Wednesday, November 25, 2015

Windows 10 pulls update as concerns about bugs grow.

Windows 10 update mysteriously pulled!

The Downloadable versions of Windows 10 (version 1511), the November 2015 update have been removed after their release earlier this month.

Microsoft let people download the full copies of the installer using the Media Creation Tool (MCT). Media produced with the MCT can be used to perform both upgrades and clean installations and it's especially convenient when updating multiple systems. This ensures that only a single download is required. But the version 1511 MCT has been removed and replaced with the original July version. Systems can still be upgraded to the November update, but direct installation is no longer possible. Instead, the original RTM version must be in stalled and the upgrade to 1511 performed through Windows Updates.

This has become inconvenient. The ability to install 1511 on clean systems is quicker than going via the RTM version. It means on large download instead of two. Upgrading multiple systems with the MCT is also obviously preferable. It's mysterious because it's not really clean why the 1511 installer has been pulled.

Source:  Arstechnica T

Email us: sales@ripeva.com 
Call us: 563-213-4015

Saturday, November 14, 2015

The Cryptowall Ransomware has Returned!


The gold standard in ransomware, CryptoWall, is making the rounds again with a new 4.0 release. In this revision, there are some pretty important changes that are going to make life more difficult for both infectees and security researchers looking to counter the software’s malicious activities.

If you aren’t already familiar with it, CryptoWall is a piece of software that falls under the category of “ransomware.” Ransomware products encrypt data on an infected system, preventing access until some amount of money is paid. The ransom for files is generally in the neighborhood of $500 but could be more or less depending on the developer. In most cases, the malware drops a list of targeted file types, such as .docx or .ppt, and attacks those. Once the files are encrypted, a message is displayed to inform the system’s user of the attack and how to pay the ransom.

Cryptowall 4.0 follows most of the “standards” for this type of malware. It uses the RSA-2048 algorithm, which is used by most major ransomware and is functionally unbreakable with current technology. It communicates with command, control, and communications (C3) systems using RC4 encryption, and communicates with its victims to collect the ransoms via the TOR browsing utility. It spreads via spam emails and so-called “drive-by downloads.” It also wipes shadow copies and disables system restore and startup repair, and network drives and local drives can both be affected.

What’s different about CryptoWall 4.0?

Where Cryptowall 4.0 differs is that it now encrypts the filenames as well as the files themselves, making it nearly impossible to identify which files are which. Previous iterations only encrypted the data within the files, not the filenames.

Additionally, the splash screen and ransom notes have been updated. Now, in addition to the usual instructions on how to pay for the decryption key and new filenames in each folder directory storing affected files, the ransom notes contain language that mocks the victim more than previous iterations.  Lastly, it seems that this version no longer uses the I2P protocol for communication, unlike version 3.0.

Recovering from CryptoWall 4.0 is essentially the same as in past versions: You either have to pay the ransom or restore from a backup. There’s no other way around it.

For more information on this variant, the helpful folks over at the BleepingComputer forums areactively peeling this bug apart, and they have a fantastic guide on removing the ransomwarehere.  For more information on ransomware, feel free to check out our Cybersecurity Resource Center or download our new e-book, The MSP’s Complete Guide to Cyber Security.

Call us : 1-855-974-7382  or Email us : sales@ripeva.com

Saturday, October 31, 2015

Understanding the role of Information Technology in Regulations, Legislation, and Guidance

Technology has made implementations for small to midsize business more affordable than ever. With the technology implementations constantly evolving, the understanding of regulations and legislation for a particular business has become difficult and in some instances unmanageable for organization users that wear multiple "hats". Legislative bodies have been formed to assist with the requirements needed to maintain your business and minimize liability to you and your clients.

This post serves as an entry point for you to meet the legal technology related requirements for operating your business.


Industry Standards and Legislation
Federal Government (non-DOD) FIPS 199, 200, FISMA, NIST 800 Series, OMB A130 Appendix III
Department of Defense and other National Security Systems DoD 8500.1 & 8500.2, DCID 6/3, DITSCAP,DIACAP
Health care HIPAA, PCI
Financial institutions GLBA, PCI
All publicly held organizations Sarbanes-Oxley
Utilities NERC,WISE
Education FERPA, PCI

If you need further assistance with Information Technology compliance needs, please contact us to schedule a free consultation. We look forward to helping you maintain your business independence.

Call us : 1-855-974-7382
Mail us : sales@ripeva.com

Wednesday, October 28, 2015

5 Questions you should Ask Before Moving Email to the Cloud

Companies need the flexibility to deploy services in a private or public cloud depending on their unique needs or industry compliance requirements. In order to maximize flexibility and minimize the total cost of ownership.

If you are considering moving your email to the cloud, there are several questions to ask when deciding on which solution is right for your and your organization.

1. Can users access email both online and offline and on any device?

2. Is the platform based on an open, extensible standard?

3. What level of management support and security does your company require?

4. Does the vendor build on a modern, distributed and highly salable model?

5. What are your total costs, including software, infrastructure and operating expenses?

Cloud-based email solutions help companies meet growing expectations as well as cost reductions. It’s the next step for companies, and it’s one that will reward both employees and the bottom line.

If you need assistance, more information, or would like to schedule a free consultation, please give us a call at (855) 974-7382.  We look forward to helping you meet your needs.

Saturday, August 29, 2015

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) was designed to improve the efficiency and effectiveness of the health care system and requires many things, including the standardization of electronic patient health, administrative and financial data. In response to the original HIPAA law, Health and Human Services (HHS) published an additional regulation referred to as the Privacy Rule that relates directly to organizations involved in health care operations that transmit health information electronically.
Typical organizations covered by HIPAA include:
  • health plans
  • health care clearing houses (billing companies);
  • health care providers (“covered entities”) that transmit health information electronically; and
  • their business associates
The HIPAA Privacy Rule:
  • Establishes conditions under which PHI can be used within a Covered Entity and disclosed to others  outside that entity;
  • Grants individuals certain rights regarding their PHI;
  • Requires that Covered Entities maintain the privacy and security of PHI.
HIPAA also establishes security and privacy standards for the use and disclosure of “protected health information” (PHI).

Saturday, March 7, 2015

Security Testing Tip: ShieldsUP

The Gibson Research Corporation is a world renown organization and has freeware tools available to help you assess your public facing security. ShieldsUp is a tool that helps you identify areas of concern on your router.

Please visit their website to test your Internet connectivity security: https://www.grc.com/intro.htm.


  • NOTE: RIPEVA is not affiliated with the organization in anyway. This post is for information purposes only.


Security Fundamentals: What is access control?

Access control provides the mechanism for ensuring that only authorized personnel can access certain organizational information.


  • NOTE: As the value of the information to the organization increases, more strict access control mechanisms are needed.

Microsoft Agent 365 - The control plane for AI agents

See every AI agent in your organization from one place. This video shows how Microsoft Agent 365 works as a unified enterpr...