Task #155325
open(IN)SECURE Newsletter - January 29, 2025
0%
Description
View this email in your browser (https://mailchi.mp/helpnetsecurity.net/insecure-newsletter-2761577?e=b0f1ce63ac)
- (IN)SECURE Newsletter January 29, 2025
------------------------------------------------------------
A smorgasbord of knowledge and news
What’s new?
5,000+ SonicWall firewalls are still vulnerable (https://www.helpnetsecurity.com/2025/01/27/5000-sonicwall-firewalls-still-open-to-attack-vulnerability-cve-2024-53704/) to attack via a high-severity vulnerability (CVE-2024-53704) that, according to SonicWall, should be considered “at imminent risk of exploitation”.
Despite warnings, more than 48,000 vulnerable (https://www.helpnetsecurity.com/2025/01/22/48000-internet-facing-fortinet-firewalls-still-open-to-attack/) Fortinet Fortigate devices are still exposed to the internet and remain at high risk, according to data from the Shadowserver Foundation.
The “email bombing + posing as tech support via Microsoft Teams” combination is proving fruitful for two threat actors looking to deliver ransomware (https://www.helpnetsecurity.com/2025/01/21/ransomware-attackers-are-vishing-organizations-via-microsoft-teams-email-bombing/) to organizations, and they seem to be ramping up their efforts.
The CISO’s rise to the C-suite comes with more engagement with the boardroom (https://www.helpnetsecurity.com/2025/01/24/cisos-board-relationships/) , an audience with the CEO, and the power to make strategic decisions for the business, according to Splunk.The ongoing evolution of the CIS Critical Security Controls (https://helpnet.link/h45)
Cybersecurity isn’t a one-time endeavor — it’s an ongoing process of adaptation and improvement. Updating (https://helpnet.link/h45) your organization to CIS Controls v8.1 will not only help meet the current challenges but also lay a robust foundation for future upgrades to your cybersecurity strategies.
Ideas to consider, practices to implement
- Defense strategies to counter escalating hybrid attacks (https://www.helpnetsecurity.com/2025/01/23/tomer-shloman-trellix-hybrid-attacks/)
- Scam Yourself attacks: How social engineering is evolving (https://www.helpnetsecurity.com/2025/01/21/scam-yourself-attacks/)
- Acronis CISO on why backup strategies fail and how to make them resilient (https://www.helpnetsecurity.com/2025/01/22/gerald-beuchelt-acronis-backup-strategy/)
- Decentralization is happening everywhere, so why are crypto wallets “walled gardens”? (https://www.helpnetsecurity.com/2025/01/20/crypto-hardware-wallets/)
- Addressing the intersection of cyber and physical security threats (https://www.helpnetsecurity.com/2025/01/21/nicholas-jackson-bitdefender-emerging-technologies-threats/)
- A humble proposal: The InfoSec CIA triad should be expanded (https://www.helpnetsecurity.com/2025/01/16/infosec-cia-triad/)
- How CISOs can elevate cybersecurity in boardroom discussions (https://www.helpnetsecurity.com/2025/01/16/ross-young-team8-cybersecurity-boardroom-discussions/)
- NDR’s role in a modern cybersecurity stack (https://www.helpnetsecurity.com/2025/01/20/cybersecurity-stack-ndr-role-video/) (Video)
Subscribe to get regular updates from Help Net Security. Choose between our daily and weekly newsletters, or you can also opt for specialized newsletters:
- Breaking news – sent for major events
- Cybersecurity jobs – sent weekly
- Open-source cybersecurity tools – sent monthly
- BloodyAD (https://www.helpnetsecurity.com/2025/01/28/bloodyad-active-directory-privilege-escalation/) - An Active Directory privilege escalation framework
- Web Cache Vulnerability Scanner (https://www.helpnetsecurity.com/2025/01/23/web-cache-vulnerability-scanner-detecting-web-cache-poisoning/) - A tool for detecting web cache poisoning
- Stratoshark (https://www.helpnetsecurity.com/2025/01/22/stratoshark-wireshark-cloud/) - Wireshark for the cloud
- Fleet (https://www.helpnetsecurity.com/2025/01/21/fleet-open-source-platform-it-security-teams/) - A for IT and security teams
- MSSqlPwner (https://www.helpnetsecurity.com/2025/01/17/mssqlpwner-open-source-pentesting-mssql-servers/) - A tool for pentesting MSSQL servers
- Contextal Platform (https://www.helpnetsecurity.com/2025/01/15/contextal-platform-open-source-threat-detection/) - A solution for contextual threat detection and intelligence
https://www.helpnetsecurity.com
https://twitter.com/helpnetsecurity
https://www.linkedin.com/company/2146685/admin/
============================================================
Copyright © 2025 Help Net Security (Astus d.o.o.), All rights reserved.
You are receiving (IN)SECURE Newsletter because you opted in at our web site located on https://www.helpnetsecurity.com.
Note: Sometimes we send promotional maildrops to our list. We never share your details with anyone! We really send a limited number of maildrops per year, so we hope you won't unsbscribe because of them. Thanks in advance!
Our mailing address is:
Help Net Security (Astus d.o.o.)
Kastav
Kastav 51215
Croatia
Want to change how you receive these emails?
You can * update your preferences (https://helpnetsecurity.us2.list-manage.com/profile?u=f76e9593a7d90f4024574218d&id=28abe5d9ef&e=b0f1ce63ac&c=c0d6044ac1)
or * unsubscribe from this list (https://helpnetsecurity.us2.list-manage.com/unsubscribe?u=f76e9593a7d90f4024574218d&id=28abe5d9ef&t=b&e=b0f1ce63ac&c=c0d6044ac1)
.
No data to display
Also available in: Atom PDF Tracking page