Update on Recent Security Incident

|
|
Major update: Announcement started |
|
The company has created a website to deal with the breach at info.starwoodhotels.com (note that at the time of writing it redirects to answers.kroll.com).
The company warns that if you made a reservation at one of its Starwood brands in the last five years then you are at risk:
If you made a reservation on or before September 10, 2018 at a Starwood property, information you provided may have been involved.
According to Marriott, its Starwood brands include: Starwood branded timeshare properties, W Hotels, St. Regis, Sheraton Hotels & Resorts, Westin Hotels & Resorts, Element Hotels, Aloft Hotels, The Luxury Collection, Tribute Portfolio, Le Méridien Hotels & Resorts, Four Points by Sheraton and Design Hotels.
It seems that different guests may be subject to different levels of exposure, according to how much data they shared. Until you have successfully confirmed your level of exposure with Marriott, you should assume the worst.
Information put at risk by the breach includes “some combination of” name, mailing address, phone number, email address, passport number, Starwood Preferred Guest (“SPG”) account information, date of birth, gender, arrival and departure information, reservation date, communication preferences, payment card numbers and payment card expiration dates.
Although payment card numbers were encrypted, thieves may have stolen the information required to decrypt them.
Marriott has not revealed what events or security failures occurred (it may not yet know), but it has released some details about how it discovered the breach.
The company says that on 8 September 2018 it was alerted to an unauthorised attempt to access the Starwood guest reservation database. Security experts called in to deal with the incident revealed that unauthorised access to the Starwood network started as far back as 2014, two years prior to Marriott’s acquisition of Starwood.
On 19 November 2018, Marriott learned that a recent attempt to encrypt and exfiltrate data from the network had included data from the Starwood guest reservation database.
As you can see from what Marriott has revealed so far, it can be difficult for everyone concerned to tell the difference between data that has been put at risk and data that has actually been stolen.
Until they can confirm otherwise, victims would be prudent to assume they amount to the same thing.
Effective June 1, 2018, all services within QuickBooks Desktop will need to meet updated system requirements. These industry standard security requirements will provide greater security and stability with TLS 1.2, an internet security protocol. To learn more about TLS 1.2, click here.
How does this impact you?
If these requirements are not met, services impacted include, but are not limited to the following:
What do you need to do?
Please take the following steps by May 31, 2018 to ensure uninterrupted QuickBooks services:
For additional information, please see this QuickBooks article.
Thank you for being a valued QuickBooks Desktop customer.
Sincerely,
The QuickBooks Desktop Team
|
|
Note: We would like to make you aware of a vulnerability affecting Sophos Mobile customers running the product installed on premises. Customers running Sophos Mobile managed in Sophos Central or the hosted Sophos Mobile as a Service are not affected by this issue. We will send the following email to all affected customers indicating any required actions. Please don’t hesitate to reach out to your account or support representative if you have additional questions.
Additional products supported for the Acoustic and Conversation Analysis suites: now including Unified Communication products (Voyager 3200 UC and Voyager 8200 UC ). UC customers can now benefit from obtaining greater insights and improve the quality of conversations, that Contact Centre customers have already been enjoying. New Bluetooth Link Quality report within the Conversation Analysis suite: Helps to identify audio issues caused by the Bluetooth radio link between the headset and the computer, allowing troubleshooting right to the supported end point. Upsell Opportunities Integration Opportunities To view the release notes and learn more about what’s new see here. To learn more about Plantronics Manager Pro and what it can offer see here. |
Yesterday Sophos announced the availability of a new product to the security product line. Sophos Launches Next Generation of Anti-Exploit and Anti-Ransomware Technology With Sophos Intercept X.
Sophos Intercept X combines four critical security components that IT administrators should expect from next-generation endpoint protection.
OXFORD, U.K. August 10, 2015 – Sophos has won all three security focused categories in The Channel Company's esteemed 2015 CRN® Annual Report Card. Sophos swept the board for the second year running as the winners of "Overall Category: Client Security Software" and "Overall Category: Network Security Appliances," and extended its recognition this year adding "Overall winner: Network Security Software" to its accolades. Sophos is the only vendor to have received top ratings in all client and network security categories, demonstrating the consistency of the channel experience across its portfolio.
The Annual Report Card summarizes results from a comprehensive study that details solution provider satisfaction with hardware, services and software vendors. The vendors with the highest marks are named to the prestigious Annual Report Card list and celebrated as best in class by their partners. The results also provide the IT vendor community with valuable feedback—directly from their solution providers—that can be used to hone product offerings and improve communication with partners.
"Our partner community is absolutely critical to our success in helping businesses and government agencies of all sizes protect their systems and information from cyber-attack," said Mike Valentine, senior vice president of worldwide sales for Sophos. "The unprecedented high marks awarded by our partners for the 2015 Annual Report Card reflects our companywide commitment to the channel. This year, CRN and its readers have recognized many of our key marketing and sales people for their accomplishments and impact within the channel, and now to receive such credit in all client and network security categories, is an honor for our entire company."
This year's elite group of honorees was selected based on the results of an in-depth invitation-only survey by The Channel Company's research team. More than 2,400 solution providers were asked to evaluate their satisfaction with 72 vendor partners in approximately 22 major product categories. The winners will be honored throughout The Channel Company's XChange 2015 event Aug. 9-11 in Washington, D.C., and highlighted in the leading media outlet for the IT channel, CRN. To view the results of the study as well as the list of this year's honorees, visit www.crn.com.
"Today's solution providers are juggling multiple vendors, product lines and customer demands. They are looking for true partnerships with their vendors in order to tailor solutions that will meet and exceed their customers' expectations," said Robert Faletra, CEO of The Channel Company. "CRN's Annual Report Card continues to give solution providers an outlet to deliver feedback to vendors and recognizes those vendors at the top of their game. We join these solution providers in applauding 2015 honoree Sophos and recognize them for their stellar performance."
Shellshock Advisory
SimpliVity is issuing this message as part of our Product Security Incident Response process to help protect our customers from a software vulnerability publicly disclosed yesterday (September 24, 2014) known as "Shellshock".
The vulnerability is in the GNU Bourne Again Shell (Bash), the command-line shell used in many Linux and Unix operating systems. Details of the vulnerability can be found at the Common Vulnerabilities and Exposures website - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271.
The SimpliVity OmniCube software uses a version of Linux that is impacted by this vulnerability. This vulnerability is not specific to the SimpliVity product. It affects a large number of software products that leverage Linux/Unix operating systems.
SimpliVity takes product security seriously. We are in the process of developing a software update that remediates this vulnerability and will make it available to all customers via SimpliVity’s Global Services Customer Support team.
While this vulnerability represents a large risk to the general marketplace, its potential impact on SimpliVity OmniCube deployments is significantly lower because this vulnerability cannot be exploited on the OmniCube Software by an unauthenticated user.
Should you have any further questions, please contact SimpliVity Customer Support at 1-855-SVT-SERVICE (USA) or 1-508-536-4151 (International), or email support@simplivity.com.
Best Regards,
Randy Boutin
VP, Customer Support
SimpliVity Corporation
![]()
|
SimpliVity is issuing this message as part of our Product Security Incident Response process to help protect our customers from a software vulnerability publicly disclosed yesterday (September 24, 2014) known as "Shellshock".
The vulnerability is in the GNU Bourne Again Shell (Bash), the command-line shell used in many Linux and Unix operating systems. Details of the vulnerability can be found at the Common Vulnerabilities and Exposures website - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6271.
The SimpliVity OmniCube software uses a version of Linux that is impacted by this vulnerability. This vulnerability is not specific to the SimpliVity product. It affects a large number of software products that leverage Linux/Unix operating systems.
SimpliVity takes product security seriously. We are in the process of developing a software update that remediates this vulnerability and will make it available to all customers via SimpliVity’s Global Services Customer Support team.
While this vulnerability represents a large risk to the general marketplace, its potential impact on SimpliVity OmniCube deployments is significantly lower because this vulnerability cannot be exploited on the OmniCube Software by an unauthenticated user.
Should you have any further questions, please contact SimpliVity Customer Support at 1-855-SVT-SERVICE (USA) or 1-508-536-4151 (International), or email support@simplivity.com.
Best Regards,
Randy Boutin
VP, Customer Support
SimpliVity Corporation
We are so happy that Sophos Products are recognized as a leader in the Security Industry. That is one of reasons their products are part of security product offerings. Security is such an important issue we need to be concerned with that you’ll always will to include the best for your business. Gartner helps us keep track of those company’s products that we should consider at the top of our list of choices.
Gartner has named Sophos as a Leader in the Magic Quadrant for Unified Threat Management – for the third year in a row.
Boston – August 20, 2014 – Sophos today announced it has taken the highest awards in the CRN 2014 Annual Report Card (ARC). The company was named overall winner in the Client Security Software and Network Security Appliances categories and swept the subcategories of product innovation, support and partnership. It is the first time in the history of the ARC that a company has swept both awards. For nearly three decades, this distinguished study has served as a benchmark for excellence throughout the IT channel, recognizing the technology vendors most highly praised by their solution provider partners.
Honorees were selected based on the results of an in-depth survey by The Channel Company’s research team. More than 2,500 solution providers were asked to evaluate their satisfaction with 81 vendor partners on each of the 18 criteria in terms of product innovation, support and partnership. The winners were honored by CRN, the top news source for solution providers and the IT channel, on Aug. 19 at The Channel Company’s XChange conference in San Antonio. To view the results of the study as well as the list of this year’s ARC honorees, visit www.crn.com.
“IT today is about solving business problems, and it requires more than just stellar products. Solution providers are looking for vendor partners that embrace the IT channel, working with them hand-in-hand to meet their customers’ needs,” said Robert Faletra, CEO of The Channel Company, publisher of CRN. “CRN’s Annual Report Card is the definitive word on who those vendors are, coming straight from the solution providers themselves. The ARC has been recognizing the vendors that deliver their solutions through the channel in the most effective ways for 29 years, and we congratulate Sophos as one of 2014’s top honorees.”
Sophos is dedicated to the channel, as evidenced by the company’s channel-first reseller strategy. We assist our partners in identifying opportunities to retain and grow their customer base and increase profits. In an increasingly complex security environment, we work with partners to make security simple to deliver, implement and manage. Our Partner Program provides partners with protection for deal registrations, attractive margins and joint lead generation initiatives. We also provide up-to-date certification, to ensure partner sales and technical teams are fully trained across our latest solutions.
“It’s an honor to sweep these important security categories,” said Michael Valentine, senior vice president, worldwide sales, Sophos. “At Sophos, 100 percent of our focus is on the channel. These awards are a testament to the trust of our partners, the strength of our solutions, and the investment that we continue to make in our partner organization. We are excited for the future as we continue to innovate to make security simple to manage, deploy and use.”
New message coming from Amazon Prime now provides streaming music for Prime Members for free. Looks kind of interesting if you enjoy listening to music on your devices. Check out their info:
Three years ago we launched Prime Instant Video, adding unlimited streaming of thousands of movies and TV shows to the existing Prime benefit of Free Two-Day Shipping. It has turned out to be one of the most important things we've done for Amazon Prime members.
Now we are doing it again for music — introducing Prime Music, the newest benefit of your membership. Prime members now get unlimited, ad-free access to over a million songs and hundreds of playlists for free.
Prime Music is available now for Prime members in the US. Kindle Fire HD/HDX devices will get Prime Music in an automatic, over-the-air update. To access Prime Music on your iOS or Android device please get the latest version of the Amazon Music app.
Sophos has recently been notified of a vulnerability in Sophos Anti-Virus Engine (SAV Engine) running on Microsoft Windows platforms. The vulnerability could in theory have allowed a remote attacker to manipulate the SAV Engine, which could result in protection being disabled or bypassed by an attacker. This vulnerability affects the Endpoint Security and Control for Windows client included in our Endpoint/Enduser, PureMessage, and SharePoint products. The vulnerability has been fixed in the January engine, which was released on the 22nd of January. If products are configured in Sophos Enterprise Console to use the “recommended” subscription, they will be updated automatically. This is the default setup, so only customers who have chosen to use ‘fixed’ or ‘previous’ subscriptions will need to take action to ensure they receive the update right away. Sophos Cloud customers and users of the standalone client will all be automatically updated. At Sophos, we constantly invest in making our products as secure as possible. When security issues like this are identified, we prioritize fixing them as quickly and completely as possible. We would like to thank the researcher, Graham Sutherland from Portcullis Computer Security Ltd, for identifying this vulnerability and for disclosing it responsibly. If you have customers using SAVi or SAVDi: From the January release onwards, SAVi and SAVDi on Windows will only run as one of the following user accounts or groups:
If an application without these permissions attempts to use SAVi, it will receive the following error return code: 0xa0040200 – SOPHOS_SAVI_ERROR_ INITIALISING On SAVDi the error message will be: “SAVI interface could not be initialized” For additional information about this vulnerability, please see this knowledgebase article. |
There are a lot of solution out their to help you keep track of and to make strong passwords for you online access to all of your sites. It is important to not only have strong passwords (ones that cannot be easily guessed) but also to have different passwords for each and every site that you access. That way if one is compromised then the rest of your secure sites are not compromised as well.
What Makes a Strong Password?
For best protection every password you use should be unique and have the characteristics of what is a strong password listed above. You may be wondering how you are going to remember so many passwords when you have a problem remember just one! Try some of these tips in creating and remembering your passwords:
1. First, think of a thing, date, phrase, event, place or anything that is unique only to you. Make sure that it is at least 8 characters in length. What ever you come up with use this as the focal point for creating the rest of the password. Some people call this the salt phrase.
2. Many use the following to confuse the spelling by replacing certain alpha characters with specific special characters. You can come up with your own rules for doing this but commonly people use the following.
3. Then for each site use either the site name or something about the site additionally added to your salt term. You can even vary the placement of the two parts to even make it more unique. Come up with some rules to use to help you remember and you will be on your way to a much safer online experience.
WeMo LED Lighting, WeMo Maker to launch this spring alongside the Crock-Pot® Smart Slow Cooker with WeMo
Playa Vista, Calif. – January 06, 2014 – Continuing to evolve the WeMo platform of simple, ingenious connected home products, Belkin today announced a slate of new WeMo devices including the WeMo LED Lighting Starter Set and WeMo Smart LED Bulbs, the WeMo Maker Kit, and Crock-Pot SmartSlow Cooker. Also on tap for the WeMo line at CES is a revised Android and iOS app offering improved functionality and enhanced lighting features. Belkin’s new WeMo line-up will be on display at PepCom's Digital Experience!, on January 6, 2014 at the Mirage Hotel and Casino and will be on display at the Belkin’s booth, South Hall 3 #30451, from January 7-10, 2014.
“Since first launching at the 2012 International CES, WeMo has become a major player in the connected home thanks to its simple, scalable, and affordable nature – words not typically associated with the connected home,” said Ohad Zeira, director of product management for WeMo. “As the most approachable entry point into the Smart Home, we are excited to introduce new products and app upgrades in 2014 that will continue that trend, as well as grow our business with Jarden Consumer Solutions and future partners to expand WeMo’s presence throughout the house.”
Belkin's new LED Lighting Starter Set and WeMo Smart LED Bulbs allow you to control, schedule and dim your smart LED bulbs from anywhere. As easy as replacing a standard light bulb, the WeMo Smart LED Bulbs work through the WeMo Link and are controlled via Wi-Fi and the WeMo app. The long-lasting bulbs are 60-watt equivalent with 800 Lumens and 3000 Kelvin for a bright, pleasing warm white light. Fully dimmable, WeMo Smart LED Bulbs can be controlled individually or in groups. The WeMo LED Starter Set includes two LED Smart Bulbs and a WeMo Link, which can support up to 50 individual Smart bulbs. Individual WeMo Smart LED bulbs also will be sold separately.
WeMo LED Lighting Starter Set (F5Z0489) - $129.99
WeMo Smart LED Bulbs (F7C033) - $39.99
The WeMo Maker empowers DIYers to build their own WeMo solutions by adding Internet connectivity to any device controlled with a DC switch, such as research robotics, motors, sprinkler systems, antennas, and more. A small module that wires into low voltage devices, WeMo Maker also lets you monitor and manage a wide range of 5V DC sensors from anywhere using a smartphone or tablet. WeMo Maker is controlled via the same free WeMo app as existing WeMo products and integrates seamlessly within the WeMo ecosystem, allowing you to create schedules or automatically control the WeMo Maker with sensor inputs. Deactivate your sprinkler system if moisture is detected or open the blinds at sunrise from Monday to Friday. WeMo Maker also works with IFTTT, which lets you create specialized recipes bringing the Internet of Things to your fingertips.
Also debuting at the 2014 International CES, the WeMo-enabled Crock-Pot Smart Slow Cooker is the first WeMo equipped product stemming from Belkin’s collaboration with Jarden Consumer Solutions, a family of household appliance brands. The Crock-Pot Smart Slow Cooker is the first smartphone controllable slow cooker, which allows you to adjust the cooker’s settings from anywhere giving you greater flexibility and control over life’s unexpected moments. Receive reminders, change the cooking time, adjust the temperature or check the status of your dish while you are away through the WeMo app and come home to a perfectly cooked meal whenever you want it, even if you have to work late or practice runs over schedule. Additional Jarden Consumer Solutions co-branded products on display at the Belkin booth include the Mr. Coffee® Smart Coffee Maker enabled with WeMo, the HOLMES® Holmes Smart Console Space Heater enabled with WeMo, the HOLMES® Smart Console Humidifier enabled with WeMo, and the HOLMES® Holmes Smart Air Purifier enabled with WeMo.
Crock-Pot Smart Slow Cooker enabled with WeMo - $99.99
Aside from growing the WeMo product family in 2014, Belkin also will upgrade the award winning WeMo app to include a customizable long press gesture for the WeMo Light Switch, enhanced sunrise/sunset rules to select a time before or after sunset/sunrise, a simulated occupancy or vacation mode setting and a countdown timer.
Availability
The WeMo LED Lighting Starter Set, WeMo Smart LED Bulbs Crock-Pot Smart Slow Cooker enabled with WeMo and WeMo Maker Kit will be available in spring 2014. The latest version of the WeMo app with the upgraded features will launch in February for both Android and iOS.
Belkin at CES
Visit Belkin at the 2014 International CES in booth #30451 in the South Hall of the Las Vegas Convention Center or on the Web. To schedule a booth tour or an appointment with a Belkin representative, please call Leah Polk at 202-213-4464.
About Belkin International, Inc.
To learn more about Belkin, visit http://www.belkin.com/aboutus/. Like us on Facebook atfacebook.com/belkin, and follow us on Twitter at Twitter.com/belkin.
Press Release:
Lately, Windows users have been discovering issues with using Windows Easy Transfer to upgrade from their old Windows PCs to a new Windows 8.1 PC. Microsoft has since come out in official forums stating that they are reducing support for Windows Easy Transfer in favor of promoting the cloud. This diminished support is seen through the incompatibility with Windows XP and Windows Vista users, as well as the ability to only transfer over data files by using only an external hard drive or USB. Unfortunately, this leaves many Windows users unable to transfer over their old documents, music, settings without a great deal of hassle and extra work. Programs will have to be re-downloaded and installed, serial numbers will need to be dug up, and the transfer process will be a long, grueling one. With support for Windows XP ending this April, many XP users will be looking to make the upgrade to Windows 8.1, but won’t find any help in getting there.
Laplink is aware of customers’ concerns over upgrading or migrating to a new PC and is now offering PCmover Home for free to any user moving from a Windows XP to Windows 8.1. We’re also offering several discounts to help alleviate Windows users’ worries over upgrading. Attached you’ll find our press release, where you can find more information on how PCmover is providing the solution to the Windows Easy Transfer Problem.
Press Release:
“Indoor GPS” Platform Will Offer Wayfinding and Context-Aware Advertising and Marketing for Public-Facing Enterprises
Sunnyvale, CA – May 16, 2013 – Aruba Networks, Inc. (NASDAQ:ARUN), a leading provider of next-generation network access solutions for the mobile enterprise, today announced the acquisition of privately-held Meridian Apps, Inc. (“Meridian”). With this acquisition, Aruba Networks enables new location-based services by combining its unique, network-based contextual information about users, devices and applications with Meridian’s Wi-Fi based wayfinding solution for smartphones and tablets.
The Meridian enterprise software platform is targeted at public-facing enterprises, including casinos, hospitals, malls, stores, transport hubs, convention centers, museums and campuses, to help customers navigate these large, indoor facilities. Enterprises use the platform to create custom-branded mobile applications to provide turn-by-turn directions, highlight points of interests along the way, deliver context-awareness advertising and offer detailed analytics about users’ travel patterns and preferences.
“GPS-based wayfinding solutions are extraordinarily popular, but they don’t work well indoors,” said Keerti Melkote, founder and Chief Technology Officer at Aruba Networks. “We intend to address that gap by creating ‘indoor GPS’ using Aruba’s Wi-Fi infrastructure and Meridian’s wayfinding platform. The addition of Meridian will enable enterprises to tap into a wealth of network-driven information so that they can better engage their customers with more personalized services. This is a clear opportunity for Wi-Fi to become not only an enabling platform for BYOD, but now across industries, a revenue-producing, customer engagement platform for the business.”
To learn more about Meridian’s platform, visit www.meridianapps.com.
Press Release from DELL SonicWall announcing the end of support for Gen4 Firewalls on July 1, 2013.
End of Support for Gen4 (and older) Dell SonicWALL firewalls will commence on July 1, 2013. All Gen4 firewalls, regardless of whether they are covered under a stand-alone support contract or through a Comprehensive GMS support contract, are subject to the same End of Support date. Our records indicate that your customers rely on one or more of these appliances:
Call us to discuss your options.