Active Zero-Day Attacks on SonicWall SMA1000: Act Now

Remote access solutions have been one of the preferred targets of cybercriminals for years. These solutions give employees, partners or external service providers access to internal company systems – but at the same time they also represent a particularly attractive entry point for attackers. If such a system is compromised, this can have far-reaching consequences for the entire IT infrastructure.

Critical vulnerabilities in UniFi OS are already being actively exploited

Multi-factor authentication (MFA) has been considered one of the most effective protection measures against account takeovers for years. Many organizations rely on an additional security feature — such as an authenticator app or SMS — to prevent threat actors from accessing corporate accounts.
But cybercriminals are constantly evolving their methods. With Kali365, security researchers and authorities are currently observing an attack method that shows that even proven protection mechanisms are not always sufficient. Companies that use Microsoft 365 in particular should follow developments closely and review their security measures.

New phishing scam bypasses MFA: Why Microsoft 365 users should be particularly attentive now

Multi-factor authentication (MFA) has been considered one of the most effective protection measures against account takeovers for years. Many organizations rely on an additional security feature — such as an authenticator app or SMS — to prevent threat actors from accessing corporate accounts.
But cybercriminals are constantly evolving their methods. With Kali365, security researchers and authorities are currently observing an attack method that shows that even proven protection mechanisms are not always sufficient. Companies that use Microsoft 365 in particular should follow developments closely and review their security measures.

The Ultimate Phishing Guide

We are all constantly confronted with spam and phishing in our professional and private lives. We smile at some attack attempts – but others are so sophisticated that they are not recognizable as cyberattacks at first glance.

In our guide “The Ultimate Phishing Guide”, we summarize our expert knowledge in a practice-oriented way so that you can quickly and easily recognize any phishing email on the one hand and build your technical protective wall in such a way that phishing emails don’t get through in the first place on the other.

Sextortion

Sextortion Sextortion is blackmail with the help of sexual content. Some people also call this type of attack the “porn scam”. In sextortion, criminals pretend to be in possession of juicy material from their victims and threaten to publish this information and data. Hence the name “sextortion”. It is made up of the English terms […]

Vishing

Vishing What is vishing? Vishing is a special form of phishing. Here too, the aim is to trick people into disclosing sensitive or confidential information. In contrast to the “conventional” phishing attack, in which victims are contacted by email, contact is made by telephone. Hence the name “vishing”. Here, the English term for voice and […]

Free guide: Vulnerabilities in Microsoft Exchange Server

It became known that critical security vulnerabilities have been found in the email transport server software “Microsoft Exchange Server”. The Perseus emergency aid was particularly used during this time. All the insights gained, concrete instructions for the right course of action during and after an incident as well as helpful tips on what you can do to secure your company even better can be found in the current white paper from Perseus.