Category: Security

Municipal contracts and the cybersecurity data to land them

Municipal contracts and the cybersecurity data to land them

A recent note came to me from a Smarter MSP reader about municipal contracts, and what types of cybersecurity data should be used when trying to land municipal contracts. Assuming they are not the only one with questions on this...

/ August 20, 2020
Widespread cloud configuration issues create opportunity for MSPs

Widespread cloud configuration issues create opportunity for MSPs

The crux of the problem with cloud security has very little to do with the platforms on which applications are deployed. The real issue is the amount of cybersecurity expertise the people deploying cloud applications don’t have. Most cloud applications...

/ August 19, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Two Microsoft Zero-Day Vulnerabilities

Cybersecurity Threat Advisory: Two Microsoft Zero-Day Vulnerabilities

Advisory Overview Microsoft has addressed two zero-day vulnerabilities in this week’s rollout of security patches. One of the zero-day vulnerabilities could allow an attacker to bypass security features intended to prevent improperly signed files from being loaded; the other zero-day...

/ August 14, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Pulse Secure VPN Server Data Leak

Cybersecurity Threat Advisory: Pulse Secure VPN Server Data Leak

Advisory Overview Over 900+ Pulse VPN servers were breached and had their data leaked online. The data includes plaintext username, passwords, IP addresses, user session cookies, administrator details and private encryption keys. Technical detail and additional information What is the...

/ August 13, 2020
Another cybersecurity view from Africa

Another cybersecurity view from Africa

A couple of weeks ago, I wrote about how South Africa’s MSPs and IT specialists are battling the pandemic and WFH trends. After the article ran, I had the opportunity to speak further on this topic with Dr. Uche Mbanaso,...

/ August 13, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: iDRAC Local File Inclusion Vulnerability

Cybersecurity Threat Advisory: iDRAC Local File Inclusion Vulnerability

Advisory Overview Dell EMC iDRAC has been updated to address a path traversal vulnerability in iDRAC versions prior to 4.20.20.20. The vulnerability that was discovered in the Integrated Dell Remote Access Controller (iDRAC) could allow cyber criminals to obtain control...

/ August 6, 2020
MSPs must watch out for TrickBot

MSPs must watch out for TrickBot

The history of malware is littered with viruses that were created solely to obtain banking information. One of the best known in recent years has been TrickBot, and lately, it has re-emerged with increased intensity. Since at least 2016, TrickBot...

/ August 6, 2020 / 8 Comments
Tech Time Warp: Zotob worm wreaks havoc on the news

Tech Time Warp: Zotob worm wreaks havoc on the news

One way to make headlines is to go after the journalists themselves. On August 16, 2005, computers at CNN, ABC, The New York Times and The Associated Press were infected by the Zotob worm, along with machines at Caterpillar, and...

/ July 31, 2020
Pandemic cybersecurity in South Africa

Pandemic cybersecurity in South Africa

The coronavirus has brought economic devastation to all parts of the world. As a journalist based in the United States, I understandably tend to focus on the United States. But it’s easy to become so focused on one’s home country that...

/ July 30, 2020
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Windows DNS Server RCE (CVE-2020-1350)

Cybersecurity Threat Advisory: Windows DNS Server RCE (CVE-2020-1350)

Advisory Overview A Remote Code Execution (RCE) vulnerability exists affecting Windows Domain Name System (DNS) Servers when they improperly handle requests. Successful exploitation of this vulnerability could allow attackers to execute code with SYSTEM level privileges. SKOUT recommends all organizations...

/ July 23, 2020