Eskenzi PR ad banner Eskenzi PR ad banner

News

Orange caution sign

One of the largest security threats that countries face is the breach of sensitive government systems and data. With the world constantly developing and undergoing digital transformation, the devices we all rely on for both our personal and work lives are increasingly manufactured in countries considered potentially or even actively hostile toward our national interests. The U.S. Department of Defense (DoD) took a step toward combating this threat by issuing an interim Rule. The new ruling amends the Federal Acquisition Regulation (FAR)...

Read moreDetails
Major Azure vulnerability discovered by security researchers at Wiz

Cloud security vendor Wiz, who also found a massive vulnerability in Microsoft Azure's CosmosDB-managed database service recently, has found another security vulnerability in Azure that impacts Linux virtual machines. Users could end up with a little-known service called OMI installed as a byproduct of enabling any of several logging reporting and/or management options in Azure's UI. In the worst case scenario, the vulnerability in OMI could be used for remote root code execution— though in...

Read moreDetails
exploit

The open source automation server Jenkins has disclosed a successful attack on its Confluence service. Attackers abused an Open Graph Navigation Library (OGNL) injection flaw – the same vulnerability type involved in the notorious 2017 Equifax hack – capable of leading to remote code execution (RCE) in Confluence Server and Data Center instances. Rated CVSS 9.8, the bug (CVE-2021-26084) was disclosed in a Confluence security advisory published on August 25, The Daily Swig reports. David...

Read moreDetails
DDOS Logo

Russian internet giant Yandex has been targeted in a massive distributed denial-of-service (DDoS) attack that started last week and and it reportedly continues this week, Bleeping Computer reports. Russian media called the assault the largest in the history of Russian internet (RuNet), and that a US based company confirmed that the attack was ongoing. The attack started over the weekend and while there are no further details about the type or size of the DDoS,...

Read moreDetails
Beating ransomware – 6 issues to solve before it strikes

Being struck by ransomware has been compared to having a heart attack. It’s something that stalks everyone in theory and yet when it happens the shock of the experience is always a surprise. For the first seconds, minutes - and sometimes hours - organisations are on their own. It’s a moment of unexpected trauma which many organisations find paralysing, something attackers plan for. This makes the attack’s effects even worse. Eventually a growing number call...

Read moreDetails
Password Security – Now’s the time to get serious

Did you know that over 80% of breaches involve brute force or lost and stolen credentials, and that over 70% of employees reuse passwords at work? Passwords are on your first line of defence against cyber-attacks and won’t be going away any time soon, getting this piece of the puzzle correct is foundational for cyber defence, the protection of your business and its data. Live Demo: Supercharge Your Active Directory Password Policy Join us for a 30-minute live demo...

Read moreDetails
garda

Gardaí have seized cyber infrastructure used by the cyber gang involved in the HSE cyber attack earlier this year. The operation is believed to have prevented more than 750 ransomware attacks, the Irish Times has reported. The Garda-led operation targeted websites, domain names and servers used in the attacks, has been led by An Garda Síochána but also involved other international law enforcement agencies, including Interpol and Europol. Garda Headquarters, in Phoenix Park, Dublin, on...

Read moreDetails
US Cyber Command issues warning on Atlassian Confluence software

The US Cyber Command issued a warning that the Atlassian Corp. PLC’s Confluence software is being exploited on a large scale and that users should patch their installations immediately. The vulnerability, formally named CVE-2021-26084, was revealed by Atlassian on Aug. 25 and was described as allowing an authenticated user to execute arbitrary code on a Confluence Server or data centre instance. It also said that Confluence Cloud customers are not affected. The issue affects all...

Read moreDetails
Sharing Is Caring? 50% Of Brits Admit To Sharing Their Passwords.

The US' CYbersecurity Infrastructure Security Agency (CISA) has added signle-factor authentication (SFA) to its list of bad practices, which outlines exceptionally risky cybersecurity practices. The agency has specified that this low-security method of authentication is particularly dangerous when used to secure Critical Infrastructure or National Critical Functions. The list also includes the use of unsupported/end-of-life software that can no longer be patched, and the use of known/default passwords and credentials. "The presence of these Bad...

Read moreDetails
Phishing username and password

Office 365 customers have been warned by Microsoft of an ongoing phishing campaign that abuses open redirects, an email sales and marketing tool that redirects a visitor to an untrusted site. An http parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. Because...

Read moreDetails
Page 94 of 390 1 93 94 95 390