News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Microsoft: 38 TB of data accidentally exposed
Microsoft: 38 TB of data accidentally exposed - Image by Mudassar Iqbal on Pixabay

The security provider Wiz found 38 TB of data including 30.000 internal Teams messages while browsing Microsoft's AI GitHub repository. According to Wiz, a SAS token misconfigured by the AI ​​research team triggered the issue. According to the Wiz Research Team, Microsoft's AI research team made a few glaring mistakes when publishing open source training data on GitHub. Apparently, when publishing data, a total of 38 terabytes of data was accidentally marked for publication and then published. Among them: private data, a hard drive backup of two employees' workstations. 38 TBytes of data including tokens, passwords and…

Read more

Cyber ​​resilience: How fatal are mistakes
Cyber ​​resilience: how fatal errors can be - Image by Gerd Altmann from Pixabay

The consequences of a cyber attack can be devastating. They range from financial loss to reputational damage to legal repercussions. And the risk increases. Three mistakes usually lead to high risk and damage from cyberattacks Recent studies confirm that ransomware attackers manage to encrypt the data in 71 percent of attacks and that paying a ransom doubles the overall recovery costs. In addition, data is stolen in 30 percent of ransomware attacks in Germany. Build strong cyber resilience The good news: Organizations can protect themselves against…

Read more

Bing & Office 365: Errors in Azure allow data theft
B2B Cyber ​​Security ShortNews

Microsoft has fallen victim to its own Azure Active Directory – AAD configuration challenges. Due to the misconfiguration, experts managed to add malicious code to some Bing search results, which exposed Microsoft 365 users. Wiz Research experts found the configuration errors and exploited them for testing. Microsoft rewarded the experts with a BugBounty and fixed the bugs immediately. What happened? The experts describe the incident: Manipulated Bing search results including malicious code “These applications allowed us to view and change various types of sensitive Microsoft data. In one particular case, we were unable to find search results on…

Read more

Researchers Discover Holey Web Application Firewalls (WAF)
B2B Cyber ​​Security ShortNews

Claroty security researchers have discovered ways to bypass Web Application Firewalls (WAF). A lack of JSON support allows attacks on potentially all providers. The providers Palo Alto Networks, Amazon Web Services, Cloudflare, F5 and Imperva have meanwhile updated their products. Security researchers from Team82, the research arm of cyber-physical systems (CPS) security specialists Claroty, have identified the possibility of a basic bypass of industry-leading web application firewalls (WAF). The attack technique involves appending JSON syntax to SQL injection payloads. Leading WAF Vendors Have Already Responded Although most database engines have supported JSON for a decade,…

Read more

The 10 biggest misconceptions about cyberattacks
The 10 biggest misconceptions about cyberattacks

Big or small, security flaws crop up in almost every company and organization that calls on the Sophos Rapid Response Team for help. The experts have summarized and evaluated the ten most common wrong arguments on the front lines against cyber attacks in the past year. “We're way too small! Our endpoint protection also keeps attackers away from the server! Our backups are safe from ransomware! ”- The Sophos Rapid Response team repeatedly encounters misjudgments in its fight against cyberattacks. Here is the list with the top 10. Mistake 1:…

Read more

Employees overestimate knowledge
Way guidance training

Home office and IT security: employees make 90 percent of mistakes because they are convinced that they are doing the right thing. Kaspersky training clearly shows that employees time and again overestimate their own knowledge. The free security training from Kaspersky and Area 9 Lyceum shows that employees overestimate their knowledge of IT security: although correct answers were given in two thirds of cases (66 percent), nine out of ten cases received the answer was wrong, but the employees are still convinced of their knowledge. The use of virtual machines, software updates and the reasons ...

Read more