We are experts in cyber security, with nearly two decades of experience providing tailored and affordable managed security services to businesses of all sizes.
6 months on we revisit Log4Shell, the lessons learned and how to prevent this from happening again.
Read our latest insight at:
https://t.co/2VqiDPYlab
#security#log4shell#log4j#vulnerability
We found that whilst there are many incident management systems out there many of the options lacked key features, were slow, had unintuitive interfaces or were not security focussed.
So in 2016 we decided to build our own.
Find out more:
https://t.co/dzsWjBQddR
#NSA cyber weapons released by the #ShadowBrokers seen targeting industries including aerospace and nuclear energy. The #DarkPulsar exploit tool and toolkits #DanderSpritz and #Fuzzbunch have been utilised to commandeer servers in Russia, Iran, and Egypt
https://t.co/j8JDV6bCqj
@JuniperNetworks announce 22 bug fixes for #JunosOS. Critical buffer overflow attack CVE-2018-7183 allows remote attackers to execute arbitrary code by leveraging a ntpq query, and sending a response with a specially crafted array.
More details: https://t.co/q1P0ia2zB9
Several #critical and high impact bugs for #CiscoPrime recently disclosed, including a permission error which can be #exploited to perform arbitrary file upload. Patches are now available. Full list of all 26 bugs at: https://t.co/9fo8nPdmMx
Over 100,000 home routers affected by new DNS redirect malware, dubbed #GhostDNS. The malware also contains web admin and rogue DNS modules, as well as a phishing module, with notable domains including #Santander and #Netflix.
https://t.co/cKlHf2sbOw
#MEGA confirm breach of Chrome cloud storage extension for https://t.co/bSTOZfDVcq. Version 3.39.4 requests elevated permissions, and if provided, password data for websites including Amazon, GitHub and Google, as well as crypto private keys are exported.
https://t.co/JyIXnUYgqW
New WiFi standard #WPA3 launches, replacing the widely used WPA2, first certified in 2004. New features include protection against brute force attacks, 192-bit encryption for sensitive networks, and individualised data encryption for public networks.
https://t.co/3lmIL8NSTi
Newly disclosed malware, dubbed #VPNFilter, infects more than 500,000 routers and NAS boxes. The #malware, which has been largely targeting #Ukraine, has the ability to listen to #network traffic and steal credentials, as well as brick an #infected device. https://t.co/T4NZ8TDHWH
The EFAIL attacks break PGP and S/MIME email encryption by coercing clients into sending the full plaintext of the emails to the attacker. Full details, including mitigation techniques, have been published at: https://t.co/Y6tAVVBAD4
iPhone unlocker device known as #GrayKey has been reported by @Malwarebytes as being available for purchase. It is suspected that the device will make use of one or more zero day exploits in #iOS to brute force a locked phone. https://t.co/VIkwbEqGZb
New record for the most powerful #DDoS attack has been recorded at 1.7Tbps against Arbos Networks. The technique used #memcached database servers to amplify the attack, in the same way as last weeks record breaking 1.3Tbps attack against #Github.
https://t.co/9oEEvItifT
New report released by @kaspersky profiles #CryptoMining gang known as Group One, who command a #botnet of over 10,000 machines. It is estimated these infected machines generated $7 million in profit for the group over the last 6 months. https://t.co/xGlGhZajSA
New Intel security flaw allows BIOS and BitLocker logins to be bypassed 'in a matter of 30 seconds'. Requires physical access and is unrelated to Meltdown and Spectre.
https://t.co/e1iiz8NBG1
New banking #malware, #Fakebank, has been discovered. This mobile banking malware can intercept SMS messages to steal sensitive user data in an attempt to steal funds.
https://t.co/D7peW71YJ6
Wireless security protocol #WPA3 has been announced. Contains new security and privacy features. Will be launched later this year.
https://t.co/Rg884Cd0Ci
A hard-coded backdoor has been discovered in WD 'My Cloud' NAS devices. It is reported that a certain username and password that is now public can be used across these devices to login as admin.
https://t.co/yuVWjNzDOd