Veeam Backup & Replication Vulnerability (CVE-2023-27532)
A vulnerability been found in Veeam Backup & Replication that enables an unauthenticated user to request encrypted credentials, which can give them access to server hosts used for backup infrastructure.
Citrix Gateway & Citrix ADC remote code exploit (CVE-2022-27518)
Apply latest patch to mitigate zero-day vulnerability CVE-2022-27518 — A vulnerability has been discovered in Citrix Gateway and Citrix ADC, listed below, that, if exploited, could allow an unauthenticated remote attacker to perform arbitrary code execution on the appliance.
Microsoft Making Hybrid Work More Secure with New Windows 11 Security Features
Microsoft is stepping up its game to protect Hybrid Workers from cyber threats. The new Windows 11 security features aim to address the ever-growing security concerns of hybrid workers. — What do these new features help with? Read more.
IT Security Alerts to Keep an Eye On: Spring4Shell, Citrix CVEs, iManage Certificate Expirations (April 2022)
Increase Cyber Vigilance as the Ukraine Conflict Escalates
iManage Security Vulnerability due to third-party Apache component Log4j
If not mitigated, potential remote exploits to an Apache component called Log4J can be executed by a malicious attacker. This vulnerability is known worldwide as CVE-2021-44228. Check this iManage Security Advisory.
Going Beyond Passwords
Passwordless Authentication simply means MFA without a password: authenticating with other methods other than a password, such as biometrics, one-off email, or phone verification. MFA is often thought of as a second factor -in addition to a password- typically tied to a phone and approved with a phone call, push, or temporary numerical code. But MFA is more than that.
Security Alert: New Malware called “FoggyWeb” enables hackers to steal Admin Credentials
Product Security Alert: Windows Print Spooler Remote Code Execution Vulnerability
#MicrosoftProductVulnerability # MicrosoftWindowsPrintSpooler #LegalTechnology
Cornerstone.IT Now NIST 800 171 Compliant
New York, NY, June 24, 2021 – Cornerstone.IT has taken security to the next level by adopting the National Institute of Standards and Technology (NIST) controls typically used for government agencies and Department of Defense contractors.