Fortinet

FortinetSecurity

No Tears for WannaCry: Five Steps Every CISO Should Consider for Protecting Your Organization from Ransomware

Credit to Author: Phil Quade| Date: Mon, 15 May 2017 15:33:01 -0700

  Over the past few days WannaCry malicious malware variants affect hundreds of organizations across the world. This cyberattack spread primarily by exploiting a vulnerability whose manufacturer had issued a critical security update for over two months ago. While there are certainly reasons why it may take an organization some time to patch vulnerable systems, including the risk of updating live systems, two months should be plenty of time for any organization to take appropriate steps to secure their environment. With the recent malware…

Read More
FortinetSecurity

Service Provider Security in the Age of Digital Transformation

Credit to Author: Richard Orgias| Date: Mon, 15 May 2017 08:13:46 -0700

Digital Transformation is Happening Now Digital Transformation is a subject on the minds of CEOs everywhere as they seek to improve business results and align more closely with the needs and the expectations of their customers. And why not? Businesses large and small are adopting digital practices that a recent McKinsey study shows delivers, on average, five times more revenue and eight times more profitability than peer companies. The appeal of improved revenues, greater profitability, and higher levels of customer engagement underpins a shift…

Read More
FortinetSecurity

Deep Analysis of Esteemaudit

Credit to Author: Dehui Yin| Date: Thu, 11 May 2017 12:13:08 -0700

A Windows 2003 RDP Zero Day Exploit In this blog, the FortiGuard team takes a look at Esteemaudit, which is an exploit that was included in the set of cybertools leaked by the hacker group known as "Shadow Brokers." They claim that they collected this set of cybertools from the compromised data of "Equation Group," a threat actor alleged to be tied to the United States National Security Agency (NSA). Esteemaudit is a Remote Desktop Protocol (RDP) exploit that targets Microsoft Windows Server 2003 / Windows XP. The vulnerability…

Read More
FortinetSecurity

Byline: Security Platform vs. Security Fabric

Credit to Author: John Maddison| Date: Thu, 11 May 2017 06:42:08 -0700

Far too often, security tools are wrapped in marketing language that doesn’t always effectively communicate—or sometimes, even intentionally obscures—what a device or tool is able to do. Visit any security trade show and you are going to be overwhelmed by devices claiming to be “cloud enabled” or that offer “advanced threat intelligence.” But what do those terms mean? The same is true for entire classes of products.

Read More
FortinetSecurity

Security Research News in Brief – April 2017 Edition

Credit to Author: Axelle Apvrille| Date: Wed, 10 May 2017 09:08:47 -0700

Welcome back to our monthly review of some of the most interesting security research publications. Previous edition: March 2017   What happened to your home? IoT Hacking and Forensic with 0-day from TROOPERS 17, by Park and Jin Figure 1: Hacking a vacuum cleaner The authors hacked a vacuum cleaner, which, besides cleaning, also includes an embedded camera and microphone. The hack wasn’t easy because the vacuum wasn’t too badly secured. The authors however found 2 vectors: 1. They connected on the…

Read More