Content Paint

cybersecurity

How Russian spooks hacked Microsoft, the gap in its “morally indefensible” response, and what CISOs can learn from the attack

Expect to start hearing more about MS Graph...

equilend cybersecurity incident

"We are working methodically to restore the involved services as quickly as possible"

HPE emails hacked

"Cozy Bear" gained unauthorized access to HPE’s cloud-based email environment

New Fortra GoAnywhere vulnerability CVE-2024-0204

A 10-line exploit is now widely available. Unpatched instances *will* come under attack.

Europe's controversial cyber resilience law gets a rewrite -- now not as terrible as it was

A rewritten EU cyber resiliency act removes the biggest threats to open source but much standards work still to be done, says Linux Foundation Europe

Russian group hacks emails of Microsoft’s “senior leadership” and cybersecurity staff

"We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes..."

Ivanti VPN appliance exploitation now happening at scale

VPN appliances "all appear to have been constructed with the code equivalent of string, stamped with the word ‘secure’ and then just left to decay for 20 years..."

insider threat risks

"In every insider threat case, there is a combination of network activity and employee behaviour. The malicious activity crosses both physical and electronic modalities..."

Pre-auth RCE zero days in Ivanti VPNs are being exploited by a Chinese APT and there won’t be a patch for weeks. Buckle up.

Attackers re-write JavaScript loaded by the VPN login page for the Appliance to capture credentials; also grabbed Veeam credentials, moved laterally for full SYSTEM control.

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.