Blog

Sticky Post

VPNs and a False Sense of Security

VPNs (Virtual Private Networks) in theory provide anonymity and secure passage to your online destination. What we’ve increasingly seen is VPN companies go through their own security breaches and exposing users internet logs. Even when a VPN provider claims that it keeps no logs, it can simply be marketing in a way where that might […]

Read More
tips for Black Friday
Sticky Post

Black Friday Cyber Shopping Safety tips

🎁 Tips for Safe Online Holiday shopping. 🛍 In 2018, 8% of consumers surveyed said they were victims of Identity theft during the holiday season. As black Friday approaches 56% of holiday shoppers plan to make purchases online in 2019. Before you shop this holiday season, we have prepared a list of cyber tips for […]

Read More
Sticky Post

Louisiana government computers knocked out after ransomware attack

(Reuters) – Louisiana state government computers were knocked out following a ransomware attack, the governor said on Monday, as results from the close gubernatorial election in the southern state await certification. Many state agencies had their servers taken down in response to the attack, Governor John Bel Edwards said in a series of messages posted […]

Read More
Sticky Post

Thousands Of Disney+ Accounts Are Up For Sale On Hacking Forums

Disney’s hotly-anticipated streaming service Disney+ finally launched this week. Despite being open to the public for just a few days, hackers have already hijacked thousands of accounts and put them up for sale on the Dark Web. Reporting for ZDNet, Catalin Cimpanu discovered several listings for Disney+ accounts on different underground hacking forums. The going rate for […]

Read More
Sticky Post

Quiksilver and Billabong Affected by Ransomware Attack

Action sports giant Boardriders was hit by a ransomware attack that affected some of its subsidiaries, including Quiksilver and Billabong, and forced the company to shut down computing systems all over the world. Boardriders has around 10,000 employees from all over the world and its Quiksilver, Billabong, ROXY, RVCA, DC Shoes, and Element brands are sold in over 110 […]

Read More
Sticky Post

‘What a mess’: McDonald’s customers frustrated as ‘Hamburglar’ hacks more app accounts Social Sharing

The so-called Hamburglar is still at large, hacking customers’ McDonald’s app accounts and ordering food on their dime. For some victims, their troubles didn’t end there as they were unhappy with how McDonald’s handled their cases. “What a mess,” said Deborah Kelly of Peterborough, Ont. She’s unimpressed after the fast-food giant mistakenly blamed mystery charges on […]

Read More
Sticky Post

Bed Bath & Beyond Discloses Breach

Home retailer Bed Bath & Beyond is the latest company to be hacked. Late Tuesday, the company said email and password information were acquired by an outside source and that less than 1 percent of online customer accounts were compromised. Additionally, no online customers’ payment cards were impacted and notifications have been to select customers. The date of […]

Read More
Sticky Post

CenturyLink customer details exposed online, 2.8 million records leaked

A database of 2.8m records containing sensitive information regarding hundreds of thousands of CenturyLink’s customers was left open online for anyone with internet access to see. The records making up the database were logs from a third party notification platform used by CenturyLink. They included multiple pieces of personal information including name, email address, phone […]

Read More
Sticky Post

Philly health department website exposed the names of thousands of people with hepatitis

A public-data tool built by the Philadelphia Department of Public Health to track the prevalence of hepatitis infections left individuals’ health records accessible, compromising the names, addresses, Social Security numbers, and intimate health records of thousands of people receiving medical care in Philadelphia. The department learned of the breach Friday when an Inquirer reporter discovered […]

Read More
Sticky Post

Major Attacks That Hit the Manufacturing Sector in 2019

The primary contributor to the ransomware attacks in the manufacturing sector includes LockerGoga ransomware, followed by WannaCry, GandCrab, and BitPayment ransomware. LockerGoga ransomware targeted several industrial and manufacturing companies including Altran Technologies, Norsk Hydro, Hexion, and Momentive. Context The manufacturing sector has been continuously facing the brunt of cyberattacks in recent years. Especially, ransomware attacks […]

Read More
Sticky Post

Cancer Treatment Centers of America in Atlanta discloses three phishing incidents in 6 months

The Cancer Treatment Centers of America (CTCA) has had its name cross my desk a lot this past year. And that’s not a good thing. There have been five Cancer Treatment Centers of America breach notices that have been publicly disclosed since November 2018. Three of them involved the Southeastern Regional Medical Center in Atlanta, Georgia. In […]

Read More
Sticky Post

DoorDash Suffers Major Data Breach Impacting Around 4.9 Million Individuals

The organization became aware of the incident earlier this month and immediately launched an investigation. The breach occurred due to unauthorized third-party access. DoorDash, a food delivery platform, has again come under fire for a major data breach that occurred on May 4, 2019. The firm has released a notification about the breach that impacted […]

Read More
Sticky Post

Threat Level Increases in 2019 as Several Cities and Counties in US Respond to Ransomware Attacks by Paying Hefty Ransom

More than 225 US mayors have signed a resolution to oppose the payment to ransomware attackers. The resolution was passed at the US Conference of Mayors Annual meeting which took place in June and July this year. Ransomware attacks are burgeoning across the cities and counties in the US. According to The U.S. Conference of […]

Read More
Sticky Post

YouTube Creators From Auto Community Targeted in Coordinated Attack Campaign

The YouTube account hacks are the result of a coordinated campaign that targeted YouTube users with phishing emails, pointing them to phishing sites, where hackers harvested their login account credentials. Some of the hacked YouTube channels in the auto community include Built, Troy Sowers, MaxtChekVids, PURE Function, and Musafir. What is the issue? Several high-profile […]

Read More
Sticky Post

Two years later, hackers are still breaching local government payment portals

Two years after hackers first started targeting local government payment portals, attacks are still going on, with eight cities having had their Click2Gov payment portals compromised in the last month alone, security researchers from Gemini Advisory have revealed in a report shared with ZDNet today. These new hacks have allowed hackers to get their hands […]

Read More
Sticky Post

Zscaler Extends Cloud Capabilities to Deliver Secure Access to B2B Applications

Provides business customers easy access to apps while minimizing the attack surface Zscaler, Inc., the leader in cloud security, today announced Zscaler B2B, a new innovation that solves a long-standing problem businesses face when exposing their applications to their customers, suppliers and manufacturers. Zscaler™ B2B is a unique solution that reduces the attack surface introduced […]

Read More
Sticky Post

Unsecured server exposes 419 million records of phone numbers linked to Facebook accounts

The exposed records included users’ unique Facebook ID and their associated phone numbers. A spokesperson for Facebook said that the exposed records are old and had been scraped before Facebook disabled access to user phone numbers. What’s the matter? Security researcher Sanyam Jain uncovered an unguarded server that was left publicly accessible without any password […]

Read More
Sticky Post

Malicious websites were used to secretly hack into iPhones for years, says Google

Security researchers at Google say they’ve found a number of malicious websites which, when visited, could quietly hack into a victim’s iPhone by exploiting a set of previously undisclosed software flaws. Google’s Project Zero said in a deep-dive blog post published late on Thursday that the websites were visited thousands of times per week by unsuspecting victims, […]

Read More
Sticky Post

Mastercard’s Priceless Specials loyalty program gets breached exposing customer information

The exposed information includes customers’ names, dates of birth, gender, email addresses, phone numbers, home addresses, payment card numbers, and the time of first registration with Priceless Specials. Mastercard suspended the German Priceless Specials loyalty program and took down its website, leaving a message that says “This issue has no connection to MasterCard’s payment network.” […]

Read More
Sticky Post

Attackers Demand $2.5 Million Ransom After Coordinated Ransomware Attacks on Texas Government Entities

Two of the impacted municipalities, the City of Borger, and the City of Keene, have publicly disclosed that they’ve been impacted by the coordinated ransomware attack. Keene Mayor Gary Heinrich said that the threat actor infiltrated into the city’s IT software, which is managed by a managed service provider (MSP). The attacker who hit over […]

Read More
Sticky Post

MoviePass customer credit card records found exposed on unprotected servers

The exposed records consisted of more than 160 million personal credit card details and over 50,000 MoviePass customers’ card numbers. Personal credit card records and MoviePass debit card details belonging to customers were left exposed. Thousands of personal credit-card numbers and customer card information belonging to the popular movie-ticket subscription service, MoviePass was found unprotected […]

Read More
Sticky Post

BEWARE, INSTAGRAM USERS.

A new bug has infiltrated Instagram and spread like wildfire. It is a hack that has spread from user account to user account undetected so far.  Over this past weekend, I was using Instagram when I was direct messaged by a friend of mine with the message titled, “Lindsay, I made this for you.”  Underneath […]

Read More
Sticky Post

Credit Karma glitch exposed users to other people’s accounts

Users of credit monitoring site Credit Karma  have complained that they were served other people’s account information when they logged in. Many took to a Reddit thread and complained on Twitter about the apparent security lapse. “First time logging in it gave me my information, but as soon as I refreshed the screen, it gave me someone else’s info,” said one Reddit […]

Read More
Sticky Post

700K Guest Records Stolen in Choice Hotels Breach

Cybercriminals reportedly stole the information from an exposed MongoDB database on a third-party server. Hotel franchisor Choice Hotels has confirmed a breach in which attackers stole 700,000 guest records from a publicly available MongoDB database without a password or any authentication. The unsecured server, which the hotel chain says belonged to a third-party vendor, contained […]

Read More
Sticky Post

What are millennials looking for in the workplace?

The millennial generation has been the most difficult generation to understand to date. Previous generations struggle to understand what millennials look for in the workplace. So let me shed some light for those in this dilemma.  Millennials have been notorious for “dating jobs”, for those of you that need a definition, it’s jumping from organization […]

Read More
Sticky Post

​State Farm customer accounts breached in credential stuffing attack

Attackers used a list of usernames and passwords obtained via credential stuffing attack to access State Farm customers’ online accounts. The investigation revealed that attackers were able to confirm valid usernames and passwords for some online accounts, however, no personal information was accessed. What is the issue? Insurance company State Farm notified its customers that […]

Read More
Sticky Post

Threat Spotlight: Lateral Phishing

This Threat Spotlight was co- authored by Asaf Cidon and Grant Ho of the Barracuda Sentinel team. Account takeover continues to be one of the fastest growing email security threats, but attackers are starting to adapt, introducing new ways to exploit compromised accounts. Teaming up with leading researchers at UC Berkeley and UC San Diego, Barracuda […]

Read More
Sticky Post

Capital One data breach impacts 100 million Americans and 6 million Canadians

An unauthorized third-party accessed the information for 106 million people by exploiting a configuration vulnerability. The exposed information includes personal information, credit card data, transaction data, Social Security numbers, linked bank account numbers, and Social Insurance numbers of consumers and small businesses who applied for credit card products between 2005 and 2019. Capital One disclosed […]

Read More
Sticky Post

Okta Device Trust: Get the Most out of Integrating Identity + Endpoint Management

Written by: Teju ShyamsundarSenior Product Marketing Manager at Okta The current state of device based access control It’s no secret that devices have changed the way we work. Mobility has transformed the enterprise enough to redefine the term “mobile device.” With modern management techniques for mobile form factors as well as laptops and tablets, the […]

Read More
Sticky Post

Louisiana Governor declares emergency after a ransomware attack hits three schools

School systems in Monroe, Morehouse Parish, and Sabine Parish, were impacted by the ransomware attacks. The state has hired cybersecurity experts from the Louisiana National Guard, Louisiana State Police, and the Office of Technology Services in order to resolve and prevent cyberattacks. Louisiana Governor John Bel Edwards has issued an emergency declaration on July 24, […]

Read More
Sticky Post

Slack Resetting Thousands of User Passwords After Learning 2015 Breach Was Worse Than Previously Known

Slack is resetting roughly 100,000 user passwords for accounts that were active in 2015. The company has only recently learned that an old security breach from four years ago was perhaps worse than previously thought. The news, first reported by ZD Net and confirmed by Slack in an announcement on its website, will only affect about 1 […]

Read More
Sticky Post

Will “fake” clouds stall your enterprise cloud transformation?

“The cloud? Sure, we’re in the cloud. We ported our on-prem solution to a virtual machine.” Heard that from your network hardware vendor recently? Don’t blame Jane Salesperson. She’s been selling appliances for years. It’s what she knows. It’s what she’s commissioned on. For her, and for the appliance company for which she works, the cloud […]

Read More
Sticky Post

American Express Customers Targeted by Novel Phishing Attack

A phishing attack using a novel technique to steal credentials from American Express customers was recently found in an email inbox protected using Microsoft’s Office 365 Advanced Threat Protection (ATP) by Cofense Phishing Defense Center researchers. The phishing campaign targeted both corporate and consumer cardholders with phishing emails full of grammatical errors but with a small but […]

Read More
Sticky Post

Sprint says hackers breached customer accounts via Samsung website

US mobile network operator Sprint said hackers broke into an unknown number of customer accounts via the Samsung.com “add a line” website. “On June 22, Sprint was informed of unauthorized access to your Sprint account using your account credentials via the Samsung.com ‘add a line’ website,” Sprint said in a letter it is sending impacted customers. […]

Read More
Sticky Post

DNA Testing Company Vitagene Exposed Over 3,000 Patient Records Due to Misconfigured Database

The AWS database was exposed on the internet for several years until it was secured on July 1, 2019. The compromised data included users’ full names, birth dates, genetic health information, and other medical conditions. A misconfigured Amazon Web Services (AWS) database had left more than 3,000 client health reports exposed to the internet for […]

Read More
Sticky Post

Los Angeles County Department of Health Services suffers data breach compromising patient records

The data breach occurred after Nemadji Research Corporation, a contractor of the L.A. County Department of Health Services fell victim to a phishing attack in March 2019. The exposed data includes patient names, addresses, dates of birth, medical record numbers and Medi-Cal identification numbers. Almost 14,591 patients who received medical care through Los Angeles County’s […]

Read More
Sticky Post

Internal data of GE Aviation found in exposed Jenkins server

The server contained source code, passwords, configuration details, and other sensitive information related to GE Aviation’s internal infrastructure. It was one of the 5,495 publicly available Jenkins instances as indexed by Shodan. A publicly available Jenkins server of GE Aviation was found spilling sensitive data out in the open. Security researcher Bob Diachenko came across […]

Read More
Sticky Post

Attackers exploit flaw in 7-Eleven app to swindle over $500,000 from Japanese customers

Around 900 customers are said to have been targeted in the attack, who collectively lost around ¥55 million. The attackers exploited a security flaw in 7pay, a mobile payment app developed by 7-Eleven. Popular supermarket chain 7-Eleven has become the latest victim in a cyber attack. Attackers banked on a security flaw in 7-Eleven’s 7pay […]

Read More
Sticky Post

Ford, TD Bank Files Found Online in Cloud Data Exposure

(Bloomberg) — Attunity Ltd., a company that manages and safeguards data, left internal files exposed on the internet for clients including Ford Motor Co., and the Toronto-Dominion Bank, in the latest example of sensitive information being publicly accessible on the web.  The incident revealed passwords and network information about Attunity as well as emails and technology designs from some […]

Read More
Sticky Post

Security holes in EA Origin platform exposed 300 million gamers to account takeover attacks

The vulnerabilities in EA’s Origin platform could be exploited by abusing authentication tokens and related trust mechanisms. Origin is known for digital distribution of some of the popular video games published by EA. Origin, the digital distribution platform by video game company Electronic Arts (EA), was found containing numerous vulnerabilities that could have led to […]

Read More
Sticky Post

AGT Attends CudaCon

NASHVILLE, TN JUNE 20th 2019- Barracuda Networks, an industry leader in email security, held their annual CudaCon conference in Nashville Tennessee. It was a wonderful event with guest speakers including Microsoft. Forrester research has recognized Barracuda as a company who is bringing innovation to email security. In its guide for buyers considering email-security solutions, Forrester’s […]

Read More
Sticky Post

Symantec refutes claims of exposing client data during its demonstration process

Contrary to the media reports, the company has called the data breach a ‘minor incident’. The hackers had targeted Symantec accounts belonging to several large Australian firms as well as major Australian government departments. Recent media reports claimed that security giant Symantec exposed confidential data and a purported list of prominent Australian clients during its […]

Read More
Sticky Post

US Customs and Border Protection agency discloses a data breach that compromised license plates and traveler photos

The CBP said that one of its contractors transferred copies of license plate images and traveler photos collected by CBP to the company’s network, which was later compromised by an attacker. The agency did not reveal the name of the contractor, however, CBP’s public statement sent to the Washington Post included the name “Perceptics” in […]

Read More
Sticky Post

AMCA web payment page breached; Nearly 12 million Quest Diagnostics patients impacted

The information that could be accessed during the breach includes Social Security numbers, bank account details, credit card numbers, as well as medical information. American Medical Collection Agency (AMCA) immediately responded by taking down the web payment page, as well as migrated its web payments portal services to a third-party vendor. What happened? American Medical […]

Read More
Sticky Post

Pacers Sports & Entertainment disclose a cybersecurity breach

Pacers Sports & Entertainment (PSE), the legal entity behind the Indiana Pacers and the Indiana Fever NBA and WNBA basketball teams, respectively, announced a cybersecurity breach on Friday during which hackers gained access to sensitive user information. In a press release published yesterday, the company blamed the cybersecurity breach on phishing campaign during which hackers managed to […]

Read More
Sticky Post

Assessing Your Company Culture And How To Change It

What is company culture? Is it defined by your company’s mission? Could it be defined by the work environment? Does your company support the millennial culture? The future is moving in a direction where employees must love their company culture. If they do not, they move on. Workers are now courting companies to make sure […]

Read More
Sticky Post

3 Things You Can Do to Prevent Account Takeovers

Written By: Swaroop Sham of Okta As you likely know, 2018 was not a good year for data security. In the first half of the year, there was a 133% increase in compromised company records compared to the first half of 2017, and an average of 291 records stolen every second. Unfortunately, just a few months […]

Read More
Sticky Post

Job portal ‘Ladders’ exposed profiles of 13 million job seekers, thanks to an unprotected AWS Elasticsearch database

The unprotected database also exposed 379,000 recruiters’ personal information on top of the massive job seekers’ data. The database contained job seekers’ sensitive information such as employment histories, job descriptions, designation, current compensation in US dollars, the industry they are seeking a job in, whether they are a U.S. citizen or if they are on […]

Read More
Sticky Post

Key Trends From the CrowdStrike 2019 Global Threat Report

Written by: Michael Busselen of Crowdstrike The CrowdStrike® 2019 Global Threat Report: “Adversary Tradecraft and the Importance of Speed,”includes the combined work of CrowdStrike’s skilled and seasoned teams that engage in global intelligence gathering and analyzing, proactive threat hunting, and incident response investigations. The threat report also reveals the trends that these teams have seen in 2018 — trends […]

Read More
Sticky Post

Chipotle customers are saying their accounts have been hacked

A stream of Chipotle customers have said their accounts have been hacked and are reporting fraudulent orders charged to their credit cards — sometimes totaling hundreds of dollars. Customers have posted on several Reddit threads complaining of account breaches and many more have tweeted at @ChipotleTweets to alert the fast food giant of the problem. In most cases, orders were put through under […]

Read More
Sticky Post

Attackers compromised Microsoft support agent’s credentials to access users’ email accounts

Written by Ryan Stewart Attackers compromised Microsoft support agent’s credentials and gained access to view ‘limited’ number of users’ email account information. Upon learning about the incident, Microsoft immediately disabled the compromised support agent’s credentials. What is the issue – Microsoft notified its users via email that a certain ‘limited’ number of users who use web […]

Read More
Sticky Post

What you need to know about SD-WAN security.

Written By: Jen Toscano As enterprises embrace digital transformation, they must find a new way to manage networking and security. Many are turning to SD-WAN to reduce MPLS costs, simplify branch IT, increase agility, and deliver an improved user experience. But, securing SaaS and internet-bound traffic for all users at all locations—without compromising on security—can present obstacles. […]

Read More
Sticky Post

CrowdStrike Falcon X Best Threat Intelligence Technology

Written by: Joanna Flower CrowdStrike’s incredible success at this year’s RSA event included winning the SC Magazine 2019 Trust Award for Best Threat Intelligence Technology for Falcon X™, our automated threat intelligence solution and part of the comprehensive CrowdStrike® Falcon® platform. This award was presented at a dinner hosted by SC Magazine on Tuesday, March 5, during […]

Read More
Sticky Post

What’s hiding in encrypted traffic? Millions of advanced threats.

Written by: Deepen Desai Once seen as the ultimate protection for data being transmitted over the internet, encryption has become a vast playground for cybercriminals. Zscaler ThreatLabZ, the research organization at Zscaler, analyzed the encrypted traffic traversing the Zscaler cloud in the second half of 2018 and prepared a report of our findings. The Zscaler cloud processes […]

Read More
Sticky Post

The Benefits Of Working Remotely

In 2019, the top fortune 1000 companies are adopting cutting edge solutions that empower the remote worker to promote better productivity. These solutions increase teamwork so employees can focus on the core business instead of being distracted in a large corporate environment. With cloud based security solutions, the employer has maximum visibility of productivity while […]

Read More
Sticky Post

CrowdStrike Receives Highest Overall Score in the January 2019 Gartner Peer Insights Customers’ Choice for EDR

Written by: Brian Burke and John Crotty of Crowdstrike In the latest customer choice recognitions for endpoint detection and response (EDR), CrowdStrike stands as the highest rated vendor in the January 2019 Gartner Peer Insights Customers’ Choice for EDR.  That’s right: We did it — AGAIN!  On the heels of being named the highest rated […]

Read More
Sticky Post

Every day should be Data Protection Day

Written by: Rainer Rhem Protecting data has become increasingly difficult. Between a lack of awareness, unintended user actions, system glitches, and increasingly sophisticated cyber adversaries, preventing data loss is no mean feat.  With increasing risks and expanding regulations for data protection, organisations must focus on closing security gaps that have emerged in the era of […]

Read More
Sticky Post

Cybersecurity Awareness With AGT

The true beginning to cybersecurity within any organization is awareness. Are you aware of your cyber surroundings? Are you and your employees trained and prepared to face a cyberthreat? You may know of the common cyber threats that cross your paths such as phishing, smishing, malware, and ransomware, but can you and your employees recognize every threat? […]

Read More
Sticky Post

Visibility and Granular Control: The Secret to Securing USB Devices In the Workplace

Written by Damien Lewke of Crowdstrike Social engineering continues to be exploited by hackers and feared by security teams. Due to attackers’ subtlety and users’ natural curiosity, hackers succeed daily in baiting users to click on a link or answer a phishing email.  Baiting is a highly successful technique that relies on an organization’s weakest […]

Read More
Sticky Post

How cloud and mobility are disrupting 30 years of network and security history

Written by: Yogi Chandiramani of Zscaler The internet is disrupting industries and business models, fundamentally changing the way we live and work in the process. The cloud has also ignited a wave of disruption, which when considered in conjunction with the proliferation of mobile devices, has rendered traditional network and security best practices obsolete. Indeed, as the […]

Read More
Sticky Post

Bad Actors Are Still Busy This Post-Holiday Season: Tips to Keep Your Organization Safe

Written by: Damien Lewke of Crowdstrike The holidays are a time for reflection, getting together with friends, shopping — and increasingly, cybercrime. With the rise of e-commerce, adversaries gleefully look forward to the holidays as an opportunity to harvest valuable payment and credential information from record numbers of unsuspecting online shoppers. In the United States […]

Read More
Sticky Post

Endpoint Security With AGT

Our world is mobile. You work in the office and everywhere else, using our mobile devices. What happens beyond your office’s firewall?  Are you secure inside your work environment? What about in the wild? Without endpoint security on your devices, you are vulnerable. What is endpoint security? Endpoint security is essential to the protection of […]

Read More
Sticky Post

Big Data, Graph, and the Cloud: Three Keys to Stopping Today’s Threats

Written By Scott Taschler of Crowdstrike Graph databases are having a bit of a moment in cybersecurity. With recent releases from industry juggernauts such as Microsoft and Google/VirusTotal, it seems “graph” could be poised to take center stage as a security industry buzzword and the next must-have cybersecurity technology. However, using a hot technology doesn’t […]

Read More
Sticky Post

Email Security & AGT

There are roughly 156 million phishing emails sent each day. 16 million of those emails make it to inboxes and are not sent to spam. Out of those numbers, 80,000 people take the lure per day from phishing emails. A phishing email attack is when a hacker baits an organization by posing to be someone […]

Read More
Sticky Post

The loss of non-regulated data costs more than you think

Written by: Pooja Deshmukh from Zscaler Are you a frequent traveler? If so, you probably participate in at least one rewards program in which you accrue airline miles or earn hotel points. The hospitality industry practically invented these loyalty programs and they’ve been enormously popular, delivering value to customers and merchants alike. It turns out, membership account […]

Read More
Sticky Post

CrowdStrike Provides Free Dashboard to Identify Vulnerable Macs

Written by Hamilton Yang, Sat Nath, and Peter Uys from Crowdstrike The recent discovery of the Remote Code Execution (RCE) vulnerability CVE-2018-4407 in Apple’s XNU operating system kernel may have been a cause for concern among organizations using Macs but CrowdStrike® is helping customers identify vulnerable Macs in their environments with a new dashboard. The XNU OS […]

Read More
Sticky Post

Elastic scalability matters…because you can’t predict the future

Written by: Jen Toscano of Zscaler The last installment in our series on the five critical elements of branch transformation is elastic scalability. In a cloud context, scalability allows your business to be nimble because cloud infrastructure and apps automatically keep up with your requirements no matter how large they become. Security stays strong and […]

Read More
Sticky Post

Should You Worry About Software Supply Chain Attacks?

Written by Jackie Castelli from CrowdStrike- While there is much discussion today about potential weaknesses in the hardware supply chain, given the recent attacks attributed to China, the software supply chain has already proven to be vulnerable with numerous attacks covered. Yet, even though these attacks seem to be making headlines more frequently, they are far […]

Read More

🛑 Holiday Cyber Alert from Ascension Global Technology (AGT)

How to Avoid Black Friday Scams: What Everyone Must Know Before Shopping The holiday season is the busiest shopping period of the year — and also the busiest season for cybercriminals.Black Friday and Cyber Monday attract millions of shoppers looking for deals, which creates the perfect opportunity for scammers to deploy fake websites, fraudulent ads, […]

Read More

The Critical Importance of Business Continuity and Disaster Recovery Plans

In today’s digital age, businesses heavily rely on technology to manage their operations, communicate with clients, and store critical data. Recent outages, such as the massive Azure outage caused by a DDoS attack and the Crowdstrike service interruption, emphasize the vulnerability of even the most robust systems. These events highlight the urgent need for comprehensive […]

Read More

Embracing the NIST Cybersecurity Framework: A Roadmap to Enhanced Cybersecurity

It’s the middle of 2024 and the cybersecurity threats keep rising. Cybersecurity is not just an IT concern; it’s a critical aspect of business resilience and trust. At Ascension Global Technology (AGT), we understand the importance of a robust and holistic cybersecurity posture, and we recommend the National Institute of Standards and Technology (NIST) Cybersecurity […]

Read More

Navigating Online Communication: Understanding Zoom’s Updated Service Policy and Exploring Safer Alternatives

In the modern digital age, virtual communication platforms have become an essential tool for both personal and professional interactions. However, recent updates to Zoom’s service policy, particularly in section 10.4, have raised concerns about data privacy and security. This article aims to shed light on the potential risks associated with continuing to use Zoom and […]

Read More

Enhancing Cybersecurity: Mitigating APT Activity Targeting Outlook Online

The digital realm’s escalating threats call for heightened vigilance and robust countermeasures. The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) have recently issued a joint Cybersecurity Advisory (CSA) titled “Enhanced Monitoring to Detect APT Activity Targeting Outlook Online.” The advisory provides invaluable guidance to enhance monitoring within Microsoft Exchange Online […]

Read More

Bridging the Gap: Aligning Compliance and Cybersecurity for Robust Business Performance

In the dynamic universe of today’s digital operations, businesses grapple with the challenge of merging two seemingly different orbits – compliance and cybersecurity. Learning to synchronize these crucial elements is pivotal for not only mitigating risks but also for sustaining a vibrant and resilient business performance.Understanding how to integrate these two areas is critical to […]

Read More

Empowering Cybersecurity Through Gap Analysis: An Investment Towards a Secure Future

The paradigm of cybersecurity thrives on a proactive ethos, emphasizing the imperative role of tools like gap analysis in assessing the efficacy of an organization’s information security management system (ISMS). However, what exactly constitutes a gap analysis, and why is it a worthy investment for organizations? This piece delves into the essence of gap analysis […]

Read More

Building a Cybersecurity Program for Small and Medium-Sized Businesses

Cybersecurity is a top priority for businesses of all sizes in today’s interconnected world. Small and medium-sized businesses (SMBs) are particularly vulnerable to cyber threats, given their limited resources and expertise. This article outlines the key areas SMBs should focus on when building a cybersecurity program and discusses best practices for each. Additionally, we’ll explore […]

Read More

Why You Need a Cybersecurity Risk Assessment

As technology advances and becomes increasingly integrated into our daily lives, the threat of cyber attacks has grown exponentially. Organizations of all sizes must prioritize cybersecurity to protect their data, reputation, and customers. One essential step in bolstering your organization’s cybersecurity is conducting a cybersecurity risk assessment. In this article, we will explore the importance […]

Read More