Tuesday, January 25, 2022

Hackers Infect macOS with New DazzleSpy Backdoor in Watering-Hole Attacks

A previously undocumented cyber-espionage malware aimed at Apple's macOS operating system leveraged a Safari web browser exploit as part of a watering hole attack targeting politically active, pro-democracy individuals in Hong Kong. Slovak cybersecurity firm ESET attributed the intrusion to an actor with "strong technical capabilities," calling out the campaign's overlaps to that of a similar
http://dlvr.it/SHmr7f

Hackers Using New Malware Packer DTPacker to Avoid Analysis, Detection

A previously undocumented malware packer named DTPacker has been observed distributing multiple remote access trojans (RATs) and information stealers such as Agent Tesla, Ave Maria, AsyncRAT, and FormBook to plunder information and facilitate follow-on attacks. "The malware uses multiple obfuscation techniques to evade antivirus, sandboxing, and analysis," enterprise security company Proofpoint 
http://dlvr.it/SHlpNY

Monday, January 24, 2022

CVE-2022-22122

In Mattermost Focalboard, versions prior to v0.7.5, v0.8.4, v0.9.5, v0.10.1 and v0.11.0-rc1; as used respectively in Mattermost, versions prior to v5.37.6, v5.39.3, v6.0.4, v6.1.1 and v6.2.0, are vulnerable to Insufficient Session Expiration. When a user initiates a logout, their session is not invalidated properly. In addition, user sessions are stored in the browser’s local storage, which by default does not have an expiration time. This makes it possible for an attacker to steal and reuse the cookies using techniques such as XSS attacks, to completely take over a victim account. (CVSS:7.5) (Last Update:2022-01-24)
http://dlvr.it/SHkrf6

CVE-2022-23227

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root. (CVSS:10.0) (Last Update:2022-01-21)
http://dlvr.it/SHjQxn

ZTNAs Address Requirements VPNs Cannot. Here's Why.

I recently hopped on the Lookout podcast to talk about virtual private networks (VPNs) and how they've been extended beyond their original use case of connecting remote laptops to your corporate network. Even in this new world where people are using personal devices and cloud apps, VPN continues to be the go-to solution for remote access and cloud access. After my conversation with Hank Schless,
http://dlvr.it/SHjNkK

Thursday, March 12, 2020

HOW TO CHOOSE A PENETRATION TESTER OR PENETRATION TESTING COMPANY?

How do you choose penetration tester or penetration testing company? Is it by his/her certification or by his/her experience? 

We bet you'll choose both. But how do we differentiate a good pentester and a bad pentester? We would like to discuss this and do leave us a comment below. Experience is needed in any industry especially in IT security field. Nowadays, a lot of platforms are given to the hackers to test their ability in a safe environment and helps an organization to secure their organization. These hackers can make millions of dollars even without any certificate at their hands!" link..." 

Certificates are indeed important. They're the standard and a quality control method in selecting your IT security consultant vendor. "link" But to get the best service, there is much more to look at beyond that fancy certificates, marketing, ads etc as a famous quote saying: "don't judge a book by its cover"

Here are our steps to help you to get the best out of the penetration testing service: 

1. Get to know your pentester 
You don't know how good they are until you meet them personally. Client should do some research and prepare a set of both technical and soft skills related pre-questionnaires relevant to your project prior to meeting the penetration tester. The important key here is to check the balance between the technical skill and soft skill of the penetration tester. You'll know later why both are important. You surely don't want your future vendor to just beat around the bush and left you thinking you've chosen the best IT security service provider. 

2. Understand your own scope
Sometimes defining a scope can be mission critical before starting penetration testing assessment. Most of the clients do not know what they truly need and just make an assumption based on their budget. Consult your pentester on this. If he can give a good suggestion to help you formulate your scope, there is a chance that you're dealing with the right person. Good and genuine pentester will recommend things you need, a salesperson will recommend things they want you to have. 

3. How much do pentester charge? 
An expensive service is not necessarily the best and a cheap service does not guarantee you'll get a quality service. One thing one must know is that good and quality penetration testing service requires time and time spent is equivalent to cost spent. A dark hacker took weeks or even months to hack a good system, so realistically don't expect a pentester to find the same vulnerabilities within just one or two days! If they promise such thing, you'll probably ended up getting just a automated scan instead of a thorough and detail penetration testing. Every pentester has their own rates. Let them calculate the cost for you and ask you can ask them to justify their pricing. A standard rate may be applied using man-days. 

4. You know the cost, but how do you define the quality of penetration service? 
Money alone does not solve everthing. If you spend too much, it doesn't necessarily guarantee you a good quality service, and likewise. Keep in mind, quality is subjective. The most important thing is that your objective is achieved. It is a good idea to ask your pentester to explain what level of quality that they can deliver to your organization. One of the best ways to know how good is your pentester is to ask them to give a demo or Proof of Concept (P.O.C) then you'll know how authentic their skill/experience is aside from their fancy certificates. 

5. Communication is vital
Once you've confirmed that your pentester skill set is acceptable and authentic, the next thing is to know if he/she can effectively communicate his/her findings during penetration testing to your organization.Here is when soft skills come to play. A good pentester can explicitly communicate technical findings during findings presentation in a language that is understandable to their client and thus ultimately come out with an effective solution to remediate vulnerabilities and develop a good action plan for their client. 

6. Report is mission critical 
Last, the penetration testing report. Don't get too excited if the pentester can deliver the report to you in a short period of time. Sometimes, pentester need to allocate longer timeline to complete the assessment so they can provide a better insight of their findings and also come up with a better solution. So the important key is constant communication during penetration testing project. 

That's all folks, we hope this brief guide can help you choose your IT security vendor, happy pentesting!

NATIONAL CYBER SECURITY POLICY

KUALA LUMPUR: The Government plans to establish a National Cybersecurity policy to better secure the nation against threats, says Gobind Singh Deo (pic).
The Communications and Multimedia Minister said his ministry will be spearheading the policy in collaboration with the National Cybersecurity Agency and the Malaysian Communications and Multimedia Commission.
"With Malaysia's digital economy growing by leaps and bounds, it is inevitable that there will be unintended consequences.
"Threats like data breaches and theft, sabotage, intrusion, and cyber espionage can have adverse impacts on organisations and the state," he said.
One of the areas is to develop more local cybersecurity talents.
"Developing the right talent is a very important aspect of cybersecurity preparedness.
"It is crucial that we establish a sustainable model with the cooperation of various government agencies (along with) academic and private institutions," he said.
Gobind added that he will suggest amending laws to combat cyberbullying and cybercrimes.
"We could introduce new provisions in the Penal Code, for example, so that such crimes could be investigated by the police.
"But before we do all these, I am in the process of discussing it with the police to get their views," he said.

Read more at https://www.thestar.com.my/news/nation/2018/12/03/national-cybersecurity-policy-for-online-threats-being-discussed-says-gobind/#cksoZWUpPFHYmTcb.99 

Cybersecurity needs AI as much as AI needs cybersecurity - Techzine Europe

Cybersecurity needs AI as much as AI needs cybersecurity  Techzine Europe http://dlvr.it/TDY1dr