Posts

Do you have one of Vulnerable to the Top 8 Most Exploited Vulnerabilities?

Image
The Most Exploited Vulnerabilities in 2016-2019 as Reported by the FBI. It probably won't surprise you that 7 of the 8 most exploited software vulnerabilities are to be found in Microsoft products. Their widespread use across organizations and institutions makes them an ideal candidate for cybercriminals. According to U.S. Government technical analysis, malicious cyber actors most often exploit vulnerabilities in Microsoft's Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets. But also Adobe Flash Player makes it to the list. Older Unpatched Systems are Vulnerable for Cybersecurity Attacks   A recent report on the most exploited vulnerabilities by the Cybersecurity & Infrastructure Security Agency (CISA) and the FBI listed the most routinely exploited vulnerabilities in the wild. The interesting thing is that most of these vulnerabilities are pretty old, yet cyb...

Four Big Reasons Companies Needing Document Management Today

Image
Today companies face utmost global competition. Like new machines, materials and processes implementation, one has to constantly update documents to prove the operational excellence and help meet quality standards. Document Management software will help you do just that! It automates and manages document control processes, eliminates paper process and can greatly increase company-wide efficiency. •ISO Compliant Document Control System Document Management provides a comprehensive set of document control capabilities for organizing and managing all quality documents, such as Standard Operating Procedures (SOPs), policies and work instructions with complete version history along with CAPA procedures, non-conformance reports, forms and more in a centralized repository. A single, cohesive system for all documents makes the search for and the retrieval of documentation easier. It also ensures that only the current version of the document is ...

Emergency Patch Released for SMBv3 Vulnerability

Image
    Emergency Patch Released for SMBv3 Vulnerability Microsoft released the KB4551762 security update to patch the RCE vulnerability found in Microsoft SMBv3 a couple of days after the flaw was disclosed as part of the March 2020 Patch Tuesday. The Windows SMBv3 Remote Code Execution vulnerability, tracked as CVE-2020-0796 and dubbed as SMBGhost, allows a remote and unauthenticated hacker to execute the arbitrary code on an exposed device. Microsoft stated that: "To exploit the vulnerability against a server, an unauthenticated attacker could send a specially crafted packet to a targeted SMBv3 server. To exploit the vulnerability against a client, an unauthenticated attacker would need to configure a malicious SMBv3 server and convince a user to connect to it." Microsoft originally planned to fix the flaw as part of its March 2020 Patch Tuesday update but pulled the plug at the last minute. Now the tech giant followed up with KB4551762 to fix the SMBGhost...

Microsoft Edge Chromium

Image
New build for high-class performance, Microsoft Edge Chromium, provides the security and privacy users need. New features added to the design to bring the best of browsing. The new layout gives the users the ability to create and custom the way you browse. With the new style of Microsoft Edge Chromium, users can choose what they see whenever they open up a new tab. Privacy is the biggest focus for the new Microsoft Edge Chromium. Users can select what privacy level to allow the browser to track. With Microsoft Defender SmartScreen users can browse in peace because it automatically protects from security issues, phishing, and malicious software. Microsoft Edge Chromium provides users to browse from anywhere on devices on the currently supported operating systems.

Patch Right Now – Microsoft Windows 10 and Server 2016/2019

Image
Anyone running Windows 10, Windows Server 2016 and Windows Server 2019 is "strongly encouraged" to install Microsoft patch right now. Microsoft January 2020 Patch Tuesday fixes 49 security bugs after the US National Security Agency (NSA) discovered a critical bug in the operating system. These 49 vulnerabilities, 7 are classified as Critical, 41 as Important, and 1 as Moderate. Microsoft patched a spoofing vulnerability present in the Windows user-mode cryptographic library, CRYPT32.DLL, on Windows 10, Windows Server 2016, and Windows Server 2019 systems. The vulnerability could allow for remote code execution. In other words, allow hackers to compromise trusted network connections using spoofed certificates to deliver malicious executable code under the pretense of a legitimately trusted entity, commit man-in-the-middle attacks, and decrypt confidential information. For example, HTTPS connections, signed emails and files, and user-mode processes launching si...

Windows 7 Extended Security Updates

Image
Windows 7 Extended Security Updates Users who are still running on Windows 7 operating system, are exposing their computers to critical vulnerabilities. Is your business prepared for Windows 7 End-of-Life? Running an unsupported operating system is not an option anymore. Data breaches, systems hacks, and vulnerabilities are very common, and ransomware can bring a business to a halt and every business is a potential risk target. With an unsupported operating system, a business is easier to exploit, leaving the network very exposed. It is best and simple to upgrade to Windows 10 latest version. It has a long life still, and that means many years of support from Microsoft. Organizations will need to anticipate the cost of purchasing the new operating system, but also of their business-critical software to ensure compatibility. As many business and enterprise users are not able to switch from Windows 7 before the End-of-Service, Microsoft intro...

Microsoft messes up another Windows 10 Update

Image
Microsoft messes up another Windows 10 Update by giving it to the wrong users. Microsoft pushes another Windows 10 update that wasn't with mistakes or bugs but delivered to the wrong machines and users. The update implements "quality improvements on Windows Autopilot configured devices". Windows Autopilot now is used to set up devices in businesses. Windows Autopilot is not installed on Windows 10 Pro or a later version when the device is not registered or configured for Windows Autopilot deployment. Windows Autopilot has never been offered to users operating on Windows 10 Home. The update was pushed on Windows 10 Home and Windows 10 Pro even though they are not machines registered for Autopilot deployment. As a reminder, if you see an update for Autopilot on Windows 10 Version 1903 displayed as an update on your Windows 10 Home or Pro machine, you do not have to download it. If you have already downloaded the update, it does no harm to your machine, it jus...

Critical Security Updates for Adobe

Image
Adobe releases critical security updates for the month of October. Adobe has released critical security updates that contain multiple vulnerability advisories in covering Adobe Experience Manager, Adobe Download Manager, Acrobat DC and Acrobat Reader DC. Adobe released security updates to patch a total of 82 security vulnerabilities across various Adobe products. Most of the vulnerabilities were discovered in Adobe Acrobat and Adobe Reader. Adobe Acrobat and Reader allow users to manage, view, edit and print files in PDF format. With successful exploitation, an attacker can gain control and affect a system that later depending on the privileges the attacker has gained can install programs. The attacker can make changes, view, or delete data, or create new accounts with full user privileges. 

Are you prepared for Office 2010 End of Support?

Image
Are you prepared for Office 2010 End of Support? Microsoft announced that extended support for Office 2010 will end on October 13, 2020, at the same time recommending organizations to migrate to Office 365 ProPlus or Office 2019. In 2020, Microsoft will end support for several applications, including Windows 7 and Office 2010.  By continuing to run Office 2010 after October 13, 2020, your business will become vulnerable to security risks as will no longer receive security and feature updates. Microsoft will no longer provide any support for bug fixes for the issues that could be discovered. Microsoft will also not provide security fixes for new vulnerabilities or technical support for issues beyond the end of support date. Since the support for Office 2010 will be coming to an end it is best to start exploring other options. Some of the options to consider are the latest versions of Office such as Office 365 ProPlus or Office 2019.

Windows 7 End-of-Life

Image
Are you prepared for Windows 7 End of Life?   Windows 7 is due to reach of End of Life (EOL) on January 14th, 2020, but a large number of the world's computers, most in corporate environments, are still running the nine-year-old system. Microsoft ended mainstream support for Windows 7 on January 2015, with extended support running until January 14, 2020. If any business fails to upgrade from Windows 7 will be saddened to hear that they will have to pay high fees for further support from Microsoft. This End-of-Life means no more bug-fixes, security patches or new functionality, making any user personal or enterprise more vulnerable to malware attacks. Microsoft will continue to offer support for the users still operating on Windows 7 to upgrade to its Windows 10 OS, but it will cost money. There is nothing wrong with continuing to use Windows 7 after its End of Life. You should know that using an outdated operating system will make your computer vulnerable to cyberatta...

Microsoft Patch Tuesday

Image
Microsoft Patch Tuesday Audit Microsoft released its September Patch Tuesday 2019 software updates and two advisories to address a total of 79 vulnerabilities in its Windows Operating sytems and other products. Microsoft resolved a total of 79 unique vulnerabilities this month, including two actively exploited and three publicly dislosed vulnerabilities, all of which affect your Windows operating systems. As part of Tuesday Patch, Microsoft has fixed 4 vulnerabilities taht could allow remote code execution if were to connect to a malicious server.

Windows 10 Version 1703 End of Life

Image
Windows 10 Version 1703 End of Life The Windows 10 version 1703 Enterprise and Education editions will reach End of Life on October 9, 2019, and you can't pay for patches either. The Home, Pro, Pro for Workstations, and IoT Core Editions of Windows 10 version 1703 reached End of Service last year, on October 8, 2018. There is no extended support available for any edition of Windows 10, version 1703 and will no longer be supported after October 9, 2019. That means no more monthly security updates containing patches for the latest security threats. The announcement was published to alert Windows 10 users of version 1703 to update their devices to the latest version of Windows as soon as possible. Update to version 1903 before version 1703 reaches its end of life this October. Let MJJT Consultants guide you with a walk-through for updating to the latest stable version of Windows. MJJT staff has the expertise to help all users still on Windows 10 version ...

Firefox 69 Update Fixes Critical Vulnerabilities

Image
Firefox 69 Update Fixes Critical Vulnerabilities Mozilla has released the latest Firefox 69 browser update version, which will block thirdparty cookies and crypto miners and disables default support for Adobe Flash Player. The Firefox 69 browser update comes with a handful of security patches, which address one critical and eight high severity vulnerabilities. The critivalvulnerability CVE-2019-11751 enables malicious code through command line for Firefox browsers on Windows OS. As quoted by Mozzilla "logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder."

Patching new wormable vulnerabilities with your Microsoft Remote Desktop

Image
Patching new wormable vulnerabilities with your Microsoft Remote Desktop Microsoft is urging users to patch a series of critical, BlueKeep-like vulnerabilities in Windows that could be used to spread malware and affect as many as 800 million machines. Microsoft released a set of fixes for Remote Desktop Services that include two critical Remote Code Execution (RCE) vulnerabilities, CVE-2019-1181 and CVE-2019-1182. These two vulnerabilities are ‘wormable’, meaning that any future malware that exploits these could propagate from vulnerable computer to vulnerable computer without user interaction. The affected versions of Windows are Windows 7 SP1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows 8.1, Windows Server 2012 R2, and all supported versions of Windows 10, including server versions.  Microsoft not only released these 2 advisories, but they also released updates for 94 vulnerabilities. Of these vulnerabilities, 26 are classified as Critical, meaning ...

Password Strength - How Secure is Your Password

Image
Today we will be talking about the importance of password strength. Studies show that changing a password every 3 months is good for internal protection in the office. In today’s world you need a strong password because even an amateur hacker can get into your email, documents, and other personal information. Most individuals use the same weak password for their email, banking, personal computer, work computer, and social networking. This makes it easy for hackers to attack. The first thing they may attack is your social networking account, I.E. Facebook or twitter. These websites have lighter security set up than a bank or your work office would. Once the hacker figures out the password to your Facebook or Twitter account they will be able to obtain all of your information by hacking into your bank account or your personal computer. This is where your life will get difficult because it is often hard to recover from identity theft. The key to picking a strong password is to use 1...

Routers VS Firewalls Which one are you missing?

Image
The most critical aspect for business security is the security of the network used to access the internet. Most businesses have some type of router, like a Linksys, which blocks some incoming files, but allows all files out. What occurs commonly is that a hacker or malware sneaks in through one of the opened ports, and then takes control over the entire network. Old routers cannot maintain and protect large amounts of bandwidth. The best way to protect your network is to get a firewall which collaborates with your router. The firewalls restrict the opening and closing of all ports on the entire network. A professional is required to set up this software. Ports that have to constantly be open will still have that capability, but the firewalls will filter out malware or viruses. This better ensures your security. We make sure that your firewalls log all activity on the network and ensure that the latest firmware filters are up to date. Expensive firewalls such as Barracuda NG Firew...

New Years Resolution For Your Business

Image
It’s that time of year again. The time has come again to review your networks and computers so you can understand your risk of disaster. We have our own list of 10 questions you should ask yourself concerning your business. Are you monitoring your windows updates? And how are they affecting your computer(s)? Do you have security software set up on your computers and servers (antivirus, firewalls)? Have you updated your computer to Windows 7 or better? Do you have Windows 2008 r2 server or better running on your network? Do you backup all your data through images on your computer and server? Does your network have a local administrator account with a password? Do you have all your product keys and manage your versions of software? Is your emergency handbook and kit up to date? Do you have offsite backup for your critical files and do you have access to them? Do you have professionals who certify and review your network on a regular basis? After all those questions, do y...

Cloud Computing: Understanding New Technology

Image
For a new start up business, this is a great way to begin without needing a large amount of start-up cash. For larger companies, this can come a bit costly for a number of different aspects, but mainly the amount of information needed to be transferred.  Nowadays everyone is trying to use cloud computing in their marketing description for their software and hardware. But honestly cloud computing is still a new technology, and many are still not clear exactly what it does or how secure it really is. Basically it comes down to the storage of computer files at a remote site. There aren’t any industry standards or clear definition of what qualifies a company to offer cloud computing service. The best definition of this type of service is having local data on your own server be recitation for two other sites and therefore anyone can access it anywhere in the world.

Fax to Email, the Future of Document Sending

Image
In this edition of the MJJT Consultants IT blog we are going to discuss a better way to send documents over the wire. Fax to email is a new technology that enables you to link your business fax number to an email address and then converts all faxes to a PDF file. This in turn will create a more efficient work environment. Email is faster and more direct method of document transfer than faxing. Using fax to email will also make for a greener environment. Some faxes simply do not need to be printed. It is very often that offices will get a “junk fax”. It’s just like junk mail or junk email they either get deleted or thrown away. In this case the fax would get thrown away and waste paper. Your business can save money on inventory by not wasting paper but most of all you will save money by not purchasing a fax machine. Fax to email is the way of the future and makes fax machines obsolete. Interested in making your business more efficient and saving money? MJJT Consultants can help yo...

Does your Website have the Three R’s?

Image
In today’s blog we will be discussing the proper way to build your business website and make sure your website is featured high in search results. It is imperative and vital to the success of your business to have a properly built website in today’s rapidly evolving technological world. Does your website have recurring visitors? Is it featured high in search results? The dynamics of a website’s construction are extremely vital to its success and your business’s success. With an increased rate of recurring visitors your site will have a better Reputation. This will feature your website higher in search results, hence making your business more popular. Reputation makes all the difference on the internet. Retention is another important concept of internet marketing that your website should possess. Studies show that engaged clients will bring in 1.7 times more customer revenue than the average customer. This means that if your customers are recurring visitors then your website has th...