Infrastructure Security

Microsoft: Threat Actors Exploiting Unpatched Windows Zerologon Flaw

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging organizations to review a Microsoft alert, as threat actors, including...

NIST Shares Draft PNT Data Service Profile for Cybersecurity Framework

by Jessica Davis

NIST recently released a draft profile for technology leveraging positioning, navigation, and timing (PNT) data, such as the Global Positioning System (GPS), meant...

NSA Warns Chinese Nation-State Actors Exploiting Vulnerabilities

by Jessica Davis

Chinese nation-state actors are actively scanning for and exploiting 25 common vulnerabilities and exposures (CVEs), which enabled multiple successful hacks on a range of victims, according to an...

DOJ Indicts Russian Hackers Behind 2017 NotPetya Malware Attack

by Jessica Davis

The Department of Justice announced the indictment of six Russian-backed hackers behind the global 2017 NotPetya malware attack. Though the cyberattack began on a...

Proof-of-Concept Prompts Alert on SharePoint Remote Execution Flaw

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency is urging organizations to review a UK National Cyber Security Centre (NCSC) alert for a remote code execution...

CISA Urges Patch of Windows Remote Code Execution TCP/IP Flaw, DoS Risk

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency urged all organizations to apply the patch for a remote code execution (RCE) vulnerability...

FBI, CISA Warn APT Hackers Chaining Vulnerabilities in Cyberattacks

by Jessica Davis

Advanced persistent threat (APT) hackers are targeting government networks, critical infrastructure, and election organizations by chaining vulnerabilities – a method of exploiting multiple...

Report: 72% Orgs Faced Increase in IoT, Endpoint Security Incidents

by Jessica Davis

Two-thirds of organizations saw an increase in the number of IoT and endpoint security incidents in the last year, with US cybersecurity decision makers naming malware, insecure networks, and remote...

61% Microsoft Exchange Servers Are Unpatched, Vulnerable to Attack

by Jessica Davis

The majority of Microsoft Exchange Servers have yet to be updated with a patch for a critical memory corruption vulnerability reported earlier this year, according to Rapid7. These...

CISA: Hackers Exploiting Unpatched Microsoft NetLogon Vulnerability

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency has urged all organizations to apply the partial patch and to implement mitigation methods for a...

Exploit Code Prompts CISA Alert to Microsoft Netlogon Vulnerability

by Jessica Davis

A recent public exploit for an elevation of privilege vulnerability found in Microsoft’s Netlogon will make unpatched systems a prime target for cybercriminals, according to a recent...

Iranian Hackers Targeting, Exploiting VPN Flaws of US Healthcare, IT Orgs

by Jessica Davis

Hackers with ties to Iran are exploiting flaws found in commonly used Virtual Private Networks (VPNs) across a range of federal agencies and businesses, including those in the healthcare...

5 Top Critical Vulnerabilities In Need of Patch, Software Update

by Jessica Davis

The healthcare sector has remained a crucial target for hackers over the course of the last five years. But despite a heavy reliance upon legacy technologies, industry stakeholders have...

Brute-Force P2P Botnet Targeting SSH Servers of Medical Centers, Banks

by Jessica Davis

Guardicore researchers are warning organizations of a sophisticated peer-to-peer botnet, which has been actively breaching SSH servers since January 2020. Known as FritzFrog,...

Citrix Urges Patch of Critical XenMobile Server Vulnerabilities

by Jessica Davis

Citrix is urging organizations to apply a patch for two critical vulnerabilities found in its XenMobile Server, a mobile device management platform, as hackers will likely quickly move to...

Microsoft Patches Remote Execution, Spoofing Flaws Under Active Exploit

by Jessica Davis

The Department of Homeland Security Cybersecurity and Infrastructure Security Agency alerted to two software updates from Microsoft. The latest patch addresses both a spoofing vulnerability...

NIST Shares Final Zero Trust Architecture Strategies, Guidance

by Jessica Davis

NIST unveiled the final version of its Zero Trust Architecture publication, which sheds light on the enterprise security model and provides private sector organizations a road map for...

Hacker Leaks 900 Enterprise VPN Server Passwords on Dark Web

by Jessica Davis

The usernames and passwords, as well as IP addresses, from more than 900 Pulse Secure Virtual Private Network enterprise servers were posted in plain text on the dark web by a Russian-speaking...

FBI: Operating Windows 7 Increases Cyber Risk to Network Infrastructure

by Jessica Davis

Organizations continuing to operate with Microsoft Windows 7 platforms on the network infrastructure are at an increased risk of cyberattack, according to a private industry notification from the...

The Risk of Nation-State Hackers, Government-Controlled Health Data

by Jessica Davis

The COVID-19 pandemic has driven a rise in targeted, sophisticated cyberattacks designed to take advantage of an increasingly connected environment. In healthcare, it’s led to a rise in...