Category: Security

Tales from the security operations center (SOC)

Tales from the security operations center (SOC)

With the frequency and variety of cyberattacks increasing daily, the need for comprehensive security measures has never been more critical. For analysts staffing a security operations center (SOC) for a global extended detection and response (XDR) service, each day brings...

/ July 4, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical update for Juniper Networks routers

Cybersecurity Threat Advisory: Critical update for Juniper Networks routers

A high-severity vulnerability in Juniper Networks, known as CVE-2024-2973, has been exploited. The following flaw affects some of its router products and users need to address it early enough to avoid exploitation. Review this Cybersecurity Threat Advisory in full to...

/ July 3, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: OpenSSH vulnerability threatens remote code execution

Cybersecurity Threat Advisory: OpenSSH vulnerability threatens remote code execution

OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems. Please review the information in this Cybersecurity Threat Advisory to limit your potential...

/ July 2, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical GitLab vulnerabilities

Cybersecurity Threat Advisory: Critical GitLab vulnerabilities

GitLab has released multiple security updates that address a total of 14 vulnerabilities. Attackers can exploit one of the vulnerabilities to run pipelines as any user. Read this Cybersecurity Threat Advisory in detail to learn more about how you can...

/ July 2, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: TeamViewer breach

Cybersecurity Threat Advisory: TeamViewer breach

On June 26, RMM software designer TeamViewer announced a recent breach of their network. According to TeamViewer, no customer data has yet been compromised by this breach. Read this Cybersecurity Threat Advisory in detail to secure your network and devices....

/ July 1, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: MOVEit Transfer vulnerability exploit

Cybersecurity Threat Advisory: MOVEit Transfer vulnerability exploit

Progress Software has released a patch for a high-severity vulnerability in MOVEit Transfer, identified as CVE-2024-5806. This vulnerability is currently under active attack and allows attackers to bypass authentication mechanisms. Organizations using MOVEit Transfer should review this Cybersecurity Threat Advisory...

/ June 28, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Five new vulnerabilities found in Zyxel NAS

Cybersecurity Threat Advisory: Five new vulnerabilities found in Zyxel NAS

Zyxel has released a patch for their NAS326 and NAS542 to fix five new vulnerabilities that have been discovered. These vulnerabilities affect devices with versions 5.21 (AAZF16/ABAG13) and earlier. Barracuda MSP recommends customers using these devices to follow the steps...

/ June 27, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Active exploitation of Microsoft vulnerabilities

Cybersecurity Threat Advisory: Active exploitation of Microsoft vulnerabilities

This Cybersecurity Threat Advisory highlights a new attack technique exploiting vulnerabilities in Microsoft Management Console (MMC). By creating malicious management saved console (MSC) files that appear legitimate, attackers can bypass traditional security measures and exploit the targeted MMC. Barracuda MSP...

/ June 26, 2024
Summer reading: Four must-read cybersecurity titles

Summer reading: Four must-read cybersecurity titles

As a journalist, I’m always writing. I also read a lot, and for someone who writes about cybersecurity, I read A LOT of cybersecurity books. While these are not precisely gripping beach reads, I have read some intriguing cybersecurity books...

/ June 26, 2024
Tip Tuesday: Overcoming the Patch Tuesday blues 

Tip Tuesday: Overcoming the Patch Tuesday blues 

Patch management serves as a key defense against cyberthreats and also ensures operating systems and business-critical software are maintained. However, it is not always a simple and straight-forward task for managed service providers (MSPs), especially in current times. With hybrid...

/ June 25, 2024