Category: Security

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical VMWare ESXi Vulnerabilities Exploited

Cybersecurity Threat Advisory: Critical VMWare ESXi Vulnerabilities Exploited

Threat Update There are two critical remote code execution vulnerabilities (CVE-2019-5544 and CVE-2020-3992) within VMWare ESXi which allow attackers to effectively gain control of a virtual machine (VM), deploy ransomware, and encrypt ESXi virtual disk drives. These vulnerabilities are reported...

/ February 5, 2021
Hit by ransomware, a second time?

Hit by ransomware, a second time?

Sometimes it is easy to overlook the obvious when distracted by the meltdown of the moment. Still, MSPs and other security stakeholders need to take a holistic view when something happens. Often, an MSP may be so concerned – understandably...

/ February 4, 2021 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apple iOS Zero-Day Vulnerabilities Exploited in Wild

Cybersecurity Threat Advisory: Apple iOS Zero-Day Vulnerabilities Exploited in Wild

Threat Update Apple has announced that they have learned of three zero-day vulnerabilities affecting their iOS operating system. One of the vulnerabilities (CVE-2021-1782) affects the system kernel, allowing for privilege escalation; while the other two (CVE-2021-1870, CVE-2021-1871) are present within...

/ February 3, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Threat Actors Abusing Windows RDP Servers

Cybersecurity Threat Advisory: Threat Actors Abusing Windows RDP Servers

Threat Update The RDP service for Windows devices operating on UDP port 3389 can currently be used in an amplified attack resulting in the potential DDoS of a target. A system which is either involved in or the target of...

/ February 1, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Updates on Global Intrusion Campaign

Cybersecurity Threat Advisory: Updates on Global Intrusion Campaign

Threat Update Government and private sector organizations are constantly releasing updates on all manner of topics relating to the SolarWinds Orion compromise. In this article, we have detailed recently released information related to the incident. Technical Detail & Additional Information...

/ January 29, 2021
Demand for managed security services starts to rise

Demand for managed security services starts to rise

One of the widely expected outcomes of the economic downturn brought on by the COVID-19 pandemic is that more organizations would rely on managed security services. After all, not only would they have fewer resources, the pandemic itself created the...

/ January 27, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: WordPress Plugin Critical Vulnerability

Cybersecurity Threat Advisory: WordPress Plugin Critical Vulnerability

Threat Update Security researchers have discovered two vulnerabilities present in a WordPress plugin called Orbit Fox. One vulnerability is rated 9.9 on the CVSS scale and allows for privilege escalation and remote code injection; The second is rated 6.4 on...

/ January 25, 2021
Cloud storage security is a great opportunity for MSPs

Cloud storage security is a great opportunity for MSPs

Companies are storing more and more of their valuable data in the cloud and cyber attackers know this. However, the efficiency and productivity benefits of cloud platforms are such that businesses cannot afford not to use them, yet it is...

/ January 25, 2021
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SonicWall NetExtender VPN Client and SMA 100 Zero-Day

Cybersecurity Threat Advisory: SonicWall NetExtender VPN Client and SMA 100 Zero-Day

*Update 1/25: From SonicWall, “While we previously communicated NetExtender 10.X as potentially having a zero-day, that has now been ruled out. It may be used with all SonicWall products. No action is required from customers or partners. Current SMA 100...

/ January 23, 2021