Guide: Scale or Fail — Why MSSPs Need Multitenant Security Solutions

The Hacker News-- Managed Security Services Providers (MSSPs) have it rough. They have the burden of protecting their client organizations from cyberattacks, with clients from different industries, different security stacks, and different support requirements. And everything is in a constant state of flux. MSSPs are turning to multitenant solutions to help reduce the complexity of … Continue reading Guide: Scale or Fail — Why MSSPs Need Multitenant Security Solutions

Microsoft Releases Patches For Critical Windows TCP/IP and Other Bugs

The Hacker News-- Microsoft on Tuesday issued fixes for 87 newly discovered security vulnerabilities as part of its October 2020 Patch Tuesday, including two critical remote code execution (RCE) flaws in Windows TCP/IP stack and Microsoft Outlook. The flaws, 11 of which are categorized as Critical, 75 are ranked Important, and one is classified Moderate in … Continue reading Microsoft Releases Patches For Critical Windows TCP/IP and Other Bugs

Microsoft and Other Tech Companies Take Down TrickBot Botnet

The Hacker News-- Days after the US Government took steps to disrupt the notorious TrickBot botnet, a group of cybersecurity and tech companies has detailed a separate coordinated effort to take down the malware's back-end infrastructure. The joint collaboration, which involved Microsoft's Digital Crimes Unit, Lumen's Black Lotus Labs, ESET, Financial Services Information Sharing and … Continue reading Microsoft and Other Tech Companies Take Down TrickBot Botnet

A Self-Service Password Reset Project Can Be Quick Win For IT

The Hacker News-- Since the beginning of this year, organizations' IT staff have faced numerous challenges and an increased workload as a result of the global pandemic and shift to a mainly remote workforce. Supporting end-users that are now working from home has introduced new challenges in troubleshooting since it isn’t as simple as visiting … Continue reading A Self-Service Password Reset Project Can Be Quick Win For IT

Watch Out — Microsoft Warns Android Users About A New Ransomware

The Hacker News-- Microsoft has warned about a new strain of mobile ransomware that takes advantage of incoming call notifications and Android's Home button to lock the device behind a ransom note. The findings concern a variant of a known Android ransomware family dubbed "MalLocker.B" which has now resurfaced with new techniques, including a novel … Continue reading Watch Out — Microsoft Warns Android Users About A New Ransomware

55 New Security Flaws Reported in Apple Software and Services

The Hacker News-- A team of five security researchers analyzed several Apple online services for three months and found as many as 55 vulnerabilities, 11 of which are critical in severity. The flaws — including 29 high severity, 13 medium severity, and 2 low severity vulnerabilities — could have allowed an attacker to "fully compromise … Continue reading 55 New Security Flaws Reported in Apple Software and Services

Researchers Find Vulnerabilities in Microsoft Azure Cloud Service

The Hacker News-- As businesses are increasingly migrating to the cloud, securing the infrastructure has never been more important. Now according to the latest research, two security flaws in Microsoft's Azure App Services could have enabled a bad actor to carry out server-side request forgery (SSRF) attacks or execute arbitrary code and take over the … Continue reading Researchers Find Vulnerabilities in Microsoft Azure Cloud Service

A Handy Guide for Choosing a Managed Detection & Response (MDR) Service

The Hacker News-- Every company needs help with cybersecurity. No CISO ever said, "I have everything I need and am fully confident that our organization is fully protected against breaches." This is especially true for small and mid-sized enterprises that don't have the luxury of enormous cybersecurity budgets and a deep bench of cybersecurity experts. … Continue reading A Handy Guide for Choosing a Managed Detection & Response (MDR) Service

ALERT! Hackers targeting IoT devices with a new P2P botnet malware

The Hacker News-- Cybersecurity researchers have taken the wraps off a new botnet hijacking Internet-connected smart devices in the wild to perform nefarious tasks, mostly DDoS attacks, and illicit cryptocurrency coin mining. Discovered by Qihoo 360's Netlab security team, the HEH Botnet — written in Go language and armed with a proprietary peer-to-peer (P2P) protocol, spreads via … Continue reading ALERT! Hackers targeting IoT devices with a new P2P botnet malware

New ‘MosaicRegressor’ UEFI Bootkit Malware Found Active in the Wild

The Hacker News-- Cybersecurity researchers have spotted a rare kind of potentially dangerous malware that targets a machine's booting process to drop persistent malware. The campaign involved the use of a compromised UEFI (or Unified Extensible Firmware Interface) containing a malicious implant, making it the second known public case where a UEFI rootkit has been used in the wild. … Continue reading New ‘MosaicRegressor’ UEFI Bootkit Malware Found Active in the Wild