Articles of interest from the week of March 21, 2022
Browser-in-the-Browser Attack Makes Phishing Nearly Invisible Can we trust web browsers to protect us, even if they say “HTTPS?” Not with the novel...
24/7/365 Monitoring & Alerting
Compromise Assessments
Threat Hunting
Vulnerability Management
CMMC Preparation & Assessment
Cybersecurity Assurance Readiness (CSAR®/RMF Pro)
ATO/RMF Support
If you are concerned about a potential threat or are experiencing a breach, contact our 24/7/365 emergency hotline at 888-860-0452.
Sign up to receive our biweekly newsletter that covers what's happening in cybersecurity including news, trends, and thought leadership.
At our core, Ingalls is a company that strives to be helpful to our clients while continuously innovating and evolving our technology and solutions. Since 2010, we have been dedicated to building a team and product that can stay steps ahead of threats, attacks, and vulnerabilities in an ever-changing landscape.
1 min read
John Frasier : May 30, 2022 12:00:00 AM
A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. (By Zeljka Zorz, Help Net Security)
May has been another busy month of security updates, with Google’s Chrome browser and Android operating system, Zoom, and Apple’s iOS releasing patches to fix serious vulnerabilities. (By Kate O’Flaherty, WIRED)
CISA, the FBI, and National Security Agency (NSA), as well as cybersecurity authorities from Canada, New Zealand, the Netherlands, and the UK, have compiled a list of the main weak security controls, poor configurations, and poor security practices that defenders should implement to thwart initial access. It also contains the authorities' collective recommended mitigations. (By Liam Tung, ZDNet)
When it comes to ransomware, more companies are seeing attacks and have had data encrypted, according to research out this week. And even though more companies are backing up or paying ransom demands, less data was recovered in 2021 compared with the previous year. (Robert Lemos, Dark Reading)
Tax software vendor Intuit has warned that QuickBooks customers are being targeted in an ongoing series of phishing attacks impersonating the company and trying to lure them with fake account suspension warnings. (By Sergiu Gatlan, Bleeping Computer)
Browser-in-the-Browser Attack Makes Phishing Nearly Invisible Can we trust web browsers to protect us, even if they say “HTTPS?” Not with the novel...
Microsoft Confirms Two New Exchange Zero-Day Flaws Being Used in the Wild Microsoft officially disclosed it is investigating two zero-day security...
1 min read
U.S. Department of Justice Disrupts Hive Ransomware Variant The Justice Department announced last week its months-long disruption campaign against...