<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Uncategorized - Techcity Company Limited</title>
	<atom:link href="https://techcity.cloud/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>https://techcity.cloud</link>
	<description>Best Cloud Computing Services!</description>
	<lastBuildDate>Tue, 24 Mar 2026 08:07:43 +0000</lastBuildDate>
	<language>vi</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://techcity.cloud/wp-content/uploads/2021/07/cropped-Techcity-Favicon-32x32.png</url>
	<title>Uncategorized - Techcity Company Limited</title>
	<link>https://techcity.cloud</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>[Ảnh] Hàng nghìn người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân trong ngày đặc biệt</title>
		<link>https://techcity.cloud/uncategorized/anh-hang-nghin-nguoi-xep-hang-nhan-phu-san-30-4-cua-bao-nhan-dan-trong-ngay-dac-biet/</link>
		
		<dc:creator><![CDATA[Lucas]]></dc:creator>
		<pubDate>Wed, 30 Apr 2025 08:00:00 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://techcity.cloud/?p=10715</guid>

					<description><![CDATA[<p>Từ 6 giờ sáng ngày 30/4, hàng nghìn người xếp hàng dài chung quanh Tòa soạn Báo Nhân Dân để nhận phụ san đặc biệt tuyên truyền kỷ niệm 50 năm Ngày Giải phóng miền Nam thống nhất đất nước.</p>
<p>The post <a href="https://techcity.cloud/uncategorized/anh-hang-nghin-nguoi-xep-hang-nhan-phu-san-30-4-cua-bao-nhan-dan-trong-ngay-dac-biet/">[Ảnh] Hàng nghìn người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân trong ngày đặc biệt</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-image"><img fetchpriority="high" decoding="async" width="820" height="614" src="https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476.jpg" alt="Sáng 30/4, hàng dài người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân. (Ảnh: QUỲNH TRANG)" class="wp-image-10718" srcset="https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476.jpg 820w, https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476-300x225.jpg 300w, https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476-768x575.jpg 768w, https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476-100x75.jpg 100w, https://techcity.cloud/wp-content/uploads/2026/03/631dc5cfe6d3548d0dc253-9559-6476-480x359.jpg 480w" sizes="(max-width:767px) 480px, (max-width:820px) 100vw, 820px" /><figcaption class="wp-element-caption">Sáng 30/4, hàng dài người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân. (Ảnh: QUỲNH TRANG)</figcaption></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><video width="770" height="433" poster="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6fd2c82b68cb1b98d6908ddeed6a7248b61d564eb12efe79f6b33fdaa0200276c3283d20cf8fac450f3eb533f4eba11325/631dc5cfe6d3548d0dc253-9559-6476.jpg" playsinline="" preload="auto"></video>00:00 / 00:00</td></tr><tr><td class="has-text-align-center" data-align="center">Hàng nghìn người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân.</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Trong ngày tháng ý nghĩa này, bằng nhiều cách khác nhau để thể hiện lòng yêu nước, người dân, đặc biệt là các bạn trẻ đã chọn cách tìm hiểu lịch sử đất nước thông qua&nbsp;<a href="https://nhandan.vn/post-876223.html" target="_blank" rel="noreferrer noopener">phụ san đặc biệt</a>&nbsp;và triển lãm tương tác của Báo Nhân Dân.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6fd0f77908d854f5cf053baaeb66571b048233fa00f1661490bc26aaab7d2a12bdec4327d8bbce8f04626ddd716a80e43a/ea1b4c3b6f27dd79843661-9932-6863.jpg" alt="Các bạn trẻ xếp hàng từ 6 giờ sáng ngày 30/4." width="770" height="576"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Các bạn trẻ xếp hàng từ 6 giờ sáng ngày 30/4.</em></td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f84d0ff771c981328019b37b7876498e0c5b91c8634b39f784a1764b98ce290f0d0c19859af282a838a577877f9d404fe/5aac5428eb3759690026-5650-7564.jpg" alt="Vào nhận phụ san 30/4 tại Trụ sở Báo Nhân Dân." width="770" height="433"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Vào nhận phụ san 30/4 tại Trụ sở Báo Nhân Dân.</em></td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f6a8708805fb97d37a3331f81252eb3e0b1f64ebcf9e2f0f1e1d5bc927866caa8409e659683ab10eb78eb23183436a37d/f9c6b9f509eabbb4e2fb-843-7961.jpg" alt="Bạn đọc nhận phụ san đặc biệt." width="770" height="433"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Bạn đọc nhận phụ san đặc biệt.</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">5 giờ sáng, bạn Phạm Thị Thảo Chi sinh năm 2004 cùng với nhóm bạn trẻ đi từ thành phố Hải Phòng đến Thủ đô Hà Nội để xem triển lãm tương tác kỷ niệm 50 năm Ngày&nbsp;<a href="https://nhandan.vn/post-876451.html" target="_blank" rel="noreferrer noopener">Giải phóng miền nam</a>, thống nhất đất nước trong khuôn viên của Báo Nhân Dân. Công nghệ 3D mapping đã tái hiện sống động Chiến dịch Hồ Chí Minh lịch sử, những bước chân thần tốc, khí thế hào hùng của cuộc tổng tiến công Sài Gòn như hiện ra trước mắt, khiến các bạn trẻ như Thảo Chi cảm thấy đang chứng kiến ngày giải phóng miền Nam 30/4 và thống nhất đất nước lịch sử cách đây 50 năm.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f0eca06f72d519161cc414bb98b8b0d5aba153d6d5e16792d255e020fe333bf6a762c9db2403b7a064263c6dbd2236c6b/eafdf583d69f64c13d8e57-1786-3610.jpg" alt="Bạn Phạm Thị Thảo Chi xếp hàng nhận phụ san của Báo Nhân Dân." width="770" height="576"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Bạn Phạm Thị Thảo Chi xếp hàng nhận phụ san của Báo Nhân Dân.</em></td></tr></tbody></table></figure>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f2b2d2c7bb5b1b518bcb500f761a406deda08ea0ecba0728e019ddef595659a453f158ec168706180fdcc8fa08baec2b5/004382bea1a213fc4ab341-791-1571.jpg" alt="Và xem triển lãm trong khuôn viên Báo Nhân Dân" width="770" height="576"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Và xem triển lãm trong khuôn viên Báo Nhân Dân</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Cũng như nhiều bạn trẻ khác, 7 giờ sáng, bạn Lê Thị Thảo Linh xếp hàng để nhận miễn phí phụ san. Thông qua tờ phụ san đặc biệt này, bạn Linh đã hiểu thêm về ngày 30/4 lịch sử, là ngày cuối cùng của chiến dịch Hồ Chí Minh. Khi quét mã QR trên tờ báo, hình ảnh hào hùng của xe tăng mang số hiệu 390 hiện lên, húc đổ cổng chính Dinh Độc Lập và xe tăng số 843 húc đổ cổng phụ Dinh Độc Lập. Bạn Linh bày tỏ, gia đình bạn Linh có ông nội và chú là hai liệt sĩ, đã chiến đấu và hy sinh tại chiến trường Quảng Trị và Sài Gòn. Những hình ảnh hiện lên trên tờ phụ san đặc biệt đã giúp bạn Linh hình dung ra Chiến dịch Hồ Chí Minh hào hùng cũng như trang lịch sử vẻ vang của dân tộc.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6fbd7a0a7ef2e1cef1bcc7b8f3d55be77535c53573ff935bfc873238cd0c26494d392ca55f547e52b12866e1196deff2e7/c2b4f40f0a10b84ee10181-6762-5834.jpg" alt="Quét mã QR trên tờ phụ san đặc biệt để tìm hiểu về Chiến dịch Hồ Chí Minh." width="770" height="1027"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Quét mã QR trên tờ phụ san đặc biệt để tìm hiểu về Chiến dịch Hồ Chí Minh.</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Như thường lệ, mỗi năm đến ngày 30/4, bà Nguyễn Thị Nga, gần 80 tuổi cùng những người bạn của mình sẽ bắt xe buýt từ Hà Đông vào trung tâm thành phố để đi tham quan các địa điểm nổi tiếng của Hà Nội như lăng Bác, cột cờ Hà Nội, Hoàng thành Thăng Long. Năm nay, có thêm một địa điểm trong chuyến đi ý nghĩa này chính là trụ sở Báo Nhân Dân.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f422a4b93883b72ba7354efc246cc5700a594f5ff91c1900f8fcab58c739d7c4e0c5e4b8206e6a781381ac0c49696fbb0/d5a5e761297e9b20c26f-2433-6220.jpg" alt="Bà Nguyễn Thị Nga xúc động khi cầm phụ san 30/4 Báo Nhân Dân trên tay." width="770" height="433"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Bà Nguyễn Thị Nga xúc động khi cầm phụ san 30/4 Báo Nhân Dân trên tay.</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Sau khi xếp hàng hơn 2 tiếng đồng hồ, được cầm trên tay phụ san đặc biệt này, các bà cảm nhận thấy một phần nào không khí hào hùng, tươi vui và hạnh phúc của ngày Lễ Độc lập cách đây 50 năm. Không giấu được những giọt nước mắt, bà Nga và những người bạn không thể tin đã 50 năm đi qua, đất nước đã đổi mới, phát triển, các bà hiểu và trân trọng hơn ai hết những phút giây hoà bình, độc lập ngày hôm nay. Những hình ảnh được tái hiện tại triển lãm của Báo Nhân Dân gợi nhớ về những phút giây không bao giờ quên.</p>



<p class="wp-block-paragraph">Không chỉ người Việt Nam, mà bạn bè quốc tế cũng rất hào hứng khi cầm trên tay tờ phụ san 30/4 của Báo Nhân Dân. Vợ chồng anh Semyon Narozhnyy, chị Maria đến từ Kazakhstan chia sẻ, tờ phụ san 30/4 rất đẹp, được in ấn công phu, cuốn hút. Dù không hiểu hết tiếng Việt in trên phụ san nhưng khi quét mã QR, hình ảnh lịch sử hào hùng trong ngày chiến thắng 30/4 hiện lên cụ thể, chi tiết cũng giúp những người nước ngoài như anh tìm hiểu thêm về lịch sử, đất nước, con người Việt Nam.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6f51854f66ab8746a38658f1e67b25ba5c48d59ba055fcd7a4d9a455b04586a141c09c27f5deeefbef702f7ea0f66b0195/c2a92141025db003e94c48-5388-7779.jpg" alt="Người nước ngoài tìm hiểu lịch sử Việt Nam thông qua tờ phụ san của Báo Nhân Dân." width="770" height="576"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Người nước ngoài tìm hiểu lịch sử Việt Nam thông qua tờ phụ san của Báo Nhân Dân.</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Hàng dài các bạn trẻ xếp hàng nối đuôi nhau để nhận phụ san cho thấy ấn phẩm đặc biệt của Báo Nhân Dân, thông qua công nghệ, đã góp phần truyền tải lịch sử đến thế hệ trẻ hôm nay, hun đúc tình yêu đất nước, niềm tự hào dân tộc đã được tiếp nối qua các thế hệ.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><img loading="lazy" decoding="async" src="https://cdn.nhandan.vn/images/ffc00e8eede7f9b1aaefa8d65cb22204a3c5ce922c141e1006deb65be037ce6fb5f8d9e5ccf0c8f3bf6a0c4e09012e943148ffd2f05e384cb6533494f3fd6cc8262fd348d7cb321d33ea4c82eb496e6f/0943324dff524d0c1443-874-2715.jpg" alt="Niềm vui vỡ òa khi nhận được phụ san 30/4 của Báo Nhân Dân." width="770" height="433"></td></tr><tr><td class="has-text-align-center" data-align="center"><em>Niềm vui vỡ òa khi nhận được phụ san 30/4 của Báo Nhân Dân.</em></td></tr></tbody></table></figure>



<p class="wp-block-paragraph">Đến nay, Báo Nhân Dân phát hơn 70.000 lượt báo và in thêm 50.000 bản để phát miễn phí như là món quà đặc biệt gửi tới bạn đọc trên cả nước. Bằng công nghệ mà Báo Nhân Dân đã tích hợp tại phụ san và triển lãm, đã tạo nên một cây cầu nối thế hệ ngày hôm nay với lịch sử hào hùng của ông cha ngày hôm qua.</p><p>The post <a href="https://techcity.cloud/uncategorized/anh-hang-nghin-nguoi-xep-hang-nhan-phu-san-30-4-cua-bao-nhan-dan-trong-ngay-dac-biet/">[Ảnh] Hàng nghìn người xếp hàng nhận phụ san 30/4 của Báo Nhân Dân trong ngày đặc biệt</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>4 Reasons Your Business Needs Zero Trust Architecture &#8211; Infographic</title>
		<link>https://techcity.cloud/uncategorized/4-reasons-your-business-needs-zero-trust-architecture-infographic/</link>
		
		<dc:creator><![CDATA[Lucas]]></dc:creator>
		<pubDate>Thu, 01 Jun 2023 09:53:39 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.techcity.cloud/?p=9241</guid>

					<description><![CDATA[<p>As cyberthreats become more pervasive and sophisticated, the traditional approach to network security has given way to a new approach – Zero Trust. Under Zero Trust,<span class="excerpt-hellip"> […]</span></p>
<p>The post <a href="https://techcity.cloud/uncategorized/4-reasons-your-business-needs-zero-trust-architecture-infographic/">4 Reasons Your Business Needs Zero Trust Architecture – Infographic</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">As cyberthreats become more pervasive and sophisticated, the traditional approach to network security has given way to a new approach – Zero Trust. Under Zero Trust, everyone attempting to enter the network is assumed to be malicious until verified.</p>



<p class="wp-block-paragraph"></p>


<a href="https://www.techcity.cloud/wp-content/uploads/2023/06/4-Reasons-Your-Business-Needs-Zero-Trust-Architecture-Infographic.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">4-Reasons-Your-Business-Needs-Zero-Trust-Architecture-Infographic</a>
<p class="wp-block-pdfemb-pdf-embedder-viewer"></p><p>The post <a href="https://techcity.cloud/uncategorized/4-reasons-your-business-needs-zero-trust-architecture-infographic/">4 Reasons Your Business Needs Zero Trust Architecture – Infographic</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is Ransomware?</title>
		<link>https://techcity.cloud/uncategorized/what-is-ransomware/</link>
		
		<dc:creator><![CDATA[Lucas]]></dc:creator>
		<pubDate>Thu, 06 Oct 2022 09:53:07 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.techcity.cloud/?p=8437</guid>

					<description><![CDATA[<p>Understanding ransomware Ransomware is a type of malware that encrypts an organization’s high-value data, such as files, documents and images, and then demands a ransom from<span class="excerpt-hellip"> […]</span></p>
<p>The post <a href="https://techcity.cloud/uncategorized/what-is-ransomware/">What is Ransomware?</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></description>
										<content:encoded><![CDATA[<h2 class="wp-block-heading">Understanding ransomware</h2>



<p class="wp-block-paragraph">Ransomware is a type of malware that encrypts an organization’s high-value data, such as files, documents and images, and then demands a ransom from the company to restore access to that data. To be successful, the ransomware malware needs to gain access to a target system, encrypt the files there, and demand a ransom from the company.&nbsp; A bitcoin or cryptocurrency ransom would then typically need to be paid to release the encrypted data files.</p>



<p class="wp-block-paragraph">Once simply a nuisance strain of malware used by cybercriminals to restrict access to files and data through encryption, ransomware has morphed into an attack method of epic proportions. While the threat of permanent data loss alone is jarring, cybercriminals and nation-state hackers have become sophisticated enough to use ransomware to penetrate and cripple large enterprises, federal governments, global infrastructure and healthcare organizations.</p>



<p class="wp-block-paragraph"><em>Depicted here is a typical ransomware killchain from&nbsp;<a href="https://www.akamai.com/resources/research-paper/akamai-ransomware-threat-report">Akamai’s Ransomware Threat Report</a>.</em></p>



<figure class="wp-block-image"><img decoding="async" src="https://www.akamai.com/site/en/images/article/2022/ransomware-killchain.png" alt="Akamai Ransomware- Threat Report" title="Akamai Ransomware- Threat Report"/></figure>



<h2 class="wp-block-heading">What is the impact of ransomware?</h2>



<p class="wp-block-paragraph">In 2020, the Snake ransomware attack brought Honda’s global operations to a standstill. That same week, Snake, a form of file-encrypting malware, also hit South American energy-distribution company Enel Argentina. In 2019, cybercriminals encrypted files that froze the computer networks of Pemex, Mexico’s state-owned gas and oil conglomerate, demanding $5 million to restore service. And in 2017, the WannaCry cryptoworm hit 230,000 computers globally by exploiting a vulnerability in Microsoft Windows.</p>



<p class="wp-block-paragraph">Today, through a mix of outdated technology, “good enough” defense strategies focused solely on perimeters and endpoints, lack of training (and poor security etiquette), and no known “silver bullet” solution, organizations of all sizes are at risk. Especially as cybercriminals are making it their business to encrypt as many computer systems on the corporate network as possible in order to extort a ransom ranging from thousands to millions of dollars. In fact, ransomware attacks were predicted to occur every 11 seconds in 2021 at a global cost of $20 billion.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.akamai.com/site/en/images/promo/2022/akamai-ransomware-threat-report-thumbnail.png" alt="" title="Akamai Ransomware Threat Report H1 2022"/></figure>



<h2 class="wp-block-heading">Ransomware Threat Report</h2>



<p class="wp-block-paragraph">The Akamai Ransomware Threat Report will focus on organizations that execute cybersecurity attacks, and the ways in which they operate.</p>



<p class="wp-block-paragraph"><a href="https://www.akamai.com/resources/research-paper/akamai-ransomware-threat-report">Download now</a></p>



<h2 class="wp-block-heading">How does ransomware spread?</h2>



<p class="wp-block-paragraph">A popular method to introduce ransomware to a new environment is through the use of phishing or<a href="https://en.wikipedia.org/wiki/Phishing" target="_blank" rel="noreferrer noopener">&nbsp;phishing emails</a>. A malicious email or email attachment may contain a link to a website that hosts a malware download or an attachment with a built-in downloader. If the email recipient opens the phishing email, then the ransomware is downloaded and executed on their computer instantly.</p>



<p class="wp-block-paragraph">Once an endpoint or victim’s computer is infected, the cyberattack will attempt to spread to as many machines as possible throughout the network by executing unauthorized&nbsp;<a href="https://www.akamai.com/our-thinking/zero-trust/lateral-movement">lateral movement</a>&nbsp;to maximize the blast radius (encrypting as many disks as possible).</p>



<p class="wp-block-paragraph">Another popular ransomware infection vector takes advantage of<a href="https://en.wikipedia.org/wiki/Remote_Desktop_Protocol" target="_blank" rel="noreferrer noopener">&nbsp;Remote Desktop Protocols (RDPs)</a>. With RDP, a hacker who has gained access to login credentials can use them to authenticate and remotely access endpoints within an enterprise network. With this access, bad actors can directly download and execute the malware on machines under their control and attempt to move laterally through the environment, capturing and encrypting data on additional assets.</p>



<p class="wp-block-paragraph">The encryption of a user’s files is the unique aspect of a ransomware attack. By encrypting highly valuable data, the cybercriminals or ransomware attacker can demand a ransom in exchange for the decryptor or decryption keys to release the files back to the company. However, ransomware hackers don’t always release the encrypted files back to the organization, even if they pay the ransom.</p>



<h2 class="wp-block-heading">Why do legacy firewalls fail when attempting protection against ransomware?</h2>



<p class="wp-block-paragraph">Legacy firewalls control communications between VLANs and zones. However, legacy firewalls don’t allow you to block traffic inside the VLAN, so this approach is ineffective when you want to prevent propagation within a segment. This is due to different network architecture limitations with the existing legacy firewall model. Once an attacker has compromised a machine on a single VLAN, they will eventually compromise another machine on the same VLAN and use it to leapfrog to other assets in the data center, including backup servers.</p>



<h2 class="wp-block-heading">How to detect and block ransomware threats</h2>



<p class="wp-block-paragraph">As a defender, you want to limit access between machines as much as possible to prevent lateral movement. Specifically around the protocols and services ransomware campaigns often exploit. There is no reason for employees’ laptops to communicate with one another and no reason for domain members to connect over SMB.</p>



<p class="wp-block-paragraph">Our solutions allow the defender to limit traffic between any two machines. Because the platform uses a software-based segmentation approach, you can create policies that block communication between laptops or limit SMB traffic between domain members and allow them only to access specific servers like the domain controller.</p>



<p class="wp-block-paragraph">Additionally, Akamai provides visibility, down to the process level, of communications and dependencies between your assets. This enables you to assess risk ahead of time and develop proactive strategies for protecting critical assets and high-risk components such as backups.&nbsp;</p>



<p class="wp-block-paragraph">The platform also comes with robust threat detection capabilities, so you can look for communication with known malicious domains or the presence of known malicious processes in your environment that may indicate a malware breach.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.akamai.com/site/en/images/promo/2022/5-step-ransomware-ebook-web-promo.png" alt=""/></figure>



<h2 class="wp-block-heading">5-Step Ransomware Defense Ebook</h2>



<p class="wp-block-paragraph">Discover how to strengthen your defenses beyond the perimeter.</p>



<p class="wp-block-paragraph"><a href="https://www.akamai.com/resources/ebook/5-step-ransomware-defense-ebook">Download now</a></p>



<h2 class="wp-block-heading">What should I do if I’m attacked by ransomware?</h2>



<p class="wp-block-paragraph">Because ransomware relies on lateral movement to execute a successful attack, that’s where organizations should focus their effort. If you determine that an active ransomware attack is in progress, use tools that provide visibility to understand the breach’s scope. Based on what you learn, you can then isolate affected parts of the network from the rest of the organization and add more security layers to critical applications and backups. Only once you have taken mitigation steps and restored services should you gradually re-enable communication flows.</p>



<p class="wp-block-paragraph">Once you have a list of all infected machines and IOCs (indicators of compromise), you can start disinfecting. Divide your machines into three label groups: Isolated, Monitored and Clean.</p>



<p class="wp-block-paragraph">Depicted here is the recommended recovery process from the&nbsp;<em><a href="https://www.akamai.com/resources/white-paper/stop-the-impact-of-ransomware-white-paper">Akamai white paper: Risk Mitigation, Prevention and Cutting the Kill Chain — Stop the Impact of Ransomware</a></em>.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.akamai.com/site/en/images/article/2022/ransomware-recovery.png" alt="Stop the Impact of Ransomware  with Guardicore Centra" title="Stop the Impact of Ransomware  with Guardicore Centra"/></figure>



<p class="wp-block-paragraph">Additionally, alerting law-enforcement agencies (such as the FBI) about the incident could facilitate an investigation and eventual prosecution against the cybercrime.</p>



<h2 class="wp-block-heading">How does crypto ransomware work?</h2>



<p class="wp-block-paragraph">A ransomware attack begins with an initial breach, often enabled by social engineering, a phishing email, malicious email attachment or vulnerabilities in the network perimeter. The malware will start to move through your network and attempt to maximize damage from its landing point. Typically, bad actors seek to seize control of a domain controller, compromise credentials and locate and encrypt any data backups in place to prevent operators from restoring infected and frozen services.</p>



<h2 class="wp-block-heading">How do you find out what ransomware you have?</h2>



<p class="wp-block-paragraph">There are many different variants of ransomware. However, looking at the specific IOCs based on suspicious domain names, IP addresses and file hashes associated with known malicious activity can help you learn more about the attack’s origin and how to respond.</p>



<figure class="wp-block-image"><img decoding="async" src="https://www.akamai.com/site/en/images/promo/guardicore-stop-the-impact-of-ransomware.png" alt=""/></figure>



<h2 class="wp-block-heading">Stop the Impact of Ransomware White Paper</h2>



<p class="wp-block-paragraph">Protect your enterprise and contain the lateral movement in your network.</p>



<p class="wp-block-paragraph"><a href="https://www.akamai.com/resources/white-paper/stop-the-impact-of-ransomware-white-paper">Download now</a></p>



<h2 class="wp-block-heading">What are the most common forms of ransomware?</h2>



<p class="wp-block-paragraph">Some campaigns are highly targeted advanced, persistent threats (APTs) run by a bad actor, while others are opportunistic, typically executed by scripts. However, there are two main categories. Attacks that encrypt files and hold them for ransom payments are known as crypto-ransomware, and ransomware that prevents users from accessing a device is known as locker ransomware.</p>



<p class="wp-block-paragraph">New types of ransomware, malicious code, malicious software, malicious attachments, scareware, and other new ransomware variants are appearing frequently in the wild. There are even documented cases of paid ransomware-as-a-service (RaaS), an example being REvil (Ransomware Evil; also known as Sodinokibi) which was a Russia-based or Russian-speaking private RaaS.</p>



<h2 class="wp-block-heading">How did ransomware get started?</h2>



<p class="wp-block-paragraph">If we look back to just a few years ago, most ransomware attacks were using<a href="https://www.cisecurity.org/blog/malvertising/" target="_blank" rel="noreferrer noopener">&nbsp;malvertising</a>&nbsp;as their initial penetration vector targeting pretty much anyone who would load these malicious ads, be it “Bob from accounting” in a large corporation or someone’s grandmother trying to read her emails. Ransomware did not really distinguish between who it was targeting – it targeted everyone and if these victims paid – great –&nbsp; and if they didn’t it was fine because there were plenty of other fish in the sea.</p>



<p class="wp-block-paragraph">However, this all changed in 2012 with<a href="https://www.nytimes.com/2012/10/24/business/global/cyberattack-on-saudi-oil-firm-disquiets-us.html" target="_blank" rel="noreferrer noopener">&nbsp;Shamoon</a>, a targeted Iranian cyberattack against the Saudi Aramco corporation. Shamoon allowed the attackers to exfiltrate large quantities of information out of Aramco and once the exfiltration was done, the attackers used Shamoon to overwrite the master boot record in the attacked machines,&nbsp; rendering them useless until they were reinstalled. This loss of functionality caused a substantial amount of downtime for the company.</p>



<p class="wp-block-paragraph">Locky was ransomware malware released in 2016. It is delivered by email (that is allegedly an invoice requiring payment) with an attached Microsoft Word document that contains malicious&nbsp;<a href="https://en.wikipedia.org/wiki/Macro_virus" target="_blank" rel="noreferrer noopener">macros</a>. When the user opens the document, it appears to be full of gibberish, and includes the phrase &#8220;Enable macro if data encoding is incorrect,&#8221; a<a href="https://en.wikipedia.org/wiki/Social_engineering_(security)" target="_blank" rel="noreferrer noopener">&nbsp;social engineering</a>&nbsp;technique.</p>



<p class="wp-block-paragraph">Petya is a family of encrypting<a href="https://en.wikipedia.org/wiki/Malware" target="_blank" rel="noreferrer noopener">&nbsp;malware</a>&nbsp;that was first discovered in 2016. The malware targets<a href="https://en.wikipedia.org/wiki/Microsoft_Windows" target="_blank" rel="noreferrer noopener">&nbsp;Microsoft Windows</a>–based systems, infecting the master boot record to execute a payload that encrypts a hard drive&#8217;s file system table and prevents Windows from booting. It subsequently demands that the user make a payment in<a href="https://en.wikipedia.org/wiki/Bitcoin" target="_blank" rel="noreferrer noopener">&nbsp;bitcoin</a>&nbsp;in order to regain access to the system.</p>



<h2 class="wp-block-heading">How did ransomware evolve?</h2>



<p class="wp-block-paragraph">Fast forward to 2017. WannaCry and NotPetya, two devastating ransomware attacks, wreaked havoc on large corporations and government entities. The unique thing about these attacks, other than showing how fragile the internet is, was that these attacks used zero-day vulnerabilities to move laterally between computers on the network in a virulent way, infecting and rendering every machine it encountered completely useless. A lot was written about NotPetya and WannaCry, but we know today that the motives behind these attacks were related to cyberattacks initiated by a nation-state adversary.</p>



<p class="wp-block-paragraph">These ransomware attacks then started being used by crimeware groups, which until that point were mostly focused on using malware like Zeus (and all of its variants) to breach people’s bank accounts to siphon money. This was often a long, complicated, and risky operation – especially when it came to actually receiving the money. Until now, the prevailing belief was just that it could be easier to target only large corporations and blackmail them into sending large amounts of money in bitcoin, which made ransomware more of a corporate threat that needs to worry CISOs, but not necessarily unsuspecting private citizens.</p>



<p class="wp-block-paragraph">Ryuk is the name of a ransomware family, first discovered in the wild in August 2018. Named after a fictional character in a popular Japanese comic book and cartoon series, it is now known as one of the nastiest ransomware families to ever plague systems worldwide.</p>



<p class="wp-block-paragraph">Now jump to 2020. While the COVID-19 pandemic rages on around the world and most people are forced into working from home, completely changing threat models, risk factors and network architectures on very short notice, the world started seeing ransomware attack operators change their modus operandi. They were now targeting large companies by conducting a<a href="https://threatpost.com/double-extortion-ransomware-attacks-spike/154818/" target="_blank" rel="noreferrer noopener">&nbsp;double extortion</a>&nbsp;attack, where the attackers not only breach the organization, encrypt the files and hold them as hostage — but they also started exfiltrating that precious and highly valuable data back to the attackers, threatening to make this data publicly available if the ransom is not paid.</p>



<h2 class="wp-block-heading">Executive order promotes segmentation for slowing ransomware</h2>



<p class="wp-block-paragraph">In 2021 a U.S.<a href="https://www.cnbc.com/2021/06/03/ransomware-attacks-white-house-memo-urges-immediate-action-by-business.html" target="_blank" rel="noreferrer noopener">&nbsp;White House memo</a>&nbsp;discussing the growth of ransomware attacks, the topic of the often overlooked importance of network segmentation was highlighted, alongside the more traditional precautions and recommendations such as patching, 2FA and updated security products.</p>



<p class="wp-block-paragraph">Network segmentation helps not only to mitigate the risk in some cases, but also to significantly lower the risk of a double extortion attack if implemented properly, by containing and minimizing the “blast radius” of a ransomware attack. Even if antivirus software and EDRs failed to prevent the ransomware from executing, proper segmentation will keep that damage contained and won’t allow the attackers to move laterally across the network to steal more sensitive data and encrypt more machines.</p>



<p class="wp-block-paragraph">The granularity of segmenting a network with Akamai’s unique software approach allows you to create “network silos” between servers, applications, different operating systems, cloud instances and so on. The strength of lowering ransomware risk by using a proper segmentation policy comes from its simplicity — a bit can either travel on the wire (or a Vswitch) to a different machine (or a VM/container) or it can be blocked,&nbsp; rendering the attackers’ attempt to reach more resources on the network useless, giving the blue team more time to respond to the attack and update the key stakeholders in the organization so they can make informed decisions about the damage of said attack.</p>



<p class="wp-block-paragraph">Network segmentation is not an alternative to an antivirus, antimalware or an EDR platform, it is a supplemental approach that has proven to significantly reduce, if not to completely eliminate the risk of large scale lateral movement based attacks across organizations.</p>



<h2 class="wp-block-heading">How do you combat the ransomware threat?</h2>



<p class="wp-block-paragraph">This new age of ransomware attacks shines a light on a problem that has been long overdue from solving: lateral movement.</p>



<p class="wp-block-paragraph">In order for the attackers to exfiltrate all of that data, they have to know where it is on the network — and in order to know that, they have to map the network and know it just as good (if not better) than the people who had originally built it. This requires the attackers to “move laterally” from one machine/server to another, often using different credentials by stealing them from various machines across the network.</p>



<p class="wp-block-paragraph">Many security vendors tried to solve this problem, and some succeeded more than others. The security market has seen new types of products emerge over the years to prevent this very problem – from DLP solutions to EDRs and EPPs – they all have tried but had very partial success in solving the problem of lateral movement.</p>



<p class="wp-block-paragraph">Solving lateral movement is hard — attackers are using the features of a network against itself.</p>



<p class="wp-block-paragraph">They will use administrator credentials and various legitimate administrative tools (such as Microsoft’s own Psexec or Remote Desktop, or even WMI) moving from machine to machine, executing malicious commands and payloads in order to steal data and later encrypt the network and start the extortion operation. Many organizations are investing resources in trying to put a Band-Aid on this problem by overly monitoring various resources using EDR/EPP products that weren’t meant to be used for that purpose, thus resulting in partial success of mitigating or even lowering the risk of a ransomware attack.</p>



<h2 class="wp-block-heading">Halting lateral movement with segmentation</h2>



<p class="wp-block-paragraph">However, there is a solution and it’s much simpler to implement than you may think — network segmentation. Segmentation is something that’s often forgotten or even ignored altogether since it’s believed to be hard to implement, and requires careful attention to network engineering and asset management. Because of this, network segmentation is often disregarded, which leaves networks “flat,” meaning every endpoint or server can talk to each other without any restriction.</p>



<p class="wp-block-paragraph">Until recently, segmenting a network meant putting different assets in different subnets with a firewall in the middle. This didn’t allow any granularity, made managing the network significantly harder, and required administrators to manage complex firewall configurations along with managing IP address allocations on different subnets, which then made designing and scaling the network much harder for the IT staff, while incorrect configurations could lead to either a security risk or a network failure (and, in some cases, even to both!). This, again, caused IT staff to not put an emphasis on segmentation and put much more trust on execution prevention products while leaving the network completely flat and unsegmented.</p><p>The post <a href="https://techcity.cloud/uncategorized/what-is-ransomware/">What is Ransomware?</a> first appeared on <a href="https://techcity.cloud">Techcity Company Limited</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
