REPORT ALL SUSPICIOUS OR CRIMINAL ACTIVITY TO 911

Showing posts with label Cybersafety. Show all posts
Showing posts with label Cybersafety. Show all posts

Tuesday, September 26, 2023

INTERNET SAFETY- Educating Your Children to be Safe Online

The internet and social media have become important to our lives. They also become important to your children's lives as they mature. In the latest issue of the Sheriff’s Office’s crime prevention newsletter, “Partners in Crime Prevention, the Sheriff’s Office suggests some ways you can guide your children to be safe on the internet.

 

 

 

Snohomish County Sheriff’s Office:

https://www.snohomishcountywa.gov/ArchiveCenter/ViewFile/Item/7071

 

 

 

Monday, October 24, 2022

CYBER SECURITY – Password Managers

Multifactor authentication (MFA) adds an additional security layer to your online accounts to ensure that unauthorized people do not access your account. MFA tries to make up for weaknesses in the ID/password model of access that have developed over the years. Those weaknesses include simple, easy passwords to guess or break (like using the word “password,” or “password1234”) or using the same password to access several online accounts.

But, even with the spread of the use of MFA, we still rely on ID and password as an entry into our accounts. There are organizations that seek to eliminate passwords (https://fidoalliance.org/), but, until industry adopts another authentication standard, we will be relying on ID and passwords in whole or in part.

An ID and password represent something we know. But if someone else also knows that ID and password, by stealing it in a hack of a major database or purchasing it in the dark web, they can access your accounts and copy your personal information to use in frauds, or, if it is a bank account, move money from your account to their own account.

Cyber criminals can also guess your password, especially if it is easy to guess like password1234, or it is short. In a brute force attack, cyber criminals use a computer program that guesses passwords. For passwords under 10 characters a successful guess can be instant or just a few seconds or minutes, even if you use numbers, upper- and lower-case letters and symbols. For passwords 12 characters or over a successful guess can take several years to several lifetimes for a successful guess. This is why cybersecurity professionals now recommend passwords be 12 characters or longer and contain a random assortment of numbers, upper- and lower-case letters and symbols.

But this approach causes a problem. Our human brains cannot remember such complicated passwords. We might be able to memorize one password that meets this standard, but not several different passwords. And it is easy for an individual to need passwords for tens if not hundreds of accounts.

A way around this might be to have a “universal” password. A password 12 or more characters long, with numbers, letters, and symbols that you memorize and use for all of your accounts. The problem with that is that if a hacker discovers your password in one account, they can access any account that you own. And cyber criminals will try your password on other accounts that you own. This is why cybersecurity professionals recommend using a different password for each account.

So, you need s separate password for each of your accounts that you own that you cannot remember. What to do?

Use a password manager. Password managers are apps that store your passwords for each of your accounts. They can reside on your smartphone, laptop, and desktop so that you can have access to your passwords just about anywhere. The information in a password manager is encrypted so that no one other than you can access it.

Password managers often offer other features that make it easier to use passwords. They can generate new passwords when you need a password for a new account or when you change passwords. They can fill in your password when you sign into your account. They also can synchronize passwords among several of your devices.

There are several password managers on the market. Some you pay for and others that are free. Check the “PC Magazine” links below for resources that evaluate the password managers that are on the market.

With a good password manager and MFA on your accounts, you improve the security of your personal information. You make it difficult for a cyber criminal to gain access to your accounts. And if someone does learn your password, they cannot access your account with MFA.

 

 

South Snohomish County Crime Watch:

 https://ssnoccrimewatch.blogspot.com/2022/10/cyber-security-multifactor.html.

 

Norton:

https://us.norton.com/blog/emerging-threats/password-attack#

 

KFMB CBS8, San Diego:

https://www.cbs8.com/article/news/verify/people-with-shorter-passwords-should-change-them-immediately/509-1e4a5b50-3692-4bb8-b17b-ff77a2e63826

 

 

National Cybersecurity Alliance:

https://staysafeonline.org/online-safety-privacy-basics/what-about-password-manager-risks/

 

Ask Leo:

https://askleo.com/are_password_managers_safe/

https://askleo.com/responses-to-your-three-common-password-manager-objections/

 

PC Magazine:

https://www.pcmag.com/picks/the-best-password-managers

https://www.pcmag.com/picks/the-best-free-password-managers

 

Tuesday, March 8, 2022

CYBER DEFENSE – Can Russia’s Attack on Ukraine be Exported to the U.S.?

The conflict in Ukraine seems so far away from our homes here in Western Washington. While our federal government has vowed not to send American troops or airmen into Ukraine, it has shown its disgust with the Russian invasion through a variety of sanctions in solidarity with its NATO and European allies along with other allies around the world. But the pledge to keep our military away from combat would keep the conflict away from American shores, or at least one would think so.

However, the Cybersecurity & Infrastructure Security Agency (CISA) has been warning businesses and U.S. government entities since at least late last year, that a potential exists of cyber-attacks related to the Russian attacks on Ukraine. Its warnings are primarily targeted to the businesses and utilities such as the electric grid, transportation, and financial services along with governmental entities where disruption could affect our daily lives. While not related to Ukraine, last May’s ransomware attack on Colonial Pipeline shows how cybercriminals could cripple an essential utility.

A cyber threat could come in two forms:

·         Spillover from an attack that targets a specific entity, not even in the U.S., but with a cyber weapon that has self-propagating properties that can spread beyond the intended target.

·         An attack in retaliation for sanctions where Russia, or its client cybercriminals, target Western organizations. Financial services could be a prime target in a tit-for-tat scenario. Or it could be another unanticipated surprise sector that is attacked.

Much of the action that needs to be taken rests with business and government. People who work in business or government need to heed the procedures set up by their IT departments to protect them from an intrusion or cyber-attack. For the rest of us there are a few things that will help protect our information and our accounts. They are actions that cyber security professionals have been recommending for some time. If you are not doing them, now is a good time to start.

·         Apply multi-factor authentication (MFA) to your accounts. CISA says that multi-factor authentication can reduce the likelihood of being hacked by 99%. Use MFA on your email, social media, online shopping, financial services, and any other accounts you consider sensitive.

·         Be sure your software is up to date. Turning on automatic updates makes this easy.

·         Think before you click. CISA says that more than 90% of successful cyber-attacks start with a phishing email. Be wary of links in emails you receive and websites that you go to.

·         Use strong, unique passwords on your accounts. Use a password manager or vault, to securely keep track of your passwords.

If you are doing these things, you are probably in reasonable shape to weather a potential cyber-attack.

 

 

 

CBS:

https://www.cbsnews.com/news/how-far-will-putin-go-and-how-far-will-america-go-to-stop-him/

 

Cybersecurity & Infrastructure Security Agency (CISA):

https://www.cisa.gov/shields-up

 

Krebs on Security:

https://krebsonsecurity.com/2022/02/russia-sanctions-may-spark-escalating-cyber-conflict/

 

Federal News Network:

https://federalnewsnetwork.com/cybersecurity/2022/03/ukraine-russia-conflict-puts-cyber-warfare-front-and-center/

 

South Snohomish County Crime Watch:

https://ssnoccrimewatch.blogspot.com/2022/02/multifactor-authentication-new-way-to.html

 

Ask Leo:

https://askleo.com/phishing_how_to_know_it_when_you_see_it/?utm_source=newsletter&utm_campaign=20191217&utm_medium=email&utm_content=featured

 

https://askleo.com/practical-password-techniques/

Wednesday, October 21, 2020

SNOHOMISH COUNTY SHERIFF’S OFFICE- Protecting Your Child’s Identity While They are Distant Learning

 

The latest issue of the Snohomish County Sheriff’s Office is now available. This issue’s subject is protecting your child’s identity while they are distant learning.

 

Snohomish County Sheriff’s Office:

https://www.snohomishcountywa.gov/ArchiveCenter/ViewFile/Item/6559

 

Wednesday, April 22, 2020

COVID-19 PHISHING SCAM- Trickbot

As some people have migrated to working from home in response to COVID-19, cyber criminals have been targeting them for their personal information and for the proprietary information of the companies that they work for.

The cyber criminals are using a piece of malware called Trickbot to harvest this information. Trickbot originally started out collecting banking information, but has been expanded to keylogging, ransomware, and other functions.

The Microsoft Security Intelligence team has warned that it has seen hundreds of emails purporting to be related to COVID-19 medical advice and testing. The emails contained attachments that had the ability to install Trickbot onto a computer. Other reports said that the emails claimed to be from volunteer and humanitarian groups offering COVID-19 testing or more information about the virus by downloading an attached document.

Other phishing strategies have included sending a text message that says, “Your phone has been monitored as being near a phone of someone who have been diagnosed with COVID-19.” The text invites you to click a link to get more information. 


Here is a picture of a phishing email intercepted by Microsoft:







Cyber security professionals as well as government agencies such as the Federal Trade Commission and the FBI warn that organizations such as the World Health Organization and the Centers for Disease Control do not send unsolicited emails to the average citizen.

Also, cyber security professionals are especially concerned about employees working from home using the internet. They do not want company secrets to be compromised nor do they want employees’ personal information stolen by cyber criminals. They recommend,



·         Use multifactor identification whenever possible.

·         Do not use devices with access to your business network for personal use.



KIRO TV:
https://www.kiro7.com/news/local/microsoft-hackers-targeting-people-working-home/OQPVIRG66JF5LA4EGUIXYQ6BGE/


Microsoft:
https://twitter.com/Microsoft/status/1248713417655037955



ZDNet:
https://www.zdnet.com/article/trickbot-malware-is-using-these-unique-macro-laced-document-attachments-with-a-coronavirus-theme/


Malwarebytes Labs:
https://blog.malwarebytes.com/detections/trojan-trickbot/




Sunday, April 5, 2020

COVID-19 CYBER SECURITY- FBI Issues Warning about Zoom Breaches


With orders to stay home, more and more people are using teleconferencing services for work or to socialize with family and friends from afar. While public health officials call it “social distancing” what they are asking us to do is “physical distancing”, staying physically well away from each other to prevent the spread of COVID-19. Keeping contact with work colleagues, family, and friends is important to ensure that we keep our sanity while we are physically apart.

Teleconferencing can be an important tool to surviving this coronavirus. From press reports, it appears that people have been flocking to teleconferencing apps and services in record numbers. Many for the first time. 

Security has become an issue for one of these teleconferencing services. The FBI office out of Boston has issued a warning that the FBI has received several reports of video-teleconferencing (VTC) sessions being disrupted by pornographic and/or hate images and threatening language. The service receiving the most attention for this activity is Zoom, so the activity is called “Zoom-bombing.”

The FBI alert cited two instances in the New England region, while others have been reported by the press. In one instance in late March 2020, a Massachusetts-based high school teacher conducted an online class when someone dialed into the session then yelled profanity and shouted the teacher’s home address. During another Zoom session, conducted by a second Massachusetts-based school, someone accessed the session then displayed swastika tattoos on the video.

Reports of similar incidents along with skyrocketing use of the Zoom app and services have revealed serious security flaws in Zoom. The CEO of Zoom,
Eric Yuan, noted in a blog post on April 1, that the growth of users went from
10 million daily users in December 2019 to 200,000 million users in March 2020. He also noted that the platform was designed for enterprise customers, not for enterprise and consumer use. Mr. Yuan listed a variety of measures that the company was doing and intended to do to enhance the security of his product.

Things that you can do to protect your session from intruders disrupting your meeting include:

·       Allow only signed-in users to join.
·       Lock the meeting.
·       Set up your own two-factor authentication.
·       Mute participants to control disruptive noise.
·       Do not share links to meetings on social media.
·       Use a waiting room to control entry of your participants.

Securing your business meetings or your private conversations via teleconferencing is an important function that you and the software that you use needs to address. When using a teleconferencing app take some time to learn how it handles security.

FBI:

The Seattle Times:

Zoom:



Here are some alternatives to Zoom,

Windows Central:


Monday, December 23, 2019

INTERNET OF THINGS- Strangers View Families Through Security Cameras


In the past week there have been press reports of strangers breaking into Ring accounts and viewing the insides of homes. In some cases, the hackers talked to a child and to a couple of dogs.

One story has a video of a young girl in her bedroom being talked to by a male voice through the camera in the room. Another story has video of two dogs lounging on a couch and a voice trying to get them to get up off of it.

Ring cameras have been receiving publicity on social media with videos of porch pirates stealing packages from front porches. Some homeowners have purchased Ring and other cameras for use indoors, in children’s bedrooms or front rooms to allow homeowners and parents to monitor what is going on in their homes. Over the past few years, videos have been posted showing burglars inside homes stealing items.

Having cameras inside can help with security to confirm that someone is in your house if the alarm goes off. They also help to monitor small children when they are in their cribs in their rooms. However, all sense of security is lost if someone breaks into your cameras and can observe your possessions and see your family moving around in your house. And talking to your children gets even creepier yet.   

While press reports have used the term hacked or breaking in, Ring, in its blog, points out that the recent incidents were not due to an intrusion or compromise of Ring’s computer systems. Many of the hackers may have obtained the usernames and passwords of Ring accounts outside of the Ring’s servers such as from databases in the dark web.

Ring recommends that its customers do the following:

·       Enable two-factor authentication to access your account.
·       Add shared users to your account instead of simply giving them your login information.
·       Do not use the same password for more than one account.
·       Create strong passwords that have a mix of letters, numbers, and characters. Some cyber security professionals recommend passwords with 12 characters or longer. A password generator can help create strong passwords.

Internet of Things (IoT) such as cameras and thermostats help us have a more secure and convenient life. In the early years of IoT, manufacturers have not designed good security measures into their devices. Both manufacturers and their customers should observe the best and most recent security practices. IoT manufacturers should make security robust and easy for customers and customers should practice good security as they use any IoT device.

The Seattle Times:

KIRO TV:

Ring:


Saturday, September 29, 2018

FACEBOOK- Hackers Exploit Facebook Bug


Yesterday, Facebook reported a breach to their web service through a feature called “View As.” The feature allows users to view their profiles as they appear to other people. The bug in this feature allowed hackers access to “access tokens.” The tokens act as digital keys allowing users to log into their accounts without needing to re-enter their password.

Actions that Facebook says it took yesterday were:



·         It removed the “View As” feature until it can remove the bug allowing access to hackers.

·         It reset the access tokens of 50 million accounts that the company knew were affected by the breach.

·         It also reset the access tokens of another 40 million accounts that may have been affected.



Another potential vulnerability because of this hack is the ability to log into other web sites or apps using your Facebook identity. Facebook says that it has not seen any evidence so far that the hackers were exploiting this vulnerability. As a precaution, it did invalidate the access for third-party app for the 90 million affected or potentially affected accounts.

Facebook says that there is no need to reset your Facebook password. The Identity Theft Resource Center (ITRC) does recommend resetting your Facebook account password. ITRC also recommends that you change the passwords to any apps that you have connected to Facebook and that you revoke permission for Facebook to connect to those apps.

For more information, check out these links,



Krebs on Security:




Identity Theft Resource Center:







Friday, March 2, 2018

CYBERSECURITY UPDATE- How to Tell if Your Computer has been Hacked


Over the last few years police and consumer protection agencies have been warning the public about phishing emails and clicking on links of unknown organizations or businesses. The fear is that by clicking on those links that some sort of malware that can collect your personal information will be downloaded onto your computer.

Sometimes it can be hard to tell if an email is suspicious. The cautious thing to do is to avoid clicking on anything in that email. But you might click because you are in a hurry, or do not pick up on warning signs. It can happen to anyone.

So how do you know if your computer has been hacked? Here are some signs to look for.



·         You send spam to your friends in your address book. This could be because malware has been installed in your computer. Or a hacker has gained access to your email account and is using it to distribute spam. Hackers do not need malware to have access to your email address book, they can gain access over the web. Let your friends know not to click on any links to spam emails from your email address. Also, immediately change your password to your email account.

·         You have been locked out of your user accounts. Notify the online service(s) that you think you have been hacked. Immediately change your passwords. Also, run your antivirus/malware software to try to remove the malware.

·         Your antivirus software no longer works. This can be due to a technical problem or malware has disabled your antivirus software. For those who use Windows computers, Microsoft offers its free, downloadable “Safety Scanner” that you can find here:  https://www.microsoft.com/en-us/wdsi/products/scanner

·         Your computer has new software installed. But you do not remember installing any software or apps. The software automatically runs when you start your computer. It may hog your resources, slow down your computer and repeatedly ask permission to pass through your firewall. You can check out suspicious software by downloading Microsoft’s “Process Explorer” at this link: https://docs.microsoft.com/en-us/sysinternals/downloads/process-explorer.

·         Malicious pop up ads show up on your screen. Malware could have been installed in your web browser. Check to see if your browser has toolbars that you do not remember installing. Remove them then run your anti-malware software.

·         Your network activity has increased dramatically. If you get warnings from your ISP that your internet data has exceeded its limit you may have malware that is accessing the internet for its own purposes.



The easiest solution to most of these problems is to run your anti-virus/anti-malware software. You should have your antivirus set to automatically update and to run in the background. Other hacking problems may have nothing to do with malware but may have been the result of stolen personal information. In those cases, change your password to ensure that you have control over affected accounts.

Check out the following links for more information.



Windows Central:




Ask Leo:






           


Thursday, October 19, 2017

OCTOBER- Cyber Security Awareness Month


October is Cyber Security Awareness Month. Cyber Security is important for our national security, our business security and for each of us for our personal security. Over the past few years there has been more publicity about online fraud, scams, and identity theft. Keeping your computer devices (PC, laptop, tablet, smartphone, IoT device) secure should be included in your plan to protect yourself from scams and fraud. Hackers can enter your computer(s) through a variety of means to gather your sensitive personal information.

An example is the KRACK vulnerability that was recently announced. This is a vulnerability that was discovered in the basic WPA2 security protocol that is used in modern modems and routers. The vulnerability could allow a middle man attack when the attacker is within range of a Wi-Fi connection. That could be someone at a coffee shop, in a nearby office or apartment unit, or in close proximity of your house. This article from Leo Notenboom should help you decide if you need to take action and if so, what action to take:

Ask Leo:


The KRACK vulnerability points out how we have become dependent on Wi-Fi access to the internet. We use Wi-Fi in our homes, it’s easier to hook up than rewiring the whole house. We also use Wi-Fi on the go when we are shopping, traveling, or hanging out with our friends.

Many cyber security experts discourage usage of open Wi-Fi when conducting online purchases or accessing financial accounts. The Department of Homeland Security’s Stop. Think. Connect. Campaign recommends that you take the following steps to protect your online accounts:



·         Use two-factor authentication wherever possible. In two-factor (or stronger) authentication, when you login to your account, the organization holding your account sends you a code via text message or email that you also enter in addition to your use ID and password. This extra step helps assure the organization that you are really you.

·         Make strong complex passwords.

·         Use unique passwords for each of your accounts.

For more tips on how to protect your information on computer devices go to,



Stop.Think.Connect:





Sunday, March 5, 2017

CYBER SECURITY- Is Someone Watching You Through Your Security Camera?


The beauty of the modern age is that you can check out your home when you are away through security cameras over the internet. And if you have a baby cam, you can see what your child is doing while you are in another part of the house.

However, if your security camera, baby cam, or web cam are connected to the internet, strangers have the capability of looking into your home through your own equipment.

According to press reports, there is at least one website, that is based in Russia, that broadcasts live video from unsecured or poorly secured web cams from around the world. Reports say that the web site claims its purpose is to publicize the problem of poorly secured web cams. But people who might have nefarious purposes can take advantage of this web site. And this does make one think that there could be people who troll for unsecured cameras online that do not advertise their activities.

The best way to protect yourself from someone intruding through your security web cam or baby cam is to change the password for the camera to a strong password like you would on your financial or online shopping accounts. The best time to change the devise’s password is when you buy a security camera or baby cam. Look up the way to change the password in the device’s manual and then change the password to a strong password. If there is not a method to change the default password, return the device to the retailer and find one that allows you to change the password.

Also, some cyber security experts recommend securing your router also so that it has a strong password that is not a default password. A secure router will help keep any device that connects to the internet through your router. This includes your PC, any laptops, tablets, smart phones, or newer Internet of Things (IoT) devices. For information on how to change a router password, watch this very good video:

Ask Leo!




KIRO TV, Jesse Jones:


CNN:





Sunday, February 26, 2017

CYBERSECURITY- Some Tips for Tax Time


Keeping your PC, laptop, tablet or smartphone secure is just as important during tax season as it is throughout the rest of the year. Scammers and fraudsters will try to steel your money and your ID online by:



·       Filing a fraudulent tax return in your name. If they file it first, then the IRS will reject your filing because it only accepts one tax return per Social Security Number.

·       Phishing and malware. Cybercriminals will try to get you to click on a link or on an attachment to install malware that collects your personal information.

·        IRS scam. Scammers will call or email you posing as IRS agents to get you to pay them for a fake tax bill.

·        Tax preparer fraud. Most tax preparers are honest and has an IRS Preparer Identification Number. There are those who are unscrupulous. Be sure that the preparer that you use has an IRS Preparer Identification Number.



For more information about how you can protect yourself from cybercrime, go to this link:



Stay Safe Online/ITRC:





Friday, January 20, 2017

MICROSOFT- Recruiting Teens for its Council for Digital Good


Microsoft is recruiting teens between the ages of 13 to 17 to advise it in how teens use the internet, what they are doing online, who they connect with, and what they share and learn.

The motivation for this effort is to find ways to effectively reduce risks that teens may encounter while using the internet and to educate youth in what they can do to mitigate those risks.

The Council for Digital Good will consist of 12 to 15 teenagers who will attend a two-day summit in August 2017 in Redmond, WA where they will participate in discussions on internet risks and interact with Microsoft staff. Parents will have their own “parent track” during these meetings. Council members will be asked to return to their schools and communities to promote “digital civility.” This is a one year pilot program.

Microsoft offers the following to council members who sign up for 1-year or 18-month terms:



·         Paid travel for Council member and one chaperone for the on-campus summit.

·         Opportunities for college and other recommendations, mentoring and personal/pre-professional growth.

·         After serving on the Council, youth may be eligible and considered for “internships” or other posts are various third-party organizations.



For those teens interested in applying, go to  https://www.microsoft.com/about/philanthropies/youthspark/youthsparkhub/programs/onlinesafety/cdg/. The deadline for applications is March 1, 2017.

The following link has information about online safety:


Digital Trends: