<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security breach Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/tag/security-breach-2/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/tag/security-breach-2/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Fri, 06 May 2016 13:00:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>security breach Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/tag/security-breach-2/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Gmail Passwords Stolen, Possibly Millions of Them</title>
		<link>https://fosterinstitute.com/gmail-passwords-stolen-possibly-millions-of-them/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 06 May 2016 13:00:32 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Gmail]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Password Safety]]></category>
		<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[two step login]]></category>
		<category><![CDATA[added security password security]]></category>
		<category><![CDATA[business IT security]]></category>
		<category><![CDATA[computer security]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[gmail security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[password safety]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[two factor auth]]></category>
		<category><![CDATA[two step verification]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=2314</guid>

					<description><![CDATA[<p>This applies to everyone, not just Gmail users. A researcher at Hold Security bought 272 million stolen passwords on the dark web. Some of the credentials were for Gmail. This is not Google’s fault. Whether you use Gmail or not, everyone, if they haven’t already, needs to enable two step login. Then it is very [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/gmail-passwords-stolen-possibly-millions-of-them/">Gmail Passwords Stolen, Possibly Millions of Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>This applies to everyone, not just Gmail users. A researcher at Hold Security bought 272 million stolen passwords on the dark web. Some of the credentials were for Gmail. This is not Google’s fault. Whether you use Gmail or not, everyone, if they haven’t already, needs to enable <span id="more-2314"></span>two step login. Then it is very unlikely that an attacker can compromise your account,  even if they discover your username and password.</p>
<p>Visit two factor auth dot org (no spaces) for a list of services that already permit you to choose two step login. Each site will walk you through the process.</p>
<p>Google calls their service 2 step verification. Google that phrase to find instructions on Google’s site.</p>
<p>Forward this to everyone who you care about so that they can be more cyber-secure too.</p>
<p>The post <a href="https://fosterinstitute.com/gmail-passwords-stolen-possibly-millions-of-them/">Gmail Passwords Stolen, Possibly Millions of Them</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</title>
		<link>https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 06 Jan 2014 22:03:50 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[Yahoo]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[yahoo]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1783</guid>

					<description><![CDATA[<p>If you used your computer, especially if you visited Yahoo (including webmail users who logged in to the mail website to check their email) between December 31 and January 3, there is a chance your computer is infected. The “drive by download” infected an estimated 27,000 users per hour. The exploit attacked a vulnerability in [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/">FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you used your computer, especially if you visited Yahoo (including webmail users who logged in to the mail website to check their email) between December 31 and January 3, there is a chance your computer is infected. The “drive by download” infected an estimated 27,000 users per hour. The exploit attacked a vulnerability in Java. Most users have Java enabled on their computers.<span id="more-1783"></span></p>
<p>An advertisement on Yahoo’s web site contained the malware. Yahoo removed the ad as soon as they were aware of the problem. The question to ask yourself is, “how many other sites contain malware?”</p>
<p>Striving to provide short newsletters is always a priority here, but in this case you may want to know more:</p>
<p>Having patches in place is always important. Please see: <a href="https://fosterinstitute.com/blog/repel-it-attacks/" title="Single Biggest Way to Repel IT Attacks">Single Biggest Way to Repel IT Attacks</a><a href="https://fosterinstitute.com/blog/repel-it-attacks/"></a></p>
<p>Unfortunately, patches won’t help against zero-day attacks. Zero-day (also known as 0-day or “oh-day”) attacks exploit problems against which even the latest patch doesn’t protect.</p>
<p>A decision that would have stopped this attack from affecting you: Consider asking your IT department to disable Java on your network.</p>
<p>Your IT Pros may give you push-back on your request since, if your users constantly visit sites that utilize Java, IT Pros may get inundated with user complaints that some websites don’t work as expected. Notify your users ahead of time that you, as the executive, requested that IT implement this change. </p>
<p>Recently, when conducting an IT Vital Systems Review visit, I suggested to an IT Professional that he disable Java, and his initial response was, “No way. I might as well disable their ability to use the Internet entirely since almost all websites use Java!” As a result of the conversation that followed, he now knows that disabling Java won’t devastate users as much as he feared. But did he disable Java? No. His executives delegated decision making to him and that delegation “isn’t necessarily a bad thing.”</p>
<p>Even if this was brought to attention in the past, then an Executive, may decide to accept the risk of using Java. There are many risks and one of the big deliverables of partnering with an outside firm on security is that they can help your IT pros choose the best protection that costs the least money and doesn’t interfere with the user experience.</p>
<p>If you want to completely disable Java all by yourself on your own home computers, here are instructions: <a href="http://www.java.com/en/download/help/disable_browser.xml" title="How do I Disable Java?">How do I Disable Java?</a>  Some of the instructions are out of date if you are using the latest browsers and OS (and I hope you are using the latest). Most of the errors related to only the first instruction about where you can find the settings:</p>
<p>-For Internet Explorer, depending on your configuration, you may find that the “Java Control Panel” is now called “Configure Java.”<br />
-In Firefox, choose Tools > Add-ons.<br />
-In Chrome, you access the Chrome menu by clicking on the icon that shows a stack of three horizontal bars. The icon is usually to the far right of the URL address bar.</p>
<p>Then follow the rest of the instructions.</p>
<p>In this attack, Windows Phones and Apple computers are not affected. If you run Windows on a Mac computer, you are still susceptible to the infection. Keep in mind that moving to Mac isn’t a panacea, and moving to a Mac may have consequences related to the interoperability with Windows machines at your office. </p>
<p>Additionally, it seems that European companies were the primary targets. That doesn’t “put you in the clear” and keep in mind that “visiting other sites besides Yahoo” isn&#8217;t safe either. </p>
<p>Yahoo is an example of a company that became aware of the problem. Many companies aren’t aware that their sites contain active infections.</p>
<p>There are other protections against these problems including:</p>
<p>-Content restrictions in browsers (we’ll deal with this next week)<br />
-Using browsers only inside of virtual machines that reset each time you launch the virtual machine (complicates the user experience)<br />
-Using application whitelisting <a href="https://fosterinstitute.com/blog/obsolete/">Is Anti-Virus Obsolete?</a><br />
-And more – and no protection is the cure-all.</p>
<p>Please post your comments below&#8230;</p>
<p>The post <a href="https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/">FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
