Facebook Linkedin
  • NEWS
    • GOVERNANCE
    • STARTUPS
    • BUDGET
    • WORKFORCE
    • PARTNERSHIPS
    • THREATS
    • DATA PRIVACY
    • Regulations & Compliance
  • FEATURES
    • Careers
    • Explainers
    • Market Trends Report
    • One Quick Question
    • Trends and Predictions
  • PODCASTS
  • Get Featured
    • READING ROOM
    • INTERVIEWS
    • WHITEPAPERS
    • INFOGRAPHICS
    • MARKET TRENDS REPORT
      • GLOBAL BLOCKCHAIN IMPACT
      • SECURITY INTELLIGENCE REPORT
      • CLOUD FORENSICS
      • DIGITAL FORENSICS
      • CYBERSECURITY HIRING
      • DATA SECURITY
      • ENDPOINT SECURITY
    • INNOVATOR’S CORNER
    • HOTSPOT
    • SPECIAL FEATURES
  • Videos
    • VIDEO INTERVIEWS
    • EVENT VIDEOS
    • WEEKLY NEWS
  • WEBINARS
  • EVENTS
    • Upcoming Events
    • Endorsed Events
    • E-Events
    • Masterclass
Search
Sunday, May 11, 2025
  • About us
  • Advisory Board
  • Careers
  • Write for CISO MAG
  • Editorial Calendar
Facebook Linkedin
CISO MAG  - News and Updates| Cyber Security Magazine CISO MAG | Cyber Security Magazine
Cisomag banner-Essentials
CISO MAG  - News and Updates| Cyber Security Magazine CISO MAG  - News and Updates| Cyber Security Magazine
  • NEWS
    • GOVERNANCE
    • STARTUPS
    • BUDGET
    • WORKFORCE
    • PARTNERSHIPS
    • THREATS
    • DATA PRIVACY
    • Regulations & Compliance
  • FEATURES
    • free-online-cybersecurity-courses-certifications
      Embark on a Cybersecurity Career with the Top Three Free Online Cybersecurity Courses
      PSTI IoT Bill, Common IoT Attacks
      3 Common IoT Attacks that Compromise Security
      Steganography attack
      How to Prevent Steganography Attacks
      Brainjacking
      How Brainjacking Became a New Cybersecurity Risk in Health Care
      Malicious QR Codes
      How Cybercriminals Exploit QR Codes to Their Advantage
      AllCareersExplainersMarket Trends ReportOne Quick QuestionTrends and Predictions
  • PODCASTS
  • Get Featured
    • READING ROOM
    • INTERVIEWS
    • WHITEPAPERS
    • INFOGRAPHICS
    • MARKET TRENDS REPORT
      • GLOBAL BLOCKCHAIN IMPACT
      • SECURITY INTELLIGENCE REPORT
      • CLOUD FORENSICS
      • DIGITAL FORENSICS
      • CYBERSECURITY HIRING
      • DATA SECURITY
      • ENDPOINT SECURITY
    • INNOVATOR’S CORNER
    • HOTSPOT
    • SPECIAL FEATURES
  • Videos
    • VIDEO INTERVIEWS
    • EVENT VIDEOS
    • WEEKLY NEWS
  • WEBINARS
  • EVENTS
    • Upcoming Events
    • Endorsed Events
    • E-Events
    • Masterclass
Home News FBI Warns About Outdated Windows 7 OS and TeamViewer
  • News
  • Threats

FBI Warns About Outdated Windows 7 OS and TeamViewer

Following the attack on a water treatment plant in Oldsmar, Florida, the FBI is warning users to stay vigilant about outdated Windows 7 OS and TeamViewer.

By
CISOMAG
-
February 15, 2021
Facebook
Twitter
Pinterest
WhatsApp
    FBI, FatPipe MPVPN zero-day

    Potential threats of using outdated Windows 7 systems, weak passwords, and desktop sharing software TeamViewer have been doing rounds since early 2020. In a Private Industry Notification (PIN), the FBI once again urged the federal government and private organizations to review their internal networks for any suspicious activities. The alert comes on the heels of a recent attack on the Oldsmar water treatment plant’s network in which attackers remotely accessed the software that controlled the chemicals used in treating the water before it is supplied to the city.

    The agencies including the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency (EPA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) stated that cybercriminals exploited out-of-date Windows 7 systems, TeamViewer software, and weak account passwords of the operators at the plant to breach the network.

    Threats with Remote Access Tools

    The FBI stated that cybercriminals often target desktop sharing software like TeamViewer to perform social engineering and phishing attacks on unwitting users.

    “Beyond its legitimate uses, when proper security measures aren’t followed, remote access tools may be used to exercise remote control over computer systems and drop files onto victim computers, making it functionally similar to Remote Access Trojans (RATs). TeamViewer’s legitimate use, however, makes the anomalous activity less suspicious to end-users and system administrators compared to RATs,” FBI said.

    For secured use of TeamViewer software, the agency recommended some security steps. These include:

    • Do not use unattended access features, such as Start TeamViewer with Windows and Grant easy access.
    • Configure TeamViewer service to manual start, so that the application and associated background services are stopped when not in use.
    • Set random passwords to generate ten-character alphanumeric passwords.
    • When configuring access control for a host, utilize custom settings to tier the access a remote party may attempt to acquire.
    • Utilize the Block and Allow list which enables a user to control which other organizational users of TeamViewer may request access to the system. This list can also be used to block users suspected of unauthorized access.

    Issues with Windows 7 OS

    Microsoft ended the security updates and technical support for their Windows 7 Operating System on January 14, 2020. The FBI warned that enterprises running Windows 7 systems are vulnerable to getting hacked due to lack of security updates, making it difficult to defend against the persistent malicious activities of cybercriminals. “Cyber actors continue to find entry points into legacy Windows operating systems and leverage Remote Desktop Protocol (RDP) exploits,” FBI added.

    Cyber Hygiene

    The agency also recommended certain cyber hygiene measures to protect against the potential risks. These include:

    • Update to the latest version of the Operating System (e.g., Windows 10).
    • Use multi-factor authentication.
    • Use strong passwords to protect Remote Desktop Protocol (RDP) credentials.
    • Ensure anti-virus, spam filters, and firewalls are up to date, properly configured, and secure.
    • Audit network configurations and isolate computer systems that cannot be updated.
    • Audit logs for all remote connection protocols.
    • Train users to identify and report attempts at social engineering.
    • Identify and suspend access of users exhibiting unusual activity.

    The authorities also advised users, security admins, and organizations to report suspicious cybercriminal activities at www.fbi.gov/contact-us/field.

    Related Story: Cybercriminals Attempt Poisoning Florida City’s Water Supply

    • TAGS
    • Cyberattacks
    • Cybercriminals
    • desktop sharing software
    • FBI
    • Federal Agencies
    • Oldsmar attack
    • out-of-date Windows 7 operating system
    • TeamViewer
    • weak account passwords
    Facebook
    Twitter
    Pinterest
    WhatsApp
      Previous articleUkraine’s PrivatBank Suffers Data Breach; 40 Mn Customer Records on Sale
      Next articleIRS Alerts U.S. Taxpayers About e-File Identity Theft via Phishing Attacks
      CISOMAG
      CISOMAG
      https://cisomag.com/

      RELATED ARTICLESMORE FROM AUTHOR

      PSTI IoT Bill, Common IoT Attacks
      Features

      3 Common IoT Attacks that Compromise Security

      SIM Swapping
      News

      FBI Issues a Lookout for SIM Swapping Attacks

      remote work, Remote workforce security
      News

      How Remote Work Increase Digital Anxiety



      Cyber Career Starter Scholarship

      Latest Issue is Out!

      Ciso mag jan
      cciso_sidebar
      boxbanner

      FOLLOW US FOR MORE UPDATES


      CYBER SHOTS
      Quick, punchy updates on Cyber trends, news and links to free resources. Only via Telegram and Signal. Join the groups now!
      Click Here Click Here

      MOST POPULAR

      Research Finds Increase in Botnet and Exploit Activity in Q2 2020

      45% companies don’t have cybersecurity leader: Study

      CISOMAG - December 11, 2017
      DEO data breach

      Nearly half of companies have suffered a data breach in the past year: Survey

      November 15, 2017
      Messaging

      Mobile messaging apps new hideout of Dark Web activities: Study

      October 27, 2017
      Kaspersky

      NSA hacking code lifted from a personal computer in U.S.: Kaspersky

      October 30, 2017

      Instagram data breach! 49 million users’ sensitive data exposed online

      May 23, 2019

      RECENT POSTS

      National Insider Risk Symposium

      May 5, 2025

      Cybersec Europe

      April 25, 2025

      HackVSIT 6.0

      April 25, 2025

      CyberX Bahrain

      April 23, 2025

      Infosecurity Europe

      April 23, 2025
      Cybersecurity News and Updates, Magazine
      CISOMAG is the handbook for Chief Information Security Officer (CISO)s, CXOs, and every stakeholder of safe internet.
      Contact us: [email protected]
      Facebook Linkedin

      EVEN MORE NEWS

      National Insider Risk Symposium

      May 5, 2025

      Cybersec Europe

      April 25, 2025

      HackVSIT 6.0

      April 25, 2025

      POPULAR CATEGORY

      • News2554
      • Threats1657
      • Features592
      • Partnerships215
      • Governance191
      • Startups161
      • Interviews120
      • Terms of Use
      • Privacy Policy
      • Advertise with us
      • Contact Us
      • MASTERCLASS
      © CISOMAG 2024
      We Care
      Ensuring that you get the best experience is our only purpose for using cookies. If you wish to continue, please accept. You are welcome to provide a controlled consent by visiting the cookie settings. For any further queries or information, please see our privacy policy.
      Do not sell my personal information.
      Cookie SettingsAccept
      Manage consent

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
      CookieDurationDescription
      cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
      cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
      cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
      cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
      cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
      viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
      Functional
      Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
      Performance
      Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
      Analytics
      Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
      Advertisement
      Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
      Others
      Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
      SAVE & ACCEPT
      MORE STORIES
      Upcoming Events

      National Insider Risk Symposium

      CISO MAG - May 5, 2025 0
      September 17-18, 2025 Location: National Housing Center, Washington, D.C., USA The National Insider Risk Symposium will return to Washington, DC this...