Articles of interest from the week of January 10, 2022
FTC to Go After Companies that Ignore Log4j Companies that fail to protect consumer data from Log4J attacks are at risk of facing Equifax-esque legal...
24/7/365 Monitoring & Alerting
Compromise Assessments
Threat Hunting
Vulnerability Management
CMMC Preparation & Assessment
Cybersecurity Assurance Readiness (CSAR®/RMF Pro)
ATO/RMF Support
If you are concerned about a potential threat or are experiencing a breach, contact our 24/7/365 emergency hotline at 888-860-0452.
Sign up to receive our biweekly newsletter that covers what's happening in cybersecurity including news, trends, and thought leadership.
At our core, Ingalls is a company that strives to be helpful to our clients while continuously innovating and evolving our technology and solutions. Since 2010, we have been dedicated to building a team and product that can stay steps ahead of threats, attacks, and vulnerabilities in an ever-changing landscape.
1 min read
John Frasier : Dec 13, 2021 12:00:00 AM
The Apache Software Foundation (ASF) has pushed out a new fix for the Log4j logging utility after the previous patch for the recently disclosed Log4Shell exploit was deemed as "incomplete in certain non-default configurations. (By Ravie Lakshmanan, The Hacker News)
Threat actors, including at least one nation-state actor, are attempting to exploit the newly disclosed Log4j flaw to deploy ransomware, remote access Trojans, and Web shells on vulnerable systems. All the while, organizations continue to download versions of the logging tool containing the vulnerability. (By Jai Vijayan, Dark Reading)
Microsoft has rolled out Patch Tuesday updates to address multiple security vulnerabilities in Windows and other software, including one actively exploited flaw that's being abused to deliver Emotet, TrickBot, or Bazaloader malware payloads. (By Ravie Lakshmanan, The Hacker News)
Ransomware is the flavor of the month for cybercriminals. The FBI reports that ransomware attacks rose 20% and losses almost tripled in 2020. And our increased use of the cloud may have played a part in that spike. A survey of CISOs conducted by IDC earlier this year found that 98% of their companies suffered at least one cloud data breach in the previous 18 months as opposed to 79% last year, and numbers got worse the more exposure they had to the cloud. (By Shai Morag, Dark Reading)
Kaspersky has discovered a malicious add-on for Microsoft's Internet Information Service (IIS) webserver software that it said is designed to harvest credentials from Outlook Web Access (OWA), the webmail client for Exchange and Office 365. (By Brandon Vigliarolo, TechRepublic)
FTC to Go After Companies that Ignore Log4j Companies that fail to protect consumer data from Log4J attacks are at risk of facing Equifax-esque legal...
1 min read
Healthcare Industry Witnessed 45% Spike in Cyber Attacks Since Nov 20 According to a new report published by Check Point Research today and shared...
Number of US Breach Victims Jumps 564% in Q1 2021 The number of publicly reported breach victims in the US has soared by 564% from the end of 2020 to...