Thursday, April 16, 2020

COVID19 Doomsday Hackers

Someone’s got nothing better to do over there in England….

This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC).

This alert provides information on exploitation by cybercriminal and advanced persistent threat (APT) groups of the current coronavirus disease 2019 (COVID-19) global pandemic. It includes a non-exhaustive list of indicators of compromise (IOCs) for detection as well as mitigation advice.

Both CISA and NCSC are seeing a growing use of COVID-19-related themes by malicious cyber actors. At the same time, the surge in teleworking has increased the use of potentially vulnerable services, such as virtual private networks (VPNs), amplifying the threat to individuals and organizations.

APT groups and cybercriminals are targeting individuals, small and medium enterprises, and large organizations with COVID-19-related scams and phishing emails. This alert provides an overview of COVID-19-related malicious cyber activity and offers practical advice that individuals and organizations can follow to reduce the risk of being impacted. The IOCs provided within the accompanying .csv and .stix files of this alert are based on analysis from CISA, NCSC, and industry.

Note: this is a fast-moving situation and this alert does not seek to catalogue all COVID-19-related malicious cyber activity. Individuals and organizations should remain alert to increased activity relating to COVID-19 and take proactive steps to protect themselves.

Technical Details

Summary of Attacks

APT (advanced persistent threat) groups are using the COVID-19 pandemic as part of their cyber operations. These cyber threat actors will often masquerade as trusted entities. Their activity includes using coronavirus-themed phishing messages or malicious applications, often masquerading as trusted entities that may have been previously compromised. Their goals and targets are consistent with long-standing priorities such as espionage and “hack-and-leak” operations.

Cybercriminals are using the pandemic for commercial gain, deploying a variety of ransomware and other malware.

Both APT groups and cybercriminals are likely to continue to exploit the COVID-19 pandemic over the coming weeks and months. Threats observed include:

  • Phishing, using the subject of coronavirus or COVID-19 as a lure,
  • Malware distribution, using coronavirus- or COVID-19- themed lures,
  • Registration of new domain names containing wording related to coronavirus or COVID-19, and
  • Attacks against newly—and often rapidly—deployed remote access and teleworking infrastructure.

Malicious cyber actors rely on basic social engineering methods to entice a user to carry out a specific action. These actors are taking advantage of human traits such as curiosity and concern around the coronavirus pandemic in order to persuade potential victims to:

  • Click on a link or download an app that may lead to a phishing website, or the downloading of malware, including ransomware.
    • For example, a malicious Android app purports to provide a real-time coronavirus outbreak tracker but instead attempts to trick the user into providing administrative access to install “CovidLock” ransomware on their device.
  • Open a file (such as an email attachment) that contains malware.
    • For example, email subject lines contain COVID-19-related phrases such as “Coronavirus Update” or “2019-nCov: Coronavirus outbreak in your city (Emergency)”

To create the impression of authenticity, malicious cyber actors may spoof sender information in an email to make it appear to come from a trustworthy source, such as the World Health Organization (WHO) or an individual with “Dr.” in their title. In several examples, actors send phishing emails that contain links to a fake email login page. Other emails purport to be from an organization’s human resources (HR) department and advise the employee to open the attachment.

Malicious file attachments containing malware payloads may be named with coronavirus- or COVID-19-related themes, such as “President discusses budget savings due to coronavirus with Cabinet.rtf.”

Note: a non-exhaustive list of IOCs related to this activity is provided within the accompanying .csv and .stix files of this alert.

Phishing

CISA and NCSC have both observed a large volume of phishing campaigns that use the social engineering techniques described above.

Examples of phishing email subject lines include:

  • 2020 Coronavirus Updates,
  • Coronavirus Updates,
  • 2019-nCov: New confirmed cases in your City, and
  • 2019-nCov: Coronavirus outbreak in your city (Emergency).

These emails contain a call to action, encouraging the victim to visit a website that malicious cyber actors use for stealing valuable data, such as usernames and passwords, credit card information, and other personal information.

SMS Phishing

Most phishing attempts come by email but NCSC has observed some attempts to carry out phishing by other means, including text messages (SMS).

Historically, SMS phishing has often used financial incentives—including government payments and rebates (such as a tax rebate)—as part of the lure. Coronavirus-related phishing continues this financial theme, particularly in light of the economic impact of the epidemic and governments’ employment and financial support packages. For example, a series of SMS messages uses a UK government-themed lure to harvest email, address, name, and banking information. These SMS messages—purporting to be from “COVID” and “UKGOV”.

 

The post COVID19 Doomsday Hackers appeared first on IPSOFACTO, IT Services.


COVID19 Doomsday Hackers syndicated from https://ipsofacto.net

Friday, March 20, 2020

Going Mobile Playbook; And love to IPSOFACTO Clients.

Dear Loving Clients,

We Send our Love back to you from the IPSOFACTO, IT Services Family

March 16- March 20 was busy; for new mobile team support and overtaxed home-to-office connectivity. The hackers and computer viruses have seen a 10x increase. (Hackers have nothing better to do right now).

Here at IPSOFACTO, IT Services we are:

  1. Helping people use and have secure mobile tools
  2. Rolling out our SAFETY BUNDLE (mobile protections, network speed increases, user efficiency, corporate oversite)
  3. Redesigning Data Systems (now is a great time to organize files)
  4. Migrating email and files to safer locations
  5. Mobile-Speed-Upgrades for hardware (firewalls and Wifi) and for Servers (patches and Virtual software)
  6. Rolling out new computers for Mobile Staff
  7. Updating Network Security profiles

Some of our clients are working from home and have seen a slowdown in employee productivity. What seems like a vacation for some sees us doing background security and network upgrades. Right now, many new data filters are rolling out to protect networks from embedded hacks.

We have been rescheduling on-site appointments to off-site.

Our clients have been calling us to ask how to roll out new collaboration software.

All our plans are in full effect. They will be re-evaluated on April 7th. We must pay our salaries here. Humans come first in these difficult times.

For IT Service, please send requests to support@ipsofacto.net We’re here to keep you up and working.

Thank you,

Steve and the IPSOFACTO, IT Services Family

 

————————————————————————

Many IPSOFACTO, IT Services clients are using this opportunity to:

  1. Avoid interruptions: We’re working in empty offices to replace old or obsolete networking equipment.
  2. Outpace competitors: Our gig economy clients are finding ways to take more market share from firms that are not working now.
  3. Launch new Marketing campaigns: more eyeballs reading more copy right now.
  4. Support the cause: Focus on clients in Healthcare and delivery services.
  5. Hire: Find new employees.
  6. Buy an office, rather than rent: Commercial office prices are down, and the interest rate is 0%. Buy a $1m live-work loft for 3%, 20yrs, $50k down.
  7. Facilitate Changes: Make the changes you wanted to make in 2019 but were too busy.
  8. Plan Better: Write up a new business plan for 2020.
  9. Embrace Yogic Living: This is a time for better health, true information, and strong compassion.

Working Mobile; things you will need

  1. Security Software
    1. Recommendation: Install OpenDNS, Webroot Antivirus and MDM on all Craft computers/laptops – this can be done remotely.
  1. VPN Access
    1. Recommendation: Meraki networks already support VPN access; setup for all  employees – this can be done remotely.
  1. Cybersecurity Incident Response Plan
    1. Recommendation: Develop/Update response plan – The increased security risk of remote work reinforces the need to have a plan in place if something goes wrong.

Email support@ipsofacto.net or call 415-362-2922; to roll-out these changes ASAP. www.ipsofacto.net

———————————————————————

Boiler Plate Network Security Guidelines

Additionally, the following is not a comprehensive list of IPSOFACTO, IT Services best practices and some may or may not apply; however, it provides users and organizations with some guidance in managing the cybersecurity risks associated with a remote workforce.

Policy: 

Review your current information security and other similar policies to determine if there are any established security guidelines for remote work and remote access to company information systems.  Some organizations may have policies specifically geared for remote work, while others may provide for contingencies in disaster recovery plans, BYOD (bring your own device) polices, and other similar plans and policies. If no relevant plans or policies are in place, this is a good time to establish at least some basic guidelines to address remote access to company information systems and use by employees of personal devices for company business.

Preparation:

Companies should review data breach and incident response plans to ensure that organizations are prepared for responding to a data breach or security incident.  Update the plans if necessary, for contact information for the (now) remote incident response team and outside advisors.

 

Remote Access:

In traditional IPSOFACTO, IT Services virtual private networks (VPNs), individuals use VPN client software to establish a secure connection to an internal network to access internal (office) resources (i.e File Share Servers, Virtual Machines, intranet websites, etc.). Organizations should scope VPN access accordingly to ensure the principle of least privilege is maintained. Regardless of which remote access method you offer, multi-factor authentication should be mandatory. Additionally, if remote devices are allowed to connect to your internal network, consider implementing a Network Access Control (NAC) solution to ensure only authorized devices are permitted to connect at IPSOFACTO, IT Services.

Organization-Owned vs Personal Devices:

Many Software as a Service (SaaS) and virtualized applications that IPSOFACTO, IT Services  managesmay be securely accessed by remote users through their personal devices if certain security controls are implemented. To reiterate, MFA should be mandatory for remote access to any application, network, or service your organization provides to teleworkers. In addition, organizations must implement controls to ensure sensitive files and information are not downloaded or stored on personal devices or personal cloud storage services. Sensitive data should only be stored on organizationally-controlled devices or authorized cloud storage services. Cloud service providers often offer conditional access controls to prevent the download of data to unauthorized devices. IT departments are advised to enforce these controls. For cloud services at IPSOFACTO, IT Services that do not provide the option to restrict the download of sensitive data, organizations are advised to implement a Cloud Access Security Broker (CASB) solution that provides these security controls.

Device Security:

Irrespective of whether a device is personally owned or organizationally owned, they are exposed to numerous risks when connecting to networks not controlled by the organization. Therefore, implementing strong security controls by IPSOFACTO, IT Services is paramount. This includes controls such as strong authentication, hardening the operating system, and applying the principle of least functionality to limit services, ports, and protocols to only those that are necessary. Protective technologies should be implemented, including anti-virus/anti-malware software, endpoint detection and response software, web content filtering software, host-based firewalls, device and file encryption, and the latest security patches. With a remote workforce, IPSOFACTO, IT Services face a myriad of challenges in providing support, pushing security updates, and providing continuous monitoring and incident reporting and response services for remote devices and users.

Other Remote Work Cyber Security Tips:

  • Remind employees of the types of information that they need to safeguard.  This often includes information such as confidential business information, trade secrets, protected intellectual property, work product, customer information, employee information, and other personal information (information that identifies a person of household). IPSOFACTO, IT Services can shore this up with data protection services.
  • Sensitive information, such as certain types of personal information (e.g., personnel records, medical records, financial records), that is stored on or sent to or from remote devices should be encrypted in transit and at rest on the device and on removable media used by the device. IPSOFACTO, IT Services can shore this up with data protection services.
  • Train employees on how to detect and handle phishing attacks and other forms of social engineering involving remote devices and remote access to company information systems. There are an increasing number of Coronavirus-based phishing emails going around, preying on the health concerns of the public. For more information about this particular risk, please see our article. Train your employees using IPSOFACTO, IT Services training programs.
  • Do not allow sharing of work computers and other devices.  When employees bring work devices home, those devices should not be shared with or used by anyone else in the home.  This reduces the risk of unauthorized or inadvertent access to protected company information.
  • Company information should never be downloaded or saved to employees’ personal devices or cloud services, including employee computers, thumb drives, or cloud services such as their personal Google Drive or Dropbox accounts. IPSOFACTO, IT Services can shore this up with data protection services such as Saas Backup.
  • “Remember password” functions should always be turned off when employees are logging into company information systems and applications from their personal devices. use IPSOFACTO as your password. Nobody can spell it correctly though it’s one of the oldest words still used in the English Language.

The post Going Mobile Playbook; And love to IPSOFACTO Clients. appeared first on IPSOFACTO, IT Services.


Going Mobile Playbook; And love to IPSOFACTO Clients. syndicated from https://ipsofacto.net

Tuesday, March 10, 2020

IPSOFACTO- In Love with Modular Construction

Modular Construction Technologies, (an area of expertise here at IPSOFACTO) is full of fantastic new advances and ideas.

‘In-housing’ the technologies that were once ‘off-burdened’ to a low tech GC is no longer happening. It was bad and had to go. Factories now produce modules and assemblers now assemble those modules. Assemblers have become the modern-day GC; only needing to put the modular pieces together while offering a little light construction, only. (seaming, taping, painting, a little dry-walling)

But what are the technical shortcomings. All technology (since the beginning of time) becomes TOO complex. Simplicity doesn’t sell. Complexity sells. Greed causes complexity, to sell more BS. Complexity is bad.

 

So in Modular Construction, we need PM tools that anyone can use. CAD based programs need to be usable by low level admin and inside Sales staff. Having access to the technology by today’s less-then-brilliant tech users is the new requirement. You shouldn’t need a PhD to use modular construction technologies. In fact, in building buildings, you are most likely to find lowest level technology users out there, construction workers.

For Accountants; they need to change their brains….they need to understand modular manufacturing inventory management work flow rather than old fashioned construction. Accountants need applications to support them. For instance, on what continents are staff working. Where are the modules built and to where are they shipping? Where are these immense amounts of 3d and 2d data being stored? How is inventory managed and accounted?

Printing; using in house or cloud-based printing facilities. Who is doing the document preparation and where…. India. China. US. Patagonia?

The future big failures in new Modular Construction will use outdated and stupid tech;  GSuite and a good plotter. yikes. That’s definitely the attitude of yesterday and not of tomorrow.

Repetition leads to perfection. Re-inventing wheels does not. When the correct mix and use of modular construction technologies is in play, repeating the same Bauhaus patterns will lead to the flare of IM Pei. But Modular lends itself to construction at breakneck speeds. Like when the Hulk destroys a city. Modular will help rebuild it in a few weeks (with the right technologies! ha!) Damn you, Hulk!

Modular construction techniques rely on technology and supports the use of (and further advances of) technology within the sector.

Some of the biggest wins to focus on are:

  1. Less waste
  2. Faster Speeds
  3. Faster permitting and inspection
  4. More efficient use of raw materials that are NOT wasted.
  5. Better inventory and accounting modeling
  6. Global Team sets
  7. Easier buying calculations, follow up, and leverage.
  8. Easier loan access (better numbers, better loans!)
  9. Greater standards for Fixtures and built in furnishings
  10. Standards for plumbing and electrical
  11. Eventual economies of scale at a global level (build identical buildings in cities thousands of miles apart, the modules coming from 1 single factory.
  12. Resale Standards and Comp reviews

And all of these incredible advances will require new technologies to manage them.

The post IPSOFACTO- In Love with Modular Construction appeared first on IPSOFACTO, IT Services.


IPSOFACTO- In Love with Modular Construction syndicated from https://ipsofacto.net

Friday, January 31, 2020

Damn You G Suite and O365

Dammit!

“The G Suite data got permanently deleted.”

…Or…

“The Office 365 data got permanently deleted.”

 

Did you know this data CAN NEVER BE RETRIEVED?

Do you think Google or Microsoft run expensive systems to store your DELETED data. They don’t. It’s gone permanently.

The conference speaker in Houston said “MAKE SURE your cloud data backed up”. My client, a freight company, was hacked and 10 years of data was deleted. They spent $450,000 to stay in business, and the data still has all the wrong dates on it.

Then he went on to mention the airline company, the Law firm, the CPA firm….all the same… They embraced O365 or G Suite, and lost their public folders, their contact groups, the calendar entries, or accidentally deleted all emails about 2019 taxes.

They all thought MS and Google stored their deleted data. How silly.

This nightmare is happening everywhere in America for a few years now.

PLEASE PLEASE, Call us.

For $35/mo all your hosted G Suite or Office365 data is backed up.

Our system is never seen, you never know its there, working in the background. All data is 256bit encrypted.

When you assistant deletes all your contacts or your email from 2018 (by accident), we restore in 5 minutes. For $35/mo.

PLEASE DO NOW. (your call to action).

 

Have a great day. And with so much stress-relieving LOVE,

Steve IT Luvr…

The post Damn You G Suite and O365 appeared first on IPSOFACTO, IT Services.


Damn You G Suite and O365 syndicated from https://ipsofacto.net

Wednesday, January 29, 2020

Press Release – We’re Ready to Welcome New Clients

San Francisco, CA based IPSOFACTO IT Services is pleased to place their technological acumen and experience at the disposal of their clients. The company welcomes all kinds of businesses, and they are just as willing to help start-ups get the necessary boost required to get off the ground as they are to allay the concerns of large organizations that want to upgrade their security and improve the efficiency of their workflow.

IPSOFACTO IT Services states that they consider it their mission to deliver, “sound, intelligent technical guidance essential to the success of fast-growth, medium, and large businesses, VC’s, government, and non-profit Foundations,” a task they have devoted themselves to wholeheartedly for more than two decades. Since their inception, the company has enjoyed a consistent rate of growth that reflected the quality of their services. In conjunction with this growth, they learned what it takes to build a business and ensure its longevity, particularly where IT systems are concerned. As such, they are able to appreciate the vital role they play, and this appreciation is upheld by a team of industry-leading experts.

According to the company, “IPSOFACTO IT Services manages systems, technology security, networks, Macs/PCs, and mobile devices for networks ranging in size between 5 and 500 workstations. Our sought after engineers hold Ph.Ds, CS, MBA, MCSE, CCNA, and advanced vendor certifications. We offer a calm, capable hand along with cost-efficient network solutions.” Given the nature of their work, the team at IPSOFACTO IT Services strongly believes in maintaining the right frame of mind as they take on any challenge set before them. This belief reinforces the quality of the service they provide, since they strive to remain mindful, ready, and aware at every stage of any project, no matter its size or complexity.

“Bay Area computer network support and San Francisco IT services clients have come to expect these qualities from IPSOFACTO,” observes the IT specialist. This may also explain the company’s present status in the IT industry; they currently enjoy, “strategic partnerships that include long-term relationships with Microsoft (and O365), Google, Apple, Lenovo, Meraki, Cloud, and others.” Such partnerships serve to indicate the degree of trust that is often placed in them, and the company asserts that this trust has never been misplaced. IPSOFACTO adds that any other businesses that often find themselves needing to outsource IT services are similarly welcome to engage the company’s assistance.

They elaborate that, “For IT security, IPSOFACTO installs hardware like cameras, keycard systems, and software like Anti-Hacking for Macs, anti-virus, anti-spam, anti-phishing systems. Ask about our Compliance Auditing Services for HipAA and ISO. For fast-growth winners, IPSOFACTO does on-and-off boarding, compiles every crucial technology manual required, and executes extremely fast and responsive systems (wifi and network). We’re also friends with most ISPs in SF.” They can even help overworked managers by smoothing out any IT-related problems.

Clients often leave highly favorable reviews of the company’s work. For instance, Karen Lee says in their 5-Star review that, “We’re opening an office in San Francisco and transferring staff from Scotland. IPSOFACTO not only designed our offices, conference rooms, and individual systems but also did the cabling. Kindly, they worked alongside our builders while I was in Malaysia. What a nice team. Economical and very friendly people.”

In a similarly glowing review, Shelley Canter says, “IPSOFACTO is a superb IT support firm! My friend who has used them for years raved about them and, after a month, I am raving as well. The level of responsiveness, professionalism, and skill is unparalleled in my experience. Just yesterday, Raul completely transformed my IT setup, taking a mass of cables (even though color-coded) into a streamlined and safer configuration. It was beyond anything I could have hoped for. I feel a surge of happiness every time I enter my office and see the new set-up. IPSOFACTO is the best!” Notably, both of these reviews have personalized responses from the company.

Businesses and other organizations that require the attention of a Bay Area IT company are invited to reach out to Steve Bouillanne of IPSOFACTO IT Services to get started. More information, including a comprehensive list of the services on offer, is available on their website. The company can also be reached through various social media platforms, including Facebook, Twitter, and so on.

The post Press Release – We’re Ready to Welcome New Clients appeared first on IPSOFACTO, IT Services.


Press Release – We’re Ready to Welcome New Clients syndicated from https://ipsofacto.net

Friday, January 17, 2020

IT Services Letter to Millenials and GenZs

Old tech that old people did in the olden days, like in the 90s

It’s true, my 20-year-old son will make me a grandpa in 2020. For Millennials and GenZs, grandpa means OLD, but to most grandpas I’ll be a 47-year-old grandpa and that’s young. At 89, my dad is an OLD grandpa…I’m not.

When I was 8 yrs old, I got my first computer, when computers first came out, called an apple 2e. I wrote code to build calendars and clocks in Fortran and C. How silly. Like using a blunt rock to do surgery.

Now I’m the CEO of San Francisco’s oldest and maybe largest IT firms. I started IPSOFACTO in 1996 when Millennials were still in elementary school and GenZs were fiction.

In 1996, IPSOFACTO did TokenRings and LotusNotes by IBM. Both are long dead now; they were the De Facto standard in corporate IT. To make TR and LN work, we removed the network interface (NIC) cards from the computers and set 0s and 1s to create identity. It was hard and mindboggling work. What is 10101101? We had to know this.

Then self-configuring Ethernet came out and we grew and grew and grew, because 100s of new technologies were springing up, and our clients needed us for them.

Before the evil empire of Apple (a truly evil place when you scratch under that chemically treated brushed metal shell), YOU could unscrew computers and laptops and change the parts. Like a Ford Mustang or a Tractor. If it broke, you could fix it yourself. Then Apple stopped ANYBODY from seeing anything they made, and so after 15 years, Millennials and GenZs lost the skill to repair their technology themselves. (sad face emoji).

In 1998, IPSOFACTO sold millions of dollars of hardware and millions more in service. But evil Apple and evil Microsoft wanted that money. MS Azure killed half our revenue and zitty faced Apple gurus (who know nothing about business Workflow models) damaged businesses with a smile.

the future of IT services

What is the future of IT Services

Companies grow and have fleets of IT laptops, computers and phones. All this technology needs to work, so that that employees can produce, and not sit around waiting for their technology to allow them to produce.

IT Services: SECURITY

In 2020, our Legal Courts are FULL of Technology lawsuits. All over the country, companies are suing other companies for stealing their IP (intellectual property). And IT companies like IPSOFACTO protect company IP…We can tell who’s stealing it, and where it went. Sadly, companies are a little slow to protect their special sauce (code and proprietary technology). Companies need to spend a little money on building fences. I didn’t say Fort Knoxes, I said fences. Hackers, saboteurs, and thieves. Ransomware and Bitcoin Blackmail. It’s happening everywhere now.

IT Services: TURNOVER

Also, while this economy is hot, the beleaguered Millennial can work anywhere. (wait until there’s a recession. You’ll hold onto your job with your dying breath). As a result of high Turnover, OnBoarding and OffBoarding is a crucial and complicated necessity for all firms.

That’s it for IT. Security (100s of complex configurations) and Turnover (100s of complex configurations)

Millennial LOVE:

I LOVE Millennials! They are my favorite generation. Every weekend in Duboce Park, they flaunt their near-perfect bodies in the sun play lots of park games (using small trampolines) and cornhole, while drinking only 1 extremely fancy beer, and talk about a clean, green planet and an end to single-use plastics. When I was their age, we got drunk behind the supermarket and had sex in cars (or behind the dumpsters at the supermarket). Ronald Reagan was president. The worst pig ever.

So, go Millennials. Demand a green and clean planet. Stop using plastic Band-Aids (gross). Bring your own bags. Carpool. Turn down the heat and wear cashmere or merino pajamas. Stop wearing polyester and nylon clothes (gross). Eat less beef. Take shorter showers. Keep using your Iphone6 until it breaks permanently. Learn how to build your own computer or phone. Use solar and water panels. Become independent. Build companies that will last and use technology in intelligent ways. Call IPSOFACTO to protect your IP and to manage your technology.

IPSOFACTO (415)362-2922 or visit https://ipsofacto.net

The post IT Services Letter to Millenials and GenZs appeared first on IPSOFACTO, IT Services.


IT Services Letter to Millenials and GenZs syndicated from https://ipsofacto.net

Tuesday, December 24, 2019

IPSOFACTO

IPSOFACTO is San Francisco's top IT service company. Located in the heart of the bay area we provide many IT solutions for small and medium businesses as well as corporate clients. Whether your business needs network support, wants to outsource your IT service, wants us to set up mxlogin office 365, we have the skills to get it done.