Ransomware threat: Get patched, find a firewall or upgrade fast

May 15, 2017

New Delhi, May 15: It was coming. On March 14 this year, Microsoft released a security update which addressed the vulnerability in the 16-year-old Windows XP operating system that the hackers behind the massive ransomware attack exploited and created havoc in 150 countries.

wannacry

The vulnerability in the Microsoft Windows software — exploited by “WannaCrypt” — crippled computers from hospitals in Britain to police stations in India, with hackers demanding hundreds of dollars from the users for them to regain control over their data.

Once Microsoft released the patch for the vulnerability — exploited by hacker group “Shadow Brokers” after stealing a software from the US National Security Agency (NSA) — some Window XP users installed the update called “Microsoft Security Bulletin MS17-010” on their desktops and laptops.

But several didn"t.

There are nearly 150 million computers running Windows XP operation system globally. Those who didn"t pay heed to the Windows XP patch are the ones who have fallen prey to the world"s biggest ransomware attack.

Microsoft which had discontiued security updates to its out-of-date software, has also provided a security update for all customers using Windows 8 and Windows Server 2003, anticipating further attacks on these earlier platforms being used by millions.

According to the company, “customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March.

“If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible,” said Phillip Misner, Principal Security Group Manager, Microsoft Security Response Centre, in a statement.

Meanwhile, “WannaCrypt” locked up machines, encrypted files and demanded approximately $600 in Bitcoin for a recovery key.

According to global cyber security firms, paying heed to updates can only save your data from being put to ransom.

“Install the official patch from Microsoft that closes the vulnerability used in the attack. Ensure that security solutions are switched on all nodes of the network. If Kaspersky Lab"s solution is used, ensure that it includes the "System Watcher", a behavioural proactive detection component and that it is switched on,” Altaf Halde, Managing Director of Kaspersky Lab (South Asia), told.

“Run the "Critical Area Scan" task in Kaspersky Lab"s solution to detect possible infection as soon as possible (otherwise it will be detected automatically, if not switched off, within 24 hours),” he added.

According to Subhendu Sahu, Acting Country Manager for India, FireEye, the ransomware poses high risks to organisations using potentially vulnerable Windows machines.

“We can certainly expect follow-on attacks. Organisations seeking to take risk management steps related to this campaign should install the latest Windows patches. They should also use the indicators of compromise which are associated with this activity. FireEye has also taken steps to help secure its customers,” Sahu told.

As investigators were working to track down those responsible for the ransomware attack, Microsoft President and Chief Legal Officer Brad Smith said the governments should treat this attack as a “wake-up call”.

The news led software security providers to ramp up anti-malware software.

“Upon learning of these incidents, McAfee quickly began working to analyse samples of the ransomware and develop mitigation guidance and detection updates for its customers. McAfee has subsequently provided DAT (that contain data in text or binary format) updates to all its customers and provided them and the public further analysis on the attacks,” Ian Yip, Chief Technology Officer, Asia Pacific, McAfee, told.

If you are a home Windows XP user, patch immediately follow up with an upgrade. If you are running a vulnerable system and cannot install the patch for some reason, try doing the following:

“Disable SMBv1 (a server component) with the steps documented at "Microsoft Knowledge Base Article 2696547" and as recommended previously. Consider adding a rule on your router or firewall to block incoming Server Message Block (SMB) traffic on port 445,” said a report in the technology website Engadget.

“This is big and set to get bigger. We haven"t seen anything like this since Conficker in 2008,” Amit Nath, Head of Asia Pacific-Corporate Business at cyber security firm F-Secure Corporation, told IANS.

The Conficker worm infected millions of computers including government, business and home computers in over 190 countries.
Always make sure your files are backed up.

“That way, if they become compromised in a ransomware attack, you can wipe your disk drive clean and restore the data from the backup. Using Cloud storage with anti-virus scanning abilities to share files will help users to mitigate any possible threats,” suggested Anand Ramamoorthy, Managing Director, South Asia, McAfee.

Remember this: “WannaCrypt” probably won"t work across the internet for PCs behind a firewall or router.

“But if a server is connected directly to the internet or a PC is on the same network as an infected computer, it can spread quickly — which is exactly what has happened,” the Engadget report added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
February 5,2020

Feb 5: Tesla is making Elon Musk a lot richer without paying him a dime.

A blistering stock rally has bolstered the value of CEO Musk's 19% stake in the electric car maker by $16 billion since the start of 2020, to $30 billion.

Tuesday's steep climb in the share price could sweeten Musk's payday under his record-breaking compensation package, which is built on stock options that rely on market value targets. Two milestones have now been achieved that could see Musk unlock options worth $1.8 billion.

The controversial chief executive, who is also the majority owner and CEO of rocket maker SpaceX, recently testified that he did not have a lot of cash as he successfully defended himself in a defamation lawsuit. He previously has taken loans using his Tesla shares as collateral.

Musk does not take a salary, choosing instead a risky options package that envisions the stock market value of Tesla rising to $650 billion over 10 years, a prospect that was derided by some investors when the deal was announced in 2018.

That target now looks less crazy. Shares of Tesla have rallied over 50% since the company posted its second consecutive quarterly profit last Wednesday, which was viewed as a major accomplishment for a company competing against established automotive heavyweights including General Motors Co  and BMW.

Tesla shares have climbed about 400% since early June, helped by the company's better-than-expected financial results and ramped-up production at its new car factory in Shanghai.

On Tuesday, Tesla surged as much as 24% before falling back in the final minutes of the trading session to end the day up 13.7%. That put its market capitalization at $160 billion, almost twice the combined value of Ford Motor and General Motors.

The shares had also rallied on Monday, partly fueled by Panasonic Corp's 6752.T saying its automotive battery venture with Tesla was profitable for the first time.

The options Musk was awarded in 2018 vest incrementally based on targets for Tesla's stock market value and its financial performance. The market capitalization would have to sustainably rise by $50 billion increments over the agreement's 10-year period, with the full package payout reached if the market cap reaches $650 billion, as well as the company's meeting revenue and profit targets.

Musk is on his way to seeing his first two tranches of options vest. He achieved operational targets on revenue and adjusted earnings last year.

The rise in Tesla's market capitalization last month to a target of $100 billion opened the way for Musk's first tranche of options to vest. With Tuesday's surging share price, the market capitalization blew past the second target of $150 billion, opening the way for the second tranche to vest. Tesla's market capitalization must stay at or above each target level for one- and six-month averages for each set of options to vest.

Tesla was valued at about $52 billion when shareholders approved the pay package in March 2018, a time when the company faced a cash crunch, production delays and increasing competition from rivals.

A full payoff for Musk would surpass anything previously granted to U.S. executives, according to Institutional Shareholder Services, a proxy advisor that recommended investors reject the pay package deal at the time.

Musk currently owns about 34 million Tesla shares, and his compensation package would let him buy another 20.3 million shares if all his options tranches vest.

When Tesla unveiled Musk’s package, it said he could in theory reap as much as $55.8 billion if no new shares were issued. However, Tesla has since awarded stock to employees and last year sold $2.7 billion in shares and convertible bonds, diluting the value of the stock.

Musk has transformed Tesla from a niche car maker with production problems into the global leader in electric vehicles, with U.S. and Chinese factories. So far it has stayed ahead of more established rivals including BMW and Volkswagen.

Many investors remain skeptical that Tesla can consistently deliver profit, cash flow and growth. More Wall Street analysts rate Tesla "sell" than "buy," and the company's stock is the most shorted on Wall Street.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 20,2020

In a bid to help struggling small businesses in Covid-19 times, Facebook has introduced Shops to help set up a single online store for customers to access on both Facebook and Instagram.

While Facebook Shops is being rolled out from Wednesday, the company will introduce Instagram Shop, a new way to discover and buy products in Instagram Explore, this summer, starting in the US.

The social networking giant also announced that it will invest in features across its family of apps to inspire people to shop and make buying and selling online easier.

"Creating a Facebook Shop is free and simple. Businesses can choose the products they want to feature from their catalogue and then customise the look and feel of their shop with a cover image and accent colours that showcase their brand," Facebook said in a statement late Tuesday.

Any seller, no matter their size or budget, can bring their business online and connect with customers wherever and whenever it's convenient for them.

People can find Facebook Shops on a business' Facebook Page or Instagram profile, or discover them through stories or ads.

"From there, you can browse the full collection, save products you're interested in and place an order — either on the business' website or without leaving the app if the business has enabled checkout in the US," informed the company.

Last month, Facebook announced $40 million in grants for 10,000 small businesses in the US to help them get through these challenging time.

The grants will go to small businesses in 34 locations where Facebook employees live and work.

The company said that in Facebook Shops, users will be able to message a business through WhatsApp, Messenger or Instagram Direct to ask questions, get support, track deliveries and more.

In the future, they will be able to view a business' shop and make purchases right within a chat in WhatsApp, Messenger or Instagram Direct.

Later this year, Facebook will add a new shop tab in the navigation bar, so people can get to Instagram Shop in just one tap.

Facebook said it is making it easier to shop for products in real time.

Soon, sellers, brands and creators will be able to tag products from their Facebook Shop or catalogue before going live and those products will be shown at the bottom of the video so people can easily tap to learn more and purchase.

"We're starting to test this with businesses on Facebook and Instagram, and we'll roll it out more broadly in the coming months," said the company.

Facebook is also working with partners like Shopify, BigCommerce, WooCommerce, ChannelAdvisor, CedCommerce, Cafe24, Tienda Nube and Feedonomics to support small businesses.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 19,2020

New Delhi, Jan 19: Messaging service WhatsApp which on Sunday faced issues in transmitting multimedia content including pictures and images, prompting social media users to share hilarious memes and messages, resumed regular services after over two hours.

#WhatsAppDown was the trending hashtag on Twitter for most part of Sunday afternoon in India along with several other countries such as Brazil, Europe and also parts of Middle-East including UAE, reported downdetector.in, a realtime problem and outage monitoring website.

Users of the popular messaging app were unable to send media files, stickers and GIFs.

Most users immediately went to Twitter to find out about the problem and check if others were facing the same issue.

Numerous tweets and memes took over the internet as soon as the news broke about the WhatsApp tech issue. After around two hours of technical glitch, the app resumed full service.

Even after full recovery of media transfer, people globally still continued checking the status of the messaging app.

WhatsApp has been one of the prime messaging apps since May 2009 and has recently collaborated with Facebook.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.