Outpost24 Discover our cybersecurity articles: Recent Episodes

None

View Details

Minimizing Intrusion Detection Time with Cyber Threat Intelligence 14.Jun.2023 Florian Barre Wed, 06/14/2023 - 07:02

Teaser With the increasing frequency of cyber-attacks, businesses need to prioritize proactive early incident detection. In this blog, we will highlight the significance of a high-quality threat intelligence solution in building a well-rounded and proactive defense strategy.

View Details

Outpost24 acquires external attack surface management provider Sweepatic to reduce risk exposure of internet facing assets 07.Jun.2023 Florian Barre Mon, 06/05/2023 - 08:00

Teaser Outpost24, a leading cybersecurity risk management platform, today announced the acquisition of Sweepatic.

View Details

Prioritizing Cybersecurity Risk with Vulnerability Prediction: Insights from Outpost24's Director of Product Management on Smashing Security

02.Jun.2023
Florian BarreFri, 06/02/2023 - 08:15
The Smashing Security podcast recently invited our Director of Product Management, John Stock, on to discuss our Vulnerability Prediction Technology (VPT) tool, the security challenges brought by remote work, and the importance of balancing risk management with business goals.

View Details

What is DORA? How to prepare your business for compliance

30.May.2023
Florian BarreTue, 05/30/2023 - 04:40
Designed to support the digital resiliency of financial institutions in the EU and UK, the Digital Operational Resilience Act is set to go in effect in January 2025. In this blog, we take a deep dive into what organizations must do in order to be compliant with this new legislation.

View Details

KrakenLabs' Threat Actors Naming Convention

09.May.2023
Florian BarreFri, 05/05/2023 - 03:54
Borja Rodriguez - Threat Hunting Team Lead at Outpost24
KrakenLabs has developed a new naming convention that uses poisonous plants to represent the origin and criminal activities of threat actors. This approach provides a creative way to classify different types of threat actors, allowing security professionals to quickly understand the nature and behavior of the threat actor, which is helpful for identifying and mitigating threats effectively.

View Details

What’s the difference: Vulnerability scanning vs Penetration testing

27.Apr.2023
Florian BarreThu, 04/27/2023 - 09:02
Vulnerability scanning and penetration testing should be an essential part of your cybersecurity strategy. This blog discusses the above methods in the context of securing your web applications, including the benefits, drawbacks, and compliance implications.

View Details

Outpost24 Expands Leadership Team by Appointing Brendan Hogan as Chief Strategy Officer

24.Apr.2023
Florian BarreMon, 04/24/2023 - 02:04
Outpost24, a leading innovator in cyber risk management, today announced it has appointed Brendan Hogan as Chief Strategy Officer (CSO). Hogan is responsible for spearheading M&A Strategy, Corporate Development and Alliance strategy for the company.

View Details

Does HIPAA require penetration testing?

14.Apr.2023
Florian BarreTue, 04/11/2023 - 09:51
The HIPAA Security Rule requires healthcare organizations to perform regular security risk assessments to protect e-PHI. Penetration testing can help organizations with this requirement.

View Details

Another Password Manager Breach: Practical Tips to Protect Stolen Credentials

05.Apr.2023
Florian BarreWed, 04/05/2023 - 04:22
In light of recent password manager breaches, our experts have provided tips on how to protect your organization from compromised credentials.

View Details

Everything you need to know about the LummaC2 stealer: Leveraging IDA Python and Unicorn to deobfuscate Windows API Hashing

05.Apr.2023
Florian BarreThu, 03/30/2023 - 02:23
Alberto Marín, KrakenLabs Malware Sandbox Lead
In this blog post, the KrakenLabs team will take a deep dive into a malware sample classified as LummaC2, an information stealer written in C language that has been sold in underground forums since December 2022. We assess LummaC2’s primary workflow, its different obfuscation techniques (like Windows API hashing and encoded strings) and how to overcome them to effectively analyze the malware with ease. We will also analyze how networking communications with the C2 work and summarize LummaC2’s MITRE Adversarial Tactics, Techniques and Common Knowledge.

View Details

The Russia-Ukraine crisis shakes up the cybercriminal ecosystem

02.Mar.2022
Florian BarreWed, 03/29/2023 - 02:56
Beatriz Pimenta Klein, Lidia López Sanz, and Maria Grozdanova, with the support of the Blueliv Labs team from Outpost24
In this article, we will highlight the most relevant threat actors and attacks that took place in late February 2022, categorizing threat actors according to their political alignment

View Details

Traffers and the growing threat against credentials

28.Mar.2023
Florian BarreWed, 03/22/2023 - 10:26
Beatriz Pimenta and Jacobo Blancas, KrakenLabs team
The Rising Threat of Traffers report, compiled by Outpost24’s Threat Intelligence team, KrakenLabs, provides a deep dive into the credential theft ecosystem, and encourages organizations to evaluate their security measures against these evolving threats.

View Details

Five key takeaways from Outpost24’s Cyber Resilience Day

09.Mar.2023
Florian BarreWed, 03/08/2023 - 10:09
True to its theme ‘Cyber Resilience’, our recent cyber security gathering was able to dissect the fast-moving threat landscape with insights and information nuggets from a panel of security experts and practitioners on the shortcomings and the need for better use of threat intelligence.

View Details

Account Takeover Vulnerability in Azure’s API Management Developer Portal

08.Mar.2023
Florian BarreTue, 03/07/2023 - 02:54
Tom Stacey, Application Security Auditor
How an Account Takeover vulnerability, discovered during a routine customer engagement, became a candidate for responsible disclosure, via the Microsoft Security Research Center Researcher Portal.

View Details

Responsible disclosure: Access control vulnerability discovered in the ThingsBoard IoT platform

28.Feb.2023
Florian BarreTue, 02/28/2023 - 02:12
Fotios Liatsis, Senior Security Consultant at Outpost24 | Ghost Labs

View Details

How to find and fix jQuery vulnerabilities

13.Feb.2023
Florian BarreMon, 02/06/2023 - 03:17
Using an outdated jQuery library can open up your web application to vulnerabilities. Read more to find out how to find and fix jQuery vulnerabilities.

View Details

Ransomware Report 2023: Targets, Motives, and Trends

07.Feb.2023
Florian BarreThu, 02/02/2023 - 04:42
Pol Casas, Jacobo Blancas & Alejandro Villanueva from the KrakenLabs team
Our annual Ransomware Report shares the latest trends and developments of the most active threat groups, and their victims to help businesses better protect themselves.

View Details

An analysis of a spam distribution botnet: the inner workings of Onliner Spambot

29.Jul.2019
Roman TaulerMon, 01/23/2023 - 05:33
Alberto Marín
Successful cybercrime campaigns make use of different elements working together to achieve their common goal. In the case of Onliner, the spambot appears to be a key piece of the puzzle in the distribution process. Many malware campaigns have been successful because the spamming process was so effective.

View Details

Cyber Threat Landscape Study 2023: Outpost24’s honeypot findings from over 42 million attacks

17.Jan.2023
Florian BarreFri, 01/13/2023 - 02:53
What are the most common cybersecurity threats facing your business? The 2023 Cyber Threat Landscape Study provides valuable threat intelligence to help you implement the appropriate security measures against real threats.

View Details

A Pen Tester’s Guide to Content Security Policy

10.Jan.2023
Florian BarreWed, 01/04/2023 - 08:53
Jimmy Bergqvist, Application Security Expert, Outpost24
In this article, we’ll look at Content Security Policy through the eyes of a penetration tester. We will outline the advantages of CSP, explain why you should have it on your site, and share some common misconfigurations that can be exploited, along with the relevant bypass scenarios.

View Details

2023 Cybersecurity Predictions

13.Dec.2022
Florian BarreTue, 12/13/2022 - 09:57
In light of the numerous large-scale cyberattacks witnessed in the last year, 2023 promises to be an exciting time for cybersecurity. Outpost24 experts share their thoughts on what we can expect in the new year, and how to best prepare against new threats.

View Details

ISO 27002 puts Threat Intelligence center stage

02.Dec.2022
Florian BarreFri, 12/02/2022 - 02:52
The updated ISO 27002 adds 11 new controls spanning a range of security services, including the addition of threat intelligence control 5.7.

View Details

Threat Actor of the Month - Shathak 19.Sep.2022 Florian Barre Mon, 09/19/2022 - 07:25

  • Threat Intelligence

Teaser Meet Shathak – a threat group tied to malware used in the Russian-speaking underground targeting enterprises across different sectors in the Americas, Europe and Asia

View Details

How Hive becomes one of the most dangerous ransomware group 25.Aug.2022 Florian Barre Tue, 08/23/2022 - 08:58 Jose Miguel Esparza, Head of Threat Intelligence

  • Threat Intelligence

Teaser The Hive Gang is a Ransomware as a Service (RaaS) providers first identified in June 2021. Although relatively new, their aggressive tactics and ever evolving malware variants have made them one of the most successful RaaS groups of its kind. Find out how the group has risen through the ranks with their advanced ransomware kit, API based portal and negotiation services.

View Details

Why do we need Vulnerability Management? 20.May.2016 sdfsdfsdfsdfs Fri, 10/20/2017 - 02:34 Victoria Sigurdsson

  • Network security

Teaser Our company already use Firewalls, Intrusion Detection Systems, and other Security Solutions. Why do we need Vulnerability Management?

View Details

Vulnerability Management for Beginners - Motor Vehicle Inspection 20.May.2016 sdfsdfsdfsdfs Fri, 10/20/2017 - 02:20 Nils Thulin

  • Network security

Teaser If you look at your company network as a company car you know that every now and then you will have to drive the car to the motor vehicle inspection.

After the inspection you get a list of what type of defects the car has and how severe the defects are.

View Details

Vulnerability Management for Beginners – Hole in the fence 24.May.2016 sdfsdfsdfsdfs Fri, 10/20/2017 - 02:14 Nils Thulin

  • Network security

Teaser If you had a valuable storage deposit with a fence around it would you not like to know if there was a hole in it?

View Details

Vulnerability Management – Business more secure 13.Jul.2016 sdfsdfsdfsdfs Fri, 10/20/2017 - 02:10 Nils Thulin

  • Network security

Teaser To work with Vulnerability Management is similar to preventing bad things to happen over time and is basically the exercise of limiting the chance of a breach by remediating vulnerabilities thereby reducing one’s overall risk level of being hacked.

View Details

Get ready for the attacks – Implement Vulnerability Management 20.Jul.2016 sdfsdfsdfsdfs Fri, 10/20/2017 - 02:05 Nils Thulin

  • Network security

Teaser Data breaches are nowadays a common factor risk but there are ways to reduce the risk. Know your assets and get on top of your infrastructure, even if you have Signature-Based Defences and Content-Based Protection you still need to work with updating and patching your systems.

View Details

Patch management is still an area of risk improvement 27.Jul.2016 sdfsdfsdfsdfs Thu, 10/19/2017 - 09:44 Nils Thulin

  • Network security

Teaser here are still serious exploits from 2010 that are not patched today...and even though solutions exists; a lot of organizations have not remediated those exploits why one should focus on Patch Management.

View Details

Business Smart Security – Moving forward 02.Aug.2016 sdfsdfsdfsdfs Thu, 10/19/2017 - 09:41 Nils Thulin

Teaser You hear about security issues and breaches so often that you have almost stopped listening to it ..until you are targeted by an attacker. It is actually not that hard to raise the bar if everyone just would do the basic security measures we would not hear so much about security issues.

View Details

Would you like extra bacon with that? 29.Sep.2016 sdfsdfsdfsdfs Thu, 10/19/2017 - 09:31 Niels Schweisshelm

Teaser Imagine heading to the office on Monday morning. The company you work for has been breached during the weekend and it’s your responsibility to notify the board members. You scroll through the e-mails you received from the security engineers and it turns out that an attacker has successfully compromised the enterprise network.

View Details

BMC Remedy vulnerabilities identified 19.Oct.2017 sdfsdfsdfsdfs Thu, 09/07/2017 - 04:53 Simon Rawet and Kristian Varnai

  • Application security

Teaser Security researchers from the Outpost24 SWAT team, Simon Rawet and Kristian Varnai, have identified and reported numerous vulnerabilities in BMC Remedy. The vulnerabilities range from relatively benign to full remote code execution without authentication.