Friday, September 30, 2011

October is Cyber Security Month

As smartphone functionality increases, malicious software becomes more commonplace. Businesses are taking advantage of the new opportunities they provide for employees to operate more efficiently while out of the office. However with the excitement surrounding this new technology, the security of sensitive information is frequently overlooked. There are many steps available to protect your information as much as possible.

What are the Risks?

Without proper virus protection and data encryption, the risk to private information has increased as cyber threats proliferate. Downloadable applications are the new frontier for computer hacking, and traditional malicious attacks pose a greater threat on smartphones, where smaller screens make it more difficult to read the e-mail addresses and links in e-mails. Charges can be billed directly through your service provider. Other opportunities for stealing data are possible with smartphones since many applications are able to access data from phone calls and text messages.

Devices running an Android operating system are more than two times as likely to encounter malicious software, as Google has taken a more open handed approach with Android marketplace applications. IPhone applications are more closely reviewed before becoming available, and so malicious applications are less common on the iPhone.

With the increase of these attacks, new security options are being offered by smartphone manufacturers as well as third party providers. Blackberry devices have built in security protocols for e-mail and applications as they are encrypted by RIM’s servers. MS Exchange users have additional protection and have customizable options for what users are able to access on their device.


How to Protect your Information

Always set a password. Mobile devices are more likely to be lost, and this is the frontline of preventing unauthorized access of information.

Limit usage on public Wi-Fi networks where the connection may not be secured, particularly when shopping or using mobile banking.

Only download applications from sites you trust, and read reviews to see if other users are reporting issues.

Review your monthly bill for any suspicious or unusual charges. Many service providers have prevention options.

Do not “jailbreak” or “root” a device to install an unapproved operating system. Many security features are disabled and software updates to increase security will not be available.

Install an anti-virus program which offers GPS tracking to locate a lost device, virus scans, and remote data wiping.

Check for manufacturer and software options for security packages. RIM offers a free Secure/Multipurpose Internet E-Mail Extensions (S/MIME) support package for Blackberry devices which provides support for encrypting messages.

Consider a third party anti-virus program such as Sophos Mobile Control, Kaspersky, CRYPTOCard, Lookout Mobile Security or Check Point which can be downloaded directly to the device and provides automatic responses to threats.


3D Corporation provides setup and deployment of your mobile devices including integration with your MS Exchange server and can help determine which security solution will work best for your business. Please visit our website at http://www.3dcorp.us/, email us at info@3dcorp.us, or call us at (360) 671-4906 for more information.

References: Market Watch, PDDNet “Your Smartphone: A New Frontier for Hackers”, Blackberry SecuritySophos Mobile Control

Monday, September 19, 2011

Adobe Releases Security Bulletin to Fix 13 Vulnerabilities

Our internet security solution provider WatchGuard recently issued an alert describing Adobe’s security bulletin release that was issued as part of their quarterly patch day cycle. The bulletin describes 13 vulnerabilities that affect Adobe Reader and Acrobat X 10.1 and earlier, running on Windows and Mac, as well as Reader 9.4.2 for UNIX. An attacker can exploit these vulnerabilities by enticing a user into viewing a maliciously crafted PDF document which could ultimately enable the attacker to gain complete control of the user’s computer.

More information on the security updates, timelines, and installation instructions can be found in the Adobe security bulletins and advisories. To read more about security threats to Adobe applications, please refer to our previous blog post entitled “An Unpatched Adobe Application does for an Unsafe Network Make”.

3D Corporation can evaluate your network and provide assistance in ensuring patches for these applications are up-to-date. For more information on the services 3D provides to keep business networks secure, please call our office at (360) 671-4906, email us at info@3dcorp.us, or visit our website at http://www.3dcorp.us/.

References: “Reader and Acrobat Updates Correct 13 Security Flaws”, watchguardsecuritycenter.com; http://www.adobe.com/support/security/

Microsoft Issues 5 Security Bulletins to Fix 14 Vulnerabilities

Microsoft has released five new security bulletins for September that fix 14 vulnerabilities in its Windows and Office products. While Microsoft doesn’t rate any of these as ‘Critical’, an attacker who successfully exploits these vulnerabilities could allow for remote code execution or elevation of privilege and ultimately give the attacker complete control of the user’s computer.

3D Corporation will automatically test and deploy security patches on the networks of our 3DProActive™ Managed and Partner clients to eliminate the risks posed by these vulnerabilities. Other Microsoft users of the above-mentioned products should download and install the appropriate patches immediately to avoid possible exploitation of their computer and/or computer networks. More information regarding these vulnerabilities and their impact can be found at Microsoft’s Security Bulletin Summary for September 2011.

3D provides up-to-date security solutions that can protect businesses from threats like these automatically. If you would like additional information on how we can make your network worry-free, please visit our website at http://www.3dcorp.us/, email us at info@3dcorp.us, or call our office at (360) 671-4906.

References: “Microsoft Black Tuesday: Updates for Mangled Office Documents and Malicious WINS Messazge”, watchguardsecuritycenter.com; Microsoft’s Security Bulletin Summary for September 2011