Doris Au

All posts by Doris Au

Doris is a product marketing manager at Barracuda. In this position, she is responsible for connecting managed service providers with multi-layered security and data protection products that can protect their customers from today’s advanced cyber threats.

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: (DVMRP) Vulnerability Found in Cisco IOS XR

Cybersecurity Threat Advisory: (DVMRP) Vulnerability Found in Cisco IOS XR

Advisory Overview A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. A successful exploit by such an attacker could...

/ September 10, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory WordPress File Manager Plugin Vulnerability

Cybersecurity Threat Advisory WordPress File Manager Plugin Vulnerability

Advisory Overview A vulnerability has been discovered in a the popular “File Manager” plugin for the content management system WordPress that can allow an unauthenticated remote attacker to create/move a potentially malicious file on a vulnerable host. This can allow...

/ September 8, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Major Vishing Campaign

Cybersecurity Threat Advisory: Major Vishing Campaign

Advisory Overview The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have recently issued a warning about the growing threat of “vishing” attacks against companies. Vishing (voice phishing) is a social engineering method that uses...

/ August 31, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FritzFrog P2P Botnet

Cybersecurity Threat Advisory: FritzFrog P2P Botnet

Advisory Overview Researchers at Guardicore have identified a peer-to-peer (P2P) botnet, dubbed FritzFrog, brute-forcing SSH servers since January. Once breached, a worm is executed to run malicious payloads which can further expand the botnet by compromising additional devices as well...

/ August 27, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Team Viewer Vulnerability

Cybersecurity Threat Advisory: Team Viewer Vulnerability

Advisory Overview A vulnerability has been discovered in remote desktop connection application “TeamViewer” that can allow an attacker to steal the login information (username and hashed password) of a user. This can allow the attacker to crack the stolen password...

/ August 20, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Two Microsoft Zero-Day Vulnerabilities

Cybersecurity Threat Advisory: Two Microsoft Zero-Day Vulnerabilities

Advisory Overview Microsoft has addressed two zero-day vulnerabilities in this week’s rollout of security patches. One of the zero-day vulnerabilities could allow an attacker to bypass security features intended to prevent improperly signed files from being loaded; the other zero-day...

/ August 14, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Pulse Secure VPN Server Data Leak

Cybersecurity Threat Advisory: Pulse Secure VPN Server Data Leak

Advisory Overview Over 900+ Pulse VPN servers were breached and had their data leaked online. The data includes plaintext username, passwords, IP addresses, user session cookies, administrator details and private encryption keys. Technical detail and additional information What is the...

/ August 13, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: iDRAC Local File Inclusion Vulnerability

Cybersecurity Threat Advisory: iDRAC Local File Inclusion Vulnerability

Advisory Overview Dell EMC iDRAC has been updated to address a path traversal vulnerability in iDRAC versions prior to 4.20.20.20. The vulnerability that was discovered in the Integrated Dell Remote Access Controller (iDRAC) could allow cyber criminals to obtain control...

/ August 6, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Windows DNS Server RCE (CVE-2020-1350)

Cybersecurity Threat Advisory: Windows DNS Server RCE (CVE-2020-1350)

Advisory Overview A Remote Code Execution (RCE) vulnerability exists affecting Windows Domain Name System (DNS) Servers when they improperly handle requests. Successful exploitation of this vulnerability could allow attackers to execute code with SYSTEM level privileges. SKOUT recommends all organizations...

/ July 23, 2020
Ask an MSP Expert: How can an RMM tool help my MSP business?

Ask an MSP Expert: How can an RMM tool help my MSP business?

Q: I am a relatively new MSP, with two technicians who are keeping up with the demand of several customers. My techs have been asking for a remote monitoring and management tool. Is this necessary, and how can an RMM...

/ July 20, 2020