Writer of all things cybersecurity
Writer of all things cybersecurity
Posts
Writer of all things cybersecurity
Writer of all things cybersecurity
Testing testing. Is this place still a thing? 👋🏽
Writer of all things cybersecurity
“Without developers managing the Boa web server, its known vulnerabilities could allow attackers to silently gain access to networks by collecting information from files."
Discontinued Web Server Poses IoT Security Risks
https://duo.com/decipher/discontinued-boa-web-server-reveals-iot-supply-chain-risks
Writer of all things cybersecurity
Updated CISA Infrastructure Resilience Planning Framework includes new tool for identifying critical infrastructure and other resources.
https://www.cisa.gov/news/2022/11/22/cisa-updates-infrastructure-resilience-planning-framework
Writer of all things cybersecurity
"If the acquired company has poor security, it could be an easy jumping off point to the parent company for much more valuable information.”
Visibility is key for #security in M&A - However, deals are often fast-moving, making due diligence difficult
https://duo.com/decipher/complex-m-and-a-deals-can-leave-security-lost-in-translation
Writer of all things cybersecurity
"It's a big shift in the way you build systems and you know there's no perfect answer here. The best you can really do is have multiple people look at something in those situations because at the end of the day you are trusting people."
Writer of all things cybersecurity
A threat actor targeted the legal/retail sectors in callback phishing attacks that cost victims thousands:
-Callback phishing attack requires significant investment, including setting up fake call centers/ unique infrastructure
-But the lack of malware in the original phishing email/ the abuse of legitimate tools make the attack harder to detect
“By design, this style of social engineering attack leaves very few artifacts because of the use of legit trusted tech tools to carry out attacks."
https://duo.com/decipher/threat-actors-find-success-in-callback-phishing-attacks
Writer of all things cybersecurity
The Hive #ransomware has victimized 1,300 companies globally as of November, in particular targeting #healthcare sector organizations, according to U.S. federal agencies in a new advisory.
https://duo.com/decipher/hive-ransomware-attacks-target-fortios-microsoft-exchange-flaws
Writer of all things cybersecurity
@howelloneill@infosec.exchange "risks of being used improperly" seems key