<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>yahoo Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/tag/yahoo-2/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/tag/yahoo-2/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Thu, 15 Dec 2016 15:24:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>yahoo Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/tag/yahoo-2/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>More than 1 Billion Passwords Stolen &#8211; What to Do</title>
		<link>https://fosterinstitute.com/more-than-1-billion-passwords-stolen-what-to-do/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 15 Dec 2016 15:24:05 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Family Cyber Safety]]></category>
		<category><![CDATA[IT Best Practices]]></category>
		<category><![CDATA[Online Security]]></category>
		<category><![CDATA[Password Safety]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Yahoo]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Have I Been Pwned]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[Login security]]></category>
		<category><![CDATA[preventative IT Manintenance Cyber]]></category>
		<category><![CDATA[pwned]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[Security expert]]></category>
		<category><![CDATA[stolen passwords]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Troy Hunt]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[yahoo breach]]></category>
		<category><![CDATA[Yahoo Security]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2410</guid>

					<description><![CDATA[<p>You hear in the news that Yahoo, or some other company, got hacked and your username and password may be in the hands of attackers. There is a way to find out if your credentials were exposed. An Australian Web Security Specialist, Troy Hunt, has compiled a database containing usernames that have been stolen in [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/more-than-1-billion-passwords-stolen-what-to-do/">More than 1 Billion Passwords Stolen &#8211; What to Do</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You hear in the news that Yahoo, or some other company, got hacked and your username and password may be in the hands of attackers. There is a way to find out if your credentials were exposed.<span id="more-2410"></span></p>
<p>An Australian Web Security Specialist, Troy Hunt, has compiled a database containing usernames that have been stolen in hacks and then published or sold.  Some people use his site to look up their own email address or username.<br />
His website is haveibeenpwned dot com.  (In this case, Pwned refers to a condition of someone else having access to your login credentials.) </p>
<p>At his site, people enter their email address or any usernames they’ve used for online logins. Sometimes, they look up addresses of their family members. If there is a hit, the details of the breach are displayed on the site.</p>
<p>Even if not on the list, there is no guarantee that person’s credentials haven’t been stolen, but it still helps to know.</p>
<p>If you ever suspect that your login credentials to any website have been exposed, it is very important that you reset the password on that site, as well as any other sites where you may have used the same password.</p>
<p>There are other strategies to protect yourself. Enabling two-step-logon is very important these days since it can thwart attackers who know your username and password. Using a password manager, as opposed to letting your browser store passwords, can help make password security more convenient, but it still needs to be used carefully. These strategies are explained in detail elsewhere in this blog.</p>
<p>Forward this to anyone who might want to know if their username and password has been hacked.</p>
<p>The post <a href="https://fosterinstitute.com/more-than-1-billion-passwords-stolen-what-to-do/">More than 1 Billion Passwords Stolen &#8211; What to Do</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</title>
		<link>https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 06 Jan 2014 22:03:50 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[Security Breach]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[Yahoo]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[yahoo]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1783</guid>

					<description><![CDATA[<p>If you used your computer, especially if you visited Yahoo (including webmail users who logged in to the mail website to check their email) between December 31 and January 3, there is a chance your computer is infected. The “drive by download” infected an estimated 27,000 users per hour. The exploit attacked a vulnerability in [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/">FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you used your computer, especially if you visited Yahoo (including webmail users who logged in to the mail website to check their email) between December 31 and January 3, there is a chance your computer is infected. The “drive by download” infected an estimated 27,000 users per hour. The exploit attacked a vulnerability in Java. Most users have Java enabled on their computers.<span id="more-1783"></span></p>
<p>An advertisement on Yahoo’s web site contained the malware. Yahoo removed the ad as soon as they were aware of the problem. The question to ask yourself is, “how many other sites contain malware?”</p>
<p>Striving to provide short newsletters is always a priority here, but in this case you may want to know more:</p>
<p>Having patches in place is always important. Please see: <a href="https://fosterinstitute.com/blog/repel-it-attacks/" title="Single Biggest Way to Repel IT Attacks">Single Biggest Way to Repel IT Attacks</a><a href="https://fosterinstitute.com/blog/repel-it-attacks/"></a></p>
<p>Unfortunately, patches won’t help against zero-day attacks. Zero-day (also known as 0-day or “oh-day”) attacks exploit problems against which even the latest patch doesn’t protect.</p>
<p>A decision that would have stopped this attack from affecting you: Consider asking your IT department to disable Java on your network.</p>
<p>Your IT Pros may give you push-back on your request since, if your users constantly visit sites that utilize Java, IT Pros may get inundated with user complaints that some websites don’t work as expected. Notify your users ahead of time that you, as the executive, requested that IT implement this change. </p>
<p>Recently, when conducting an IT Vital Systems Review visit, I suggested to an IT Professional that he disable Java, and his initial response was, “No way. I might as well disable their ability to use the Internet entirely since almost all websites use Java!” As a result of the conversation that followed, he now knows that disabling Java won’t devastate users as much as he feared. But did he disable Java? No. His executives delegated decision making to him and that delegation “isn’t necessarily a bad thing.”</p>
<p>Even if this was brought to attention in the past, then an Executive, may decide to accept the risk of using Java. There are many risks and one of the big deliverables of partnering with an outside firm on security is that they can help your IT pros choose the best protection that costs the least money and doesn’t interfere with the user experience.</p>
<p>If you want to completely disable Java all by yourself on your own home computers, here are instructions: <a href="http://www.java.com/en/download/help/disable_browser.xml" title="How do I Disable Java?">How do I Disable Java?</a>  Some of the instructions are out of date if you are using the latest browsers and OS (and I hope you are using the latest). Most of the errors related to only the first instruction about where you can find the settings:</p>
<p>-For Internet Explorer, depending on your configuration, you may find that the “Java Control Panel” is now called “Configure Java.”<br />
-In Firefox, choose Tools > Add-ons.<br />
-In Chrome, you access the Chrome menu by clicking on the icon that shows a stack of three horizontal bars. The icon is usually to the far right of the URL address bar.</p>
<p>Then follow the rest of the instructions.</p>
<p>In this attack, Windows Phones and Apple computers are not affected. If you run Windows on a Mac computer, you are still susceptible to the infection. Keep in mind that moving to Mac isn’t a panacea, and moving to a Mac may have consequences related to the interoperability with Windows machines at your office. </p>
<p>Additionally, it seems that European companies were the primary targets. That doesn’t “put you in the clear” and keep in mind that “visiting other sites besides Yahoo” isn&#8217;t safe either. </p>
<p>Yahoo is an example of a company that became aware of the problem. Many companies aren’t aware that their sites contain active infections.</p>
<p>There are other protections against these problems including:</p>
<p>-Content restrictions in browsers (we’ll deal with this next week)<br />
-Using browsers only inside of virtual machines that reset each time you launch the virtual machine (complicates the user experience)<br />
-Using application whitelisting <a href="https://fosterinstitute.com/blog/obsolete/">Is Anti-Virus Obsolete?</a><br />
-And more – and no protection is the cure-all.</p>
<p>Please post your comments below&#8230;</p>
<p>The post <a href="https://fosterinstitute.com/fyi-were-you-online-between-123113-and-1314-your-pc-may-be-infected/">FYI: Were you online between 12/31/13 and 1/3/14? Your PC may be infected.</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
