Social Justice: a global perspective
Today, we commemorate World Day of Social Justice and honor those across the globe who stand for the equitable access to opportunities within societies where individuals’ rights are recognized and protected. I have the distinct honor of leading the Social Justice work here at Cisco (even writing that gives me chills). I am as proud […]
A fundamental guide to endpoint security
Anyone that utilizes technology in their daily lives understands that it is ever-changing, and the sentiment is especially true within the cybersecurity industry. Adversaries continue to evolve with new tactics to bypass defenses, so it is necessary that the methods of detecting and preventing these threats do so at an even more rapid pace. However, […]
VMware urges admins to remove deprecated, vulnerable auth plug-in
VMware urged admins today to remove a discontinued authentication plugin exposed to authentication relay and session hijack attacks in Windows domain environments via two security vulnerabilities left unpatched. The vulnerable VMware Enhanced Authentication Plug-in (EAP) enables seamless login to vSphere’s management interfaces via integrated Windows Authentication and Windows-based smart card functionality on Windows client systems. VMware […]
New Migo Malware Targeting Redis Servers for Cryptocurrency Mining
Feb 20, 2024NewsroomServer Security / Cryptojacking A novel malware campaign has been observed targeting Redis servers for initial access with the ultimate goal of mining cryptocurrency on compromised Linux hosts. “This particular campaign involves the use of a number of novel system weakening techniques against the data store itself,” Cado security researcher Matt Muir said […]
‘KeyTrap’ DNS Bug Threatens Widespread Internet Outages
Although it’s been sitting there since 2000, researchers were just recently able to suss out a fundamental design flaw in a Domain Name System (DNS) security extension, which under certain circumstances could be exploited to take down wide expanses of the Internet. DNS servers translate website URLs into IP addresses and, mostly invisibly, carry all […]
Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll Affiliates – Krebs on Security
U.S. and U.K. authorities have seized the darknet websites run by LockBit, a prolific and destructive ransomware group that has claimed more than 2,000 victims worldwide and extorted over $120 million in payments. Instead of listing data stolen from ransomware victims who didn’t pay, LockBit’s victim shaming website now offers free recovery tools, as well […]
LogMeOnce vs Bitwarden (2024): Which One is Better?
If you’re looking to compare LogMeOnce and Bitwarden, you know the importance of using a password manager to protect your online accounts. LogMeOnce packs its password management software with a suite of features like encrypted note-taking, activity logging and a sharing center. And, Bitwarden is known for its bang-for-buck pricing and secure, open-source platform. In […]