article thumbnail

Microsoft Exchange ProxyNotShell vulnerability explained and how to mitigate it

CSO Magazine

Last year, two high severity, easily exploitable Microsoft Exchange vulnerabilities dubbed ProxyLogon and ProxyShell made waves in the infosec sphere. Both vulnerabilities impact Microsoft Exchange Server on-premises and hybrid setups running Exchange versions 2013, 2016, and 2019 with an internet-exposed Outlook Web App (OWA) component.

InfoSec 97
article thumbnail

New Leak Shows Business Side of China’s APT Menace

Krebs on Security

Danowski said that in 2013, i-SOON established a department for research on developing new APT network penetration methods. “The infosec industry is always trying to distinguish [the work] of one APT group from another. APT stands for Advanced Persistent Threat, a term that generally refers to state-sponsored hacking groups. .

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

First American Financial Pays Farcical $500K Fine

Krebs on Security

It’s difficult not to hum a tune whenever the phrase “accepted the risk” comes up if you’ve ever seen this excellent infosec industry parody. ” The SEC said the 800 million+ records had been publicly available on First American’s website since 2013.

Insurance 331
article thumbnail

Project Svalbard: The Future of Have I Been Pwned

Troy Hunt

Back in 2013, I was beginning to get the sense that data breaches were becoming a big thing. Increasingly, I was writing about what I thought was a pretty fascinating segment of the infosec industry; password reuse across Gawker and Twitter resulting in a breach of the former sending Acai berry spam via the latter. "Have I been pwned?"

article thumbnail

Announcing the public availability of the Cisco Cloud Controls Framework (CCF)

Cisco Security

ISO IEC 27001:2013 – Information technology — Security techniques — Information security management systems — Requirements. Infosec Registered Assessors Program (IRAP December 2020). Today, the Cisco CCF V1.0 ISO 22301:2019 – Security and resilience — Business continuity management systems — Requirements.

Marketing 145
article thumbnail

Reflection on Black Hat 2013 – a Technical Perspective

NopSec

Aside from mingling with my infosec peers, and plenty of customer interactions at BlackHat Briefings and Sponsor Expo Hall, this year I personally attended training classes alongside my team of engineers. The post Reflection on Black Hat 2013 – a Technical Perspective appeared first on NopSec.

InfoSec 40
article thumbnail

Business Must Change: InfoSec in 2019

The Falcon's View

Consider, if you will, that fundamentally we in infosec want people to make better decisions. That's right, it's infosec. Those are the Three Ways of DevOps as introduced within The Phoenix Project way back in 2013. 3) InfoSec Bifurcation: Functional vs. Strategic. Truly, that's at the core of much that we do.

InfoSec 40