Welcome


This blog is dedicated to the topics of Course materials, Innovation, and Technology in Education. it is intended as an information source for the college store industry, or anyone interested in how course materials are changing. Suggestions for discussion topics or news stories are welcome.

The site uses Google's cookies to provide services and analyze traffic. Your IP address and user agent are shared with Google, along with performance and security statistics to ensure service quality, generate usage statistics, detect abuse and take action.
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, October 3, 2016

Is Ransomware Targeting Education?

Education may or may not be the main target for ransomware schemes, according to difference sources. One study from the security-analyst firm BitSight Technologies found that 13% of educational institutions examined by the company had experienced a ransomware attack in the last year, compared to 5.9% of government agencies or 3.5% of health-care providers.

Ransomware disables data from a system until users pay a ransom for its release. U.S. Department of Justice statistics for 2016 indicate there are nearly 4,000 ransomware attacks every day.

“Establishing email security protocols, monitoring key third-party vendors, tracking security ratings, and avoiding file sharing are all ways to mitigate risks associated with ransomware,” Stephen Boyer, co-founder and chief technology officer of BitSight, said in an article for Campus Technology.

Another report from the security firm Datto painted a much different picture for education. The company surveyed 1,100 managed service providers and placed education ninth on its list of ransomware attacks at 12%, far behind professional services (44%) and health care (38%). The study also found that 46% of ransomware attacks came from email phishing, followed by 36% resulting from lack of employee training.

“Malicious emails, coupled with a general lack of employee cybersecurity training, are the leading cause of a successful ransomware attack,” the authors wrote in Datto’s 2016 Global Ransomware Report. “Today’s businesses must provide regular cybersecurity training to ensure all employees are able to spot and avoid a potential phishing scam in their inbox, a leading entrance point for the malware.”

Tuesday, May 3, 2016

More Malware Attacks, Harder to Detect

Malware attacks are happening more often and are harder to detect, according to the State of the Endpoint Report from the Ponemon Institute. Of the 694 IT security administrators surveyed, the number of respondents with a strategy in place to deal with malware fell from 43% in 2015 to 38% this year.

The report found that 68% had experienced distributed denial-of-service (DDoS) attacks, where multiple systems are used to target a single system. In addition, 80% said that they believed their mobile endpoints—defined as laptops, desktops, smartphones, printers, POS machines, or ATMs—had been targets, up from 58% in 2015.

As troubling as that may sound, a bigger concern involves employees. More than 80% of respondents said the biggest threat to endpoint security was negligent or careless employees who don’t follow security policies.

“You’ve got how many different types of laptops? How many versions of Windows? How many applications for those devices? How many phone types, etc.?” asked Michael Davis, chief technology officer of the security start-up firm CounterTack in an article for InformationWeek. “IT has to struggle with all of that variation, while also trying to enforce a standard set of security protocols. And then, on top of that, they have to deal with the end user, so it’s very difficult to enforce anything, even from a purely technology perspective.”

Tuesday, April 5, 2016

More Malware Attacks on the Horizon

College students love their electronic devices, but that love affair could make them prime candidates for malware attacks. Research from the IT security firm Check Point found mobile malware used against Android devices is now among the most prevalent forms of attacks for the first time, while iOS platforms could soon see a steep increase.

The firm reported that while Android attacks are still more common and will become even harder to detect, the popularity of iPhones and iPads make those devices high-quality targets for cybercriminals. Check Point said it identified more than 1,400 different malware types globally in February, with the Conficker, Sality, and Dorkbot families as the most common variants.

“On top of these risks, we’ll experience a trend of cybercriminals using advanced techniques to not only take over and control individual devices but groups of multiple devices,” David De Laine, regional managing director for Check Point, told the industry newsletter ARNnet. “Controlling one device is fun, but controlling an army of devices is a real moneymaker. Botnets are getting bigger and more well-orchestrated, giving hackers a range of malicious capabilities from massive spamming schemes and heavy DDOS attacks to cryptocurrency mining.”

A denial-of-service (DOS) attack is an attempt to make a device or network unavailable to its user. A distributed denial-of-service (DDOS) is an attack on more than one unique Internet protocol address.

Friday, February 19, 2016

Malware Targets Android Phones

Most college students can’t function without their smartphone nearby. If it’s an Android device, there’s a malware that could make their lives miserable.

The malware, called Mazar Android Bot, is spread through a text message with a malicious link that takes over the user’s device, according to a report from ITProPortal. The text alerts the user that a multimedia message has been sent and includes a link to view the message.

The user is then prompted to download the package with the malware that bears a generic name such as “MMS Messaging” to make it look like a legitimate application.

Once downloaded, the malware alerts the attacker that a new device has been compromised. The malware can install a proxy application that lets the attacker intercept all Internet traffic on the device. It also makes it possible for man-in-the-middle attacks, which are used to steal account logins, social media credentials, and banking information.

Security experts believe the malware is of Russian origin because Mazar Bot can’t be installed on phones owned by Russians. The bad news is that as it spreads the malware is likely to evolve into new forms.

“Attackers may be testing this new type of Android malware to see how they can improve their tactics and reach their final goals, which probably is making more money,” Andra Zaharia, a security specialist at Heimdal Security, said in a report for MSN.com. “We can expect this malware to expand its reach.”

Monday, July 6, 2015

Cybercriminals Target Ed Sector

The 2015 Global Threat Intelligence Report found that the education sector accounted for more than a third of all the reported malware incidents. NTT.Com Security analyzed more than six billion attacks and reported that the bring-your-own-device (BYOD) format instructors are beginning to use could be to blame.

Students and staff use a variety of devices on institutional networks, often providing personal information in the process. Cybercriminals understand that and so focus their attacks on those networks.

“The history of open networks at education institutions has resulted in network architectures where there is usually no strong separation between areas containing sensitive data and untested areas where professors, students, or visitors can connect,” said Chris Camejo, director of assessment services for NTT.Com Security. “This makes it more difficult to prevent, detect, and respond to attack. IT officials must develop a strategy that is custom to the BYOD culture that they have embraced.”

Tuesday, November 19, 2013

Beware of CryptoLocker

CryptoLocker is a form of ransomware that targets computers by disguising itself as a legitimate attachment that, when opened, locks up all the files of an infected computer, including backup files. Only the hackers have the decryption key, demanding $300, or two Bitcoins, to release it.

Now, to add insult to injury, the gang behind the malware has created a customer service site for victims who need help in making the payment, according to a report from The Today Show. People can use CryptoLocker Decryption Service to check the status of their payment and complete the transaction, at an additional cost.

“They were leaving money on the table,” said Lawrence Abrams, who has tracked the spread of this malware on BleepingComputer.com. “They created this site to capture all of the money they were losing because people couldn’t figure out how to make the ransom payment or missed the deadline.”

There is a 72-hour deadline to pay for the decryption key, which jumps from two Bitcoins to 10, or nearly $4,000 on today’s market, if missed. A Bitcoin is a peer-to-peer digital currency which the U.S Department of Justice and the Securities and Exchange Commission consider a legitimate financial instrument.

According to Abrams, CryptoLocker uses Zip files to worm its way into computers and is password protected, which allows it to get past security software. He added that the password has been “PaSdlaoQ” for everyone so far.

The advice to protect users from the malware is not new: Don’t open attachments from unknown senders, have up-to-date security software, and back up files often.

“This is scary stuff,” said Brian Krebs on the KrebsOnSecurity blog. “People need to rethink how they protect their important files.”

Thursday, October 24, 2013

Malware Hits More Higher Ed Networks

Colleges and universities are losing the battle against malware, according to security firm OpenDNS, which reported that networks run by higher education institutions are three times more likely to be infected than government agencies or businesses.

The most common threat is Expiro, software that can replicate itself, steal disk space, and slow computer memory to a halt. The malware can also corrupt data, steal personal information, and erase hard drives.

“Our research shows that while higher education institutions face the same cyber-attacks as enterprises and government agencies, they tend to be compromised by malware and botnets at a much higher rate,” Dan Hubbard, chief technology officer at OpenDNS, told Campus Technology during the Educause 2013 conference. “Clearly, colleges and universities must operate more open networks and support an endless number of access devices, which puts them at higher risk.”

Hubbard suggested that “fundamental security best practices” can reduce infection rates, such as alerting users when spear-phishing appears, an e-mail fraud that seeks unauthorized access to confidential information. Institutions should also use analytics to block access to malvertising (online advertising that spreads malware) and watering holes (sites infected with malware).