Resources

Blog

Another Month, Another Onslaught of Ransomware Attacks

Ransomware & Malware – Not “IF” but “WHEN”. Are We Ready to Do Something About It? I’m going to play a little Captain Obvious here but cyberattacks, particularly ransomware and malware, continue to embarrass organizations globally. Boards of directors and executive leadership teams at enterprises, big and small, claim to

Read More »

Patch Now: Microsoft Releases Updates for Over 75 Flaws

Microsoft Releases Patches for 9 Critical Flaws & 3 Zero-Day Vulnerabilities On Tuesday, Microsoft released its security updates for February 2023, including patches for over 75 flaws. Among the 75 vulnerabilities, nine were rated “critical” and 66 “important” in terms of severity of threat to the organization. Three of them

Read More »

Microsoft Launches Brute Force Attack Protection For All Windows Versions

Microsoft Releases Policy to Further Prevent Brute Force Attack Attempts Earlier this week, Microsoft announced additional protection against brute force attacks, one of the most common methods used to attack Windows machines. IT admins can now configure a group policy to automatically block brute force attacks targeting local administrator accounts

Read More »

What is an Active Directory Forest?

Active Directory (AD) Organizational Structure: Understanding AD Forests Active Directory is a vital component of any Microsoft enterprise and often a target for threat actors. As such, it is important not only to secure Active Directory but understand how to best configure and manage its’ components in order to reduce

Read More »

Azure AD Connect: New Update

New Azure AD Connect Version 2.0.91.0 Released This week, Microsoft released an updated version of Azure AD Connect. This new version provides compliance of the Azure AD Connect Health component with the Federal Information Processing Standards (FIPS) requirements. Keep track and understand all the versions that have been released —

Read More »

‘Wormable’ Flaw Leads January 2022 Patch Tuesday

Microsoft Releases Over 100 Updates in Patch Tuesday for January 2022 The January security updates from the Redmond-based software giant cover security defects in a wide range of default Windows OS components, including a critical flaw in the HTTP Protocol Stack (http.sys) that Microsoft describes as “wormable,” and another code

Read More »
Zoho ManageEngine Zero Day Flaw Active Exploit

ManageEngine Zero-Day Flaw Actively Being Exploited

FBI Warns: APT Groups Exploiting Critical Vulnerability in ManageEngine Software Earlier this month, the FBI and Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory highlighting a newly discovered vulnerability being actively exploited in ManageEngine ServiceDesk Plus, owned by Zoho Corp, an IT help desk and asset management software.

Read More »
Security Flaw Found in ManageEngine

FBI & CISA Warning: ManageEngine Flaw Poses Serious Risk

APT Actors Exploit Vulnerability in ManageEngine ADSelfService Plus Reports confirm a critical security vulnerability in ManageEngine ADSelfService Plus, a self-service password management and single sign-on (SSO) tool for Active Directory environments, is actively being exploited. This newly discovered vulnerability, CVE-2021-40539, presents a critical authentication bypass risk that affects REST API

Read More »
Fortinet VPN Password Leak

Credentials for Nearly 500,000 Fortinet VPN Users Leaked

Hackers Leak Passwords for Fortinet VPN Servers A list with nearly half a million Fortinet VPN user credentials, allegedly scraped from unprotected devices, is now being shared on hacker forums across the dark web. On Tuesday, a threat actor known as “Orange”, thought to be a member of the popular

Read More »