Skip To Main Content
David Strom on Muck Rack

David Strom

Verified
St. Louis
Covers:  networking, security, cloud computing, storage, Internet applications, interesting case studies
Cybersecurity reporter for B2B IT pubs, speak on IT topics

David Strom’s Journalist Portfolio

View as a grid

Understanding how cybercrime group FIN7 has evolved into a major ransomware player

Understanding how cybercrime group FIN7 has evolved into a major ransomware player

avast.com — Malware group FIN7 is once again on the move, leveraging software supply chains, remote program execution methods, and stolen credentials to deliver ransomware to enterprise networks. The group has been around since at least 2015. Initially, the gang made its reputation by maintaining persistent access at target companies with its custom backdoor malware, and for targeting point-of-sale systems with credit card skimmer software.

How to evaluate software asset management tools

How to evaluate software asset management tools

InfoWorld — The vulnerabilities of the Apache Log4j logging package-and the attacks they've drawn -have made one thing very clear: If you haven't yet implemented a software inventory across your enterprise, now is the time to start evaluating and implementing such tools.

WordPress security: Top tools and best practices

WordPress security: Top tools and best practices

CSO Online — If you run a WordPress website, you need to get serious about keeping it as secure as possible. WordPress continues to be a widespread target for hackers. Last November, more than a million GoDaddy-managed WordPress customers were part of a breach that could have exposed their email addresses, private SSL keys, and admin passwords.

More Mobile Apps Means More Man-in-the-Middle Attacks

More Mobile Apps Means More Man-in-the-Middle Attacks

securityintelligence.com — When you travel outside your corporate network with your mobile device, you are much more vulnerable to man-in-the-middle (MitM) attacks. This is how attackers intercept data as it's being passed from a mobile device to a server. Of course, this is problematic for a number of reasons.

FIR B2B #75: Beth Winkowski does B2B PR very well - FIR Podcast Network

FIR B2B #75: Beth Winkowski does B2B PR very well - FIR Podcast Network

firpodcastnetwork.com — This week we speak with someone who does B2B public relations very well. Beth Winkowski has had her own PR firm for more than a decade after working for years with leading-edge tech companies. Both Paul and David have always admired her judgment, sensitivity and attention to detail.

What is Fileless Malware and Why Should You Care?

What is Fileless Malware and Why Should You Care?

iboss.com — Security researchers have showed that close to two-thirds of them have seen an increase in non-malware attacks since the beginning of 2016. This could take the form of using in-memory PowerShell commands, hide inside Word macros or leverage the macro code to do damage to your systems. found by security researchers from an attack earlier this year in Israel So what are IT managers to do to try to fight fileless attacks?

What to look for in hiring your next CISO

What to look for in hiring your next CISO

hpe.com — CISO is a trendy job title, but turnover is high. Here's how to hire one who'll last. Hiring a chief information security officer (CISO) is a tricky process. The job title is in the limelight, especially these days, when breaches are happening to so many businesses.

How Ransomware is Changing the Nature of Customer Service

How Ransomware is Changing the Nature of Customer Service

iboss.com — There have been plenty of articles written about the rise of ransomware, especially lately. Whether you believe users are forgetful or just click-happy, there is one thing that isn't often discussed, and that has to do with how good the ransomware creators are at providing terrific technical support. Yes, I am serious.

Improving Your Privacy Settings in Windows 10

Improving Your Privacy Settings in Windows 10

securityintelligence.com — Microsoft's Windows 10 is rapidly replacing older operating systems in both personal and professional environments. As with any OS, however, there are several key things you need to know upfront. The addition of unique advertising IDs that inject Microsoft ads into your browser, recommended express privacy settings and cloud syncing of personal information can inadvertently overshare your sensitive data if you don't take precautions.

Why Grammar Counts in Decoding Phished Emails

Why Grammar Counts in Decoding Phished Emails

blog.iboss.com — When it comes to crafting the "best" phishing email scam letter, over the years it has been assumed that the less polished a letter, the better. Having something that is poorly worded, or purposely uses bad syntax and grammar tends to eliminate the sharper-eyed readers who probably wouldn't respond to the phish anyway.

Going beyond the password: past, present and future technologies

Going beyond the password: past, present and future technologies

Windows ITPro — We have a love/hate affair when it comes to using passwords. The average person has to remember dozens of them for various logins, and many of us try to cope by reusing our favorites.

There are Better Ways to Manage Data than Google Docs

There are Better Ways to Manage Data than Google Docs

quickbase.com — Google Docs is a favorite way to build applications for lightweight data manipulation, reporting, and analytics as well as useful for building websites that can capture and display data. While it is a great tool to get started using an online all-purpose office suite, you should also know its limitations and when it is time to move on to something more industrial strength.

Five Networking Pet Peeves - InformationWeek

Five Networking Pet Peeves - InformationWeek

InformationWeek — Here are some of the more frustrating, unsolved networking problems that can get your blood boiling, in the opinion of our expert. Now that you can e-mail anyone, anytime, anywhere, run significant applications from within an ordinary Web browser, and run your life from your laptop, it's worth taking a step back to think about some of the more frustrating networking problems that remain unsolved. Here are the top five things that get me steamed: Why can't American cell phones work as well as the rest of the world's?

Bitdefender Box Review - Home Network Security

Bitdefender Box Review - Home Network Security

Tom's Guide — When the well-regarded Romanian antivirus firm Bitdefender first announced its Box, a new breed of security hardware that protects a smart home's connected devices by monitoring the home's network, we were intrigued. But now that we've had a chance to use the Box, it sadly overreaches and isn't quite ready for prime time. It tries to do too many things, and does few of them well. The Bitdefender Box will be useful only in a very limited number of circumstances, and falls far short of being the kind of unique protective appliance it promises to be.

Review: Single sign-on tools offer impressive new capabilities

Review: Single sign-on tools offer impressive new capabilities

Network World — Centrify edges Okta and OneLogin in seven-vendor shootout. Since we last looked at single sign-on products in 2012, the field has gotten more crowded and more capable. A number of new vendors have come to ply their wares, and a number of old vendors have been acquired or altered their products. For this round of evaluations, we looked at seven SSO services: Centrify's Identity Service, Microsoft's Azure AD Premium, Okta's Identity and Mobility Management, OneLogin, Ping Identity's Ping One, Secure Auth's IdP, and SmartSignin. In addition to these products, we also looked briefly at AVG's Business SSO.

CheckPoint, Watchguard earn top spots in UTM shootout

CheckPoint, Watchguard earn top spots in UTM shootout

Network World — UTM appliances for SMB security are getting smaller, more powerful and more feature rich. When it comes to unified threat management appliances aimed at the SMB market, vendors are finding a way to fit additional security features into smaller and more powerful appliances. In 2013, we looked at nine UTMs. This time around we reviewed six products: the Calyptix AccessEnforcer AE800, Check Point Software's 620, Dell/Sonicwall's NSA 220 Wireless-N, Fortinet's FortiWiFi-92D, Sophos' UTM SG125 and Watchguard Technologies' Firebox T10-W. (Cisco, Juniper and Netgear declined to participate.) We observed several megatrends across all the units that we tested:

Customer-driven infrastructure: building future-ready consumer applications

Customer-driven infrastructure: building future-ready consumer applications

GigaOM — The days when IT could tell end users which kinds of computing gear to purchase and use ended sometime in the 1990s, but for many years afterwards, IT retained a stranglehold on the deployment and maintenance of enterprise infrastructure, corporate-wide applications, and building data centers. Those days are quickly becoming another memory for IT departments, which have seen the evolution of customer-facing applications and the web- and cloud-based worlds that have arisen. These apps are changing the way that IT delivers its services, builds its enterprise architectures, and selects its systems. This paper is intended for IT managers and department heads who are looking to evaluate their computing requirements and make the transition to cloud, mobile, and web-based apps.

SSDs Speed Up Exchange Operations for Law Firm - Nimble

SSDs Speed Up Exchange Operations for Law Firm - Nimble

tomsitpro.com — 125-person firm deploys Nimble Storage's SSD to speed up Microsoft Exchange email operations, including disaster recovery. The notion of using solid state hard drives ( SSDs) to speed up storage operations isn't very new. There are more than a dozen vendors that offer some kind of SSD storage, or combine solid-state electronics with traditional rotating media, for both dedicated storage and storage area networks. But last month we saw a case study posted online about how one 125-person law firm deployed Nimble Storage's SSD to help speed up its Microsoft Exchange email operations, including disaster recovery.

Getting in Sync, Electronically

Getting in Sync, Electronically

The New York Times — IT is a sad fact of the business world that too many people - among them those in the executive suite, small-business owners and employees down through the ranks - spend too much time in meetings. But Web sites and software have made planning them simpler and quicker. For instance, such tools can determine when potential participants could attend and will automatically send them e-mail reminders. But not all meetings are alike. Different tools are needed in different situations, depending on the number of people involved, whether it is an internal meeting or includes people from outside companies and who does the scheduling.

Capturing the Essence of Mr. Lincoln With Theatrics

Capturing the Essence of Mr. Lincoln With Theatrics

The New York Times — A combination of ordinary and custom-built PCs, 100 miles of cabling and dozens of digital sound processors are used to create effects that range from something as simple as falling rain on a windowpane to complex holographic videos.

Red vs. blue vs. purple teams: How to run an effective exercise

Red vs. blue vs. purple teams: How to run an effective exercise

CSO Online — In the arsenal of cybersecurity defenses is the exercise that goes by the name of red team/blue team simulated attack. These simulations are designed to closely mimic real-world conditions. For example, one red team member might take on the role of an employee clicking on a phishing link that deposits malware on the network.