Researchers Disclose More Malware Used in SolarWinds Hack

Researchers Disclose More Malware Used in SolarWinds Hack

3rd Party Risk Management , Breach Notification , Critical Infrastructure Security Microsoft, FireEye Find Additional Payloads Used During Supply Chain Attack Scott Ferguson (Ferguson_Writes) • March 4, 2021     Researchers with Microsoft and FireEye are disclosing additional malware used by the hacking group that targeted SolarWinds in December 2020, according to a pair of…

Dasera Wins Globee Awards 17th Annual Cyber Security Global Excellence Awards®

Dasera Wins Globee Awards 17th Annual Cyber Security Global Excellence Awards®

SUNNYVALE, Calif.–(BUSINESS WIRE)–Cloud Data Lifecycle Security startup Dasera announced today that it has been named a winner of the Globee Awards 17th Annual Cyber Security Global Excellence Awards® for demonstrating extraordinary innovation and leadership in information security. Accolades include a Gold Award for Structured Data Security and a Silver Award for Startup of the Year….

Microsoft says China-based hackers found bug to target U.S. firms

Microsoft says China-based hackers found bug to target U.S. firms

China-based government hackers have exploited a bug in Microsoft’s email server software to target U.S. organizations, the company said Tuesday. Microsoft said that a “highly skilled and sophisticated” state-sponsored group operating from China has been trying to steal information from a number of American targets, including universities, defence contractors, law firms and infectious-disease researchers. Microsoft…

Microsoft warns customers against new China cyber attack on exchange email

Microsoft warns customers against new China cyber attack on exchange email

Microsoft has warned its customers against a new sophisticated nation-state cyber attack that has its origin in China and is primarily targeting on-premises ‘Exchange Server’ software of the tech giant. Called “Hafnium,” it operates from China and is attacking infectious disease researchers, law firms, higher education institutions, defence contractors, policy…

Qualys Update on Accellion FTA Security Incident

Qualys Update on Accellion FTA Security Incident

FOSTER CITY, Calif., March 3, 2021 /PRNewswire/ — Qualys, Inc. (NASDAQ: QLYS), a pioneer and leading provider of cloud-based IT, security, and compliance solutions, today issued an update on the security incident regarding the Accellion FTA file transfer solution. Qualys received new information about a previously identified zero-day exploit in a third-party solution, Accellion FTA that Qualys deployed to…

OODA Loop – CISA tells Federal Agencies to Immediately Patch or ‘Disconnect’ Microsoft Exchange Servers

OODA Loop – CISA tells Federal Agencies to Immediately Patch or ‘Disconnect’ Microsoft Exchange Servers

The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency has posted a new emergency directive calling on federal agencies to immediately patch or disconnect Microsoft Exchange servers. The alert follows a recent warning from Microsoft about major zero-day attacks on email servers, according to a recent posting by the tech giant. The zero-day…

Zero-day vulnerabilities in Microsoft Exchange Server

Zero-day vulnerabilities in Microsoft Exchange Server

Zero-day vulnerabilities in Microsoft Exchange Server | IT Security News 4. March 2021 The four vulnerabilities inside Microsoft Exchange Server allow an attacker to compromise a vulnerable server. As a result, an attacker will gain access to all registered email accounts, or be able to execute arbitrary code (remote code execution or RCE) within the…