Open Forum

 View Only
  • 1.  Security BUZZ - A Cautionary Tale of a Disney Employee

    Posted 13 days ago

    In today's rapidly evolving digital landscape, the integration of artificial intelligence (AI) into everyday tools has become commonplace. However, this advancement brings with it a new wave of cyber threats that can have profound personal and professional consequences.

    Consider the recent experience of Matthew Van Andel, a Disney employee who faced a significant cyberattack after downloading free AI software from a reputable platform. Unbeknownst to him, the software contained malicious malware that infiltrated his home personal computer. This breach allowed hackers to access sensitive information, including his personal accounts and Disney's internal communications. The fallout was severe: over 44 million internal messages were leaked online, and Van Andel's personal and professional life was upended. He ultimately lost his job due to allegations of accessing inappropriate content on his work computer, a claim he firmly denies. This incident underscores the potential dangers of downloading and using AI tools without proper verification. (The full article is available online on the Wall Street Journal website.)

    Key takeaway:

    1. Password Manager becomes the HIGHEST risk if you don't protect it. In Matthews' case, he used a password manager, but it was not protected by MFA. When the hacker obtained his password to the vault through the malware installed on his computer, the game was over. Not only was the attacker able to access it remotely, but he also posted online every account password Matthew had in the vault. If you are using a password manager, make sure MFA with the highest level of security is enabled and protecting your vault
    2. Exercise Caution with Software Downloads: Always verify the source of any software, especially free AI tools. Download applications only from trusted and official platforms to minimize the risk of introducing malicious software into your systems
    3. Passwordless is THE only remedy. Password-based authentication has been vulnerable for decades. While multi-factor authentication (MFA) provides an additional layer of security, it can still be compromised under certain circumstances. Whenever possible, transition to passwordless authentication. In 2023, both Apple and Google introduced Passkey, which uses your phone's biometric features for authentication. With this method, no static data (such as passwords or codes) that can be later reused is exchanged with the website. Start migrating to Passkey
    4. Convenience kills security. Hackers have recently ramped up the theft of what are called session cookies. These are files that are stored by your browser and save you the annoyance of logging in every time you need to read a Gmail or check up on Facebook. Often, they are suitable for a fixed period, like a week or a month. However, once a hacker gets on your computer, they can use it to gain access to websites that require two-factor authentication. A session cookie gets created whenever users click "remember me" while logging into a website. Avoid checking "remember me" and attempt to empty your browser cache monthly
    5. Utilize Comprehensive Security Software: While built-in protections like Windows Defender offer a baseline defense, consider supplementing them with additional antivirus programs that can provide enhanced protection against a broader range of threats

    Resources for moving to passwordless authentication:

    https://passkey.org/

    https://fidoalliance.org/passkeys-directory/

    https://www.passkeys.com/websites-with-passkey-support-sites-directory

    #ALTACyber



    ------------------------------
    Genady Vishnevetsky
    Chief Info Security Officer
    Stewart Title Guaranty Company
    Houston TX
    ------------------------------
    ALTA Marketplace


  • 2.  RE: Security BUZZ - A Cautionary Tale of a Disney Employee

    Posted 10 days ago

    Great insight as per your usual Genady.

    Thanks for sharing

     

    signature_986404206

    Deb Grace

    EVP Business Development, AccuTitle

    Cell: 505-999-0089

    Office Direct: 844-848-5379 x131

    Website: www.accutitle.com

    Support: [email protected]

    Email: [email protected]

    Product Demo: [email protected]/bookings/"> Schedule Online

    AccuTitle Info: Contact Us

    Feedback: Review Us

     

    Title: Facebook  - Description: Facebook iconTitle: instagram - Description: instagram icon Title: linkedin - Description: linkedin icon Title: Twitter - Description: twitter icon   

    A logo with a black background  Description automatically generated

    Learn more at accuair.io

     

     

     

       

    Membership Committee Member

       Subcommittee Chair – Ambassador Program

    Values Committee Member

       Awards Nomination Co-Chair

    Graphical user interface, text  Description automatically generated

     

    Florida Land Title Association 

     

     

     

     

      Membership Committee Member

          Ambassador Program Manager

       Cyber Security/Best Practices Committee Member

     

    Merchant Logo

    Texas Land Title Association

     

    Woman's Leadership Summit

    October Research, LLC

     

     


     

     

    Notice: The information transmitted is intended for the named recipient(s) only and may contain confidential and/or privileged material. Any review, distribution, copying, other use of or taking any actions based on this information by anyone other than the intended recipient(s) is strictly prohibited. If you have received this in error, please delete all material and promptly notify the sender. Thank you for your cooperation.




    ALTA Marketplace