News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Researcher: Cracked Cisco appliance and installed Doom on it 
B2B Cyber ​​Security ShortNews

Security researcher Aaron Thacker actually just wanted to build a server out of a Cisco appliance. He discovered a vulnerability in the web-based management interface of the Cisco Integrated Management Controller. He then installed Doom and played it as a demo in the management console. Security researcher Aaron Thacker only managed to hack a Cisco C195 Email Security Appliance, but the vulnerability affects a whole range of Cisco devices. Thacker just wanted to build a server out of the appliance and discovered the vulnerability during the conversion. He then started a chain of attacks: He changed the BIOS,…

Read more

Successful phishing: Attackers attack MFA service providers for Cisco Duo 
B2B Cyber ​​Security ShortNews

Cisco calls its Zero Trust security platform “Duo” for short. Their access is protected by state-of-the-art multi-factor authentication (MFA). Through a phishing attack on Cisco's service provider, attackers were able to access the provider and steal logs that contained information such as telephone numbers, network operators, countries and other metadata. Cisco has released a message informing about the incident affecting the Duo telephony provider. This provider is used by Duo to send MFA messages to customers via SMS and VOIP. Cisco is actively working with the vendor to investigate and resolve the incident….

Read more

These threats have shaped 2023
These threats have shaped 2023

In 2023, botnets returned from the dead, ransomware actors found creative ways to make money from theft, and threat actors that had been on the loose for a decade reinvented themselves to stay relevant. The threat intelligence experts at Cisco Talos have analyzed the key developments from 2023 and summarized them in an annual review that is worth reading. The standard work for the cybercrime year 2023 highlights the most important trends that shaped the threat landscape last year. Ransomware attack vector The greatest threat to companies in 2023 was still posed by ransomware. Already in the second year in…

Read more

Artificial intelligence: The most important trends in 2024
Artificial intelligence: These are the most important trends in 2024

Further developments in the area of ​​artificial intelligence pose both cybersecurity risks and opportunities for companies. Generative AI will become increasingly important, especially in business applications. AI technologies are developing at an unprecedented pace. The advances in artificial intelligence, especially generative AI (GenAI), open up new possibilities that will significantly change our economy, ways of working and living. However, the Cisco AI Readiness Index shows that although 95 percent of German companies have or are developing an AI strategy, only 7 percent are best prepared for the use of artificial intelligence...

Read more

Only 7 percent of German companies are prepared for AI
Only 7% of German companies are prepared for AI

8.000 managers in 30 countries took part in the “AI Readiness” study and commented on the use of AI in the company. Germany is ill-prepared. IT infrastructure and cybersecurity are cited as the highest priority areas for the use of AI. 14 percent of companies worldwide are fully prepared to use AI - in Germany only 7 percent. This is shown by Cisco's first AI Readiness Index, for which over 8.000 companies were surveyed, more than 300 in Germany alone. Compared to seven other EU countries and Great Britain, Germany is...

Read more

Learn to hack to prevent attacks
Learn to hack to prevent attacks

“Ethical hackers” hack into corporate networks to identify security holes before attackers find them. This can be learned in a course. Cyber ​​specialists are in short supply. Current studies assume a need for more than 100.000 security employees in companies and authorities - in Germany alone (Cybersecurity Workforce Study; (ISC)2 Research). They are urgently needed to build a resilient security structure for the business location. Hacking as a course offering cyber specialists also offers excellent prospects on the job market. One of the more unusual areas of activity in these future professions is “offensive cybersecurity” (OffSec). Here you will find…

Read more

Cisco: Web UI of IOS XE with 10.0 vulnerability
B2B Cyber ​​Security ShortNews

The BSI warns of an actively exploited vulnerability in the Cisco Web UI of IOS XE. The CVE-2023-20198 vulnerability has the highest CVSS score of 10.0 and is therefore critical. Many switches, routers and WLAN controllers are at risk. On October 16, Cisco released an advisory regarding an unpatched and actively exploited vulnerability in the Web UI of IOS XE. The vulnerability with the identifier CVE-2023-20198 allows remote, unauthenticated attackers to create new accounts (with level 15 access rights) on the affected system. Attackers are therefore able to take control of affected…

Read more

AI as a threat and opportunity for IT security
B2B Cyber ​​Security ShortNews

IT security is one of the areas that is currently being changed by AI. On the one hand, AI helps criminals make attacks more efficient, sophisticated, scalable and evade detection. On the other hand, security departments and law enforcement agencies receive new tools to detect and attribute illegal activities more effectively. Cisco Talos analyzed the current state of this race and identified the following trends: Increasing danger Thanks to AI, cybercriminals require fewer and fewer people and knowledge for attacks and software development. This both lowers barriers to entry, so that the number of criminals and attacks increases, and...

Read more

.ZIP domain: Hackers love the Google gift
B2B Cyber ​​Security ShortNews

Google has been marketing the new .zip domain (TLD) since the beginning of May. They cost as little as $15 a year, but could quickly make millions for cybercriminals. Since May 2023, more than 10.000 .ZIP domains have already been registered. Because: E-mail recipients think they see a ZIP file, but for them a link to a dangerous .zip website. Talos researchers took a closer look at the new .zip domains. Analyzing telemetry data, they've noticed patterns that don't bode well. Because the new ending seems to be attracting hackers across the board. The problem…

Read more

New Study: Web Shells Are Top Incidence Vector
New Study: Web Shells Are Top Incidence Vector

The number of attacks via web shells increased at an above-average rate in the first three months of 2023. The Cisco Talos Report shows that attacks via web shells are the new top attack vector in the first quarter of 1. Ransomware can be warded off better. According to Cisco Talos analysis, this type of attack was responsible for a quarter of all incidents investigated by the Incident Response Team in the first quarter of 2023. At the same time, the proportion of detected ransomware attacks fell from 2023% to 20%. However, the cyber researchers are not giving the all-clear: Because a fifth of all observed threat activities were…

Read more