<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/malware/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Thu, 16 Jan 2025 19:17:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Malware Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/malware/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Mac Users &#8211; Urgent Security Alert: Protecting Your Mac from Banshee Stealer Malware</title>
		<link>https://fosterinstitute.com/mac-users-urgent-security-alert-protecting-your-mac-from-banshee-stealer-malware/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sat, 11 Jan 2025 23:29:10 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Apple Virus]]></category>
		<category><![CDATA[Mac Protection]]></category>
		<category><![CDATA[Mac Virus]]></category>
		<category><![CDATA[Malware]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5972</guid>

					<description><![CDATA[<p>Mac Users – Beware of Current Malware There is a virus for Mac named Banshee Stealer that is potentially affecting millions of Mac users. IMMEDIATE ACTIONS REQUIRED: &#8211; Never enter your Mac user or admin password unless you recognize the need to enter it because of an action you’re performing, such as powering on your [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/mac-users-urgent-security-alert-protecting-your-mac-from-banshee-stealer-malware/">Mac Users &#8211; Urgent Security Alert: Protecting Your Mac from Banshee Stealer Malware</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Mac Users – Beware of Current Malware</strong></p>
<p>There is a virus for Mac named Banshee Stealer that is potentially affecting millions of Mac users.</p>
<p><strong>IMMEDIATE ACTIONS REQUIRED:</strong></p>
<p><strong>&#8211; Never enter your Mac user or admin password unless you recognize the need to enter it because of an action you’re performing, such as powering on your Mac.</strong></p>
<p><strong>&#8211; Back up your critical data immediately in case you need to perform a clean MacOS install</strong></p>
<p><strong>&#8211; Because Banshee Stealer is unnoticeable, strongly consider running an anti-malware tool capable of detecting it.</strong></p>
<p><strong>What Anti-Malware Tools Work? </strong></p>
<p>Intego, Malwarebytes, and Combo Cleaner are the only Mac-based anti-malware tools that I can find today that advertise that they can identify and stop the newest version of Banshee Stealer. There might be others. Combo Cleaner is available in the Mac App Store. Downloading apps from the store reduces the likelihood of getting a fake infected version. We don’t endorse any of the tools mentioned, nor do we receive any compensation. There are many online reviews about those two products. Stay current with your Mac OS updates, and hopefully, Apple’s built-in tools will soon detect and conquer the newest version of Banshee Stealer.</p>
<p>I realize many Mac users do not want to install anti-malware. If that’s you, please carefully understand all the information in this article to reduce your exposure. The newest variant of Banshee Stealer cleverly evades Apple’s built-in anti-malware tool, XProtect.</p>
<p><strong>What is Banshee Stealer?</strong></p>
<p>The sophisticated Banshee Stealer malware compromises computers and laptops running MacOS, including Intel-based Macs and those with Apple Silicon chips. Attackers use it to breach privacy, inflict financial losses, and steal identities. So far, iPhones and iPads have not been affected by Banshee Stealer. In my presentations and speeches, participants often ask if Macs are susceptible to viruses and other malware; this is an example of when they are.</p>
<p>Banshee Stealer is a new variant; it started as Malware-as-a-Service (MaaS). Threat actors could purchase access for $3,000 per month to attack Mac users. The new variant resurfaced in September, using encryption from Apple&#8217;s XProtect anti-virus tool, evading antivirus detection for months.</p>
<p><strong>How Can Your Computer Become Infected with Banshee Stealer?</strong></p>
<ul>
<li>If you click on links in email messages that take you to a site that might appear normal but will infect your computer with Banshee Stealer</li>
<li>If you open attachments to email messages that contain the Banshee Stealer malware or take you to a site that downloads and installs Banshee Stealer</li>
<li>Scanning QR codes in email mail or other messages for the same reason</li>
<li>If you enter your username and password into what appears to be a legitimate Apple pop-up</li>
<li>Downloading programs and applications that have Banshee Stealer hidden inside</li>
<li>If you follow a fake prompt that tells you an update or program needs to be installed, a password needs to be reset, or some application asks to use your camera or microphone or have some other elevated privilege.</li>
</ul>
<p><strong>Symptoms:</strong></p>
<p>Banshee Stealer is designed to be undetectable. You might not find out your Mac was infected until your finances, identity, and privacy are in shambles. Possible symptoms include:</p>
<ul>
<li>Your Mac computer or laptop starts behaving differently than before.</li>
<li>You might receive unexpected prompts asking you to install software, reset your password, grant permission, etc.</li>
<li>If you notice that your bank or other online accounts have been compromised, an attacker may have used Banshee Stealer to steal your passwords.</li>
<li>If your Mac starts operating much slower than before, or if the battery life seems shorter, Banshee Stealer might upload data in the background or perform other activities on your computer.</li>
<li>If you notice unexpected file changes on your computer</li>
<li>If you have a Crypto Wallet that gets compromised.</li>
</ul>
<p><strong>What to Do to Help Prevent Infection:</strong></p>
<p>Strongly consider using anti-malware capable of detecting Banshee Stealer, as discussed above.</p>
<p>Beware of all prompts that pop up on your screen that look like they are Apple prompts asking for your password. Banshee Stealer is great at mimicking the Apple prompts, and if you enter your username and password, Banshee Stealer captures them. It is essential that you only enter your username and password when you are actively expecting to need to, such as:</p>
<ul>
<li>When you power on the computer or when you log in after the screen is locked</li>
<li>When you are installing new software right then</li>
<li>When you are logging into Keychain</li>
<li>When you told the Mac to install system updates</li>
<li>Administrative tasks like when you are intentionally accessing system files</li>
<li>And some of the changes to system preferences you’re making right then.</li>
</ul>
<p>Only install programs and applications from trusted companies. Remember that attackers can sometimes infect trusted companies and install malware without the software provider&#8217;s knowledge. This is called a supply chain attack, and it can be very successful if people trust the website or tool. Getting programs from the Mac App Store helps minimize the risk of downloading malware hidden inside an otherwise functional program.</p>
<p>Do not double-click on a link or button on a website. Legitimate website navigation involves single-clicks. Threat actors have determined that people will follow instructions to double-click or double-click if something does not seem work the first time. During a double-click process, attackers will quickly replace the original link with a malicious one right after the first click before the second. Users do not realize what they&#8217;ve done and might have executed a script or unknowingly performed another task the threat actor wanted.</p>
<p>Do not click on links in email messages or other messages, and do not scan a QR code—it functions as a link. Do not click on links on services such as YouTube; threat actors will put links into the descriptions and comments. View every link everywhere as suspicious and avoid clicking.</p>
<p>Do not open attachments that arrive via email or another method unless you confirm with the sender that it is indeed the file they sent. Remember that attackers can compromise other companies or users and use their email addresses to send malicious files when you expect them. This is a way for even the most security-conscious people to be infected.</p>
<p>Update your MacOS regularly. Instead of answering a prompt on your screen telling you about an update, regularly click on the apple in the top left corner and choose System Settings, General, then Software Update.</p>
<p>Consider removing as many browser extensions as possible. Sometimes malware infects browser extensions or comes included when you install an extension.</p>
<p>Use multi-factor authentication (MFA) on all the websites, Software as a Service (SaaS) solutions, and everywhere else you can. Choosing to receive a text message for the second step of the login process is much better than having no MFA, but it is not the most secure choice due to the SIM-Swapping attackers use. They learn as much as they can about you, frequently using AI, and contact your phone provider and try to convince your provider that they are you and that you have a new SIM chip or a new phone. Recent breaches have exposed your location history gathered by companies who write apps and sell your location information. Threat Actors can use AI to combine location information with publicly available data to learn much about you and your life. If the phone provider is duped, they’ll successfully take over your account and be able to receive the text messages on their device. If you ever change your phone number, you&#8217;ll need to go to all the websites where you set up text-based MFA, disable MFA, and re-enable MFA when you get the new number.</p>
<p>For more secure multi-factor authentication, if the website or SaaS tool allows, set up an authenticator app on your smartphone that generates a number every thirty seconds. This Time-Based One-Time Password (TOTP) is more secure because it doesn&#8217;t rely on a text message. Popular authenticators include Google Authenticator, Microsoft Authenticator, Authy, and more. (Same disclaimers as above). Be sure to back up your authenticator app in case you lose or upgrade your phone. Otherwise, you could be locked out of everything you set up for TOTP. If you can’t generate the codes, you won’t be able to log in to the sites that require that code. There are other options that are more secure than text message-based MFA, including USB Keys, Passkeys, etc.</p>
<p>Be sure you use different passwords for every website or SaaS offering. When attackers compromise your password anywhere, they’ll perform credential stuffing, meaning they try the same username and password at dozens of other popular websites and SaaS platforms. It is challenging to remember passwords, and password manager software can be very helpful. Password managers remember your passwords for you and can fill them in when prompted. Although web browsers have this feature, too, many people consider password managers more secure since, if an attacker compromises your browser, the passwords are not readily available to them. Some password managers will synchronize across multiple devices, reset weak passwords for you, and offer other features. It is almost always best not to use the VPN and other services that come with password managers. 1Password, DashLane, Keeper, LastPass, and many others are common. (Same disclaimers about not endorsing these nor do we get compensation). And Apple has revamped the MacOS Keychain password manager to be more secure than it was. When you use a password manager, be sure it is backing up somewhere in case you lose your laptop. Apple Keychain automatically backs up to iCloud and synchronizes across your other devices.</p>
<p>If you have sensitive data, consider encrypting the files in case Banshee Stealer or other malware accesses and steals them.</p>
<p>Computers and devices communicate through a network, copper or WiFi. Malware can move from one computer to another. If you use your Mac at home and family members have Macs who aren’t as careful as you are, having a segmented network for you to use, separate from everyone else, helps protect you from malware spreading from their computers onto yours. Segmentation is slightly technical, and the easiest way to segment a home network might be to have all the other family members connect to the “guest” network and use the primary network.</p>
<p>Set up text messages for all financial transactions. Most financial institutions offer SMS or email alerts whenever transactions larger than a certain amount are processed. I have my accounts set to text me anytime a transaction of more than one dollar occurs on any account because that is the minimum amount my banks allow. Yes, I receive many alerts, but I’d prefer to receive many alerts than not knowing about an unauthorized withdrawal. Continue to monitor bank statements and other financial records.</p>
<p>If your company has an Extended Detection and Response (XDR) solution, contact your IT professionals to be sure they&#8217;ve installed the XDR agent on your Mac, too. If your business isn&#8217;t already using XDR, you must. This technology is designed to detect and stop malicious activity before it has time to do much, if any, harm. Examples of XDR tools include Crowd Strike, Cynet, Sentinel One, and more (we don&#8217;t endorse nor receive compensation for mentioning them).  As cybersecurity consultants, we recommend that our customers get XDR from their IT Team&#8217;s vendor. The typical approximately $20/mo/user seems expensive until after a breach. Many companies get breached even though they have XDR in place, but the most common reason is that something wasn&#8217;t implemented correctly or there is a breakdown or delay in communications. Companies engage with us to perform independent periodic vigorous red team exercises to attack and test their XDR response. Most XDR implementations fail the first exercise, but finding weaknesses before the threat actors do is the point. After the exercise and forthcoming recommendations are implemented, a company is much more prepared for a real-world attack.</p>
<p>This recommendation isn’t for everyone; I left it for last. Implementing this can be complicated and frustrating and is most often initiated by enterprises using Windows and Mac. Another strategy to help avoid getting malware from websites is to use a hosted browser, also known as browser isolation. This service runs a web browser on their servers, and your computer shows you their browser. Thus, all browser attacks will attack the company hosting the browser, not your computer’s browser. Sometimes, hosted browsers work better than others, but you might consider this option to further isolate and protect your computer from browser-based threats. For example, if a website wants to access your local mic and camera, it won’t work since you’ll be using the hosted browser. But this protects you from malicious websites that take over your mic and camera. My research to locate a hosted browser for the Mac was complex, and I want to rush this blog to the press due to the urgency of Banshee Stealer. Candidates for stand-alone hosted browser solutions for the Mac include Menlo Secure Cloud Browser, Authentic8, and the Puffin Browser. Zscaler and Cloudflare also offer hosted browser solutions for the Mac, but they don’t seem to be sold as a stand-alone solution but as part of a larger package. We are not endorsing or receiving any compensation for listing those products.</p>
<p><strong>Proactive Steps to Take In Case You Get Infected:</strong></p>
<p>There are other steps to take that will help you if you do get infected. Be sure you are backing up with Mac OS’s built-in Time Machine or another service. Using multiple external USB drives for backup and rotating them is a great idea. Mac OS will keep track of each drive and apply the backups when you plug in the specific drive. Strongly consider an online backup service. Examples of highly rated cloud backup services for Mac users include BackBlaze, iDrive, and Acronis, but there are others. We are not endorsing those, nor do we receive any compensation for recommending them. You might even copy your files to an online storage service; use multi-factor authentication and all the other industry-best cybersecurity practices for cloud storage. Some people copy their most important files to one or more external drives, leaving them disconnected except when copying files.</p>
<p><strong>What to do if you think you are infected:</strong></p>
<p>Turn off your Wi-Fi or disconnect your Ethernet cable to stop any more files from being stolen and uploaded.</p>
<p>Run an anti-malware package described above under prevention.</p>
<p>Continue to watch your financial accounts for any suspicious activity.</p>
<p>Follow all the steps above under the section on what to do to avoid infection.</p>
<p>Consider moving your assets to a new, secure wallet if you use cryptocurrency.</p>
<p>You should contact gurus at Apple or another support organization who can help you with your Mac.</p>
<p>Reset all of your passwords. If you are not using a password manager, now might be a good time to do so.</p>
<p>Decide whether to alert your business and associates that if they receive an email pretending to be from you, it is likely not from you.</p>
<p>If you want to feel confident you’ve removed all of the malware, consider backing up your data and performing a clean install of macOS.</p>
<p><strong>Final Thoughts:</strong></p>
<p>I hope you do not become infected with Banshee Stealer and are not already infected, which is tricky to detect. Following the guidance in this article can also help protect you from other Mac malware. Tell your friends.</p>
<p>&nbsp;</p>
<p>The post <a href="https://fosterinstitute.com/mac-users-urgent-security-alert-protecting-your-mac-from-banshee-stealer-malware/">Mac Users &#8211; Urgent Security Alert: Protecting Your Mac from Banshee Stealer Malware</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Protecting Your Financial Interests in the Wake of a Major Data Breach</title>
		<link>https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Sun, 21 Apr 2024 13:33:01 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Anti-virus]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Credit Freeze]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Fraud]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Restoration]]></category>
		<category><![CDATA[Family Security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[Malicious Advertising]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Restoring]]></category>
		<category><![CDATA[Security Breach]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5779</guid>

					<description><![CDATA[<p>In today&#8217;s digital age, the security of your personal information is more than a convenience &#8211; it&#8217;s a crucial aspect of your financial strategy. Recently, a significant breach at a major phone provider has put the personal data of 73 million individuals at risk, including high-net-worth individuals like yourself. This exposed data includes not only [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/">Protecting Your Financial Interests in the Wake of a Major Data Breach</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In today&#8217;s digital age, the security of your personal information is more than a convenience &#8211; it&#8217;s a crucial aspect of your financial strategy. Recently, a significant breach at a major phone provider has put the personal data of 73 million individuals at risk, including high-net-worth individuals like yourself. This exposed data includes not only names and contact details but also sensitive information such as social security numbers, dates of birth, and account credentials. The potential financial repercussions are substantial, making it imperative to take action to safeguard your assets. Follow these guidelines to mitigate risks and ensure your financial security remains uncompromised.</p>
<h3>Credit Freeze</h3>
<p>If you haven’t already, consider freezing your credit to prevent new credit accounts from being opened in your name without your permission. Here are in-depth instructions and details: <a href="https://fosterinstitute.com/help-protect-your-financial-future-freeze-your-credit/" target="_blank" rel="noopener">Help Protect Your Financial Future: Freeze Your Credit &#8211; Foster Institute</a></p>
<h3>Monitor Financial Accounts</h3>
<p>Keep a close watch on your financial accounts for any unauthorized activity or transactions. Consider subscribing to an identity theft protection service, which can help monitor your information and alert you to potential misuse of your personal data. If you didn’t place the credit freeze mentioned above, doing so is essential.</p>
<h3>Beware of Fraud and Scams</h3>
<p>Beware of email, text, phone calls, or messages popping up on your computer that claim you are hacked and offer tech support help. Familiarize yourself and your family with the latest fraud techniques. Be skeptical of emails, phone calls, or messages that request personal information or direct you to websites asking for personal or financial data.</p>
<h3>Be Cautious with Search Engine Results that are Ads</h3>
<p>Threat actors can purchase ads so that, if you search for keywords such as &#8216;My phone provider database was hacked,&#8217; the ad, disguised as a helpful search result, will appear at the top. This can lead you to a page designed to defraud you or compromise your computer</p>
<p>To help protect yourself, when you search, scroll down and click on the organic search results rather than the ads. You are more likely to access safer websites.</p>
<p>Malicious advertising is not limited to search engines. Advertisements on websites can be just as dangerous. These attacks are called malvertising and trick millions of users each year.</p>
<h3>Change Passwords Immediately</h3>
<p>If you haven’t recently, change passwords for all your accounts including phone provider, social media, banking, and other sensitive accounts, especially if you’ve used the same password for multiple accounts.</p>
<h3>Use a Password Manager</h3>
<p>Consider using a password manager to manage your unique passwords on every website. Detailed information about using password managers: <a href="https://fosterinstitute.com/password-managers-speed-your-workflow/" target="_blank" rel="noopener">Password Managers Speed Your Workflow &#8211; Foster Institute</a></p>
<h3>Set Up Unique Security Questions</h3>
<p>When setting up security questions, avoid real answers that are easy for a bad actor to research. Instead, use fictional answers like, “The fourth crater on the moon.” Save your secret answers in a randomly named file such as “socks.docx,” and consider encrypting this file for added safety.</p>
<h3>Enable Two-Step Verification</h3>
<p>Enable two-step verification for accounts. Prioritize setting this up on sensitive websites and services where it&#8217;s available.</p>
<h3>Update Operating Systems and Software</h3>
<p>Ensure that all your devices have the latest security software, web browsers, and operating systems updates and patches. This is one of the best defenses against viruses, malware, and other online threats.</p>
<h3>Secure Your Tax Identity with an ID.me Account</h3>
<p>Given that social security numbers were compromised, there&#8217;s an elevated risk of someone attempting to file a fraudulent federal tax return in your name. To combat this, consider registering for an ID.me account which provides access to IRS services. With this account, you can also apply for an IRS Identity Protection PIN (IP PIN) that adds an extra layer of security to your tax filings by requiring this unique six-digit number on your tax return.</p>
<h3>Protect Your Property Records</h3>
<p>With personal details like your SSN in the wrong hands, even your home ownership documents could be targeted. It&#8217;s advisable to monitor and possibly register your property deeds with services that alert you to any unauthorized filings or changes. While a universal solution for this isn&#8217;t available yet, taking initial steps such as contacting your local county clerk&#8217;s office to inquire about protective measures can be beneficial.</p>
<h3>Awareness for Business Impact</h3>
<p>Businesses, particularly those utilizing services from the breached provider, should be acutely aware of the implications this breach can have on their operations. It&#8217;s crucial for business owners to assess their exposure and strengthen their internal security measures, including employee training on data privacy and regular security audits to prevent further damage.</p>
<h3>Register for Online Tax Accounts in All States</h3>
<p>To prevent the misuse of your personal information for fraudulent state tax filings, consider registering for an online tax account in each of the 50 states. This pre-emptive registration can block identity thieves from creating accounts in your name, a tactic increasingly used to commit tax fraud across state lines.</p>
<h3>Digital Footprint and Data Sharing</h3>
<p>Be vigilant about the information you share online and through mobile applications. It&#8217;s crucial to minimize data sharing and scrutinize the permissions you grant to apps, especially those that request access to sensitive personal information. Educate yourself and limit exposures to safeguard against unauthorized data usage. The less information threat actors can gather about you, the more difficult it will be for them to misuse your identity.</p>
<h3>Review and Update Privacy Settings</h3>
<p>Regularly review and update your privacy settings on social media and other online platforms to ensure minimal public exposure of personal information. This proactive measure can significantly deter fraudsters from using accessible data to facilitate identity theft or scams.</p>
<h3>Legal and Financial Consultation</h3>
<p>Consult with legal and financial advisors to explore additional protective measures tailored to your personal or business circumstances. Discuss setting up legal structures such as trusts to shield assets, or other strategies that may offer enhanced security against identity theft and financial fraud.</p>
<h3>Emergency Contacts and Protocols</h3>
<p>Prepare an emergency contact list and establish protocols for immediate action if you suspect identity theft or if a data breach occurs. Include the contact information for essential services such as credit bureaus, your bank, and legal advisers, to ensure a swift and organized response to security threats.</p>
<p>Forward this message to your friends so they can follow these steps can help mitigate the damage from the breach and protect their personal information.</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6>Disclaimer: The information provided in this blog is for general informational purposes only. Technology changes constantly, and some of this information might become obsolete or incorrect. We do not endorse or receive compensation for mentioning products, services, or brand names. Any outbound links provided are for your convenience and to get you started, but we cannot guarantee the security or safety of those external websites. Conducting your research and making an informed decision about any products or services mentioned here is essential. We shall not be held responsible for any actions taken based on the information provided.</h6>
<p>The post <a href="https://fosterinstitute.com/protecting-your-financial-interests-in-the-wake-of-a-major-data-breach/">Protecting Your Financial Interests in the Wake of a Major Data Breach</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Leadership in the Line of Fire: Cleanup or Clean Slate?</title>
		<link>https://fosterinstitute.com/cleanup-or-clean-slate/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 12 Apr 2024 23:01:04 +0000</pubDate>
				<category><![CDATA[Anti-virus]]></category>
		<category><![CDATA[Backup]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Attacks]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Restoration]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Restoring]]></category>
		<category><![CDATA[Security Breach]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/?p=5768</guid>

					<description><![CDATA[<p>The post <a href="https://fosterinstitute.com/cleanup-or-clean-slate/">Leadership in the Line of Fire: Cleanup or Clean Slate?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>The debate between cleaning up an infected computer using security tools versus wiping the system and reinstalling everything from scratch is a longstanding one in the field of cybersecurity. Both approaches have their pros and cons, and the best choice often depends on the specific circumstances and the security policies of the organization. Here&#8217;s a breakdown of each approach:</p>
<h3>Cleaning Up with Security Tools (e.g., Antivirus, EDR, XDR)</h3>
<p><strong>Pros:</strong><br />
&#8211; Faster and more convenient: Cleaning a system with antivirus or EDR/XDR tools is usually quicker than a full reinstall. It allows users to return to work with minimal downtime.<br />
&#8211; Data preservation: This method reduces the risk of losing unsaved data or settings that may not be backed up, though it&#8217;s not foolproof.<br />
&#8211; Immediate response: These tools&#8217; immediate response capabilities help contain and control the spread of malware quickly, reducing further damage.</p>
<p><strong>Cons:</strong><br />
&#8211; Risk of incomplete removal: Some sophisticated malware can hide or embed itself into system files in ways that are difficult for security tools to detect and remove completely.<br />
&#8211; System integrity concern: Even after malware is removed, system settings might be altered in ways that leave vulnerabilities or stability issues. This can compromise the system&#8217;s overall security and functionality, potentially making it less reliable.<br />
&#8211; Potential for reinfection: If the root cause or entry point of the infection isn&#8217;t identified and secured, the system might be reinfected.</p>
<h3>Wiping and Reinstalling</h3>
<p><strong>Pros:</strong><br />
&#8211; System integrity: This approach helps ensure that any malware, including that which might have evaded detection, is completely removed from the system.<br />
&#8211; Clean slate: Reinstalling the operating system and applications can resolve any issues related to software corruption and remove unwanted configurations left by the malware.<br />
&#8211; Opportunity to update and improve: It&#8217;s a good chance to update systems to the latest OS version, apply security patches, and improve configurations for better security.</p>
<p><strong>Cons:</strong><br />
&#8211; Time-consuming: The process can be lengthy, especially if data backup and restoration are involved.<br />
&#8211; Potential data loss: If backups are not recent or complete, there could be a loss of data.<br />
&#8211; Productivity impact: The downtime required to wipe and reinstall a system can impact the user&#8217;s productivity.</p>
<h3>Best Practice Recommendations</h3>
<p>Wiping the system and reinstalling the OS and applications provides more peace of mind that you&#8217;ve removed malware known for its persistence and capability to evade detection. This is essential in high-security environments.</p>
<p>For many organizations, the decision might be based on a risk assessment that considers the nature of the data on the machine, the type of malware, and the criticality of the systems involved. In environments where security is paramount or where compliance requirements dictate stringent responses to security incidents, wiping and reinstalling is often the safer, though more resource-intensive, choice.</p>
<h3>Be Ready to Reinstall</h3>
<p><strong>&#8211; Spare Computers:</strong> Keep spare, ready-to-use, prepared workstations to swap out with a user&#8217;s infected computer so the user doesn&#8217;t lose productivity while your IT team rebuilds their infected machine to become a new, clean spare.<br />
<strong>&#8211; Store Data Elsewhere:</strong> If data files are stored somewhere outside the computer, there&#8217;s no need to back up local data files before erasing the hard drive. If your company has workers who use their laptops offline while traveling, they most likely will have data stored locally. Hopefully, you already have a plan in place to back up their data regularly.<br />
<strong>&#8211; Speedy Reloading:</strong> Use automated installation techniques, such as OS distribution tools or image deployment solutions, to expedite the reloading process and minimize downtime.</p>
<h3>Conclusion</h3>
<p>The uncomfortable reality is that threat actors own all of the tools designed to remove malware from a computer and practice designing their malware to be resilient to the cleaning process. Forgo cleaning tools and completely erase the computer, then reload from scratch to help ensure a higher likelihood that the infection is fully eradicated.</p>
<p><strong>Subscribe</strong> to maximize your executive potential with Foster Institute’s E-Savvy Newsletter, packed with practical IT security solutions and actionable strategies for success: <a href="https://fosterinstitute.com/e-savvy-newsletter/">https://fosterinstitute.com/e-savvy-newsletter/</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h6>Disclaimer: The information provided in this blog is for general informational purposes only. Technology changes constantly, and some of this information might become obsolete or incorrect. We do not endorse or receive compensation for mentioning products, services, or brand names. Any outbound links provided are for your convenience and to get you started, but we cannot guarantee the security or safety of those external websites. Conducting your research and making an informed decision about any products or services mentioned here is essential. We shall not be held responsible for any actions taken based on the information provided.</h6></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p>The post <a href="https://fosterinstitute.com/cleanup-or-clean-slate/">Leadership in the Line of Fire: Cleanup or Clean Slate?</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Patching – 10 Steps to Seal the Holes in Your Armor</title>
		<link>https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 15 May 2017 15:42:19 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[browser security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Patch Updates]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[applying patches]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[ipad security]]></category>
		<category><![CDATA[iphone Security]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Microsoft patch]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[patch deployment]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[updating patches]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2482</guid>

					<description><![CDATA[<p>You’ve likely heard of the massive ransomware attack that has taken down so many organizations, including hospitals, around the world. The ransomware appears to have exploited a bug for which Microsoft released a fix a little over a month ago. Follow these 10 steps to help protect your organization from this, and from future attacks: [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/">Patching – 10 Steps to Seal the Holes in Your Armor</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You’ve likely heard of the massive ransomware attack that has taken down so many organizations, including hospitals, around the world. The ransomware appears to have exploited a bug for which Microsoft released a fix a little over a month ago. Follow these 10 steps to help protect your organization from this, and from future attacks:<span id="more-2482"></span></p>
<p>Instructions for Windows and Apple home users are listed below the numbers. For organizations, here are 10 Steps To Avoid Incidents Including the Massive Ransomware Attack:</p>
<p>1. The reality is that most organizations are missing critical security patches and there is a very strong likelihood that yours is too.</p>
<p>2. Provide your team with extra time, and perhaps additional personnel, to test and then deploy patches ASAP. Some organizations are adding a new IT professional to their team whose sole responsibility is to manage patches. If the patch fails testing, then time must be invested to resolve the issue or implement compensating controls.</p>
<p>3. Prioritize critical security patches for the operating system, all the browsers, Flash, Java, your PDF Reader, and Microsoft Office. They are usually the easiest to attack and form your first line of defense.</p>
<p>4. Many IT teams are very reluctant to apply patches for fear of breaking your systems that are already running. Help remove their fears by reassuring them that you take on responsibility if the patch causes a problem. Encourage them to follow a procedure that mitigates risks:</p>
<p>5. Test Patches in a test environment that uses the same applications as the rest of your network. For very small companies, your test environment might be a single computer. For larger organizations, and organizations that stand to lose a great deal in the event of an attack, create a separate testing environment that is isolated from the production environment.</p>
<p>6. Have a pre-tested rollback plan so that, if the patch does cause a problem, your IT team will already know what they need to do right away to roll back a patch that causes an unexpected problem. They will then go back to the testing phase.</p>
<p>7. Deploy the patches in stages rather than patching all machines simultaneously. That way, even if the patch does cause a problem, not all your machines will be affected.</p>
<p>8. You may decide to empower your IT team with a patch management tool such as Ninite, LANGuard, Shavlik, or others. Allow them to test and choose a tool, and provide them with the means and time to do so, ASAP.</p>
<p>9. Ask IT, perhaps weekly and at least monthly, to provide you with a list of missing patches, not a pie chart.</p>
<p>10. You must upgrade from older operating systems, any of the ones that Microsoft no longer supports. If some machines cannot be upgraded, then they must be isolated or some other compensating control put into place. Microsoft clearly states when they stop producing patches for old operating systems.  So, there was no patch available for Windows XP and others.</p>
<p>Call me if they are not able to apply patches. Let’s team up to help prevent this.</p>
<p>At home, or if your organization is so small that you do not have an IT team or have an outsourced IT company that takes care of your patches, be sure that the option that provides automatic updates to Microsoft is enabled. The instructions are easy to find – just google the phrase: configure automatic updates site:Microsoft.com</p>
<p>Apple computer users, google: Automatic security updates os x site:apple.com</p>
<p>iPhone and iPad users, google: Automatic security downloads ios site:apple.com</p>
<p>Additionally, manually check for updates in Microsoft Office to be sure those are applied. Be sure that automatic updates are enabled in your browsers. Regularly download and apply patches to, or new versions of, Flash, Java, and your PDF reader.</p>
<p>Please forward this to everyone you care about and want to help stay secure.</p>
<p>The post <a href="https://fosterinstitute.com/patching-10-steps-to-seal-the-holes-in-your-armor/">Patching – 10 Steps to Seal the Holes in Your Armor</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>E-Mail Protection Solution</title>
		<link>https://fosterinstitute.com/e-mail-protection-solution/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 16 Mar 2017 21:18:29 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Scams]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Mimecast]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Targeted Threat Protection]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Wire Transfer Fraud]]></category>
		<category><![CDATA[Bad Attachment]]></category>
		<category><![CDATA[Computer Virus]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[email insurance]]></category>
		<category><![CDATA[Email Protection]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Infected files]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[IT Virus]]></category>
		<category><![CDATA[malicious file]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Transfer Money Scams]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2442</guid>

					<description><![CDATA[<p>Everyone is concerned about the danger of a user clicking on a link in an email message, perhaps invoking a ransomware attack, or users responding to requests to transfer money. There are tools that will help.FYI: We do not receive any kind of compensation or payment for recommending products, nor do we endorse any of [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/e-mail-protection-solution/">E-Mail Protection Solution</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Everyone is concerned about the danger of a user clicking on a link in an email message, perhaps invoking a ransomware attack, or users responding to requests to transfer money. There are tools that will help.<span id="more-2442"></span>FYI: We do not receive any kind of compensation or payment for recommending products, nor do we endorse any of them.</p>
<p>An example tool that can help protect against users opening or clicking in an email is Mimecast Targeted Threat Protection. At least one of our clients use this tool and now we do too.  There are similar solutions that may work better in your situation.</p>
<p>Here’s what the tools do: When an inbound email contains one or more links and a user clicks, Mimecast will intercept the link and attempt to determine if the link goes to a website that is known to be malicious. If it is a known bad site, the click is blocked and the user receives a message. Your existing firewall (if you have the web content filtering feature enabled) may provide you with similar protection already for users inside your office, but not always for users who are travelling or working from home.</p>
<p>These tools scan email attachments in an effort to detect malicious code in the attachments. Your existing spam filtering mechanism may offer this feature.</p>
<p>Mimecast will also block email messages that seem to be from impostors. When a user receives an email that appears to be from someone impersonating the boss, requesting a wire transfer, the service will warn the user to be careful.</p>
<p>While there are no guarantees this kind of tool will stop an email phishing attack, any kind of protection is a welcomed improvement. Ask whomever is providing your anti-spam solution if they offer an add-on solution similar to Mimecast’s Targeted Threat Protection.</p>
<p>Please forward this to everyone you know who is concerned about their users clicking a link in an email message, opening an infected attachment, or responding to an email asking them to transfer money.</p>
<p>The post <a href="https://fosterinstitute.com/e-mail-protection-solution/">E-Mail Protection Solution</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Only One Virus is a Huge Problem</title>
		<link>https://fosterinstitute.com/only-one-virus-is-a-huge-problem/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 03 Nov 2016 15:34:55 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Application Updates]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Infected Apps]]></category>
		<category><![CDATA[Invisible Security Threats]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[IT Virus]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Click to Play]]></category>
		<category><![CDATA[cyber infection]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[cyber security warning IT Pro Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[network security protections]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[updating patches]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus infections]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2390</guid>

					<description><![CDATA[<p>If your office has even one instance of a virus, ransomware, or any other kind of malware, that is a huge symptom. Yesterday, someone told me their security was good since they only get infected by a few viruses each year. Even a single infection means there is a possibility that their machines are already [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/only-one-virus-is-a-huge-problem/">Only One Virus is a Huge Problem</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If your office has even one instance of a virus, ransomware, or any other kind of malware, that is a huge symptom. <span id="more-2390"></span></p>
<p>Yesterday, someone told me their security was good since they only get infected by a few viruses each year. </p>
<p>Even a single infection means there is a possibility that their machines are already infected. </p>
<p>If one virus can get in, other undetectable viruses can too.</p>
<p>Unless security protections are very poor on a network or computer, visible virus infections are rare these days. </p>
<p>People who see virus infections need to act, including patching their Internet facing applications and enabling click-to-play. Those features already come with Windows and applications so there is nothing to buy or download. For more information, see foster institute dot come slash blog.</p>
<p>If you know someone whose computers on their network catch viruses, tell them the viruses are more like chest pain, not like the common cold. Infections are the sign of some greater damage that is about to, or already has, occurred.</p>
<p>The post <a href="https://fosterinstitute.com/only-one-virus-is-a-huge-problem/">Only One Virus is a Huge Problem</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
