Penetration Testing, Incident Response, PCI Assessments
Appalachia Technologies Acquires Cyber Protection Group
Cyber Protection Group is excited to announce that it has been acquired by Appalachia Technologies out of Mechanicsburg, PA. We are excited about this acquisition because our clients will benefit from deeper resources and expertise from Appalachia Technologies. Appalachia was founded in 2004 and is a Best Places to Work for in PA for 5 years in a row. Appalachia has been a Top 50 Fastest Growing Company in PA and named on the Channel Futures MSP 501 and CRN MSP 500 Lists. They are a SOC2, Type II Audited company that provides services such as: Security Assessments, Penetration Testing, Vulnerability Scanning, Managed Threat Detection and Response, Firewall, VPN, and other services. Read More
United States Improves Critical Infrastructure Security
United States Improves Critical Infrastructure Security by Passing Five Bills. The cyber security incident that recently affected Colonial Pipeline showed the extreme need to protect our critical infrastructure. Ransomware successfully hindered the delivery of fuel to a large portion of the East Coast. Colonial Pipelines and other critical infrastructure could prevent cyber security incidents with enhanced security that prepares themselves for the imminent attacks. Finally, the United States House Committee on Homeland Security recently passed five bills to increase cyber defenses for United State organizations and critical infrastructure. Why Attack Critical Infrastructure? People and organizations not only depend on critical infrastructure, they need the critical infrastructure. Read More
Hacking Group Stops Oil Pipeline and Breaks 45% of the United States Oil Supply
Hacking Group Stops Oil Pipeline and Breaks 45% of the United States Oil Supply. When you hear about a cyber attack, generally you assume that some sort of IT infrastructure suffered damage. Your assumptions might include servers, web applications, or even the business processes that those systems support. However, ransomware disables the largest pipeline in the United States in a recent attack. This attack goes to show that as cyber attacks evolve, the cyber world can be used to inflict damage on the physical world and its infrastructure. Read More
What is Penetration Testing and Why Do You Need It?
What is Penetration Testing and Why Do You Need It? Across all your systems, applications, and software on your network lay vulnerabilities. Malicious attackers can exploit vulnerabilities and serious damage. These vulnerabilities can lead to data loss, system downtime, financial loss, malware, and even ransomware. Most of the time, organizations can easily remediate these vulnerabilities; however, if you do not know of their existence, how can you fix it? What is Penetration Testing? Penetration Testing is a practice conducted on systems in order to find exploitable vulnerabilities. By finding vulnerabilities, organizations can stay proactive in their security stance. Read More
Quick! Update Your iPhone and iPad!
Quick! Update Your iPhone and iPad! These days, your smartphones and tablets are more of extra ligaments rather than just simply devices. Monday, Apple quickly released a security update for their iPhone and iPad product lines. Furthermore, if you happen to own either an iPhone, iPad, or Apple Watch you should immediately run updates in order to install the latest security patches. Read More
A Week in Security: REvil Extortion, RDP Stolen Credentials, Geico Breach, and Chrome Exploits
A Week in Security: REvil Extortion, RDP Stolen Credentials, Geico Breach, and Chrome Exploits. As we approach the weekend, let us look back at this past week at the top cyber security news. This week in cyber security, REvil attempted to extort Apple using their stolen data. Additionally, UAS leaked 1.3 million Windows RDP logins for sale on their marketplace. Read More
1.3 Million Windows RDP Logins Stolen and Sold on Dark Web
1.3 Million Windows RDP Logins Stolen and Sold on Dark Web. Remote Desktop Protocol (RDP) is one of the most widely used services to remotely control other systems. However, when left open, the system is vulnerable to complete remote control to whomever decides to access it. Read More
Half a Billion LinkedIn Accounts Are Being Sold Online
Half a Billion LinkedIn Accounts Are Being Sold Online. When setting up a LinkedIn account, you enter certain information regarding yourself such as an email address, birthday, schooling, work experience. Read More
The Second Largest Ransomware Attack In History
The Second Largest Ransomware Attack In History. Suffering from a ransomware attack can be devastating in itself. Operations and systems become disabled, workflow stops, not to mention the financial loss and exfiltration of your sensitive data. Read More
BYOB? What about BYOD?
BYOB? What about BYOD? Generally, no company ever lets employees bring in their own beer, but what about their own devices? Read More