Secmatics is a UK based cybersecurity company. We provide network and application level security services that are built on our own automated analysis platform.
Good security isn't just about tools and technology. Creating the right culture and ensuring that everybody is aware of potential threats are critical components of any effective security program.
The Secmatics CSO (Canine Security Officer) shows how it should be done by diligently checking recent logs for signs of suspicious activity. The check did not identify any issues, sadly there were also no tasty treats to be found. #infosec #cybersecurityawareness
Insecure remote access solutions can provide an easy way for hackers to get into your network. Our health check service is an easy way to make sure you don't invite them in. https://t.co/rARKBouJ7r
We take a brief look at the risk of exposing Microsoft’s Remote Desktop (RDP) directly to the Internet. TL;DR: Don't do it. https://t.co/nksbGO5OeN #cybersecurity
Sneak Peek: We are currently working on a set of deployment guides that enable high risk services, such as RDP, to be easily protected using our Zero Trust technology. Get in touch if you would like to know more. https://t.co/BCk3ArWf2u #zerotrust#infosec
MITRE, the company that maintains the Common Vulnerabilities and Exposures (CVE) database, was recently breached due to a vulnerability in their own VPN infrastructure.
The issues used to gain access to MITRE, CVE-2023-46805 and CVE-2024-21887, were fairly well covered in the news earlier this year. They could be chained together to enable a remote attacker to take full control of Ivanti Connect Secure, a VPN server that (at the time of writing) has just over 30,000 Internet-visible deployments. Unfortunately, this wasn’t the first critical VPN vulnerability... Read more at: https://t.co/lHqNX111B0 #mitre #cve #breach
As of April 2024 there are over 3.5 million Internet-visible Remote Desktop (RDP) servers, this equates to 3.5 million accidents just waiting to happen. https://t.co/muJOviJpph
Attention grabbing headlines relating to the #Roku “Data Breach” seem to have spread everywhere over the last few days. It is worth looking into what actually happened though, mainly because so many organisations are at risk from exactly the same attack. https://t.co/oGDA36xHEZ
Patches are now available for the critical severity GlobalProtect vulnerability disclosed late last week. These servers are easily identifiable and our current data shows over 80 thousand Internet-visible GlobalProtect instances. https://t.co/5sO7X4foGD
Cybersecurity investment is usually focused on business risk, but let’s not forget that when things go wrong it is often individuals that pay the price. https://t.co/fzUjARErUH #infosec
Recent research shows that 94% of ransomware-stricken organisations report attempts to sabotage their backups, with success rates as high as 79% in some critical sectors. https://t.co/mdVuyYDAAR #ransomware#backup#cybersecurity
It seems as though nobody is safe from cyberattacks. CVS Group, a leading UK veterinary service provider, found this out the hard way.
Don’t wait for this to happen to your business. If you need help finding and mitigating high risk threats then we can help.
https://t.co/YlX7056HVK
The Cyber Safety Review Board's report on the Summer 2023 Microsoft Exchange Online intrusion:
"However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key." https://t.co/iI1lwu7Hyu
This not surprising. As we noted last year:
"One of the main design goals of a secure key management system is to ensure that you have full traceability of the keys and know exactly what hardware and software components could have accessed them. Without such a system it is next to impossible to retrace all of the direct and indirect touch points at which a key could potentially have been compromised" https://t.co/nqPjcRjf9X
#microsoft #cybersecurity #CISA
A lot of people seem to be worried about the use of AI in cyberattacks.
Meanwhile, state-sponsored cyber groups are busy attacking critical US infrastructure by connecting to Internet-visible PLCs with password of "1111".
Don't worry about AI. Worry about this instead. https://t.co/RRu8k1o7dw
Want to know what your organisation is exposing to the Internet? https://t.co/FQBpRFI4yR
The France Travail breach impacted 0.5% of the world's population.
Is it time to put more focus on designing secure multilayered systems?
Or is that still too expensive? #cybersecurity#FranceTravail
This was true 50 years ago, and it is still true today:
"The panel cannot overemphasize its belief that 'patching' of known faults in the design or implementation of existing systems without any better technical foundation than is presently available, is futile for achieving multilevel security."
COMPUTER SECURITY TECHNOLOGY PLANNING STUDY. James P. Anderson, October 1972.
https://t.co/pupR34DQl3 #cybersecurity #history
Many small businesses are struggling to build effective cybersecurity defenses. Our Cyber➾Guard service provides everything you need though a single subscription. https://t.co/NvtBK2dQzv
#cybersecurity#SmallBusiness#SMB
"By cross referencing the indicators of compromise against the exploit timestamp and the NetScaler version being used, we were able to recreate a precise granular timeline of the global attack, here is how it unfolded..." #ransomware#netscaler#breach
https://t.co/LIckSUwfnI