Recent AD News

650+ compromised credentials found to be in use within NEW Cooperative-the latest organization hit by ransomware

NEW Cooperative, an Iowa-based farm cooperative was recently hit by a ransomware attack that forced it to take its systems offline. NEW Cooperative has operations in over 50 locations and provides a variety of digital and software services to its network of farmers. The ransomware group BlackMatter is reportedly behind the attack. Security experts believe that BlackMatter is either being run by…
Read more
Recent AD News

CISA, FBI, and NSA anticipate a rise in Conti ransomware attacks, issue joint cybersecurity advisory

The FBI, National Security Agency, and the Cybersecurity Infrastructure and Security Agency issued a joint advisory on Sept 22, 2021, warning US organizations to prepare for a rise in Conti ransomware attacks and urged them to apply mitigations suggested. The joint advisory noted that the Conti ransomware has been used in over 400 attacks targeting the US and international…
Read more
Recent AD News

Azure security flaw puts Zero-Trust in the spotlight

In the wake of the recent Microsoft Azure vulnerability, ChaosDB, security experts are stressing that organizations, especially those that rely on public cloud infrastructure can no longer delay adopting the zero-trust model. Cloud security firm Wiz, which first discovered the vulnerability in Microsoft Azure’s managed database service, Cosmos DB said that the vulnerability gave threat…
Read more
Recent AD News

Attackers use stolen credentials to intrude into the UN network

Threat actors leveraged the stolen credentials of a UN employee to gain access to Umoja, a proprietary project management software that’s used in the intergovernmental organization. After intrusion, the attackers stole data that is likely to enable them to go after other agencies within the UN. “We can confirm that unknown attackers were able to breach parts of the UN infrastructure in…
Read more
Recent AD News

CISA and FBI expect ransomware attacks to soar over the Labor Day weekend, issue advisory

Ransomware attacks in the US spiked during all major holiday weekends this year, including Mother’s Day, Memorial Day, and the Independence day weekends. It looks like when employees are taking a break, ransomware gangs are getting to work. The worrying trend has prompted the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI to issue an advisory to all US government and…
Read more
Recent AD News

Another zero-day vulnerability confirmed by Microsoft

This vulnerability, present in the Windows Print Spooler service, allows local attackers to get access to system privileges. Microsoft has confirmed another Windows Print Spooler vulnerability, that is being tracked as CVE-2021-36958. This vulnerability, which is a part of the PrintNightmare set of vulnerabilities, allows the local attackers to gain access to system privileges. Microsoft…
Read more
Recent AD News

Automate access decisions with risk-based contextual authentication

Fortifying Access Management while Working Remotely With more businesses opting for their workforce to work from home, there has been an exponential increase in remote user-focused cyberattacks. As IT teams scramble to deploy strict security measures like multi-factor authentication (MFA) to prevent any possible security event, the user experience of remote employees ends up taking a hit. A…
Read more
Recent AD News

2020 recorded the highest number of CVE’s to ever be reported

In an analysis carried out by the National Institute of Standards and Technology (NIST) on common vulnerabilities and exposures, it has been found that 2020 holds the record for the highest reports of security loopholes than any other year to date. The report shows that, in the year 2020 alone, as much as 18,103 vulnerabilities were reported with almost 10,342 of them classified as high or…
Read more
Recent AD News

Microsoft announces Azure Best Practices and Launches Conditional Access Enhancements

Joy Chik, corporate vice president for Microsoft Identity, recently laid out a general overview of Azure AD security best practice. This announcement comes in the light of improvements that were recently announced to Azure Active Directory including conditional access policy management enhancements and synchronization service additions. Microsoft has suggested that companies using Azure AD…
Read more
Recent AD News

Accellion Zero-Days Responsible for Recent Data Theft and Extortion Attacks

A recent string of attacks consisting of data threats and extortion have been linked to the the Accellion File Transfer Appliance’s CVE’s. Cybersecurity researchers said that a cybercrime group called UNC2546 was responsible for the two month long attack The crime group exploited multiple zero-day vulnerabilities in the legacy FTA software to install a new web shell named DEWMODE on victim…
Read more