Category: Featured

Tech Time Warp: Cracking the code on password safety, at least for now
October 2023 marks the 20th anniversary of Cybersecurity Awareness Month. This National Cybersecurity Alliance-coordinated event is an excellent time to remind colleagues, friends, and family about the important of protecting yourself online. In this week’s Tech Time Warp will look...
Cybersecurity Threat Advisory: Atlassian zero-day vulnerability patch
Atlassian has recently announced a patch for a new zero-day vulnerability which allows for privilege escalation on affected versions of Confluence Data Center and Confluence Server. This Cybersecurity Threat Advisory explains the exploitation of this vulnerability, which could allow attackers...

Cybersecurity Threat Advisory: Update on libwebp vulnerability by Google
Google has identified a critical security vulnerability within the libwebp image library, which plays a crucial role in rendering WebP format images. This vulnerability, known as CVE-2023–5129, has been assigned the highest severity rating of 10.0 on the CVSS rating...

Cybersecurity Threat Advisory: Microsoft Sharepoint Server exploit
A proof-of-concept exploit code has surfaced on GitHub for a crucial authentication bypass vulnerability in Microsoft SharePoint Server. The exploit allows attackers to escalate privileges in Microsoft SharePoint Servers. Barracuda MSP recommends reviewing this Cybersecurity Threat Advisory in detail to...

The rising role of vCISO
Cybersecurity threats continue to rise, but the available IT talent pool is shrinking. In fact, studies show there is still a need for more than 3.4 million security professionals, which is an increase of more than 26 percent from 2021....

MSPs must place training bets carefully
There has always been a fine line between when an emerging IT platform creates enough demand for managed services and when it essentially becomes a commodity that most internal IT teams can manage on their own. Timing that transition is...
Cybersecurity Threat Advisory: New Cisco vulnerabilities discovered
Cisco is warning of five new Catalyst SD-WAN Manager product vulnerabilities. The most critical vulnerability allows unauthorized remote access to the server. Multiple vulnerabilities were discovered in SD-WAN Manager that allows an attacker to access the compromised instance or cause...

Cybersecurity Threat Advisory: WS_FTP Server vulnerabilities uncovered
Multiple vulnerabilities have been found in all versions of WS_FTP Server. The critical and high vulnerabilities include a directory traversal flaw (CVE-2023-42657) with a CVSS score of 9.9, a high-severity reflected cross-site scripting (XSS) issue (CVE-2023-40045, CVSS 8.3), a SQL...

Tech Time Warp: Spilling the tea about HotJava
In the mid-1990s, when early internet users were first exposed to the online world via AOL CD-ROMs, websites were static places. You could find text, graphics, and some choppy audio and video. But that was about to change with the...

Cybersecurity Threat Advisory: New Microsoft Word vulnerability
A new Microsoft Word vulnerability, CVE-2023-36761, was disclosed by Microsoft. This new vulnerability is rated 5.3 by NIST, a medium-level vulnerability but Microsoft has rated this as “Important”. Barracuda MSP recommends reviewing this Cybersecurity Threat Advisory in detail and follow...