📰 Right Security Testing News
Right Security Testing News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Right Security Testing. Real-time updates on events, politics, business and more.
April 13, 2021
Diagram of attack scenario (Source: Forescout and JSOF) Forescout Research Labs and the Israeli security firm JSOF have found nine Domain Name System vulnerabilities affecting four TCP/IP stacks that, if exploited, could lead to remote code execution or denial-of-service attacks - potentially on millions of devices. The group of vulnerabilities, dubbed Name:Wreck, affects the FreeBSD, IPNet, NetX and Nucleus NET stacks. The widespread use of these stacks, together with external exposure of the...
February 4, 2021
Alejandro Mayorkas (right) is the new secretary of the Department of Homeland Security. (Photo: DHS) Alejandro Mayorkas, the newly confirmed secretary of the Department of Homeland Security, says his initial priorities include reviewing all available intelligence on the SolarWinds supply chain hack and scrutinizing the governments cybersecurity programs. Mayorkas, who previously served as the deputy secretary of Homeland Security during the Obama administration, also promised to strengthen th...
February 2, 2021
Get Permission Washington State Auditor Pat McCarthy says her office was not notified about a vulnerability in Accellions file transfer product. A data breach of a Washington state auditors system exposed 1.4 million unemployment claimants’ records. The breach involved exploiting a flaw in Accellions file transfer product, called File Transfer Appliance, and the state’s auditor says the office was never notified of the vulnerability and that a fix was available, the Seattle Times reports. ...
January 27, 2021
InfoRiskToday Compliance March 29, 2021 March 25, 2021 DougOlenick) • January 27, 2021 Get Permission The number of distributed denial-of-service attacks launched in 2020 surpassed 10 million, up from 8.5 million in 2019, according to NetScouts Atlas Security Engineering and Response Team. DDoS attacks are often waged as part of extortion campaigns, with hackers threatening to escalate attacks if a ransom is no...
January 18, 2021
Get Permission Virginia National Guard airmen guard the grounds of the U.S. Capitol. (U.S. Air National Guard photo by Staff Sgt. Bryan Myhr) The U.S. Capitol siege is being exploited for disinformation purposes ahead of Inauguration Day by Russia, Iran and China, intelligence officials warn. A "joint threat assessment" released on Thursday by the FBI, Department of Homeland Security and eight other agencies warns that "Russian, Iranian and Chinese influence actors have seized the opportunity ...
January 8, 2021
Get Permission The U.S. federal court system is investigating an "apparent compromise" of a confidential electronic filing system used for sensitive legal documents, according to the Administrative Office of the U.S. Courts. The courts also have suspended their use of the hacked SolarWinds Orion network monitoring platform. In addition, the courts are immediately changing their security procedures, temporarily accepting sensitive legal documents only on paper or via secure devices, such as thu...
January 8, 2021
U.S. Secretary of State Mike Pompeo The U.S. Department of State has announced plans to create a Bureau of Cyberspace Security and Emerging Technologies to enhance its security and help it deal with international cybersecurity issues. But it remains to be seen if those plans will be carried out by the incoming Biden administration, which has announced other cybersecurity steps. Secretary of State Mike Pompeo announced Thursday that he has directed the State Department to create the bureau. The ...
January 7, 2021
Get Permission Reacting to news reports claiming hackers may have used Czech software firm JetBrains’ TeamCity tool as an initial infection vector during the attack against SolarWinds, JetBrains CEO Maxim Shafirov says the company has not been contacted by investigators. But he says customer misconfiguration of TeamCity could have enabled a hack. "JetBrains has not taken part or been involved in this attack in any way," the CEO says. He adds, however, that "it’s important to stress that Te...
December 23, 2020
Retired Gen. Keith Alexander, president, IronNet Cybersecurity He has commanded armed forces and directed the National Security Agency. Now, hes president of vendor IronNet Cybersecurity. From this unique perspective, retired General Keith Alexander says the SolarWinds breach is "a call for action." Theres plenty of speculation about the breachs scope, damage and attribution. But its clear to Alexander that the U.S. public and private sectors have been dangerously exposed. "The breach highlight...
December 16, 2020
Get Permission The Russian hacking group suspected of leveraging a tainted SolarWinds software update to infiltrate as many as 18,000 organizations is presenting a forensics challenge unlike any other. To ensnare such a large group of private companies, government agencies and organizations is the equivalent of factory ocean trawler scraping the seabed. The question now for organizations is whether they were selected by the hackers for further probing, says Joe Slowik, senior security researc...