Cybersecurity Threat Advisory: TransUnion Incident: Credit Info Exposed
Advisory Overview: TransUnion, a credit reporting bureau, recently began notifying some consumers that their credit information had been obtained by an unauthorized person or persons. The access occurred when a threat actor illegally accessed a TransUnion website that allows businesses...
How to take a security-centric approach with your RMM
Q: We recognize that cybersecurity needs to be a priority for our MSP. How can we use the tools we have — or similar tools — to recognize vulnerabilities and anomalies in our customers’ network? Cybercriminals are very good at...
Cybersecurity Threat Advisory: American Express Breach by Ex-employee
Advisory Overview American Express – a provider of credit, travel, and other business and personal finance services –advised some customers on September 30, 2019 that their personal and American Express account information may have been compromised and may be used...
Cybersecurity Threat Advisory: Comodo Security Breached by vBulletin Zero Day
Advisory Overview: Cybersecurity firm Comodo – who provides website security certificates and other services – recently suffered a breach of their web forum site which included usernames, IP addresses, and other data of forum users. Since many users re-use credentials...
Cybersecurity Threat Advisory: Microsoft Releases Patch for Internet Explorer Vulnerability
Advisory Overview: Microsoft has released an emergency patch for Internet Explorer (multiple versions) that fixes a critical vulnerability in that browser. By manipulating Internet Explorer via a specially-configured website, a threat actor can gain privileges equal to the user who...
Cybersecurity Threat Advisory: LastPass Bug Leaks Credentials From Previous Site
Advisory Summary: LastPass is a very popular and widely used password manager – software designed to save user passwords, create secure passwords, and automatically fill in usernames and passwords on websites. Recently, security researchers have discovered that JavaScript embedded in...
Ask an MSP Expert: Should I outsource NOC and Help Desk services?
Q: My managed service business is at a stage where we need more technicians to focus on resolving support tickets and provide help desk support. I am debating between hiring a Level 1 help desk agent or outsource to a...
Cybersecurity Threat Advisory: UK National Cyber Security Centre Urges Python Migration
Advisory Overview: The UK National Cyber Security Centre (NCSC) has warned developers to migrate from Python 2.X to Python 3.X based code due to an upcoming end of life date of January 1st, 2020. By continuing to use unsupported versions...
Cybersecurity Threat Advisory: Pulse Connect Secure VPN and FortiGate SSL VPN Vulnerability
Advisory Overview: Researchers have discovered critical security flaws in FortiGate and Pulse Connect Virtual Private Network (VPN) systems. VPN’s are routinely used to secure online communication, such as between a remote worker’s desktop and the corporate network, and are very...
Cybersecurity Threat Advisory: Supplemental Advisory for the BlueKeep Vulnerability
Advisory Overview: Microsoft recently undertook efforts to protect Windows desktops and servers against a threat known as BlueKeep, a vulnerability in Remote Desktop Protocol – a tool used to remotely access a Windows desktop or server. During these efforts, Microsoft...
