Blog
An overview of the OSI model and its security threats
Fri, 05/05/2023
The Open Systems Interconnection (OSI) model is a conceptual framework developed by the International Standards Organization (ISO). It has been in use for over 40 years, and is cited in every computer network book. It is also a favorite resource for just about every cybersecurity exam. The OSI model is represented in seven layers that help us...
Blog
Patch now! The Mirai IoT botnet is exploiting TP-Link routers
By Graham Cluley on Thu, 05/04/2023
Businesses should patch their TP-Link routers as soon as possible, after the revelation that a legendary IoT botnet is targeting them for recruitment.
The notorious Mirai botnet, which hijacks control of vulnerable IoT devices, is now exploiting TP-Link Archer AX21 routers to launch distributed denial-of-service (DDoS) attacks.
The warning comes...
Blog
Cybersecurity – Change is coming and that’s a good thing
By Guest Authors on Thu, 05/04/2023
“The cyber economy is the economy”
Those words were spoken by the US National Security Advisor way back in 2005, and it is remarkable to see how prescient they were. The economy is not only supported by the cyber world, but that world is entirely data driven. Data has become a primary focus, not just for regulatory fodder, but for business survival...
Blog
Cybersecurity in the Cloud: The Challenging Hurdles It Has To Overcome
By Guest Authors on Wed, 05/03/2023
Cloud Security Challenges
Organizations embracing cloud environments must understand that cloud applications and services have become popular targets for cybercriminals. A few notable and inherent risks with cloud deployments include:
API Vulnerabilities
Unfortunately, API exploits are on the rise, costing organizations dearly. Whether it’s...
Blog
Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware
By Graham Cluley on Thu, 04/27/2023
Iranian state-sponsored hacking group Charming Kitten has been named as the group responsible for a new wave of attacks targeting critical infrastructure in the United States and elsewhere.
The group (who are also known to security researchers by a wide variety of other names including Mint Sandstorm, Phosphorous, Newscaster, and APT35) has been...
Blog
Spring is the Perfect Season for a Digital Declutter
By Editorial Staff on Mon, 04/24/2023
Spring is here! Who’s up for some digital spring cleaning? Digital de-cluttering helps you organize your life and has the bonus of reducing your vulnerability to common threats. But knowing where to begin can be hard; most of us leave a larger digital footprint than we realize. I have created a checklist to help you clear away the clutter and reap...
Blog
The K-12 Report: A Cybersecurity Assessment of the 2021-2022 School Year
By Katrina Thompson on Mon, 04/24/2023
The K-12 Report breaks down the cyber risks faced by public schools across the country and is sponsored by the CIS (Center for Internet Security) and the MS-ISAC (Multi-State Information Sharing & Analysis Center).
Published “to prepare K-12 leaders with the information to make informed decisions around cyber risk”, the report provides a data...
Blog
US charges three men with six million dollar business email compromise plot
By Graham Cluley on Thu, 04/20/2023
Three Nigerian nationals face charges in a US federal court related to a business email compromise (BEC) scam that is said to have stolen more than US $6 million from victims.
29-year-old Kosi Goodness Simon-Ebo was extradited from Canada to the United States earlier this month, according to a Department of Justice press release, and will appear...
Blog
FTC accuses payments firm of knowingly assisting tech support scammers
By Graham Cluley on Thu, 04/20/2023
Multinational payment processing firm Nexway has been rapped across the knuckles by the US authorities, who claim that the firm knowingly processed fraudulent credit card payments on behalf of tech support scammers.
A Federal Trade Commission (FTC) complaint argues that Nexway and its subsidiaries broke the law by helping scammers cheat money from unsuspecting consumers.
Victims were tricked...
Blog
EPA Has ‘New Rules’ for Protecting Public Drinking Water
By Katrina Thompson on Wed, 04/19/2023
The EPA isn't mincing words when it comes to protecting public drinking water. Earlier this month they released a memorandum putting specifics into the general advice to maintain cybersecurity at public water systems (PWSs). Per the report, “[The] EPA clarifies with this memorandum that states must evaluate the cybersecurity of operational technology...
Blog
A Day in the Life of a SOC Team
By Fortra Staff on Tue, 04/18/2023
This piece was originally published on Fortra’s AlertLogic.com Blog.
Managed detection and response (MDR) would be nothing without a SOC (security operations center). They’re on the frontline of our clients’ defenses — a living, breathing layer of intelligence and protection to complement our automated cybersecurity features. These are the people...
Blog
What Is Microsegmentation and 5 Compelling Security Use Cases
By Guest Authors on Mon, 04/17/2023
What Is Microsegmentation?
Microsegmentation is a security technique that partitions a network into small, isolated sections to reduce the attack surface and reduce an organizations risk. Each microsegment is typically defined by specific security policies, accessible only to authorized users and devices.
Microsegmentation is often seen as a more...
Blog
Microsoft warns accounting firms of targeted attacks as Tax Day approaches
By Graham Cluley on Fri, 04/14/2023
Accountants are being warned to be on their guard from malicious hackers, as cybercriminals exploit the rush to prepare tax returns for clients before the deadline of US Tax Day.
US Tax Day, which falls on Tuesday April 18 this year, is the day on which income tax returns for individuals are due to be submitted to the government.
Inevitably it's a...
Blog
Glamourizing fraudsters hurts victims of fraud, and society
By Martina Dove on Fri, 04/14/2023
We seem to be fascinated by fraudsters, and recent documentaries prove this. The documentary landscape is populated with many fraud-centered stories, such as The Tinder Swindler, Fyre, The Con, Fake Heiress, The Inventor, and many others. Some have even been made into series, such as the story of Elisabeth Holmes in The Dropout, and the story of...
Blog
The U.S. Army Is Revamping Its Cybersecurity Approach
By Guest Authors on Thu, 04/13/2023
Military cybersecurity operations are shifting to a digital battlefield, where tools and technology work to save lives and increase efficiency. With these advancements comes the increased need for resilient measures to meet the needs of soldiers, leadership, and civilians alike.
A ransomware attack rocked the U.S. Marshals Service in February 2023,...
Blog
Tripwire’s Vulnerability Exposure Research Team (VERT): What you need to know
By Joe Pettit on Thu, 04/13/2023
Each month, at the State of Security, we publish a range of content provided by VERT. Whether it’s a round-up of all the latest cybersecurity news, our Patch Priority Index that helps guide administrators on what they should be patching , a book review, general musings from the team, or most notability our Patch Tuesday round-up. VERT is helping...
Blog
CISA Publishes Advisory on Improving Network Monitoring and Hardening
By Anastasios Arampatzis on Wed, 04/12/2023
CISA released in late February a cybersecurity advisory on the key findings from a recent Cybersecurity and Infrastructure Security Agency (CISA) red team assessment to provide organizations recommendations for improving their cyber posture. According to the Agency, the necessary actions to harden their environments include monitoring network...