{"id":50499,"date":"2021-04-09T20:05:14","date_gmt":"2021-04-09T16:05:14","guid":{"rendered":"https:\/\/www.msp360.com\/resources\/?p=50499"},"modified":"2021-04-09T20:06:08","modified_gmt":"2021-04-09T16:06:08","slug":"news-you-mightve-missed-05-08-apr","status":"publish","type":"post","link":"https:\/\/www.msp360.com\/resources\/blog\/news-you-mightve-missed-05-08-apr\/","title":{"rendered":"News You Might&#8217;ve Missed.  05 &#8211; 08 Apr"},"content":{"rendered":"<p>What's new this week in the news for MSPs? New security and compliance certifications for Google Cloud; Microsoft cloud outage boots Teams, Azure, and Office 365 offline; password changes to auto-login in safe mode from REvil ransomware; and unpatched Fortinet VPN devices the target of new Cring ransomware.<!--more--><\/p>\n<p>Let's see what it's all about.<\/p>\n<h2>New Security and Compliance Certifications for Google Cloud<\/h2>\n<p>As a component of its pledge to be the most trusted cloud and serve as a security transformation partner, this week Google outlined its roadmap to achieve that goal.<\/p>\n<p>In addition to government and security compliance certifications across Canada, Europe, and Asia, <a href=\"https:\/\/siliconangle.com\/2021\/04\/08\/google-outlines-new-compliance-security-certifications-google-cloud\/\" target=\"_blank\" rel=\"noopener noreferrer\">new certifications are being added to Google Cloud\u2019s compliant programs<\/a>, including Cloud DNS.<\/p>\n<p>The program is designed to ensure security authorization and assessment, and monitoring for cloud services and products offered to federal government agencies are all standardized. Federal data must remain consistently protected and at the highest level in the cloud. The goal of the program is to make sure that this is the case.<\/p>\n<p>Clients can use Assured Workloads for Government if they wish to have access to the support. This service lets customers of the Google Cloud Platform build controlled environments in a straightforward way, where personnel access controls and US data locations are kept strictly enforced.<\/p>\n<h2>Microsoft Cloud Outage Boots Teams, Azure, and Office 365 Offline<\/h2>\n<p>Most of Microsoft\u2019s Internet services <a href=\"https:\/\/siliconangle.com\/2021\/04\/01\/no-foolin-microsoft-cloud-outage-takes-azure-teams-office-365-offline\/\" target=\"_blank\" rel=\"noopener noreferrer\">were taken offline<\/a> when the IT giant was hit by a mammoth cloud outage this week.<br \/>\nThe services affected were Microsoft Teams, OneDrive, Office 365, Skype, Xbox Live, Bing, and its Azure cloud services.<\/p>\n<p id=\"last\">Users on Twitter were the first to report the outage, which was later confirmed by the DownDetector website. According to DownDector, thousands of notices came in from Teams, Xbox Live, and Office users.<\/p>\n<div id=\"slidebox\"><a class=\"close\">\u00a0<\/a><!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-4a146d91-d63d-4e82-9aab-1f5f0c43f780\" data-portal=\"5442029\" data-id=\"4a146d91-d63d-4e82-9aab-1f5f0c43f780\"><span class=\"hs-cta-node hs-cta-4a146d91-d63d-4e82-9aab-1f5f0c43f780\" id=\"hs-cta-4a146d91-d63d-4e82-9aab-1f5f0c43f780\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/4a146d91-d63d-4e82-9aab-1f5f0c43f780\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-4a146d91-d63d-4e82-9aab-1f5f0c43f780\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/4a146d91-d63d-4e82-9aab-1f5f0c43f780.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code --><\/div>\n<p>A domain name system error was the cause of the outage, as the Microsoft 365 Twitter account status stated. About 90 minutes later, it seemed Microsoft had gotten the situation mostly under control.<\/p>\n<p>Some experts say that the outage is a considerable embarrassment for Microsoft, since it is the second such occurrence in 30 days.<\/p>\n<p>Microsoft says the issue occurred due to recent changes to one of its authentication systems.<\/p>\n<div class=\"call-to-action\">\n<div class=\"call-to-action__left\" style=\"width: 40%;\"><img decoding=\"async\" src=\"https:\/\/www.msp360.com\/resources\/wp-content\/uploads\/2020\/06\/Ransomware-Awareness-Poster-Pack-2.png\" alt=\"Poster Pack\" \/><\/div>\n<div class=\"call-to-action__right\" style=\"width: 60%;\">\n<div class=\"call-to-action__title\">MSP's Ransomware Awareness Poster Pack<\/div>\n<div class=\"call-to-action__text\">\n<p>4 white-label posters to help you educate your end-users on how not to get hit by ransomware.<\/p>\n<\/div>\n<!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper hs-cta-deferred\" id=\"hs-cta-wrapper-38530902-54cb-489c-9f02-772612f0072d\" data-portal=\"5442029\" data-id=\"38530902-54cb-489c-9f02-772612f0072d\"><span class=\"hs-cta-node hs-cta-38530902-54cb-489c-9f02-772612f0072d\" id=\"hs-cta-38530902-54cb-489c-9f02-772612f0072d\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/5442029\/38530902-54cb-489c-9f02-772612f0072d\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-38530902-54cb-489c-9f02-772612f0072d\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/5442029\/38530902-54cb-489c-9f02-772612f0072d.png\" alt=\"CTA\"><\/a><\/span><\/span><!-- end HubSpot Call-to-Action Code -->\n<\/div>\n<\/div>\n<h2>Password Changes to Auto-Login in Safe Mode from REvil Ransomware<\/h2>\n<p>A <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/revil-ransomware-now-changes-password-to-auto-login-in-safe-mode\/\" target=\"_blank\" rel=\"noopener noreferrer\">recent change to the code of REvil ransomware<\/a> allows its threat actors to modify the Windows password in safe mode, allowing them to automate encryption.<\/p>\n<p>In March, BleepingComputer shared that the threat actors changed the REvil\/Sodinokibi ransomware code to add a new encryption mode in Windows safe mode. They use the -smode command-line argument to enable this mode, which reboots devices in safe mode, allowing them subequently to encrypt the files.<\/p>\n<p>Security experts believe that the threat actors added the mode to avoid security software detection. It also enables the shutdown of backup software mail servers and database servers, which improves their success rates in encrypting files.<\/p>\n<p>The ransomware also changes the Windows Registry so that the device is automatically logged into with the account\u2019s new information.<\/p>\n<h2>Unpatched Fortinet VPN Devices the Target of New Cring Ransomware<\/h2>\n<p>A specific vulnerability in Fortinet VPN devices is making them the target of a new ransomware strain that is <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-cring-ransomware-hits-unpatched-fortinet-vpn-devices\/\" target=\"_blank\" rel=\"noopener noreferrer\">human-operated and called Cring<\/a>. It allows the threat operators to access and encrypt industrial sector businesses\u2019 networks.<\/p>\n<p>To gain the initial access, Cring operators leave custom Mimikatz samples; CobaltStrike follows this. Then they use the legitimate Windows CertUtil certificate manager to bypass security software detection to spread the ransomware payloads. Cring operators can move laterally on the targets' enterprise network, stealing Windows user credentials through Mimikatz to control the domain admin account using the Fortinet VPN device.<\/p>\n<p>The ransomware payloads are then installed on the victims\u2019 network using the Cobalt Strike threat simulation framework in a malicious PowerShell script. Only certain files on the compromised devices are encrypted by the ransomware, using robust encryption algorithms.<\/p>\n<h2>That's a Wrap for News You Might've Missed<\/h2>\n<p>I hope this update has been helpful. MSP360 is your resource for MSP news. Stay home, stay safe and healthy, and remember to check back every week for more highlights.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What&#8217;s new this week in the news for MSPs? New security and compliance certifications for Google Cloud; Microsoft cloud outage boots Teams, Azure, and Office 365 offline; password changes to auto-login in safe mode from REvil ransomware; and unpatched Fortinet VPN devices the target of new Cring ransomware.<\/p>\n","protected":false},"author":84,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[877,885],"tags":[],"class_list":["post-50499","post","type-post","status-publish","format-standard","hentry","category-blog-articles","category-other"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/50499","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/users\/84"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/comments?post=50499"}],"version-history":[{"count":0,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/50499\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media?parent=50499"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/categories?post=50499"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/tags?post=50499"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}