This week's episode covers North Korea hacking Russia, malware in SSD hard drives, a USB drive warning, and the Log4Shell exploits continue.

 

 


North Korean Hackers Start New Year with Attacks on Russian Foreign Ministry

The Hacker News

Attack Type:

CS Standards and Regs v2   Threat actors v2   

 

What To Know:  North Korea is launching targeted cyber-attacks against Russia’s Ministry of Foreign Affairs.

Why You Should Care:  North Korea is bold, has respectable offensive cyber warfare capabilities, and will use them against the United States if they deem it necessary or advantageous.


Firmware attack can drop persistent malware in hidden SSD area

Bleeping Computer

Attack Type: 

Malicious Logic v2   Threat actors v2   Tech failure v2

 

What To Know:  Solid state hard drives have a “hidden” area that can be used to hide malicious code.

Why You Should Care: The use of solid-state drive technology has become widespread and may constitute a risk to your organization.


FBI warns cybercriminals have tried to hack US firms by mailing malicious USB drives

CNN

Attack Type: 

Threat actors v2   Human v2   Human v2

 

What To Know:  ^^^^ Notice that I put human stupidity twice.  Hackers are using USPS to snail mail thumb drives to businesses, which have viruses on them.  The thumb drives are labeled as being from reputable organizations.

Why You Should Care:  People still need to be trained in the handling of USB drives.  And then trained again.  No one should be using an uncontrolled USB drive, any more than they should be taking pills out of an unlabeled bottle.


Log4j flaw attack levels remain high, Microsoft warns

ZDNet

Attack Type: 

 Malicious Logic v2   Malicious Logic v2   Human v2   Tech failure v2   CS Standards and Regs v2

 

What To Know:  Log4j was one of the big cybersecurity news items for 2021, so big in fact that the MSM covered it as well.  This is a nasty bug that is still widespread. Your network NEEDS proper patch and vulnerability management.  Now.

Why You Should Care:  If you are running Apache Web Server, it is highly probable this bug affects you.  It is extremely easy to exploit, and hackers can cause extreme damage to your business.

 

News & Updates

APPALACHIA IN THE NEWS: Appalachia Technologies Cited in Case Study to Improve Efficiencies and Service Delivery   Improve and Evolve - this is one of the five Core Values of Appalachia Technologies and one we believe helps us to stay at the forefront of our industry.  Our Technical Assistance Center (TAC), while performing well and delivering quality service, was being challenged by processes for documentation that were manual and outdated.  Not satisfied with the current way of doing this, Chris Swecker, Manager of TAC, began to explore IT Glue.  IT Glue centralizes information, allowing for efficiencies in response time, accuracy, and client satisfaction.  As he explains, "IT Glue became our source of truth."  Chris and his team built on the success by incorporating additional tools to assist with password rotation and a client-side tool for password management and shared documentation.  

Contact Us

Learn more about what Appalachia Technologies can do for your business.

Appalachia Technologies
5000 Ritter Road Suite 104
Mechanicsburg, Pennsylvania 17055

Appalachia Technologies
  • About Us
  • IT Services
  • Compliance
  • Resources
  • Contact Us
  • Who We Serve
  • Speaker Request
  • (888) 277-8320