loader from loading.io

Welcome! Why You Have to be Applying ALL Patches Not Just the OS ones plus more on Tech Talk with Craig Peterson on WGAN

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Release Date: 09/11/2020

Defend Your Digital Domain: Transforming Home Networks for Cybersecurity show art Defend Your Digital Domain: Transforming Home Networks for Cybersecurity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there! Is your home Wi-Fi a potential cyber threat? Let’s bolster your network's defenses! Here's what you'll find in this guide: Privacy Concerns: Understand the risks associated with a vulnerable home network and the importance of safeguarding your personal information. Wi-Fi Security: Learn how to secure your home Wi-Fi network to prevent unauthorized access and protect your devices. Smart Devices: Explore the security challenges posed by smart devices and how to mitigate these risks effectively. Network Segregation: Delve into the concept of dividing your home network for...

info_outline
Unlocking the Secrets of Online Privacy: Cracking the Code to Secure Chats show art Unlocking the Secrets of Online Privacy: Cracking the Code to Secure Chats

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Have you ever paused mid-message, wondering who might be lurking in the digital shadows? I've delved deep into the realms of online privacy, spam prevention, encryption, and the intricacies of organizing your digital life to keep your conversations secure. Join me on this thrilling journey through cyberspace as we unravel the secrets of safeguarding your chats. Here's what you'll discover in our expedition: Privacy in the Digital Age: Uncover the nuances of online privacy and learn how to navigate the digital landscape confidently. Combatting Cyber Threats: Dive into the world of...

info_outline
Defend Your Inbox: The Ultimate Plus Addressing Privacy Solution! show art Defend Your Inbox: The Ultimate Plus Addressing Privacy Solution!

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there! Ever find yourself drowning in a sea of spam emails? πŸ“§ Fret not! I've got the perfect solution to not only declutter your inbox but also fortify your online privacy and cybersecurity. πŸ›‘οΈ Introducing the ultimate guide to digital clean up, with a focus on plus addressing for enhanced privacy and organization. No more sifting through unwanted emails – this guide is your ticket to a streamlined and secure email experience. πŸ“₯ Here's what you'll find in this comprehensive guide: Privacy Reinforcement: Learn how plus addressing can act as a shield, allowing you to...

info_outline
Online Advertising Transformed: Google's Move Beyond Cookie Dependency show art Online Advertising Transformed: Google's Move Beyond Cookie Dependency

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hold onto your hats, tech enthusiasts! πŸŽ©πŸ’» Get ready for a seismic shift in the digital landscape as Google bids farewell to cookies, ushering in a new era where privacy is more than just wishful thinking. Say goodbye to the cookie craze! πŸͺ🚫 In my latest deep dive, "Digital Clean Up: Navigating Google's Game-Changing Shift in Online Advertising," I'm unraveling the intricacies of this groundbreaking move and what it means for all of us navigating the vast realms of the internet. πŸŒπŸ” Here's what you can expect in this enlightening journey: Advertising Evolution: Explore...

info_outline
Crack the Code: Mastering Windows Security and Digital Clean-Up Tactics show art Crack the Code: Mastering Windows Security and Digital Clean-Up Tactics

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In the fast-paced world of technology, your Windows device needs the ultimate defense against cyber threats. I've revamped the guide, diving deep into the realms of anti-virus protection, cybersecurity, and online privacy. Here's your roadmap to a digitally clean and secure future: Windows Defender vs. Norton vs. Malwarebytes: Uncover the strengths and limitations of each superhero in the battle against cyber villains. The War Against Malware: Arm yourself with knowledge on the latest malware trends and the tools to combat them effectively. Guarding Your Cyber Fortress: Explore...

info_outline
Boost Online Privacy: A Cyber Spring Clean show art Boost Online Privacy: A Cyber Spring Clean

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Is your digital realm resembling a messy attic? Files overflowing like forgotten knick-knacks, an inbox resembling a confetti blizzard, and social media feeds choked with digital dust bunnies? Fear not, fellow data denizens, for spring cleaning season has arrived – and this year, we're reclaiming our online peace of mind! But unlike dusting cobwebs and decluttering drawers, taming our digital wilderness requires a different arsenal. Forget brooms and vacuum cleaners – we're talking AI-powered assistants, data-detective hounds, and even a digital shredder for those long-dormant devices...

info_outline
Beyond Delete: The Ultimate Guide to Shredding Sensitive Digital Trails show art Beyond Delete: The Ultimate Guide to Shredding Sensitive Digital Trails

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there cyber enthusiasts! Ever wondered how to transform your digital space into a fortress of security? Well, buckle up, because we've crafted the ultimate guide to help you declutter, fortify, and defend your digital realm. Our mission: to make cybersecurity engaging and effective, without drowning you in techno-jargon. Check out these key points we've covered: Wi-Fi Wonders: Unveiling the mysteries of Wi-Fi security to ensure your online activities remain secure from prying eyes. Password Power: Dive into the world of password protection, unlocking the secrets to crafting...

info_outline
Securing Your Digital Realm: The Ultimate Cybersecurity First-Aid Kit Unveiled! show art Securing Your Digital Realm: The Ultimate Cybersecurity First-Aid Kit Unveiled!

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In the vast landscape of the digital world, safeguarding your online presence is paramount. Welcome to another episode of TechTalk with Craig Peterson, where today, we unravel the secrets to fortifying your digital realm with "The Ultimate Cybersecurity First-Aid Kit." Decrypting Wi-Fi Woes Our journey begins with the cornerstone of your digital fortress: Wi-Fi encryption. No secret stays safe forever, and that includes your Wi-Fi password. We delve into the importance of encrypting your Wi-Fi, ensuring that your digital stronghold remains impenetrable. Password Party Extravaganza "abc123"...

info_outline
The Mobile Malware Menace: Protecting Against Evolving Threats show art The Mobile Malware Menace: Protecting Against Evolving Threats

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In today's fast-paced digital age, staying ahead of the curve is not just an advantage; it's a necessity. From the electrifying world of electric vehicles to the intricate web of mobile security, and the visionary influence of Elon Musk, there's a lot to unpack. Join us on this insightful journey as we explore key topics that are shaping the future of technology. 1. Electric Vehicles (EVs): Paving the Way for a Green Future The surge in popularity of electric vehicles is undeniable. We delve into the latest advancements, innovations, and the environmental impact of EVs, providing you with a...

info_outline
Scan Smart, Stay Safe: Mastering the Art of QR Code Defense show art Scan Smart, Stay Safe: Mastering the Art of QR Code Defense

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In a world dominated by QR codes, the risk of falling prey to digital tricksters is on the rise. Fear not, fellow entrepreneurs, for we've decoded the secrets to outsmarting these cyber hosers and keeping your digital fortress secure! QR Code Unveiled: Understanding the Basics Let's kick things off with a deep dive into the world of QR codes. Learn what makes them tick and how scammers exploit these seemingly innocent codes to compromise your cybersecurity. The Rise of AI and Its Role in QR Code Shenanigans Artificial Intelligence (AI) has ushered in a new era, and unfortunately,...

info_outline
 
More Episodes

Welcome!

Craig Explains Why companies believe that they are Completely Patched up and Why it means more than your Operating System.

For more tech tips, news, and updates visit - CraigPeterson.com

---

Read More:

iOS 13.7 launched today with a new system for battling the pandemic

Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

The accidental notary: Apple approves notorious malware to run on Macs

Most IoT Hardware Dangerously Easy to Crack

55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

The Hidden Cost of Losing Security Talent

 

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] Hey, do you have a 99% patch rate? Gonna talk right now about why that is a load of UMHUM in every case that I've ever seen?

Craig Peterson here and here we go.

Hey everybody. Thanks for joining me today. this is something that I don't know if I can ever repeat enough, but I want to take a little bit of a different angle on this than I have before. Most of us know that we're supposed to patch. What do we patch? What are we using? You might turn on automatic updates on windows. You might have those turned on MacOS, of course, on your iOS devices. Maybe you've got an Android device it's less than two years old and still gets updates so you have that turned on. Here's the problem. I have yet to walk into a business that doesn't say that they have just a phenomenal patch rate.

You know, so for instance, you'll walk in there and you say, how good are you guys at keeping up on patches?  Almost every last one of them says, yeah, almost a hundred. We're probably 99, 98% of the patches are up to date and we're just phenomenal. We're safe. Yeah, we're safe. don't worry about us. Yeah, we're safe. Don't worry about it.

 I've been in a couple of businesses and said that and then, they got nailed something awful and they were too embarrassed to call me back. When I talked to them later on, I found out what had really happened with them.

Many people and many businesses are focused on that patch rate and that kind of makes sense. We have to make sure the patches are done, particularly the critical patches. But why is it that I go into a business and every business says, yeah, we're patched up. it might not be a hundred percent, but we're patched up. Every business says that.

Yet I always find critical vulnerabilities when I poke around. When I do a scan. When we do these paid assessments to come up with an action plan for businesses. We scan their systems, which means their workstations, it also of course means there are servers and maybe other devices that are out there. I have never scanned a device that did not contain a critical vulnerability.

Where's the disconnect? Why are businesses and people saying, yeah, we have this 99% patch rate? Yet I am continually finding major problems. It has to do with what's being patched. People are not patching the right thing. So let's look at a couple of different things here.

First of all. When we're talking about workstations, desktops, laptops. Here are the four types of software that are attacked the most. Number one internet browser add-ins. How many of us have extensions on our browsers? Some of those extensions are in fact, malicious themselves. Internet browsers.

Another big attack vector is operating systems. Of course, all of our office applications, all of our productivity stuff, software like I'm using right now for the radio show. All of this stuff gets attacked. But when we're talking about a 99% patch rate yeah. We're pretty much all patched up. What they're almost all always thinking about and talking about is patching the operating system and that's where things end.

Now on the server-side, when we go into businesses, we're finding the webserver software, the database server, the operating systems on those servers, the remote server management stuff, like RDP, the active directory. Those are what is always being attacked. So why the disconnect? It's because it's difficult to patch everything.

Microsoft, I already mentioned has the ability to automatically install updates. In fact, if you don't have the business versions, the enterprise versions of Windows, professional, you're forced to do updates. You don't even get to say when you want those updates to happen. If you're running iOS, on your iPhone, on your iPad, again, updates just happen automatically.

But how about all of those apps? If you're getting those apps on your mobile devices, from the stores, like the Google play store or the Apple store, you were probably getting updates for your applications. If you're not getting them from there, you're probably not getting updates.

So not patching the right thing is a very big deal.  I wanted to talk right now about one specific thing that people are not patching. Frankly, that is our web server. You've got a website, right? If you're a business, any size business, you've got a website. You have to have a website. You have to get the message out.

Now, of course, you can have some emails from other things too, but we're going to focus on one thing right now, the website. Hackers are actively exploiting right now, a vulnerability in a WordPress plugin. Now, I mentioned our browser plugins are the extensions for our browsers and how those can be hacked in many cases.

It's another vector, obviously for the bad guys to get on to our computers and really start messing around. in this case, we're talking about WordPress web server, which is the number one most popular web server out there, WordPress and there are more than 700,000 active installations of this. We are using it for our own little websites for our families, We're using it for our businesses. We're using it for our associations or organizations. This particular file manager plugin, which extends features for WordPress allows bad guys to run command and malicious software things, like scripts whenever they want to. Now, how many people are keeping their WordPress installation up to date.

Are you keeping your flash UpToDate? Are you keeping your other Adobe software up to date? How about all of the other software you're running on your computers? I look at this computer and it's just astounding how much software I have installed here on my Mac that I use all the time.

So the attackers are using this exploit to upload files that have these shell scripts in them that are hidden in an image. Makes it even harder for you to find.

So we have to be very careful. We don't know the impact of all of this yet. It's probably pretty bad. There are some companies that are blocking it. We block it as well, but we're talking about millions of exploit attempts.

Over the course of the last couple of weeks, that is pretty bad. And we're only seen about half of the sites out there. The WordPress sites actually patched up. So make sure you do the update. You have to inventory everything you have. Everything your enterprise uses. What software do you have? What is it installed on? Is it up to date?

Don't just Willy nilly, allow people to install software on their computers, and don't do it yourself either. Every time you install software, you open up another potential way for bad guys to get in. Its something else you have to track. It's something else you have to inventory. It's something else you have to update. You have to upgrade.

People are just downloading stuff, Willy nilly. And remember what was the very first thing I said, that's attacked frequently internet browser, add-ins. That means internet browser add-ins means that those wonderful little bars that people install on their browsers are, yeah, those are malicious much of the time. At the very least, they are providing something called adware that's tracking, where you're going. Sometimes it replaces the ads on the website shows you stuff. It clicks through to these not clickbait sites, but click through to make them money on ads that they're running.

It's bad. We can't do it now. I wish we had more time. All right.

Your listening to Craig Peterson.

Stick around because when we get back, we're going to talk about an Apple problem with security this time.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553