About Alvaka-Admin

This author has not yet filled in any details.
So far Alvaka-Admin has created 663 blog entries.

CryptXXX is ransomware that also steals your passwords and your Bitcoins

Most of my recent blogs are about ransomware. That is because ransomware is the most prevalent cyber threat today facing individuals, small and large businesses, governments and not-for-profits. No one is safe from this scourge.

Today I must tell you about a new one. Like Jigsaw, this new one called CryptXXX, is a game changer. Jigsaw was different from prior strains in that it immediately starts to delete your files just to show you that it means business. CryptXXX is different in that it introduces two new problems other than encrypting all your files and then demanding payment. Up until now ransomware has not actually breached your system and exfiltrated data. Sure you had a security incident, but it was not identified as a breach in the classic sense. Now with CryptXXX not only is your data held hostage, but now the culprits steal two new things from you. CryptXXX steals login names and passwords which puts all your systems, local and in the cloud, and any websites you frequent at risk. CryptXXX also steals your Bitcoins if you have any. The stealing of the Bitcoins is a particular insult because....

2024-04-21T19:40:11-07:00May 18th, 2016|

What the heck *&#@ did you say about custom software development?

Here is a guest article from Tim Martin of Action Point (www.action-point.com ). I asked for permission to run his blog because it is a very important message. The only thing missing is his unique Irish accent. Tim writes:

What the *&#@ did you just say?

This was the reaction I got from a potential client after our initial meeting to discuss their need for a customized software.  Two days later we signed a contract and they have become one of our most valued clients.

 

It’s about time for a little straight talk around here…

As the head of business development in the US for Action Point I’ve never been accused of being indirect or subtle. In the technology industry in general but especially when dealing with custom software companies, straight talk is a rare commodity. So what did I say to the client?...

2016-03-28T15:00:00-07:00March 28th, 2016|

What is it like to upgrade to Windows 10?

I finally got around to upgrading my Lenovo notebook from Windows 8.1 to Windows 10. I can tell you in short it was a relatively fast and easy upgrade. My Lenovo is fairly quick and I have all solid state drive storage so that probably helped make things go fast.

Here is how my upgrade went:

  • I did the pre-download option of Windows 10 so all the files were already on my system when I started the upgrade.
  • Once launched the Lenovo ran for about five minutes with a green screen of...
2019-05-14T07:29:29-07:00March 24th, 2016|

What is Phishing, aka Social Engineering, and How Do I Avoid It?

I recently warned of a very large recent upsurge in ransomware.  Now I must warn you to beware of new successful social engineering exploits.  What is social engineering?

Wikipedia has a good definition:

Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme.

In other words, phishing, the internet term for social engineering scams is simply a way to trick you into doing something so that you reveal vital information like bank account info, tax return info or send money unwittingly to a devious person.

Let me tell you about social engineering exploits in three recent real world examples.  In the first case, City of Hope in Duarte, CA (City of Hope employees fall victim to phishing attack) had three employees targeted by a phishing scam. They unwittingly revealed protected health information (PHI) which by law must be kept confidential. In the other two cases, the loss of data was much more vast. Both Seagate Technologies (Seagate Phish Exposes All Employee W-2’s) and Snapchat (Snapchat falls hook, line & sinker in phishing attack: Employee data leaked after CEO email scam) had an employee get tricked into providing W2 information on all past and current...

2026-04-15T04:53:53-07:00March 9th, 2016|

Tips on Renewing Warranties on IT, Server and Software

Here is a good blog on whether or not you should renew your warranties on firewalls, servers, routers, software, etc. It is written by a friend of mine, Ken Zimmerman, at Trivalent Group out of Grand Rapids, Michigan.  He provides [...]

2026-04-15T04:40:36-07:00March 8th, 2016|

Be Ransomware Aware

Educate your users - Don’t let them be tricked into downloading malware

 Everyone should follow this advice:

  1. Be very cautious when opening an attachment or clicking a link in an email, instant message, or post on social networks (like Facebook)—even if you know the sender. If you are suspicious, call to ask the sender if they sent it.  If not, delete it.
  2. The attack can look like it is from an official sources like banks, UPS, FedEx, USPS, eFax, etc. This has been the most common attack method to date.
  3. If an e-mail gets blocked and quarantined by your spam filter...
2016-02-29T22:28:51-08:00February 29th, 2016|

I Am a Non-Technical Executive: What Seven Things Should I Be Asking My IT Guys About IT Security?

Irvine, CA - Overseeing IT and security is a daunting task, even if you are an IT professional. If you are an executive to whom IT reports, then the task becomes near impossible. The list of following questions is designed to empower you to have a meaningful discussion with your IT team so you can be an informed and responsible manager pursuing your due diligence role in protecting the assets of your firm. If you are an IT professional, these are questions you should be prepared to answer.

1.       Q. When did we last do a risk assessment? Please share that document with me. I would particularly like to see the Risk Assessment Table.

A.      Make sure your IT team is periodically assessing the risks to your IT systems.  They should be recommending upgrades and new solutions for you from time-to-time, and you should be listening.  They need to be able to express the threat in operational and economic terms in order to justify the expenditure.  If your team can’t give you a clear and coherent answer on when and how they last did this, send them off with a task and a deadline.

2.       Q. When did we last do a Vulnerability Scan? What were the results of that scan? I would like to see the report.  Who did the remediation? When is our next scan planned?...

2026-04-15T04:42:02-07:00February 25th, 2016|

New Virulent, Wide-Spread and Expensive Ransomware Outbreak Coming to You Soon

Orange County, CA - We have seen a surge in ransomware attacks in the past week.  While only two Alvaka clients have gotten hit, they are a tale of different system administration acumen. 

1.  A multi-state firm got hit with the latest breed of ransomware on Friday.  Where an otherwise non-event for the most part went wrong was that a key user insisted on having elevated administrative rights for their IT infrastructure.  Instead of using a regular user account, with very limited user rights for day-to-day activities, this more powerful account, when struck by the ransomware, infected all the important file shares of the firm, including the branch location file stores.  Fortunately they had good backups, but because of poor folder naming conventions and structures it took the guys in our Alvaka Networks’ Network Operations Center about 28 hours straight to get all the user permissions back in order for client to get back to work.  The lack of least-permissions as used by this client goes in direct opposition to what we recommend at Alvaka.  Least-permissions is the practice of using accounts that grant the user to only the locations on the network for which they have a business need to access.

2.  In another example, that struck today, a $200m manufacturer/distributor got hit by the same ransomware.  This time it was a Jr executive.  He saw some problems with his system, but did not report the problem not knowing what it was and went home.  The problem was detected after he left, but the outcome was very different than the prior scenario.  Why?  Because this user only...

2024-03-14T00:20:41-07:00February 16th, 2016|

Where’s the Beef?

Irvine - I want to let everyone know that we are embarking on some new messaging at Alvaka Networks.  Our new home page (www.alvaka.net) features some new messaging and calls-to-action centered on statements that are common amongst our new clientele followed-up with the phrase “What do I do now?”

This new marketing effort has its genesis in our new marketing consultant, John Pietro.  You won’t recognize Pietro’s name, but you will recognize his work.  He is most famous for his Wendy’s “Where’s the beef?” campaign.  His work is not limited to that one campaign, but is likely his most famous and arguably the most famous, memorable and successful campaign in fast food history.  How is coaching will serve us in the tech services business remains to be seen, but I like where he is taking us....

2016-02-10T01:03:52-08:00February 10th, 2016|