Cyber security expert weighs in on recent LA OMV cyberattack

KLFY News | December 04, 2019

Two weeks ago, several Louisiana DMV’s were the victim of a ransomware attack that hit computer servers and disrupted critical functions across the state. Many of the DMV branch locations remain closed as state workers try to recover. News 10 spoke with a cyber security expert about the recovery process and why the government industry continues to be a prime target. Kierk Sanderlin, Head of Engineering with Check Point Software, said, “Typically, what we see is that malware like a virus gets introduced into the environment and it may be delivered through an email like a phishing email. It may be a link embedded on a website, but somebody clicks on something. Somebody opens the file that contains this malware which ultimately infects their mobile device laptop.” Louisiana’s Office of Motor Vehicles Commissioner Karen St. Germain told The Advocate that 28 percent of her agency’s 79 locations are up and running, and another six planned to open Monday. St. Germain says officials worked through the thanksgiving weekend on service restorations and the agency is opening offices “as fast as we possibly can.”

Spotlight

Hybrid work changes the way people use applications. In this video, learn about how Netskope Cloud Firewall delivers the protection you need everywhere your business operates.

Spotlight

Hybrid work changes the way people use applications. In this video, learn about how Netskope Cloud Firewall delivers the protection you need everywhere your business operates.

Related News

ENTERPRISE SECURITY, PLATFORM SECURITY, SOFTWARE SECURITY

KnowBe4 Helps Organizations Battle QR Code Phishing Attacks With New Tool

PRWeb | May 23, 2023

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, today announced the launch of its new QR Code Phishing Security Test (QR Code PST) tool. The no-charge tool assists organizations in identifying users that are most susceptible to scanning malicious QR codes. Many organizations are aware of the typical social engineering techniques used by bad actors such as phishing, spear phishing and impersonation, to manipulate employees and infiltrate systems. However, bad actors are now taking advantage of the rise in popularity of QR codes and are using them to launch targeted phishing attacks. QR code phishing is a social engineering attack that includes a malicious link within a QR code that users are prompted to scan with their smartphones. According to QRTIGER, an online QR code generator company, dynamic QR code scans increased 433% globally from 2021 to 2022 and scans quadrupled in 2022 alone. The malicious links in QR Codes take users to risky websites, execute malware or ransomware on their devices or steal information. In fact, last year the FBI released a warning that QR codes may be tampered with by cybercriminals to direct victims to malicious sites. This is also sometimes referred to as QRLjacking. KnowBe4’s new QR Code PST helps manage the threat of malicious QR codes by identifying users who may scan these codes and expose an organization to vulnerabilities that have the potential to cause significant downtime and security breach risks. The new, complementary tool is available for immediate use for up to 100 users in 35 languages with additional feature options. Additionally, after being used the tool calculates an organization’s Phish-prone™ Percentage (PPP) — the number of end users who are prone to being phished. “QR codes pose a unique cybersecurity threat because unlike traditional phishing, there is no URL to verify or way to confirm its legitimacy before scanning the code,” said Stu Sjouwerman, CEO, KnowBe4. “As bad actors diversify their social engineering techniques, it is imperative that organizations educate their employees on the potential danger of QR codes. KnowBe4’s new QR Code Phishing Security Test is a great tool to use as a first step in determining how vulnerable an organization is to the threat of malicious QR codes. Training employees to be alert and to think twice before scanning, contributes towards strengthening an organization’s security culture and encourages a healthy level of skepticism.” To begin using the new, complementary QR Phishing Security Test, visit: https://info.knowbe4.com/qr-code-phishing-security-test. About KnowBe4 KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 60,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. Kevin Mitnick, an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Tens of thousands of organizations rely on KnowBe4 to mobilize their end users as their last line of defense.

Read More

ENTERPRISE SECURITY, PLATFORM SECURITY, SOFTWARE SECURITY

NordLocker introduces easier secure sharing option

Globenewswire | May 26, 2023

NordLocker has launched a new feature that allows users to securely share a password-protected locker, otherwise known as a folder, of files. In order to receive the sent files, the recipient doesn’t even need to be a NordLocker user. This convenient sharing feature is incredibly easy to use. The files are shared via a link, and the recipient needs a password to access the files. For security purposes, once the set expiration date passes, the link becomes inaccessible. Thanks to NordLocker’s end-to-end encryption, files are fully protected throughout their journey. “Whether it’s holiday videos or a client contract – here at NordLocker we believe that all files should be shared securely. With this new feature, we make secure sharing that much easier,” says Aivaras Vencevicius, head of product at NordLocker. Currently, this feature is available on NordLocker’s web application. Other improvements In addition, NordLocker has introduced biometrics on iOS, which allows a more convenient and quicker login. iOS users are now also able to download NordLocker application logs for more information on their app. As privacy is at NordLocker’s core, it’s worth noting that these activity logs are encrypted and stored on the customer’s side. NordLocker’s customer support can only see it if the user decides to share it with the NordLocker team. “With cybercrime rising every year, file encryption is becoming essential. We see that threats are becoming more sophisticated – phishing emails are becoming harder to detect, and malware is becoming more dangerous and advanced. Therefore I strongly recommend to treat your digital belongings just like you’d treat your physical assets – keep them locked up and secure,” says Aivaras Vencevicius, head of product at NordLocker. ABOUT NORDLOCKER NordLocker is the world’s first end-to-end file encryption tool with a private cloud. It was created by the cybersecurity experts behind NordVPN – one of the most advanced VPN service providers in the world. NordLocker is available for Windows, macOS, Android, iOS, supports all file types, offers a fast and intuitive interface, and guarantees secure sync between devices. With NordLocker, files are protected from hacking, surveillance, and data collection. For more information: nordlocker.com.

Read More

DATA SECURITY, ENTERPRISE SECURITY

Sonatype Launches New Partner Acceleration Program to Help Partners Scale and Secure their Customers’ Software Supply Chains

Globenewswire | April 04, 2023

Sonatype, the pioneer of software supply chain management, today announced the launch of its Partner Acceleration Program. This new program framework delivers a wider range of benefits and increased go-to-market value for Sonatype Solution Providers, Global System Integrators and Technology Integration Alliances. With the initial program launch, Sonatype has formalized its partner benefits for Solution Providers delivering Sonatype technology and services, ranging from design support to on-premises and cloud platform integration. “The open source intelligence and security that Sonatype’s platform provides across the entire software development life cycle is second to none,” said Allen Talbott, Vice President of Sales at Saltworks Security. “Our long-time partnership with Sonatype has been incredibly valuable in growing our business, securing new clients, and giving our customers the information, tools, and software supply chain guidance they need to transform their development processes and build world-class application security programs.” Ninety-one percent of organizations have adopted or have plans to adopt a digital-first business strategy. As the digital landscape becomes increasingly dangerous and complex, software supply chain management and security is critical to the digital transformation and success of today's businesses. Sonatype is on a mission to empower every engineering team with intelligence to create and maintain secure, quality and innovative software at scale. The new Sonatype Partner Acceleration Program features an ecosystem of technically certified solution providers, system integrators, and technology alliances that share this same vision, enabling organizations to scale and secure their application development processes while propelling growth. “Software supply chain management remains a critical piece to securing the applications our customers develop and maintain over time,” said Joey Campione, President at Opticca Security. “Sonatype’s platform continues to deliver consistent results, reliability and increases overall developer productivity, providing our customers with what they need to continue to innovate at an accelerated pace. As a strategic partner, Sonatype’s solutions and support has been integral to scaling our business, and we anticipate that the new partner program will only amplify this further.” Sonatype partners report higher win rates, increased profits, and more opportunities to build new revenue streams. With the Sonatype Partner Acceleration Program, Solution Providers receive structured tiers of benefits that support increased time to value and customer growth. As partners grow their business with Sonatype, they have access to increasing program benefits and exclusive resources, including dedicated partner managers, co-branded marketing materials, technical support, event opportunities, and more. “This is an incredible time of growth for our Sonatype partner ecosystem. The demand for software supply chain management solutions continues to skyrocket as organizations increasingly recognize the need to understand the open source their applications depend on,” said Bruce Gordon, Senior Vice President of Global Channel Sales & Alliances at Sonatype. “We have an outstanding community of partners from across the globe providing industry-leading services and technologies. We’re excited to now provide this partner community with additional benefits designed to increase the value and delivery speed of safe and secure open source software.” ABOUT SONATYPE Sonatype is the software supply chain management company. We empower developers and security professionals with intelligent tools to innovate more securely at scale. Our platform addresses every element of an organization’s entire software development life cycle, including third-party open source code, first-party source code, and containerized code. Sonatype identifies critical security vulnerabilities and code quality issues and reports results directly to developers when they can most effectively fix them. This helps organizations develop consistently high-quality, secure software which fully meets their business needs and those of their end-customers and partners. More than 2,000 organizations, including 70% of the Fortune 100, and 15 million software developers already rely on our tools and guidance to help them deliver and maintain exceptional and secure software.

Read More