Log4Shell (Dec 2021): The Vulnerability in Everything
On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...
Insights
Articles in Multi-Cloud.
On December 9, 2021, a critical vulnerability in Apache Log4j 2 — a Java logging library used in countless applications — became public. Tracked as...
When a library vulnerability like Log4Shell hits, the first question is "where are we affected?" Here is how to answer it across Azure and AWS workloads.
Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.
The short version: In December 2021, a flaw was found in Log4j, a small piece of free software used inside thousands of products. Companies spent weeks just...
On July 2, 2021 — the start of a US holiday weekend — the REvil ransomware group exploited a zero-day vulnerability in Kaseya VSA, a remote monitoring and...
Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.
MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.
The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to...
On May 7, 2021, Colonial Pipeline — which carries a large share of the fuel supply for the US East Coast — shut down its pipeline operations after a...
Colonial Pipeline and Change Healthcare were both breached through remote access accounts without MFA. Here is how to find accounts and access paths that...
Sign-ins without MFA to remote access systems are a leading ransomware entry point. These detections highlight them.
The short version: In 2021, Colonial Pipeline shut down fuel deliveries across the US East Coast after ransomware. The attackers got in through one old...
On May 12, 2021, President Biden signed Executive Order 14028, Improving the Nation's Cybersecurity, in response to SolarWinds, Microsoft Exchange...
"Zero trust" can sound abstract. In practice, it means verifying every access request based on identity, device and context — and limiting what each request...
Use this self-assessment to estimate your zero trust maturity across five pillars. Score each item: 0 = not started, 1 = partial, 2 = complete.
The short version: In 2021, a US executive order made "zero trust" official federal policy and required multi-factor authentication, encryption and better...
In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...
Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...
Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.
The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...
In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...
SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...
You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.
The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...