />
80 different passwords attempted with this guessed username: support<br />
80 different passwords attempted with this guessed username: Other<br />
80 different passwords attempted with this guessed username: a<br />
78 different passwords attempted with this guessed username: test2<br />
78 different passwords attempted with this guessed username: server<br />
78 different passwords attempted with this guessed username: 1<br />
78 different passwords attempted with this guessed username: john<br />
78 different passwords attempted with this guessed username: test3<br />
78 different passwords attempted with this guessed username: console<br />
78 different passwords attempted with this guessed username: owner<br />
78 different passwords attempted with this guessed username: actuser<br />
78 different passwords attempted with this guessed username: 123<br />
78 different passwords attempted with this guessed username: adm<br />
78 different passwords attempted with this guessed username: admin2<br />
78 different passwords attempted with this guessed username: user4<br />
78 different passwords attempted with this guessed username: user5<br />
32 different passwords attempted with this guessed username: surferquest<br />
18 different passwords attempted with this guessed username: auditor<br />
15 different passwords attempted with this guessed username: alilong<br />
14 different passwords attempted with this guessed username: SCOTT<br />
13 different passwords attempted with this guessed username: chirotouch<br />
13 different passwords attempted with this guessed username: PEGGY<br />
12 different passwords attempted with this guessed username: follow<br />
12 different passwords attempted with this guessed username: CHERYL<br />
12 different passwords attempted with this guessed username: TERRI<br />
11 different passwords attempted with this guessed username: ETB User<br />
10 different passwords attempted with this guessed username: system_backupDB<br />
10 different passwords attempted with this guessed username: QBPOSDBSrvUser<br />
10 different passwords attempted with this guessed username: xuhai<br />
10 different passwords attempted with this guessed username: tu<br />
9 different passwords attempted with this guessed username: mroot<br />
9 different passwords attempted with this guessed username: manager<br />
9 different passwords attempted with this guessed username: justin<br />
8 different passwords attempted with this guessed username: iis<br />
8 different passwords attempted with this guessed username: Linux<br />
7 different passwords attempted with this guessed username: acs<br />
7 different passwords attempted with this guessed username: vetvault<br />
7 different passwords attempted with this guessed username: squirrel<br />
7 different passwords attempted with this guessed username: user01<br />
7 different passwords attempted with this guessed username: crsuser<br />
6 different passwords attempted with this guessed username: saleslan<br />
6 different passwords attempted with this guessed username: IUSR_SOR<br />
6 different passwords attempted with this guessed username: scan<br />
6 different passwords attempted with this guessed username: expedite<br />
6 different passwords attempted with this guessed username: DSNVSUser<br />
6 different passwords attempted with this guessed username: reception<br />
6 different passwords attempted with this guessed username: hei<br />
6 different passwords attempted with this guessed username: VNIAdmin_DoNotDelete<br />
6 different passwords attempted with this guessed username: kaypro<br />
6 different passwords attempted with this guessed username: payroll<br />
6 different passwords attempted with this guessed username: mark<br />
6 different passwords attempted with this guessed username: alex<br />
6 different passwords attempted with this guessed username: linhai<br />
6 different passwords attempted with this guessed username: ntsec_admin<br />
6 different passwords attempted with this guessed username: lisa<br />
6 different passwords attempted with this guessed username: oprrs<br />
6 different passwords attempted with this guessed username: monster<br />
5 different passwords attempted with this guessed username: Acsadmin<br />
5 different passwords attempted with this guessed username: cli<br />
5 different passwords attempted with this guessed username: awesen<br />
5 different passwords attempted with this guessed username: aloha<br />
5 different passwords attempted with this guessed username: micrologic<br />
5 different passwords attempted with this guessed username: scanner<br />
5 different passwords attempted with this guessed username: swentz<br />
5 different passwords attempted with this guessed username: jacob<br />
5 different passwords attempted with this guessed username: jordan<br />
5 different passwords attempted with this guessed username: backoffice<br />
5 different passwords attempted with this guessed username: amiga<br />
5 different passwords attempted with this guessed username: pos<br />
4 different passwords attempted with this guessed username: warehouse<br />
4 different passwords attempted with this guessed username: rdspos<br />
4 different passwords attempted with this guessed username: linda<br />
4 different passwords attempted with this guessed username: copier<br />
4 different passwords attempted with this guessed username: rds<br />
4 different passwords attempted with this guessed username: acasey<br />
4 different passwords attempted with this guessed username: mary<br />
4 different passwords attempted with this guessed username: sapsupport<br />
4 different passwords attempted with this guessed username: Post6<br />
4 different passwords attempted with this guessed username: james<br />
4 different passwords attempted with this guessed username: micros<br />
4 different passwords attempted with this guessed username: spppse<br />
4 different passwords attempted with this guessed username: possvr<br />
4 different passwords attempted with this guessed username: apple_terminal<br />
3 different passwords attempted with this guessed username: shipping<br />
3 different passwords attempted with this guessed username: manw<br />
3 different passwords attempted with this guessed username: MssqlUser<br />
3 different passwords attempted with this guessed username: miass<br />
3 different passwords attempted with this guessed username: receptionist<br />
3 different passwords attempted with this guessed username: grace<br />
3 different passwords attempted with this guessed username: iusr_qa<br />
3 different passwords attempted with this guessed username: hk<br />
3 different passwords attempted with this guessed username: fax<br />
3 different passwords attempted with this guessed username: menw<br />
3 different passwords attempted with this guessed username: sales<br />
3 different passwords attempted with this guessed username: parts<br />
3 different passwords attempted with this guessed username: Tsmotw<br />
3 different passwords attempted with this guessed username: svc-netmon<br />
3 different passwords attempted with this guessed username: staff<br />
3 different passwords attempted with this guessed username: adminsc5<br />
3 different passwords attempted with this guessed username: ssyyet<br />
3 different passwords attempted with this guessed username: sysadmin<br />
3 different passwords attempted with this guessed username: ashley<br />
3 different passwords attempted with this guessed username: araxi<br />
3 different passwords attempted with this guessed username: ccdrs<br />
3 different passwords attempted with this guessed username: ava<br />
3 different passwords attempted with this guessed username: Cat<br />
3 different passwords attempted with this guessed username: Spectra<br />
3 different passwords attempted with this guessed username: tech<br />
3 different passwords attempted with this guessed username: voicemail<br />
3 different passwords attempted with this guessed username: adm1n<br />
3 different passwords attempted with this guessed username: terry<br />
3 different passwords attempted with this guessed username: Administrador<br />
2 different passwords attempted with this guessed username: laptop<br />
2 different passwords attempted with this guessed username: lab<br />
2 different passwords attempted with this guessed username: Astsm<br />
2 different passwords attempted with this guessed username: larry<br />
2 different passwords attempted with this guessed username: lee<br />
2 different passwords attempted with this guessed username: billing<br />
2 different passwords attempted with this guessed username: besadmin<br />
2 different passwords attempted with this guessed username: bill<br />
2 different passwords attempted with this guessed username: joshua<br />
2 different passwords attempted with this guessed username: kathy<br />
2 different passwords attempted with this guessed username: avery<br />
2 different passwords attempted with this guessed username: beadmin<br />
2 different passwords attempted with this guessed username: Kantech<br />
2 different passwords attempted with this guessed username: keith<br />
2 different passwords attempted with this guessed username: kiosk<br />
2 different passwords attempted with this guessed username: aubrey<br />
2 different passwords attempted with this guessed username: joseph<br />
2 different passwords attempted with this guessed username: benjamin<br />
2 different passwords attempted with this guessed username: lewis<br />
2 different passwords attempted with this guessed username: alan<br />
2 different passwords attempted with this guessed username: aiden<br />
2 different passwords attempted with this guessed username: addison<br />
2 different passwords attempted with this guessed username: lvellman<br />
2 different passwords attempted with this guessed username: madison<br />
2 different passwords attempted with this guessed username: manger<br />
2 different passwords attempted with this guessed username: accountant<br />
2 different passwords attempted with this guessed username: mia<br />
2 different passwords attempted with this guessed username: abigail<br />
2 different passwords attempted with this guessed username: mason<br />
2 different passwords attempted with this guessed username: matthew<br />
2 different passwords attempted with this guessed username: adam<br />
2 different passwords attempted with this guessed username: angela<br />
2 different passwords attempted with this guessed username: andrew<br />
2 different passwords attempted with this guessed username: andrea<br />
2 different passwords attempted with this guessed username: liam<br />
2 different passwords attempted with this guessed username: anthony<br />
2 different passwords attempted with this guessed username: lillian<br />
2 different passwords attempted with this guessed username: logmeinremoteuser<br />
2 different passwords attempted with this guessed username: lori<br />
2 different passwords attempted with this guessed username: lucas<br />
2 different passwords attempted with this guessed username: amelia<br />
2 different passwords attempted with this guessed username: alexander<br />
2 different passwords attempted with this guessed username: logan<br />
2 different passwords attempted with this guessed username: joe<br />
2 different passwords attempted with this guessed username: cindy<br />
2 different passwords attempted with this guessed username: chris<br />
2 different passwords attempted with this guessed username: chloe<br />
2 different passwords attempted with this guessed username: CorpOwner<br />
2 different passwords attempted with this guessed username: evelyn<br />
2 different passwords attempted with this guessed username: consult<br />
2 different passwords attempted with this guessed username: front<br />
2 different passwords attempted with this guessed username: frontdesk<br />
2 different passwords attempted with this guessed username: gabriel<br />
2 different passwords attempted with this guessed username: checkout<br />
2 different passwords attempted with this guessed username: FranOwner<br />
2 different passwords attempted with this guessed username: checkin<br />
2 different passwords attempted with this guessed username: ethan<br />
2 different passwords attempted with this guessed username: elijah<br />
2 different passwords attempted with this guessed username: elizabeth<br />
2 different passwords attempted with this guessed username: ella<br />
2 different passwords attempted with this guessed username: doctor<br />
2 different passwords attempted with this guessed username: don<br />
2 different passwords attempted with this guessed username: donna<br />
2 different passwords attempted with this guessed username: dennis<br />
2 different passwords attempted with this guessed username: daniel<br />
2 different passwords attempted with this guessed username: cs13368<br />
2 different passwords attempted with this guessed username: emily<br />
2 different passwords attempted with this guessed username: emma<br />
2 different passwords attempted with this guessed username: eric<br />
2 different passwords attempted with this guessed username: general<br />
2 different passwords attempted with this guessed username: bruce<br />
2 different passwords attempted with this guessed username: jack<br />
2 different passwords attempted with this guessed username: jackson<br />
2 different passwords attempted with this guessed username: buexec<br />
2 different passwords attempted with this guessed username: isabella<br />
2 different passwords attempted with this guessed username: bruno<br />
2 different passwords attempted with this guessed username: bkupexec<br />
2 different passwords attempted with this guessed username: jerry<br />
2 different passwords attempted with this guessed username: jim<br />
2 different passwords attempted with this guessed username: brian<br />
2 different passwords attempted with this guessed username: jayden<br />
2 different passwords attempted with this guessed username: jeff<br />
2 different passwords attempted with this guessed username: intern<br />
2 different passwords attempted with this guessed username: harper<br />
2 different passwords attempted with this guessed username: charlie<br />
2 different passwords attempted with this guessed username: chad<br />
2 different passwords attempted with this guessed username: glenn<br />
2 different passwords attempted with this guessed username: charlotte<br />
2 different passwords attempted with this guessed username: grocery<br />
2 different passwords attempted with this guessed username: canon<br />
2 different passwords attempted with this guessed username: info<br />
2 different passwords attempted with this guessed username: install<br />
2 different passwords attempted with this guessed username: celerant<br />
2 different passwords attempted with this guessed username: henry<br />
2 different passwords attempted with this guessed username: carlos<br />
2 different passwords attempted with this guessed username: remote<br />
2 different passwords attempted with this guessed username: tim<br />
2 different passwords attempted with this guessed username: tom<br />
2 different passwords attempted with this guessed username: Ray<br />
2 different passwords attempted with this guessed username: robert<br />
2 different passwords attempted with this guessed username: roger<br />
2 different passwords attempted with this guessed username: RETAIL<br />
2 different passwords attempted with this guessed username: ricoh<br />
2 different passwords attempted with this guessed username: Post4<br />
2 different passwords attempted with this guessed username: Post7<br />
2 different passwords attempted with this guessed username: trish<br />
2 different passwords attempted with this guessed username: peter<br />
2 different passwords attempted with this guessed username: production<br />
2 different passwords attempted with this guessed username: tony<br />
2 different passwords attempted with this guessed username: toshiba<br />
2 different passwords attempted with this guessed username: tool<br />
2 different passwords attempted with this guessed username: sophia<br />
2 different passwords attempted with this guessed username: sqladmin<br />
2 different passwords attempted with this guessed username: Tech01<br />
2 different passwords attempted with this guessed username: sofia<br />
2 different passwords attempted with this guessed username: steve<br />
2 different passwords attempted with this guessed username: symantec<br />
2 different passwords attempted with this guessed username: stanley<br />
2 different passwords attempted with this guessed username: t1<br />
2 different passwords attempted with this guessed username: samuel<br />
2 different passwords attempted with this guessed username: scans<br />
2 different passwords attempted with this guessed username: terasoma<br />
2 different passwords attempted with this guessed username: temp<br />
2 different passwords attempted with this guessed username: Silverx<br />
2 different passwords attempted with this guessed username: skaner<br />
2 different passwords attempted with this guessed username: security<br />
2 different passwords attempted with this guessed username: shop<br />
2 different passwords attempted with this guessed username: operator<br />
2 different passwords attempted with this guessed username: olivia<br />
2 different passwords attempted with this guessed username: natalie<br />
2 different passwords attempted with this guessed username: zoey<br />
2 different passwords attempted with this guessed username: mike<br />
2 different passwords attempted with this guessed username: william<br />
2 different passwords attempted with this guessed username: ospite<br />
2 different passwords attempted with this guessed username: office<br />
2 different passwords attempted with this guessed username: veronica<br />
2 different passwords attempted with this guessed username: vismail<br />
2 different passwords attempted with this guessed username: victoria<br />
2 different passwords attempted with this guessed username: noah<br />
2 different passwords attempted with this guessed username: ncrm<br />
2 different passwords attempted with this guessed username: wand<br />
2 different passwords attempted with this guessed username: nss256wendys<br />
2 different passwords attempted with this guessed username: michael<br />
2 different passwords attempted with this guessed username: microssvc<br />
2 different passwords attempted with this guessed username: visitor<br />
2 different passwords attempted with this guessed username: xerox<br />
1 different passwords attempted with this guessed username: template<br />
1 different passwords attempted with this guessed username: cia<br />
1 different passwords attempted with this guessed username: cihan<br />
1 different passwords attempted with this guessed username: cayetano<br />
1 different passwords attempted with this guessed username: muhasebe<br />
1 different passwords attempted with this guessed username: bruno1234<br />
1 different passwords attempted with this guessed username: comercial<br />
1 different passwords attempted with this guessed username: susan<br />
1 different passwords attempted with this guessed username: vrfy<br />
1 different passwords attempted with this guessed username: camilie<br />
1 different passwords attempted with this guessed username: teresa<br />
1 different passwords attempted with this guessed username: telnet<br />
1 different passwords attempted with this guessed username: ted<br />
1 different passwords attempted with this guessed username: tape<br />
1 different passwords attempted with this guessed username: washington<br />
1 different passwords attempted with this guessed username: web<br />
1 different passwords attempted with this guessed username: taylor<br />
1 different passwords attempted with this guessed username: tcp<br />
1 different passwords attempted with this guessed username: tarragona<br />
1 different passwords attempted with this guessed username: tanya<br />
1 different passwords attempted with this guessed username: teds<br />
1 different passwords attempted with this guessed username: acct1<br />
1 different passwords attempted with this guessed username: t12010<br />
1 different passwords attempted with this guessed username: tammy<br />
1 different passwords attempted with this guessed username: www<br />
1 different passwords attempted with this guessed username: ceyda<br />
1 different passwords attempted with this guessed username: accounting<br />
1 different passwords attempted with this guessed username: training<br />
1 different passwords attempted with this guessed username: tracy<br />
1 different passwords attempted with this guessed username: travis<br />
1 different passwords attempted with this guessed username: transition<br />
1 different passwords attempted with this guessed username: vance<br />
1 different passwords attempted with this guessed username: tracey<br />
1 different passwords attempted with this guessed username: appservadmin<br />
1 different passwords attempted with this guessed username: appismo<br />
1 different passwords attempted with this guessed username: vanschoor<br />
1 different passwords attempted with this guessed username: trent<br />
1 different passwords attempted with this guessed username: user02<br />
1 different passwords attempted with this guessed username: tsadmin<br />
1 different passwords attempted with this guessed username: user8<br />
1 different passwords attempted with this guessed username: user7<br />
1 different passwords attempted with this guessed username: truck<br />
1 different passwords attempted with this guessed username: tricia<br />
1 different passwords attempted with this guessed username: uwe<br />
1 different passwords attempted with this guessed username: troisi<br />
1 different passwords attempted with this guessed username: uucp<br />
1 different passwords attempted with this guessed username: timc<br />
1 different passwords attempted with this guessed username: thomas<br />
1 different passwords attempted with this guessed username: timeclock<br />
1 different passwords attempted with this guessed username: beer<br />
1 different passwords attempted with this guessed username: therese<br />
1 different passwords attempted with this guessed username: term<br />
1 different passwords attempted with this guessed username: teri<br />
1 different passwords attempted with this guessed username: theresa<br />
1 different passwords attempted with this guessed username: texas<br />
1 different passwords attempted with this guessed username: backupexec<br />
1 different passwords attempted with this guessed username: vcs<br />
1 different passwords attempted with this guessed username: toni<br />
1 different passwords attempted with this guessed username: vargas<br />
1 different passwords attempted with this guessed username: tonya<br />
1 different passwords attempted with this guessed username: tommy<br />
1 different passwords attempted with this guessed username: timothy<br />
1 different passwords attempted with this guessed username: timeclock mails<br />
1 different passwords attempted with this guessed username: todd<br />
1 different passwords attempted with this guessed username: tina<br />
1 different passwords attempted with this guessed username: perl<br />
1 different passwords attempted with this guessed username: pentagon<br />
1 different passwords attempted with this guessed username: piotr<br />
1 different passwords attempted with this guessed username: Post2<br />
1 different passwords attempted with this guessed username: Post1<br />
1 different passwords attempted with this guessed username: paul1234<br />
1 different passwords attempted with this guessed username: kevin<br />
1 different passwords attempted with this guessed username: pcadmin<br />
1 different passwords attempted with this guessed username: karen<br />
1 different passwords attempted with this guessed username: pdf<br />
1 different passwords attempted with this guessed username: posuser<br />
1 different passwords attempted with this guessed username: postmaster<br />
1 different passwords attempted with this guessed username: prepress<br />
1 different passwords attempted with this guessed username: program<br />
1 different passwords attempted with this guessed username: IUSR_SERVER<br />
1 different passwords attempted with this guessed username: jimmy<br />
1 different passwords attempted with this guessed username: Post3<br />
1 different passwords attempted with this guessed username: Post5<br />
1 different passwords attempted with this guessed username: poste2<br />
1 different passwords attempted with this guessed username: Post8<br />
1 different passwords attempted with this guessed username: paul<br />
1 different passwords attempted with this guessed username: myhost<br />
1 different passwords attempted with this guessed username: nasa<br />
1 different passwords attempted with this guessed username: love<br />
1 different passwords attempted with this guessed username: neil<br />
1 different passwords attempted with this guessed username: micros1<br />
1 different passwords attempted with this guessed username: michelle<br />
1 different passwords attempted with this guessed username: miguel<br />
1 different passwords attempted with this guessed username: marco<br />
1 different passwords attempted with this guessed username: mode<br />
1 different passwords attempted with this guessed username: parking<br />
1 different passwords attempted with this guessed username: ospite1234<br />
1 different passwords attempted with this guessed username: patrizia<br />
1 different passwords attempted with this guessed username: kubik<br />
1 different passwords attempted with this guessed username: patrizia2<br />
1 different passwords attempted with this guessed username: lorenzo<br />
1 different passwords attempted with this guessed username: netsis<br />
1 different passwords attempted with this guessed username: network<br />
1 different passwords attempted with this guessed username: orders<br />
1 different passwords attempted with this guessed username: new<br />
1 different passwords attempted with this guessed username: publish<br />
1 different passwords attempted with this guessed username: socket<br />
1 different passwords attempted with this guessed username: SmokinPremiums<br />
1 different passwords attempted with this guessed username: solaris<br />
1 different passwords attempted with this guessed username: documents<br />
1 different passwords attempted with this guessed username: domain<br />
1 different passwords attempted with this guessed username: scan123<br />
1 different passwords attempted with this guessed username: expn<br />
1 different passwords attempted with this guessed username: evan<br />
1 different passwords attempted with this guessed username: silver<br />
1 different passwords attempted with this guessed username: esmtp<br />
1 different passwords attempted with this guessed username: station4<br />
1 different passwords attempted with this guessed username: cscadmin<br />
1 different passwords attempted with this guessed username: sue<br />
1 different passwords attempted with this guessed username: supervisor<br />
1 different passwords attempted with this guessed username: contract<br />
1 different passwords attempted with this guessed username: spiceworks<br />
1 different passwords attempted with this guessed username: soss<br />
1 different passwords attempted with this guessed username: daniela<br />
1 different passwords attempted with this guessed username: csi<br />
1 different passwords attempted with this guessed username: SQLAgentCmdExec<br />
1 different passwords attempted with this guessed username: salesman<br />
1 different passwords attempted with this guessed username: reguser<br />
1 different passwords attempted with this guessed username: rcpt<br />
1 different passwords attempted with this guessed username: relay<br />
1 different passwords attempted with this guessed username: guard<br />
1 different passwords attempted with this guessed username: halt<br />
1 different passwords attempted with this guessed username: qwerty<br />
1 different passwords attempted with this guessed username: query<br />
1 different passwords attempted with this guessed username: rad<br />
1 different passwords attempted with this guessed username: radiant<br />
1 different passwords attempted with this guessed username: IME_ADMIN<br />
1 different passwords attempted with this guessed username: rupert<br />
1 different passwords attempted with this guessed username: fuji1<br />
1 different passwords attempted with this guessed username: FPUPDENGUSR<br />
1 different passwords attempted with this guessed username: fbi<br />
1 different passwords attempted with this guessed username: sales2<br />
1 different passwords attempted with this guessed username: report<br />
1 different passwords attempted with this guessed username: renteria<br />
1 different passwords attempted with this guessed username: good<br />
1 different passwords attempted with this guessed username: gans<br />
1 different passwords attempted with this guessed username: Richard</p>
<p>The post <a href="https://fosterinstitute.com/anatomy-of-a-password-attack-and-how-to-prevent-them/">Anatomy of a Password Attack, and How to Prevent Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tell People about Covering Cameras, and You Might Save a Life</title>
		<link>https://fosterinstitute.com/tell-people-about-covering-cameras-and-you-might-save-a-life/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 26 May 2022 21:33:27 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5249</guid>

					<description><![CDATA[<p>Have you ever noticed you are in a video conference call and did not realize your camera was capturing you? Or maybe you have two cameras, and your software unexpectedly selected the wrong one and broadcast an unflattering camera angle or showed something in the background you thought was out of frame? Embarrassing. Cover up [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/tell-people-about-covering-cameras-and-you-might-save-a-life/">Tell People about Covering Cameras, and You Might Save a Life</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Have you ever noticed you are in a video conference call and did not realize your camera was capturing you? Or maybe you have two cameras, and your software unexpectedly selected the wrong one and broadcast an unflattering camera angle or showed something in the background you thought was out of frame? Embarrassing. Cover up cameras when you aren&#8217;t using them.</p>
<p>A young adult received an extortion email claiming to have taken humiliating photos through his laptop&#8217;s webcam. The message threatened to send the images to friends and relatives and post them on social media. The youngster felt so distressed that he took his life. All people, including young people, need to know the risk, and please spread the word.</p>
<p>The letters are almost always fake. Executives call us after receiving similar messages. You will know the extortionist is bluffing if you keep your camera covered.</p>
<p>Even a non-technical person could spy on you through your computer, laptop, tablet, or phone, by running typical remote access applications or launching web meeting programs in the background without your knowledge. A bad actor could use advanced techniques to spy on you by remotely activating cameras, and they might disable the camera indicator light.</p>
<p>The most significant danger of covering your camera on a laptop is that if your cover is thicker than a piece of paper, your screen might crack if you stack something on top or compress the closed laptop. The thinner the camera cover, the better.</p>
<p>If you want to use the feature that adjusts the screen brightness based on the ambient light around you, consider using a translucent cover but be sure it blurs the image enough.</p>
<p>You can purchase re-usable peel-and-stick covers for cameras. Remember that sliding covers are risky for laptops and tablets that close. You could trim a part of a sticky note to be your cover for laptops and desktops. Avoid anything that will leave a sticky residue if you peel the tape off later.</p>
<p>If it is impractical to cover your device&#8217;s camera, at least check the privacy settings on your phone to control what apps can access your camera. A cover is more secure.</p>
<p>Remember to cover webcams built into some monitors, video game consoles, VR headsets, televisions, and other devices when you&#8217;re not using them.</p>
<p>If you have been thinking about covering your cameras, but have not gotten around to it yet, today might be your day. Please spread the word that the extortion letters are almost always fake, and covering a camera is a way to remove all doubt that an unauthorized person took pictures or recorded videos of them. Ensure that youngsters know too; you could save a life.</p>
<p>The post <a href="https://fosterinstitute.com/tell-people-about-covering-cameras-and-you-might-save-a-life/">Tell People about Covering Cameras, and You Might Save a Life</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Make Contingency Plans to Prepare for an Attack Against Critical Infrastructure</title>
		<link>https://fosterinstitute.com/make-contingency-plans-to-prepare-for-an-attack-against-critical-infrastructure/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 07 Apr 2022 22:03:56 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5227</guid>

					<description><![CDATA[<p>An executive asked for a short list of what they should be doing now to prepare for the unlikely event of a disruption to our critical infrastructure. Here are some basics: Make contingency plans for what you’ll do if the power goes out for an extended time. Consider how you’ll respond if you’re unable to [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/make-contingency-plans-to-prepare-for-an-attack-against-critical-infrastructure/">Make Contingency Plans to Prepare for an Attack Against Critical Infrastructure</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>An executive asked for a short list of what they should be doing now to prepare for the unlikely event of a disruption to our critical infrastructure. Here are some basics:</p>
<ul>
<li>Make contingency plans for what you’ll do if the power goes out for an extended time.</li>
<li>Consider how you’ll respond if you’re unable to use your online banking.</li>
<li>What is your plan if one of your vendors or SaaS providers shuts down for an extended period?</li>
<li>Make contingency plans in case your Internet Service Provider goes down.</li>
<li>What will you do if fuel becomes unavailable as it was to some regions after the Colonial Pipeline attack?</li>
<li>What if your shipping companies cannot deliver packages to you or your customers?</li>
<li>Should you take out enough cash to make payroll for your next pay cycle?</li>
</ul>
<p>Find cybersecurity specific recommendations here: <a href="https://fosterinstitute.com/10-things-every-organization-can-do-right-now-to-protect-themselves-from-state-sponsored-foreign-attacks/" target="_blank" rel="noopener">https://fosterinstitute.com/10-things-every-organization-can-do-right-now-to-protect-themselves-from-state-sponsored-foreign-attacks/</a></p>
<p>Here are tips to protect your and your worker’s families: <a href="https://fosterinstitute.com/family-disaster-preparedness-protect-your-loved-ones/" target="_blank" rel="noopener">https://fosterinstitute.com/family-disaster-preparedness-protect-your-loved-ones/</a></p>
<p>The post <a href="https://fosterinstitute.com/make-contingency-plans-to-prepare-for-an-attack-against-critical-infrastructure/">Make Contingency Plans to Prepare for an Attack Against Critical Infrastructure</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Watch for Threatening Email and Social Media Messages Saying You’re Hacked</title>
		<link>https://fosterinstitute.com/watch-for-threatening-email-messages-that-contain-your-actual-passwords/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 25 Mar 2022 09:58:00 +0000</pubDate>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2657</guid>

					<description><![CDATA[<p>Someone contacted me to explain that attackers hacked a family member&#8217;s Instagram account and threatened to expose some embarrassing photographs unless they paid the bad actor more than a thousand dollars. I told them: What he is experiencing is a common ploy. The bad actors probably didn’t hack his account, and I’m sure he reset [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/watch-for-threatening-email-messages-that-contain-your-actual-passwords/">Watch for Threatening Email and Social Media Messages Saying You’re Hacked</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Someone contacted me to explain that attackers hacked a family member&#8217;s Instagram account and threatened to expose some embarrassing photographs unless they paid the bad actor more than a thousand dollars. I told them:</p>
<p><span id="more-2657"></span>What he is experiencing is a common ploy. The bad actors probably didn’t hack his account, and I’m sure he reset his password just in case. The chances are that they don’t have any pictures. They certainly don’t have photos if whatever they claim happened didn’t happen.</p>
<p>The bullies are adept at social engineering, and their goal is to be terrifying. They’re incentivized because they make more money.</p>
<p>They commonly send information to make their messages look legitimate. They find passwords on the dark web and send those, where someone works, where they went to school, date of birth, and the names and ages of family members. That information is often easy to find, and bad actors having those details doesn’t mean they hacked an account. Often the entire information gathering process is automated. <a href="https://fosterinstitute.com/why-phishing-messages-contain-such-accurate-information/" target="_blank" rel="noopener">https://fosterinstitute.com/why-phishing-messages-contain-such-accurate-information/</a></p>
<p>The best thing is to avoid communicating with the bad actors and act like you never receive the messages. The bad actors will pick on someone else to try to get money from them.</p>
<p>I wouldn’t be surprised if he starts getting email messages from them.</p>
<p>Do this now: Be sure none of your email programs displays graphics or images when you open a message. On your iPhone or iPad, go to Settings &gt; Mail and turn off “Load Remote Images.” If you don&#8217;t see that option, look under Settings &gt; Mail &gt; Privacy Protection &gt; and choose &#8220;Block all Remote Content.&#8221; In Outlook, select File &gt; Options &gt; Trust Center &gt; Automatic Downloads and choose: Don&#8217;t download pictures automatically. Note that the setting can move around, but a quick search engine search for &#8220;how to block email tracking&#8221; and the name of your device or application will produce fast results. Take similar steps for every device you use to check your email. This step will usually prevent the attacker from knowing you opened the email message, but you must change the setting before receiving the message.</p>
<p>Cover up the cameras on your computers, tablets, and phones if you do not use the camera often.</p>
<p>If you do receive one of these messages, print it out and save it in case you need it for evidence in the future. Do not forward the message unless you are confident that the transmitted message contains no graphics.</p>
<p>It is up to you to decide if you want to warn family, friends, and everyone else in your address book in case the attacker follows through with their threat. Reassure your contacts that the contents of the message are false.</p>
<p>Make a detailed log, and make copies of all email messages, phone calls, and text messages you receive from them. Submit a complaint at <a href="http://ic3.gov" target="_blank" rel="noopener">ic3.gov</a>. Contact the police if you fear that your life is in danger. If the email message came from Gmail, notify Google, and they can investigate.</p>
<p>Visit <a href="http://www.haveibeenpwned.com" target="_blank" rel="noopener">www.haveibeenpwned.com</a> to see if there is evidence that your password has shown up posted on the dark web.</p>
<p>Reset sensitive passwords and enable two-step verification on websites where you log in. Be sure you are current on all security patches on your devices.</p>
<p>Please forward this to everyone you know so that they will prepare for threatening social media and email messages.</p>
<p>The post <a href="https://fosterinstitute.com/watch-for-threatening-email-messages-that-contain-your-actual-passwords/">Watch for Threatening Email and Social Media Messages Saying You’re Hacked</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>10 Things Every Organization Can Do Right Now to Protect Themselves from State-Sponsored Foreign Attacks!</title>
		<link>https://fosterinstitute.com/10-things-every-organization-can-do-right-now-to-protect-themselves-from-state-sponsored-foreign-attacks/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 24 Feb 2022 01:50:20 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Ransomware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5141</guid>

					<description><![CDATA[<p>Help protect your organization from attacks related to possible cyber-warfare. Ask your IT pros, in-house or outsourced, to: If your network firewall supports blocking data traffic by country, restrict all connections from all non-essential countries. You might need to allow traffic from specific addresses if one of your providers has a data center in another [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/10-things-every-organization-can-do-right-now-to-protect-themselves-from-state-sponsored-foreign-attacks/">10 Things Every Organization Can Do Right Now to Protect Themselves from State-Sponsored Foreign Attacks!</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Help protect your organization from attacks related to possible cyber-warfare. Ask your IT pros, in-house or outsourced, to:</p>



<ul class="wp-block-list"><li>If your network firewall supports blocking data traffic by country, restrict all connections from all non-essential countries. You might need to allow traffic from specific addresses if one of your providers has a data center in another country.</li><li>If you use Office 365, configure Conditional Access by Country to only accept users logging in from countries where your users will be when they access Office 365. You might need to upgrade your O365 license to enable conditional access by country.</li><li>Configure firewalls on your websites and web applications to only accept connections from countries where you do business. Before limiting countries, ask your web developers if they use tools hosted in other countries. You’ll need to allow connections from those specific companies; else, your web application might malfunction.</li><li>Block your users, in case they get fooled by a fraudulent email message, from accessing websites in countries and categories except those essential for business. When you configure web content filtering, you might be surprised to find out that some of the sites you use must connect to other countries to work correctly. Your team can allow those specific sites without enabling the entire country. Be careful not to overload your IT team with this recommendation.</li><li>If you haven&#8217;t already, be sure to implement multi-factor authentication for your VPN, Microsoft Office 365, your privileged user accounts, social media accounts including LinkedIn, and anywhere attackers could inflict damage if they gain access.</li><li>Shut down any unnecessarily exposed ports on your firewall, including remote management. If you must leave ports open, filter by the source address to prevent connections from anywhere except authorized static addresses.</li><li>Configure your spam filter to block email messages from all countries except for those from which you wish to receive messages.</li><li>Implement the email protection features SPF, DKIM, and DMARC to help block fraudulent emails and messages that someone tampered with. There are services to help IT departments accomplish this.</li><li>Discuss Distributed Denial of Service (DDOS) attacks with your Internet provider and web hosting companies and ways they can protect you in case an attacker floods your network, your phone systems, or your websites with so much traffic that it shuts down your systems.</li><li>Uninstall all the programs you do not use. If foreign attackers take over a software company, as they have recently, you won&#8217;t be affected if those programs are not installed.</li></ul>



<p class="wp-block-paragraph">All of these are in addition to the other protections you should already have, including double-checking that all the critical security updates from Microsoft and your browsers are installed on all of your systems, using anti-virus and Endpoint Detection and Response tools, making sure no users are local administrators to make it difficult for attackers to install malware on their computers, using application control, and other recommendations you read in these blogs.</p>



<p class="wp-block-paragraph">Alert your users to the heightened threat and tell them to be wary of fake news. Remind them never to enter their usernames and passwords when prompted, no matter how convincing a site appears. If they read something that seems scary and instructs them to do something urgently, they must pause before acting. They should ask the IT department if they have the slightest suspicion. If they spot something fraudulent, you might tell them to send an alert to your other users to know the message is fake. They should remove links before they forward the message.</p>



<p class="wp-block-paragraph">If you have an on-prem Exchange server, attackers will target the server relentlessly. Immediately ensure the Exchange server is patched with all critical updates. Be sure your firewall is configured to block all traffic except specific IP addresses. Talk to your executives about fast-tracking your migration to hosted Exchange if migration is possible.</p>



<p class="wp-block-paragraph">While the following won&#8217;t prevent an attack, you want to be prepared:</p>



<ul class="wp-block-list"><li>Confirm that the backups of your cloud data function correctly in case attackers delete your Office 365 or other cloud data and render the cloud provider&#8217;s backups useless.</li><li>After ransomware attacks, many organizations&#8217; executives are shocked at how long it takes to restore. Be sure your whole disaster recovery process is quick enough to meet your return to operations (RTO) requirements. You might prioritize which services need to be running soonest and make recovery point objectives (RPOs). Practice restoring and measure the time it takes to restore and recover.</li></ul>



<p class="wp-block-paragraph">Make contingency plans for what you’ll do if the power goes out for an extended time. Consider how you’ll respond if you’re unable to use your online banking. What is your plan if one of your vendors or SaaS providers shuts down for an extended period? Make contingency plans in case your Internet Service Provider goes down. What will you do if fuel becomes unavailable as it was to some regions after the Colonial Pipeline attack? What if your shipping companies cannot deliver packages to you or your customers? Should you take out enough cash to make payroll for your next pay cycle? Planning for these and other risks will allow you to have systems in place in the unlikely event they occur.</p>



<p class="wp-block-paragraph">You can find additional guidance at <a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-011a" target="_blank" rel="noreferrer noopener">https://www.cisa.gov/uscert/ncas/alerts/aa22-011a</a></p>
<p>The post <a href="https://fosterinstitute.com/10-things-every-organization-can-do-right-now-to-protect-themselves-from-state-sponsored-foreign-attacks/">10 Things Every Organization Can Do Right Now to Protect Themselves from State-Sponsored Foreign Attacks!</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
