Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

The Concerning Lack of Transparency in Bug Bounty Programs

In this video, James Rees shares his concerns about the lack of transparency in bug bounty programs. He highlights the fact that testers are not always properly vetted or regularly checked, leaving companies unsure of who is testing their systems. He also notes that certain regions tend to have more malicious actors, raising questions about the validity of testers from those areas. This lack of transparency can be concerning for companies and users alike, and James encourages more accountability and validation measures to be put in place for bug bounty programs.

8 Dangerous Ransomware Examples

The threat of ransomware has been ever present in 2020, especially within the high-stakes industries like healthcare and those involved in the election. According to Verizon's 2019 Data Breach Investigations Report, 24% of security incidents that involved specific malware functionality exhibited ransomware functionality.

Expert Advice on why you should automate server hardening

We recently engaged in a conversation with our team of experts regarding their ongoing server hardening project. We inquired about the obstacles encountered during manual hardening procedures and asked if they’d be willing to explain the underlying reasons for issues that arise when automation is not employed. Their latest encounter with a client provided a valuable opportunity to further expound on strategies to mitigate these challenges.

What Is DNS Spoofing and How Can You Prevent It?

Have you ever typed in a website’s address and ended up somewhere completely different? Or received emails from what appears to be a familiar company, but with suspicious links that lead to unfamiliar pages? These scenarios may be the result of DNS spoofing, a type of cyber-attack that can leave your sensitive information vulnerable. In this blog post, we’ll dive into what DNS spoofing is, how it works, who is at risk, and most importantly – how you can prevent it.

ManageEngine: 7 GPO misconfigurations to rectify under 30 mins

Group Policy Objects (GPOs) regulate security and access within an AD environment. They are extremely powerful and equally complicated. The sheer number of GPOs, the way they coexist, and their unpredictable order of precedence requires administrators to have high levels of mastery. An uninformed change to a GPO can affect the way users interact with your network permanently. It's crucial to take utmost care while configuring GPOs. Of course, there is always the possibility of misconfiguring a setting or two in the grand scheme of things.

ManageEngine: Ensure identity security and kick-start your Zero Trust journey with ADSelfService Plus

According to Verizon's 2022 Data Breach Investigations Report, 81% of data breaches involve stolen or weak credentials. Identity-based attacks are on the rise, and it has become essential to put identities at the forefront of your security strategy. Don't worry, this is not as complicated as it sounds. Join this webinar as we walk you through some simple steps to form an identity-centered security approach with Zero Trust at the core.

ManageEngine: 4 MFA best practices to secure endpoints

MFA prevents 80 to 90% of cyberattacks, according to Anne Neuberger, American national security official. With cyberattacks becoming more sophisticated and advanced by the day, implementing MFA alone will not get you through. Join this webinar and learn best practices to maximize the benefits of implementing MFA and bolster your endpoint security. What you'll learn

ManageEngine: The evolution of AI and ML in cybersecurity

Artificial intelligence and machine learning are critical for a mature cybersecurity program. These technologies enable organizations to detect time, count, and pattern anomalies; and compute a risk score for every user and entity in the network. Instead of writing threat detection rules, security analysts can rely on the system learning on its own and alerting them about potential threats. AI and ML in cybersecurity helps decrease false positives, while increasing the occurrence of true positives.