Cyber Defense Advisors

Cyber Threat Trends

  • by
  • October 17, 2022

Zimbra Releases Patch for Actively Exploited Vulnerability in its Collaboration Suite

Zimbra has released patches to contain an actively exploited security flaw in its enterprise collaboration suite that could be leveraged to upload arbitrary files to vulnerable instances. Tracked as CVE-2022-41352 (CVSS score: 9.8), the issue affects a component of the Zimbra suite called Amavis, an open source content filter, and more specifically, the cpio utility it uses to scan and […]

Cyber News, Cyber Threat Trends

Stories from the SOC:  Feeling so foolish – SocGholish drive by compromise

Executive summary: SocGholish, also known as FakeUpdate, is a JavaScript framework leveraged in social engineering drive by compromises that has been a thorn in cybersecurity professionals’ and organizations’ sides for at least 5 years now. Upon visiting a compromised website, users are redirected to a page for a browser update and a zip archive file […]

Cyber News, Cyber Threat Trends

Top skill-building resources and advice for CISOs

The role of the CISO has evolved, and so have the responsibilities. Some believe a CISO must have technical knowledge and experience as a cybersecurity professional, others think leadership skills such as being able to communicate with boards are what matters most. Ultimately, the hiring organisations will define what it needs in terms of cybersecurity […]

Cyber News, Cyber Threat Trends

Global Cops Arrest Dozens Linked to Financial Crime Gang

Black Axe syndicate responsible for multimillion-dollar losses

Cyber News, Cyber Threat Trends

Spanish Police Bust Region’s “Biggest Narco Bank”

Underground organization said to have laundered €300m annually

Cyber News, Cyber Threat Trends

Hackney Council Ransomware Attack Cost £12m+

Local government’s travails highlight devastating impact of breaches

Cyber News, Cyber Threat Trends
  • by
  • October 17, 2022

INTERPOL-led Operation Takes Down ‘Black Axe’ Cyber Crime Organization

The International Criminal Police Organization, also called the Interpol, has announced the arrests of 75 individuals as part of a coordinated global operation against an organized cybercrime syndicate called Black Axe. “‘Black Axe’ and other West African organized crime groups have developed transnational networks, defrauding victims of millions while channeling their profits into lavish

Cyber News, Cyber Threat Trends

What is Spyware?

No one likes the feeling that someone is looking over their shoulder when they work, shop or surf online. But this is just what crooks and scammers do without our knowledge using “spyware.” Spyware is a piece of software that can covertly gather information on you. It can track the websites you visit and even […]

Cyber News, Cyber Threat Trends
  • by
  • October 16, 2022

Create a Per-User Secret in Secrets Manager: Part 1

User-Specific Secrets on AWS: IAM Policies ACM.82 IAM Policies to allow users to describe their own secrets This is a continuation of my series of posts on Automating Cybersecurity Metrics. In the last post, we created an SSH key for a user programatically. I created a policy for our Developer Group Role using the ${aws:username} parameter which […]

Cyber News, Cyber Threat Trends