HIPAA Simple Security Risk Assessment
Advanced Persistent Threats and Zero Day Exploits get a lot of press these days. I am reprinting content from the Office for Civil Rights (OCR) in the US Department of Health and Human Services. Advanced Persistent Threats and Zero Day Exploits An advanced persistent threat (APT) is a long-term cybersecurity attack that continuously attempts to find and exploit vulnerabilities in a target’s information systems to steal information or disrupt the target’s operations.1  Although individual APT attacks need not be technologically sophisticated, the persistent nature of the attack, as well as the attacker’s ability to change tactics to avoid detection, make APTs a formidable threat. APTs are a serious threat to any information technology (IT) system, but especially those that are part of the health care field.  Healthcare services ... Read More
February 7, 2025Mark Anthony Germanos
Still vulnerable to cyber attacks and ransomware
Malvertising is the newest attack on your identity. Yes, you read that right. Internet thieves have a new tool against unsuspecting victims: malvertising. Take the hostility of malware and the persuasiveness of advertising, put them together, and you get malvertising. Our friends at Respond Software created this short video for us: Wikipedia reports this overview of malvertising. Websites or web publishers unknowingly incorporate a corrupted or malicious advertisement into their page. Computers can become infected pre-click and post click. It is a misconception that infection only happens when visitors begin clicking on a malvertisement. "Examples of pre-click malware include being embedded in main scripts of the page or drive-by-downloads. Malware can also auto-run, as in the case of auto redirects, where the user is automatically taken to a ... Read More
February 7, 2025Mark Anthony Germanos
Save money. Do not fall for this rip off.
Phishing attackers have found a new avenue: bogus job offers A series of phishing campaigns are targeting companies in various industries with phony job offers using direct messages on LinkedIn, according to researchers at Proofpoint. The attacker initially makes contact by sending an invitation to the target on LinkedIn with a short message regarding job offers. Within a week after the target accepts the invitation, the attacker will send a follow-up email with either a link or a PDF attachment that contains embedded URLs. These links take the target to a spoofed version of a real staffing service, which forces the download of either a Word document or a JScript loader. This document or loader will result in the installation of a JScript backdoor known as “More_eggs.” More_eggs ... Read More
February 7, 2025Mark Anthony Germanos