U.S. Cybersecurity Agency Publishes List of Free Security Tools and Services
A very comprehensive list of free cybersecurity tools recommended by U.S. Cybersecurity Agency you may find in the news published by the Hacker News.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday published a repository of free tools and services to enable organizations to mitigate, detect, and respond effectively to malicious attacks and further improve their security posture.
The "Free Cybersecurity Services and Tools" resource hub comprises a mix of 101 services provided by CISA, open-source utilities, and other implements offered by private and public sector organizations across the cybersecurity community.
Read further on the Hacker News
We Become Sophos Authorized Partner
Trilight Security OÜ has recently been designated as Sophos Reseller. This is a title which opens to us the new opportunities to bring intelligent and reliable cybersecurity solutions to the market. These premium security solutions allow our customers to enjoy various benefits which the next-gen security tools and endpoint protections Sophos offers.
In the first place, these are small and mid-sized business that will benefit from simplified cybersecurity management offered by Sophos solutions and Trilight Security team taking advantage of the in-depth training and support by partner vendor.
Through this partnership we will be able to provide our customers with comprehensive range of Sophos solutions, securing systems and data against modern cyber threats, minimizing the risks and inspiring confidence based on earned reputation of the vendor: Sophos is well known for going above and beyond to provide partners with best industry cybersecurity solutions and superior support.
Trilight Security offers a long range of Sophos products and can assist customers with consulting, selection, installation and management of its facilities.
About Trilight Security
Trilight Security is a Managed Security Service Provider based in Estonia, European Union. We work with customers from small and medium to enterprises, with focus on providing reliable and affordable cybersecurity services to SMB from EU and Associated Countries. Our qualified cybersecurity and IT experts detect, investigate, respond to threats before they disrupt business or take necessary steps to minimize their potential or real impact. More information is available at www.trilightsecurity.com
About Sophos
As a worldwide leader in next-generation cybersecurity, Sophos protects more than 400,000 organizations of all sizes in more than 150 countries from today's most advanced cyber threats. Powered by SophosLabs's global threat intelligence and data science team, Sophos' cloud-native and AI-powered solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cyberattack techniques, including ransomware, malware, exploits, data exfiltration, active-adversary breaches, phishing, and more. Sophos Central, a cloud-native management platform, integrates Sophos' entire portfolio of next-generation products, including the Intercept X endpoint solution and the XG next-generation firewall, into a single "synchronized security" system accessible through a set of APIs. Sophos has been driving a transition to next- generation cybersecurity, leveraging advanced capabilities in cloud, machine learning, APIs, automation, managed threat response, and more, to deliver enterprise-grade protection to any size organization. Sophos sells its products and services exclusively through a global channel of more than 53,000 partners and managed service providers (MSPs). Sophos also makes its innovative commercial technologies available to consumers via Sophos Home. More information is available at www.sophos.com.
Critical Flaws Discovered in Cisco Small Business RV Series Routers
The Hacker News reported on serious flaws found in budget Cisco routes.
Cisco has patched multiple critical security vulnerabilities impacting its RV Series routers that could be weaponized to elevate privileges and execute arbitrary code on affected systems, while also warning of the existence of proof-of-concept (PoC) exploit code targeting some of these bugs.
Three of the 15 flaws, tracked as CVE-2022-20699, CVE-2022-20700, and CVE-2022-20707, carry the highest CVSS rating of 10.0, and affect its Small Business RV160, RV260, RV340, and RV345 Series routers.
Read further in The Hacker News
QNAP Warns of DeadBolt Ransomware Targeting Internet-Facing NAS Devices
The Hacker News reported on new type of Ransomware.
"DeadBolt has been widely targeting all NAS exposed to the Internet without any protection and encrypting users' data for Bitcoin ransom," the company said. "QNAP urges all QNAP NAS users to immediately update QTS to the latest available version."
A query on IoT search engine Censys shows that at least 3,687 devices have been encrypted by the DeadBolt ransomware so far, with most NAS devices located in the U.S., Taiwan, France, Italy, the U.K., Hong Kong, Germany, the Netherlands, Poland, and South Korea.
Read more on The Hacker News
Cisco Releases Patch for Critical Bug Affecting Unified CCMP and Unified CCDM
The Hacker News reported on important patch released by Cisco.
Cisco Systems has rolled out security updates for a critical security vulnerability affecting Unified Contact Center Management Portal (Unified CCMP) and Unified Contact Center Domain Manager (Unified CCDM) that could be exploited by a remote attacker to take control of an affected system.
Tracked as CVE-2022-20658, the vulnerability has been rated 9.6 in severity on the CVSS scoring system, and concerns a privilege escalation flaw arising out of a lack of server-side validation of user permissions that could be weaponized to create rogue Administrator accounts by submitting a crafted HTTP request.
Read further on The Hacker News
GoodFirms Publishes Interview with Trilight Security CEO
The GoodFirms.co, a renowned B2B service suppliers reviews service has chosen Trilight Security CEO for the interview.
GoodFirms: Please introduce your company and give a brief about your role within the organization.
Trilight CEO: We are Trilight Security, a cybersecurity services provider. Basically, we are the MSSP and provide managed security service to our SMB customers and larger enterprises. I'm one of the co-founders of the company and currently perform CEO duties...
Read further on the GoodFirms.co
Hackers Using Microsoft MSHTML Flaw to Spy on Targeted PCs with Malware
The Hacker News describes he way how the Microsoft flaw is being utilized by hackers.
A new Iranian threat actor has been discovered exploiting a now-addressed critical flaw in the Microsoft Windows MSHTML platform to target Farsi-speaking victims with a new PowerShell-based information stealer designed to harvest extensive details from infected machines.
"The stealer is a PowerShell script, short with powerful collection capabilities in only ~150 lines, it provides the adversary a lot of critical information including screen captures, Telegram files, document collection, and extensive data about the victim's environment," SafeBreach Labs researcher Tomer Bar said in a report published Wednesday.
Read more on The Hacker News
Navigating The Threat Landscape 2021: From Ransomware to Botnets
The Hacker News studies Global Threat Landscape Report which indicates a drastic rise in sophisticated cyberattacks targeting digital infrastructures, organizations, and individuals in 2021.
When new threats emerge, attackers take advantage of them, however, most businesses are only aware of the current threats. Organizations struggle to address these threats due to their resource sophistication and their lack of understanding of evolving threat landscapes. For these reasons, organizations need visibility on the advanced threats especially targeting their infrastructure. This article will outline the evolution in the cyber threat landscape 2021.
Read further on The Hacker News
Trilight Security Featured as One of the Most Reviewed IT Services Companies in Estonia
This year marks an important milestone for Trilight Security as we are celebrating our first year in the IT industry! Over the past year, we've been working with small and mid-market businesses across industries such as financial services, information technology, business services, and more.
The Manifest recognized our efforts and named us a Most Reviewed IT Services Company in Estonia! This award is due to the numerous positive reviews we've received so far.
Our journey began in Tallinn, Estonia when Trilight Security was founded with the mission of providing world-class cybersecurity services. Since then, we've worked with various clients in Europe and beyond.
Our collaboration with organizations from aerospace industry demonstrates the scale and impact of our work. We partnered with the Ukrainian-based aerospace agency in 2020, and we conducted tests on their IT infrastructure. We simulated attacks and identified vulnerabilities in their system. Our work allowed the client to meet their country's IT requirements. They praised our superb knowledge throughout the process.
Positive feedback from such customers led the Manifest to include us on their list of Most Reviewed IT Services Companies in Estonia for 2021!
The Manifest is a B2B resource guide that analyzes and compiles industry data. Their website features leading companies to allow entrepreneurs and business managers to connect with the perfect agencies for their needs.
We're proud to receive this award from the Manifest. This recognition speaks to our expertise as an IT agency, and it affirms our dedication to our clients. Being recognized as an industry leader is no small feat, and with this award, we're only inspired to continue improving our technology and innovating our approaches.
Do you have any projects in mind? Contact us today, and let's discuss how we can work together to reach your goals!
Penetration Testing Your AWS Environment: A CTO's Guide
The Hacker News explains how AWS environment should assessed from the point of view of cybersecurity.
There are many options available, and knowing what you need will help you make your often limited security budget go as far as possible. Broadly, the key focus areas for most penetration testing projects involving AWS:
- Your externally accessible cloud infrastructure
- Any application(s) you're building or hosting
- Your internal cloud infrastructure
- Your AWS configuration itself
- Secrets management
Read further on The Hacker News