Newsletter

Network Monitoring News – Jan 2017

W2’s

The IRS is warning of a new series of phishing attacks targeting your finance, payroll and human resource departments. Some versions of this scam are requesting wire transfers as well. Employers should consider creating an internal policy, if one is lacking, on the distribution of employee W-2 information and conducting wire transfers.

Here’s how the scam works: Cybercriminals use various spoofing techniques to disguise an email to make it appear as if it is from an organization executive. The email is sent to an employee in the payroll or human resources departments, requesting a list of all employees and their Forms W-2. This scam is sometimes referred to as business email compromise (BEC) or business email spoofing (BES).

Malware being less suspicious

For the last year malware writers were using javascript files to distribute malware. Attackers have recently switched to less suspicious attachment types, most notably .LNK and .SVG files. LNK files are files for shortcuts or links to executable files. In this instance, ransomware/malware files.

SVG files are image files. Unfortunately this file format is allowed to contain javascript which of course means executable content is only an image preview away.

Those that have ContentCatcher are already protected with FileWall. The ContentCatcher team has added .lnk and .svg attachments hidden within zip files to the default drop list for your protection.

IOT

The Internet of Things is gaining ground. Many items purchased today have the ability to connect to the internet. Sadly, most of them have very little in terms of security but this is slowly changing. Now, we face something entirely different, privacy concerns. Recently police were trying to access records of an Amazon echo device to help solve a crime. In this particular case, an IOT water heater was also used to compile evidence based on how much water was used with the prosecutor saying, it was enough to wash away evidence. Thinking of business and IOT devices, it is extremely important to make sure these types of devices are protected. Attackers are gaining access and using the information found within to gain a stronger foothold, phish users or whatever else they have yet to think of for financial gain.

Ron Samson

Share
Published by
Ron Samson

Recent Posts

SOC Alert Fatigue: How to Reduce Noise Without Weakening Detection Coverage

Cut SOC alert fatigue by prioritizing business risk, correlating duplicate signals, and tuning false positives—so…

4 hours ago

Build a Practical Security Monitoring Roadmap for a Lean IT Team

Build a lean security monitoring roadmap around 5–8 high-risk scenarios, minimum viable telemetry, alert ownership,…

57 years ago

Ransomware Early Warning Signals Your SOC Should Detect Before Encryption

Detect ransomware staging before encryption using identity, endpoint and backup signals to catch credential abuse,…

1 day ago

What to Look for in a Managed Security Provider When You Already Own the Tools

Make your SIEM, EDR and firewall stack deliver outcomes: assess provider depth, 30/60/90-day operations, detection…

57 years ago

Security Monitoring for Compliance: What Auditors Expect Versus What Actually Reduces Risk

Turn compliance logs into faster threat response. Learn how tuned detections, triage and proven escalation…

57 years ago

How to Reduce Security Alert Fatigue Without Missing Real Threats

Turn hundreds of daily alerts into faster, risk-based decisions with asset context and correlation that…

57 years ago