Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware

September 30, 2024 at 01:06PM Summary: Cybersecurity teams are facing threats from “Storm-0501,” a ransomware group targeting vulnerable organizations in hybrid cloud environments. Microsoft reports that the group exploits weak passwords and overprivileged accounts to access cloud environments, using compromised credentials to extract data and spread ransomware. Security experts emphasize the importance of a zero-trust … Read more

Ivanti fixes maximum severity RCE bug in Endpoint Management software

September 10, 2024 at 03:37PM Ivanti has patched a critical vulnerability (CVE-2024-29847) in its Endpoint Management software that could allow unauthenticated attackers to execute remote code on the core server. The company has also addressed almost two dozen other high and critical severity flaws in its products. Ivanti has seen a rise in fixed flaws … Read more

Patch management still seemingly abysmal because no one wants the job

July 25, 2024 at 03:33AM Summary: Patching remains a challenging and laborious task for IT professionals, with low success rates and growing complexities from an increasing number of software applications and vulnerabilities. While automation tools and improved visibility in endpoint management products offer potential solutions, lack of ownership and reluctance to adopt new approaches are … Read more

Ivanti warns critical EPM bug lets hackers hijack enrolled devices

January 4, 2024 at 04:46PM Ivanti resolved a critical remote code execution (RCE) vulnerability in its Endpoint Management software (EPM), impacting all supported versions. Attackers on internal networks can exploit the flaw without requiring privileges or user interaction. Ivanti has prevented public access to full details on the vulnerability, aiming to provide customers with time … Read more

Open-Source Security Agents Promise Greater Simplicity, Flexibility

October 19, 2023 at 08:13AM Some security startups are building ecosystems around the open-source security agent osquery to reduce reliance on proprietary software and customize IT monitoring and security. Companies like Fleet, Wazuh, Kolide, Zentral, and Uptycs use or integrate with osquery to provide universal endpoint monitoring. The recent update by Fleet allows the agents … Read more

BlackBerry Unveils Next-Generation UEM Redefining the Endpoint Management Market

October 12, 2023 at 05:06PM BlackBerry has announced two new Unified Endpoint Management (UEM) innovations – BlackBerry UEM at the edge and BlackBerry UEM for IoT. BlackBerry UEM at the edge enhances enterprise productivity by placing workloads close to the end user, resulting in ultra-low latency connectivity. BlackBerry UEM for IoT enables organizations to manage … Read more