Over the past two decades, the tech industry has witnessed a marked shift from traditional enterprise networks and collocation data centers to cloud computing. Cloud computing allows users to access servers, storage, and applications over the internet. In contrast to conventional enterprise networks that are typically built onsite and require a significant investment in hardware, software, and personnel to operate and maintain, cloud computing requires no on-premises infrastructure. Cloud service providers (CSPs), such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud, offer automated services that allow customers to provision new systems and applications quickly and efficiently and scale their environments on demand. Despite its numerous advantages, cloud computing introduces several challenges that IT departments, security teams, and application developers must consider when securing their cloud environments.
[Read more…] about 9 Challenges to Securing the CloudWhat is a Penetration Test?
A penetration test, or pen test, is a simulated cyberattack against a computer system to identify weaknesses that malicious hackers could use to gain unauthorized access to data and computing resources. Pen tests aim to identify as many potential security threats and vulnerabilities as possible in an environment. When conducted effectively and regularly, pen tests can help businesses identify and fix security weaknesses before cybercriminals find and exploit them. By conducting regular pen tests, organizations can get feedback on the effectiveness of their security processes and improve their overall security posture.
[Read more…] about What is a Penetration Test?Cybersecurity Daily: January 17, 2024
Your daily dose of relevant cybersecurity advisories, industry news, and product updates for January 17, 2024.
Alerts & Advisories
- Ivanti Zero-Day Exploits Skyrocket Worldwide; No Patches Yet
- Alert: Over 178,000 SonicWall Firewalls Potentially Vulnerable to Exploits – Act Now
- GitHub Rotates Credentials in Response to Vulnerability
- Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows
- MacOS info-stealers quickly evolve to evade XProtect detection
- Cisco Fixes High-Risk Vulnerability Impacting Unity Connection Software
- CISA adds patched MS SharePoint server vulnerability to KEV catalog
- WordPress Plugin Flaw Exposes 300,000+ to Hack Attacks
- Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks
- Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches
- Citrix warns of new Netscaler zero-days exploited in attacks
- Google fixes actively exploited Chrome zero-day (CVE-2024-0519)
- VMware patches critical access control vulnerability in Aria Automation
- Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances
- Oracle Patches 200 Vulnerabilities With January 2024 CPU
- New Bluetooth vulnerability allows takeover of iOS, Android, Linux, and MacOS devices
- Experts warn of a vulnerability affecting Bosch BCC100 Thermostat
Weekly Malware Roundup – January 15, 2024
This is the GreyKeep Security Malware Roundup for January 8, 2024. Here’s a summary of what’s in this week’s edition:
Targets
MSSQL Server Windows WordPress Apple Mac | YouTube Apache Hadoop Apache Flink NAS devices |
Organizations
Quantum Radiology | Iran |
Threat Actors
RE#TURGENCE (Turkey) | Water Curupira |
Cybersecurity Daily: January 10, 2024
Your daily dose of relevant cybersecurity advisories, industry news, and product updates for January 10, 2024.
Alerts & Advisories
- Hackers target Microsoft SQL servers in Mimic ransomware attacks
- Ivanti patches critical EPM flaw that could allow hackers to hijack managed devices
- Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V
- CISA Flags 6 Vulnerabilities – Apple, Apache, Adobe , D-Link, Joomla Under Attack
- Kyocera Device Manager Vulnerability Exposes Enterprise Credentials
- Cacti Monitoring Tool Spiked by Critical SQL Injection Vulnerability
- Multiple QNAP High-Severity Flaws Let Attackers Execute Remote Code
- Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs
- Android’s January 2024 Security Update Patches 58 Vulnerabilities
- SAP’s First Patches of 2024 Resolve Critical Vulnerabilities
- Beware Weaponized YouTube Channels Spreading Lumma Stealer