Archive for October 18, 2023

President Biden Gets A Truth Social Account… No I Am Not Making That Up

Posted in Commentary with tags on October 18, 2023 by itnerd

Seriously. In the last couple of days, the campaign team for President Joe Biden has set up a Truth Social account. In effect, making this the ultimate 5000 IQ move. Here’s why:

The @BidenHQ account, the official digital rapid response channel of the Biden-Harris campaign, joined Truth Social on Monday following a swift rise on other social media platforms since its launch early October.

The account then began posting their signature videos, starting with clips of Donald Trump’s opponents such as Ron DeSantis and Nikki Haley calling out Trump’s policies and statements.

Deputy Biden campaign manager Rob Flaherty commented on the new digital strategy on X, saying, “A thing about campaigns is sometimes you just do things for the lolz.”

In a statement to Fox News Digital, the Biden campaign said, “There’s very little ‘truth’ happening on Truth Social, but at least now it’ll be a little fun.”

Here’s where it gets funny. After two days, this account has more followers than the Trump campaign’s account:

The account passed 23K followers on Truth Social on Wednesday.

The Team Trump account, the official account of the Trump campaign on Truth Social, has fewer than 20K followers.

The reason why this is hysterically funny is that Truth Social is thought to be the home of MAGA nation. But based on this, that perhaps isn’t the case. And if you’re Trump, you have to feel a little less manly being trolled on your home turf. Sucks to be him.

Give the Gift of Imagination this Holiday Season with Epson’s EcoTank ET-2850

Posted in Commentary with tags on October 18, 2023 by itnerd

With the holiday season right around the corner, it’s time to consider high-quality gifts that keep on giving. If there’s a creative kid in your life, a printer from Epson makes the perfect present because the crafting fun never has to end!

Encourage them to embrace their crafty side with the EcoTank ET-2850 Wireless Colour All-in-One Cartridge-Free Supertank Printer (MSRP: $399.99 CAD). A gift that will outlive most of their toys, this product’s capabilities allow kids of all ages to let their imaginations run wild. With up to 2 years of ink in the box, they can fully immerse themselves in whatever activity they’re working on without the fear of running out of ink.

Since they can print to their heart’s desire, the little ones can transform basic cut-outs into detailed decorations, while the older ones may feel inspired to create collages for gallery walls or stencils for DIY tote bags – we doubt you’ll hear “I’m bored!” quite as often. This printer has impressive print quality that produces sharp text and outstanding colour photos and graphics on virtually any paper type, which will help their crafts shine. Plus, if they’re tech savvy, they’ll enjoy the ability to easily print from their smart device with the intuitive Epson Smart Panel App.

Valve Adds Extra Security After Shadow PC Gets Pwned

Posted in Commentary with tags on October 18, 2023 by itnerd

Valve, the company behind the Steam video game platform has announced a new security feature after multiple reports of game updates being poisoned with malware:

As part of a security update, any Steamworks account setting builds live on the default/public branch of a released app will need to have a phone number associated with their account, so that Steam can text you a confirmation code before continuing. The same will be true for any Steamworks account that needs to add new users. This change will go live on October 24, 2023, so be sure to add a phone number to your account now. We also plan on adding this requirement for other Steamworks actions in the future.

This action was timely as Shadow PC got pwned because one employee downloaded a Steam game boobytrapped with malware.  Ken Westin, Field CISO, Panther Labs had this comment:

“This reflects a trend Panther has been seeing over the past few years as adversaries shift the focus of their attacks to developers who often have access to the crown jewels of tech companies — their source code. When attackers gain access to code repositories, DevOps tools, and cloud infrastructure it can be quite lucrative as they can not only steal code and deploy malware, but also inject malicious code to infect customers downstream. This trend is increasingly being utilized by not only criminal groups, but also nation-state actors as we have seen with the Lazarus Group out of North Korea. Organizations need to take additional measures to not only secure developers themselves, but also the environments they interact with on a daily basis — those with privileged access are particularly vulnerable.”

Perhaps other game platforms, or other platforms that distribute software should look at their security measures so as not to be the next vehicle for an attack. I say that because this is a great move by Steam to ensure the security of its platform.

Cyware Appoints Boyar Naito as Senior Director of Partnerships and Business Development

Posted in Commentary with tags on October 18, 2023 by itnerd

Cyware has announced the appointment of Boyar Naito as its new Senior Director of Partnerships and Business Development. Naito, with his extensive experience in the tech space, will provide invaluable guidance for Cyware’s business growth and partnerships.

Boyar Naito’s expertise lies at the intersection of technology and business development, where he has successfully managed and launched innovative products, forged key partnerships, and led high-performing teams throughout his career. His 15-year tenure at Google, one of the world’s most influential tech giants, has armed him with unique insights and experiences that will be invaluable for Cyware’s next phase of growth.

At Google, Naito held various leadership roles and was instrumental in spearheading numerous strategic partnerships, leaving an indelible mark on the tech industry. His decision to bring his skills and experience to Cyware underscores the company’s position.

EnGenius Expands Cloud Capabilities for MSPs

Posted in Commentary with tags on October 18, 2023 by itnerd

EnGenius unveils the MSP Portal within EnGenius Cloud. Tailored for the unique needs of Managed Service Providers, ISPs, VARs, and IT Services companies, the MSP Portal is a leap forward in simplifying multi-tenant network management. This new offering not only provides extra features but also enhances control and collaboration. 

Optimizing Inventory and License Management Across Organizations

EnGenius’ MSP Portal simplifies inventory and licensing management for MSPs across multiple organizations. MSPs can easily assign, move, and deregister network devices in different organizations using a unified panel. This streamlined approach minimizes complexities and reduces costs.

Empowering Support Teams across Multiple Organizations

EnGenius’s MSP Portal brings significant upgrades to support team management across various organizations.

Roger Liu, EVP at EnGenius Technologies, explains, “Consider a common scenario where you need to replace a support engineer from multiple tenants with another engineer member. This meant navigating through individual organization setting pages and configuring support privilege settings one by one. With the MSP Portal, those days are over. Administrators can easily assign or remove support team members across various organizations through a single integrated control panel. With this simplified configuration process, managing support teams has never been easier.”

Accelerated Customer Onboarding

The MSP Portal aims to make it easier and faster to bring new customers on board. MSPs can manage multiple tenant networks through a single dashboard and even duplicate selected or entire network configurations for new tenants. This reduces the need for repetitive configurations for site-based or organization-based settings, including network general settings (Alert/Firmware), SSID, Radio, VLAN, Firewall, and VPN settings.

Added Security and Flexibility 

EnGenius prioritizes security and stability and will offer MSPs the ability to disable automatic firmware updates and select a firmware version for uninterrupted network operation.  Security is enhanced through Single Sign-On (SSO), which allows control over the authentication of support team members and boosts operational efficiency across multiple systems. The support team can effortlessly access EnGenius Cloud using their internal credentials through SSO, ensuring simplicity and convenience.

EnGenius’s dedication to innovation and support has reached a new milestone with the introduction of the MSP Portal in EnGenius Cloud. This strategic enhancement goes beyond being just a feature and aligns with EnGenius’s objective of delivering exceptional service to clients by comprehending their requirements and challenges.

For more information on the EnGenius Cloud MSP Portal, please visit https://www.engeniustech.com/msp-portal.html.

 

Cryptojacking Malware Campaign Targeting Jupyter to Steal Credentials & Access Cloud Services

Posted in Commentary with tags on October 18, 2023 by itnerd

Cado Security has discovered a new cryptojacking campaign targeting exposed Jupyter Notebooks, commonly deployed in cloud environments, with providers such as Google and AWS offering them as managed services. This campaign is particularly “cloud-y” – not only is it targeting Jupyter, but the malware developer is deliberately trying to steal cloud credentials. Cado even saw attempts to use these credentials to access cloud services.

The payloads for the campaign are all hosted on codeberg.org, providing much of the same functionality as Github – the first time Cado researchers have encountered this platform in an active malware campaign. The malware includes relatively sophisticated command and control (C2) infrastructure, with the controller using Discord’s bot functionality to issue commands on compromised nodes and monitor the campaign’s progress.

Qubitstrike (the name given to malware by the developer) attackers specifically seek Cloud Service Provider (CSP) credentials. Cado observed attempts by the attackers to utilize stolen CSP credentials for further exploitation.

You can read the report here.

Nyriad Unveils Storage-as-a-Service (STaaS) Offering

Posted in Commentary with tags on October 18, 2023 by itnerd

Nyriad today announced the launch of UltraIOTM-as-a-Service, an on-premise Storage-as-a-Service (STaaS) offering tailored to meet the ever-increasing data management demands of modern enterprises.

Enterprises today face a myriad of hurdles, including capital budget constraints, rapid and unpredictable data growth, gaps in IT talent, operational complexity and ever-stringent sustainability mandates. Nyriad’s UltraIO-as-a-Service offering comprehensively addresses these challenges with flexible, simple-to-use STaaS options.

Nyriad’s UltraIO-as-a-Service user experience is defined by its simplicity, requiring only three key decisions: Contract Term, Data Services and Reserve Commitment. From there, Nyriad and its value-added reseller partners handle implementation and ongoing 24/7/365 proactive monitoring, alerting and customer support.

UltraIO-as-a-Service Features

The Nyriad UltraIO-as-a-Service STaaS offering focuses on three core customer-friendly tenets: Capacity Flexibility, Billing Simplicity and Operational Simplicity.

●  Capacity Flexibility:

○  Real-time flexibility to increase the Reserve Capacity throughout the term as business needs evolve, allowing the business to capitalize on lower Reserve Rates.

○  Allows customers to scale the Reserve Capacity back down within the term as long as it remains above the initial contracted amount.

○  Delivers an On-demand Capacity amount equal to or greater than the Reserve Capacity, allowing customers to rapidly deploy new workloads and offerings without requiring new contracts or additional capacity deployments.

●  Billing Simplicity:

○  Comprehensive reporting ensures visibility into storage consumption and system usage.

○  Eliminates billing surprises. The monthly On-Demand price per GB is the same as the Reserve Pricing – there are no premiums or overage charges for using the burst capacity.

○  Billing is based on the capacity used, eliminating the complexity associated with charging for allocated capacity or effective use based on data reduction.

●  Operational Simplicity:

○  Easily integrates with an ecosystem of third-party file systems and software solutions. 

○  Delivers round-the-clock proactive support with service-level agreements (SLAs).

○  Allows customers to subscribe to a single storage system for block, file and object data types – eliminating the cost and operational complexity of multiple storage solutions.

The UltraIO-as-a-Service is built on top of the UltraIO storage system, which delivers a powerful combination of consistent performance, fail-safe data availability and true management simplicity. Architected with a combination of GPUs and CPUs and leveraging advanced erasure coding techniques, the system leverages higher-capacity drives to deliver a high efficiency ratio of usable to raw capacity, up to 92 percent, at a low total cost of ownership. UltraIO can reduce the time required to complete complex projects by up to 35 percent and supports sustainability initiatives by reducing the carbon footprint by two-thirds compared to similarly sized RAID-based storage arrays from other vendors.

Nyriad’s introduction of UltraIO-as-a-Service comes at a pivotal moment for the global enterprise storage landscape. According to IDC’s IT Infrastructure for Storage and Data Management Survey (#US50532023, March 2023), the adoption of Storage as a Service (STaaS) is no longer a mere option but a strategic imperative for organizations aiming to remain competitive.

“Storage-as-a-Service models have changed the way companies of all sizes across industries consume storage to speed deployment, deploy burst capacity-on-demand and manage operational complexity, among other reasons,” said Dave Pearson, Research Vice President, Infrastructure Systems, Platforms, and Technologies Group, IDC. “As the models evolve and businesses become more accustomed to consuming storage as a service, customers are now scrutinizing service models more stringently to ensure they fully understand the nuances of each offering and don’t run into any surprises. With Nyriad’s introduction of their UltraIO-as-a-Service storage model, Nyriad looks to have provided a simple to understand and flexible offering for their partners and customers alike.”

“Nyriad’s UltraIO-as-a-Service STaaS offering removes much of the complexity we see with many similar offerings available today,” said Rod Wright, Executive Vice President, Global Sales and Engineering, Technologent. “Technologent thrives on our ability to provide compelling and easily accessible offerings that support our customers’ business needs. Delivering innovative and modern solutions like UltraIO-as-a-Service positions us as a critical and forward-thinking partner who always strives to add value for our customers.”

“We spent considerable time listening to our customers and partners to understand which features of existing storage-as-a-service offerings deliver real value to their customers,” said Andrew Russell, Chief Revenue Officer, Nyriad, Inc. “Armed with that intelligence, we are confident UltraIO-as-a-Service positions our partners to offer their end customers an easy-to-understand, easy-to-deploy, and easy-to-consume storage solution that meets their technology, business, and budgetary requirements.” 

To learn more about UltraIO-as-a-Service, please visit: www.nyriad.io/staas

Guest Post: Patient data breaches doubled, reaching 87M in 2023

Posted in Commentary with tags on October 18, 2023 by itnerd

Healthcare companies are increasingly falling victim to sophisticated hacking efforts, insider threats, and basic security flaws despite the highly confidential nature of patient data.

According to the data presented by the Atlas VPN team, 87 million patients in the United States had their information breached in 2023. That is more than twice as much as last year when 37 million people had their data exposed.

In 2022, over 37 million patients in the U.S. had their personal information exposed by healthcare organizations. However, breaches have skyrocketed this year. Just in the first half of 2023, hackers stole the data of over 41 million people. The third quarter marked an even greater cause for alarm, with 45 million more patients impacted. 

Overall, there have already been 480 reported data breaches across the healthcare sector in the first three quarters of 2023 alone. This compares to only 373 total breaches during the entirety of 2022, highlighting the alarming acceleration in attacks. 

The largest data incident so far was the HCA Healthcare breach, which impacted 11 million people.

Cybersecurity writer at Atlas VPN, Vilius Kardelis, shares his thoughts on data breaches in healthcare organizations:

“The sensitive nature of medical records makes them highly desirable targets for criminals, thus demanding the strongest security standards. Patients deserve to know their most personal information is safe, and providers must ensure that confidence. Healthcare has to view data protection as being just as critical as patient care.”

Most vulnerable states

While healthcare data breaches impact patients nationwide, analysis shows certain states have been affected more than others.

California tops the list with 43 healthcare organizations afflicted by data breaches so far this year. The state’s massive population and concentration of healthcare providers likely make California a prime target.

New York comes in second, with 42 healthcare data breaches reported. Texas is third, with 38 healthcare entities experiencing breaches. Other states near the top include Massachusetts and Pennsylvania, with 31 and 30 breaches, respectively.

Interestingly, Vermont remains the only state with no reported healthcare breaches in 2023.

To read the full article, head over to:

https://atlasvpn.com/blog/patient-data-breaches-doubled-reaching-87m-in-2023

patient-data-breaches-doubled-reaching-87m-in-2023

Twitter Is Testing A $1 Charge For Users To Allegedly Stop Bots

Posted in Commentary with tags on October 18, 2023 by itnerd

The end of Twitter is closer than you think. Yes, I’ve been saying that since Elon Musk took over and turned the once popular social media site into a cesspool of hate among other things. But this news brainwave from Elon shows that he’s officially out of ideas and is unable to get the site to make money. Remember when Elon said that he would charge a small fee to stop bots from taking over the platform? Well, it’s happening. This appeared overnight that details the fact that Twitter is testing a subscription feature called “Not A Bot”. The test will be conducted with new accounts on web in New Zealand and the Philippines. Here’s how it works:

  • Users in the two test countries are required to verify their phone number.
  • Successful verification then leads to the next step which is paying $1 USD a year to interact with others on X.

And if you don’t pay, you can only read Tweets. You won’t be able to do anything that any free account can currently do.

My thoughts on this are as follows. First, this will not deter bots. Because bots are already running rampant on the platform, and some even have verified checkmarks. Meaning that they’re paying to be on the platform. All this does is lower the bar of entry for bots. Or put another way, they’re getting a discount to be on the platform under this scheme.

The thing is, the bot thing has always been cover for Elon. The real end goal for Elon is to use this as a means to force people to pay to use Twitter. The problem with that logic is that traffic to Twitter has been in free fall since he took over. Which suggests that less people are using Twitter today than a year ago. Or that people are using Twitter less as there’s no value in using Twitter anymore. Perhaps both. Thus getting people to serve up $1 a year is not going to be a money maker. But to be fair, the “Not a bot” document kind of suggests that. Not that I believe it though.

Mark my words, Elon will at some point try to make this a world wide thing. Then he’ll jack the price on it in another desperate attempt to make money. And that will put one of the final nails in Twitter’s coffin.

Get your popcorn ready.