Why are software updates and system maintenance so important?
by Tina Siering
Many of the current malware threats exploit vulnerabilities in operating systems and deployed software to compromise systems. As soon as they are known, the manufacturers patch the entry points as part of updates - i.e., they close them with minor or major adjustments to the architecture. "A software update is available": Surely you are also familiar with this message that pops up on the screen at regular intervals. This article shows why you should not simply click away from this message, but rather treat it as a top priority.
Read more … Why are software updates and system maintenance so important?
Borat RAT - Malicious malicious code in a triple pack
by Tina Siering
Borat, the whimsical fictional character of actor Sacha Baron Cohen, is known for absurd jokes, hilarious entertainment and, of course, the iconic neon green mankini. However, anything but funny is a new malware called Borat RAT. The Remote Access Trojan (RAT) is increasingly spreading around the world and is considered particularly treacherous and dangerous among security experts due to its combination of RAT, spyware and ransomware. In this article, learn how criminals are using Borat RAT, what purposes the malware serves, and how organizations can protect themselves from the new malware through incident response readiness and managed detection and response (MDR) solutions.
Read more … Borat RAT - Malicious malicious code in a triple pack
Dark Utilities: Platform offers Command&Control as a Service
by Tina Siering
The use of cloud services has been commonplace for companies and private users for several years. The cloud simplifies and accelerates data exchange, makes information available worldwide, regardless of device, and enables modern, location-independent work. Many service business models are also based on data exchange via the cloud or via platforms that can be accessed via the Internet. Various "as-a-service" services offer immediate access to software via practical subscription models, in many cases making the purchase of hardware superfluous and relieving companies of resource-intensive care and maintenance work. Cybercriminals have also discovered the many advantages of this type of platform for themselves. With the "Dark Utilities" service, a platform is now available that enables cyberattacks at low cost, with outsourced development effort and without the need for in-house server infrastructure. In this article, learn how Dark Utilities works, what the dangers are, and how you can protect yourself and your company from the new, dark business model.
Read more … Dark Utilities: Platform offers Command&Control as a Service
Six golden rules for enhanced email security
by Tina Siering
The most widely used method of communication in organizations and companies is still e-mail. It is therefore not surprising that more than 90 percent of successful cyber attacks start with a supposedly harmless e-mail. In almost all cases, the weak point is invariably the same: the human being. Fake sender identities increase the chances that malware attachments will be opened. The perfidious game of the CEO-Frauds is so successful because the attackers already familiarize themselves in advance with the company's circumstances in great detail. With the following six rules, you can effectively protect yourself from the threat of ransomware, phishing, virus-infected attachments and the like.
What do the ancient Romans, Leonardo da Vinci and 21st century cybercriminals have in common? The answer is "steganography," the hiding of secret information in an innocuous, inconspicuous environment. The ancient technique of steganography is in fact currently one of the greatest dangers that can lurk for users during digital data transmission. Cyber criminals have currently refined the techniques of steganography to such an extent that malware can hardly be detected by conventional security technology. In this article, you will find out what exactly this term means, what tricks hackers can use to infiltrate malware onto your computer, and how you can protect yourself against this undetected danger.
Read more … Steganography: How secret code in media files becomes a threat to IT security
LastPass confirms security incident
by Tina Siering
Back in mid-August 2022, unknown attackers gained access to servers of the password manager provider LastPass and were able to successfully copy internal data.
The company has now acknowledged the incident in a blog post and assured: Master passwords and user data in the encrypted password vault should not be affected. What users of the service should consider, however, can be read in the short blog post on the topic.
Vulnerabilities in Apple's WebKit and the operating system kernel allow attackers to execute malicious code on iPhones, iPads and Macs and significantly expand privileges. Users of affected devices should immediately install the manufacturer's emergency update.
Read more … Apple fixes two critical zero-day vulnerabilities - updates strongly recommended
Security risk IoT devices - the underestimated danger
by Tina Siering
The abbreviation IoT stands for "Internet of Things" and refers to the increasing networking between "smart" devices and machines both with each other and with the Internet. To achieve this, the devices are equipped with network cards (LAN or WLAN). Often used for cost-saving reasons, smart building objects found in companies, such as fire detectors or IP cameras, already form the standard today. However, when acquiring IoT devices, many organisations are not aware that they entail major risks for IT security. To protect themselves from data espionage, operational failures and network compromises, companies and organisations should take effective security precautions.
Read more … Security risk IoT devices - the underestimated danger
How hackers are circumventing multi-factor authentication - and organizations should upgrade now
by Tina Siering
The use of multi-factor authentication (MFA) significantly increases the level of access security compared to the simple use of username and password and makes it more difficult for cybercriminals to access sensitive data. With MFA, two or more credentials are required to gain access to a system, for example, via additional confirmation of login via personal smartphone. Multi-factor authentication actually adds a significant amount of security - but that the process protects one hundred percent against successful account takeovers is a fallacy! Learn in this article which seven tactics are used by cybercriminals to circumvent MFA.
If you are interested in the extremely exciting tasks of white hat hackers, are thinking of pursuing a career in the field, or simply want to learn more about the methods and techniques of ethical hackers, we recommend the top 6 reading tips from our IT security consultants.
Read more … Books about ethical hacking - The Top 6 of our IT Security Consultants