Items tagged with security
by
Paul Lilly - Wed, Aug 11, 2021
Microsoft is pretty confident that it has finally addressed the dreaded PrintNightmare that has been keeping IT admins awake at night. Okay, maybe that is a slight exaggeration. However, the vulnerability within Microsoft's Windows Print...
Read more...
by
Nathan Ord - Tue, Aug 10, 2021
Ransomware infections have been on the rise lately, affecting companies like Gigabyte or, more famously, Kaseya. Subsequently, the fight against the ransomware plague needs to meet and exceed threat actors’ efforts, and Microsoft is...
Read more...
by
Nathan Ord - Tue, Aug 10, 2021
Network Attached Storage (NAS) devices from Synology are being targeted by the StealthWorker Botnet in an ongoing brute-force attack that could lead to ransomware infections. Perhaps we should just drop the “network attached” of NAS...
Read more...
by
Nathan Ord - Sun, Aug 08, 2021
Earlier in the month, Tenable security researchers discovered a vulnerability allowing attackers to bypass authentication on millions of routers from 17 different vendors. However, it now appears that threat actors are actively exploiting...
Read more...
by
Paul Lilly - Fri, Aug 06, 2021
Which do you prefer when browsing the web—raw speed or a combination of security and privacy? Generally speaking, modern browsers deliver the whole kit and caboodle, which is the way it should be. That said, Microsoft is testing a new...
Read more...
by
Nathan Ord - Thu, Aug 05, 2021
Google is looking to make home security cheaper and easier to setup using wire-free options, smart alerts, and enhanced privacy via a line of new next-generation of Nest Cams and Doorbell. With these new products, Google is taking a hard...
Read more...
by
Nathan Ord - Tue, Jul 27, 2021
If you want to be stealthy, perhaps not wearing a hot pink suit is a good choice. When it comes to cybersecurity, avoiding computer languages that people have come to know and recognize is a good idea as well. Threat actors have seemingly...
Read more...
by
Nathan Ord - Tue, Jul 27, 2021
In the past, there have been some big slip-ups when commentators did not know that they were on-air and began speaking their mind to other people. This seems to have happened again at the Tokyo Olympics when an Italian TV announcer did not...
Read more...
by
Nathan Ord - Mon, Jul 26, 2021
Hackers and threat actors are constantly searching for new ways to breach systems for cybersecurity research or exploitation, respectively. Thankfully, French researcher Gilles Lionel got to an NTLM Relay Attack, dubbed PetitPotam, first...
Read more...
by
Paul Lilly - Wed, Jul 21, 2021
Microsoft is warning of a vulnerability in both Windows 11 (not yet released, but available in preview form to Windows Insiders) and Windows 10 that could reveal a user's admin password, which in turn could be used to elevate their own...
Read more...
by
Nathan Ord - Tue, Jul 20, 2021
Earlier this year, the Colonial Pipeline ransomware incident crippled fuel delivery to the Eastern Seaboard, sending people into a panic and decreasing the supply of gas, if only briefly. Amazingly, this is only the first time something of...
Read more...
by
Nathan Ord - Fri, Jul 16, 2021
Just as there is a traditional weapons market, a private sector cyberweapons market enables people and organizations to attack anyone worldwide for a fee. However, Microsoft takes this threat of cyberweapons seriously, and is now working...
Read more...
by
Paul Lilly - Fri, Jul 16, 2021
Remember that scene in Office Space where a trio of disgruntled employees take a problematic printer to field and beat it to a pulp? Anyone who has ever dealt with stubborn printer issues has probably felt that way. It doesn't help that we...
Read more...
by
Paul Lilly - Thu, Jul 15, 2021
Over the past few years, biometric security solutions have been on the rise, replacing the use of traditional passwords on both mobile devices and the PC. Windows Hello is one such implementation. It allows users to near-instantaneously...
Read more...
by
Nathan Ord - Thu, Jul 15, 2021
Earlier this year, a vulnerability within Apple’s WebKit for Safari was discovered by Google’s Threat Analysis Group (TAG) and then tracked as CVE-2021-1879. Now, it is reported that this vulnerability was likely exploited by a familiar...
Read more...
by
Nathan Ord - Wed, Jul 14, 2021
After last week's out-of-band update to patch the PrintNightmare vulnerability, Microsoft has now released more vulnerability fixes as part of Patch Tuesday. With this update, the Redmond, Washington-based company knocked out a whopping...
Read more...
by
Nathan Ord - Wed, Jul 14, 2021
It appears that REvil, the threat actor group behind attacks on JBS Global and Kaseya, among others, has gone dark. While this could be a good thing, it may not be worth holding your breath as there are other explanations for REvil...
Read more...
by
Nathan Ord - Wed, Jul 14, 2021
Yesterday, Microsoft reported that it had detected a 0-day remote code execution exploit being used in the wild against SolarWinds’ Serv-U FTP product. The vulnerability that allowed this exploit has since been patched, but it is still...
Read more...
by
Paul Lilly - Fri, Jul 09, 2021
If you are still relying on Apple's discontinued AirPort Time Capsule to back up you data, you may want to seek out an alternative. Otherwise, you could lose all your files to what a data retrieval company is calling a flaw in the physical...
Read more...
by
Paul Lilly - Fri, Jul 09, 2021
Customers of Kaseya's Vector Signal Analysis (VSA) software are being warned to be on the lookout for phishing emails claiming to offer up a security update, but in reality contain a malicious payload. The phishing campaign is a result of...
Read more...
by
Paul Lilly - Wed, Jul 07, 2021
As if fussing with a printer is not maddening enough, a recent Windows Print Spooler exploit called 'PrintNightmare' left users vulnerable to remote code execution attacks. Not cool. Fortunately, Microsoft has made rather quick work of...
Read more...
by
Nathan Ord - Tue, Jul 06, 2021
Over the weekend, cybersecurity experts, forensics teams, and white-hat hackers worldwide have been battling the ransomware incident affecting Kaseya VSA customers. Now, the Florida-based IT and remote management company is reporting that...
Read more...