Vulnerability Management – Just Do It!

Abilities Identify Security issues based on analysis of vulnerabilities – apply cybersecurity and privacy principles to organizational requirements Knowledge Application vulnerabilities, data backup and recovery, host/network access control mechanisms, system administration, network, and operating system hardening techniques. Skills Detecting host and network intrusions Conduct vulnerability scans and recognize vulnerabilities in security systems. Tasks Keep up … Read more

APC UPS (Power Supplies) 3 Critical Vulnerabilities

Do you have an APC UPS(Uninterruptible Power Supply)? (Image above from Armis Research) I do not know which devices actually have these vulnerabilities, assuming Armis research is correct then it may be all devices that connect to the cloud. Armis Research found some vulnerabilities: Armis has discovered a set of three critical vulnerabilities in APC … Read more

Global Cyberwar: What Does That Look Like?

First we have to discuss – what is a “Global Cyberwar”? It has to do with the current conflict with Russia — Ukraine. In this image(Feb28 and Mar1) there is some interesting information which is from SecurityWeek magazine : The groups and what country they support (Ukraine, UNK (Unknown?), or Russia).  Where they will congregate … Read more

What Are The “Good” Hackers Up To?

The Zero Day Initiative has a blog post to discuss the Top 5 Bugs submitted in 2021. In essence the good hackers try to find bugs or problems in software which would allow an attacker to perform functions that should not be done. An example from the Pwn2Own 2021 blog post: Hi, I am Orange … Read more

Unpatched Exchange Server Sends Phishing Emails That Look Legitimate

Certitute has a story that shows what happens when you decide for one reason or another not to update your Exchange server Apparently somebody did not update the Exchange server (which runs the email for the company). So when the system is not updated it becomes vulnerable of various vulnerabilities. From the story: The IIS … Read more