<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Bulletin Archives - Tarheel Media Digital Marketing</title>
	<atom:link href="https://tarheel.media/category/security-bulletin/feed/" rel="self" type="application/rss+xml" />
	<link>https://tarheel.media/category/security-bulletin/</link>
	<description>Digital Marketing The Right Way</description>
	<lastBuildDate>Wed, 29 Oct 2025 22:06:24 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://tarheel.media/wp-content/uploads/2022/12/cropped-tarheel-icon-1-32x32.png</url>
	<title>Security Bulletin Archives - Tarheel Media Digital Marketing</title>
	<link>https://tarheel.media/category/security-bulletin/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Breaking News: Web Service Scandal Unfolds with Polyfill.io and Cloudflare</title>
		<link>https://tarheel.media/security-bulletin/2024/06/28/breaking-news-web-service-scandal-unfolds-with-polyfill-io-and-cloudflare/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Fri, 28 Jun 2024 14:03:22 +0000</pubDate>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[browser compatibility]]></category>
		<category><![CDATA[CDNJS]]></category>
		<category><![CDATA[Cloudflare]]></category>
		<category><![CDATA[code injection]]></category>
		<category><![CDATA[code integrity]]></category>
		<category><![CDATA[content delivery network]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[internet safety]]></category>
		<category><![CDATA[JavaScript library]]></category>
		<category><![CDATA[malicious script]]></category>
		<category><![CDATA[online trust]]></category>
		<category><![CDATA[Polyfill.io]]></category>
		<category><![CDATA[reverse proxy]]></category>
		<category><![CDATA[script replacement]]></category>
		<category><![CDATA[secure browsing]]></category>
		<category><![CDATA[SEO optimization]]></category>
		<category><![CDATA[supply chain attack]]></category>
		<category><![CDATA[tech scandal]]></category>
		<category><![CDATA[User experience]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[web services]]></category>
		<category><![CDATA[Website performance]]></category>
		<category><![CDATA[Website protection]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=6597</guid>

					<description><![CDATA[<p>Polyfill.io supply‑chain incident: what happened In the past few days a supply‑chain incident involving Polyfill.io disrupted a large number of websites. Polyfill.io, a service that delivers small JavaScript polyfills to add missing browser features, allegedly distributed suspicious code that injected into many sites. Some reports estimate the impact reached more than 100,000 domains. Operators and  [...]</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2024/06/28/breaking-news-web-service-scandal-unfolds-with-polyfill-io-and-cloudflare/">Breaking News: Web Service Scandal Unfolds with Polyfill.io and Cloudflare</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><!--StartFragment --></p>
<p><!--StartFragment --></p>
<h2>Polyfill.io supply‑chain incident: what happened</h2>
<p>In the past few days a supply‑chain incident involving Polyfill.io disrupted a large number of websites. Polyfill.io, a service that delivers small JavaScript polyfills to add missing browser features, allegedly distributed suspicious code that injected into many sites. Some reports estimate the impact reached more than 100,000 domains. Operators and investigators took the Polyfill.io domain offline while they responded.</p>
<h2>How Cloudflare responded</h2>
<p>Cloudflare moved quickly to reduce exposure. The company replaced references to Polyfill.io with a secure mirror served through cdnjs and has said it never recommended Polyfill.io. Cloudflare’s action reduced the risk of further automatic propagation through CDNs and reverse proxies.</p>
<h2>Polyfill.io’s response and ownership concerns</h2>
<p>Polyfill.io has publicly disputed the allegations. At the same time, reporting shows the project was in the process of being acquired by a Chinese firm, which raised additional concern because of that buyer’s reported ties to the Chinese government. Polyfill.io’s public statement is here: <a href="https://twitter.com/Polyfill_Global/status/1805923380857897277">https://twitter.com/Polyfill_Global/status/1805923380857897277</a>.</p>
<h2>Who this affects</h2>
<p>We do not use Polyfill.io, so our systems were not directly dependent on it. However, sites that relied on CDNs, reverse proxies, or other intermediaries sometimes received Polyfill.io assets even if the site owner never included them directly. That’s why some organizations saw collateral impact despite not calling Polyfill.io in their own code.</p>
<h2>What you should do now</h2>
<p>Remove any references to Polyfill.io from your projects and replace them with a trusted alternative. Cloudflare’s cdnjs mirror offers a non‑breaking option that serves the same polyfill content. Also audit other third‑party front‑end dependencies, and prefer self‑hosting critical libraries or pinning and hosting copies you control when practical.</p>
<h2>Offer of help and next steps</h2>
<p>If you want assistance locating or replacing Polyfill.io references, or if you’d like a broader audit of third‑party scripts and CDNs, we can help. We will continue to monitor the situation and share verified updates as more information becomes available</p>
<p><!--EndFragment --></p>
<p><!--EndFragment --></p>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2024%2F06%2F28%2Fbreaking-news-web-service-scandal-unfolds-with-polyfill-io-and-cloudflare%2F&amp;action_name=Breaking%20News%3A%20Web%20Service%20Scandal%20Unfolds%20with%20Polyfill.io%20and%20Cloudflare&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2024/06/28/breaking-news-web-service-scandal-unfolds-with-polyfill-io-and-cloudflare/">Breaking News: Web Service Scandal Unfolds with Polyfill.io and Cloudflare</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Email Phishing Alert</title>
		<link>https://tarheel.media/security-bulletin/2024/06/10/email-phishing-alert/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Mon, 10 Jun 2024 19:34:00 +0000</pubDate>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=6540</guid>

					<description><![CDATA[<p>This morning after a report made by a customer, we have concluded that there is a wide-spread attempt to exploit login credentials from users of WordPress sites that are using their email address as their username (which is the default for any kind of 3rd party login).</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2024/06/10/email-phishing-alert/">Email Phishing Alert</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column" style="--awb-bg-blend:overlay;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-1"><p>This morning after a report made by a customer, we have concluded that there is a wide-spread attempt to exploit login credentials from users of WordPress sites that are using their email address as their username (which is the default for any kind of 3rd party login).</p>
<p>It would seem the more popular we get, the more scammers and fraudsters target us and our customers.</p>
<p>The best defense for these attacks is to be informed and in effort to do just this, we will take you through 5 steps to take when getting a suspicious email claiming to be from your WordPress site or your vendor&#8217;s WordPress site.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-overflow:hidden;--awb-bg-color:var(--awb-custom_color_1);--awb-bg-color-hover:var(--awb-custom_color_1);--awb-bg-size:cover;--awb-border-radius:100px 100px 100px 100px;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-2 fusion-text-no-margin" style="--awb-content-alignment:center;--awb-font-size:64px;--awb-line-height:78px;--awb-text-color:var(--awb-color1);--awb-margin-top:auto;--awb-margin-right:auto;--awb-margin-bottom:auto;--awb-margin-left:auto;--awb-text-font-family:Menlo, Consolas, Monaco, &#039;Liberation Mono&#039;, &#039;Lucida Console&#039;, monospace;--awb-text-font-style:normal;--awb-text-font-weight:400;"><p>1</p>
</div></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-1 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">CHECK SERVER MESSAGES</h3></div><div class="fusion-text fusion-text-3"><p>Most emails attempting to steal your username and password will fake the email and many email servers will alert you of this. Google and our own email servers will generally classify these emails as spam.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-3 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-overflow:hidden;--awb-bg-color:var(--awb-custom_color_1);--awb-bg-color-hover:var(--awb-custom_color_1);--awb-bg-size:cover;--awb-border-radius:100px 100px 100px 100px;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-4 fusion-text-no-margin" style="--awb-content-alignment:center;--awb-font-size:64px;--awb-line-height:78px;--awb-text-color:var(--awb-color1);--awb-margin-top:auto;--awb-margin-right:auto;--awb-margin-bottom:auto;--awb-margin-left:auto;--awb-text-font-family:Menlo, Consolas, Monaco, &#039;Liberation Mono&#039;, &#039;Lucida Console&#039;, monospace;--awb-text-font-style:normal;--awb-text-font-weight:400;"><p>2</p>
</div></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-4 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-2 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">LOGIN MANUALLY &#8211; ALWAYS</h3></div><div class="fusion-text fusion-text-5"><p>When you get an email from your WordPress website asking you to login; go to your website manually and do not use any links included in that email (except for password resets).</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-4 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-5 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-overflow:hidden;--awb-bg-color:var(--awb-custom_color_1);--awb-bg-color-hover:var(--awb-custom_color_1);--awb-bg-size:cover;--awb-border-radius:100px 100px 100px 100px;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-6 fusion-text-no-margin" style="--awb-content-alignment:center;--awb-font-size:64px;--awb-line-height:78px;--awb-text-color:var(--awb-color1);--awb-margin-top:auto;--awb-margin-right:auto;--awb-margin-bottom:auto;--awb-margin-left:auto;--awb-text-font-family:Menlo, Consolas, Monaco, &#039;Liberation Mono&#039;, &#039;Lucida Console&#039;, monospace;--awb-text-font-style:normal;--awb-text-font-weight:400;"><p>3</p>
</div></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-6 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-3 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">RESETTING YOUR PASSWORD</h3></div><div class="fusion-text fusion-text-7"><p>Your WordPress website will NEVER prompt you to reset your password out of nowhere unless someone is trying to break into your website. Simply ignore the email if it is unexpected. If you have forgotten your password, visit the login page of your WordPress website and click &#8220;Forgot Password&#8221; and follow the instructions there.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-5 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-7 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-overflow:hidden;--awb-bg-color:var(--awb-custom_color_1);--awb-bg-color-hover:var(--awb-custom_color_1);--awb-bg-size:cover;--awb-border-radius:100px 100px 100px 100px;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-8 fusion-text-no-margin" style="--awb-content-alignment:center;--awb-font-size:64px;--awb-line-height:78px;--awb-text-color:var(--awb-color1);--awb-margin-top:auto;--awb-margin-right:auto;--awb-margin-bottom:auto;--awb-margin-left:auto;--awb-text-font-family:Menlo, Consolas, Monaco, &#039;Liberation Mono&#039;, &#039;Lucida Console&#039;, monospace;--awb-text-font-style:normal;--awb-text-font-weight:400;"><p>4</p>
</div></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-8 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-4 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">CHECK UNIFORMITY</h3></div><div class="fusion-text fusion-text-9"><p>Most WordPress websites have the same &#8220;from&#8221; email address and name. If you notice that this changes, it usually means someone is attempting to mimic your website. Ignore the email and instruct your customers to ignore the email.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-6 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-9 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-padding-top:0px;--awb-padding-right:0px;--awb-padding-bottom:0px;--awb-padding-left:0px;--awb-overflow:hidden;--awb-bg-color:var(--awb-custom_color_1);--awb-bg-color-hover:var(--awb-custom_color_1);--awb-bg-size:cover;--awb-border-radius:100px 100px 100px 100px;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-10 fusion-text-no-margin" style="--awb-content-alignment:center;--awb-font-size:64px;--awb-line-height:78px;--awb-text-color:var(--awb-color1);--awb-margin-top:auto;--awb-margin-right:auto;--awb-margin-bottom:auto;--awb-margin-left:auto;--awb-text-font-family:Menlo, Consolas, Monaco, &#039;Liberation Mono&#039;, &#039;Lucida Console&#039;, monospace;--awb-text-font-style:normal;--awb-text-font-weight:400;"><p>5</p>
</div></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-10 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-5 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">THE SMELL TEST</h3></div><div class="fusion-text fusion-text-11"><p>If it doesn&#8217;t pass the smell test, contact us. We&#8217;ll help you figure out whether or not something is very wrong with your website, or if someone is trying to steal your (or your customer&#8217;s) login credentials.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-7 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-11 fusion_builder_column_1_1 1_1 fusion-flex-column" style="--awb-bg-blend:overlay;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-12"><p>We are constantly striving to improve the security for our customers and their customers. If you have any questions or suggestions, please do not hesitate to reach out to us.</p>
</div></div></div></div></div>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2024%2F06%2F10%2Femail-phishing-alert%2F&amp;action_name=Email%20Phishing%20Alert&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2024/06/10/email-phishing-alert/">Email Phishing Alert</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>FBI WARNING: Dangerous new email scam</title>
		<link>https://tarheel.media/security-bulletin/2024/06/02/fbi-warning-dangerous-new-email-scam/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Sun, 02 Jun 2024 05:30:05 +0000</pubDate>
				<category><![CDATA[Email Systems]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[alert]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[fbi]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[linus]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[warning]]></category>
		<category><![CDATA[youtube]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=6523</guid>

					<description><![CDATA[<p>We issued a security bulletin back in October of 2023 which covered one of our customers who had their Microsoft account and emails compromised which led to a scammer to send out emails on behalf of that company and request invoices and all sorts of financial data from their customers, including banks. https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/ As it  [...]</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2024/06/02/fbi-warning-dangerous-new-email-scam/">FBI WARNING: Dangerous new email scam</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>We issued a <a href="https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/">security bulletin</a> back in October of 2023 which covered one of our customers who had their Microsoft account and emails compromised which led to a scammer to send out emails on behalf of that company and request invoices and all sorts of financial data from their customers, including banks.</p>
<div class="video-shortcode">
<blockquote class="wp-embedded-content" data-secret="0CePYUmbSf"><p><a href="https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/">SECURITY BULLITEN: Phishing Fraud and Account Security</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;SECURITY BULLITEN: Phishing Fraud and Account Security&#8221; &#8212; Tarheel Media Digital Marketing" src="https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/embed/#?secret=NH8FFsiQoQ#?secret=0CePYUmbSf" data-secret="0CePYUmbSf" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></div>
<p>As it turns out, this has now become a very big deal, even Linus and other popular YouTubers are sounding the alarms with the FBI issuing a new warning about this scam and a scam that uses the exact same tactics to appear as if someone is sending email from the FBI, itself.</p>
<div class="video-shortcode"><iframe class="fusion-hidden" data-privacy-type="youtube" src="" title="FBI Issues Warning: A Dangerous New Email Scam" width="1260" height="709" data-privacy-src="https://www.youtube.com/embed/vi3W26aZ9n0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe><div class="fusion-privacy-placeholder" style="width:1260px; height:709px;" data-privacy-type="youtube"><div class="fusion-privacy-placeholder-content"><div class="fusion-privacy-label">For privacy reasons YouTube needs your permission to be loaded. For more details, please see our <a class="privacy-policy-link" href="https://tarheel.media/privacy-policy/" rel="privacy-policy">Privacy Policy</a>.</div><button data-privacy-type="youtube" class="fusion-button button-default fusion-button-default-size button fusion-privacy-consent">I Accept</button></div></div></div>
<h3>How does this scam work?</h3>
<p>This scam works by an attacker first compromising the email of a victim, usually a business owner or someone very high up in that business that other victims wouldn&#8217;t generally question.  They sit and watch how they conduct business and then will very closely mimic language and regiments of that business owner or business person.</p>
<p>Once they have enough information to construct a conversation that would appear to be exactly that person, they attack by sending out emails requesting money or private information (PII) which helps them collect money in fraudulent bank accounts from other victims.</p>
<h3>What we have done</h3>
<p>The attack on our customer only happened through Microsoft because it cannot happen on our servers.  We are using both SPF and DMARC DNS records for our email services which specifically lets other email providers know when there is something wrong &#8211; that is someone who sent out an email that did not physically come from the IP address listed in those records.   Unless the receiving provider doesn&#8217;t check these records, it is an impossibility for someone to get an email from one of our customers and not know something is amiss.</p>
<p>Otherwise, there isn&#8217;t much we can do further until other technologies develop.</p>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2024%2F06%2F02%2Ffbi-warning-dangerous-new-email-scam%2F&amp;action_name=FBI%20WARNING%3A%20Dangerous%20new%20email%20scam&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2024/06/02/fbi-warning-dangerous-new-email-scam/">FBI WARNING: Dangerous new email scam</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Important Update: Let&#8217;s Encrypt SSL Certificate Changes Affecting Device Compatibility</title>
		<link>https://tarheel.media/company-news/2024/03/15/important-update-lets-encrypt-ssl-certificate-changes-affecting-device-compatibility/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Sat, 16 Mar 2024 01:23:38 +0000</pubDate>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[Web Design]]></category>
		<category><![CDATA[Web Development]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Android devices]]></category>
		<category><![CDATA[compatibility]]></category>
		<category><![CDATA[device compatibility]]></category>
		<category><![CDATA[digital security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HTTPS]]></category>
		<category><![CDATA[IdenTrust DST Root CA X3]]></category>
		<category><![CDATA[ISRG Root X1]]></category>
		<category><![CDATA[Let's Encrypt]]></category>
		<category><![CDATA[online trust]]></category>
		<category><![CDATA[SSL certificate]]></category>
		<category><![CDATA[Tarheel Media]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[web hosting]]></category>
		<category><![CDATA[Website security]]></category>
		<category><![CDATA[wellsm]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=3995</guid>

					<description><![CDATA[<p>At Tarheel Media, we prioritize the security and functionality of your websites. That's why we're reaching out to inform you of an upcoming change that could impact the compatibility of Let's Encrypt SSL certificates with certain devices. Let's Encrypt, a trusted provider of free SSL certificates, has been issuing certificates through two chains: the ISRG  [...]</p>
<p>The post <a href="https://tarheel.media/company-news/2024/03/15/important-update-lets-encrypt-ssl-certificate-changes-affecting-device-compatibility/">Important Update: Let&#8217;s Encrypt SSL Certificate Changes Affecting Device Compatibility</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>At Tarheel Media, we prioritize the security and functionality of your websites. That&#8217;s why we&#8217;re reaching out to inform you of an upcoming change that could impact the compatibility of Let&#8217;s Encrypt SSL certificates with certain devices.</p>
<p>Let&#8217;s Encrypt, a trusted provider of free SSL certificates, has been issuing certificates through two chains: the ISRG Root X1 chain and the ISRG Root X1 chain cross-signed by IdenTrust’s DST Root CA X3. The cross-signed chain has been crucial in ensuring widespread trust for Let&#8217;s Encrypt certificates across various devices.</p>
<p>However, Let&#8217;s Encrypt is now making a vital change that may affect the compatibility of these certificates. Specifically, they are removing the root from the trust store, which could result in older devices &#8211; such as those running Android 7 &#8211; being unable to use or trust these certificates.</p>
<p>This change is significant as it may impact the security and accessibility of websites, especially for users accessing them from devices that rely on the now-unsupported chain. We understand the importance of ensuring seamless browsing experiences for all users, which is why we want to bring this update to your attention.</p>
<p>As your trusted web development partner, we are here to assist you in navigating through these changes. If you have any concerns or questions regarding your SSL certificates and their compatibility, please don&#8217;t hesitate to reach out to us. Our team is dedicated to ensuring that your websites remain secure and functional for all users, regardless of device compatibility challenges.</p>
<p>We appreciate your attention to this matter and your continued trust in Tarheel Media for your web development needs.</p>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fcompany-news%2F2024%2F03%2F15%2Fimportant-update-lets-encrypt-ssl-certificate-changes-affecting-device-compatibility%2F&amp;action_name=Important%20Update%3A%20Let%26%238217%3Bs%20Encrypt%20SSL%20Certificate%20Changes%20Affecting%20Device%20Compatibility&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/company-news/2024/03/15/important-update-lets-encrypt-ssl-certificate-changes-affecting-device-compatibility/">Important Update: Let&#8217;s Encrypt SSL Certificate Changes Affecting Device Compatibility</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>SECURITY BULLITEN: Phishing Fraud and Account Security</title>
		<link>https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Tue, 03 Oct 2023 11:40:51 +0000</pubDate>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Press Release]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Service Updates]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[company]]></category>
		<category><![CDATA[corporate]]></category>
		<category><![CDATA[crime]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[justice]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[prevent]]></category>
		<category><![CDATA[preventative]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=3795</guid>

					<description><![CDATA[<p>Sophisticated Phishing Fraud aimed at several local Goldsboro, North Carolina businesses from late September until October 3, 2023 and Tarheel Media's involvement to stop it.</p>
<p>The post <a href="https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/">SECURITY BULLITEN: Phishing Fraud and Account Security</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fusion-fullwidth fullwidth-box fusion-builder-row-8 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-12 fusion_builder_column_1_1 1_1 fusion-flex-column" style="--awb-bg-blend:overlay;--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-13"><p>We were alerted yesterday that one of our customers local to Goldsboro, North Carolina had been targeted in a very sophisticated and elaborate phishing scam. Phishing is a fraud that consists of targeting a victim into thinking they are communicating or interacting with a legitimate company in an effort to steal sensitive data such as passwords, financial data, or any other data that in some way benefits the attacker.</p>
<p>As we are aware of this situation, the fraudster contacted our customer masquerading as one of their customers, and when our unsuspecting customer tried downloading an attachment they were asked to enter their Microsoft login details to download the file. Upon doing so, it took only seconds for the pre-programmed bot the fraudster already had in place to login to our client&#8217;s Microsoft account and download all the data it could before the customer was notified by Microsoft of a suspicious login.</p>
<p>This kind of breach is the most dangerous because it is a breach into everything on the computer and connected with that Microsoft account including the very login to that PC as Microsoft now requires that all PC logins be &#8220;online&#8221; and connected to Microsoft&#8217;s website.</p>
<p>There are far more implications as well. Because Outlook is also connected to your Microsoft account and login details to our servers are saved in your Outlook, this breach could have also been a breach into our mail server limited and localized to the customer&#8217;s email account. That meant the fraudster now could have had access to every email the customer had ever sent to their clients.</p>
<p>Soon after the breach that went unnoticed by the customer, the fraudster created a domain name that mimicked the customer&#8217;s domain name. Imagine for a moment if your company&#8217;s domain name was &#8220;google.com&#8221;, and the fraudster registered &#8220;google.co&#8221; and began emailing the customers of our customer pretending to be our customer. The sophistication of this act was far greater than any breech we&#8217;ve been told about to date and we&#8217;ve seen some very sophisticated breeches from local businesses right here in Goldsboro.</p>
<p>The fraudster very tediously mimicked everything about the company including the owner&#8217;s constant carbon copying of his son in every email, but of course, his son never got that email because it was carbon copied to &#8220;sons-name@google.co&#8221;.</p>
<p>After 2 weeks of gaining our customer&#8217;s customers trust, the fraudster made their move and began requesting the invoices be paid via ACH Debit. One of those customers of our customers reached out to our customer and wanted to know why they could no longer pay their invoices via check. The jig was up when our customer learned that emails were being received he didn&#8217;t send.</p>
<p>This is the point I was called. The customer believed that their email had been hacked. We quickly traced this breach back to the Microsoft breach from the phishing email and even found that our own email servers were too hardened for the attacker to break into even with the username and password through Outlook. Instead of logging directly into our email server, they had to resort to creating their own domain name to send emails from.</p>
<p>We want people to be very aware of how these scams work. As you read, paying close attention to the domain name is the best defense against phishing of any kind. Today, it is very hard to deliver email to a domain the email did not come from in an authorized manner because of SPF records, DMARC records, and other security features on DNS servers that alert mail servers to what IP addresses are authorized to send email from that domain name. Our servers are equipped with these security features as well as errant login detection that stops logins that doesn&#8217;t seem to be within the norms of a customer&#8217;s geographical location for logins. This has proven to be a valid defense which is why the fraudster was unable to login with the customer&#8217;s credentials. We are well aware that customers have complained about the minor inconveniences this has seldomly caused, but this security feature really did pay off in a big way in the past few weeks.</p>
<p>In hindsight, it&#8217;s always great to go over what went right and what went wrong; the basics of after-action problem solving that I was all too acquainted with from my time in the US Army. This could have been anyone and the likelihood of this happening to someone in the future is many orders higher than you even think &#8211; it&#8217;s 100%. Don&#8217;t think about &#8220;<em>if</em> it happens&#8221; think about &#8220;<em>when</em> it happens&#8221;. In this case, the customer made the right call to get help and that should be your first step. Upon contacting us, we&#8217;re going to step you through this process, the same process we have outlined in our company policy if we are ever breached:</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-9 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-13 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-1 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-14 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-6 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:26px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">STOP THE BREACH</h3></div><div class="fusion-text fusion-text-14"><p>Changing passwords, logging out unauthorized users, and securing all of your accounts are essential and <b>nothing else matters</b> until this is completed. I cannot express how important it is to secure the breach before doing anything else at this point, you must shut down the attacker&#8217;s access to your company or everything that follows becomes a circular event.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-10 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-15 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-2 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-16 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-7 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:24px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">ALERT YOUR CUSTOMERS</h3></div><div class="fusion-text fusion-text-15"><p>It is not only the right thing to do, <u><b>it is the law</b></u>. Let your customers know you experienced a data breach and exactly what information you suspect &#8220;could have been&#8221; obtained &#8211; even if there is the slightest chance they got a credit card number, you need to let those customers know &#8220;your financial data may have been exposed&#8221;. In a situation like what was experienced in this article, education is the best defense and the only immediate way of stopping it. Educating your customers on how to identify a phishing email stops the fraudster&#8217;s ability to phish.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-11 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-17 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-3 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-18 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-8 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:24px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">ALERT AUTHORITIES</h3></div><div class="fusion-text fusion-text-16"><p>The North Carolina State Attorney General&#8217;s office has a hotline specifically for this:<b> 1-877-5-NO-SCAM</b></p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-12 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-19 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-4 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-20 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-9 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:24px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">ALERT SERVICE PROVIDERS</h3></div><div class="fusion-text fusion-text-17"><p>Filing abuse reports and DCMA takedowns outright disables any further progress from the fraudster. We in addition to a normal abuse report, include a &#8220;<b>Letter of Preservation</b>&#8221; which notifies the service provider of the fraudster to <u>SAVE ALL DATA</u> associated with that account before deleting it in case the NC Department of Justice prosecutes it. We will file these for our customers, especially if we have active contracts on hand as they allow us and give us the legal authority to do so (a quasi- and very limited power of attorney in these situations).</p>
<p><span style="color: #999999;">Note: Our timely abuse reports and DMCA takedowns in this case resulted in total shut-down in less than 6 hours.</span></p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-13 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-21 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-5 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-22 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-10 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:24px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">REGISTER SIMILAR DOMAINS</h3></div><div class="fusion-text fusion-text-18"><p>In this situation, specifically registering the .co variant to the domain name would have outright prevented this kind of attack on our customer and their customers. This could be a $200 per year expense but it is far cheaper than the liability that could have been caused. We are more than willing to sit down with any customer and go through the variants that should be registered to help prevent an event like this from happening.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-14 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-center fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-23 fusion_builder_column_1_6 1_6 fusion-flex-column fusion-flex-align-self-flex-start" style="--awb-bg-size:cover;--awb-width-large:16.666666666667%;--awb-margin-top-large:0px;--awb-spacing-right-large:11.52%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:11.52%;--awb-width-medium:16.666666666667%;--awb-order-medium:0;--awb-spacing-right-medium:11.52%;--awb-spacing-left-medium:11.52%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><i class="fb-icon-element-6 fb-icon-element fontawesome-icon fa-angle-double-right fas circle-no fusion-text-flow" style="--awb-iconcolor:var(--awb-color5);--awb-iconcolor-hover:var(--awb-color5);--awb-font-size:54px;--awb-margin-right:27px;"></i></div></div><div class="fusion-layout-column fusion_builder_column fusion-builder-column-24 fusion_builder_column_5_6 5_6 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:83.333333333333%;--awb-margin-top-large:0px;--awb-spacing-right-large:2.304%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:2.304%;--awb-width-medium:83.333333333333%;--awb-order-medium:0;--awb-spacing-right-medium:2.304%;--awb-spacing-left-medium:2.304%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-title title fusion-title-11 fusion-sep-none fusion-title-text fusion-title-size-three" style="--awb-text-color:var(--awb-color5);--awb-margin-top-small:10px;--awb-margin-right-small:0px;--awb-margin-bottom-small:10px;--awb-margin-left-small:0px;--awb-font-size:24px;"><h3 class="fusion-title-heading title-heading-left" style="margin:0;text-transform:uppercase;font-size:1em;line-height:32px;">EDUCATE YOUR EMPLOYEES</h3></div><div class="fusion-text fusion-text-19"><p>As I said in alerting your customers, education is key, but not just the education of your customers. Ensuring that your employees know how to identify a phishing email effectively removes the most common vector of attack substantially reducing the risk of future breaches of any kind. We will be happy to offer a proactive service to any company to spot-check your employees to see if they can be tricked by a controlled phishing email &#8211; an email that does not legitimately represent your company but does not leak data other than to alert someone in your company that the particular employee was tricked and needs to be educated on how to identify these emails.</p>
</div></div></div></div></div><div class="fusion-fullwidth fullwidth-box fusion-builder-row-15 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-25 fusion_builder_column_1_1 1_1 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-20"><p>If you have any questions on this article or on how best to secure your company in data breaches, please visit our support center or call 919-648-1333 option 1.</p>
<p><strong>Copyright Notice EXCLUSIVE to this article: All content and photos in this article may be copied for the purpose of news, awareness, or education so long as it is clear that MLW &amp; Associates, LLC, Tarheel Media&#8217;s parent company maintains the copyrights.</strong></p>
</div></div></div></div></div>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fpress-release%2F2023%2F10%2F03%2Fsecurity-bulliten-phishing-fraud-and-account-security%2F&amp;action_name=SECURITY%20BULLITEN%3A%20Phishing%20Fraud%20and%20Account%20Security&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/press-release/2023/10/03/security-bulliten-phishing-fraud-and-account-security/">SECURITY BULLITEN: Phishing Fraud and Account Security</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Safeguard Your Digital Fortress: The Importance of Website Security</title>
		<link>https://tarheel.media/security-bulletin/2023/05/20/safeguard-your-digital-fortress-the-importance-of-website-security/</link>
		
		<dc:creator><![CDATA[Michael Gilmore]]></dc:creator>
		<pubDate>Sat, 20 May 2023 09:32:57 +0000</pubDate>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Tech News]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Website Security]]></category>
		<category><![CDATA[Cyber threats]]></category>
		<category><![CDATA[Cybersecurity measures]]></category>
		<category><![CDATA[Data breaches]]></category>
		<category><![CDATA[Data protection]]></category>
		<category><![CDATA[Digital protection]]></category>
		<category><![CDATA[Downtime prevention]]></category>
		<category><![CDATA[Fortifying your website]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[Malware protection]]></category>
		<category><![CDATA[Proactive security]]></category>
		<category><![CDATA[User trust]]></category>
		<category><![CDATA[Website security]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=3324</guid>

					<description><![CDATA[<p>In today's digital landscape, where businesses heavily rely on their online presence, website security has become paramount. The rise in cyber threats and the ever-evolving tactics of hackers underscore the importance of safeguarding your digital fortress. In this blog post, we'll explore why website security is crucial and shed light on why hackers relentlessly target  [...]</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2023/05/20/safeguard-your-digital-fortress-the-importance-of-website-security/">Safeguard Your Digital Fortress: The Importance of Website Security</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In today&#8217;s digital landscape, where businesses heavily rely on their online presence, website security has become paramount. The rise in cyber threats and the ever-evolving tactics of hackers underscore the importance of safeguarding your digital fortress. In this blog post, we&#8217;ll explore why website security is crucial and shed light on why hackers relentlessly target websites.</p>
<h2>Protecting Your Valuable Assets</h2>
<p>Your website is more than just a virtual storefront; it&#8217;s a hub of valuable assets. From customer data and financial information to proprietary business secrets, your website holds sensitive data that can be a goldmine for hackers. Implementing robust security measures ensures the protection of these valuable assets and safeguards your business&#8217;s reputation.</p>
<h2>Preserving User Trust</h2>
<p>Customers expect their online interactions to be secure and their information to be handled responsibly. A security breach can severely damage the trust your users have placed in your business. By prioritizing website security, you demonstrate your commitment to safeguarding their data, fostering trust, and encouraging continued engagement.</p>
<h2>Avoiding Costly Downtime</h2>
<p>A compromised website can lead to prolonged downtime, which translates into lost revenue, missed opportunities, and dissatisfied customers. Hackers may exploit vulnerabilities to disrupt your website&#8217;s functionality or install malicious code that disrupts operations. Proactive security measures help minimize the risk of such incidents, ensuring uninterrupted business continuity.</p>
<h2>Preventing Data Breaches</h2>
<p>Data breaches have become an all-too-common occurrence, with severe consequences for businesses. Hackers exploit vulnerabilities to gain unauthorized access to databases, compromising sensitive customer information. Such breaches can result in legal consequences, financial penalties, and irreparable damage to your brand&#8217;s reputation. Robust security protocols act as a shield against data breaches, reducing the risk of costly fallout.</p>
<h2>Thwarting Malicious Intent</h2>
<p>Hackers have various motivations for targeting websites, ranging from financial gain to political activism or simply causing chaos. They may inject malware, deface webpages, or steal sensitive information for their nefarious purposes. By bolstering your website security, you actively thwart their attempts and create a formidable barrier against malicious intent.</p>
<h2>Staying One Step Ahead</h2>
<p>Cyber threats are constantly evolving, with hackers employing sophisticated techniques to breach security defenses. Regularly updating and maintaining your website&#8217;s security protocols allows you to stay one step ahead of potential threats. By keeping pace with the latest security standards, you ensure your website remains resilient against emerging vulnerabilities.</p>
<h3>Conclusion</h3>
<p>Investing in website security is not an option but a necessity in today&#8217;s digital landscape. By prioritizing security, you protect your valuable assets, preserve user trust, avoid costly downtime, prevent data breaches, and thwart malicious intent. Stay proactive, leverage robust security measures, and work with experienced professionals to fortify your digital fortress against ever-present threats. Remember, safeguarding your website is an ongoing commitment that helps safeguard your business&#8217;s future.</p>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2023%2F05%2F20%2Fsafeguard-your-digital-fortress-the-importance-of-website-security%2F&amp;action_name=Safeguard%20Your%20Digital%20Fortress%3A%20The%20Importance%20of%20Website%20Security&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2023/05/20/safeguard-your-digital-fortress-the-importance-of-website-security/">Safeguard Your Digital Fortress: The Importance of Website Security</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Outdated WordPress Plugins make 60,000 Websites Vulnerable</title>
		<link>https://tarheel.media/security-bulletin/2023/05/17/outdated-wordpress-plugins-make-60000-websites-vulnerable/</link>
		
		<dc:creator><![CDATA[Michael Gilmore]]></dc:creator>
		<pubDate>Wed, 17 May 2023 18:27:20 +0000</pubDate>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Exploitable plugins]]></category>
		<category><![CDATA[Information system security]]></category>
		<category><![CDATA[Penetration testing]]></category>
		<category><![CDATA[Plugin vulnerabilities]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Security disclosure process]]></category>
		<category><![CDATA[Security research]]></category>
		<category><![CDATA[SQL injections]]></category>
		<category><![CDATA[Unauthorized access]]></category>
		<category><![CDATA[Vulnerable websites]]></category>
		<category><![CDATA[Website hijacking]]></category>
		<category><![CDATA[Website intrusions]]></category>
		<category><![CDATA[Website maintenance]]></category>
		<category><![CDATA[Website protection]]></category>
		<category><![CDATA[Website security]]></category>
		<category><![CDATA[Website updates]]></category>
		<category><![CDATA[Website vulnerabilities]]></category>
		<category><![CDATA[WordPress database]]></category>
		<category><![CDATA[WordPress security]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=3160</guid>

					<description><![CDATA[<p>The security firm, Cyllective, identified around 5,000 plugins on WordPress.org that contained various security exploits such as SQL Injections. The Penetration Testing Team lead, Dave Miller said what started as a random experiment turned into a treasure trove for hackers. Once they started the experiment, they were quickly surprised at how relaxed the security was  [...]</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2023/05/17/outdated-wordpress-plugins-make-60000-websites-vulnerable/">Outdated WordPress Plugins make 60,000 Websites Vulnerable</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The security firm, Cyllective, identified around 5,000 plugins on WordPress.org that contained various security exploits such as SQL Injections. The Penetration Testing Team lead, Dave Miller said what started as a random experiment turned into a treasure trove for hackers. Once they started the experiment, they were quickly surprised at how relaxed the security was on WordPress.org&#8217;s repository in allowing old and exploitable plugins to remain and be installed.</p>
<p>If that wasn&#8217;t bad enough, Dave&#8217;s team came across remote code execution vulnerabilities or RCE&#8217;s. RCE&#8217;s are usually where bad code allows an attacker to gain administrative or super-user privileges and entirely take over a website or the entire information system.</p>
<p>Dave&#8217;s team, however, focused in on the SQL injections &#8211; a way of appending your own SQL query from code that does not escape its <span style="color: #008080;">$_POST</span> variables which is the variable where the stuff you submit to a website is stored. After just 3 months of research, Dave&#8217;s team found a staggering 35 plugins that had already been exploited by unauthorized users or hackers. While 35 sounds like a low number, those 35 plugins were in operation and were exploited on over 60,500 WordPress websites.</p>
<p>&#8220;Although the vast majority of the vulnerabilities I reported were unauthenticated SQL injection vulnerabilities, which would have enabled an attacker to dump the entire WordPress database contents, these were not the most devastating ones,” Dave said.</p>
<p>“The sitemap-by-click5 plugin suffered from an unauthenticated arbitrary options update flaw, which would have allowed an attacker to maliciously enable the registration functionality and set the default user role to that of an administrator.&#8221;</p>
<p>Dave explained that this would allow an attacker to create their own administrator account and entirely take over the WordPress website. Dave went on to say that he hopes this research forwards the ability to quickly identify security exploits in the future and minimize website intrusions.</p>
<p>After dealing with these WordPress Plugins and WordPress.org a pretty heavy blow, Dave did applaud the WordPress team for how well the disclosure process went in allowing Dave&#8217;s team to reach out and get these updates out there to these vulnerable websites that desperately needed it.</p>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2023%2F05%2F17%2Foutdated-wordpress-plugins-make-60000-websites-vulnerable%2F&amp;action_name=Outdated%20WordPress%20Plugins%20make%2060%2C000%20Websites%20Vulnerable&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2023/05/17/outdated-wordpress-plugins-make-60000-websites-vulnerable/">Outdated WordPress Plugins make 60,000 Websites Vulnerable</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Increased Attack Rates</title>
		<link>https://tarheel.media/security-bulletin/2022/12/08/increased-attack-rates/</link>
		
		<dc:creator><![CDATA[Mike W.]]></dc:creator>
		<pubDate>Thu, 08 Dec 2022 13:02:43 +0000</pubDate>
				<category><![CDATA[Security Bulletin]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://tarheel.media/?p=2714</guid>

					<description><![CDATA[<p>We're observing an increased attack rate of brute force attacks against client email and WordPress accounts. We began to see an uptick in brute force attacks Monday, December 5, 2022 at about 3:40 am.  These attacks begin subsiding around 7:00am.   These attacks increased in intensity by about twice the rate of Monday's attack on Wednesday  [...]</p>
<p>The post <a href="https://tarheel.media/security-bulletin/2022/12/08/increased-attack-rates/">Increased Attack Rates</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>We&#8217;re observing an increased attack rate of brute force attacks against client email and WordPress accounts.</p>
<p>We began to see an uptick in brute force attacks Monday, December 5, 2022 at about 3:40 am.  These attacks begin subsiding around 7:00am.   These attacks increased in intensity by about twice the rate of Monday&#8217;s attack on Wednesday morning and lasted throughout the night Thursday Morning.</p>
<h2>OUR ADVISORY</h2>
<ol>
<li>Please <strong>change your WordPress &#8220;Display Name&#8221;</strong> to something other than your username.  If your login is &#8216;iplaybb&#8217; ensure your display name is &#8216;John Doe&#8217; and not &#8216;iplaybb&#8217;.  These attacks on WordPress seem to attempt to use the display name as the login.</li>
<li>Please be sure to <strong>change your passwords regularly</strong> to something that is not easily guessed and ensure it does not contain a common word or phrase.</li>
</ol>
<img decoding="async" src="https://stats.tarheel.media/piwik.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Ftarheel.media%2Fsecurity-bulletin%2F2022%2F12%2F08%2Fincreased-attack-rates%2F&amp;action_name=Increased%20Attack%20Rates&amp;urlref=https%3A%2F%2Ftarheel.media%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" /><p>The post <a href="https://tarheel.media/security-bulletin/2022/12/08/increased-attack-rates/">Increased Attack Rates</a> appeared first on <a href="https://tarheel.media">Tarheel Media Digital Marketing</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
