๐ Announcement! I've just signed with @WileyGlobal to publish my upcoming book. This book demystifies complex concepts and guides businesses in transforming security strategies into real-world solutions. Thanks to @stiennon and @jimminatel for their incredible support.
After delving into Dan Sullivan's insightful "The Gap and the Gain," I'm eager to explore how its principles, with a unique twist, can profoundly influence our approach to operationalising cybersecurity for enhanced effectiveness. https://t.co/bj5Yx1WYPC
We have now posted our @rapid7 analysis into CVE-2023-40044, a .NET deserialization vulnerability affecting the Ad Hoc Transfer module of WS_FTP Server. Now available on @AttackerKb - H/T @stephenfewer https://t.co/1tbagry11y #infosec#cybersecurity
Our latest @rapid7 analysis details CVE-2023-22515, "a critical privilege escalation vulnerability affecting on-premises instances of Confluence Server and Confluence Data Center" more details here: https://t.co/X5A6bPMtxi #infosec#cybersecurity
๐จ Security Alert ๐จ
CVE-2023-42793 is a critical authentication bypass in JetBrains TeamCity CI/CD servers. Stay vigilant and update your systems ASAP! Read more: https://t.co/sVpCjM4V5c
#CyberSecurity#InfoSec#CVE2023#TeamCity#Rapid7
"๐ Building a strong security culture is crucial in today's digital landscape. Check out my lastest Forbes article on how to cultivate a thriving security culture for your organization! ๐ผ๐ป #Cybersecurity#SecurityCulture#TechTrends Read more: https://t.co/j1VgzBVsGP
Rapid7 obtained a leaked copy of the manual and analyzed its content. Notably, the author claimed they had compromised 4,865 Cisco SSL VPN services and 9,870 Fortinet VPN services with the username/password combination test:test
In February 2023, a well-known initial access broker called โBassterlordโ was observed in XSS forums selling a guide on breaking into corporate networks. The guide, which included chapters on SSL VPN brute forcing, was being sold for $10,000 USD.
When several other forums started leaking information from the guide, Bassterlord posted on Twitter about shifting to a content rental model rather than selling the guide wholesale.
Anonymised log entry where an attacker attempts a (failed) login to the ASA SSL VPN service. The analysis of log files across different incident response cases, frequently observed failed login attempts occurring within milliseconds of one another, pointing at automated attacks
Today, I bring to your attention a compelling case that underscores the critical need for Operationalising Cybersecurity ๐. The recent findings from @Rapid7's Managed Detection and Response (MDR) teams provide a poignant example.
https://t.co/3RDEVVYrrb
We're pleased to share that Rapid7 CTO @Hart_Jason helped to secure @EM360Tech's Most Popular Podcast of Q2, 2023!
See why it reached breaking numbers with the EM360 audience here: https://t.co/QR7oZJtboT
Our latest @rapid7 analysis details CVE-2023-35082, a new vulnerability that allows unauthenticated attackers to access the API in older unsupported versions of MobileIron Core (11.2 and below). https://t.co/044O5mRxRH #infosec#cybersecurity H/T @stephenfewer
๐จ๐ป Exciting news! Check out my latest Forbes article on "Maximizing Cybersecurity Impact with Protection Level Agreements" ๐๐ฅ Learn how Protection Level Agreements (PLAs) can bolster your Cybersecurity defenses and reduce risks. Read it here https://t.co/xfGFdF38ZA