PrintNightmare, Vulnerability Affecting Windows Print Spooler Eleven years ago, an escalation of privilege bug in the Windows print spooler services was used in the Stuxnet attack, the notorious worm that destroyed the enrichment centrifuges of an Iranian Nuclear facility. Over the past eleven years, Microsoft's print spooler is still plagued by multiple vulnerabilities. Yesterday, proof-of-concept
On June 15, 2021 “The Securities and Exchange Commission (“SEC”) announced settled charges against real estate settlement services company First American Financial Corporation for disclosure controls and procedures violations related to a cybersecurity vulnerability that exposed sensitive customer information.” On May 24, 2019, Brian Krebs notified First American Financial Corporation of a vulnerability with its
- What is Ethical Hacking? Everything You Need to Know About Ethical Hacking—With Examples GalleryBusiness Email Compromise, Cloud, Cyber, Exploit, Hackers, Hedge Fund, Investment Adviser, Malware, Microsoft, Microsoft Windows 10, NTLM hash, OWASP, Password, Penetration Test, Phishing, Red Team, Technology, Vulnerability
Our founder Anand Mohabir was interviewed by Kindra Cooper, from Springboard, on the topic of Ethical hacking. “There’s a lot that comes into play when you’re trying to become an ethical hacker. You have to know how a network is designed and operated, how servers interact, how virtual machines, storage and firewalls work,” said Mohabir.
- 2021 SEC OCIE Cybersecurity Exam Priorities GalleryAlternative Asset Management, Awareness, Azure, BCP, BEC, Business Email Compromise, Cloud, coronavirus, Cyber, Exploit, Hackers, Hedge Fund, Identity Theft, Insider threats, Investment Adviser, Malware, OCIE, OWASP, Password, Penetration Test, Phishing, PII, Privacy, Private Equity, Regulatory, RIA, SEC, Table Top, Vulnerability, WFH, Work from home
Yesterday the U.S. Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations (OCIE) released its 2021 exam priorities. In the letter the SEC highlighted that their focus remains the same from prior years with a slight shift in priorities and adjustment of focus. The SEC stated that they will review whether firms have
CFTC issues an alert about potential Microsoft Azure and Office 365 compromise resulting from SolarWinds breach
On January 13, 2021, the Market Participant Division (MPD) of the CFTC sent an email to registrants informing them about an alert that was issued by the DHS Cybersecurity and Infrastructure Security Agency (CISA). In the alert CISA highlighted post compromise activity related to the SolarWinds Breach. More specifically, the alert highlighted that threat actors
- Solarwinds ORION delivers backdoor Trojan to worldwide networks GalleryAlternative Asset Management, Awareness, Cloud, Cyber, Exploit, Hackers, Hedge Fund, Identity Theft, Insider threats, Malware, Password, PII, Privacy, Remote Management, Reverse Shell, RMM, Vulnerability
Fireye detected that Solarwinds Orion is being used by attackers to steal sensitive company data. Fireye’s threat research division found that a highly sophisticated and evasive attacker compromised the Solarwind’s Orion IT monitoring and management platform to deliver a backdoor trojan. It is suspected that the campaign has started as early as April 2020 and
- Elteni is shortlisted for Best Cybersecurity Solution – 2021 Fund Intelligence Operations and Services Award Gallery
Elteni is shortlisted for Best Cybersecurity Solution – 2021 Fund Intelligence Operations and Services AwardAlternative Asset Management, Award, Cyber, Featured, Hedge Fund, Investment Adviser, Private Equity, Regulatory, RIA, Services, Technology
A Cayman Islands investment firm's backups stored in a Microsoft Azure Blob Storage was not secured properly thus resulting in a potential leak of personal banking information, individual passport data, and other sensitive information. A researcher discovered the gaping hole left open by the firm’s Hong Kong based IT provider via a special search engine
Yesterday The Office and Compliance Inspections and Examinations ("OCIE") issued an alert about safeguarding client accounts against credential compromise that highlighted the issue of "credential stuffing attacks". Credential stuffing is a type of cyber attack where many compromised user credentials are tried against systems to gain unauthorized access, using automated means. Over the past few
A service provider of SEI Investments Co., affected by a ransomware attack. SEI Investments Co., a fund administrator for several high-profile asset management firms experienced a breach, exposing the personal information of investors for approximately 100 clients. SEI stated that the breach occurred through one of their service providers that faced a ransomware attack. M.J.