top of page


Apache Foundation software again under scrutiny
Another critical vulnerability in Apache Foundation software (CVE-2022-42889) reminds users of last year's Log4Shell catastrophic blunder.
Oct 19, 2022


"Ransom Cartel" ransomware-as-a-service
A detailed look into the relatively new "Ransom Cartel" ransomware reveals the range of techniques used by threat actors today.
Oct 17, 2022


Active Directory in the crosshairs
Attacker techniques are leveraging Microsoft Active Directory as the enabler for ransomware spread.
Oct 13, 2022


Exchange admins still waiting for zero-day patch
Microsoft Patch Tuesday release for October 2022 documents 85 fixed vulnerabilities. Exchange users left waiting for zero-day patch.
Oct 11, 2022


Beyond phishing: targeting Microsoft public-facing services
Beyond phishing, how are hackers infiltrating networks? CISA offers some clues.
Oct 10, 2022


Password rotation: an obsolete practice
Mandatory password resets are still being observed in many organizations, even though the practice can now decrease security posture.
Oct 7, 2022


Managed Detection and Response (MDR) - a growing trend
The explosion of security related events is saturating the ability to analyze and respond. It is time to outsource.
Oct 4, 2022


Vmware and Microsoft Exchange: running on-prem is getting difficult
The emergence of a Microsoft Exchange flaw as well as Vmware malware shows how difficult it is becoming to run on-prem infrastructure.
Oct 3, 2022


Searching for unsigned DLLs as indicator of compromise
Once an attacker has gained initial access to a network (usually via phishing), it becomes crucial to have operational visibility.
Sep 30, 2022
bottom of page
