Category: Security

  • Microsoft Enhances Teams Security in Prevention of Storm-0324 Malware Distribution

    On September 12, Microsoft released new information about threat actors Storm-0324, a group that gains initial access to systems through email-based phishing and then distributes access to other malicious groups. The transfer of access typically leads to ransomware deployment, making Storm-0324 essentially a middle-man group for system intrusion, one that specializes in initial system penetration.…

  • Human Error: The Largest Threat to our Cybersecurity

    Constantly, we hear that new, emerging technologies pose the greatest threats to our cybersecurity. The fear of the unknown drives organizations to enhance their security measures, aiming to prepare for complex attacks by various threat actor groups. Countless news reports highlight new technologies and innovations in the realm of cybersecurity, all aimed at discovering, tracking,…

  • ALPHV/BlackCat Hacker Group Claims Responsiblity for MGM Resorts Ransomware Attack

    MGM Resorts is currently scrambling to recover from a powerful ransomware attack that happened last Monday, causing a substantial amount of network systems to go down. Company websites as well as many crucial systems are currently offline, including the MGM app, which facilitates reservations, acts as a digital key to unlock rooms, and allows users…

  • Apple Releases Patch for Zero-Day iOS, macOS Vulnerabilities BLASTPASS

    Apple has just rolled out a crucial security update for iPhones and iPads in response to the discovery of newly identified vulnerabilities CVE-2023-41064 and CVE-2023-41061 in their system software. These vulnerabilities, also known as “BLASTPASS,” were found by researchers at the University of Toronto’s Citizen Lab, who revealed that the flaw was actively being exploited…

  • Prompt Injection: Generative AI’s Largest Vulnerability

    With the popularization of generative AI tools like ChatGPT, information has become increasingly easy to retrieve. Ask it anything, and ChatGPT will respond to the best of its ability, modifying itself to your prompt’s specifications as best it can. The more detailed the prompt, the more specific of a response you can get from an…

  • Protecting Your MSSQL Databases: Defending Against the FreeWorld Ransomware Threat

    A new cyberattack campaign named “DB#JAMMER” has emerged, specifically targeting exposed Microsoft SQL Server (MSSQL) databases. The implications of this campaign are nothing short of severe, especially for organizations relying on this technology, as DB#JAMMER is no ordinary cyberattack; it’s a well-choreographed assault that employs intricate tactics, including relentless brute-force attacks aimed at breaching MSSQL…

  • Critical Vulnerability in Hikvision Surveillance Cameras Points to Greater Issue Within the IoT

    Security researchers from Cyfirma recently discovered that over 80,000 Hikvision surveillance cameras are still susceptible to a critical vulnerability that was patched in a security update over 2 years ago. CVE-2021-36260, which was added to the National Vulnerability Database in January of 2022, allows attackers to exploit Hikvision cameras due to their lack of input…

  • Overview: Phish Tale of the Week North Korean Hackers Could be About to Cash Out 41 Million in Stolen Bitcoin New WinRAR Zero-Day Vulnerability Could Install Malware When You Unzip Files How can Netizen help? Phish Tale of the Week Phishing attempts can often target specific groups that can be exploited by malicious actors and…

  • Google Dorking: How a Simple Google Search Can Expose Your Sensitive Data

    Google Dorking leverages search operators to narrow down results. While useful, it can also expose vulnerabilities, as demonstrated by Hamid Firoozi’s breach of a dam’s computer system. To mitigate such risks, conduct security audits, restrict search engine access, and educate your team. Netizen offers cybersecurity solutions to safeguard your digital infrastructure.

  • Netizen: August Vulnerability Review

    Security vulnerabilities are a common occurrence in managing any business’s organizational security. The prompt patching and remediation of any new vulnerabilities are critical to reducing the outside attack surface. Netizen’s Security Operations Center (SOC) has compiled five vulnerabilities from July that should be immediately patched or addressed if present in your environment. Detailed writeups below:…