news

20 Jul 2024 - Microsoft Global Outage. What happened?

 

Turns out the issue was actually nothing to do with Microsoft, but a cybersecurity firm called CrowdStrike, which provides software to a wide range of industries, including aspects of Windows Defender, the security software built into Windows.

 

CrowdStrike issued an update to one of their technologies called Falcon Sensor which was a low-level driver that sits close to the core of Windows. Unfortunately, this driver was faulty and immediately started to cause Windows machines around the world to crash, including Microsoft’s own machines used to run it’s cloud services like Azure and 365.

 

My takeaway on this is surprise that Crowdstrike were permitted to directly issue updates to windows PC’s and not have to go though Microsoft first for vetting/testing etc. A situation that many indeed change after this debacle

 

23 Jun 2023 - Apple fixes actively exploited zero-days in iOS, macOS and Safari

The bugs allowed the installation of Triangulation spyware on iPhones through iMessage zero-click exploits
Apple has released new updates for iOS, iPadOS, macOS, watchOS and Safari browser to resolve a series of security vulnerabilities that the company said were actively exploited in the wild.

As part of these updates, Apple has addressed three newly discovered zero-day bugs that allowed for the installation of Triangulation spyware on iPhones through iMessage zero-click exploits.

This week, Kaspersky released a report providing comprehensive details about an iOS spyware component used in a mobile surveillance campaign dubbed "Operation Triangulation."

Although the campaign has been active since 2019, the identity of the threat actor responsible for the campaign remains unknown.

"The implant, which we dubbed TriangleDB, is deployed after the attackers obtain root privileges on the target iOS device by exploiting a kernel vulnerability. It is deployed in memory, meaning that all traces of the implant are lost when the device gets rebooted," Kaspersky said in its report.

"Therefore, if the victim reboots their device, the attackers have to reinfect it by sending an iMessage with a malicious attachment, thus launching the whole exploitation chain again. In case no reboot occurs, the implant uninstalls itself after 30 days, unless this period is extended by the attackers."

Full article @ Computing.co.uk

27 Jun 2023 - Microsoft warns of rise in credential stealing attacks by Russia-linked group

Midnight Blizzard/Nobelium/Cozy Bear threat group is focusing on governments, IT service providers, defence industry, among others
Microsoft warned last week that it has detected a notable increase in credential attack activity, pointing to the notorious threat actor known as Midnight Blizzard as the orchestrator.

What distinguishes these attacks is the clever use of residential proxy services to hide the source of their malicious activities, the software company said.

The threat actor Midnight Blizzard, formerly identified as Nobelium, has been associated with Russia and is also monitored under various names such as APT29, Cozy Bear, Iron Hemlock and The Dukes.

Full article @ Computing.co.uk

02 Jun 2023 - Windows 11 adoption decelerated in May

Windows 10 continues to maintain a significant lead over the latest version of the operating system
Despite Microsoft's efforts to enhance Windows 11 with a variety of new features, the majority of people are still opting to stick with Windows 10.

According to StatCounter's latest report on the market share of different desktop Windows versions, Windows 10 continues to hold its position as the predominant operating system among Windows users. Approximately 71.9% of all customers still rely on Windows 10 for their daily computing requirements.

Windows 11 experienced a slight slowdown last month, with a market share of 22.95%, showing a small decrease compared to April 2023.

In April, Windows 11 reached its peak market share of 23.01%, marking a notable increase of 2.06 percentage points compared to March 2023.

The combined share of Windows 10 and Windows 11 accounts for 94.85% of the entire Windows OS market. The remaining percentage is divided among users who are still running older versions of Windows, such as Windows 7 (3.61%), Windows 8.1 (0.72%), Windows 8 (0.37%), and Windows XP.

Full article @ Computing.co.uk

05 Jun 2023 - Gigabyte rolls out firmware update to close backdoor

Updated BIOS code and signature verification process for files downloaded from remote servers
Gigabyte has released new firmware to mitigate the potential security risk posed by a firmware issue affecting over 270 of its motherboard models.

The updates come after researchers at cybersecurity firm Eclypsium identified backdoor-like behaviour on certain Gigabyte motherboards.

It was discovered that the firmware on the identified models triggered and executed a Windows native executable during system startup, which downloaded and executed additional payloads.

Gigabyte has now released firmware updates for a range of motherboard series, including Intel 400/500/600/700 and AMD 400/500/600 series, in order to address these identified issues.

Additionally, the company has emphasised its commitment to enhancing security measures by implementing stricter security checks during the operating system boot process.

Full article @ Computing.co.uk

06 Jun 2023 - BA, Boots and BBC among companies targeted in cyberattack

Ransomware group Clop claims it is behind the mass hack
A wide-ranging breach centred on the popular file transfer tool MOVEit has impacted a growing number of organisations, including British Airways, Boots, and BBC.

According to the three companies, the breach occurred at their payroll provider, Zellis.

Full article @ Computing.co.uk

 

20 Jun 2023 - Microsoft Outage blamed on Russian Attack

Microsoft blames June outage on Russian DDoS
'Anonymous Sudan' is hiding its real identity

Microsoft has confirmed its services succumbed to DDoS attacks earlier this month, while a cybersecurity firm has pointed at Russia as the culprit.
The attacks hit Azure, Outlook and OneDrive over the course of three days, taking down services like Teams and Sharepoint Online.

The company gave early indications that the outages were the result of a DDoS attack when it attributed them to a "spike in network traffic". However, it wasn't until Friday that the company confirmed the news.

A post on the Microsoft Security Response Center says "This recent DDoS activity targeted layer 7 rather than layer 3 or 4... [The attacker] has been observed launching several types of layer 7 DDoS attack traffic."

Those types include HTTP(s) flood attacks; cache bypassing; and slowloris.

Full article @ Computing.co.uk

 

07 Mar 2023 - Internet Explorer 11 now disabled on Windows 10

On February 14th, 2023, Internet Explorer 11 was permanently disabled on Windows 10 devices. Disabling was done via a Microsoft Edge update.

If you wish to regain access to IE11 there is a workaround by removing the 2 "IEToEdge" Browser helper Objects the Edge update inserted into IE11.

Obviously only attempt this if you know what you are doing, otherwise please call us to assist.

07 Mar 2023 - First Windows 12 hints appear in Intel leaks

Microsoft investing in AI for Windows' next generation
While there haven't yet been any official announcements about Windows 12, there are indications that Microsoft's next-generation operating system is on the horizon.
Full Article @ Conputing

24 Nov 2022 - Ransomware incidents now dominate COBRA meetings

The UK now ranks third in a list of countries where businesses suffer the most ransomware attacks
The impact of ransomware incidents in the UK has grown to the point that they now dominate discussions at the government's emergency COBRA meetings.

We recommend all clients have a backup strategy in place and test it regularly

Full article @ Computing

22 Sep 2022 - EU Countries calling Google Analytics unlawful

A forth EU country, Denmark has stated that Google Analytics breaks EU GDPR.

The Danish Data Protection Agency (DPA), Datatilsynet, has become the fourth national regulator to conclude that the manner in which companies are currently using Google Analytics breaches European Union regulations that demand stricter safeguards for personal data moved outside the bloc.

In a judgement published on Wednesday, the regulator said that the use of Google's popular tool is illegal because it enables companies to move users' data outside the EU without the necessary protections.

Dataltilsynet's decision follows those from Austria, France and Italy, with the regulator noting that the common opinion represents a pan-European attitude among the data regulators and is a crucial step toward a coordinated strategy.

Full article @ Computing

09 Sep 2022 - RIP HM Queen Elizabeth II

We are shocked and deeply saddened by the death of Her Majesty The Queen.

For over 70 years she served our country and Commonwealth with grace and selfless devotion and made us proud to be British.

On behalf of 4IT Systems we send our deepest condolences to the Royal Family at this difficult time.

 

15 Aug 2022 - E-Mail Server Failure

So we opened the office this morning to be greeted with the fact that the machine hosting our Exchange e-mail server (and 2nd domain controller) had failed over the weekend. Attempts at repair were unsuccessful meaning the server had to be rebuilt.
Thankfully decisions made when commissioning the server meant a rebuild was fairly painless and we were able to fire up our Exchange & 2nd Domain Controller virtual machines within just a few hours.

So apologies for any late replies to e-mails today

Please note this failure affected 4IT e-mail only.

08 Aug 2022 - Gone Green - Hosting Powered By 100% Renewable Energy

We're excited to let you know that all our hosting is now officially green hosting, powered 100% by renewable energy.

This means all your our clients websites are now powered exclusively by wind and solar power.
 
Additionally, the data centre is extremely energy efficient with a PUE (Power Usage Effectiveness) of 1.12. PUE describes how efficiently a data centre uses energy, the lower the better. Most hosts have a PUE of 1.2 or higher.

For full details please see out datasheet

06 Jul 2022 - Chrome users should update immediately

Google patches high-risk Chrome zero-day vulnerability

Flaw is a heap buffer overflow in WebRTC

Google has released a Chrome update to deal with another high-risk zero-day vulnerability, the fourth this year.

Google has not, as of yet, released technical details, but in a version update notice the flaw is described as a "heap buffer overflow in WebRTC. Reported by Jan Vojtesek from the Avast Threat Intelligence team on 2022-07-01".

On 4th July, Google said in a blog post: "Google is aware that an exploit for CVE-2022-2294 exists in the wild."

It said that the zero-day vulnerability was exploited by hackers in the wild.

25 Apr 2022 - Temporary Office Closure April 25th - April 29th

The office will be temporarily closed from 11am Monday April 25th - 2pm Friday April 29th.

E-Mails will be responded to as normal during this period.
All clients have been notified of the alternative support arrangements.

05 Apr 2022 - US adds Russia's Kaspersky to its lists of national security threats

Two Chinese telecom firms have also been added to the list.

The US Federal Communications Commission (FCC) said last week that it had added Russia's cybersecurity firm Kaspersky Lab to its list of communications equipment and service providers that it believes constitute a danger to US national security.

This is the first time a Russian firm has been added to the list, which was previously dominated by Chinese firms such as Huawei and ZTE.

Companies on the list cannot receive any of the $8 billion available annually from the FCC's Universal Service Fund, which has been set up to support telecommunication services in rural areas or for low-income customers or institutions such as hospitals, schools and libraries.

The FCC added five Chinese corporations to its list last year. They were: Huawei Technologies, ZTE Corp., Hangzhou Hikvision Digital Technology, Hytera Communications, and Zhejiang Dahua Technology.

On Friday, two more Chinese companies were added: China Mobile and China Telecom.

Full article @ Computing

25 Mar 2022 - Temporary Office Closure March 28th - April 1st

The office will be temporarily closed from 11am Monday March 28th - 2pm Friday April 1st.

E-Mails will be responded to as normal during this period.
All clients have been notified of the alternative support arrangements.

04 Mar 2022 - Russia / Ukraine and Kaspersky

As we all watch in horror at the situation unfolding in Ukraine, ordinary citizens are reacting in the only way they can and are boycotting Russian goods.
For those in IT, the obvious target is Kaspersky, previously accused of having links with Russian security services after being accused of allegedly facilitating a back door hack on a US NSA agent’s laptop a few years ago.
Those of you considering cancelling your Kaspersky subscription to stand in solidarity with Ukraine, we recommend replacing it with BitDefender which has been a consistent top 3 performer in the AV charts for many years now.
If you need any assistance with this, please contact us

07 Jan 2022 - New year mail issues *Resolved*

The 4IT office have had e-mail issues since 01/01/2022 thanks to a bug in Exchange 2016 & 2019 that can’t handle the year 2022!
From Jan 1st 2022 all e-mails to and from our office have been stuck in an internal Exchange message queue. This did not come to our attention until yesterday and rectifying measures have been implemented to resolve the issue today restoring mail flow.
If you have tried to e-mail us since 01/01/2022 you may receive a delay delivery notification because your mail was stuck in a queue. You can safely ignore these as all e-mails have now been received.

Thanks

Mark

 

** UPDATE **

If you have received a "Delivery Failed" message, please resend your e-mail.

24 Dec 2021 - Christmas Closure

We are now closed for the Christmas period and will reopen Tuesday 4th Jan 2022
Wishing all our clients and friends a safe and happy Christmas and a joyful New Year

14 Oct 2021 - First Windows 11 Patch Tuesday update lowers AMD chip performance

The first Windows 11 update reduced Ryzen processor performance by as much as 15 per cent
Microsoft's first-ever Patch Tuesday update for Windows 11 makes the existing L3 cache latency issue for AMD Ryzen chips even worse, according to a report.
AMD disclosed the issue last week, stating that Microsoft's latest Windows OS was causing substantial performance drops in some AMD processors.
The company said Windows 11 has two separate bugs, which are reducing Ryzen processors' performance by as much as 15 per cent.

Full article @ Computing

4IT Comment : This is a less than stellar launch for a new product. Thanksfully fixes are already in the pipeline and will be available within days.

04 Oct 2021 - Temporary Office Closure Oct 4th - Oct 8th

The office is temporarily closed until 2pm Friday Oct 8th.

E-Mails will be responded to as normal during this period.
All clients have been notified of the alternative support arrangements.

18 Sep 2021 - Microsoft announces general availability of Office 2021

Microsoft will release Office 2021, the next consumer version of its productivity suite, on October 5th. That’s the same day the company will launch Windows 11. Much like Office 2019 before it, Office 2021 is a one-time purchase that will be available on both Windows and macOS.

Full article @ Engadget

16 Sep 2021 - Patch Tuesday: Microsoft patches a zero-day bug under active attack

In total, 66 security flaws have been addressed in this month's security update
Microsoft has released software updates to address dozens of security vulnerabilities in Windows and other products, including a zero-day that is being actively exploited in the wild.
In total, Microsoft's September 2021 Patch Tuesday update plugs a total of 66 security holes across Windows, Office, SharePoint Server, Azure Sphere, Azure Open Management Infrastructure, Visual Studio, BitLocker, Windows DNS and Windows Subsystem for Linux, among other software.
Of all security flaws fixed this month, three are rated as 'Critical', one is 'Moderate' and the remainder are 'Important' in terms of severity.
In addition, 20 Chromium security bugs in Microsoft Edge have been addressed this month.
In a security advisory last week, Microsoft disclosed details of a zero-day, remote code execution (RCE) bug in MSHTML, which the company said, was being used by threat actors in a limited number of attacks against Windows systems.

 

Full Article @ Computing

 

4IT Comment
The most serious issue here is with Internet Explorer. This is an old browser and we recommend that all clients should no longer be using this unless a good reason exists. Users should switch over to Edge wherever possible. Edge now shares the same underlying engine as Google Chrome.

 

03 Sep 2021 - EU fines WhatsApp €225m for GDPR breach

It's the second-largest fine ever handed out under the GDPR
Ireland's Data Protection Commission (DPC) has issued Facebook-owned WhatsApp a financial penalty of €225 million (about £193 million) for breaching European data privacy rules.
The data watchdog announced the decision on Thursday, noting that the messaging platform did not properly inform EU citizens about how it handles their personal data. The company also failed to tell users how it shares the information its collects with its parent company.
The company plans to appeal the decision.

Full article @ Computing

02 Sep 2021 - Apple bans employee Slack channel on pay equity

Apple has reportedly banned a Slack channel a group of employees created to discuss salary information.
Apple's rules for Slack clearly state that employees should not create Slack channels for activities that are not recognised as Apple Employee clubs or Diversity Network Associations (DNAs).
However, Apple doesn't appear to enforce these rules strictly. It permits many channels devoted to non-work topics, such as gaming, dogs, dad jokes and foosball, some of which have membership in the thousands.
Apple has seen an uptick in employee activism in recent years, for a variety of reasons.
The company has shut down multiple employee surveys in the past, which were aimed at gathering salary data.
Last week, a group of current and former Apple employees launched a new website under the name AppleToo, inviting colleagues to share stories of harassment, discrimination and retaliation experienced while working at the company.
"For too long, Apple has evaded public scrutiny," the group stated.
"The truth is that for many Apple workers ... the culture of secrecy creates an opaque, intimidating fortress. When we press for accountability and redress to the persistent injustices we witness or experience in our workplace, we are faced with a pattern of isolation, degradation, and gas lighting."

Full article @ Computing

01 Sep 2021 - Microsoft announces release date for Windows 11

Phased roll-out will begin 5th October
Microsoft announced on Tuesday that it will be releasing Windows 11 on 5 October.
The new operating system will be available as a free upgrade for compatible Windows 10 PCs, or on new PCs that come pre-loaded with Windows 11.

Full article @ Computing

26 Jul 2021 - Microsoft warns of evolved LemonDuck malware.

Microsoft warns of evolved LemonDuck malware targeting Windows and Linux machines

LemonDuck crypto miner has new features allowing key theft, introduction of backdoors and more, Microsoft warns
Microsoft has published a detailed report warning of an evolution in LemonDuck cryptomining malware enables threat actors to steal credentials, insert backdoors and carry out a variety of other malicious activities on vulnerable systems.
When first identified by security researchers a few years back, LemonDuck was primarily a cryptocurrency botnet that enabled Monero mining on affected systems, but it has now evolved to be a highly sophisticated malware strain, according to researchers from Microsoft 365 Defender Threat Intelligence Team.
LemonDuck is no longer limited to cryptomining, and can inflict severe security breaches on vulnerable systems.

Full article @ Computing

21 Jun 2021 - MacOS Unacceptably insecure, say Apple

MacOS does not meet the 'dramatically higher bar' established by iOS for customer protection, says senior vice president Federighi
Criticising the security of his own Mac operating system, Apple's senior vice president of software engineering, Craig Federighi, told a federal court on Wednesday that the level of malware on the MacOS operating system is unacceptable.
The admission came during Federighi's testimony in Apple's antitrust case with Fortnite maker Epic Games in the federal court in Oakland, California.

Full Article @ Computing

Display Older News

Explore 4IT Systems Ltd