Apple Targeted In $50 Million Ransomware Attack

NetStandard’s Security Minute Series In this week’s big-game ransomware news, Revil announced that they have attacked Quanta, a Taiwanese computer manufacturer. Quanta is notable because the company is one of Apple’s largest suppliers, and manufactures MacBooks and Apple Watches. Revil is demanding $50 million ransom, or else they will release confidential Apple schematics, plans, and […]
This Month Includes New Patches for Microsoft Exchange

NetStandard’s Security Minute Series This past week was Patch Tuesday! This month includes new patches for Microsoft Exchange. The new Exchange vulnerabilities are not known to be exploited in the wild….yet….though with the increased attack focus on Exchange these days, exploits will surely come soon. Patch now! April 2021 Security Updates – Release Notes – Security […]
It’s World Backup Day – Are Your Backups Providing Value?

Your Data Is More Valuable Than Your Device Because it’s 2021, and the entire IT industry has spent literal decades telling everyone they need backups, I’m sure you have a backup system in place. Hopefully you sleep well at night, confident that the backup system you paid good money for is making a copy of […]
This Might Make You Think Twice About Participating in a Security Awareness Training

NetStandard’s Security Minute Series We have all seen the “fake tech support” scams, or the various similar ones that all involve talking to a scammer in a (usually foreign) datacenter somewhere. KnowBe4 called one of these scammers and documented the whole process. It’s fascinating – if you only click on one link today, make it […]
Microsoft Continues to Take Unprecedented Steps to Resolve the Exchange Vulnerabilities

NetStandard’s Security Minute Series Since the release of ransomware targeting the new Exchange vulnerabilities (which Scott discussed last week), the number of attacks has grown by 10X. This has become the most significant software vulnerability in a very long time: Exploits on Organizations Worldwide Grow Tenfold after Microsoft’s Revelation of Four Zero-days – Check Point SoftwareMicrosoft […]
Take the Ransom Out of Ransomware

NetStandard’s Security Minute Series So the Exchange attacks just keep getting worse. The estimated number of affected Exchange servers is up into the tens of thousands (I’ve seen some estimates in the hundreds of thousands!), and there are at least 10 other attack groups trying to piggyback onto the Exchange webshells that the initial attack […]
For Our Customers: Recent Exchange Vulnerabilities

Last week, it was widely reported that four previously unknown or “zero-day” vulnerabilities in Microsoft’s Exchange Server software were being actively exploited by groups of cyber attackers. These defects could allow attackers to steal data or deploy malicious software to unpatched Exchange Servers.NetStandard began applying patches to address these vulnerabilities immediately after Microsoft made them […]
Maximize Your Security Offerings With Microsoft

NetStandard’s Security Minute Series The biggest news of the week: Microsoft announced emergency out-of-band patches for Exchange Server, to fix 4 actively exploited 0-day vulnerabilities. There are many, many reports of hundreds of servers being compromised – basically every security vendor is finding this in their clients. If you run on-premise Exchange Server, or know […]
Cybersecurity Trends to Keep an Eye on

NetStandard’s Security Minute Series There’s a new critical vulnerability in vCenter, allowing an attacker to use port 443 to gain root access to vCenter. Even if you don’t have port 443 exposed to the internet, an attacker that breaches an end-user PC (from a phishing attack) could use this for lateral movement, and gain access […]
Cyberattacks Are Evolving, Are You?

NetStandard’s Security Minute Series This is scary: The IT monitoring software Centreon was attacked, and allowed the Sandworm group access to Centreon for 3 years. IT monitoring software is generally very trusted software, with visibility to everything inside a network, so this attack is pretty serious: French IT monitoring firm Centreon says no customers affected by […]