Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

Beware of Auto-Install of Windows update KB5041571

The article released on August 13, 2024 regarding the security update for Windows 11 for hot fix KB5041571 discusses the new features and improvements to the operating system. The security update includes changes to the lock screen, NetJoinLegacyAccountReuse, Secure Boot Advanced Targeting (SBAT) and Linux Extensible Firmware Interface (EFI), and Domain Name System (DNS). The article also includes a servicing stack update to improve the reliability of the Windows update process.

Defending Healthcare: Trustwave's Dedication to Fight Cyber Threats to Patient Safety

Hospitals face a challenging dilemma: delivering the highest quality of medical care while shielding patient and family data from ever-evolving cyber threats, all while ensuring that critical operations continue uninterrupted. At Trustwave, we understand the immense pressure hospitals are under and are dedicated to creating a safer digital environment where healthcare providers can thrive, and patients receive the uncompromised care they deserve.

File-Sharing Phishing Attacks Increased by 350% Over the Past Year

File-sharing phishing attacks have skyrocketed over the past year, according to a new report from Abnormal Security. “In file-sharing phishing attacks, threat actors exploit popular platforms and plausible pretexts to impersonate trusted contacts and trick employees into disclosing private information or installing malware,” the report says.

Trustwave Rapid Response: Mitigate Windows TCP/IP RCE Vulnerability (CVE-2024-38063)

Microsoft has disclosed a critical (CVSS 9.8) TCP/IP remote code execution (RCE) vulnerability that impacts all Windows systems utilizing IPv6. To conduct this attack, threat actors can repeatedly send IPv6 packets that include specially crafted packets. By doing this, an unauthenticated attacker could exploit this vulnerability, leading to remote code execution. Systems that have IPv6 disabled are not susceptible to this vulnerability.

The Polar Bear in Your Kitchen: A Cybersecurity Analogy

Imagine for a moment that your home has a rodent problem. To address this, you install a fancy system designed to automatically detect and trap animals before they can roam around your house and cause any damage. The system seems to work well; from time to time, you arrive home to find a mouse or a squirrel caught by the device. No big deal, right? Lots of small critters about and the system is working as designed to catch them.

How To Hunt Insider Threats

An insider threat occurs when a legitimate user of an organization’s systems intentionally or accidentally puts the organization’s data at risk. These threats can have a devastating impact on a company’s data, reputation, and bottom line. Insider threat hunting has become essential to proactively identify and mitigate these risks before they escalate into full-blown security incidents.

Elastic: Revealing the threat landscape: 2024 Elastic Global Threat Report

Keeping up with the threat landscape is crucial for every security team, but that becomes challenging in a space that's always evolving. The Elastic Global Threat Report provides valuable insights on the past year's unique telemetry gathered from ~1 billion data points. Hosted by experts and industry veterans, this webinar dives into the major findings from the 2024 Elastic Global Threat Report.

1Password: Managing Shadow IT: Mitigating security risk and ensuring compliance

Have you ever encountered a system on your network without knowing who owns it? You may also have virtual machines running with an unknown purpose. In today's world of hybrid work - digital transformation dictates enterprises operations. However, this shift also increases instances of shadow IT - technologies and systems deployed without explicit organizational approval. This opens up your organization to security and compliance risks.