Skip to main content

Net Standard

Tips on How Public and Private Entities Can Combat the Rising Tide of Ransomware

NetStandard’s Security Minute Series  This Tuesday, 5/4, I’m doing a webinar with Miller Group. Sign up, tell your friends!  The Ransomware Task Force, a group of more than 50 cybersecurity experts, has published a detailed framework for how public and private entities can work together to help stem the rising tide of ransomware. It calls for a “whole […]

Apple Targeted In $50 Million Ransomware Attack

NetStandard’s Security Minute Series  In this week’s big-game ransomware news, Revil announced that they have attacked Quanta, a Taiwanese computer manufacturer. Quanta is notable because the company is one of Apple’s largest suppliers, and manufactures MacBooks and Apple Watches. Revil is demanding $50 million ransom, or else they will release confidential Apple schematics, plans, and […]

This Month Includes New Patches for Microsoft Exchange

NetStandard’s Security Minute Series  This past week was Patch Tuesday! This month includes new patches for Microsoft Exchange. The new Exchange vulnerabilities are not known to be exploited in the wild….yet….though with the increased attack focus on Exchange these days, exploits will surely come soon. Patch now! April 2021 Security Updates – Release Notes – Security […]

It’s World Backup Day – Are Your Backups Providing Value?

Your Data Is More Valuable Than Your Device Because it’s 2021, and the entire IT industry has spent literal decades telling everyone they need backups, I’m sure you have a backup system in place. Hopefully you sleep well at night, confident that the backup system you paid good money for is making a copy of […]

This Might Make You Think Twice About Participating in a Security Awareness Training

NetStandard’s Security Minute Series We have all seen the “fake tech support” scams, or the various similar ones that all involve talking to a scammer in a (usually foreign) datacenter somewhere. KnowBe4 called one of these scammers and documented the whole process. It’s fascinating – if you only click on one link today, make it […]

Microsoft Continues to Take Unprecedented Steps to Resolve the Exchange Vulnerabilities

NetStandard’s Security Minute Series Since the release of ransomware targeting the new Exchange vulnerabilities (which Scott discussed last week), the number of attacks has grown by 10X. This has become the most significant software vulnerability in a very long time: Exploits on Organizations Worldwide Grow Tenfold after Microsoft’s Revelation of Four Zero-days – Check Point SoftwareMicrosoft […]

Take the Ransom Out of Ransomware

NetStandard’s Security Minute Series So the Exchange attacks just keep getting worse. The estimated number of affected Exchange servers is up into the tens of thousands (I’ve seen some estimates in the hundreds of thousands!), and there are at least 10 other attack groups trying to piggyback onto the Exchange webshells that the initial attack […]

For Our Customers: Recent Exchange Vulnerabilities

Last week, it was widely reported that four previously unknown or “zero-day” vulnerabilities in Microsoft’s Exchange Server software were being actively exploited by groups of cyber attackers. These defects could allow attackers to steal data or deploy malicious software to unpatched Exchange Servers.NetStandard began applying patches to address these vulnerabilities immediately after Microsoft made them […]

Maximize Your Security Offerings With Microsoft

NetStandard’s Security Minute Series The biggest news of the week: Microsoft announced emergency out-of-band patches for Exchange Server, to fix 4 actively exploited 0-day vulnerabilities. There are many, many reports of hundreds of servers being compromised – basically every security vendor is finding this in their clients. If you run on-premise Exchange Server, or know […]

Cybersecurity Trends to Keep an Eye on

NetStandard’s Security Minute Series There’s a new critical vulnerability in vCenter, allowing an attacker to use port 443 to gain root access to vCenter. Even if you don’t have port 443 exposed to the internet, an attacker that breaches an end-user PC (from a phishing attack) could use this for lateral movement, and gain access […]