Tag: cyber risk
30 articles

Salesloft Drift integration: Risky Must-Have Fixes
A widely used Salesloft–Drift integration meant to speed workflows is being abused to pivot into Google Workspace accounts—now’s the time to audit OAuth permissions, enforce least privilege, and revoke any unnecessary app access before attackers do.

exploit code Exclusive: Risky Leak Spurs Policy Shift
After a SharePoint zero-day was weaponized, Microsoft quietly stopped sharing proof-of-concept exploit code with some Chinese firms — a pragmatic but politically fraught move that highlights the uneasy trade-off between helping defenders and giving attackers a roadmap. The incident makes clear we need faster patching, tighter disclosure controls, and better international norms to protect users without splintering cooperation.

SAP NetWeaver Critical Threat: Must-Have Patch Urgency
A public, weaponized exploit chaining two critical SAP NetWeaver flaws lets attackers bypass authentication and gain remote code execution. If you haven’t patched every NetWeaver instance, prioritize fixes, network segmentation and monitoring now to avoid data theft and disruption.

reducing cyber risk: Must-Have Culture for Best Defense
Technology can only take you so far—attackers now target people and culture, not just systems. Building a stronger security culture with clear policies, consistent training, and aligned incentives is the simplest, most effective way to cut cyber risk.

Equation Editor: Must-Have Fix for Risky Exploit
Eight years after Microsoft patched the Equation Editor, attackers are still exploiting CVE-2017-11882 to drop keyloggers and steal credentials from unpatched Office installs. If you haven’t audited Office versions or enforced updates and controls like EDR and MFA, now’s the time—old vulnerabilities keep paying off for attackers.

Charon ransomware: Stunningly Devastating Threat
A new ransomware called Charon is using APT-style stealth—DLL side‑loading and process injection—to strike Middle East public-sector and aviation systems, forcing a rethink of how we protect critical services. Assume attackers are getting smarter: prioritize EDR, MFA, network segmentation and practiced response plans to keep cities and flights safe.