<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" >

<channel><title><![CDATA[myVDH - Blog]]></title><link><![CDATA[http://www.myvdh.com/blog]]></link><description><![CDATA[Blog]]></description><pubDate>Thu, 29 Jan 2026 18:33:42 +0800</pubDate><generator>Weebly</generator><item><title><![CDATA[Celsius email system breach leads to phishing attack on customers]]></title><link><![CDATA[http://www.myvdh.com/blog/celsius-email-system-breach-leads-to-phishing-attack-on-customers]]></link><comments><![CDATA[http://www.myvdh.com/blog/celsius-email-system-breach-leads-to-phishing-attack-on-customers#comments]]></comments><pubDate>Wed, 14 Apr 2021 16:00:00 GMT</pubDate><category><![CDATA[Security]]></category><guid isPermaLink="false">http://www.myvdh.com/blog/celsius-email-system-breach-leads-to-phishing-attack-on-customers</guid><description><![CDATA[Cryptocurrency rewards platform Celsius Network has disclosed a security breach exposing customer information that led to a phishing attack.Today, Celsius CEO Alex Mashinsky&nbsp;stated that Celsius' third-party marketing server was compromised, and threat actors gained access to a partial Celsius customer list."An unauthorized party managed to gain access to a back-up third-party email distribution system which had connections to a partial customer email list. Once inside the system, this unaut [...] ]]></description><content:encoded><![CDATA[<div class="paragraph">Cryptocurrency rewards platform Celsius Network has disclosed a security breach exposing customer information that led to a phishing attack.<br /><span></span>Today, Celsius CEO Alex Mashinsky&nbsp;stated that Celsius' third-party marketing server was compromised, and threat actors gained access to a partial Celsius customer list.<br /><br /><span style="color:rgb(7, 7, 7)">"An unauthorized party managed to gain access to a back-up third-party email distribution system which had connections to a partial customer email list. Once inside the system, this unauthorized party sent a fraudulent email announcement, of which we know some of the recipients to be Celsius customers."<br /><br /></span>"The intent was to make the recipients believe the fraudulent email came from Celsius, that the fraudulent site was a true Celsius site, and to take ownership of recipients&rsquo; cryptocurrency assets from their personal (non-Celsius) wallet by prompting the user to provide the seed phrase to their personal wallet address," disclosed a Celsius&nbsp;advisory.<br /><span></span>After gaining access to the customer list, the threat actors impersonated Celsius Networks in phishing texts and emails that promoted a new Celsius Web Wallet. As an incentive to get people to visit the site, the text states Celsius is offering $500 in the CEL cryptocurrency if they create a wallet and enter a special promo code.<br /><span></span><br /><span style="font-weight:700">Celsius phishing text message</span><br /><br />Clicking on the link led recipients to the phishing site celsiuswallet[.]network, which is now down, that asked visitors to create a Celsius Web Wallet.<br /><span></span>When you attempted to create this fake wallet, the site asked visitors to link their other online wallets and input those wallet's seed phrases. Once this seed phrase is provided, the threat actors can import your wallet and steal any cryptocurrency within it.<br /><span></span><br /><span style="font-weight:700">Celsius phishing site</span><br /><br />VirusTotal&nbsp;shows that the celsiuswallet[.]network phishing domain initially had a DNS SOA record that indicated it was registered at the Njalla&nbsp;registrar.<br /><span></span><br /><span style="font-weight:700">Njalla SOA</span>Njalla is a registrar located in Sweden that is a favorite for certain threat actors, such as the Fancy Bear and Cozy Bear Russian hacking groups.<br /><br /><br /><span></span>A recent scam site using Njalla called 'Solar Leaks' was created to allegedly&nbsp;sell data stolen during the SolarWinds attacks.<br /><span></span><span style="color:rgb(7, 7, 7)"></span></div>]]></content:encoded></item><item><title><![CDATA[100% A.I Data DISASTER RECOVERY when files get ransomware attacked]]></title><link><![CDATA[http://www.myvdh.com/blog/100-ai-data-disaster-recovery-when-files-get-ransomware-attacked]]></link><comments><![CDATA[http://www.myvdh.com/blog/100-ai-data-disaster-recovery-when-files-get-ransomware-attacked#comments]]></comments><pubDate>Tue, 13 Apr 2021 16:00:00 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">http://www.myvdh.com/blog/100-ai-data-disaster-recovery-when-files-get-ransomware-attacked</guid><description><![CDATA[You cannot guarantee your management that the following disasters won&rsquo;t happen.&nbsp;Antivirus failed to protect&nbsp;Hard-disks failure&nbsp;On-premise file backups infected&nbsp;Online file backups infected&nbsp;Office fire destroys file data&nbsp;Traditional data recovery services cannot work&#8203;Traditional antivirus, online / backups can only do so much&hellip; there is still margin of failure.&nbsp;Companies and IT departments know that these are real problems waiting to happen.&nb [...] ]]></description><content:encoded><![CDATA[<div class="paragraph"><br />You cannot guarantee your management that the following disasters won&rsquo;t happen.<ul><li>&nbsp;Antivirus failed to protect</li><li>&nbsp;Hard-disks failure</li><li>&nbsp;On-premise file backups infected</li></ul><ul><li>&nbsp;Online file backups infected</li><li>&nbsp;Office fire destroys file data</li><li>&nbsp;Traditional data recovery services cannot work</li></ul><br />&#8203;Traditional antivirus, online / backups can only do so much&hellip; there is still margin of failure.<ul><li>&nbsp;Companies and IT departments know that these are real problems waiting to happen.</li><li>&nbsp;They cannot predict when these &ldquo;ticking IT time bombs&rdquo; will go off.</li></ul><br />&#8203;With a.i. Data Disaster Recovery (ai-DDR) technology implemented, it helps overcome these major issues.<ul><li>&nbsp;ai-DDR is a proprietary encrypted artificial intelligence system operating in the datacentre background analyzing real-time data streams.</li><li>&nbsp;When the client notifies our datacentre of a disaster that occurred, the ai-DDR is then helps reconstruct the corrupted files.</li></ul> The a.i. Data Disaster Recovery ai-DDR system has been operating since 2010 with 100% track record.</div>]]></content:encoded></item><item><title><![CDATA[Joker malware infects over 500,000 Huawei Android devices]]></title><link><![CDATA[http://www.myvdh.com/blog/joker-malware-infects-over-500000-huawei-android-devices]]></link><comments><![CDATA[http://www.myvdh.com/blog/joker-malware-infects-over-500000-huawei-android-devices#comments]]></comments><pubDate>Fri, 09 Apr 2021 16:00:00 GMT</pubDate><category><![CDATA[Security]]></category><guid isPermaLink="false">http://www.myvdh.com/blog/joker-malware-infects-over-500000-huawei-android-devices</guid><description><![CDATA[More than 500,000 Huawei users have downloaded from the company&rsquo;s official Android store applications infected with Joker malware that subscribes to premium mobile services.Researchers found ten seemingly harmless apps in AppGallery that contained code for connecting to malicious command and control server to receive configurations and additional components.Masked by functional appsA report from antivirus maker Doctor Web notes that the malicious apps retained their advertised functionalit [...] ]]></description><content:encoded><![CDATA[<div class="paragraph">More than 500,000 Huawei users have downloaded from the company&rsquo;s official Android store applications infected with Joker malware that subscribes to premium mobile services.<br />Researchers found ten seemingly harmless apps in AppGallery that contained code for connecting to malicious command and control server to receive configurations and additional components.<br /><br />Masked by functional appsA report from antivirus maker Doctor Web notes that the malicious apps retained their advertised functionality but downloaded components that subscribed users to premium mobile services.<br /><br />To keep users in the dark the infected apps requested access to notifications, which allowed them to intercept confirmation codes delivered over SMS by the subscription service.<br />According to the researchers, the malware could subscribe a user to a maximum of five services, although the threat actor could modify this limitation at any time.<br />The list of malicious applications included virtual keyboards, a camera app, a launcher, an online messenger, a sticker collection, coloring programs, and a game.<br /><br />Most of them came from one developer (Shanxi Kuailaipai Network Technology Co., Ltd.) and two from a different one. These ten apps were downloaded by more than 538,000 Huawei users, Doctor Web says.<br /><br />Doctor Web informed Huawei of these apps and the company removed them from AppGallery. While new users can no longer download them, those that already have the apps running on their devices need to run a manual cleanup. The table below lists the name name of the application and its package:<br /></div>  <div id="472914536245679441"><div><style type="text/css">	#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table-wrapper {  padding: 20px 0;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table {  width: 100%;  border: 1px solid #C9CDCF;  border-spacing: 0;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table td.cell {  border-right: 1px solid #C9CDCF;  border-bottom: 1px solid #C9CDCF;  word-break: break-word;  background-color: #FFFFFF;  width: 50%;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table td.cell .paragraph {  width: 90%;  margin: 0 5%;  padding-bottom: 10px;  padding-top: 10px;  text-align: center;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table.style-top tr:first-child td,#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table.style-side td:first-of-type {  background-color: #F8F8F8;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table.style-top tr:first-child td .paragraph,#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table.style-side td:first-of-type .paragraph {  font-weight: 700;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table tr:last-child td {  border-bottom: none;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table td:last-of-type {  border-right: none;}#element-c88585a2-facb-4b4a-9af8-74830c7e62e9 .simple-table .empty-content-area-element {  padding-left: 0px !important;}</style><div id="element-c88585a2-facb-4b4a-9af8-74830c7e62e9" data-platform-element-id="702688850553606843-1.4.3" class="platform-element-contents">	<div class="simple-table-wrapper">  <table class="simple-table style-top">      <tr>          <td class="cell"><div class="paragraph">Application Name</div></td>          <td class="cell"><div class="paragraph">Package name</div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Super Keyboard</span></div></td>          <td class="cell"><div class="paragraph">&#8203;<span style="color:rgb(7, 7, 7)">com.nova.superkeyboard</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Happy Colour</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.colour.syuhgbvcff</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Fun Color</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.funcolor.toucheffects</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">New 2021 Keyboard</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.newyear.onekeyboard</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Camera MX - Photo Video Camera</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.sdkfj.uhbnji.dsfeff</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">BeautyPlus Camera</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.beautyplus.excetwa.camera</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Color RollingIcon</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.hwcolor.jinbao.rollingicon</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Funney Meme Emoji</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.meme.rouijhhkl</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">Happy Tapping</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.tap.tap.duedd</span></div></td>      </tr>      <tr>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">All-in-One Messenger</span></div></td>          <td class="cell"><div class="paragraph"><span style="color:rgb(7, 7, 7)">com.messenger.sjdoifo</span></div></td>      </tr>  </table></div></div><div style="clear:both;"></div></div></div>  <div class="paragraph">The researchers say that the same modules downloaded by the infected apps in AppGallery were also present in other apps on Google Play, used by other versions of Joker malware. The full list of indicators of compromise is available&nbsp;<a href="https://github.com/DoctorWebLtd/malware-iocs/blob/master/Android.Joker/README.adoc">here</a>.<br /><br />Once active, the malware communicates to its remote server to get the configuration file, which contains a list of tasks, websites for premium services, JavaScript that mimics user interaction.<br /><br />Joker malware&rsquo;s history goes as far back as 2017 and constantly found its way in apps distributed through Google Play store. In October 2019,&nbsp;<a href="https://twitter.com/sh1shk0va">Tatyana Shishkova</a>, Android malware analyst at Kaspersky, tweeted about more than 70 compromised apps that had made it into the official store.<br /><br />And the reports about the malware in Google Play kept coming. In early 2020,&nbsp;<a href="https://www.bleepingcomputer.com/news/security/google-removed-over-17k-joker-malware-infected-apps-from-play-store/">Google announced</a>&nbsp;that since 2017, it had removed about 1,700 apps infected with Joker.<br /><br />Last February, Joker was still&nbsp;<a href="https://www.bleepingcomputer.com/news/security/android-malware-joker-still-fools-googles-defense-new-clicker-found/">present in the store</a>&nbsp;and it&nbsp;<a href="https://www.bleepingcomputer.com/news/security/joker-android-malware-keeps-evading-google-play-store-defenses/">continued to slip</a>&nbsp;past Google&rsquo;s defenses even in July last year.</div>]]></content:encoded></item><item><title><![CDATA[Fortinet FortiOS VPN Likely Exploited by Hackers, Feds Say]]></title><link><![CDATA[http://www.myvdh.com/blog/fortinet-fortios-vpn-likely-exploited-by-hackers-feds-say]]></link><comments><![CDATA[http://www.myvdh.com/blog/fortinet-fortios-vpn-likely-exploited-by-hackers-feds-say#comments]]></comments><pubDate>Sun, 04 Apr 2021 16:00:00 GMT</pubDate><category><![CDATA[Security]]></category><guid isPermaLink="false">http://www.myvdh.com/blog/fortinet-fortios-vpn-likely-exploited-by-hackers-feds-say</guid><description><![CDATA[Threat actors have been targeting VPNs even more this last year.Two federal agencies say advanced persistent threat (APT) groups are likely exploiting vulnerabilities in the&nbsp;Fortinet&nbsp;FortiOS VPN.The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued the&nbsp;advisory. They said APT actors have historically exploited critical vulnerabilities to conduct distributed denial-of-service (DDoS) attacks, ransomware attacks, structured query language (SQL) injection atta [...] ]]></description><content:encoded><![CDATA[<div class="paragraph"><span><strong>Threat actors have been targeting VPNs even more this last year.</strong></span><br /><br />Two federal agencies say advanced persistent threat (APT) groups are likely exploiting vulnerabilities in the&nbsp;<a href="https://www.fortinet.com/partners/partner-program/become-a-fortinet-partner" target="_blank">Fortinet</a>&nbsp;FortiOS VPN.<br /><br />The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued the&nbsp;advisory. They said APT actors have historically exploited critical vulnerabilities to conduct distributed denial-of-service (DDoS) attacks, ransomware attacks, structured query language (SQL) injection attacks,&nbsp;spear phishing&nbsp;campaigns, website defacements and disinformation campaigns.<br /><br />The ATP actors are using multiple common vulnerabilities and exposures (CVEs) to exploit&nbsp;Fortinet&nbsp;FortiOS vulnerabilities. They&rsquo;re doing this to to gain access to multiple government, commercial and technology services networks.<br /><br />These malicious hackers may use other CVEs to gain access to critical infrastructure networks to prepare for follow-on attacks.<br /><br /><strong>Customers Urged to Upgrade&nbsp;</strong><br /><br />Fortinet&nbsp;sent us the following statement:<br /><br />&ldquo;The security of our customers is our first priority. CVE-2018-13379 is an old vulnerability resolved in May 2019. Fortinet immediately issued a product security incident response team (PSIRT) advisory and communicated directly with customers and via corporate blog posts on multiple occasions in August 2019 and July 2020 strongly recommending an upgrade. Upon resolution we have consistently communicated with customers, as recently as late as 2020. CVE-2019-5591 was resolved in July 2019 and CVE-2020-12812 was resolved in July 2020. If customers have not done so, we urge them to immediately implement the upgrade and mitigations.&rdquo;<br /><br />Zach Hanley is senior red team engineer at&nbsp;Horizon3.A<a href="https://www.horizon3.ai/" target="_blank">I</a>.<br /><br />&ldquo;Attackers are increasingly targeting critical external applications,&rdquo; he said. &ldquo;VPNs have been targeted even more this last year. These three vulnerabilities targeting the Fortinet VPN allow an attacker to obtain valid credentials, bypass multifactor authentication (MFA), and man-in-the-middle (MITM) authentication traffic to intercept credentials. The common theme here is once they are successful, they will look just like your normal users.&rdquo;<br /><br /><strong>Taking Advantage of Sensitive Vulnerabilities</strong><br /><br />Yaniv Bar-Dayan is&nbsp;Vulcan Cyber&lsquo;s CEO and co-founder.<br /><br />&ldquo;Last year saw a multitude of damaging consequences from ransomware, breaches and targeted attacks against sensitive data,&rdquo; he said. &ldquo;From breaches of COVID-19 research data, to attacks on critical infrastructure and government agencies, cybercriminals have taken advantage of the most sensitive vulnerabilities at the expense of the organizations that have the most to lose.&rdquo;<br />The past year should have been a wake-up call to security teams that have been resistant to change, Bar-Dayan said.<br /><br />&ldquo;As&nbsp;remote working&nbsp;continues to be the norm, even after this pandemic subsides, an agile security team and agile infrastructure will be critical,&rdquo; he said.<br />Security teams must carefully orchestrate and manage remediation activities, Bar-Dayan said.<br /><br />Furthermore, organizations must continue looking for new ways to be ready for the ever evolving threat landscape.<br /><br />Dirk Schrader is global vice president of security research at New Net Technologies (<a href="https://www.newnettechnologies.com/" target="_blank">NNT</a>).<br />&#8203;<br />&ldquo;Exploiting vulnerabilities in key infrastructure devices like firewalls is a critical path for attackers as it allows [them] to establish [a] foothold behind them,&rdquo; he said. &ldquo;For any organization, monitoring these devices, patching them [and] controlling any configuration changes on them is a priority job for the security teams.&rdquo;</div>]]></content:encoded></item><item><title><![CDATA[The Often-Overlooked Element of a Hack: Endpoints]]></title><link><![CDATA[http://www.myvdh.com/blog/the-often-overlooked-element-of-a-hack-endpoints]]></link><comments><![CDATA[http://www.myvdh.com/blog/the-often-overlooked-element-of-a-hack-endpoints#comments]]></comments><pubDate>Tue, 30 Mar 2021 16:00:00 GMT</pubDate><category><![CDATA[Security]]></category><guid isPermaLink="false">http://www.myvdh.com/blog/the-often-overlooked-element-of-a-hack-endpoints</guid><description><![CDATA[It is Vital to Maintain Granular Visibility and Control Over Access Points to Establish Resilience&nbsp;The number of data breaches has skyrocketed during the ongoing health crisis, as hackers have taken full advantage of these uncertain times. According to the&nbsp;FBI&rsquo;s 2020 Internet Crime Report, complaints soared by 69.4% in the last year. Unfortunately, media coverage of mega breaches (e.g.,&nbsp;SolarWinds,&nbsp;Capital One) often puts a spotlight on the tail end of the cyber-attack  [...] ]]></description><content:encoded><![CDATA[<div class="paragraph"><span><span><strong>It is Vital to Maintain Granular Visibility and Control Over Access Points to E</strong><strong>stablish Resilience&nbsp;</strong></span></span><br /><br /><span><span>The number of data breaches has skyrocketed during the ongoing health crisis, as hackers have taken full advantage of these uncertain times. According to the&nbsp;FBI&rsquo;s 2020 Internet Crime Report, complaints soared by 69.4% in the last year. Unfortunately, media coverage of mega breaches (e.g.,&nbsp;SolarWinds,&nbsp;Capital One) often puts a spotlight on the tail end of the cyber-attack life cycle, focusing on the exfiltration points rather than how the threat actor got there. Implementing an effective enterprise security strategy requires an understanding of hackers&rsquo; tactics, techniques, and procedures (so-called TTPs). In this context, it is vital for security practitioners to review the entire cyber-attack lifecycle to gain a full grasp of the areas that need to be addressed as part of an in-depth cyber defense approach.</span></span><br /><br /><span><span>Post-mortem analysis has repeatedly found that the most common source of a hack are compromised credentials that are subsequently used to establish a beachhead on an end user endpoint (e.g., desktop, laptop, or mobile device). This tactic, however, is often &ldquo;overlooked&rdquo; in anatomy of a hack discussions. This is surprising, considering that endpoints serve as the main points of access to an enterprise network and can be exploited by malicious actors. In fact, a recent Ponemon Institute survey revealed that 68 percent of organizations suffered a successful endpoint attack within the last 12 months.</span></span><br /><br /><strong><span><span>Today&rsquo;s Cyber-Attack Lifecycle</span></span></strong><br /><br /><span><span>Most of today&rsquo;s cyber-attacks are front-ended by credential harvesting campaigns that use social engineering techniques, password sniffers, phishing campaigns, digital scanners, malware attacks, or any combination of these. Cyber criminals also take advantage of millions of stolen credentials being sold on the Dark Web.&nbsp;</span></span><br /><br /><span><span>Once in possession of stolen, weak, or&nbsp;<strong>compromised credentials</strong>,&nbsp;attackers are leveraging brute force, credential stuffing, or password spraying campaigns to gain access to their target environment. Increasingly, cyber adversaries take advantage of the fact that organizations and their workforce are relying on mobile devices, home computers, and laptops to connect to company networks to conduct business. In turn, these endpoint devices become the natural point of entry for many attacks.&nbsp;</span></span><br /><br /><span><span>Once they have compromised an end user device, hackers detect and disable endpoint security measures (e.g., data loss prevention; disk and endpoint encryption; endpoint detection and response; anti-virus or anti-malware) to avoid detection. Next, they move laterally to perform reconnaissance and identify IT schedules, additional security controls, network traffic flows, and scan the entire IT environment to gain an accurate picture of its resources, privileged accounts, and services. Domain controllers, Active Directory, and servers are prime reconnaissance targets to hunt for additional privileged credentials and privileged access.&nbsp;<br />&#8203;</span></span><br /><span><span>Once an attacker has identified where valuable data resides, they typically look for ways to elevate access privileges to exfiltrate the data and conceal their activity to avoid detection.&nbsp;</span></span><br /><br /><strong><span><span>Boosting Endpoint Visibility and Control<br />&#8203;</span></span></strong><br /><span><span>When establishing visibility and security controls across endpoints, security professionals need to understand that each endpoint bears some or all responsibility for its own security. This is different from the traditional network security approach, in which case established security measures apply to the entire network rather than individual devices and servers. Thus, making each&nbsp;<a href="https://www.securityweek.com/different-flavors-cyber-resilience">endpoint resilient</a>&nbsp;is paramount to implementing a successful defense strategy.</span></span><br /><br /><span><span>At a minimum, organizations therefore should deploy simple forms of endpoint security like anti-virus or anti-malware software across their entire fleet of devices. Many organizations are going beyond these simple measures and nowadays leverage modern endpoint security technology that encompasses encryption, intrusion detection, and behavior-blocking elements to identify and block threats and risky behavior, either by end users or intruders.</span></span><br /><br /><span><span>To counteract human error, malicious actions, and decayed, insecure software, Forrester Research recommends taking a pro-active approach to endpoint security and establishing endpoint resilience by:</span></span><ul><li><span><span>Maintaining a trusted connection with endpoints to detect unsafe behaviors or conditions that could put sensitive data at risk. This includes maintaining granular visibility and control over endpoint hardware, operating systems, applications, and data gathered on the device; and self-healing capabilities for the device, mission-critical security controls, and productivity applications.</span></span></li><li><span><span>Ensuring that endpoint misconfigurations are automatically repaired when possible, as organizations cannot assume that the health of their IT controls or security tools installed on their employees&rsquo; endpoints will remain stable over time.</span></span></li><li><span><span>Focusing on the return on investment of the security tools being used. Organizations often use a variety of endpoint security and management tools. Yet, each new tool introduced can serve as both a potential risk and an operational burden. Maintaining continuous endpoint visibility ensures that controls are always working as intended. By doing so, IT security professionals will ensure the ROI of their security investments &mdash; both from risk reduction and operational perspectives.&nbsp;</span></span></li><li><span><span>Understanding not just the tail end of the cyber-attack kill chain, but also focusing on initial attack vectors like endpoints provides a roadmap for aligning preventive measures with today&rsquo;s threats. It is vital to maintain granular visibility and control over access points to prevent and remediate vulnerabilities that can and often will surface on them.&nbsp;</span></span></li></ul></div>]]></content:encoded></item></channel></rss>