Skip to content

Because not only autumn has a place in October: Cybersecurity Awareness Month.

Is Cybersecurity Awareness Month the event of the year?

Welcome back to the incredible and majestic Pandora FMS blog. In today’s post, we are going to deal with an event belonging to the month of October, that depressing month in which we become aware of fall, it is colder and someone keeps cutting short our daylight hours. If April is the month of flowers and November the month of the male mustache for testicular cancer, October is the Cybersecurity Awareness Month.

What is Cybersecurity Awareness Month?

Cybersecurity Awareness Month, which is commemorated every October, was created between the United States government and national industry to ensure that everyone had the necessary resources to stay safe and secure online.

Since its inception, under the supervision of the US Department of Homeland Security and the National Cyber Security Alliance, Cybersecurity Awareness Month has grown stronger and more widespread, reaching out to millions of users and businesses, and all types of corporations and institutions. Today, in 2021, it continues to make an impact, and not only in its country of origin, it already does around the world because, who would not join the cause of feeling more protected in these times we live in?

Cybersecurity Awareness Month: Origins

As we’ve explained, the National Cyber Security Alliance and the US Department of Homeland Security launched Cybersecurity Awareness Month in October as a shared effort to help Americans stay safe online. And they did it a few of years ago, at least all those that distance us from October 2004.

When a baby starts to walk, the first steps are short and simple. So were the early Cybersecurity Awareness Month awareness efforts. Most of them focused on giving recommendations on how to update the antivirus, at least twice a year. But little by little they increased their ambitions, their reach and their participation. For example, launching complex campaigns in the industry, involving clients, NGOs and even university campuses.

The organizers made it clear in these years that responsibility for cybersecurity problems is fully shared. From large companies to small users with their battered laptops, all of us must protect our digital treasures and always keep them under supervision.

The European Cybersecurity Month (ECSM)

What is European Cybersecurity Month? The European Cybersecurity Month works, like the American Cybersecurity Awareness Month, as an annual campaign devoted to promoting cybersecurity among users, companies and institutions. The only difference is that the European Cybersecurity Month is promoted by the European Union.

Throughout the month of October, safety information is provided online and awareness is raised through good practices. Activities are carried out around the entire continent: conferences, workshops, seminars, presentations, etc. Everything in order to make us finally aware of digital hygiene.

We must thank the European Union Agency for Cybersecurity (ENISA) and the European Commission for the fruitful month of European Cybersecurity Month, which, of course, has the full support of the EU Member States.

Some events of Cybersecurity Awareness Month

Like the Homecoming Week for high schools, Cybersecurity Awareness Month is also divided into different segments. We are going to list those established by the National Cybersecurity Alliance this year, 2021.

First week

The first week will be themed on creating strong passwords, using multi-factor authentication, backing up data, and updating software.

Only that way will we be able to realize how dependent we are on technology and reconsider the amount of personal and commercial data that we treasure on platforms located on the Internet. There, at the hand of any cybercriminal.

Second week

The motto? “You must be careful with emails, text messages, and chats opened by strangers and incognitos.” You are just one click away from a suspicious email, link, or attachment, to bother the hell out of you. Indeed phishing and digital scams in general have been on the rise since we began with this pandemic. Since we have the damn COVID among us, phishing attacks represent more than 80% of reported security incidents.

Third week

The third week of Cybersecurity Awareness Month will be focused on supporting, inspiring and applauding students who have chosen, or want to choose, a university career focused on cybersecurity. Whether they are teenagers, adults or confused kids who want to change fields of study. Cybersecurity is cool, youngster! It is fully growing and has space and credits for everyone!

Fourth week

This week we will try to make security a priority for companies more than ever. Incorporate security in products, processes, tools… Promote cybersecurity in employees and teams. Get cybersecurity in the minds of department heads until they themselves celebrate the vanguards and news of this discipline on a daily basis.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

Windows Print Spooler Failure: Why Should I Upgrade Immediately?

Updating the operating system is a common activity. However, in July 2021, one of Microsoft’s Windows updates gained prominence.  

Let’s talk about it: Windows print spooler failure: why should I update immediately?

What is Print Spooler Failure?

The print spooler is one of the Windows operating system components. Its purpose is to allow the exchange of information between computer and printer, as well as ordering the queue of documents that must be printed.

When this tool has a failure or there is a communication error between software and hardware, prints are not made.

Generally, these errors do not imply major security holes. However, the online disclosure of the flaw known as PrintNightmare sparks warning signs.

What is PrintNightmare?

PrintNightmare means exactly that. It has become known as a serious security hole in Windows print spooler.

Through this loophole, hackers can use the print spooler and its high level of access within Windows to completely control the computer.

With this, they can access any information, control programs and applications already installed, modify documents and folders, create new user accounts, and even install new apps. All this without the user having any control.

The print spooler failure does not only affect the latest versions of the Microsoft operating system. In fact, it can be exploited on computers with older versions, and even newer versions such as Windows 7.

If this error has been around for so long, why have updates been released to fix it just now?

Data security is essential to a company’s operations. Both protecting strategic information and customer data. Learn if your company is prepared for a cyberattack.

Print Spooler Failure Disclosure

The codes referring to this failure were released on the internet even before Microsoft experts were aware of the existence of the error.

Researchers at Sangfor Technologies, a Chinese company that works with network security systems, discovered this error and made a Proof of Concept (PoC), which is a hands-on exercise. It is used as documentation during the process of recognition, diagnosis, and correction of faults made by developers, whose goal is to demonstrate the feasibility and forms of a certain attack on a system.

Thus, the PoC created by Sangfor ended up being put online, as the researchers believed that the error had been resolved. When it was determined that Microsoft was not aware of the flaw, the information was taken down.

However, the PoC information ended up being posted on GitHub (a programmer’s social network that also serves as an information repository) before the fix was made available. Thus, sensitive data was available so that it could be analyzed and possible attacks planned.

According to Microsoft itself, the information regarding the print spooler failure and PrintNightmare have been used to carry out real attacks on computers using the Windows operating system.

Faced with this problem, Microsoft was forced to fix the errors quickly and release a new system update. It was released on July 6, 2021 and, according to the company, it is available for Windows 10, 8.1, and 7.

The company recommends that all Windows users immediately update their operating system in order to prevent the invasion of hackers through the print spooler failure.

How to Update Windows Operating System?

Normally, the Windows operating system is configured to automatically update the system. However, it is not uncommon for this function to fail.

Manually updating your Windows operating system is quite simple. Just access the settings through the Start Menu and click the icon referring to Updates and Security. Then click on the Windows Update tab and request to update the system.

For Windows 10, the update that fixes the print spooler failure is designated as follows: KB5004945. Once the update has been downloaded, simply restart your computer for the updates to install and the problem to be fixed.

senhasegura aims to maintain the security of information, acting against data theft and ensuring the sovereignty of companies over their information.

Visit our website and schedule a demonstration of our products.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

Key concepts of systems and networks

Together we check out the key concepts of systems and networks

In the middle of the information century, who has not surfed the Internet or used a computer, be it a desktop or a laptop? But do you really know what a computer is and what it is made of? and what about the Internet?

It is important to know at least the most superficial layer of something as important as computer systems and networks, and therefore, we are going to talk about the key concepts of these two topics.

computer system is a device made up of the union of hardware and software, which allows the use of this system by a person, whether qualified or not, that depends on the purpose of the system.

But, what does “hardware” and “software” mean? Let’s talk a little more about it.

You can define as hardware the set of physical components that make up a computer system. We are going to define the main components of a computer system, although there are a few more:

  • Processor: It is the component in charge of executing all the system programs. It is in turn made up of one or more CPUs.
  • RAM memory: This component stores the data and instructions executed by the CPUs and other system components.
  • Hard Drives: Information and content are stored here in computer systems.
  • Motherboard: It is the component where the others are located, and works as a bridge for communication between them.

Well, now that we have a basic understanding of what hardware is, we move on to software.

Software are all the programs that run on a computer system, among which you may differentiate three types of software:

  • System Software: It is responsible for the proper functioning of the operating system and hardware in general, such as device drivers.
  • Programming software: They are tools whose sole purpose is the development of new software.
  • Application software: It is any program designed to perform one or more specific tasks, for example video games or applications designed for business or education.

We already know what a computer system is, but without communication with the outside we are not making the most out of the potential that these systems have (which is a lot), so we decided to connect it to that abstract site full of information and services: the ‘Internet’.

Everyone knows the term “Internet”, but do we know what the “Internet” is?
We could say that the Internet is the great global network that unites all existing devices, allowing communication between all of them from anywhere on the planet. In turn, this large network is made up of other smaller networks, such as those of a country, city, neighborhood, etc.
Mainly, we distinguish three types of networks:

  • LAN: It is the smallest network, a local area network, such as the one in work areas or the one you have at home.
  • MAN: It is a somewhat larger network, being able to cover from neighborhoods to cities. They can also be the networks used by large companies for communication between their different offices.
  • WAN: It is a network that connects countries or even continents to each other, not devices. We can say that the Internet is the ultimate WAN network.

Ok, we already know what the Internet is made of. But, how do devices communicate on these networks? There are systems used to identify each computer on the network, known as IP addresses. An IP address is, basically, the ID or identifier of a device, so it is unique and unrepeatable.

At the beginning, when the idea of an IP address was created, there were only a few dozen computers in the whole world, and this, as we already know, has gotten quite out of control since then. As a result of this increase, they decided to come up with a new concept, known as DNS (for its acronym Domain Name System).

What the DNS protocol does is, basically, translate the domain name that we enter, either in the web browser or in any other program, and convert it into an IP address, with which it communicates with the destination. Of course, all domain names are stored on DNS servers, scattered around the world to avoid connection overload, and to avoid slow name resolutions.

There are a large number of protocols, each with a different purpose. These protocols are grouped in layers, such as application, transport, Internet or access to the network, according to the TCP/IP model. But, that’s not all. We still lack another important concept in relation to communications between devices, what we know as “ports” of a computer system.

Imagine a road, if all the traffic that wants to enter a city only had a single road, what would happen? Well, the same thing happens in computing, and that is why these virtual ports exist.

These ports range from 0 to 65535, but the first 1024 are reserved for “important” protocols, such as the DNS protocol, which we have mentioned above, belonging to the application layer and that uses port 53 for both UDP and TCP connections.

TCP and UDP are two protocols belonging to the transport layer, whose main difference is that the TCP protocol is connection-oriented. That is, the TCP protocol makes sure that the data reaches its destination, while the UDP protocol sends the data, faster but less securely. This data may even not arrive or at least not fully arrive.

The protocols for web connections or HTTP/HTTPS, both belong to the application layer. Depending on which one you choose, it uses a different port. That is, for HTTP connections, port 80/TCP is used, although it is deprecated due to its lack of security, so the standard has become HTTPS connections, which use port 443/TCP and include a security layer based on SSL/TLS.

Connections made through safe channels or SSH, also from the application layer, use port 22/TCP, and thus we could continue with lots of other protocols.

Of course, these ports are a standard in the systems that receive the requests, the client that initiates the request can use any port that is not reserved to send the request and receive this data. As you can see, this is much easier to communicate with servers, although they can also modify their default ports, but the normal thing is that they do not do so if they want to provide a public service.

Finally, we are going to talk about a concept that, due to the pandemic, is the order of the day: the VPN.

As its name indicates (Virtual Private Network), we can define a VPN as a network “tunnel” that is created between client and server, where data are fully encrypted and sent through the Internet. The common use of VPNs is anonymity on the network, since the IP that is exposed is that of the VPN server, or, also, to be able to visit pages that cannot be accessed from the source country.
In the business environment, this tunnel allows direct communication between the client device with any other device in the network of that server, which allows access to an environment as if we were physically in the office of our company. It also allows access control and registration, which otherwise could not be done.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.

ESET ramps up its consumer offering with new ESET HOME platform and ARM64 compatibility

BRATISLAVA — October 19, 2021 — Today, ESET, a global leader in cybersecurity, launched a new version of its consumer offering, which includes ESET NOD32 Antivirus, ESET Internet Security and ESET Smart Security® Premium. Users of these products will now have access to ESET HOME available as a mobile app or web portal to manage the security of all their Windows and Android home devices from one seamless and convenient interface.

Based on the ESET Threat Report T1 2021, the volume of cyberattacks in 2021 remained formidable, with a rise in threats targeting employees working remotely from home. According to customer research conducted by ESET, households often have a single person who takes care of IT security for everyone. As such, a solution that provides holistic security management at the home admin’s fingertips is crucial. To effectively address home users’ requirements and provide top-level protection ESET is introducing LiveGuard, integrated within ESET Smart Security® Premium. LiveGuard provides an additional proactive layer of protection against never-before-seen types of threats. Additionally, ESET NOD32 Antivirus, ESET Internet Security and ESET Smart Security® Premium offer improved protection and a host of new features for customers. At the center of the new offer is ESET HOME, a new and improved management platform that makes it easy to manage security at home whenever and wherever required. ESET HOME gives users comprehensive oversight of all their ESET solutions for Windows or Android devices in one place, allowing complete visibility of the current protection status of the various devices connected to their accounts. Accessible via web portal and mobile app, the ESET HOME platform is designed with mobile users in mind and built for on-the-go security management. The application enables users to add, manage and share licenses with family and friends, and to manage Anti-Theft, Parental Control and Password Manager via the web portal. Closely following the needs of its customers, ESET offers fresh improvements to its Banking & Payment Protection with extra security for customers accessing web-based cryptocurrency wallets, which are under ever-increasing threat by hackers, and banking websites for more secure ways of managing their assets. In addition, ESET NOD32 Antivirus has been ported to ARM64 and is available for free in the beta channel. Other key updates in the home security suite include:
  • ESET HOME — Parents can use ESET HOME to share licenses with family and friends or to monitor their children’s online activity and control their screen time in Parental Control (via the ESET HOME web portal).
  • LiveGuard — Integrated with ESET Smart Security® Premium, LiveGuard provides additional protection against never-before-seen types of threats, shielding users from the malware before its code executes. This service, personalized for each user, analyzes suspicious files, including documents, scripts, installers and executable files, in a safe sandbox environment.
  • Protection improvements — Banking & Payment Protection, available with ESET Internet Security and ESET Smart Security® Premium will now have the option to run by default, protecting any supported browser with a hardened mode. Ransomware Shield has been bolstered with enhanced behavior-based detection techniques. Exploit Blocker has been improved to cover additional malicious techniques.
  • Password Manager — Available with ESET Smart Security® Premium, Password Manager has been completely redesigned for improved security and ease of use. Password Manager is available in all major browsers as a browser extension and on Android and iOS devices as a native application. New features include support for KeePass and Microsoft Authenticator.

Mária Trnková, consumer & IoT segment director at ESET, commented, “We are incredibly excited about this launch and to provide consumers with the very latest in cybersecurity protection. The updated product suite, including our new LiveGuard feature and the impressive ESET HOME platform, puts users firmly in control of their home cybersecurity needs and instills them with the confidence needed to manage multiple devices on the go. After more than a year of being heavily reliant on technology, and with the threat landscape constantly evolving, it is vital to us that our consumer users are protected with cutting-edge solutions that are easily accessible and best in class in terms of user experience.”

To find out more about the new features and improvements in the latest version of our consumer offering, head to https://www.eset.com/hk/.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

The Importance of Integrating Security into DevOps

Technology has undergone constant change, as innovations that emerge today can be surpassed tomorrow, and so on. This is a reality that can be contemplated in the IT sector or corporate software developers.

As the market becomes increasingly competitive as a result of new technologies, the ideal of agility and efficiency must be achieved with excellence. Hence the need to increasingly integrate a company’s activities.

How? By integrating security into DevOps. But how does this work? That’s exactly what this article is about. Keep reading it!

What Is DevOps?

First of all, let’s understand this concept: DevOps is the combination of the development and operations words.

DevOps encompasses a set of processes and methods for integrating software development activities into IT operations.

The truth is that these two sectors have always been independent in their work, however, this reality causes some problems for companies, such as not knowing which of the two to request a certain demand, since the division of work is usually not clear enough for everyone.

With DevOps technology, this context tends to change as the activities to be done are distributed in a clear and organized way.

The implementation of this software development methodology brings a very beneficial transformation for software developers and IT operators, as it adds agility, speed, efficiency, and security to the entire environment.

But does DevOps really bring benefits to information security? Discover it now!

Also read: The Pillars of Information Security

DevOps Benefits

As it is a new technology, it is natural that some questions arise about its functionality and implementation advantages. That is why we are going to present here some improvements that DevOps adds to your company’s information security. Check it out!

Greater Collaboration Through Constant Analysis In practice, DevOps technology tends to automate operations across the entire environment. From this, the manager can follow all the steps of the processes accurately.

DevOps actively collaborates to make security happen through reliable monitoring and constant performance analysis early in the process.

Increased Reliability

With tests being performed at each stage of the process, the result becomes more reliable, as possible failures and correction needs are soon identified and resolved, and the operation continues without major problems.

DevOps allows teams to perform their activities in a synchronized way, from certified accesses, in addition to making the applications easier to use through an improved interface.

Intervention Power The use of DevOps increases employee participation, as the possibility of intervention at each stage facilitates the perception of failures and problem-solving before the final work is compromised.

All this happens through access control, which suggests even more security to the process as a whole.

The Importance of DevOps to Security

After learning about the benefits of this innovation to improve a company’s operations as a whole, it is clear that security is one of the priorities of this technology.

The purpose of integrating security into DevOps is to ensure security from the beginning of development and not just at the end, as is often the case.

Ideally, the two areas work in constant communication, based on an automated and integrated system that allows checking each step of the work, analyzing performance, and solving possible failures during the process.

When mapping each phase of development, the manager is able to identify the need for improvement to ensure greater protection in final operations.

Thus, DevOps works to integrate the development and IT teams with a focus on application security through the continuous delivery of analysis so that problems are solved more efficiently.

How to Implement DevOps In Your Company?

It is always important to have a company that specializes in the subject when implementing an innovation such as DevOps in your company, as it makes it easier to guide employees and conduct the work with the appropriate support.

By outsourcing this service, the manager is responsible for the interaction and control of deliveries between the teams. This dynamic tends to add more speed and efficiency to the final results.

Furthermore, the training required for the implementation of DevOps, being carried out by specialized professionals, will ensure greater collaboration and better performance of the teams involved in the processes.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×