<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/network-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Network-security ]]></title>
                <link>https://www.itpro.com/tag/network-security</link>
        <description><![CDATA[ All the latest network-security content from the ITPro team ]]></description>
                                    <lastBuildDate>Fri, 26 Sep 2025 10:29:11 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warnings ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/cisco-asa-customers-urged-to-take-immediate-action-as-ncsc-cisa-issue-critical-vulnerability-warnings</link>
                                                                            <description>
                            <![CDATA[ Cisco customers are urged to upgrade and secure systems immediately ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X3RPSiT74dQsebZ52iKP2E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Sep 2025 10:29:11 +0000</pubDate>                                                                                                                                <updated>Fri, 26 Sep 2025 10:29:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:description>                                                            <media:text><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Cisco, developer of the Cisco ASA (Adaptive Security Appliance) device range, pictured at Mobile World Congress Barcelona 2023.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tS8HTW7yrXNbExyfrJHDUN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security agencies are warning that hackers are exploiting vulnerabilities in <a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco </a>Adaptive Security Appliance (ASA) 5500-X Series devices to install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, execute commands, and steal data.</p><p>The first vulnerability, tracked as CVE-2025-20333, allows authenticated attackers to execute arbitrary code on devices using ASA and Firewall Threat Defense (FTD) software. </p><p>Meanwhile, a second vulnerability (CVE-2025-20362) allows them to access restricted URL endpoints without authentication.</p><div class="product"><a data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="e6ff6323-2156-449f-8eb6-ce8595c4e50b" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"In May 2025, Cisco was engaged by multiple government agencies that provide incident response services to government organizations to support the investigation of attacks that were targeting certain Cisco Adaptive Security Appliance (ASA) 5500-X Series devices that were running Cisco Secure Firewall ASA Software with <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN </a>web services enabled," the networking giant said in a <a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks" target="_blank">customer advisory.</a></p><p>"Attackers were observed to have exploited multiple zero-day vulnerabilities and employed advanced evasion techniques such as disabling logging, intercepting CLI commands, and intentionally crashing devices to prevent diagnostic analysis."</p><h2 id="cisa-ncsc-respond-to-cisco-asa-flaws">CISA, NCSC respond to Cisco ASA flaws</h2><p>According to the US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a>, the campaign is 'widespread' and connected with “ArcaneDoor” activity identified early last year</p><p>This threat campaign targeted perimeter network devices from several vendors, including Cisco, to deliver malware strains such as Line Runner and Line Dancer. </p><p>"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," the agency said. </p><p>The UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has also issued guidance in the wake of the exploitation. The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>agency noted that some Cisco ASA 5500-X series models will be out of support from September 2025 and August 2026. </p><p>With this in mind, enterprises using these models should take immediate action to mitigate potential risks. </p><p>“It is critical for organizations to take note of the recommended actions highlighted by Cisco today, particularly on detection and remediation,” said NCSC <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">chief technology officer</a> Ollie Whitehouse.</p><p>“We strongly encourage network defenders to follow vendor best practices and engage with the NCSC’s malware analysis report to assist with their investigations.</p><p>“End-of-life technology presents a significant risk for organisations. Systems and devices should be promptly migrated to modern versions to address vulnerabilities and strengthen resilience.”</p><h2 id="new-malware-strains-are-a-potent-threat">New malware strains are a potent threat</h2><p>New RayInitiator and Line Viper malware strains believed to be used in attacks represent a “significant evolution” on Line Dancer and Line Runner, the NCSC warned, particularly in terms of sophistication and their ability to evade detection. </p><p>CISA has now issued a directive ordering federal agencies - which have already been targeted - to identify, analyze, and mitigate potential compromises immediately.</p><p>"CISA is directing agencies to account for all Cisco ASA and Firepower devices, collect forensics and assess compromise via CISA-provided procedures and tools, disconnect end-of-support devices, and upgrade devices that will remain in service," it said. </p><p>"These actions are directed to address the immediate risk, assess compromise, and inform analysis of the ongoing threat actor campaign.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/networking/cisco-polishes-its-platform-but-the-network-is-still-king">Cisco polishes its platform but the network is still king</a></li><li><a href="https://www.itpro.com/security/cisco-cybersecurity-readiness-index-2025-ai">96% of businesses have low cyber-readiness, claims Cisco</a></li><li><a href="https://www.itpro.com/business/business-strategy/cisco-promises-ai-training-for-a-million-americans">Cisco promises AI training for a million Americans</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hackers are using an old Cisco flaw to target network devices – here’s how you can stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/networking/russian-hackers-are-using-an-old-cisco-flaw-to-target-network-devices-heres-how-you-can-stay-safe</link>
                                                                            <description>
                            <![CDATA[ With the aim of carrying out espionage, Russia's Center 16 is targeting infrastructure organizations around the world ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BLQQRourHjGWQnodMPmdyY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Aug 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:description>                                                            <media:text><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Russian government-linked hackers are exploiting unpatched <a href="https://www.itpro.com/infrastructure/networking/everything-you-need-to-know-about-cisco">Cisco </a>networking devices to spy on <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">critical infrastructure organizations</a>.</p><p>The attackers are mainly <a href="https://www.itpro.com/security/uk-cyber-experts-on-red-alert-after-salt-typhoon-attacks-on-us-telcos">targeting organizations in the telecommunications</a>, higher education and manufacturing sectors, with known victims in a number of geographic regions, including North America, Asia, Africa and Europe.</p><p>The group carrying out the attacks is believed to be part of the Russian Federal Security Service's (FSB) Center 16, and has a number of names, including Static Tundra, Berserk Bear, Energetic Bear and Dragonfly. </p><p>It's exploiting Simple Network Management Protocol (SNMP) and <a href="https://www.itpro.com/security/edge-devices-security-risk-leaders-do">end-of-life networking devices</a> running a seven-year-old unpatched vulnerability in Cisco Smart Install (SMI).</p><p>"For years, Static Tundra has been compromising Cisco devices by exploiting a previously disclosed vulnerability in the Smart Install feature of Cisco IOS software and Cisco IOS XE software (CVE-2018-0171) that has been left unpatched, often after those devices are end-of-life," said Cisco Talos researchers Sara McBroom and Brandon White in an <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank"><u>advisory</u></a>.</p><p>"We assess that the purpose of this campaign is to compromise and extract device configuration information en masse, which can later be leveraged as needed based on then-current strategic goals and interests of the Russian government. This is demonstrated by Static Tundra’s adaptation and shifts in operational focus as Russia’s priorities have changed over time."</p><p>Over the last year, the group has been spotted collecting configuration files for thousands of networking devices associated with US organizations across critical infrastructure sectors. </p><p>On some vulnerable devices, it modified these configuration files to enable unauthorized access, through which they then carried out reconnaissance in their victims' networks - revealing their interest in protocols and applications commonly associated with industrial control systems.</p><p>The group has been compromising network devices for more than ten years, focusing particularly on devices accepting legacy unencrypted protocols like SMI and SNMP versions 1 and 2. </p><p>It's also made use of custom tools against certain Cisco devices, such as the malware known as SYNful Knock in 2015.</p><p>"Once they establish initial access to a network device, Static Tundra will pivot further into the target environment, compromising additional network devices and establishing channels for long-term persistence and information gathering," said McBroom and White. </p><p>"This is demonstrated by the group’s ability to maintain access in target environments for multiple years without being detected."</p><p>Cisco Talos is urging customers to apply the patch for CVE-2018-0171 or, if that's not an option, to disable Smart Install.</p><p>"The threat extends beyond Russia's operations — other state-sponsored actors are likely conducting similar network device compromise campaigns, making comprehensive patching and security hardening critical for all organizations," McBroom and White warn.</p><p>"Threat actors will continue to abuse devices which remain unpatched and have Smart Install enabled."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/the-convergence-of-network-and-security-how-it-helps-achieve-business-outcomes">The convergence of network and security – how it helps achieve business outcomes</a></li><li><a href="https://www.itpro.com/security/midnight-blizzard-grapeloader-campaign">Russian hackers tried to lure diplomats with wine tasting</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach">‘All US forces must now assume their networks are compromised’ after Salt Typhoon breach</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Edge devices are now your weakest link: VPNs, firewalls, and routers were the leading source of initial compromise in 30% of incidents last year – here’s why ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/edge-devices-are-now-your-weakest-link-vpns-firewalls-and-routers-were-the-leading-source-of-initial-compromise-in-30-percent-of-incidents-last-year-heres-why</link>
                                                                            <description>
                            <![CDATA[ Compromised network edge devices have rapidly emerged as one of the biggest attack points for small and medium businesses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VUegmB9AzLZosktdmgsaQZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Apr 2025 09:18:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:description>                                                            <media:text><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Compromised network edge devices have rapidly emerged as one of the biggest attack points for small and medium businesses, prompting calls for firms to shore up defenses. </p><p>Statistics from Sophos’ <a href="https://news.sophos.com/en-us/2025/04/16/the-sophos-annual-threat-report-cybercrime-on-main-street-2025/"><em>Annual Threat Report</em></a> show <a href="https://www.itpro.com/security/data-protection/the-top-five-risks-of-perimeter-firewalls">firewalls</a>, routers, and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">VPNs </a>accounted for initial compromise in nearly 30% of all incidents observed by the firm over the last year. </p><p>Virtual private networks (VPNs) were cited as the most frequently compromised, accounting for over 25% of all incidents and also 25% of ransomware attacks. </p><p>What’s more, these figures come from cases that could be confirmed by telemetry, Sophos said, so the actual number of cases could be much higher. </p><p>Sean Gallagher, principal threat researcher at Sophos, said the report highlights how attackers have aggressively targeted edge devices over the last several years.</p><p>“Compounding the issue is the increasing number of end-of-life (EOL) devices found in the wild – a problem Sophos calls digital detritus,” he commented. </p><p>“Because these devices are exposed to the internet and often low on the patching priority list, they are a highly effective method for infiltrating networks.”</p><p>Gallagher added the aggressive targeting of edge devices forms part of a larger shift in cyber criminal tactics. In its report, Sophos said this means attackers don’t have to deploy custom <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and can employ ‘living off the land’ techniques to maximize their impact on target organizations.</p><p>“They can exploit businesses’ own systems, increasing their agility and hiding in the places security leaders aren’t looking,” Gallagher said. </p><p>Other popular attack methods highlighted in the report were social engineering via Software as a Service platforms. These widely-adopted platforms have become heavily abused products commonly used for initial compromise. </p><p>Business email compromise is also a growing concern, according to the report, attributing to an alarming rate of initial compromises in security incidents. </p><p>In these instances, malware deployment, credential theft, and <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135">social engineering</a> are being used extensively, the report warned. </p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing</a> of credentials via adversary-in-the-middle (AiTM) attacks and multi-factor authentication (MFA) token capture was cited as the main drivers of the increase.</p><p>AiTM attacks are a specific variant of the traditional 'man in the middle' attack method, whereby cyber criminals intercept communications between two parties to steal data. </p><p>This new type of attack differs greatly, however, enabling threat actors to actively interfere with and modify communications rather than simply intercepting them. </p><p>This particular method has been growing in popularity among threat groups in recent years, with state-backed threat actors in particular employing the technique. </p><p>In an advisory last year, Microsoft warned AiTM attacks have now become <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">one of the 'go-to' methods for cyber criminals</a>, with the tech giant's Digital Crimes Unit (DCU) observing a 146% increase across 2024. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li>Six of the <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">best malware removal services</a> you can use today</li><li>We ranked the <a href="https://www.itpro.com/security/27098/best-vpn-services">best VPNs for businesses</a></li><li>The <a href="https://www.itpro.com/networking/27835/best-wi-fi-routers">best Wi-Fi and access points</a> for your enterprise</li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HPE eyes enterprise data sovereignty gains with Aruba Networking Central expansion ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/networking/hpe-aruba-networking-central-updates</link>
                                                                            <description>
                            <![CDATA[ HPE has announced a sweeping expansion of its Aruba Networking Central platform, offering users a raft of new features focused on driving security and data sovereignty. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xzBeUv99EiFABAuCwLioLN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Apr 2025 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:description>                                                            <media:text><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/strategy/28233/everything-you-need-to-know-about-hpe">HPE</a> has announced a sweeping expansion of its Aruba Networking Central platform, offering users a raft of new features focused on driving security and data sovereignty. </p><p>As part of the move, users of the network management solution will be granted access to a <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/363449/aws-launches-five-new-bare-metal-instances-to-give">virtual private cloud (VPC) </a>environment aimed at shoring up <a href="https://www.itpro.com/security/data-protection/top-data-security-trends">data security</a> and meeting regulatory requirements, the company said. </p><p>This will be complemented by an on-premises option capable of operating while disconnected from the cloud. </p><p>Phil Mottram, EVP and general manager for HPE Aruba Networking, said the expansion comes in direct response to evolving enterprise needs with regard to data sovereignty. </p><p>Enterprises operating on both sides of the Atlantic, particularly in the European Union (EU), face strict rules governing the use, storage, and sharing of customer data. </p><p>“Organizations are increasingly prioritizing <a href="https://www.itpro.com/security/data-protection/data-sovereignty-a-growing-priority-for-uk-enterprises">data sovereignty</a>, requiring regional and local presence for mission-critical IT solutions,” he said. </p><p>“With these innovations, HPE now uniquely addresses the most pressing enterprise challenges for corporate, nonprofit, and government entities with unprecedented network management deployment flexibility.”</p><h2 id="hpe-aruba-networking-central-changes">HPE Aruba Networking Central changes</h2><p>As part of the expansion, <a href="https://www.itpro.com/infrastructure/networking/our-cloud-works-juniper-networks-exec-fires-shots-at-ciscos-networking-architecture-and-explains-hpes-acquisition-strategy-in-detail">HPE Aruba Networking Central</a> will gain four new deployment options. This means the solution can now be deployed in a cloud-delivered <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a>, VPC, on-prem, or NaaS format. </p><p>Similarly, integration of FIPS 140-2 certified hardware aims to help enterprises meet government security requirements and adhere to regulations including <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know">GDPR</a>.</p><p>Described as a “comprehensive networking management solution”, HPE said this will boost efficiency for use-cases such as <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>data capture, training, and inferencing - all of which typically require greater levels of control through air-gapped on-prem and cloud-based VPC options. </p><p>Underpinning this is the company’s GreenLake platform, which will provide enterprise users with local cloud options across a range of locations. </p><p>The firm is also keen to highlight gains made with regard to global points of presence (PoP), with dedicated instances now hosted in the US, Canada, EU, Middle East, Africa, Asia Pacific, and China. </p><h2 id="aiops-tools-look-to-drive-network-productivity">AIOps tools look to drive network productivity</h2><p>Elsewhere, other new features unveiled by HPE include the launch of automated network AIOps capabilities. </p><p>This will enable enterprises to continuously monitor critical wires and wireless network operations, optimize processes, and detect performance issues. </p><p>“A fabric of AI assistants acts as network architects, monitoring and gathering data, providing diagnostics and recommendations to extend existing capacity and performance, close security gaps, and identify configuration errors before they impact network operations,” the company said in an announcement. </p><p>“Combined with our continued innovation across AI, security and connectivity, HPE Aruba Networking Central continues to offer the most powerful and versatile network management application on the market, helping organizations meet their security, privacy and control requirements,” Mottram said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/data-centres/hpe-unveils-mod-pod-ai-data-center-in-a-box-at-nvidia-gtc">HPE unveils Mod Pod AI ‘data center-in-a-box’ at Nvidia GTC</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/what-hpes-results-say-about-the-direction-of-enterprise-ai">What HPE's results say about the direction of enterprise AI</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/hpe-s-one-click-ai-solution-for-private-cloud-cuts-project-times-from-months-to-a-single-moment">HPE’s ‘one-click AI solution’ for private cloud cuts project times from months to a ‘single moment’</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Billions of IoT devices will need to be secured in the next four years – zero trust could be the key to success ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/iot-security-zero-trust-architecture</link>
                                                                            <description>
                            <![CDATA[ Researchers have warned more than 28 billion IoT devices will need to be secured by 2028 as attacks on connected devices surge. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zpp4XSZpbQpqEGPdWupU84</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Feb 2025 09:00:00 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Feb 2025 12:40:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:description>                                                            <media:text><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT cybersecurity concept image showing a digitized padlock sitting on a blue circuit board atop network traffic.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/t5zGC2uXPBqGdnfQdHUCeS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With the number of <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT</a> devices expected to skyrocket in the next four years, researchers have called on more robust <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> protections to counter a wave of rising threats. </p><p>In a new <a href="https://www.juniperresearch.com/research/iot-emerging-technology/iot-security/iot-cybersecurity-market-report/?utm_source=vuelio&utm_medium=email&utm_id=pr2_iotcybersecurity_emerging_emerging_feb25" target="_blank"><u>study by Juniper Research</u></a>, the number of devices is set to hit 28 billion globally by 2028. However, amidst this sharp growth, the increasing complexity of IoT networks means there's a greater need for effective frameworks that underpin security solutions. </p><p>A key factor in this call to action is the fact that industry has a fragmented approach to <a href="https://www.itpro.com/cloud/cloud-security/iot-security-strategy-an-arms-race-for-businesses">IoT security</a>, researchers said. </p><p>"The IoT cybersecurity market is expected to reach $51 billion by 2028; partly driven by adoption from SMEs," said research author Michelle Joynson. </p><p>"To capitalize, vendors must simplify their solutions in a time when IoT architectures are becoming increasingly complex, and a greater number of connectivity technologies are used."</p><p>IDC advises enterprise IoT users to protect themselves against high-risk events such as data breaches, financial losses, and regulatory non-compliance by implementing <a href="https://www.itpro.com/security/what-is-zero-trust-network-access-ztna">zero trust architecture (ZTA)</a> frameworks as a priority. </p><p>"ZTA frameworks operate on the principle that no device on a network is to be inherently trusted; requiring constant authentication," said IDC. </p><p>"These frameworks also offer greater visibility of IoT device activity through continuous authentication; enabling earlier threat detection and mitigation."</p><p>As for vendors, the scale of expected IoT growth and rapid pace of digitalization by SMBs means these frameworks will need to be deployed across IoT networks of various sizes. </p><p>As the number of networks grows, vendors should be leveraging the scalability of their ZTA frameworks to make sure that cybersecurity solutions can keep pace. </p><h2 id="iot-remains-a-security-blind-spot-for-enterprises">IoT remains a security blind spot for enterprises</h2><p>IoT has become something of a wild west in terms of security, with connected devices representing the biggest targets in the UK last year. </p><p>Research from Beaming, for example, found there were at least 161 attacks on IoT devices per day, with threat actors increasingly targeting applications such as building control systems, network-enabled printers, <a href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools">remote monitoring tools</a>, and industrial control systems.  </p><p>According to the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, many devices aren't secure by design or by default, aren't given regular firmware updates, or have weak authentication measures with limited logging, making it hard to detect suspicious activity.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qQyHwhHoccvsxdAQrEgLgJ" name="Fortinet’s tested and validated architectures for cloud network security" caption="" alt="Fortinet’s tested and validated architectures for cloud network security" src="https://cdn.mos.cms.futurecdn.net/qQyHwhHoccvsxdAQrEgLgJ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/fortinets-tested-and-validated-architectures-for-cloud-network-security"><em>Speed up cloud deployment and improve security</em></a></p></div></div><p>Similarly, many may not be configured securely, lack proper network segmentation, or use unsupported or end-of-life (EOL) hardware.</p><p>Last year, analysis from WithSecure identified a steep rise in security incidents caused by the mass exploitation of IoT and edge devices, including <a href="https://www.itpro.com/security/why-the-moveit-breach-still-lives-rent-free-in-the-minds-of-it-leaders">MOVEit</a>, CitrixBleed, Cisco XE, <a href="https://www.itpro.com/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited">Fortinet’s FortiOS</a>, <a href="https://www.itpro.com/security/ivanti-connect-secure-flaws-have-been-targeted-250000-times-a-day-since-january-and-hackers-show-no-signs-of-stopping">Ivanti ConnectSecure</a>, Palo Alto’s PAN-OS, Juniper’s Junos, and <a href="https://www.itpro.com/security/ransomware/screenconnect-vulnerabilities-are-incredibly-trivial-to-exploit-researchers-warn">ConnectWise ScreenConnect</a>.</p><p>Earlier this month, the Five Eyes cybersecurity agencies released <a href="https://www.itpro.com/security/five-eyes-cyber-agencies-issue-guidance-on-edge-device-vulnerabilities">guidance on how to secure edge devices</a>, including IoT devices, recommending that they include and enable standard logging and forensic features that are robust and secure by default.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/infrastructure/internet-of-things/new-industry-backed-iot-security-standards-aim-to-improve-device-safety">New industry-backed IoT standards aim to bolster security</a></li><li><a href="https://www.itpro.com/security/implementing-zero-trust-with-the-internet-of-things-iot">Implementing zero trust with the Internet of Things</a></li><li><a href="https://www.itpro.com/internet-of-things-iot/30844/what-the-internet-of-things-iot-means-for-data-security">What the Internet of Things (IoT) means for data security</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cisco claims new smart switches provide next-level perimeter defense ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/firewalls/cisco-claims-new-smart-switches-provide-next-level-perimeter-defense</link>
                                                                            <description>
                            <![CDATA[ Cisco’s ‘security everywhere’ mantra has just taken on new meaning with the launch of a series of smart network switches. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TWrS5bmsAar3pPZ3HfWmMf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yNfyTfqotSJUNhETEb4zd3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Feb 2025 11:07:04 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Feb 2025 14:45:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Firewalls]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yNfyTfqotSJUNhETEb4zd3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital contour concept on dark background]]></media:description>                                                            <media:text><![CDATA[Digital contour concept on dark background]]></media:text>
                                <media:title type="plain"><![CDATA[Digital contour concept on dark background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yNfyTfqotSJUNhETEb4zd3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cisco’s <em>‘</em><a href="https://www.itpro.com/business/business-strategy/cisco-wants-integration-everywhere-all-at-once"><em>security everywhere</em></a><em>’</em> mantra has just taken on new meaning with the launch of a series of smart network switches it says will redefine the way firewalls, the old stalwart of cybersecurity, work entirely.</p><p>Unveiled at <a href="https://www.itpro.com/news/live/cisco-live-emea-2025-all-the-news-and-updates-as-they-happen">Cisco Live in Amsterdam</a>, Cisco said its N9300 Smart Switches will introduce new capabilities to help businesses defuse some of the lateral movement techniques used by the most sophisticated groups operating in today’s threat landscape.</p><p>The N9300 switches are equipped with data processing units (DPUs), that allow the for the deployment of advanced services such as <a href="https://www.itpro.com/security/cisco-launches-hypershield-a-must-have-solution-for-those-defending-against-iot-based-cyber-attacks">Cisco Hypershield</a> directly into the switching fabric.</p><p>Hypershield is a <a href="https://www.itpro.com/cloud/cloud-security/what-is-firewall-as-a-service-fwaas">firewalling capability</a> launched by Cisco in 2024 that enables the micro-segmentation of a network, but it required hardware with built-in DPUs, which did not exist at the time.</p><p>But now Cisco's souped-up N9300s don’t just switch traffic, they run services like Hypershield with high performance at high throughput rates.</p><p>The firm said that as customers upgrade their hardware the combination of its new switches and Hypershield will unlock unprecedented levels of protection at the data center and beyond.</p><h2 id="redefining-the-firewall">Redefining the firewall</h2><p>Speaking during a panel session on AI-ready data centers, Tom Gillis SVP and GM of the security, data center, internet, and cloud infrastructure group at Cisco, said the N9330 switches mean the firm is in a position to ‘redefine’ the way firewalls function in modern <a href="https://www.itpro.com/infrastructure/370352/ignoring-climate-change-wreak-havoc-uk-it-infrastructure">ICT infrastructure</a>.</p><p>“A firewall used to live in a box at the edge of the network. So with Cisco Hypershield we’ve taken that concept and broken it into a million little pieces. So instead of a box you try to shield at the edge, you have the ability to put a <a href="https://www.itpro.com/security/does-every-business-need-zero-trust">micro perimeter</a> at each one of those services that make up an application.”</p><p>Gillis explained that Cisco is leveraging its in-house switching ASIC, Silicon One, to enable the performance required to deliver advanced inspection at every connection across distributed applications with minimal orchestration.</p><p>“The net of this is that it lets folks like you put firewalls in places you couldn’t even imagine. You don’t have to cable up an appliance, you don’t have to write a bunch of rules, and here’s the best plus: it’s dynamic and upgrading itself.”</p><p>Cisco’s unified <a href="https://www.itpro.com/security/366127/breaking-the-channel-mould-with-firewall-management">firewall management system</a>, Secure Firewall, enables automated deployment of firewalls to the cloud that can be managed centrally, scaled up automatically, and are ‘self-healing’.</p><p>‘Self-healing’ refers to the fact that if the firewall detects any type of failure, Cisco Security Cloud will take that image down, redeploy a new image, and sync it back with the cluster.</p><p>Automating the deployment, scaling, and upkeep of these appliances will be increasingly important if firms are to rigorously segment their increasingly distributed and fine-grained application ecosystems, which are often made up of thousands of microservices running across <a href="https://www.itpro.com/cloud/34476/what-is-multi-cloud">multi-cloud services</a>.</p><h2 id="neutralizing-the-typhoon">Neutralizing the Typhoon</h2><p>Cisco emphasised that this is a significant step forward for the securing applications, and network security more broadly.</p><p>In recent years, <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">state-sponsored threat actors</a> have been found targeting complex vulnerabilities in network infrastructure and using that to establish persistence on sensitive enterprise and government networks.</p><p>The various groups tracked under the <a href="https://www.itpro.com/security/uk-cyber-experts-on-red-alert-after-salt-typhoon-attacks-on-us-telcos">Typhoon</a> moniker in Microsoft’s threat actor taxonomy - and thought to be based in China - have been responsible for a number of highly sophisticated attacks on critical national infrastructure and government institutions in the US.</p><p>In December, a senior White House security official confirmed that the <a href="https://www.itpro.com/security/cyber-attacks/salt-typhoon-hacker-group-recorded-conversations-of-very-senior-us-political-figures">Salt Typhoon group was able to record conversations of senior political operators</a> in the US after hacking several major telecom providers in the region.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="3cvMNbN3QogMsPACwHfYdc" name="Making cloud accessible and affordable for small businesses" caption="" alt="Making cloud accessible and affordable for small businesses" src="https://cdn.mos.cms.futurecdn.net/3cvMNbN3QogMsPACwHfYdc.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ANS)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/making-cloud-accessible-and-affordable-for-small-businesses"><em>Removing the barriers to growth</em></a></p></div></div><p>Last month, the <a href="https://www.itpro.com/security/us-sanctions-chinese-tech-firm-that-targets-critical-infrastructure">Treasury imposed sanctions on several Chinese firms</a> accused of having some role in recent cyber intrusions attributed to the Flax Typhoon group.</p><p>Speaking to <em>ITPro, </em>Martin Lee, technical lead of security research at <a href="https://www.itpro.com/security/data-breaches/368794/cisco-talos-confirms-data-breach-ransomware-gang">Talos</a>, Cisco’s threat intelligence arm, described this type of activity, noting that threat actors have been observed using complex techniques to compromise network devices and using these as ingress points on the network.</p><p>“If you can find your way in through the <a href="https://www.itpro.com/infrastructure/359386/governments-rural-network-infrastructure-plans-ignore-businesses-claims-three">network infrastructure</a>, you can then get inside of your environment and use that target device as a platform to launch attacks against the target systems,” he explained.</p><p>“This kind of threat actor and this kind of activity underlines why getting the network architecture and segmentation right is so important. If they’ve managed to compromise one environment, you’re forcing them to do work to compromise the other one and it’s that work that is the noise that you can detect.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cisco-is-jailbreaking-ai-models-so-you-dont-have-to-worry-about-it">Cisco is jailbreaking AI models so you don't have to worry about security</a></li><li><a href="https://www.itpro.com/infrastructure/networking/cisco-polishes-its-platform-but-the-network-is-still-king">Networking is still king as Cisco polishes its network capabilities</a></li><li><a href="https://www.itpro.com/business/business-strategy/ciscos-savvy-coreweave-deal-will-supercharge-its-ai-ambitions">Cisco's 'savvy' CoreWeave deal will supercharge its AI ambitions</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five Eyes cyber agencies issue guidance on edge device vulnerabilities ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/five-eyes-cyber-agencies-issue-guidance-on-edge-device-vulnerabilities</link>
                                                                            <description>
                            <![CDATA[ Cybersecurity agencies including the NCSC and CISA have issued fresh guidance on edge device security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">44gupsKEJXkvZessyUyQnN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Feb 2025 08:20:00 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Feb 2025 14:34:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:description>                                                            <media:text><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:text>
                                <media:title type="plain"><![CDATA[ Future technology background glowing futuristic globe HUD, digital data flowing and network structure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/As3sJhQBLWiw9GhuFnV3f6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A host of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> agencies have teamed up to offer guidance on how to secure edge devices from ever-increasing threats.</p><p>The advice covers network edge devices and appliances, such as firewalls, routers, <a href="https://www.itpro.com/security/27098/best-vpn-services">virtual private networks (VPN)</a> gateways, <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">Internet of Things (IoT)</a> devices, internet-facing servers and internet-facing <a href="https://www.itpro.com/security/364189/from-it-to-ot-whats-the-partner-opportunity">operational technology (OT)</a> systems. </p><p>Issued by the UK's <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, <a href="https://www.itpro.com/security/what-is-cisa">CISA</a>, and agencies in Australia, Canada, New Zealand, and the US, the guidelines encourage device manufacturers to include and enable standard logging and forensic features that are robust and secure by default. </p><p>This, the NCSC points out, should make it easier for network defenders to detect malicious activity and investigate following an intrusion. </p><p>The <a href="https://www.ncsc.gov.uk/guidance/guidance-on-digital-forensics-protective-monitoring"><u>guidelines</u></a> also set out a set of minimum standards for forensic visibility to help network defenders secure organizational networks, both proactively and when responding to a compromise.</p><p>"In the face of a relentless wave of intrusions involving network devices globally our new guidance sets what we collectively see as the standard required to meet the contemporary threat," said NCSC technical director <a href="https://www.itpro.com/business/public-sector/uks-ncsc-names-ollie-whitehouse-as-its-new-cto">Ollie Whitehouse</a>.</p><p>"In doing so, we are giving manufacturers and their customers the tools to ensure products not only defend against <a href="https://www.itpro.com/security/cyber-attacks">cyber attacks</a> but also provide investigative capabilities post-intrusion."</p><p>The NCSC said malicious actors are increasingly exploiting vulnerabilities and insecure design features to gain and maintain valuable accesses. Devices often aren't secure by design or by default, aren't given regular firmware updates, or have weak authentication measures with limited logging, making it hard to detect suspicious activity. </p><p>Similarly, many may not be configured securely, lack proper network segmentation, and use unsupported or <a href="https://www.itpro.com/software/windows/windows-10-end-of-life-could-prompt-torrent-of-e-waste-as-240-million-devices-set-for-scrapheap">end-of-life (EOL) hardware</a>, thereby increasing their vulnerability to exploitation. </p><p>Last summer, a report from WithSecure identified the mass exploitation of edge services as the year's prevailing trend for attackers.</p><p>The year saw a sharp rise in security incidents caused by the mass exploitation of edge devices, including such as <a href="https://www.itpro.com/security/a-new-critical-moveit-vulnerability-is-being-exploited-by-hackers-heres-what-you-need-to-know">MOVEit</a>, CitrixBleed, Cisco XE, Fortinet’s <a href="https://www.itpro.com/security/cyber-security/359119/us-agencies-warn-of-fortinet-fortios-vulnerabilities-being-exploited">FortiOS</a>, <a href="https://www.itpro.com/security/ivanti-connect-secure-flaws-have-been-targeted-250000-times-a-day-since-january-and-hackers-show-no-signs-of-stopping">Ivanti ConnectSecure</a>, Palo Alto’s PAN-OS, Juniper’s Junos, and Con<a href="https://www.itpro.com/security/ransomware/screenconnect-vulnerabilities-are-incredibly-trivial-to-exploit-researchers-warn">nectWise ScreenConnect</a>.  </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nMPk3hYgRaNUm4dqd8ZtSQ" name="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission" caption="" alt="Discover how these data centers from Germany and Australia became more resilient to disruption, while also lowering operating costs and CO2 emission." src="https://cdn.mos.cms.futurecdn.net/nMPk3hYgRaNUm4dqd8ZtSQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ABB)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/discover-how-these-data-centers-from-germany-and-australia-became-more-resilient-to-disruption-while-also-lowering-operating-costs-and-co2-emission"><em>Data centers fortified with robust maintenance</em></a></p></div></div><p>The number of edge service and infrastructure Common Vulnerabilities and Exposures (CVEs) added to the Known Exploited Vulnerability Catalogue (KEV) was 22% higher than in 2023.</p><p>Juliette Hudson, CTO of CybaVerse, said the new guidance is much needed given the scale of threats facing edge devices currently.</p><p>"These are guidelines that shouldn't be ignored, because when edge devices are insecure, the entire networks they run within are at heightened exposure to attack. Today, all businesses are digital businesses, where they rely on smart devices and the internet to deliver services, but this expands the enterprise attack surface," she said.</p><p>"Having good visibility across network assets and running proactive monitoring for threats are essential, but device manufacturers also have a key role to play, and it is essential they practice good security hygiene in the development process."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/five-eyes-advisory-raises-alarm-over-state-backed-living-off-the-land-attacks">Five Eyes raises alarm over 'living off the land' attacks</a></li><li><a href="https://www.itpro.com/internet-of-things-iot/34509/how-edge-computing-can-benefit-businesses">How edge computing can benefit businesses</a></li><li><a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368117/best-enterprise-vpn-of-2022">Check out the best VPNs for enterprises</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ T-Mobile security chief insists its defenses stood up to attacks linked to Salt Typhoon ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/t-mobile-security-chief-insists-its-defenses-stood-up-to-attacks-linked-to-salt-typhoon</link>
                                                                            <description>
                            <![CDATA[ No T-Mobile customers or services were affected after its security teams detected suspicious activity on their routers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aiTPnuhicTQ3MebNb5CXpD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Z97bFeonHiHPpBZpBgncG6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Nov 2024 11:02:48 +0000</pubDate>                                                                                                                                <updated>Thu, 28 Nov 2024 16:37:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Z97bFeonHiHPpBZpBgncG6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Night shot of the T-Mobile headquarters in Bellevue, Washington, US, lit up in pink.]]></media:description>                                                            <media:text><![CDATA[Night shot of the T-Mobile headquarters in Bellevue, Washington, US, lit up in pink.]]></media:text>
                                <media:title type="plain"><![CDATA[Night shot of the T-Mobile headquarters in Bellevue, Washington, US, lit up in pink.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Z97bFeonHiHPpBZpBgncG6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-attacks/t-mobiles-vm-logs-allegedly-leaked-in-20-gb-capgemini-data-breach">T-Mobile</a> was able to protect sensitive customer information and prevent disruption to its services after detecting malicious attempts to infiltrate its systems, according to its security chief.</p><p>Jeff Simon, <a href="https://www.itpro.com/security/data-breaches/368386/former-uber-security-chief-to-face-fraud-charges-over-hack-coverup">chief security officer</a> at T-Mobile, published an <a href="https://www.t-mobile.com/news/un-carrier/update-cyberattacks-targeting-us-wireless-companies" target="_blank">update</a> on a string of recent cyber attacks targeting wireless companies, believed to be orchestrated by the Salt Typhoon group.</p><p>The update states that the attacks originated from the network one of T-Mobile’s wireline providers it was connected to, but Simon said connectivity to the provider’s network, which may still be compromised, was quickly severed.</p><p>Simon noted that unlike other providers, and despite media reporting, T-Mobile’s customer information was not impacted.</p><p>“Many reports claim these bad actors have gained access to some providers’ customer information over an extended period of time – <a href="https://www.itpro.com/security/cyber-security/361889/t-mobile-scam-calls-hit-an-all-time-high-in-2021">phone calls</a>, <a href="https://www.itpro.com/608649/text-messages-to-break-stolen-laptops">text messages</a>, and other sensitive information, particularly from government officials. This is not the case at T-Mobile,” he wrote.</p><p>“Our defenses protected our sensitive customer information, prevented any disruption of our services, and stopped the attack from advancing. Bad actors had no access to sensitive customer data (including calls, <a href="https://www.itpro.com/610073/spinvox-and-skype-cosy-up-on-voicemail">voicemails</a> or texts).”</p><p>Speaking to <a href="https://news.bloomberglaw.com/us-law-week/t-mobile-engineers-spotted-hackers-running-commands-on-routers" target="_blank"><em>Bloomberg</em></a>, Simon said T-Mobile’s network engineers discovered the attack after noticing suspicious behavior on some of the company’s network devices.</p><p>The behavior wasn’t “inherently malicious” but may have been used to gain a clearer understanding of the company's corporate network, with threat actors probing for potential <a href="https://www.itpro.com/security/network-security/369481/vmware-brings-xdr-to-carbon-black-push-lateral-security">lateral movement</a> opportunities.</p><p>Simon stated that T-Mobile’s layered network design, featuring <a href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">network segmentation</a> and robust monitoring, partnerships with third-party cyber experts, and its swift response all helped to  prevent the attackers from causing further damage.</p><h2 id="salt-typhoon-is-on-a-rampage">Salt Typhoon is on a rampage</h2><p>Although T-Mobile were unable to “definitively identify” the attacker’s identity, the behavior is consistent with previous attacks leveraged by the Salt Typhoon group.</p><p><a href="https://www.itpro.com/tag/trend-micro">Trend Micro</a> published a <a href="https://www.trendmicro.com/en_us/research/24/k/earth-estries.html" target="_blank">report</a> on 25 November detailing previous activity of Salt Typhoon, also known as Earth Estries, Ghost Emperor, or UNC2286).</p><p>The report stated the group has primarily targeted <a href="https://www.itpro.com/security/these-three-critical-sectors-are-riddled-with-high-risk-vulnerabilities">critical sectors</a> such as telecommunications and government entities across the <a href="https://www.itpro.com/business/policy-and-legislation/sec-passes-rules-compelling-us-public-companies-to-report-data-breaches-within-four-days">US</a>, Asia, <a href="https://www.itpro.com/business/business-strategy/365615/kenna-security-pushes-into-europe-the-middle-east-and-africa">Middle East</a>, and <a href="https://www.itpro.com/server-storage/data-centres/369705/equinix-invests-160-million-in-south-africa-data-centre">South Africa</a> since 2023 and potentially even earlier.</p><p>“The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian <a href="https://www.itpro.com/business/business-strategy/epsilon-telecommunications-appoints-new-group-ceo">telecommunications</a> companies and government entities,” Trend Micro outlined.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="r6TdD5pcpfowGKcw5BioJF" name="Harness increased performance, efficiency, and lower TCO with Dell PowerEdge powered by AMD" caption="" alt="Harness increased performance, efficiency, and lower TCO with Dell PowerEdge powered by AMD" src="https://cdn.mos.cms.futurecdn.net/r6TdD5pcpfowGKcw5BioJF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/servers-and-storage/harness-increased-performance-efficiency-and-lower-tco-with-dell-poweredge-powered-by-amd"><em>The benefits of a server refresh</em></a></p></div></div><p>“Earth Estries exploits public-facing server vulnerabilities to establish initial access and uses <a href="https://www.itpro.com/security/living-off-the-land-attacks">living-off-the-land</a> binaries for lateral movement within networks to deploy malware and conduct long-term espionage.”</p><p>According to the report, the group has compromised over 20 organizations in the telecommunications, technology, consulting, chemical, and <a href="https://www.itpro.com/security/data-breaches/breach-at-us-transportation-department-exposes-240000-employee-records">transportation</a> industries, as well as government agencies.</p><p>Reports of Salt Typhoon infiltrating internet service providers (ISPs) in the US came out in September 2024, with the <em>Wall Street Journal </em><a href="https://www.wsj.com/tech/cybersecurity/u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b" target="_blank">confirming</a> in October that major players <a href="https://www.itpro.com/security/data-breaches/the-verizon-data-breach-that-exposed-63000-employees-is-a-reminder-of-how-a-simple-mistake-can-have-costly-implications">Verizon</a> Communications, <a href="https://www.itpro.com/security/everything-you-need-to-know-about-the-atandt-data-breach">AT&T</a>, and Lumen Technologies were among a list of companies whose networks were breached.</p><p>Unnamed sources familiar with the matter told the<em>WSJ </em>that<em> </em>the access may have allowed the group to access information from systems the federal government uses for court-authorized <a href="https://www.itpro.com/security/spyware/370302/greek-intelligence-predator-spyware-wiretap-facebook-staffer">wiretapping</a>, describing the compromise as "potentially catastrophic”.</p><p>T-Mobile appears to have avoided the worst impacts of Salt Typhoon’s campaign, according to Simon, who added that he had recently attended a meeting of leaders at the White House to discuss how the industry can work together to mitigate the threats the group pose and avoid further damage.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Check Point acquires Perimeter 81 in push to meet SASE demand   ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/acquisition/check-point-acquires-perimeter-81-in-push-to-meet-sase-demand</link>
                                                                            <description>
                            <![CDATA[ The half-billion dollar deal greatly expands Check Point’s service edge offering ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pzMmgdi7XgYXJPiniUWALg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Aug 2023 15:31:48 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Aug 2023 15:14:46 +0000</updated>
                                                                                                                                            <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg">
                                                            <media:credit><![CDATA[Check Point]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:description>                                                            <media:text><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:text>
                                <media:title type="plain"><![CDATA[The Check Point logo (A stylized pink circle with a series of three nodes drawn against it in white to produce a curcular cutout effect in the top right hand corner of the circle, with a black circle to the top and right of this and the words CHECK POINT to the right of it in black text) against a white background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qyypwQ53tpVe4zWHhQg9ne-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security firm Check Point has announced the acquisition of network security firm Perimeter 81 for $490 million.</p><p>The acquisition comes as Check Point looks to widen its range of security service edge (SSE) and secure access service edge (SASE) offerings to serve a growing market of remote users, cloud, and data centers in need of secure access.</p><p>Check Point said it identified Perimeter 81 as a world leader in SASE solutions, with a market-leading approach to on-prem and <a href="https://www.itpro.com/cloud-security/34458/what-is-cloud-security"><u>cloud security</u></a>. It aims to integrate the firm’s offerings within its wide range of products and services to offer the most secure</p><p>Perimeter 81’s approach to <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a> access and mesh connectivity was specifically noted by Check Point in its post on the acquisition, with both linked to the secure and seamless remote browsing that Check Point aims to provide for its customers.</p><p>The acquisition is expected to close in Q3 2023, subject to normal close proceedings. It will be completed in cash and debt-free.</p><p>Gartner has <a href="https://blogs.gartner.com/andrew-lerner/2022/12/20/networking-investments-for-2023-and-beyond/" target="_blank"><u>predicted</u></a> that by 2025, 65% of enterprises will group their SASE components such as <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan"><u>SD-WAN</u></a> under dedicated SASE vendors, compared to 15% in 2021.</p><p>“With the advent of <a href="https://www.itpro.com/business-strategy/flexible-working/369931/turning-back-the-clock-on-hybrid-work-is-a-huge-mistake"><u>hybrid work</u></a> and the rise of <a href="https://www.itpro.com/cloud/369991/only-10-businesses-benefitting-from-cloud-technology"><u>cloud transformation</u></a>, the demand for security services that expand beyond the network perimeter is increasing,” said Gil Shwed, CEO at Check Point Software Technologies. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BGMShiXj4N58xh9zNYcDCk" name="Defence in depth_thumb.jpg" caption="" alt="Whitepaper cover with title over purple shaded image of female worker peering over the top of an office cubicle" src="https://cdn.mos.cms.futurecdn.net/BGMShiXj4N58xh9zNYcDCk.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><em>Email is the most widely used business application and its vulnerable to cyber attacks. Learn how you can close the gap in your your Microsoft 365 security.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/microsoft-office/356963/defence-in-depth-closing-the-gaps-in-microsoft-365-security"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>"By leveraging Perimeter 81´s capabilities and integrating them into the Check Point Infinity platform we continue with our vision to deliver the best security through comprehensive, collaborative and consolidated solutions.”</p><p>Perimeter 81 currently has more than 200 employees worldwide, in comparison to Check Point’s 6,000. It is based in Tel Aviv, the site of Check Point’s international headquarters.</p><p>It currently offers a unified security stack through which it states customers can use to easily deploy and scale their secure corporate network.</p><p>“This strategic move marks an exciting period for our company, partners, and customers. By joining Check Point, a global leader in cyber security for over 30 years, we aim to deliver the premier SASE platform in the market,” said Amit Bareket, CEO at Perimeter 81. </p><p>"Our interconnection represents a significant step towards a comprehensive and scalable security for the modern era. We look forward to the positive impact we will jointly create."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenSSH vulnerability uncovered by researchers, RCE exploit developed  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/openssh-vulnerability-uncovered-by-researchers-rce-exploit-developed</link>
                                                                            <description>
                            <![CDATA[ Attackers can remotely manipulate common libraries to execute arbitrary code ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BcSSgyBb3FeqZGPC5zxgBH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Jul 2023 09:32:45 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Jul 2023 10:57:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:description>                                                            <media:text><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:text>
                                <media:title type="plain"><![CDATA[OpenSSH vulnerability: A red warning sign on a background of code, denoting malware and cyber attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qKCkPsC9o3LPrJHDP6Jkr7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have uncovered a vulnerability, tracked as CVE-2023-38408, in the secure networking suite OpenSSH which would allow hackers to remotely execute code using simple commands.</p><p>Exploitation of the vulnerability makes use of a commonly-used helper program in OpenSSH called ssh-agent, which holds a user’s private keys for use in frequent, often automated, SSH public key authentication.</p><p>Administrators managing remote servers often enable ‘ssh-agent forwarding’, which enables the ssh-agent to be accessed from a chosen server so that local SSH keys to be used without storing keys on the server itself.</p><p>Qualys researchers <a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent" target="_blank"><u>discovered</u></a> that when a forwarded agent is set up using default settings, with PKCS11 enabled, it’s possible for a threat actor with a connection to the same remote server to load and unload shared libraries on a victim’s machine with malicious side effects.</p><p>Security researchers used this technique to achieve one-shot, remote code execution (RCE) by combining just four side effects of loading and unloading common shared libraries.</p><p>Once an attacker has achieved RCE, a host of malicious actions can be undertaken including the installation of <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a>, carrying out a <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach"><u>data breach</u></a>, or total system takeover.</p><p>“This newly uncovered ssh-agent vulnerability underlines the continuous need for rigorous security measures and immediate response,” wrote Saeed Abbasi, manager, Vulnerability Signatures at Qualys.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="fJNPj3JADSPXRojuC6w3p8" name="State of ransomware readiness 2022_thumbnail.jpg" caption="" alt="Whitepaper cover with red and white title over a black and white image of a businessman stood looking out of an office window" src="https://cdn.mos.cms.futurecdn.net/fJNPj3JADSPXRojuC6w3p8.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>State of ransomware readiness 2022</strong></p><p class="fancy-box__body-text"><em>Find out how organizations are defending against ransomware attacks today</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/state-of-ransomware-readiness-2022"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Even robust systems can harbor hidden vulnerabilities, as demonstrated by the shortcomings of the ssh-agent. Proactively rectifying such vulnerabilities through actions such as implementing patches is critical to maintaining the integrity of digital assets.”</p><p>OpenSSH is a widely-used solution for encrypted data transfer and remote logins, particularly by administrators seeking to easily manage <a href="https://www.itpro.com/security/cyber-security/359457/what-are-ssh-keys"><u>SSH keys</u></a>. It is used worldwide for secure connections.</p><p>Researchers found the default installations of Ubuntu Desktop 22.04 and 21.10 to be vulnerable and warned that other <a href="https://www.itpro.com/operating-systems/28025/best-linux-distros"><u>Linux distributions</u></a> or <a href="https://www.itpro.com/operating-systems/24841/windows-vs-linux-whats-the-best-operating-system"><u>operating systems</u></a> could also be exploited if left unpatched.</p><p>Vulnerable OpenSSH releases include:</p><ul><li>1:7.9p1-10+deb10u2</li><li>1:7.9p1-10+deb10u1</li><li>1:8.4p1-5+deb11u1</li><li>1:9.2p1-2</li><li>1:9.3p1-1</li></ul><p>The issue has been fixed as of version 1:9.3p2-1.</p><p>OpenSSH noted that the flaw can only be exploited if specific libraries are present in the victim’s system, and that if agents are not forwarded to a hacker-compromised network, attacks cannot be achieved remotely.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ASUS routers receive patches for critical vulnerabilities affecting more than a dozen product lines ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/routers/asus-routers-receive-patches-for-critical-vulnerabilities-affecting-more-than-a-dozen-product-lines</link>
                                                                            <description>
                            <![CDATA[ Nearly 20 models have been affected by a spate of vulnerabilities, including two rated ‘critical’ ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">882jnuveAVpDcfuYoKDbLW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yiL5NjEQcpWpVKGHSyRUwf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 20 Jun 2023 11:39:24 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Routers]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yiL5NjEQcpWpVKGHSyRUwf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ASUS logo displayed at COMPUTEX 2023 in Taipei]]></media:description>                                                            <media:text><![CDATA[ASUS logo displayed at COMPUTEX 2023 in Taipei]]></media:text>
                                <media:title type="plain"><![CDATA[ASUS logo displayed at COMPUTEX 2023 in Taipei]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yiL5NjEQcpWpVKGHSyRUwf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>ASUS has announced a raft of firmware updates to fix critical vulnerabilities found in a number of router devices. </p><p>The firm revealed that nine security vulnerabilities were discovered in networking appliances - two of which were rated as ‘critical’ with six designated as ‘high’ risk. </p><p>Tracked as <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1160"><u>CVE-2018-1160</u></a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26376"><u>CVE-2022-26376</u></a>, the two critical vulnerabilities were given a 9.8 severity rating out of a possible 10, the company said. </p><p>Analysis shows that the former of these pertains to an out of bounds write bug found in Netatalk prior to version 3.1.12. This near-five-year-old vulnerability could enable an unauthorised party to achieve arbitrary code execution. </p><p>Meanwhile, CVE-2022-26376 is a memory corruption vulnerability found in Asuswrt and Asuswrt-Merlin New Gen firmware. This flaw could allow an attacker to trigger this vulnerability by leveraging a “specially-crafted HTTP” request, which would cause memory corruption. </p><p>Nearly 20 router models have been affected by disclosed vulnerabilities, ASUS revealed. </p><p>These include:</p><ul><li>GT6</li><li>GT-AXE16000</li><li>GT-AX11000 PRO</li><li>GT-AXE11000</li><li>GT-AX6000</li><li>GT-AX11000</li><li>GS-AX5400</li><li>GS-AX3000</li><li>XT9</li><li>XT8</li><li>XT8 V2</li><li>RT-AX86U PRO</li><li>RT-AX86U</li><li>RT-AX86S</li><li>RT-AX82U</li><li>RT-AX58U</li><li>RT-AX3000</li><li>TUF-AX6000</li><li>TUF-AX5400.</li></ul><p>In its <a href="https://www.asus.com/content/asus-product-security-advisory/"><u>security advisory</u></a> on 19 June, ASUS urged customers to patch affected routers as soon as possible to avoid risk of exposure.  </p><p>The firm warned that customers choosing not to install new firmware updates should disable services accessible from via WAN to “avoid potential unwanted intrusions”. </p><p>“These services include remote access from WAN, port forwarding, DDNS, VPN server, DMZ, port trigger,” ASUS said. </p><p>The company also recommended frequent auditing of equipment to ensure firmware is up to date and to mitigate risk.</p><p>“We strongly encourage you to periodically audit both your equipment and your security procedures, as this will ensure that you will be better protected,” the firm said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dragos’ new partner program aims to turn resellers into OT experts ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/dragos-new-partner-program-aims-to-turn-resellers-into-ot-experts</link>
                                                                            <description>
                            <![CDATA[ The initiative will help partners fully manage customer deployments with Dragos’ ISC/OT security offerings ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zdEUBGiYaw3RfS3q2JktJc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 14 Jun 2023 11:36:49 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:08:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:description>                                                            <media:text><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:text>
                                <media:title type="plain"><![CDATA[Dragos: Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber security provider Dragos has announced the launch of its new Dragos Global Partner Program, which will enable partners to act as industrial controls systems (ICS) and operational technology (OT) experts and advisors.</p><p>Dragos specializes in cyber security for ICS and <a href="https://www.itpro.com/security/364189/from-it-to-ot-whats-the-partner-opportunity"><u>OT environments</u></a>, providing visibility into ICS/OT assets, <a href="https://www.itpro.com/security/cyber-security/363052/ics-and-ot-vulnerabilities-more-than-doubled-in-2021"><u>vulnerabilities</u></a>, threats, and response actions. </p><p>The firm’s solutions protect organizations across industries such as energy, manufacturing, building automation systems, water, government, food, and more. </p><p>Partners will have access to the Dragos platform for visibility into customer assets, Dragos Professional Services, as well as threat intelligence via the Dragos WorldView offering. Dragos OT Watch also enables managed ICS/OT threat hunts and notification triage, while Neighborhood Keeper provides collective defense.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ZA9hLXndi7rAvoRNaj2ffT" name="IT best practices for accelerating the journey to carbon neutrality_LISTING.jpg" caption="" alt="Whitepaper cover with image of wind turbines and solar farm" src="https://cdn.mos.cms.futurecdn.net/ZA9hLXndi7rAvoRNaj2ffT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: IBM)</span></figcaption></figure><p class="fancy-box__body-text"><strong>IT best practices for accelerating the journey to carbon neutrality</strong></p><p class="fancy-box__body-text"><em>Considerations and pragmatic solutions for IT executives driving sustainable IT</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/sustainability/369565/it-best-practices-for-accelerating-the-journey-to-carbon"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Positioned as the only channel program that spans OT, services, and threat intelligence, the initiative provides training to help partners position themselves as specialist advisors able to offer their customers assessment services, resell the Dragos security platform, as well as manage deployment.</p><p>In an announcement, Dragos said partners will be able to offer the full range of ICS/OT cyber security technology and services to increase revenue opportunities and deliver positive results for customers.</p><p>“Market demand for OT cyber security is accelerating as evolving threats, geopolitical dynamics, and regulations shine a spotlight on the need to protect industrial infrastructure,” said Christophe Culine, VP of global sales and CRO at Dragos. </p><p>“With the new Dragos Global Partner Program, we will transfer our knowledge and experience as the industry’s ICS/OT cyber security leader to our channel partners, enabling them to fully manage their customers’ deployments with the industry’s most comprehensive and complete ICS/OT security solution.”</p><p>Partners can access the program’s training via a self-service portal that pulls together automated deal registration, marketing materials, and access to self-paced ICS <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs"><u>cyber security skills</u></a> training through Dragos Academy training modules.</p><p>There are also market development funds (MDF), including proposal-based MDFs for demand and lead generation, as well as cumulative volume discounts and deal registration with increased margin for identifying opportunities.</p><p>Sean Tufts, practice director of ICS and IoT security at Dragos partner Optiv, said the partner program enables both businesses to achieve joint commercial success.</p><p>“The comprehensive, unparalleled training we get from Dragos and the highly differentiated product offerings allow us to triage and investigate potential incidents for our customers, enabling quicker response and visibility into the breadth and depth of attacks as well as affected devices,” he said. </p><p>“All this allows us to give our customers the confidence that their operational technology and industrial infrastructure are secure, resilient, and compliant.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Barracuda Networks says hacked devices “must be immediately replaced” despite patches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/barracuda-networks-says-hacked-devices-must-be-immediately-replaced-despite-patches</link>
                                                                            <description>
                            <![CDATA[ Seven-month exploitation of a critical vulnerability enabled persistent backdoor access in its email security gateway devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vYfzzGT59nVwtY36bAxK9S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 08 Jun 2023 10:05:44 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 09:45:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:description>                                                            <media:text><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:text>
                                <media:title type="plain"><![CDATA[Barracuda Networks hack: Secure mail on digital screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NBihq6k5jNtbC7WmGtAt3m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A critical vulnerability in Barracuda Networks’ email security gateway (ESG) devices now means all devices must now be replaced.</p><p>The order came directly from the security company this week which said devices should be replaced regardless of whether the zero-day vulnerability was patched.</p><p>Barracuda updated its security advisory and also communicated the instruction to customers via the user interface of their ESG devices.</p><p>“Barracuda’s remediation recommendation at this time is full replacement of the impacted ESG,” the company said. “Impacted ESG appliances must be immediately replaced regardless of patch version level.”</p><p>Barracuda has not offered any further description as to why the devices must be fully replaced, but it may be due to the malware installed after exploiting the vulnerability allowing for persistent backdoor access for attackers.</p><p>The firm, which has more than 200,000 customers globally, has been engaging affected clients since news of the vulnerability emerged in late May. </p><h2 id="barracuda-esg-vulnerability-what-happened">Barracuda ESG vulnerability - what happened?</h2><p>Last month, Barracuda said it detected “anomalous traffic” <a href="https://www.itpro.com/security/barracuda-network-appliance-vulnerability-actively-exploited-for-seven-months"><u>originating from its email security gateway appliances</u></a>. A subsequent investigation identified a critical vulnerability exploit, tracked as CVE-2023-28681, in the appliance. </p><p>Initially, the company issued a patch to remediate the vulnerability for all ESG appliances globally. A script was deployed to contain the incident and prevent unauthorized access methods, Barracuda said. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kTsiQoiFtbpj9ToE5cqEQ" name="The (hard) key to stop phishing_listing.jpg" caption="" alt="Blue webinar screen with title and contributor images" src="https://cdn.mos.cms.futurecdn.net/kTsiQoiFtbpj9ToE5cqEQ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Cloudflare)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The (hard) key to stop phishing</strong></p><p class="fancy-box__body-text"><em>How Cloudflare stopped a targeted attack and you can too</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-hard-key-to-stop-phishing"><strong>WATCH FOR FREE</strong></a></p></div></div><p>However, last week the company revealed that further analysis of the incident found the vulnerability had been actively exploited for several months before it was discovered and patched. </p><p>Barracuda said the “earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022”.</p><p>The vulnerability enabled threat actors to obtain “unauthorized access to a subset of ESG appliances”, it added. The company said that <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> was identified on a subset of appliances, offering would-be attackers persistent backdoor access. </p><p>Two particular malware strains were uncovered by Barracuda during its post-mortem analysis of the incident. </p><p>The first was SALTWATER, a “<a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>trojanized</u></a> module for the Barracuda SMTP daemon that contains backdoor functionality”. </p><p>The second malware strain, known as SEASPY, was also identified. SEASPY also offered attackers backdoor functionality with persistence, while disguising itself as a legitimate Barracuda Networks service. </p><p>No other Barracuda products, including its <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS</a> email security services, were affected by the vulnerability, Barracuda said. </p><p><em>ITPro </em>approached Barracuda Networks for comment on the latest update. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued over ‘widespread’ exploitation of Zyxel NAS devices ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/warning-issued-over-widespread-exploitation-of-zyxel-nas-devices</link>
                                                                            <description>
                            <![CDATA[ Zyxel has been forced to issue patches for several vulnerabilities affecting NAS devices ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VgZs93kfPZKFCbFn8PTPiR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Six3Lm5uJLhgjo6XGBqPFf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Jun 2023 16:26:51 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 07:54:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Six3Lm5uJLhgjo6XGBqPFf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fiber optics carrying computer virus attacking binary code]]></media:description>                                                            <media:text><![CDATA[Fiber optics carrying computer virus attacking binary code]]></media:text>
                                <media:title type="plain"><![CDATA[Fiber optics carrying computer virus attacking binary code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Six3Lm5uJLhgjo6XGBqPFf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers at two companies have issued warnings over ‘widespread’ exploitation of Zyxel network devices. </p><p>Researchers at Rapid7 raised the alarm over the ongoing exploitation of a critical authenticated command injection vulnerability, tracked as CVE-2023-28771, that was found to affect multiple Zyxel devices. </p><p>The flaw was present in the default confirmation of vulnerable devices, Rapid7 found, and exploitable via Zyxel’s Wide Area Network (WAN) interface. </p><p>Zyxel researchers explained this is “intended to be exposed to the internet”, and that a VPN would not need to be configured on a targeted device for it to be at risk. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Y8zp3VtzSfMaNA32DY582d" name="Beat cyber criminals at their own game_thumb.jpg" caption="" alt="Red whitepaper cover with title and logo above circular images of colleagues using laptops, and servers" src="https://cdn.mos.cms.futurecdn.net/Y8zp3VtzSfMaNA32DY582d.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Beat cyber criminals at their own game</strong></p><p class="fancy-box__body-text"><em>A guide to winning the vulnerability race and protection your organization</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/beat-cyber-criminals-at-their-own-game"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Successful exploitation of the vulnerability would allow an attacker to remotely execute code on a target system by sending a “specially crafted IKEv2 packet” to UDP port 500 on the device, researchers said. </p><p>Zyxel released an advisory for CVE-2023-28771 on 25 April. The US Cybersecurity and Infrastructure Agency (CISA) has since added the flaw to its known exploited vulnerabilities list and warned organizations to remain vigilant.  </p><p>Technical analysis from Rapid7 found that it was being “widely exploited and that compromised Zyxel devices were being leveraged to conduct downstream attacks as part of a Mirai-based <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet"><u>botnet</u></a>”.</p><p>“As of May 19, there were at least 42,000 instances of Zyxel devices on the public internet. However, this number only includes devices that expose their web interfaces on the <a href="https://www.itpro.com/software-defined-wide-area-network-sd-wan/33346/what-is-sd-wan">WAN</a>, which is not a default setting,” researchers noted. </p><p>“Since the vulnerability is in the <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022">VPN service</a>, which is enabled by default on the WAN, we expect the actual number of exposed and vulnerable devices to be much higher.”</p><h2 id="additional-zyxel-vulnerabilities-disclosed">Additional Zyxel vulnerabilities disclosed</h2><p>Zyxel has also issued a patch for a security vulnerability affecting owners of its Linux-operated NAS326, NAS540, and NAS542 storage devices running the latest firmware.</p><p>These Zyxel <a href="https://www.itpro.com/storage/29658/how-to-pick-the-best-nas-for-your-business">NAS appliances</a> allow for the storage of user data in a single location, including cloud data, photos, videos, or USB data, according to researchers at Sternum. </p><p>In an advisory, the firm said researchers were “in the process of scanning one of the Zyxel NAS units” and uncovered the flaw when a “Dangerous String Format” alert was triggered.</p><p>“In this situation, there was a problem with a ntpdate_date process, which, as the name suggests, is responsible for periodically synchronizing the device’s internal clock via NTP pings,” researchers explained. </p><p>“Knowing that it was passed as a string to ntpdate_date, Sternum researchers investigated further to see if it could be used to manipulate the device.”</p><p>Analysis revealed the flaw that could be used by an unauthenticated user to "execute an arbitrary system command with root privileges on the system”. </p><p>This could be used for more malicious purposes, Sternum added, such as remote <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> injection. </p><p>Zyxel acknowledged the vulnerability and issued a patch and CVE notice on 30 May. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Barracuda network appliance vulnerability “actively exploited” for seven months ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/barracuda-network-appliance-vulnerability-actively-exploited-for-seven-months</link>
                                                                            <description>
                            <![CDATA[ The company has issued a patch, but warned customers that the vulnerability left them exposed for over half a year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JwiQTgXFZa9B3Bx6x3hojd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8UD9Rbm37RcjHhKFrHRB96-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 01 Jun 2023 11:02:21 +0000</pubDate>                                                                                                                                <updated>Tue, 13 Jun 2023 07:24:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8UD9Rbm37RcjHhKFrHRB96-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital security padlock with encrypted binary code on futuristic circuit board]]></media:description>                                                            <media:text><![CDATA[Digital security padlock with encrypted binary code on futuristic circuit board]]></media:text>
                                <media:title type="plain"><![CDATA[Digital security padlock with encrypted binary code on futuristic circuit board]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8UD9Rbm37RcjHhKFrHRB96-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A critical vulnerability discovered in Barracuda Networks devices may have been actively exploited for seven months, the company has revealed. </p><p>The security firm said the flaw, which was first discovered in May, affected its Email Security Gateway (ESG) appliance and was patched after an initial investigation. </p><p>This week, however,  analysis of the vulnerability revealed it had been actively exploited for several months before the patch was issued. </p><p>Barracuda Networks said the “earliest identified evidence of exploitation of CVE-2023-2868 is currently October 2022”.</p><p>In its advisory, the firm said the vulnerability stemmed from “incomplete input validation” of user-supplied .tar files. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="k8ftzpSTX7UAHzb6bhxVzh" name="Quantifying the public vulnerability market_listing.jpg" caption="" alt="Whitepaper cover with title over solid purple circle graphics" src="https://cdn.mos.cms.futurecdn.net/k8ftzpSTX7UAHzb6bhxVzh.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Quantifying the public vulnerability market: 2022 edition</strong></p><p class="fancy-box__body-text"><em>An analysis of vulnerability disclosures, impact severity, and product analysis</em></p><p class="fancy-box__body-text"><strong>DOWNLOAD FOR FREE</strong></p></div></div><p>The flaw meant that a remote attacker could format file names in a deliberate manner to remotely execute a system command through Perl’s gx operator. </p><p>The investigation also revealed that a third party exploited this to gain unauthorized access to a subset of ESG appliances. </p><p>“Barracuda&apos;s investigation to date has determined that a third party utilized the technique described above to gain unauthorized access to a subset of ESG appliances,” the firm said in its advisory. </p><p><a href="https://www.itpro.com/malware/28076/what-is-malware"><u>Malware</u></a> was identified on this subset of appliances, Barracuda revealed, which would allow for persistent backdoor access. In addition, the company said it uncovered evidence of data exfiltration on impacted appliances.  </p><p>Two specific malware strains were highlighted by Barracuda during a post-mortem analysis of the incident. This included SALTWATER, a <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>trojanized </u></a>module for the Barracuda SMTP daemon that contains backdoor functionality.</p><p>SALTWATER enables threat actors to upload or download arbitrary files and execute commands, as well as proxy and tunneling capabilities, Barracuda said. </p><p>Another type of malware, known as SEASPY, was also identified during the probe led by Barracuda and Mandiant. SEASPY contains backdoor functionality that is activated by a ‘magic pocket’, according to researchers.</p><p>“SEASPY is an x64 ELF persistence backdoor that poses as a legitimate Barracuda Networks service and establishes itself as a PCAP filter, specifically monitoring traffic on port 25 (SMTP),” the firm said. </p><h2 id="barracuda-engaging-with-affected-customers">Barracuda engaging with affected customers</h2><p>Barracuda insisted that no other products were affected by the vulnerability, including its SaaS <a href="https://www.itpro.com/security/29591/why-email-security-is-your-next-big-opportunity"><u>email security</u></a> services. </p><p>The company added that customers potentially impacted by the incident have been notified via the ESG user interface, and the company has reached out to specific customers directly. </p><p>Barracuda has around 200,000 customers globally. However, the exact number of those affected by the vulnerability has yet to be determined. </p><p><em>ITPro</em> approached Barracuda for comment on the matter, but hadn’t received a response at the time of publication. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ASUS, Cisco, Netgear devices exploited in ongoing Chinese hacking campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/asus-cisco-netgear-devices-exploited-in-ongoing-chinese-hacking-campaign</link>
                                                                            <description>
                            <![CDATA[ Critical national infrastructure is the target of sustained attempts from state-sponsored hackers, according to Five Eyes advisories ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rZgNYQA8qHZazZPioTpAW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 25 May 2023 09:53:27 +0000</pubDate>                                                                                                                                <updated>Thu, 25 May 2023 11:31:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:description>                                                            <media:text><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:text>
                                <media:title type="plain"><![CDATA[Black laptop being used by a person out of shot, denoting an anonymous hacker, against a bright backdrop of a Chinese flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FRayTvQKar4rQVZNj8Mzrf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations globally have been urged to remain vigilant amid an ongoing hacking campaign that leverages office networking devices to target critical national infrastructure (CNI) assets. </p><p>Research from Microsoft this week revealed that attacks carried out by Volt Typhoon, a Chinese state-sponsored group that commonly focuses on espionage and intelligence gathering, are specifically <a href="https://www.itpro.com/security/ransomware/370327/ex-ncsc-ceo-ciaran-martin-ransomware-cni"><u>targeting CNI organizations</u></a>. </p><p>Microsoft said Volt Typhoon relies “almost exclusively” on living-off-the-land (LOTL) techniques and hands-on-keyboard activity. </p><p>LOTL attacks typically see attackers compromise a victim’s system and use the systems and tools that are already installed to achieve their goals, rather than executing their own code or malware payloads, for example.</p><p>“To achieve their objective, the threat actor puts strong emphasis on stealth in this campaign,” said Microsoft, which assisted the Five Eyes investigation. </p><p>“They issue commands via the command line to (1) collect data, including credentials from local and network systems, (2) put the data into an archive file to stage it for exfiltration, and then (3) use the stolen valid credentials to maintain persistence.”</p><p>As part of the campaign, Volt Typhoon has been observed blending into normal network activity by routing traffic through compromised small office and home office (SOHO) network equipment. This includes <a href="https://www.itpro.com/infrastructure/network-internet/369507/what-is-a-router"><u>routers</u></a>, firewalls, and <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/368103/best-business-vpn-in-2022"><u>VPN hardware</u></a>.</p><p>Microsoft confirmed that a number of devices, including those manufactured by ASUS, <a href="https://www.itpro.com/security/cyber-attacks/cisco-reveals-exploit-code-is-publicly-available-for-critical-switch-vulnerabilities"><u>Cisco</u></a>, D-Link, Netgear, and Zyxel are at risk and urged owners of these devices to ensure interfaces are not exposed to the public internet to mitigate threats. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YXFRHbAWK6pCoyVSsdrjKg" name="The Total Economic Impact™ of Mimecast_listing.jpg" caption="" alt="Whitepaper cover with title and green clicker board image top right" src="https://cdn.mos.cms.futurecdn.net/YXFRHbAWK6pCoyVSsdrjKg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of Mimecast</strong></p><p class="fancy-box__body-text"><em>Cost savings and business benefits enabled by using Mimecast with Microsoft 365</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/359472/the-total-economic-impacttm-of-mimecast"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Owners of network <a href="https://www.itpro.com/internet-of-things-iot/34509/how-edge-computing-can-benefit-businesses"><u>edge devices</u></a> should ensure that management interfaces are not exposed to the public internet in order to reduce their attack surface,” the firm said in a <a href="https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/" target="_blank"><u>blog post</u></a>. </p><p>“By proxying through these devices, Volt Typhoon enhances the stealth of their operations and lowers overhead costs for acquiring infrastructure.”</p><p>Marc Burnard, senior consultant for information security research at Secureworks, said that targeting network devices is a common tactic employed by threat actors such as Volt Typhoon, which is also tracked as ‘Bronze Silhouette’.</p><p>This enables the group to ‘blend in’ to network traffic and operate behind the scenes with impunity, thereby gaining a stronger foothold and compromising additional assets. </p><p>“From our first-hand <a href="https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations" target="_blank"><u>observations</u></a>, we determine the group to have a consistent focus on operational security including a minimal intrusion footprint, defense evasion techniques, and use of compromised infrastructure,” he said. </p><p>“Think of a spy going undercover, their goal is to blend in and go unnoticed. This is exactly what Bronze Silhouette does by mimicking usual network activity.”</p><p>Burnard added that these tactics highlight the group’s “operational maturity and adherence to a modus operandi” that focuses specifically on reducing the likelihood of detection. </p><h2 id="five-eyes-response-to-chinese-hacking-threat">Five Eyes response to Chinese hacking threat</h2><p>The campaign by Volt Typhoon has prompted Five Eyes security agencies to issue an urgent warning to critical infrastructure organizations. </p><p>The UK’s National Cyber Security Centre (NCSC) issued a joint statement with the equivalent authorities from the US, Canada, Australia, and New Zealand calling for heightened vigilance amid the ongoing attacks. </p><p>“It is vital that operators of critical national infrastructure take action to prevent attackers hiding on their systems, as described in this joint advisory with our international partners,” said Paul Chichester, director of operations at the NCSC. </p><p>“We strongly encourage UK essential service providers to follow our guidance to help detect this malicious activity and prevent persistent compromise.”</p><p>According to Microsoft, the purpose of the campaign by Volt Typhoon appears to have broader geopolitical goals amid rising tensions between the US and China. </p><p>The group has been active since mid-2021, the firm revealed, and has already targeted critical infrastructure organizations in the United States and Guam, a key site for US military activities in the Pacific. </p><p>“Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The rise of identity-based cyber attacks and how to mitigate them ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/the-rise-of-identity-based-cyber-attacks-and-how-to-mitigate-them</link>
                                                                            <description>
                            <![CDATA[ If identity-based cyber attacks are successful, they can give hackers the opportunity to infiltrate an entire network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Dmdzt3Pb6T2ghHcUFX3EiF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 May 2023 08:20:49 +0000</pubDate>                                                                                                                                <updated>Tue, 09 May 2023 08:46:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sandra Vogel ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:description>                                                            <media:text><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:text>
                                <media:title type="plain"><![CDATA[The reflection of a hacker seen in a broken mirror to represent identity-based cyber attacks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fYUM6JWPRVgRkHVduyaHcB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Identity-based cyber attacks are an increasing weapon of choice the more we work in a world increasingly reliant on identity-based authorization. This means, in essence, <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>stealing or faking our passwords</u></a> or other login credentials. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackershttps://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">The top 12 password-cracking techniques used by hackers</a></p></div></div><p>In response, organizations are adding new layers of authentication, which, inevitably, cyber criminals work to find ways through or around. In this <a href="https://www.itpro.com/security/cyber-security/368087/cyber-security-companies-must-remember-who-the-enemies-are"><u>cat-and-mouse game</u></a>, identity-based attacks are on the rise, and organizations must implement several measures to defend themselves from these.</p><h2 id="identity-based-cyber-attacks-are-a-growing-threat">Identity-based cyber attacks are a growing threat</h2><p>Hacking into computer systems is as old an activity as computer systems themselves. But the <a href="https://www.itpro.com/security/cyber-security/369983/what-is-attack-surface-management"><u>attack surface</u></a> is wider than ever before; there are more systems around, <a href="https://www.itpro.com/solid-state-storage-ssd/31387/what-the-future-holds-for-data-storage"><u>storing more data</u></a> about individuals and organizations, offering more potential for exploitation. </p><p>“With so much more personal information now online, companies, institutions, infrastructure, and even democracies are being maliciously targeted by actors wishing to exploit it,” Del Heppenstall, partner and head of cyber at KPMG in the UK tells <em>ITPro</em>.</p><p>It’s <a href="https://www.itpro.com/data-breaches/34355/an-inside-job-the-human-factor-of-cybersecurity"><u>people that are most often the source</u></a> of a data breach. The 2022 <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank"><u><em>Verizon Data Breach Investigations Report</em></u></a> found 82% of data breaches involve the “human element”. That human element can be through sheer malevolence, such as <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one"><u>social engineering attacks</u></a>, of course. But more often than not, it’s a simple incident of human error, such as people falling prey to fake SMS messages, succumbing to a <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> exercise, or <a href="https://www.itpro.com/security/cyber-security/369527/revealed-the-top-200-most-common-passwords-of-2022"><u>reusing common passwords</u></a> across personal and professional logins. Mistakes are inevitable – after all, we are only human – which is why <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust strategies</u></a> are important. </p><p>“Adversaries can easily launch high-volume password spraying where they only need to be right once out of millions of attempts,” former BP CISO, Simon Hodgkinson, says. “Similarly, with <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas"><u>high-volume phishing attacks</u></a>, all it takes is one person to click on the link and provide their credentials. The defenders on the other hand need to be right 100% of the time.”</p><h2 id="guarding-against-the-inevitable">Guarding against the inevitable</h2><p>Not only do the attackers really know their business, they’re pushing hard and faster. The <a href="https://www.microsoft.com/en-us/security/business/security-insider/threat-briefs/anatomy-of-a-modern-attack-surface/" target="_blank"><u><em>Microsoft Digital Defense Report 2022</em></u></a> notes the volume of password attacks has risen to an estimated 921 attacks every second. That’s a 74% increase in just one year.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">The rise of phishing as a service (PhaaS) and how to tackle it</a></p></div></div><p>So what is an organization to do? Hodgkinson tells <em>ITPro</em>: “One must be pragmatic. Cyber risk cannot be eradicated. Organizations can only put in place mitigations aligned to their risk appetite and have robust response plans in place. Every organization should assume that they will be compromised at some point.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="YssANqmxxS4hiCype5M99b" name="Anatomy_of_Identity_Based_Attacks_listing.jpg" caption="" alt="Image of female and male colleagues looking at a computer" src="https://cdn.mos.cms.futurecdn.net/YssANqmxxS4hiCype5M99b.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Okta)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Anatomy of identity-based attacks</strong></p><p class="fancy-box__body-text"><em>Helping security teams mitigate identity-based attacks</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/anatomy-of-identity-based-attacks"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>In this context, organizations must put security front and center. For Heppenstall, the security-first approach that most organizations now take can be strengthened by moving to an identity-focused approach. </p><p>He mentions features like least privilege, enhanced monitoring, threat analytics and controls, the establishment of communications guidelines both internally and with external entities and individuals, and continuous validation of end-users including internal, contractors, and third parties. He also suggests “keeping proactive and reactive risk management capabilities around identity and access management, then integrating it with business and security needs will be key to handling threats”.</p><h2 id="taking-a-nuanced-approach-to-tightening-the-net">Taking a nuanced approach to tightening the net</h2><p>For Kevin Curran, IEEE senior member and professor of cyber security at Ulster University, organizations can fall short if they don’t understand the difference between <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy"><u>identity management</u></a> and authentication. </p><p>It’s crucial to “establish how roles are identified in a system and how they are assigned to individuals”, he tells <em>ITPro</em>. This means “security teams need to pay attention when removing, adding, and updating individuals alongside their roles in a system”. </p><p>“There needs to be a sensible allocation of levels of access to individuals or groups of individuals,” he continues. “Only then can security teams assume that they have established a ‘foundation’ of protecting the sensitive data within the system and securing the organization itself.”</p><p>Best practice isn’t only about technology: there are <a href="https://www.itpro.com/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in"><u>cultural and process factors to take into account</u></a> too. Hodgkinson gives <em>ITPro</em> a strong example of how cultural shift has helped other industry sectors with different issues.</p><p>“The airline and oil and gas industries dramatically improved safety by embracing a culture of ‘speak up’,” he explains. “When there was an accident or a near miss, people were encouraged to share. This led to a culture of continuous improvement in safety. A similar approach is required in cyber – let’s encourage people to report and share their learnings.” </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370285/can-we-ever-achieve-cyber-security-buy-in">Can we ever achieve cyber security buy-in?</a></p></div></div><p>What would this look like in practice? “If one user clicked on a phishing link, they should share why so others learn from it,” he adds. “This will require organizations to positively support employees who have made a mistake.”</p><p>All in all, it would seem that organizations must accept the inevitable and assume attacks will happen. They must also understand that their best mitigation is not solely a matter of best technology practice. It’s also about organizational culture, accepting that people are fallible, and providing a culture of support and learning in that context.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The top malware and ransomware threats for April 2023 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/the-top-malware-and-ransomware-threats-for-april-2023</link>
                                                                            <description>
                            <![CDATA[ New ransomware gangs and malware abound as hackers continue to evolve their tactics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NKveEGmf2wzVUN4mjRA3v9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Apr 2023 11:53:32 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Apr 2023 07:28:42 +0000</updated>
                                                                                                                                            <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ connor.jones@futurenet.com (Connor Jones) ]]></author>                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Connor Jones is the News and Analysis Editor at ITPro, CloudPro, and ChannelPro. As the brands’ leader for news, he welcomes pitches on all topics, and he personally still reports breaking news on the topics of cyber security, software, and Big Tech firms.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;He has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;Connor is currently in his third year at ITPro, but has been a journalist for much longer, having written for the likes of Red Bull Esports and UNILAD. He has a master’s degree in Magazine Journalism from one of the UK’s leading journalism departments at the University of Sheffield, as well as an undergraduate degree in English Language from Sheffield Hallam University.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;When he’s not hitting the phones trying to squeeze stories out of sources and press offices, in his free time Connor studies software development, is a keen cook, and enjoys leading an active life through cycling, hiking, racket sports, and weightlifting.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:description>                                                            <media:text><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:text>
                                <media:title type="plain"><![CDATA[Top malware and ransomware cause &#039;system hacked&#039; alert to appear on a computer screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wxwQh5vaMoKWvRvc4tsgMe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Alerts for new malware strains and active ransomware groups were spread widely across the security industry throughout March and the first half of April.</p><p>New strains of malware targeting organizations of all kinds were discovered, harnessing infection vectors that may not already be in their threat models.</p><p>It’s highly important that organizations stay on top of emerging threats and patch their systems against the most prevalent types of attacks. </p><p>Patching isn’t always an easy task to do, especially in large organizations, but as a bare minimum, it’s advised that active threats are protected against if a more comprehensive patch operation isn’t feasible.</p><p>Knowing what cyber security vulnerabilities and zero days to patch is one thing, but it’s equally important to pay close attention to the ways malware is evolving to bypass security detections so the workforce can be aware of what suspicious activity to look out for.</p><p>Here you’ll find a complete list of the most dangerous malware and ransomware threats of April 2023.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:5000px;"><p class="vanilla-image-block" style="padding-top:73.18%;"><img id="vs9yTRo5yQxteYSCkYk7Qi" name="onenote-GettyImages-1237632217.jpg" alt="OneNote logo on a smartphone against white background with Windows logo on it" src="https://cdn.mos.cms.futurecdn.net/vs9yTRo5yQxteYSCkYk7Qi.jpg" mos="" align="middle" fullscreen="" width="5000" height="3659" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="onenote-exploited-to-bypass-macro-attacks">OneNote exploited to bypass macro attacks</h2><p>Ever since Microsoft made the long-awaited decision to <a href="https://www.itpro.com/security/cyber-security/368513/microsoft-confirms-vba-macro-backtrack-is-only-temporary"><u>disable VBA macros</u></a> in Office documents by default last year, cyber attackers have been experimenting with inventive ways to deliver malware in a trusted way.</p><p>Microsoft OneNote is installed on Windows by default, unlike Word, Excel, and PowerPoint, and can therefore allow all Windows users to open email attachments in the OneNote format regardless of whether they have a Microsoft 365 subscription.</p><p>The combination of using a malware-laden OneNote file to seem more legitimate and the weaker detection measures the application provides against embedded malware, now makes OneNote a more reliable threat vector than Office documents.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="p7aA9ci4nXKjR9pXsMHoAN" name="Mapping the digital attack surface_thumb.png" caption="" alt="Red whitepaper cover with title and logo" src="https://cdn.mos.cms.futurecdn.net/p7aA9ci4nXKjR9pXsMHoAN.png" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Trend Micro)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Mapping the digital attack surface</strong></p><p class="fancy-box__body-text">Why global organisations are struggling to manage cyber risk</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.co.uk/security/cyber-security/370166/mapping-the-digital-attack-surface"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Zscaler’s ThreatLabz researchers found that a variety of scripts and malware have been observed running after successful phishing attacks led victims to download and open the files.</p><p><a href="https://www.itpro.com/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer"><u>Remote access trojans (RATs)</u></a> and information stealers have been installed following successful attacks. </p><p>Researchers also <a href="https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution" target="_blank"><u>said</u></a> that MSHTA, WSCRIPT, and CSCRIPT can be executed from within OneNote, using multi-layered obfuscation techniques to evade detection. </p><p>CHM, HTA, JS, WSF, and VBS scripts are also supported via OneNote documents.</p><p>Organizations should inform their staff about the dangers of OneNote attachments in emails. If an email seems suspicious, it should be checked by the organization’s security team before downloading any attachments.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:2329px;"><p class="vanilla-image-block" style="padding-top:55.26%;"><img id="ZLh8NqNMJxu2ezah4ARbhn" name="botnet-GettyImages-1398190099.jpg" alt="Mockup of a botnet and its different stages" src="https://cdn.mos.cms.futurecdn.net/ZLh8NqNMJxu2ezah4ARbhn.jpg" mos="" align="middle" fullscreen="" width="2329" height="1287" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="emotet-returns-again-with-new-tricks">Emotet returns again with new tricks</h2><p>Trend Micro announced in March that the <a href="https://www.itpro.com/security/cyber-security/370253/new-emotet-socially-engineers-evade-detection?utm_campaign=itpro_newsletter_20230314&utm_source=itpro_uk_newsletter&refid=8FF9B2F3D90B6CB87A72F4BDCC18B32F&utm_medium=email" target="_blank"><u>Emotet botnet has returned once again</u></a> after another of its trademark periods of downtime.</p><p>Emotet was observed mimicking replies in existing email chains, increasing the perceived legitimacy of responses rather than it being a cold email from an unrecognized sender.</p><p>While OneNote is being exploited to bypass Microsoft’s VBA macro defenses, Emotet instead deploys social engineering tactics to trick victims into manually re-enabling macros, allowing malicious Office documents to execute commands, like downloading DLLs, and install malware.</p><p>The new version of Emotet also uses binary padding - crafting large files, such as 500MB Word documents, to bypass security scans.</p><p>The prevailing advice is that workers should remain mindful that attempts to re-enable VBA macros will likely lead to malicious activity and should be flagged to the security team as soon as possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:6500px;"><p class="vanilla-image-block" style="padding-top:53.85%;"><img id="L6DSTHdion3mCrSBkWnF9C" name="malware-GettyImages-1420039900.jpg" alt="Mockup of a padlock covered in blue and red neon code denoting ransomware, malware, and security" src="https://cdn.mos.cms.futurecdn.net/L6DSTHdion3mCrSBkWnF9C.jpg" mos="" align="middle" fullscreen="" width="6500" height="3500" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="cl0p-overtakes-lockbit-in-ransomware-rankings">Cl0p overtakes LockBit in ransomware rankings</h2><p>Cl0p’s exploitation of the <a href="https://www.itpro.com/security/data-breaches/370409/the-goanywhere-data-breach-explained"><u>vulnerability in GoAnywhere MFT</u></a> propelled it to the top of Malwarebytes’ ransomware rankings for April, overtaking LockBit by a small margin.</p><p>The group claimed to have breached more than 130 organizations in a month including Proctor and Gamble, Virgin Red, Saks Fith Avenue, and the <a href="https://www.itpro.com/security/ransomware/370329/pension-protection-fund-confirms-employee-data-exposed-goanywhere-breach"><u>UK’s Pension Protection Fund (PPF)</u></a>.</p><p>Although Cl0p operates its own namesake ransomware program, many of the GoAnywhere-related breaches are thought not to have involved ransomware.</p><p>Regardless, it overtook LockBit this month after it dominated in March with 126 attacks. For context, the second-place gang from last month, ALPHV, only registered 32 attacks.</p><p>The reliability of LockBit was questioned earlier this month by DarkTracer International, accusing it of running an inefficient website on the dark web.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">The reliability of the RaaS service operated by LockBit ransomware gang seems to have declined. They appear to have become negligent in managing the service, as fake victims and meaningless data have begun to fill the list, which is being left unattended. pic.twitter.com/mfGhH93oYh<a href="https://twitter.com/darktracer_int/status/1646125694127345664">April 12, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>LockBit responded by attempting another of its ‘pranks’, like it has done in the past with the likes of <a href="https://www.itpro.com/security/ransomware/369449/lockbit-repeats-pr-stunt-as-thales-ransomware-investigation-reveals-no-breach"><u>Mandiant and Thales</u></a>, but it ultimately backfired when its team, which doe snot speak English natively, confused DarkTracer with Cambridge, UK-based Darktrace. </p><p>This forced Darktrace to publicly deny that it had been attacked by LockBit, and the vent prompted many in the community to mock the ransomware gang’s mistake.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">Earlier today @darktracer_int stated Lockbit ransomware group was declining and becoming negligent in managing their service.Lockbit responded to them on their onion domain. pic.twitter.com/3ISlwIZtPw<a href="https://twitter.com/vxunderground/status/1646433205916925953">April 13, 2023</a></p></blockquote><div class="see-more__filter"></div></div><p>A patch for the GoAnywhere MFT vulnerability has been available since February and should be applied as a priority if it hasn’t been already to prevent further attacks from Cl0p.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FRRDLEFjuVCi2yG5QJMqoU" name="malware-getty.jpg" alt="Blue and gold mockup of motherboard with lock denoting malware and security" src="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="microsoft-signals-new-ransomware-gang-on-the-block-in-patch-tuesday">Microsoft signals new ransomware gang on the block in Patch Tuesday</h2><p>In yet another <a href="https://www.itpro.com/windows/microsoft-april-patch-tuesday-password-feature"><u>error-strewn Patch Tuesday</u></a> from Microsoft, it highlighted an actively exploited zero-day vulnerability.</p><p>Researchers identified the new ransomware gang, known as Nokoyama, exploiting the vulnerability since February.</p><p>Trend Micro’s <a href="https://www.trendmicro.com/en_us/research/22/c/nokoyawa-ransomware-possibly-related-to-hive-.html" target="_blank"><u>report</u></a> on the group linked the operation to the <a href="https://www.itpro.com/security/cyber-crime/369952/fbis-landmark-takedown-hive-ransomware-unlikely-significant-impact"><u>recently taken down Hive</u></a> group, which claimed attacks on the likes of New York Racing Association, Tata Power, and <a href="https://www.itpro.com/security/368903/altice-reportedly-hit-by-hive-ransomware-attack"><u>Altice</u></a>.</p><p>The researchers said the two groups share a number of similarities in their attack chain such as the use of Cobalt Strike and <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> emails, but noted Hive’s <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware"><u>double extortion</u></a> technique hasn’t been used by Nokoyama yet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:8000px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="o7aE2bbqGF7TeVESbqgZfb" name="malware-GettyImages-1345812496.jpg" alt="Mockup of brigtly coloured alert with code and a warning sign, reading 'malware'" src="https://cdn.mos.cms.futurecdn.net/o7aE2bbqGF7TeVESbqgZfb.jpg" mos="" align="middle" fullscreen="" width="8000" height="4500" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="fusioncore-malware-as-a-service-operation">FusionCore malware as a service operation</h2><p>Researchers at CYFIRMA detailed an emerging threat actor believed to be operating from inside Europe earlier this month.</p><p>FusionCore has been described as a ‘one-stop shop’ for malware services, with a wide range of tools on offer, plus hacker-for-hire services too.</p><p>The malware on offer has been described as “cost-effective, yet customizable”, and its ransomware affiliate scheme provides both a ransomware payload and affiliate software to manage negotiations with victims.</p><p>“FusionCore typically provides sellers with a detailed set of instructions for any service or product being sold, enabling individuals with minimal experience to carry out complex attacks,” CYFIRMA <a href="https://www.cyfirma.com/outofband/the-rise-of-fusioncore-an-emerging-cybercrime-group-from-europe/" target="_blank"><u>said</u></a>.</p><p>A number of indicators of compromise (IOCs) can be found on the researcher’s blog.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="WUxCWQvnDGZ7w4W2rRGJE" name="china-hacker-security-getty.jpg" alt="Laptop with china flag on screen and code overlaid, denoting Chinese hacking" src="https://cdn.mos.cms.futurecdn.net/WUxCWQvnDGZ7w4W2rRGJE.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="chinese-hackers-targeting-products-with-no-edr-support">Chinese hackers targeting products with no EDR support</h2><p>Mandiant’s blog in March highlighted a threat actor, which it tracks as UNC3886, targeting products that aren’t supported by endpoint detection and response (EDR) products.</p><p>These include firewalls, IoT devices, hypervisors, and VPNs from Fortinet, SonicWall, Pulse Secure, and others.</p><p>Dozens of attacks have been investigated by the security firm and have involved the exploitation of zero-day vulnerabilities and the use of custom malware to both steal credentials and maintain a lasting presence in a victim’s IT environment.</p><p>Full details of the attack scenarios, their methods, and the products being targeted can be found in <a href="https://www.mandiant.com/resources/blog/fortinet-malware-ecosystem" target="_blank"><u>Mandiant’s detailed blog</u></a>.</p><p>The takeaway for admins here is that they should be communicating regularly with vendors to ensure any potential threats can be mitigated.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:3840px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="VUDZptndWJDCBjYxYfV9u6" name="python-code-GettyImages-1346778393.jpg" alt="Python code on a screen" src="https://cdn.mos.cms.futurecdn.net/VUDZptndWJDCBjYxYfV9u6.jpg" mos="" align="middle" fullscreen="" width="3840" height="2160" attribution="" endorsement="" class=""></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><h2 id="developers-beware-of-w4sp-copycats">Developers beware of W4SP copycats</h2><p>Sonatype said that one of the key malware trends for March this year was a continuation of malicious packages being uploaded to the PyPI registry - a destination for developers to download and use software built by the <a href="https://www.itpro.com/business-strategy/careers-training/356640/how-to-become-a-python-software-developer"><u>Python community</u></a>.</p><p>It noticed a number of packages mimicking the W4SP stealer - a popular information stealer since the middle of 2022 used to carry out <a href="https://www.itpro.com/security/cyber-security/369082/c-suite-executives-say-software-supply-chain-hacks-have-become-chief-concern"><u>software supply chain attacks</u></a>.</p><p>“These types of packages are a cause for concern as they pose a serious threat to developers who may inadvertently download and install them,” it <a href="https://blog.sonatype.com/malware-monthly-march-2023" target="_blank"><u>said</u></a>.</p><p>The packages have since been taken down, but with the ongoing attempts to poison the software supply chain, and the damage such attacks can cause - think <a href="https://www.itpro.com/security/malware/370353/3cx-ceo-state-sponsored-hackers-behind-supply-chain-malware-attack"><u>3CX as a recent example</u></a>, then developers need to be especially vigilant when downloading open-source software, ensuring that it’s safe to use.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is the Network and Information Systems 2 (NIS2) Directive? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive</link>
                                                                            <description>
                            <![CDATA[ Everything your business needs to understand about the implications of the new EU regulations and how it differs from the UK's own updated NIS rules ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wgvrPngQXeQ3MTWkTtJgBF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MjRjdYwLLDb5TtHJ4vqa5F-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Apr 2023 07:00:06 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Jul 2025 14:56:28 +0000</updated>
                                                                                                                                            <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rene Millman) ]]></author>                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MjRjdYwLLDb5TtHJ4vqa5F-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract render of the European continent at night, with lines of glowing blue light emanating from London ]]></media:description>                                                            <media:text><![CDATA[An abstract render of the European continent at night, with lines of glowing blue light emanating from London ]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract render of the European continent at night, with lines of glowing blue light emanating from London ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MjRjdYwLLDb5TtHJ4vqa5F-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>To address the ongoing threat of cyber attacks, the European Union (EU) has put in place an updated Network and Information Systems Directive (NIS2). This is a comprehensive legal framework intended to bolster cyber security by imposing obligations on organizations to manage cyber risks, report incidents, and cooperate with authorities to smoothen <a href="https://www.itpro.com/security/building-an-incident-response-strategy"><u>incident response</u></a>.</p><p>The directive applies to certain <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat"><u>critical sectors</u></a> such as energy, transportation, and health and requires companies to proactively protect their systems from threats like <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> and <a href="https://www.itpro.com/security/ransomware/how-it-leaders-can-respond-to-the-evolution-of-ransomware"><u>ransomware</u></a>, as well as report certain types of incidents to relevant authorities.</p><p>The twin directives of NIS2 and the Critical Entities Resilience (CER), which replaced the European Critical Infrastructure Directive of 2008, came into force in January 2023. Member states were given until 17 October 2024 to comply, with all of the law’s measures now applying to business operations.</p><p>Both aim to improve the cybersecurity of businesses throughout the region, by setting strict standards for network and IT security. While CER is centered on critical entities, NIS2 compels organizations to adopt risk management strategies that encompass the widest possible range of cyberattacks.</p><p>In 2022, the UK <a href="https://www.itpro.com/policy-legislation/it-regulation/369630/uk-updates-nis-regulations-bringing-stricter-rules-for-msps"><u>updated its own NIS regulations</u></a> as the EU’s updated law does not apply within the region. </p><p>Its NIS regulations carry stringent requirements for <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service">managed service providers (MSPs)</a>, particularly around <a href="https://www.itpro.com/security/cyber-attacks/uk-public-sector-at-risk-from-supply-chain-attacks-new-report-warns"><u>supply chain security</u></a>, remote access, incident response planning, and <a href="https://www.itpro.com/business-strategy/careers-training/367767/attracting-and-retaining-talent-through-training">staff training</a>. MSPs must also report any incidents to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>. </p><h2 id="what-are-the-key-provisions-in-the-nis2-directive">What are the key provisions in the NIS2 Directive?</h2><p>The NIS2 Directive is a set of regulations that aims to raise cyber security standards of network and information systems throughout the EU. It requires companies operating in essential sectors, such as energy, transport, banking, financial services, healthcare, drinking water supply, digital infrastructure, public administration, chemicals, food supply and distribution, and space, to bolster network security, incident management, business continuity, and compliance.</p><p>NIS2 sets out clear standards for companies in all of these sectors, requiring leaders to conduct plans for cyber risk assessments, draw up plans for incident response strategies, report major cybersecurity incidents within 24 hours, and ensure staff are adequately trained to respond to cyber incidents.</p><p>It also draws up plans for the Cooperation Group, which will work with the EU Commission and European Union Agency for Cybersecurity (ENISA) and regional cybersecurity agencies to share information on cyber incidents and best practices. This will be established on 17 January 2025.</p><p>There are also requirements for incident reporting, voluntary certification schemes, and supervision and enforcement by national authorities. The directive, finally, includes risk management through regular risk assessments and implementation of appropriate security measures to mitigate identified threats. These measures may include <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">incident management processes</a>, business continuity plans, and compliance with relevant regulations. Companies must also monitor and evaluate the effectiveness of these measures on an ongoing basis.</p><h2 id="to-which-organizations-does-nis2-apply">To which organizations does NIS2 apply?</h2><p>NIS2 applies to all medium or large-sized important entities and operators of essential services (OES) and digital service providers (DSPs) operating within the EU. These are defined as those organizations with 250 employees or more, an annual turnover of €50 million ($54 million) or more, or alternatively a balance sheet of €43 million ($46 million) or more.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Vwn9JgNr3K9DKq4qVs3DN4" name="Fuelling growth through transactions (1).jpg" caption="" alt="Fuelling growth through transactions" src="https://cdn.mos.cms.futurecdn.net/Vwn9JgNr3K9DKq4qVs3DN4.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Paysafe)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/fuelling-growth-through-transactions"><em>Prepare for the future of payments with flexible solutions</em></a></p></div></div><p>An OES is a company or organization that provides a service essential for maintaining public life or economic and societal activities. Organizations in sectors such as electricity, water, health, transport, and digital infrastructure fall under this definition.</p><p>In the previous iteration of NIS, EU member states could individually identify OES according to their own definitions. NIS2’s size-based approach standardizes this approach to prevent inconsistencies across different member states. Governments and entities operating in defense, judiciary, and law enforcement are exempt from NIS2, though the law does apply to central and regional administrations due to growing cyberattacks on the public sector.</p><iframe allow="" height="200px" width="100%" id="" style="" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=60811227&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=true&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="nis2-vs-uk-nis-what-s-the-difference">NIS2 vs UK NIS: What’s the difference? </h2><p>Although both NIS2 and UK NIS intend to improve the cybersecurity posture of businesses in their respective regions, they differ in several crucial aspects.</p><p>For a start, the regulations set out deviating reporting processes, fines, oversight, and certification.</p><p>There are also specific requirements for MSPs in the UK legislation. UK-based <a href="https://www.itpro.com/strategy/28223/cio-job-description-what-does-a-cio-do">CIOs</a> and IT managers must also understand the requirements and implications of both sets of regulations, and ensure overall compliance if they fall under the jurisdiction of both.</p><h3 class="article-body__section" id="section-nis2-vs-uk-nis-incident-reporting"><span>NIS2 vs UK NIS: Incident reporting</span></h3><p>Both the UK's NIS regulations and NIS2 require OES and DSPs to report certain types of incidents to the relevant authorities.</p><p>The EU directive does encourage member states to establish mechanisms for the exchange of information between OES and DSPs, including the exchange of information on specific incidents. This information exchange can be done on a voluntary basis, and it's up to each member state to decide how to implement it.</p><p>The UK regulations define a cybersecurity incident as an event that has a significant impact on the continuity of the essential services they provide, the security of the network and information systems they use to provide those services, or the personal data they process.</p><h3 class="article-body__section" id="section-nis2-vs-uk-nis-certification"><span>NIS2 vs UK NIS: Certification</span></h3><p>NIS2 allows member states to adopt voluntary certification schemes for OES and DSPs. This means that the certification process is not mandatory, and companies may choose to be certified under the voluntary scheme to demonstrate their credentials.</p><p>The UK NIS regulations require OES and DSPs to be certified by a relevant certifying body, while the EU NIS directive allows member states to adopt voluntary certification schemes for OES and DSPs.</p><p>Certification requirements under the UK NIS regulations mean that OES and DSPs must be certified by a relevant certifying body to demonstrate that they have taken appropriate steps to manage risks. This certification process is mandatory and ensures that companies operating in these sectors are held to a high standard of cybersecurity.</p><h3 class="article-body__section" id="section-nis2-vs-uk-nis-supervision-and-enforcement"><span>NIS2 vs UK NIS: Supervision and enforcement</span></h3><p>The UK NIS regulations have designated the NCSC as the organization with the power to supervise and enforce compliance, while the EU’s directive grants member states the remit to delegate supervision and enforcement to regulators within each country, depending on their preference.</p><p>The level of fines also differs. NIS2 sets out varying fines according to whether an entity is classed as important or essential – noncompliance on the part of the former can be met with a fine of €7 million ($7.59 million) or 1.4% of global annual turnover, while the latter can face fines of €10 million ($10.84 million) or 2% of global annual turnover. Precedence is given to whichever monetary amount is higher.</p><p>The UK’s NIs regulation, meanwhile, can impose a fine of up to £17 million, or 4% of global turnover, for non-compliance, while the EU’s version allows member states to impose non-specific administrative fines. The penalties are expected to be much higher in the UK than across the continent.</p><h3 class="article-body__section" id="section-nis2-vs-uk-nis-demands-for-msps"><span>NIS2 vs UK NIS: Demands for MSPs</span></h3><p>There are <a href="https://www.itpro.com/business/policy-legislation/366410/uk-cyber-security-overhaul-brings-a-sword-of-damocles-to-msps">stricter rules and requirements for MSPs</a> under UK NIS than NIS2, which means UK MSPs will have to comply with stricter security measures.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/policy-legislation/366410/uk-cyber-security-overhaul-brings-a-sword-of-damocles-to-msps">UK cyber security overhaul brings “a sword of Damocles” to MSPs</a></p></div></div><p>Examples include implementing strong access controls, such as <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a>, to prevent unauthorised access to systems and networks; regularly testing and assessing the effectiveness of security measures to identify vulnerabilities and address them promptly; and maintaining comprehensive records of security incidents, including details of the incident and the steps taken to address it</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AdRem NetCrunch 13 review: Great network monitoring for time-poor SMBs ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370341/adrem-netcrunch-13-review-great-network-monitoring</link>
                                                                            <description>
                            <![CDATA[ Easily deployed and affordable network monitoring for SMBs with a range of highly informative viewpoints ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vEJemVALQHs16x8XAG4czs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sGouP4BVEp4s8G3rR8gMvb-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Mar 2023 11:00:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/sGouP4BVEp4s8G3rR8gMvb-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The AdRem NetCrunch 13 user interface]]></media:description>                                                            <media:text><![CDATA[The AdRem NetCrunch 13 user interface]]></media:text>
                                <media:title type="plain"><![CDATA[The AdRem NetCrunch 13 user interface]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sGouP4BVEp4s8G3rR8gMvb-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SMBs that want a network monitoring solution that does all the hard work for them will love AdRem's NetCrunch. We found it can be deployed in as little as 15 minutes, and once we'd added all our device credentials to the discovery wizard, it scanned our lab network and presented its findings in a very informative central console.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools" data-original-url="/business/business-operations/367876/best-network-monitoring-tools">Best network monitoring tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/364372/beyond-network-monitoring" data-original-url="/infrastructure/network-internet/364372/beyond-network-monitoring">Beyond network monitoring</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/358532/how-to-choose-networking-software-for-your-business" data-original-url="/security/network-security/358532/how-to-choose-networking-software-for-your-business">How to choose networking software for your business</a></p></div></div><p>The amount of detail gathered by network monitoring software can be overwhelming, but <a href="https://www.itpro.com/network-internet/30680/adrem-netcrunch-933-review" target="_blank" data-original-url="https://www.itpro.com/network-internet/30680/adrem-netcrunch-933-review">NetCrunch</a> is able to organise this into easily digestible console views. It succeeds admirably, with the Atlas overview page using colour-coded icons for all monitored devices and services so you can see at a glance which ones have problems.</p><p>The Top Charts tab presents graphical views of nodes with the most alerts and those with the highest CPU, memory and storage usage. Move to the Nodes page and you can see them all or use one-click filters to change it to show systems that are down, those with critical alerts or those in a warning state.</p><p>More tabs are provided for quickly pulling up views of VMware and Hyper-V virtualisation hosts. Once our ESXi 7 host had been discovered, another tab was added to the Atlas page so we could see all its active <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines" target="_blank" data-original-url="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">VMs</a>, their status, the datastores in use and host CPU utilisation.</p><p>Smart Pages go further as the Atlas automatically provides a range of views based on the device categories selected in the left pane. These can be anything from a list of workstation and server nodes to networking devices such as switches, and you can create your own custom views.</p><p>NetCrunch 13 adds a new Active Alerts console page that provides real-time views of the latest network issues, which can be filtered by severity. We tested this by shutting down one of our Windows servers: within four minutes, a new critical alert took centre stage at the top of this screen.</p><p>The Active Alerts analytics page shows graphs of all alerts over the last day, week or month, and you can drill down to selected items for more detailed information. A summary view provides a canned report of all alerts, while the history page allows you to browse the NetCrunch event log over any time period and create custom views using its integral query builder. </p><p>Another smart feature is NetCrunch's Monitoring Packs, which group together performance data and alerts for specific devices or services and are automatically assigned during the discovery process. NetCrunch Essentials provides 110 packs, which the Professional version extends to over 270, with the Enterprise edition adding sensors for cloud services such as Amazon Web Services, <a href="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws" target="_blank" data-original-url="https://www.itpro.com/microsoft-azure/34048/microsoft-azure-review-competitive-cloud-pricing-takes-a-bite-out-of-aws">Microsoft Azure</a> and 365, Google and <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now" target="_blank" data-original-url="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now#:~:text=Zoom%20is%20a%20very%20slick,comes%20to%20its%20basic%20features.">Zoom</a>.</p><p>We tested this by adding the OneDrive sensor, which ran a swift two-step authorisation process for our Microsoft 365 account. We could then see total cloud storage allocated to the account along with free, trash and used space, and load daily, weekly and monthly performance trend graphs.</p><p>Along with great monitoring features, NetCrunch looks good value as its flexible pricing schemes are based on a combination of nodes and interfaces. We've shown the yearly cost of NetCrunch Essentials for 100 nodes and interfaces, but if you have lots of network switches to monitor, increasing the interface count to 350 only pushes the yearly price up to $1,330 (£1,065).</p><p>AdRem's NetCrunch 13 is a great network monitoring choice for time-poor SMBs as deployment is a breeze and it does most of the legwork for you. Even though it requires a dedicated Windows Server host, value still looks good and its smart consoles ensure support staff are never out of the loop.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT manager's guide to getting home in time for dinner ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370217/the-it-managers-guide-to-getting-home-in-time-for-dinner</link>
                                                                            <description>
                            <![CDATA[ A cloud based networking solution that does away with configurations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fcxNgw12ecG9M2U3J1Ycan</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/goH3DUReMuea7tNkdVG39a-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 14:26:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Firewalls]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/goH3DUReMuea7tNkdVG39a-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title and image of a book with a cartoon image of a man up to the eyeballs in IT Helpdesk tickets / requests]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title and image of a book with a cartoon image of a man up to the eyeballs in IT Helpdesk tickets / requests]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title and image of a book with a cartoon image of a man up to the eyeballs in IT Helpdesk tickets / requests]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/goH3DUReMuea7tNkdVG39a-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For IT managers it never ends. In the morning it’s endless tickets about individual desktop issues, then a database isn’t responding, a server goes down, or for some unknown reason backups are failing. Even the most diligent administrator gets hit with a pile of issues, and as always they tend to cluster around the worst times of day like early morning or quitting time.</p><p>That’s why many IT managers look to simplify their systems as much as possible. Not only does it make life easier, but it also increases the chance that you won’t be staying late to fix some obscure server issue. Some things just can’t be pared down, of course, but what if we told you edge networking wasn’t one of those things?</p><p>Download now to learn more about how Zero Trust Network Access, a dependable Firewall-as-a-Service, and a Secure Web Gateway wrapped up in a single, secure, networking package can get you home in time for dinner.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=11034"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zero Trust myths: Fact or fiction? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/zero-day-exploit/370183/zero-trust-myths-fact-or-fiction</link>
                                                                            <description>
                            <![CDATA[ What the myths get right and wrong about Zero Trust ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hMAMMmLJ9CASmrFsMyXjT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VrzXjkVbXZ2DQ9RKwaQQhV-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 14:20:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/VrzXjkVbXZ2DQ9RKwaQQhV-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Webinar screen with title and contributor images]]></media:description>                                                            <media:text><![CDATA[Webinar screen with title and contributor images]]></media:text>
                                <media:title type="plain"><![CDATA[Webinar screen with title and contributor images]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VrzXjkVbXZ2DQ9RKwaQQhV-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In this webinar you will:</p><ul><li>Learn how Zero Trust can help your organisations' network security</li><li>Understand how Zero Trust solves challenges of modern security deployment</li><li>Discover just how new (or not) the Zero Trust concept is</li><li>Determine the difference between Zero Trust and legacy business VPNs</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10998"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Achieving zero trust for corporate networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370182/achieving-zero-trust-for-corporate-networks</link>
                                                                            <description>
                            <![CDATA[ Zero trust is a new way of thinking about information security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cgBDgEoXcw4Bir2rV8uUPs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GB7YYAdRm3LRnVVscE6aUg-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 13:00:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/GB7YYAdRm3LRnVVscE6aUg-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Webinar title screen with images of contributors]]></media:description>                                                            <media:text><![CDATA[Webinar title screen with images of contributors]]></media:text>
                                <media:title type="plain"><![CDATA[Webinar title screen with images of contributors]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GB7YYAdRm3LRnVVscE6aUg-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Between the rise in social-engineering attacks and the Biden Administration’s executive order for mandating zero-trust initiatives across government agency networks, demand for zero trust is at an all-time high.</p><p>In this webinar, experts discuss the growing importance of zero trust models to the future of cybersecurity. The panel of speakers follow their discussion with a real time demonstration of Perimeter 81’s zero trust offering.</p><p>Watch the full webcast to learn more about zero trust initiatives and see how partnering with Perimeter 81 could accelerate your zero-trust journey.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10997"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Organisations seek SSE solutions to help ease pain of remote work ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370181/organisations-seek-sse-solutions-to-help-ease-pain-of-remote-work</link>
                                                                            <description>
                            <![CDATA[ How ZTNA wins the network security game ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">peauAWBGFYgiKPBwrQwSNN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PzPYrQG3haFGEtLbFLjsDN-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 12:57:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cloud Security]]></category>
                                                    <category><![CDATA[Cloud]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/PzPYrQG3haFGEtLbFLjsDN-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue whitepaper cover with title over a digital image of a book on top of a white surface with stars in the background ]]></media:description>                                                            <media:text><![CDATA[Blue whitepaper cover with title over a digital image of a book on top of a white surface with stars in the background ]]></media:text>
                                <media:title type="plain"><![CDATA[Blue whitepaper cover with title over a digital image of a book on top of a white surface with stars in the background ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PzPYrQG3haFGEtLbFLjsDN-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many businesses today are rethinking their network security solutions since the adoption of remote and hybrid work, and considering the multiple cyber security options now available. For the majority, the best solution would be to introduce new elements - like Zero Trust - that can be implemented alongside legacy infrastructure.</p><p>This study shares how converged network security - Security Services Edge (SSE) - could be the solution to achieve this, offering integrated cloud-based abilities without compromising existing environments.</p><p>Download now for the full results of this study, discover the main challenges in managing network security, including remote access, and realise the numerous drivers for adopting SSE.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10991"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ZTNA vs on-premises VPN ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/remote-access/370180/ztna-vs-on-premises-vpn</link>
                                                                            <description>
                            <![CDATA[ How ZTNA wins the network security game ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hjhUqyWjcDkSocDS3UeSbN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NeckmEo98JWfdotfzrjgbk-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 12:52:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/NeckmEo98JWfdotfzrjgbk-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with digital images of two books, one open and one with digital image of a cloud and person icon in the centre, with square graphics of a network, shield, and verified icons]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with digital images of two books, one open and one with digital image of a cloud and person icon in the centre, with square graphics of a network, shield, and verified icons]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with digital images of two books, one open and one with digital image of a cloud and person icon in the centre, with square graphics of a network, shield, and verified icons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NeckmEo98JWfdotfzrjgbk-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT leaders today are tasked with finding innovative ways to secure their remote workforce, with legacy hardware firewall VPNs no longer able to meet today’s security needs. One solution is enterprise level network security with Zero Trust, that enables network access for users to only what they need to perform their roles.</p><p>This guide further explains the benefits of a Zero Trust Network Access (ZTNA) security model and how organisations can significantly reduce the level of exposure to cyber attacks and limit unwanted access to their data.</p><p>Download now to see how ZTNA compares to On-premise Firewall VPNs, and how it can offer a safer hybrid work environment.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10984"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The WFH cyber security checklist ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/remote-access/370179/the-wfh-cyber-security-checklist</link>
                                                                            <description>
                            <![CDATA[ Ten ways to win the remote access game with ZTNA ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h2rHrEMqELJE8dPmCx58uX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HZj96Z5myU4QbgD5zye974-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 12:43:55 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/HZj96Z5myU4QbgD5zye974-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark whitepaper cover with title and image of two books, one open and one with the author on the front cover]]></media:description>                                                            <media:text><![CDATA[Dark whitepaper cover with title and image of two books, one open and one with the author on the front cover]]></media:text>
                                <media:title type="plain"><![CDATA[Dark whitepaper cover with title and image of two books, one open and one with the author on the front cover]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HZj96Z5myU4QbgD5zye974-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Since the global pandemic, the modern workforce has become largely remote in a bid to continue business operations. With more remote devices now accessing the company network from multiple locations, and the adoption of cloud-based collaborative tools, cyber criminals have revelled in exploiting vulnerabilities following this shift.</p><p>With employees today determining how they work - the majority opting for remote/hybrid opportunities - this resource can help organisations ensure the security of their remote employees with ten clear cyber security checks.</p><p>Download now to learn how to radically simplify your cyber security and discover the tools that can meet the needs of both your remote workforce, and deliver the robust protection your IT teams require.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10983"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The essential guide to preventing ransomware attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/370178/the-essential-guide-to-preventing-ransomware-attacks</link>
                                                                            <description>
                            <![CDATA[ Vital tips and guidelines to protect your business using ZTNA and SSE ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qvtudpyJAXot2dyLgNGhrG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4eRfmiXyLuCUJqizfhK2R7-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 12:25:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/4eRfmiXyLuCUJqizfhK2R7-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blue whitepaper cover with title and word ransomware made up of newspaper cut out letters]]></media:description>                                                            <media:text><![CDATA[Blue whitepaper cover with title and word ransomware made up of newspaper cut out letters]]></media:text>
                                <media:title type="plain"><![CDATA[Blue whitepaper cover with title and word ransomware made up of newspaper cut out letters]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4eRfmiXyLuCUJqizfhK2R7-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>According to a recent study by Perimeter 81, two thirds of the 500 IT professionals they surveyed had experienced a ransomware attack during the course of their career, highlighting just how encompassing ransomware has become. As malicious actors continue to take advantage of zero-day vulnerabilities, the time has come for businesses to ensure they have the tools to counter attacks.</p><p>This eBook focuses on practical data to help organisations understand the full implications of a ransomware attack, from the risks associated with hardware VPNs, to how to protect your remote workforce, and shares how to select the best approach to prevent malware, both now and in the future.</p><p>Download now to learn the six principles of Zero Trust Network Access (ZTNA), and discover how this key component of Security Services Edge (SSE) can offer your business complete cloud security.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10982"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Network security musts: The seven point checklist ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/network-internet/370177/network-security-musts-the-seven-point-checklist</link>
                                                                            <description>
                            <![CDATA[ How to acquire and deploy your cloud-based network security solution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g8k3aQh7jsyF55ggJ3Rmq9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K6PsDHYCFzosCEuQe7Pmd6-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Mar 2023 12:23:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/K6PsDHYCFzosCEuQe7Pmd6-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title and digital image of a scroll of paper with tick list on it, with square graphics containing flame, shield, and verified icons]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title and digital image of a scroll of paper with tick list on it, with square graphics containing flame, shield, and verified icons]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title and digital image of a scroll of paper with tick list on it, with square graphics containing flame, shield, and verified icons]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K6PsDHYCFzosCEuQe7Pmd6-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are multiple benefits when it comes to using a cloud-based network security solution. As there’s no need for hardware, it’s cost effective, faster to deploy, and as it’s built for purpose, it has the ability to evolve as your business grows.</p><p>This resource shares the seven security musts of cloud-based network security, including firewall defence and Zero Trust, and explains how to assess your own infrastructure first to establish your security needs.</p><p>Download now to discover the right solution for your organisation, and discover the full-featured cloud-based network security solution that ticks all boxes.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="45kyzij2XAsVPuNU7f5egJ" name="" alt="Perimeter 81 logo" src="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" mos="https://cdn.mos.cms.futurecdn.net/45kyzij2XAsVPuNU7f5egJ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49988/perimeter81q1?locale=1&p=false&wp=10981"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 security checklist ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/cloud/cloud-security/370245/microsoft-365-security-checklist</link>
                                                                            <description>
                            <![CDATA[ A practical guide for the time-strapped admin ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7pn4n5yg7Rd6H5rVxKdMdf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ug5GyVmcJNwy4JdDwUHAXD-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Mar 2023 14:59:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Ug5GyVmcJNwy4JdDwUHAXD-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark whitepaper cover with digital image of laptops around a central network block with blue light beam shining down on the block]]></media:description>                                                            <media:text><![CDATA[Dark whitepaper cover with digital image of laptops around a central network block with blue light beam shining down on the block]]></media:text>
                                <media:title type="plain"><![CDATA[Dark whitepaper cover with digital image of laptops around a central network block with blue light beam shining down on the block]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ug5GyVmcJNwy4JdDwUHAXD-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It’s very easy to assume that as a small business owner, once you opt for a renowned cloud service such as Microsoft 365 for email and collaboration tools, your data and business is secure - this isn’t the case.</p><p>This eBook shares the importance of establishing your business security needs - particularly when it comes to data laws and compliance - and why you need to keep on top of your security settings in Microsoft 365 with the ever evolving threat landscape.</p><p>Download this checklist - aimed at SMBs and MSPs - as it goes through each security setting for Microsoft 365, explaining why you might need them, what the implications are, and recommended configurations.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nCmE5ukURN7NcFxLTZuzoN" name="" alt="Hornetsecurity logo" src="https://cdn.mos.cms.futurecdn.net/nCmE5ukURN7NcFxLTZuzoN.jpg" mos="https://cdn.mos.cms.futurecdn.net/nCmE5ukURN7NcFxLTZuzoN.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49985/hornet-demand-q1-2023-efpl100119?locale=1&p=false&wp=10973"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The global use of collaboration solutions in hybrid working environments ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/370219/the-global-use-of-collaboration-solutions-in-hybrid-working</link>
                                                                            <description>
                            <![CDATA[ How companies manage security risks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">q5qjCeS1pJHXN5YAWJtpYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VNCs6oMsMgazrtCTAPp6EK-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 09 Mar 2023 08:13:35 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/VNCs6oMsMgazrtCTAPp6EK-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black whitepaper cover with title and logos and bottom-right image of a mobile phone screen with pink, green and black messages popping up from the screen]]></media:description>                                                            <media:text><![CDATA[Black whitepaper cover with title and logos and bottom-right image of a mobile phone screen with pink, green and black messages popping up from the screen]]></media:text>
                                <media:title type="plain"><![CDATA[Black whitepaper cover with title and logos and bottom-right image of a mobile phone screen with pink, green and black messages popping up from the screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VNCs6oMsMgazrtCTAPp6EK-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many hybrid working environments have been adopted industry-wide since the global pandemic, with employees using collaboration tools when working from home. IT managers are therefore tasked with, not only the security of internal infrastructure, but also those collaboration solutions on the edge.</p><p>This study delves into how employees use collaboration channels, as well as how sensitive information and data is shared via these solutions, and discusses the risks and challenges when it comes to using them.</p><p>Download now to learn the risk factors when it comes to collaboration solutions, and why back ups are critical to success.</p><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nCmE5ukURN7NcFxLTZuzoN" name="" alt="Hornetsecurity logo" src="https://cdn.mos.cms.futurecdn.net/nCmE5ukURN7NcFxLTZuzoN.jpg" mos="https://cdn.mos.cms.futurecdn.net/nCmE5ukURN7NcFxLTZuzoN.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49985/hornet-demand-q1-2023-efpl100119?locale=1&p=false&wp=10974"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HPE accelerates network security drive with Axis Security acquisition ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business-strategy/mergers-and-acquisitions/370187/hpe-network-security-drive-axis-security-acquisition</link>
                                                                            <description>
                            <![CDATA[ The acquisition builds on the recent purchase of Italian private cellular technology provider, Athonet ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rfUpGYisywXLc9YKFTLWRn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xe72f2xWKLZuwHiDvXAK34-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Mar 2023 12:14:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xe72f2xWKLZuwHiDvXAK34-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A view of a building with an HPE logo displayed on the outside]]></media:description>                                                            <media:text><![CDATA[A view of a building with an HPE logo displayed on the outside]]></media:text>
                                <media:title type="plain"><![CDATA[A view of a building with an HPE logo displayed on the outside]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xe72f2xWKLZuwHiDvXAK34-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>HPE has confirmed the acquisition of Israel-based cloud security provider, Axis Security.</p><p>The exact terms of the deal are yet to be detailed by HPE, however, the acquisition is expected to close in its second fiscal quarter. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/channel/369997/hpe-appoints-heather-walls-to-lead-ireland-channel-push" data-original-url="/channel/369997/hpe-appoints-heather-walls-to-lead-ireland-channel-push">HPE appoints Heather Walls to lead Ireland channel push</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/369663/hpe-expands-partner-ecosystem-amid-greenlake-updates" data-original-url="/cloud/369663/hpe-expands-partner-ecosystem-amid-greenlake-updates">HPE expands partner ecosystem amid GreenLake updates</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/370129/hpe-eyes-private-5g-expansion-with-athonet" data-original-url="/business-strategy/mergers-and-acquisitions/370129/hpe-eyes-private-5g-expansion-with-athonet">HPE eyes private 5G expansion with Athonet acquisition</a></p></div></div><p>In an announcement yesterday, HPE said the acquisition will enable the firm to expand its edge-to-cloud security capabilities by offering a unified Secure Access Service Edge (SASE) solution. </p><p>This, the company revealed, will help meet “increasing demand” for integrated networking and security solutions in a rapidly expanding and increasingly competitive global marketplace. </p><p>Axis, based in Tel Aviv, provides a cloud-native SSE platform called Atmos, which delivers “authenticated user access to private applications at the network edge”, a secure web gateway, and a cloud access security broker that provides in-line access to SaaS apps. </p><p>HPE said it will integrate Axis Security technology within its existing <a href="https://www.itpro.com/infrastructure/network-internet/368369/hpe-wins-contract-to-provide-the-home-depot-with-aruba-edge" data-original-url="https://www.itpro.com/infrastructure/network-internet/368369/hpe-wins-contract-to-provide-the-home-depot-with-aruba-edge">Aruba secure networking services</a> in a bid to bolster its SASE offering, which delivers WAN and cloud security controls directly to the application network edge as opposed to routing data through a data centre. </p><p>This will help customers flexibly deliver provider networking components as a service through one dedicated point of control instead of acquiring, maintaining, and licencing separate components individually. </p><p>“Our SSE platform is a natural complement to Aruba’s SD-WAN, network firewall, and dynamic segmentation offerings,” said Dor Knafo, CEO of Axis Security.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9qDUhmSsLu8o6C4Q9NqjAX" name="9qDUhmSsLu8o6C4Q9NqjAX.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/9qDUhmSsLu8o6C4Q9NqjAX.png" mos="https://cdn.mos.cms.futurecdn.net/9qDUhmSsLu8o6C4Q9NqjAX.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>PowerEdge - Cyber resilient infrastructure for a Zero Trust world</strong></p><p class="fancy-box__body-text">Combat threats with an in-depth security stance</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/370028/poweredge-cyber-resilient-infrastructure-for-a-zero-trust-world" data-original-url="/security/cyber-security/370028/poweredge-cyber-resilient-infrastructure-for-a-zero-trust-world">FREE DOWNLOAD</a></p></div></div><p>“Together, we create a unified SASE platform, designed to extend connectivity to edge, and do so through a combination of modern access services – all working together in harmony.” </p><p>In addition, HPE revealed its <a href="https://www.itpro.com/cloud/369663/hpe-expands-partner-ecosystem-amid-greenlake-updates" data-original-url="https://www.itpro.com/cloud/369663/hpe-expands-partner-ecosystem-amid-greenlake-updates">GreenLake</a> edge-to-cloud platform will also integrate Axis Security’s cloud-native SSE platform. </p><p>“As we transition from a post-pandemic world, and a hybrid work environment has become the new normal, a new approach is needed for network edge security to protect critical SaaS applications,” said Phil Mottram, executive vice president and general manager at HPE Aruba Networking. </p><p>“The convergence of Aruba and Axis Security solutions will transform edge-to-cloud connectivity with a comprehensive SASE solution that provides enterprises with the highest levels of security for both IoT devices and all users’ access across geographically distributed locations.” </p><p>Mottram said the acquisition builds on a <a href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/370129/hpe-eyes-private-5g-expansion-with-athonet" data-original-url="https://www.itpro.com/business-strategy/mergers-and-acquisitions/370129/hpe-eyes-private-5g-expansion-with-athonet">recent acquisition</a> of private cellular technology provider Athonet, as the company accelerates plans to expand SASE and private 5G solutions for customers. </p><p>Following the acquisition last month, HPE said the combination of its Aruba intelligent edge platform with Athonet will deliver the “most complete private 5G and Wi-Fi portfolio” currently available on the market. </p><p>“Combined with the HPE telco and Aruba networking portfolios, Athonet will put HPE at the forefront of a growing market that is predicted by IDC to increase to more than $1.6 trillion by 2026,” the company said. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SolarWinds Network Performance Monitor 2022.4 review: Quirky licensing and a remarkable range of troubleshooting tools ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370102/solarwinds-network-performance-monitor-20224-review</link>
                                                                            <description>
                            <![CDATA[ Lots of optional extras to consider, but NPM delivers a big monitoring toolbox in a smart web console ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jj9V9uE6bR77w7dWNCbCWk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K7o8QuCLZYQDJwN3cSh2AD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Feb 2023 12:00:08 +0000</pubDate>                                                                                                                                <updated>Fri, 23 Jun 2023 08:50:12 +0000</updated>
                                                                                                                                            <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K7o8QuCLZYQDJwN3cSh2AD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The SolarWinds NPM console ]]></media:description>                                                            <media:text><![CDATA[The SolarWinds NPM console ]]></media:text>
                                <media:title type="plain"><![CDATA[The SolarWinds NPM console ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K7o8QuCLZYQDJwN3cSh2AD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>SolarWinds offers one of the most extensive ranges of network management products and its Network Performance Monitor (NPM) has always taken pride of place. This is no surprise: it offers a wealth of network troubleshooting and monitoring features all easily accessed from the same Orion web console that's used by all its stablemates.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/network-security/370057/paessler-prtg-network-monitor-224-review-extremely-versatile" data-original-url="/security/network-security/370057/paessler-prtg-network-monitor-224-review-extremely-versatile">Paessler PRTG Network Monitor 22.4 review: Extremely versatile network monitoring</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools" data-original-url="/business/business-operations/367876/best-network-monitoring-tools">Best network monitoring tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/366982/paessler-prtg-network-monitor-214-review-hard-to-beat" data-original-url="/infrastructure/network-internet/366982/paessler-prtg-network-monitor-214-review-hard-to-beat">Paessler PRTG Network Monitor 21.4 review: Hard to beat</a></p></div></div><p>You need to be careful with licensing, though, as it's based on monitored elements, which can be nodes, interfaces and volumes. We've shown the price for an SL250 yearly subscription licence, which allows you to monitor up to 250 of each type, but if any single element goes over this limit, you'll need to upgrade to an SL500 licence, which pushes yearly costs to £4,594.</p><p>New features in NPM 2022.4 aren't very exciting. Along with visibility into VeloCloud SD-WAN services, the interface status views have been improved to show their assigned alert thresholds. NPM can monitor and report on Microsoft Azure cloud services, but for Amazon Web Services, you'll need the optional <a href="https://www.itpro.com/cloud/369995/solarwinds-hybrid-cloud-observability-review-the-big-network-picture" target="_blank" data-original-url="https://www.itpro.com/cloud/369995/solarwinds-hybrid-cloud-observability-review-the-big-network-picture">SolarWinds Hybrid Cloud Observability</a> or Server and Application Monitor products.</p><p>It took 90 minutes on a Windows Server 2019 host for the routine to download and install all the required components. When evaluating <a href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools" target="_blank" data-original-url="http://https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools">NPM</a> you can use the included SQL Server Express, which has a 10GB database limit, but this isn't supported for production environments so you'll need to source a full version of <a href="https://www.itpro.com/sql/30242/what-is-sql" target="_blank" data-original-url="https://www.itpro.com/sql/30242/what-is-sql">SQL Server</a> 2016 or later.</p><p>Our first network discovery took ten minutes, and NPM reported back with a detailed list of all our lab systems. Discovery tasks can be scheduled to run at regular intervals and will alert you when changes have occurred or new devices are detected.</p><p>The Orion web console presents an avalanche of information that can be refined with customised views. New dashboards are produced by adding extra columns, choosing resource views and placing them in the desired order and, if you run out of room, the network operations centre rotates through multiple dashboard views at predefined intervals.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LRT7yhXiMvaMhyff3P9Yqb" name="" alt="The SolarWinds NPM user interface" src="https://cdn.mos.cms.futurecdn.net/LRT7yhXiMvaMhyff3P9Yqb.jpg" mos="https://cdn.mos.cms.futurecdn.net/LRT7yhXiMvaMhyff3P9Yqb.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Coloured icons highlight device issues, with the console's Alerts & Activity tab providing a detailed overview where you can drill down into each entry to see what the problem is. The Message Center adds full search facilities and alerts can be linked to actions such as sending SMS messages and emails.</p><p>NPM provides only basic availability monitoring of virtualisation hosts so you may need to consider the Virtualization Manager, which offers much more but costs £1,337 for an 8-socket licence. Snapping into the Orion web console, it presented plenty of details about our VMware and Hyper-V hosts, including CPU, memory and datastore use, along with VM resource usage. </p><p>Businesses that need to quickly identify the root cause of problems will find the NPM Performance Monitor a boon as it compares data collected from multiple monitors in one dashboard. You can also stay on top of cloud service performance issues with NPM's NetPath, which probes external web locations and provides hop-by-hop maps with latency and packet loss details.</p><p>NPM's Quality of Experience (QoE) service is another winner. This uses sensors linked to switch mirror ports to identify, categorise and analyse traffic for over 1,500 apps. The QoE dashboard is ideal for keeping an eye on app usage: it displays transactions, traffic volumes and response times, and separates them into business, social and potentially risky categories.</p><p>The quirky licensing needs to be kept under control, but NPM offers a remarkable range of network monitoring and troubleshooting tools. The Orion web console is well-designed and easily customised, ensuring support staff always stay one step ahead of network problems.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Paessler PRTG Network Monitor 22.4 review: Extremely versatile network monitoring ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/370057/paessler-prtg-network-monitor-224-review-extremely-versatile</link>
                                                                            <description>
                            <![CDATA[ With all sensors included in the price, PRTG is a great choice for SMBs that want the big network picture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2RbhkTVdFbDa251agCeUy5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tCKndqzr9pApDbykuMYMyM-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Feb 2023 12:00:05 +0000</pubDate>                                                                                                                                <updated>Wed, 08 Nov 2023 15:35:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5BukGWzBsbwY54VJpZvHoi.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Dave is an IT consultant and freelance journalist specialising in hands-on reviews of computer networking products covering all market sectors from small businesses to enterprises. Founder of Binary Testing Ltd – the UK’s premier independent network testing laboratory - Dave has over 45 years of experience in the IT industry. He started his career working on mainframe computers including ICL and Unisys within the pharmaceutical, services and corporate financial sectors and managed one of the largest Unisys mainframe installations in the world.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Since moving into journalism in 1994, Dave has produced many thousands of in-depth business networking product reviews from his lab which have been reproduced globally. Writing for ITPro and its sister title, PC Pro, he covers all areas of business IT infrastructure, including servers, storage, network security, data protection, cloud, infrastructure and services.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/tCKndqzr9pApDbykuMYMyM-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Paessler prtg network monitor user interface ]]></media:description>                                                            <media:text><![CDATA[The Paessler prtg network monitor user interface ]]></media:text>
                                <media:title type="plain"><![CDATA[The Paessler prtg network monitor user interface ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tCKndqzr9pApDbykuMYMyM-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Paessler&apos;s PRTG network monitor is probably one of the most versatile network monitoring products on the market thanks to its simple sensor-based licensing. Just choose the sensor pack you require and it can be assigned to anything on the network you want PRTG to keep a close eye on. And when we say anything, we mean it. The PRTG network monitor 22.4 on review currently offers 284 different types of sensor covering almost every type of network device, server, workstation, hardware component, service and business application.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools" data-original-url="/business/business-operations/367876/best-network-monitoring-tools">Best network monitoring tools</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/364372/beyond-network-monitoring" data-original-url="/infrastructure/network-internet/364372/beyond-network-monitoring">Beyond network monitoring</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/366982/paessler-prtg-network-monitor-214-review-hard-to-beat" data-original-url="/infrastructure/network-internet/366982/paessler-prtg-network-monitor-214-review-hard-to-beat">Paessler PRTG Network Monitor 21.4 review: Hard to beat</a></p></div></div><p>Value looks even better, since the price includes sensors for monitoring VMware, Hyper-V, Citrix XenServer and Nutanix virtualisation hosts – features some competing vendors charge extra for. Even better, higher-level functions such as NetFlow, sFlow and jFlow monitoring are included as well.</p><p>With a perpetual 1,000-sensor licence costing €2,499, PRTG is good value, but if you don't want to incur the extra cost of a host system, Paessler can run it in the cloud for you. A yearly hosted 1,000-sensor licence costs €2,399 and you can monitor your local networks by installing remote probes in them. </p><p>Either way, you'll need to keep a close eye on sensor usage. During its first discovery, PRTG assigns the most appropriate ones to each device and they can get used up very quickly. For example, a 24-port TP-Link gigabit switch was awarded 47, our VMware ESXi 7 host received 31 and a Windows Server 2019 Hyper-V host slurped up 48 more.</p><p>Fortunately, the PRTG web console home page provides a complete summary showing the total number of sensors in use. If you have devices no longer on the network or components you don't want to monitor, you can delete them and return unused ones to the sensor pool for use elsewhere.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="xQJcGa8eoyMUvcycoGnKbZ" name="" alt="Paessler user interface" src="https://cdn.mos.cms.futurecdn.net/xQJcGa8eoyMUvcycoGnKbZ.png" mos="https://cdn.mos.cms.futurecdn.net/xQJcGa8eoyMUvcycoGnKbZ.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>PRTG's main device view is capable of presenting a huge amount of information that can be neatly organised into hierarchical groupings. You can use these to represent things such as network locations, sets of application servers, cloud services, virtualisation hosts and so on. When devices are moved to other groups they inherit settings such as discovery schedules and login credentials from the parent group, or they can have their own settings.</p><p>Network pain points are easy to spot as each sensor is assigned a colour showing if they are up, down, paused or in a warning state. Plus, PRTG provides plenty of alerting methods including email, SMS, Syslog, <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" target="_blank" data-original-url="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a> and <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops" target="_blank" data-original-url="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Microsoft Teams</a>. Clicking on any device pulls up a complete overview and activity graphs of all its associated sensors.</p><p>You can drill down deeper into selected sensors and see activity summaries, live views and details of what's occurred over the past 48 hours, week, month or year. It's easy to spot the busiest devices from the Top 10 sensor page and you can use PRTG's libraries to load groups of sensor data for comparison.</p><p>Paessler provides pre-configured libraries for views such as CPU, memory and network interfaces, and you can easily create custom libraries for more specific activities. PRTG can be remotely monitored from a web browser or you can use Paessler's slick <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">Windows</a> and macOS desktop apps, which provide the same features and just as much information. Mobile support is simply the best as the free Android and iOS apps can remotely access the PRTG server, display all sensor data and receive alerts.</p><p>PRTG Network Monitor is a great choice for SMBs and the ability to assign sensors to any device you want makes it extremely versatile. It provides lots of informative consoles and everything is included in the price so you don't need to concern yourself with optional modules.</p><p><em>Paessler PRTG Network Monitor 22.4 requirements: Core Server and Probe: Windows 10 Server 2012 R2 upwards</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: How secure is metaverse tech? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech</link>
                                                                            <description>
                            <![CDATA[ If we're not careful, the risks of this new frontier could outweigh the rewards ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hiH2QHFVmKCi5G9beQYTZw</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Nov 2022 18:35:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XUeGWhY7e8yR6tXnpQo2V-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Metaverse technology: although it still hasn’t found its feet, it’s the headline-grabbing area of development that has seen massive investment in just the past few years. Meta has spent over $15 billion on the tech through its Reality Labs division, and Microsoft, Apple, Nvidia, and more have all begun development using variations on metaverse tech.</p><p>But like any new technology, metaverse tech will also usher in new security risks, from innovative threat actors and existing vulnerabilities inherited by building this new frontier on legacy architecture.</p><p>This week, we spoke to Rick McElroy, Principal Cyber Security Strategist at VMware, about the opportunities and challenges metaverse tech, and what we can do while it’s still in its infancy.</p><iframe frameborder="0" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=51929629&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 id="highlights">Highlights</h2><p>“The cool part of all of it is, we actually get to design it. Right? Like, we're humans, we're now working on some in the future. And so we do get to look at the past, have those design considerations? And then really move forward with like, how can we start to fundamentally get rid of some of these things from the beginning, because we know that they're going to happen, right? And so I hope the opportunity is exciting for folks that are working on those projects.”</p><p>“I can tell you, I've talked to no CISOs over the last 18 months where it's at the top of their project list. Generally speaking, ransomware is still at the top of that list. Again, the security fundamentals of being able to patch as quickly as possible, and then of course, recover from some types of these attacks.”</p><p>“We're not writing a new internet protocol for the metaverse, it's going to be IPv6 and IPv4. Generally speaking, it'll be IPv6, because it's a lot of new companies that are adopting it. Manipulation of that TCP/IP stack is still real, those threats exist all the time, adversaries take advantage.”</p><p><a href="https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech" data-original-url="https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech"><em>Read the full transcript here.</em></a></p><h2 id="footnotes">Footnotes</h2><ul><li><a href="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3" data-original-url="https://www.itpro.com/infrastructure/network-internet/367513/what-is-web3">What is Web3 and will it revolutionise the internet again?</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/359093/microsoft-signs-22bn-deal-to-supply-us-army-with-hololens" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/359093/microsoft-signs-22bn-deal-to-supply-us-army-with-hololens">Microsoft signs $22bn deal to supply US Army with HoloLens devices</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/361676/apple-mixed-reality-ar-headet-2022-launch-analyst" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/361676/apple-mixed-reality-ar-headet-2022-launch-analyst">Apple's mixed reality headset could debut in 2022</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/357592/why-ar-not-vr-is-the-next-big-thing-in-business">Why AR, not VR, is the next big thing in business</a></li><li><a href="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker" data-original-url="https://www.itpro.com/business/business-strategy/369410/metas-earnings-are-cause-for-conern-and-2023-looks-even-bleaker">Meta's earnings are 'cause for concern' and 2023 looks even bleaker</a></li><li><a href="https://www.itpro.com/technology/voice-assistant/367610/future-of-virtual-assistants-lies-in-the-metaverse" data-original-url="https://www.itpro.com/technology/voice-assistant/367610/future-of-virtual-assistants-lies-in-the-metaverse">The future of virtual assistants might lie in the metaverse</a></li><li><a href="https://www.mentalfloss.com/article/55136/did-pentagon-really-ban-furbys" data-original-url="https://https://www.mentalfloss.com/article/55136/did-pentagon-really-ban-furbys">Did the Pentagon really ban Furbys?</a></li><li><a href="https://www.itpro.com/security/368221/what-is-metaverse-security" data-original-url="https://www.itpro.com/security/368221/what-is-metaverse-security">What is metaverse security?</a></li><li><a href="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points" data-original-url="https://www.itpro.com/security/cyber-security/356762/protect-your-end-points">How to protect your endpoints</a></li><li><a href="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what" data-original-url="https://www.itpro.com/security/cyber-security/354468/if-not-passwords-then-what">If not passwords then what?</a></li><li><a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip" data-original-url="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">What is TCP/IP?</a></li><li><a href="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip" data-original-url="https://www.itpro.com/network-internet/internet-protocol-version-6-ipv6/360855/what-is-tcpip">Whatever happened to IPv6?</a></li><li><a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">What is zero trust?</a></li><li>What is GDPR? Everything you need to know, from requirements to fines</li><li><a href="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa" data-original-url="https://www.itpro.com/network-internet/34504/what-is-the-california-consumer-privacy-act-ccpa">What is the California Consumer Privacy Act (CCPA)?</a></li><li><a href="https://www.itpro.com/business-operations/sales/366246/understanding-pci-compliance-the-role-of-the-channel" data-original-url="https://www.itpro.com/business-operations/sales/366246/understanding-pci-compliance-the-role-of-the-channel">Understanding PCI compliance: The role of the channel</a></li><li><a href="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7" data-original-url="https://www.itpro.com/infrastructure/network-internet/366963/what-is-wi-fi-7">What is Wi-Fi 7?</a></li><li><a href="https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack" data-original-url="https://www.itpro.com/security/368469/us-unveils-encryption-tools-to-withstand-quantum-computer-attack">US unveils next-gen encryption tools to withstand quantum computing attacks</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/368873/seven-steps-to-keeping-metaverse-meetings-safe-and-secure" data-original-url="https://www.itpro.com/business-strategy/collaboration/368873/seven-steps-to-keeping-metaverse-meetings-safe-and-secure">Seven steps to keeping metaverse meetings safe and secure</a></li><li><a href="https://www.itpro.com/business/business-strategy/369294/meta-deepens-metaverse-partnership-with-microsoft-and-accenture" data-original-url="https://www.itpro.com/business/business-strategy/369294/meta-deepens-metaverse-partnership-with-microsoft-and-accenture">Meta deepens metaverse partnership with Microsoft and Accenture, still lacks compelling business case</a></li><li><a href="https://www.itpro.com/technology/augmented-reality-ar/361197/immersive-tech-can-be-more-than-just-a-gimmick" data-original-url="https://www.itpro.com/technology/augmented-reality-ar/361197/immersive-tech-can-be-more-than-just-a-gimmick">Immersive tech can be more than just a gimmick</a></li><li><a href="https://www.itpro.com/business-strategy/digital-transformation/368403/siemens-and-nvidia-partner-on-industrial-metaverse" data-original-url="https://www.itpro.com/business-strategy/digital-transformation/368403/siemens-and-nvidia-partner-on-industrial-metaverse">Siemens and Nvidia partner on industrial metaverse concept</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned" data-original-url="https://www.itpro.com/business-strategy/collaboration/367376/into-the-metaverse-everything-we-learned">Into the metaverse: Everything we learned from our virtual tour</a></li><li><a href="https://www.itpro.com/business-strategy/collaboration/362032/metaverse-waste-of-time-effort-and-processing-power" data-original-url="https://www.itpro.com/business-strategy/collaboration/362032/metaverse-waste-of-time-effort-and-processing-power">The metaverse is a waste of time, effort and processing power</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/magazine-signup" data-original-url="https://www.itpro.com/magazine-signup">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Podcast transcript: How secure is metaverse tech? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369544/podcast-transcript-how-secure-is-metaverse-tech</link>
                                                                            <description>
                            <![CDATA[ Read the full transcript for this episode of the IT Pro Podcast ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mzq5HmLipZZjt4E3zeQ67Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Nov 2022 18:35:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast logo with the episode title &amp;#039;How secure is metaverse tech?&amp;#039;&amp;#039;]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wq7yNVyNy9FZJZnBm4HkfK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><em>This automatically-generated transcript is taken from the IT Pro Podcast episode</em> ‘<a href="https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech" data-original-url="https://www.itpro.com/security/369545/the-it-pro-podcast-how-secure-is-metaverse-tech">How secure is metaverse tech?</a>’ <em>We apologise for any errors.</em></p><h2 id="rory-bathgate">Rory Bathgate</h2><p>Hi, I’m Rory Bathgate. And you’re listening to the IT Pro Podcast, where this week we’re considering the risks and rewards of metaverse technology. In just the past few years alone, metaverse technology has seen massive growth and investment. Facebook retooled itself as Meta last year, and the company has subsequently spent over $15 billion on the tech through its Reality Labs division. Meanwhile, other big names in tech such as Microsoft and Nvidia have announced forays into metaverse tech themselves, and McKinsey says that in all, over $120bn was spent on metaverse tech in the first five months of 2022. But like with all innovations in the tech industry, metaverse tech carries the potential to bring many vulnerabilities along with its proposed benefits, with existing vulnerabilities carried across to this new frontier along with the potential for novel threats that make use of metaverse technology also becoming an issue. This week, we’re speaking to Rick McElroy, Principal Cyber Security Strategist at VMware, about the challenges posed by metaverse tech, and what can be done to address these while it’s still in its infancy. Rick, thanks so much for being on the show.</p><h2 id="rick-mcelroy">Rick McElroy </h2><p>Hey, thanks for having me. </p><h2 id="rory">Rory </h2><p>So just to start off with, what do you see as the main business use cases for Metaverse technology?</p><h2 id="rick">Rick </h2><p>Oh, that's interesting. I personally, think about the cost savings of sending humans like myself all over the globe, to whether that's facilitation of a meeting, audit, controls some sort of incident response engagement, there is a huge cost to transporting humans all over the globe to do their job, right. There's a huge cost to educate those humans. You just got back from VMware Explorer. And I think certainly organisations have explored something like virtualized conferences during the pandemic. And then I would say, as that starts to mature, as it starts to become more real, I do expect organisations to, to achieve some cost savings by being able to bring together people remotely in these types of areas. I certainly think I'm in the education space. This is a huge area where you can have virtualized universities where there's better connection than we do from an online university perspective. And so I do think, you know, some of those verticals are exploring those areas today. </p><h2 id="rory-2">Rory </h2><p>Fantastic. So you mainly see it as one of many tools to bring into the workplace, not necessarily radically changing how offices work in any way, potentially, but maybe for specific use cases, such as in education and in conferencing?</p><h2 id="rick-2">Rick </h2><p>I think potentially, in the end. But if you look at what happened over the pandemic, so the realism of having to send employees home caused a lot of organisations to have to change technologies change process, do all of these things. Well, we're back on the other side. And some companies have decided to start to bring people back to offices. And so it is a long tail, especially inside of organisations to adopt technology. When you look at certain verticals, certainly the federal vertical, the state and local verticals and municipalities and governments, they're just a little slower to bring that tech in, right? And so I know, meta, and all the good folks are instantly gonna see some consumer adoption. But I think in organisations, there'll be a vetting period. </p><h2 id="rory-3">Rory </h2><p>That's interesting that there might be a public private, delayed adoption. I mean, of course, that's something that we see across the tech sector. But it's interesting that you mentioned that. So assuming that metaverse technology does really take off in a big way, and certainly a lot of really large tech firms like Microsoft, Apple, of course, Meta. They all seem to think it will. What are some of the immediate cyber security concerns that it will raise? </p><h2 id="rick-3">Rick </h2><p>Well, I think the first one for me is we're building a bunch of new tech on top of old technology. So if you look at the back end of what's being built, it's still sitting on top of Linux servers with containers, which we fundamentally know are insecure based on lots of threat analysis, and lots of consulting with companies. And then of course, watching what the attackers are doing, right? So my first concern is, with any new technology, not building that with the misuse cases in mind, as a rush to market generally becomes, I think, concerning from a security and risk perspective. And so, I think having some thoughtfulness as we start to deliver some of this new technology specific areas that I think about: we haven't quite nailed identity yet, and misuse of identity. So those are key areas that I think if we dragged relying on passwords into the metaverse, that's probably a path that we know. It's a recipe towards breaches and towards some of that disastrous results. But I think if we're thoughtful about things like identities, if we're thoughtful about controls that we put in place to help identify folks, so that they can't run scams or report some of the misinformation that we see from other platforms, those types of things, great. But I think we're moving a little faster than then I think the security and privacy community's comfortable with.</p><h2 id="rory-4">Rory </h2><p>Yeah, I mean, you know, you're a cybersecurity expert yourself. I think there are a lot of cybersecurity experts right now who are shaking their heads going. No, we've, you know, we want to move away from the whole password headache and towards something more more secure something, you know, this is a software error. This is a technology in its infancy, maybe we can design something from the ground up, you know, is properly secured by design. On that note, there's been talk I know around continuous digital authentication, and the role that that can play in the metaverse or in metaverse tech, I should say. So, could you talk a bit about that? For those who don't know, could you lay out what it is in brief and how it could help in this role?</p><h2 id="rick-4">Rick </h2><p>Yeah, absolutely. The idea of a continual, you know, authentication strategy. Most people are familiar with a one time authentication, I go to a website, I need a service, it has a login, I use a username and password, good to go, right? Continual auth moves towards using factors to continually authenticate the device, the identity of the human that's on the device. And then of course, other factors, one of which will probably be biometrics as we start to look towards that future with Meta. But I think the intrinsic risk is really, you know, this idea of to actually get to a place where you can use continual auth on an identification, it butts up against privacy. Right, so for nations that are concerning, and certainly citizens that are concerned about privacy, as we start to gather this data, it clearly butts up against the line of privacy. And I think for some of the organisations that are involved in the build out of the metaverse, or whatever we wind up adopting as that nomenclature in the future, hey've shown that they haven't been good shepherds of privacy today. And so I think them having some transparency and addressing their current issues would help alleviate some of the concerns in the future.</p><h2 id="rory-5">Rory </h2><p>That's interesting. And on that point of the nomenclature, I think, certainly right now there is a tendency to talk about the metaverse, which is often I guess, just by name association, and by the amount of money that they've poured into it already associated with Reality Labs, other researchers at Meta, and with Meta itself. Do you think that we need to be having conversations right now around maybe broadening the term out and not letting it fall into the hands of a very choice few players and maybe broadening the technology out in its infancy?</p><h2 id="rick-5">Rick </h2><p>Well, I mean, I certainly think it's brilliant. I will credit that. I mean, it's pretty brilliant, what they did. Um, that being said look Apple is, you know, currently developing their technology and platforms. So I have a feeling their ecosystem is going to do what Apple's ecosystem does right. And so I do see them as a major player in this market moving forward, but that's all going to look different. Look, I think Apple has taken a different stand on privacy and security than some of the other vendors, I appreciate what they've done. They've certainly helped to secure these devices, I think they've enabled a world, or are starting to enable the world where we're not just ad tracks, and all of this private data is floating around for those purposes. And so I think, having a vision towards that, as we start to deliver that it's going to benefit all of the consumers of that technology, right? And so I do think we have to broaden this out, because they think if we continually say "one organisation is going to own the future of a virtual reality world," that's probably going to be incorrect. There'll be a number of technology players, Nvidia is doing some really cool things with this digital clone of Earth and being able to, you know, look at storm patterns, and all of this really cool stuff. We know, the military is embracing AR and VR for training purposes, to drive down the cost of, you know, sending munitions down range, and again, being able to do that stuff. And so I do, but I think fundamentally, we have to ask ourselves the question, what do we want in this future? And I think everybody needs a voice at that table. Certainly security should be at the table, but there needs to be other consumer voices there as well, to advocate for things like what happens when we have cyber stalking and bullying, how are we going to do this? What are we going to do when you have completely made up personas in a in a virtualized reality? That look like me that talk like me, how am I as a consumer going to be able to vet Rory on the other end of this call in a virtualized world, to know that that's actually who it is that I'm talking to, and then take action based on that. And you can imagine, in a corporation where a CEO can tell a CFO to wire transfer hundreds of thousands of dollars outside of a company, that's going to become a problem. We were already seeing that in the current version of the digital world that we have. And we will certainly see massive amounts of scam and fraud inside of you know, the metaverse virtual reality, whatever we call that,</p><h2 id="rory-6">Rory </h2><p>Right I mean, I know that there are already, you do see reports around deep fakes being used for job interviews. And some of that might be at the moment, again, still in its early stages. But certainly, I can see the potential for identity fraud and phishing to kind of take on a whole new, a whole new identity in this new realm. I guess on that note, what do you what do you think, like a metaverse threat actor will look like?</p><h2 id="rick-6">Rick </h2><p>It's very interesting. So what I think about is how cybercriminals always look at technology, right? And so again, because I got to wear this adversarial hat for a long time, and still do, and we think about the misuse cases, right? So it's pretty typical developer wants to get the thing working. How do we do this at scale? How do we make sure we're not burning people's eyeballs out or engaging the brain? These are all considerations as we're strapping things to our faces, right? From our perspective, we look at misuse cases. So how can I start to deny service to that thing, so that I can make the consumer or the organisation pay me some sort of extortion? Right? How can I start to — and you've seen some of this in attempts of virtualized worlds. How can I do something like digital mods that fill up a space that's supposed to be a safe space that's created for something right, so I'm interfering, you know, on those fronts, and then, of course, I'm how can I get to the money, right? So if the answer is, well, it's easier for me to go into the metaverse and scam a nother human than it is for me to create a bunch of malware that I then have to test, send out, figure out who QAs it, get somebody to click on a link, like I know we purport that it's fairly easy to trick humans. But that being said, we've got a bunch of technology to do that. That won't exist in the metaverse, right. So you can expect a number of security companies to start to address the risks as well. And then certainly, as companies start to adopt it, I mean, I think back to something simplistic, like when, when Furbies came out, right? And then the DoD banned them from the Pentagon because they recorded conversations, or Google Glass was banned from Google campuses when it came out because it recorded right. And so how does the other person know that the conversations report being recorded? Did they consent? All of those things, those are all considerations from a legal perspective and a risk perspective, we're gonna have to build into this new world. And I think, look, the cool part of all of it is, we actually get to design it. Right? Like, we're humans, we're now working on some in the future. And so we do get to look at the past, have those design considerations? And then really move forward with like, how can we start to fundamentally get rid of some of these things from the beginning, because we know that they're going to happen, right? And so I hope the opportunity is exciting for folks that are working on those projects.</p><h2 id="rory-7">Rory </h2><p>I had never heard about that Furby ban. That's, that's incredible. It does raise kind of an interesting point, though, which is that certain dichotomies that currently exist in the sector are going to, I guess, necessarily have to be carried over into metal as tech, such as public and private sector. If you're talking about educational bodies, but also government entities, perhaps even like you're saying the Department of Defence wanting to use metaverse tech versus versus private companies, are the necessary discussions around that happening right now? Or do you think there's there's too much focus on the maybe the private sector applications, the business applications of this tech right now?</p><h2 id="rick-7">Rick </h2><p>I think governments across the globe are struggling with the tech that they have, and so they're hesitant to start to adopt it. Certainly, you know, folks like DARPA, and some of the research agencies have, that's what they do. But I think more broadly, as you look at governments, they're really struggling with patching. They're, they're struggling with endpoint detection and response and being able to report that they've had a breach. Right? So you see, new executive orders new legislation across the globe, to try to get them to a place where it's reasonable security to build on top of, and so I do expect for the next few years, they have some fundamental projects and some heavy lifts that they're going through. Great, we encourage it, we're helping them as much as possible along with, I think, a lot of other vendors, but then they'll start to build upon that right. And so getting something like continual authentication over the technology they have, they they they're going to have to figure that process out, they're gonna have to figure the tech out, and then they can build on it, right? And so my expectation in the future is the work they're doing now, from a security fundamentals perspective, will benefit them in the future.</p><h2 id="rory-8">Rory </h2><p>That's fantastic. So you mentioned you made a reference there to some of the work that VMware has been doing in this space. And in, in general, across the across the industry. Seeing, or given that this is something that is likely to create massive waves in the tech sector, however, it turns out, what is VMware specifically currently doing in anticipation of this sort of big shift?</p><h2 id="rick-8">Rick </h2><p>Well, look, I mean, I think we have to work on this idea that things are born secure. So so you'll hear us say this a lot. You'll hear us talk about this a lot. What does that mean? It means that the design considerations for security and misused or thought about upfront, and then technology enables developers to be able to deliver that in a way that covers the full lifecycle. Now look, that's a whole mouthful, all of the security professionals that are listening in the IT professionals will understand parts and pieces of that, maybe that is a big piece is your secure software design lifecycle. A big piece is going to be the ability to contextualise all of the data and telemetry to be able to do you know, behavioural analysis to find the bad guys. That being said, what we're really working on, is this idea that applications and infrastructure are born secure, maintained throughout the entire lifecycle of that workload, that application, that server in a secure fashion, and then eventually turned off securely, right? So whether that's an encryption of data and deletion, whether that's ensuring that your data is backed up to an air gapped environment, that then is restored clean, all of those things is really, I think, what VMware is working on, because we understand, we're the fundamental virtualization technology that lives underneath all of this, right? And so, when we look at it, it's a stack, we have to provide, I think, strong prevention and detection controls there that other people can rely on build the top up, and that's what we're focused on.</p><h2 id="rory-9">Rory </h2><p>And in your discussions with customers, is this coming up more and more as a concern, or maybe something that they're excited about that you're having to then discuss with them about the actual reality of it?</p><h2 id="rick-9">Rick </h2><p>I'm very lucky, I live on the West Coast of America, and I work with West Coast companies. So we have a tendency to move a little faster than I think a whole lot of other places. So yes, I would say Northern California is already in some cases adopting, you see a lot of companies that are being built around it right to do those things. That being said, the rest of the globe, intentionally is a little slower, right? I mean, after all, these are the pioneers that are proving the tech and all of that stuff, right. So I get to see a little preview, I get to see some of the folks that are working on it. And then I think I have a pretty strong idea, as I talk to people about it. I can tell you, I've talked to no CISOs over the last 18 months where it's at the top of their project list. Generally speaking, ransomware is still at the top of that list. Again, the security fundamentals of being able to patch as quickly as possible, and then of course, recover from some types of these attacks. And then what they're really concerned about is the fewest number of tools to do the security job. So they're retooling. They're rebuilding their processes in an automated fashion, to again, with this eye towards being able to deliver quickly these other solutions coming down the road. And so fundamentally, we're fixing a bunch of stuff and architectures, to allow for the future and rapid delivery of these solutions.</p><h2 id="rory-10">Rory </h2><p>That raises an interesting question about kind of, fixing the environment we have now before moving into this new space. Do you think that, whereas people are currently kind of talking around the metaverse technology as this, this whole new realm to exist in but in its current form, it's going to have to be entrenched in a lot of the systems that we already have. Do you think that there's a potential for some of the worst problems that we're currently experiencing to currently be carried over into into Metaverse technology?</p><h2 id="rick-10">Rick </h2><p>Yes. And I'll give you one brief example. We're not writing a new internet protocol for the metaverse, it's going to be IPv6 and IPv4. Generally speaking, it'll be IPv6, because it's a lot of new companies that are adopting it. Manipulation of that TCP/IP stack is still real, those threats exist all the time, adversaries take advantage. And so again, we're using insecure protocols today that a bunch of technology had to be built on top of, to allow for things like transport layer security, session layer security, cryptography, the data at rest, all of those things, right. And so here's the good news. The good news is, we've proven a bunch of this technology over the last 25 years. I would certainly hope that again, as organisations are implementing this technology and organisations are building this technology, that we take those lessons and build them in. And crypto, in my humble opinion, it's a must like, like the fact that we are even telling consumers to consider using a VPN, like, no, your application should have good strong encryption built into it. And the consumer should not have to be concerned about the transport layer security. Now it's great that they are, I encourage everybody today to be, but that's just one small example of how the underlying, you know, internet protocols if at all are, you know, easily subverted and built on top of. And then of course, you know, Linux operating systems are still going to be in play, right? You know, things like software defined radio attacks for the chips in the motherboards, the firmware that sits underneath of all of that those are all part of the supply chain of the metaverse, and will need good security controls.</p><h2 id="rory-11">Rory </h2><p>Is there a risk that we're moving too quick with Metaverse tech right now, and we risk sort of building it on top of all of these systems and reaching a point maybe in five to ten years where it's too late, we can't pull those systems out from underneath metaverse tech?</p><h2 id="rick-11">Rick </h2><p>It's a good question. I think I have a futurist hat that I wear, and a technology hat. And I do love the future of technology. But then I have a very realist, a little bit pessimistic brain as well, which keeps me in security. So I think the pure security professionals, and if you asked any hacker, we would say yes, we're entirely moving too fast. But I think we would have said that of almost any technology. So that being said, I think there is a speed market and a balance here. Look, you've got to create a market, you got to sell into a market so that you can prove a market, go secure the market, right? And so those pieces don't exist in vacuums. And so I do think we have to move fast in certain areas. Certainly, I think I have some caution about just moving super fast when it comes to like, video game markets and stuff. Which is, fine and probably going to be where we see the largest spread of the technology first. So no, look, security is never going to get our way because if we did, it would take another 10-15 years of development. So we have to be realistic as well and say, look, I think there are amazing use cases in the future, you know, this idea that I can perform surgeries or consult for, you know, in a third world country where maybe they don't have access to surgeons. This is amazing, you know that what we're talking about here, I think, being able to bring humans together in a way, that's not a zoom box. I know the last two and a half years zoom boxes have been killing me, right? So at some point, I do think like it's going to be fun, it'll be really cool,some of the stuff we see from an AR perspective or, you know, walking into office buildings, those types. But yes, the the adversaries are going to take advantage. And they're going to look for us to make some mistakes along this development path. And they'll take advantage of it.</p><h2 id="rory-12">Rory </h2><p>So with that in mind, is this something that security teams and individual companies, on a customer by customer basis, should be worrying about yet, in anticipation of implementing this? Or is this more of a, like you were saying, a kind of secure by design concern for those architects that are leading the way in the sector.</p><h2 id="rick-12">Rick </h2><p>I think if you're bleeding edge companies, certainly you're going to look to move as fast as possible, especially if you're diversifying your business portfolio as well, where you have an existing, you know, social or web company that I think could benefit from that adoption, you're gonna move a little faster. So it is probably a design consideration over the next three years for those types of organisations. Generally speaking, again, the design consideration the architecture, discussions that we're having, fundamentally revolve around things like continual authentication, zero trust, enabling, you know, again, born secure applications, where we understand vulnerabilities that exist, and then we're able to rapidly do those. Because we ran really fast to get to this point. And so there's a little bit of reworking we have to do in architectures, and most of it has to do with cloud, right? So if you think about how we used to do security versus how we're doing it now a lot of people are reworking it. Metaverse will be a consideration as part of this strategy, only because we know the metaverse will be powered by the cloud. And generally speaking, if you're accounting for some of the cloud security components, you'll be accounting for things that you need in the metaverse as well.</p><h2 id="rory-13">Rory </h2><p>So with those security concerns to one side for a second. On a regulatory basis, how is the metaverse — this is a very broad question — but how is the metaverse going to be regulated?</p><h2 id="rick-13">Rick </h2><p>This is a great question. I generally think regulation will follow all other regulations for tech, which means it'll be late to the table. Now, I don't say that to knock legislators or regulators. Generally, it's just the way that it goes, they have to figure it out. You know, clear considerations we're going to have to think about upfront: what do we do on education especially for, you know, children? Right? And who, you know, how is that going to work? And I have a whole lot of questions, right, I got a lot of nieces and nephews, that'll probably wind up strapping a headset on at some point. But as you can imagine, if you're a parent, you have major concerns over how that works in a non-physical way today. Now, I would also say, from a safety perspective, at least in America, there's probably some benefit to moving towards these models as well, right. So I think it'll be per-vertical. I think some of the, again, some of the some of the industries will move a little bit faster than the other ones. And then what we'll see is iterations through regulations over time, right. So we know GDPR didn't get it exactly right the first time and there's the you know, we know the California Privacy Act had to change. So we'll put something out there, it'll iterate, but it probably won't be fast enough to satisfy anybody's needs. Because generally speaking again, when it comes to things like cybercrime and theft, we have to observe the behaviour, laws across the globe have to be created, they have to be voted on democracies, take a little take a little while to get that done right. And then we see some benefit from it. So I do think, particular to regulations in the industry that are helpful, something like PCI DSS, I think, is has been more meaningful for credit card encryptions and to disrupt credit card theft. So adoptions of models like that, instead of adopting, you know, models that add a bunch of overhead for no particular reason than to add the overhead right. I think there's an effective way to do that.</p><h2 id="rory-14">Rory </h2><p>It's interesting, you mentioned GDPR. But considering these issues across different continents across different countries, do you think also that this focus currently on the metaverse as if it's going to be one unified entity as opposed to a series of different metaverses used by different organisations, different entities will run into issues like data sovereignty as well, that maybe could stymie this unified vision that people are currently talking about?</p><h2 id="rick-14">Rick </h2><p>I think the metaverse will follow the real world Internet, and we thought that the internet was gonna wind up 'The Internet'. It's not actually true. There's a lot of different internets, and a lot of different rules, especially depending on how you're governed, right? So no, I don't expect that say the CCP's version of the metaverse is going to be the exact same as the UK's, or the exact same as the US's. Certainly I think, the local citizen, and the consumers are going to have a big say, because they're voting with dollars, right? But I think each government has had to, again, based on risk, based on breaches, based on privacy, has had to sort of draw that line. And so what we've ended up with is a lot of different internets, and a lot of different piles of data around. I think the metaverse is is certainly going to find that, and I can't imagine that authoritarian governments across the globe are going to want to facilitate open access to information and not having a big say in how that's developed.</p><h2 id="rory-15">Rory </h2><p>On that point of having a say, do you think that some sort of framework that companies could agree to that that governments could agree to around metaverse tech is necessary? Or or will it just naturally fall into, like you're saying, a geographic perspective?</p><h2 id="rick-15">Rick </h2><p>No, I think generally technology happens to follow that right? So whether it's IEEE standards, ISO standards that you know, NIST standards, will certainly account for it as well. And so I would assume NIST is probably already looking at some guidance around metaverse. I'm probably not in the room for like the draft discussion, but at some point, it'll come out for a draft form. We as security professionals, with the way on it will iterate through the changes make some recommendations. But yeah, I would expect there'll be specific, you know, standards for metaverse for things like communications, interoperability, all of those things. And if, if you're going to win in that space, you're going to have to be open. Like, I think it's gonna be really hard to go down the path of a closed technology unless you're someone like Apple who already has a massive consumer base</p><h2 id="rory-16">Rory </h2><p>To kind of round off the discussion: to turn one of the earliest questions I asked on its head, we've talked about a lot of the security drawbacks of metaverse tech. But given that we have an opportunity to, as you say, kind of author our own future with this technology, what are some of the real benefits or potential benefits that to security specifically, that that could be be achieved through metaverse technology?</p><h2 id="rick-16">Rick </h2><p>Well, I'll tell you one that I think about all the time. And you hear this from security professionals: I have a team of people that help me, that team might be called the manage detection and response team, it could be called managed security provider, you know, we have all kinds of names for our third parties. But one of the hardest things to achieve is the context of what's happening in the environment, right, the familiarity of each one of these humans, or these groups of humans working together to drive a singular outcome. So, when it comes to upfront consulting, when it comes to architecture design, when it comes to incident response, when it comes to facilitating incident response across the globe, being able to do briefings, man, again, I think have disparate teams sit in a room like we're with each other on a virtualized whiteboard. It's one of the hardest things that I have a problem with today, with the technology that we have in place for remote work. And yes, I know there's tonnes of companies. Yes, we've used all the tech, it is not the same as sitting down real time with six people, when someone has their hands on a whiteboard, eraser. And we're just iterating through stuff, it's just not right. So I think I'm hopeful from that perspective. And then I certainly think from, you know, from my own home life, look, again, I have to get on planes all the time, my friends all have to get on planes, we are trading off that work life balance. And I think, for us, and our experience of burnout and fatigue, and the hours, I do think particular to cybersecurity, there will be an impact to that. And then I hope, if we actually do our jobs right, with continual identity authentication, maybe we can get to a place where we start to eliminate some of this fraud, and the scams, that one human purports to another human, because all they're doing is lying and tricking the other human. So maybe we can think about those use cases in the metaverse and drive some of them down, right? And I don't know how we do that yet. Some people would say we're gonna adopt MRI technology, other people you know, it gets a little dystopian, too, right. That being said, we do have a chance to design it, we do have a chance to consider it. And so what I'm looking for, for these organisations that are building this technology, and the developers, and the architects is like proof, prove that is trustworthy. Give me the transparency that we need to adopt it. Because I think we want to, we love the future, we love it. But it's just a little risky, and so you got to give us what we need to lead the organisations to this change.</p><h2 id="rory-17">Rory </h2><p>Well it certainly sounds like if we play our cards, right, there's, there's lots to look forward to.</p><h2 id="rick-17">Rick </h2><p>Absolutely, I think it's, it's just, it's really cool, right? I mean, we're at a point where we can, we can play with our own reality in a way that's safe, we can move significant chunks of pieces, like, you know, this idea that Nvidia did with this digital Earth. And being able to use actual weather models, and what happens if we, you know, move that, like putting all those pieces together that has a huge value to humanity. And that's the exciting future that I want to make sure, you know, we safeguard and shepherd this technology through.</p><h2 id="rory-18">Rory </h2><p>Fantastic. Well, Rick, thank you so much for being on the show. </p><h2 id="rick-18">Rick </h2><p>Thanks for having me.</p><h2 id="rory-19">Rory </h2><p>As always, You can find links to all of the topics we've spoken about today in the show notes and even more on our website at itpro.co.uk. You can also follow us on social media, as well as subscribe to our daily newsletter. Don't forget to subscribe to the IT Pro Podcast wherever you find podcasts. And if you're enjoying the show, leave us a rating and a review. We'll be back next week with more insight from the world of IT but until then, goodbye.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ VMware brings XDR capabilities to Carbon Black in a push for lateral security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/369481/vmware-brings-xdr-to-carbon-black-push-lateral-security</link>
                                                                            <description>
                            <![CDATA[ The cloud giant aims to provide customers with the means to identify and rectify weaknesses across their environments ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rsMKVviJDC1TsnZX9PN5xa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LYWHzTvaR4fdwvepRyb9ig-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Nov 2022 14:03:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LYWHzTvaR4fdwvepRyb9ig-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A telephoto shot of the VMware logo on the conference floor of VMware Explore Europe]]></media:description>                                                            <media:text><![CDATA[A telephoto shot of the VMware logo on the conference floor of VMware Explore Europe]]></media:text>
                                <media:title type="plain"><![CDATA[A telephoto shot of the VMware logo on the conference floor of VMware Explore Europe]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LYWHzTvaR4fdwvepRyb9ig-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>VMware has revealed an addition to its network detection and visibility solutions in the form of Carbon Black XDR, seeking to address the very significant threat posed by lateral attacks and empower companies to combat threat actors that have already breached their networks.</p><p>Whereas <a href="https://www.itpro.com/security/31384/how-to-protect-your-business-from-endpoint-attacks" data-original-url="https://www.itpro.com/security/31384/how-to-protect-your-business-from-endpoint-attacks">endpoint detection and response (EDR)</a> reacts to endpoint data, extended detection and response attempts to provide environment-wide, comprehensive visibility on threats. In this way, VMware Carbon Black XDR adds to and extends the capabilities of VMware Carbon Black Enterprise, the threat hunting and response solution already available for VMware customers.</p><p>VMware identifies this as crucial in drawing attention to the danger of threat actors performing lateral attacks once gaining access to a system, with historical focus having been placed almost exclusively on endpoint tools to prevent malicious access altogether.</p><p>The service leverages data within VMware Contexa, the firm’s threat intelligence solution that provides observability across VMware’s network, as well as endpoint and user technologies. The company claims it processes over 1.5 trillion endpoint events daily, using <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning" data-original-url="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning (ML)</a> to contextualise this information in parallel with the input of more than 500 VMware Threat Analysis Unit partners and researchers. VMware Carbon Black XDR can then use this data to prompt action by security teams, and inform policy changes.</p><p>In August, VMware research suggested cyber attacks were on the rise following Russia's <a href="https://www.itpro.com/security/hacking/368759/vmware-warns-of-tumultuous-threats-amid-russia-ukraine-cyber-war" data-original-url="https://www.itpro.com/security/hacking/368759/vmware-warns-of-tumultuous-threats-amid-russia-ukraine-cyber-war">invasion of Ukraine</a>, with 25% of attacks seeing lateral movement by attackers once systems had been compromised.</p><p>"Lateral security is the new battleground," said Tom Gillis, SVP and general manager, networking and advanced security business group at VMware.</p><p>“By bringing VMware Carbon Black XDR to market, we’re improving threat detection and prevention across endpoints and networks to address the need from our customers to limit the lateral movement of attackers inside their environment.</p><p>"Our XDR solution is not replacing SIEM, rather it’s helping to paint a broader picture of the threat landscape for customers. We are correlating high-fidelity, process-level data from the endpoint with packet-level data on the network to create super high-fidelity and actionable alerts that can also be fed into a larger SIEM. That data is pulled from VMware Contexa, our threat intelligence cloud that combines the telemetry of Carbon Black and NSX."</p><p>VMware has been quick to note the uptake in demand for XDR solutions within the current threat environment, citing a Forrester study it commissioned which indicated that although 75% of responding organisations have not implemented XDR, 27% are planning to in the next 12 months. Data from the same study suggested that ROI increased following early adoption of the technology, bringing the boons of automation and adding another feather to the cap of existing security stacks.</p><p>Carbon Black was <a href="https://www.itpro.com/acquisition/34256/why-vmware-is-acquiring-pivotal-and-carbon-black" data-original-url="https://www.itpro.com/acquisition/34256/why-vmware-is-acquiring-pivotal-and-carbon-black">acquired by VMware</a> in 2019, in the interest of boosting security oversight across VMware’s cloud offerings. Since then, its offerings have been expanded and are now part of VMware’s array of network and endpoint security options. These include Contexa and the upcoming Project Northstar, a SaaS-based tool for network security for applying multi-cloud security policies through a central cloud console, which is currently in tech preview.</p><p>Joe Baguely, VP & CTO EMEA at VMware, spoke to <em>IT Pro</em> about how VMware Carbon Black XDR expands upon past efforts by VMware:</p><p>"We've actually been talking about these threats for over 10 years. When we first <a href="https://www.itpro.com/641899/vmware-confirms-q2-revenue-growth-and-new-acquisitions" data-original-url="https://www.itpro.com/641899/vmware-confirms-q2-revenue-growth-and-new-acquisitions">acquired Nicira</a>, which became NSX, we talked about east to west security and what we're talking about now with natural security is pretty much the same thing. But what we're doing in that space is when we talk about it back in the past, we were literally introducing the concept of having micro firewalls per workload. But it was pretty basic, pretty manual.</p><p>"What we're doing with Carbon Black and the XDR technologies and EDR, is we're making that much more intelligent. We're bringing <a href="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai" data-original-url="https://www.itpro.com/machine-learning/31708/what-are-the-pros-and-cons-of-ai">artificial intelligence (AI)</a> and ML to that. And we're bringing all the intelligence we've got around threat analysis to what's going on in the data centre, to make it much more responsive."</p><p>VMware’s NSX security solutions aim to provide consistent, <a href="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model" data-original-url="https://www.itpro.com/security/361919/how-to-build-a-zero-trust-model">zero trust</a>, multi-cloud security policies alongside granular protection such as network segmentation. The firm also states that NSX is uniquely able to combat lateral attacks, as it sits alongside a <a href="https://www.itpro.com/612016/what-is-virtualisation" data-original-url="https://www.itpro.com/612016/what-is-virtualisation">hypervisor</a> to protect individual virtual machines within a <a href="https://www.itpro.com/virtualisation/34516/vmware-vsphere-vs-proxmox-which-is-best-for-your-business" data-original-url="https://www.itpro.com/virtualisation/34516/vmware-vsphere-vs-proxmox-which-is-best-for-your-business">VMware vSphere</a> environment, and alongside <a href="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes" data-original-url="https://www.itpro.com/enterprise-applications/31654/what-is-kubernetes">Kubernetes</a> to protect native clouds.</p><p>VMware Carbon Black XDR is available for certain customers in early access, with the security specialist team handling sign up requests.</p><h2 id="carbon-black-in-action">Carbon Black in action</h2><p>"Carbon black is an absolute godsend for us," said Ed Higgs, group director of IT Shared Services at Rentokil Initial, speaking to <em>IT Pro</em>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/369472/vmware-and-hpe-unveil-new-hybrid-cloud-pay-as-you-go-service" data-original-url="/cloud/369472/vmware-and-hpe-unveil-new-hybrid-cloud-pay-as-you-go-service">VMware and HPE unveil new hybrid cloud, pay-as-you-go service</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now" data-original-url="/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now">Six cyber security holes you need to plug now</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/369478/vmware-and-equinix-cloud-bare-metal-new-distributed-service" data-original-url="/cloud/cloud-computing/369478/vmware-and-equinix-cloud-bare-metal-new-distributed-service">VMware and Equinix combine cloud with bare metal in new distributed service</a></p></div></div><p>"We're very acquisitive. We acquire just over one company a week and we've just done one for $6.1 billion - we just acquired Terminix in the US. It’s massive for us, and obviously all those acquisitions bring relative complexities, but whenever we've got an acquisition, the first thing they do is install Carbon Black, because that gives us visibility from day one."</p><p>Referring to the threat posed by lateral security, Higgs praised Carbon Black for the security insight it provides:</p><p>"We've been pretty good over years in managing the perimeter," added Higgs. "We pay companies, like everyone else, to hack us and see where they get and, of course, they're still finding things. When they first started doing it, there were massive gaping holes, and over the years we’ve matured and matured.</p><p>"Carbon Black and NSX have significantly reduced [a threat actor's] capability to do anything - because as soon as anyone elevates a role, on any of our systems, we immediately get a notification and they can go on and delete the account, segregate the environment, whatever they need to do. The last time we paid someone to hack into our systems, we had to tell the [Carbon Black team] to ignore the test, because we don't want them to stop the testers straight away, otherwise they wouldn't get to anything else that they might find."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Information security vs cyber security vs network security: What are the differences? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369418/information-security-vs-cyber-security-vs-network-security</link>
                                                                            <description>
                            <![CDATA[ A guide to the essential differences between information, network, and cyber security and the basic tenets of each ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2HJ4vtZNCMJCkfwqC9rbCb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2zGpqpHzZBsLbJfej9Lx9P-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Oct 2022 10:06:41 +0000</pubDate>                                                                                                                                <updated>Fri, 17 May 2024 15:19:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Careers and Training]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like &lt;a href=&quot;https://www.itpro.co.uk/security/cyber-security/361099/cyber-security-and-insurance-companies-evolving-with-the-threat-of-ransomware&quot;&gt;security&lt;/a&gt;, &lt;a href=&quot;https://www.itpro.co.uk/security/privacy/361191/is-australia-becoming-a-surveillance-state&quot;&gt;privacy&lt;/a&gt;, &lt;a href=&quot;https://www.itpro.co.uk/technology/artificial-intelligence-ai/359765/with-ai-on-the-rise-is-it-time-to-join-a-union&quot;&gt;worker rights&lt;/a&gt;, and &lt;a href=&quot;https://www.itpro.co.uk/business-strategy/startups/361311/why-does-japan-lag-behind-on-startups&quot;&gt;startups&lt;/a&gt;, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.&lt;/p&gt;
&lt;p&gt;After studying an undergraduate degree in Arabic and Spanish at the University of Leeds, Zach completed a journalism internship at The Argentina Independent in Buenos Aires where he wrote about the country’s history, politics, and technology.&lt;/p&gt;
&lt;p&gt;Contact him at zach.marzouk@futurenet.com or find Zach’s thoughts (and more) on Twitter &lt;a href=&quot;https://twitter.com/ZachMarzouk&quot;&gt;@ZachMarzouk&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2zGpqpHzZBsLbJfej9Lx9P-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Three lines of wooden hexagonal blocks that diverge into three discrete lines, on a bright blue background]]></media:description>                                                            <media:text><![CDATA[Three lines of wooden hexagonal blocks that diverge into three discrete lines, on a bright blue background]]></media:text>
                                <media:title type="plain"><![CDATA[Three lines of wooden hexagonal blocks that diverge into three discrete lines, on a bright blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2zGpqpHzZBsLbJfej9Lx9P-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks have become par for the course for enterprises and small and medium-sized businesses (SMBs) over the last couple of decades. </p><p>The prospect of a cyber security incident – which may range from a minor <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> infection to a major <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware</u></a> attack, with the likes of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing</u></a> and <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one"><u>social engineering</u></a> in between – is close to certain for many organizations. This is why maintaining and iterating on a strong security posture is essential across modern businesses. </p><p>But security isn’t straightforward and there are different pillars that all come together to form an organization’s outlook. Indeed, information security, <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cyber security</u></a>, and network security are all different pillars businesses need to pay attention to, which ensures there aren’t any <a href="https://www.itpro.com/security/cyber-security/368543/six-cyber-security-holes-you-need-to-plug-now"><u>holes that cyber criminals can exploit</u></a>. There are different aspects of your business that you need to protect, and slightly different schools of thought around each one – including which particular <a href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs"><u>cyber security skills</u></a> are required. </p><p>It can be easy to conflate these categories of security, which may come to complicate matters when devising a comprehensive <a href="https://www.itpro.com/security/34049/how-to-build-a-comprehensive-cyber-security-strategy"><u>business security strategy</u></a> – so it’s important to know what each school refers to and what each entails. That’s why we’ve put together a quick guide on the differences between information security, cyber security and network security, so you know exactly what your business needs when keeping the <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets"><u>hackers</u></a> out.</p><h2 id="what-is-information-security">What is information security?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PXLSqWshWUUrd9ukXp8uif" name="" alt="A close up shot of a log in menu on a computer screen showing the password field filled in" src="https://cdn.mos.cms.futurecdn.net/PXLSqWshWUUrd9ukXp8uif.jpg" mos="https://cdn.mos.cms.futurecdn.net/PXLSqWshWUUrd9ukXp8uif.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Information security, also known as InfoSec, largely centers around preventing unauthorized access to critical data or personal information your organization stores. It is the “protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability,” according to the US Computer Science Resource Center (CSRC). Information security also involves three categories: confidentiality, integrity, and availability. </p><ul><li><strong>Confidentiality: </strong>Ensuring sensitive information isn’t disclosed to unauthorized users while making sure that authorized users have access to it</li><li><strong>Integrity:</strong> Making sure that the data is accurate and complete. Here, the information shouldn’t be edited by anyone who isn’t authorized to access it</li><li><strong>Availability:</strong> Data needs to be available when it’s needed. For example, a <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack"><u>denial of service attack (DoS)</u></a> could prevent this from happening</li></ul><p>There are also several industry standards organizations must adhere to if following this triad, including maintaining password strength, using <a href="https://www.itpro.com/antivirus/28144/best-antivirus"><u>antivirus software</u></a>, deploying access controls, <a href="https://www.itpro.com/security/33974/our-5-minute-guide-to-security-awareness-training"><u>security awareness training</u></a>, and more.</p><p>Organizations can meet their information security standards by implementing a strict risk management process. It should identify information, related assets, and the threats and impact of unauthorized access. It should also monitor activities and make adjustments to address any new issues or improvements that have emerged, as well as evaluate any risks to the organization.</p><h2 id="what-is-cyber-security">What is cyber security?</h2><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="jEcgjwrxDgkjXfaDBqsrBL" name="" alt="A shield with a keyhole on a radar system denoting cyber security" src="https://cdn.mos.cms.futurecdn.net/jEcgjwrxDgkjXfaDBqsrBL.jpg" mos="https://cdn.mos.cms.futurecdn.net/jEcgjwrxDgkjXfaDBqsrBL.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p>This is the process your organization must follow to be aware of the latest and emerging cyber security threats and trends – and to protect itself in light of the <a href="https://www.itpro.com/security/cyber-security/360456/how-the-cyber-security-threat-landscape-is-changing"><u>changing cyber security landscape</u></a>. Having a healthy cyber security posture involves adopting policies such as <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust"><u>zero trust</u></a>, and using new tools and technologies to fight prospective threats where appropriate, as well as maintain compliance. Additionally, all staff within the organization must stick to these policies to make sure the business is fully protected.</p><p>As threats evolve, security policies need to be continuously evaluated and updated if need be. Your hardware and software – including endpoints and operating systems – for example, should be functional and secure to the best of your knowledge, but should also be periodically updated and refreshed. Software that you need to continuously assess includes security services, endpoint management tools, or even cloud services.</p><p>It’s also key to ensure staff follow any policies and procedures you put in place. Your business could have the best security tools out there, but it makes no difference if employees continue to <a href="https://www.itpro.com/strategy/28072/what-is-byod"><u>use their own devices</u></a> without IT’s knowledge to access data. You might also have an extensive antivirus product in force, but you must still ensure employees are aware of the dangers of <a href="https://www.itpro.com/security/29093/what-is-phishing"><u>phishing emails</u></a>.</p><h2 id="what-is-network-security">What is network security?</h2><p>Network security spans how an organization protects the usability and integrity of its network and data. This field includes both hardware and software involved in a network and aims to prevent a variety of threats from entering the business’ networks or spreading through it.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="7zHQkZEy8XcbqpjEM82LgS" name="Time matters_ Proactively prepare for and respond faster to business disruptions and disasters.jpg" caption="" alt="Time matters: Proactively prepare for and respond faster to business disruptions and disasters Whitepaper from ServiceNow" src="https://cdn.mos.cms.futurecdn.net/7zHQkZEy8XcbqpjEM82LgS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><em>Find out how you can strengthen your organization with business continuity management</em><br><br><a data-analytics-id="inline-link" href="https://www.itpro.com/security/time-matters-proactively-prepare-for-and-respond-faster-to-business-disruptions-and-disasters">DOWNLOAD NOW</a></p></div></div><p>It works by combining a number of defensive layers at the edge, and within the network perimeter. As you may assume, different policies and controls are available in each security layer. For example, authorized users must be able to access network resources, where it’s required for their specific roles, such as in a least privilege access regime, while bad actors must be blocked from carrying out any nefarious actions.</p><p>Network security is essential for all organizations as it directly affects their ability to safely deliver services or products to employees and customers. It doesn’t matter if it’s enterprise applications or accessing a <a href="https://www.itpro.com/mobile/remote-access/368050/best-free-remote-desktop-software-2023"><u>remote desktop</u></a>, ensuring the protection of data and apps on your network is vital for your business, as well as <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations"><u>securing your reputation</u></a>.</p><h2 id="what-is-the-difference-between-information-security-and-cyber-security">What is the difference between information security and cyber security?</h2><p>These two terms are sometimes used interchangeably, so it’s important to understand the differences between them. While information security is the protection of your data from any unauthorized access, cyber security is protecting it from unauthorized access specifically in the online realm.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28196/the-cybersecurity-skills-your-business-needs" data-original-url="/security/28196/the-cybersecurity-skills-your-business-needs">The cyber security skills your business needs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy" data-original-url="/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">Who should take ownership of your cyber security strategy?</a></p></div></div><p>For example, cyber security centers around preventing <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware attacks</u></a>, spyware, or compromised social media accounts, for example. An example of information security is implementing controls for intrusion detection systems or making sure hard-copy files are locked down. <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>Chief information security officers (CISOs)</u></a> need to understand and identify whether any information is confidential or critical to the organization and whether it might be targeted by hackers.</p><p>Some people might ask which is more important but these two areas go hand-in-hand. Your organization must have clear policies and procedures around how to deploy both forms of defense – not just one. Both are continuously evolving too. Ultimately, your business must understand, first, what and where the most sensitive data lies, and secondly, which specific measures it’s putting in place to protect that data.</p><h2 id="information-security-vs-network-security-what-x2019-s-the-difference">Information security vs network security: What’s the difference?</h2><p>Information security protects information from unauthorized users, data modification, and access. Network security, on the other hand, must protect data flowing over a particular network. While network security focuses purely on the network, information security is concerned with information overall, irrespective of where it’s located.</p><p>For example, when it comes to attacks, network security involves protecting your network from specific threats like DDoS attacks, <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus"><u>trojans</u></a>, <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale"><u>zero-day attacks</u></a>, and spyware. Information security, meanwhile, involves protecting the data from leakage or access without permission, no matter the type of threat or the data’s location.</p><h2 id="cyber-security-vs-networking-security-what-x2019-s-the-difference">Cyber security vs networking security: What’s the difference?</h2><p>It isn’t always clear where one begins and ends, but network security is broadly a subset of cyber security which, itself, is a subset of information security. While cyber security centers around how to protect the organization from different types of cyber attack, network security specifically focuses on defending against anything that may compromise the integrity of the corporate network.  </p><p>Network security aims to protect data as it travels through the network between users and endpoints and normally involves protecting against DoS attacks, viruses, or worms, as well as preventing unauthorized access. This may also involve taking measures to prevent, say, social engineering attacks in which hackers aim to seize employees’ credentials – alongside other methods normally deployed to breach the network. Cyber security, meanwhile, protects the data living inside endpoints as well as corporate servers, and protects everything within the digital realm. As such, cyber security covers all the devices that an organization owns, and cyber security practitioners will normally aim to negate the threat from malware, phishing, SQL injection, and zero-day exploits, among other forms of attack.</p><h2 id="why-your-business-needs-all-three-working-in-harmony">Why your business needs all three working in harmony</h2><p><br></p><p>It feels as if the scale of cyber security threats is expanding, but what’s also clear is the variety of attack vectors and opportunities for hackers to strike is increasing. Having effective information security policies in place is crucial to this, with the volume of data expanding. But so too is adopting cyber security principles to stay abreast of the latest threats. Strong network security policies, meanwhile, ensure the organization’s corporate network is airtight, and all data transmitted across it is safe from exploitation. </p><p><em>ITPro created this content as part of a paid partnership with Jamf. The contents of this article are entirely independent and solely reflect the editorial opinion of ITPro. </em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Building a better password strategy for your business ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369393/building-a-better-password-strategy-for-your-business</link>
                                                                            <description>
                            <![CDATA[ Exploring the strategies and exploits that hackers are using to circumvent password security measures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3piE71qspDFm4nqadnEK9R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Oct 2022 08:39:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (ITPro) ]]></author>                    <dc:creator><![CDATA[ ITPro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:description>                                                            <media:text><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:text>
                                <media:title type="plain"><![CDATA[Whitepaper cover with title in block red box and image of keyboard keys, with a padlock and finger print]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sr7PL6RyX4xfWCPshjfCie-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT security leaders and hackers are consistently head-to-head in trying to ensure, and circumvent, password security. Security professionals know that weak credentials are a key aspect of cyber attacks, so it’s vital to have a layered defence strategy to not only protect your business, but also your channel partners.</p><p>This whitepaper discusses the current state of today’s password security, shares things to consider and avoid in developing your organisation’s password strategy, and looks at the latest tools and techniques coming to an ever evolving cyber security landscape.</p><p>Download now to learn:</p><ul><li>The biggest threats affecting password security</li><li>Best practices for ensuring strong credentials</li><li>and How password management tools can support security improvements</li></ul><p><em>Provided by</em></p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4bnNgGoetdNzyX3NB4mHg" name="" alt="Enzoic logo" src="https://cdn.mos.cms.futurecdn.net/4bnNgGoetdNzyX3NB4mHg.jpg" mos="https://cdn.mos.cms.futurecdn.net/4bnNgGoetdNzyX3NB4mHg.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><iframe frameborder="0" height="1000" width="100%" data-lazy-priority="low" data-lazy-src="https://dennis.cvtr.io/forms/49856/enzoic?locale=1&p=false&wp=10450"></iframe>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WatchGuard finds malware volume decreased in Q2, but warns Emotet is resurging ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369191/watchguard-finds-that-malware-volume-decreased-in-q2-but-warns-emotet-is-resurging</link>
                                                                            <description>
                            <![CDATA[ The network security company underlined that Microsoft Office exploits continue to spread more than any other category of malware too ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">e23Grksr2DE1iFbyiSrre6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 28 Sep 2022 10:31:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:description>                                                            <media:text><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:text>
                                <media:title type="plain"><![CDATA[Image of a cyber criminal using several computers in a dark room ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2QVtGsQqwJmbv96BVLpaAJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new report shows there’s been a reduction in overall malware detections from the peaks seen in the first half of 2021, although there’s been an ongoing Emotet botnet resurgence.</p><p>Microsoft Office exploits continue to spread more than any other category of <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, according to WatchGuard Threat Lab’s Q2 Internet Security Report. The quarter’s top incident was the Follina Office exploit, first reported in April but not patched until late May. Delivered via a malicious document, Follina was able to circumvent Windows Protected View and Windows Defender and has been actively exploited by t<a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" target="_blank" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">hreat actors, including nation states</a>, stated the report.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/361340/what-is-emotet" data-original-url="/security/hacking/361340/what-is-emotet">What is Emotet?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/369179/fancy-bear-hackers-exploit-powerpoint-files-to-spread-graphite-malware" data-original-url="/security/hacking/369179/fancy-bear-hackers-exploit-powerpoint-files-to-spread-graphite-malware">Fancy Bear hackers exploit PowerPoint files to spread Graphite malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/369189/lazarus-group-targets-macos-users-with-counterfeit-crypto-job-offers" data-original-url="/security/malware/369189/lazarus-group-targets-macos-users-with-counterfeit-crypto-job-offers">Lazarus group targets macOS users with counterfeit crypto job offers</a></p></div></div><p>Researchers also found that the endpoint <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" target="_blank" data-original-url="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">detections of malware</a> were down overall, but not equally. Despite a 20% decrease in total endpoint malware detections, malware exploiting browsers collectively increased by 23%, with Chrome seeing a 50% surge. WatchGuard found that one potential reason for the increase in Chrome detections is the persistence of various zero-day exploits. Scripts continued to account for the lion’s share of endpoint detections (87%) in Q2. Additionally, network-based malware detections dropped 15.7% quarter over quarter. This includes drops in both basic malware and evasive or zero-day malware.</p><p>The network security company also warned of a resurgent <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet" target="_blank" data-original-url="https://www.itpro.com/security/hacking/361340/what-is-emotet">Emotet</a>. Although the volume has declined since last quarter, Emotet remains one of network security’s biggest threats. One of the quarter’s top 10 overall and top 5 encrypted malware detections, XLM.Trojan.abracadabra – a Win Code injector that spreads the Emotet botnet – was widely seen in Japan.</p><p>“While overall malware attacks in Q2 fell off from the all-time highs seen in previous quarters, over 81% of detections came via TLS encrypted connections, continuing a worrisome upward trend,” said Corey Nachreiner, chief security officer at WatchGuard. “This could reflect threat actors shifting their tactics to rely on more elusive malware.”</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="rNAQoa9nwMcMG72HQokQfh" name="rNAQoa9nwMcMG72HQokQfh.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" mos="https://cdn.mos.cms.futurecdn.net/rNAQoa9nwMcMG72HQokQfh.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Storage's role in addressing the challenges of ensuring cyber resilience</strong></p><p class="fancy-box__body-text">Understanding the role of data storage in cyber resiliency</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber" data-original-url="/security/cyber-attacks/368461/storages-role-in-addressing-the-challenges-of-ensuring-cyber">FREE DOWNLOAD</a></p></div></div><p>The report also found that the top 10 code signatures accounted for over 75% of network attack detections. The quarter saw increased targeting of industrial control systems (ICS) and supervisory control and data acquisition (SCADA) systems that control industrial equipment and processes, as well as new signatures like WEB Directory Traversal -7 and WEB Directory Traversal -8. The two new signatures are similar, the first exploits a vulnerability first uncovered in 2012 in a specific SCADA interface software while the second is most widely detected in Germany.</p><p>WatchGuard also shared that in Q2 it blocked a total of more than 18.1 million malware variants and more than 4.2 million <a href="https://www.itpro.com/infrastructure/network-internet/368366/one-day-it-projects-to-improve-your-business-network" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/368366/one-day-it-projects-to-improve-your-business-network">network</a> threats. Europe, the Middle East, and Africa (MENA) was also the most targeted region, receiving 52% of malware hits. The remainder was split between the Americas and the Asia Pacific, with APAC receiving slightly more.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DrayTek Vigor 2866ax review: Faster than you might expect ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/routers/369016/draytek-vigor-2866ax-review-faster-than-you-might-expect</link>
                                                                            <description>
                            <![CDATA[ A versatile and very affordable SMB security router with Wi-Fi 6 and top-notch WAN redundancy ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sFPRnXb1WDP4cuzZes8bkQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rDbJhLq6vEs7FzNVkV833i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 07 Sep 2022 16:46:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Routers]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rDbJhLq6vEs7FzNVkV833i-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A photograph of the DrayTek Vigor 2866ax]]></media:description>                                                            <media:text><![CDATA[A photograph of the DrayTek Vigor 2866ax]]></media:text>
                                <media:title type="plain"><![CDATA[A photograph of the DrayTek Vigor 2866ax]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rDbJhLq6vEs7FzNVkV833i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>DrayTek’s Vigor 2866ax looks like an ordinary wireless router – and for a small office it can fulfil that role perfectly well. It offers a solid set of Wi-Fi 6 services, with speeds of up to 574Mbits/sec on its 2.4GHz radio and 2.4Gbits/sec on the 5GHz band. It’s also one of the very few SMB routers we’ve seen that supports wide 160MHz channels for maximum bandwidth. Round the back, six Gigabit Ethernet ports allow for the direct connection of wired clients, or the sixth can alternatively be configured as a WAN socket, as we’ll discuss below.</p><p>Installation is a cinch. The router’s web console provides quick-start wizards for configuring internet access, presenting secure wireless services and setting up VPNs. The price includes support for 32 IPsec tunnels plus 16 <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/355071/does-your-business-need-its-own-vpn" data-original-url="https://www.itpro.com/network-internet/virtual-private-network-vpn/355071/does-your-business-need-its-own-vpn">SSL VPNs</a>, with optional hardware acceleration for increased performance. The firewall is also enabled out of the box, and preconfigured with a strict security policy; this can be customised with rules and filters, which are also used to enforce application controls and web content filtering. Cloud management is available via the optional VigorACS 3 web portal.</p><p>DrayTek’s URL keyword filtering service is basic, but you can beef it up with the optional Cyren GlobalView service, which divides the web up into 81 site categories that can be blocked or allowed using up to eight profiles. A free 30-day trial can be activated from your MyVigor account, after which it costs around £35 per year.</p><p>Application controls are also free on registration, and provide a list of 160 apps and protocols that can be controlled. Services including Facebook, WhatsApp and LinkedIn can be instantly blocked using profiles enabled within your firewall rules, although we did notice that Twitter is oddly not covered.</p><p>One area where the Vigor 2866ax really stands out is WAN redundancy. Alongside the built-in G.Fast/VDSL2 modem, <a href="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained" data-original-url="https://www.itpro.com/network-internet/30276/what-is-ethernet-the-standards-explained">one of the Ethernet sockets</a> can be set as an internet connection, and the two front-facing USB 2 ports will each take a 3G or 4G modem. Each WAN connection can be configured as an active or backup link, with the latter automatically brought online when the primary link fails or its traffic exceeds specific thresholds. Alternatively, you can set mutiple links as simultaneously active, and enable the load balancing service to distribute traffic across them all.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LWA9M9wBLdSj82UNLNkrXT" name="" alt="A photograph of the DrayTek Vigor 2866ax" src="https://cdn.mos.cms.futurecdn.net/LWA9M9wBLdSj82UNLNkrXT.jpg" mos="https://cdn.mos.cms.futurecdn.net/LWA9M9wBLdSj82UNLNkrXT.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Wireless services are also good for the price. <a href="https://www.itpro.com/broadband/30390/what-is-ssid" data-original-url="https://www.itpro.com/broadband/30390/what-is-ssid">Up to four SSIDs</a> can be defined on the 2.4GHz and 5GHz bands, each with its own security scheme, and you can present hotspot services for guest users with custom web portals and a range of authentication methods.</p><p>Performance is helped along by a clever hardware acceleration option that allows traffic that’s already been through the firewall and content filters to bypass the CPU. This can yield huge performance benefits: with acceleration disabled, close-range file copies between a server (connected via Ethernet) and <a href="https://www.itpro.com/hardware/laptops/368274/best-windows-laptops" data-original-url="https://www.itpro.com/hardware/laptops/368274/best-windows-laptops">a Windows workstation</a> connected over <a href="https://www.itpro.com/network-internet/wifi-hotspots/367703/what-is-wi-fi-6" data-original-url="https://www.itpro.com/network-internet/wifi-hotspots/367703/what-is-wi-fi-6">Wi-Fi 6</a> averaged 65MB/sec, with router CPU usage peaking at 80%. Enabling acceleration saw speeds leap up to 105MB/sec, while CPU usage dropped to barely 5%. We were also able to gain a small performance increase by enabling the 160MHz channel width, which saw copy speed increase slightly to 107MB/sec.</p><p>The Vigor 2866ax offers a lot for a low price; it’s a great choice for small businesses that want reliable internet and security services in one unit. It lacks some advanced features such as gateway malware protection and anti-spam, but all the essential security measures are present, and thanks to DrayTek’s powerful hardware acceleration it’s faster than you might expect.</p><h2 id="draytek-vigor-2866ax-specifications">DrayTek Vigor 2866ax specifications</h2><div ><table><tbody><tr><td  ><strong>Chassis</strong></td><td  >Fanless desktop unit</td></tr><tr><td  ><strong>Modem</strong></td><td  >G.Fast/VDSL2 RJ-11 modem</td></tr><tr><td  ><strong>Network</strong></td><td  >6 x GbE ports (5 x LAN, LAN/WAN), 2.4/5GHz 802.11ax wireless</td></tr><tr><td  ><strong>Other ports</strong></td><td  >2 x USB 2 </td></tr><tr><td  ><strong>Dimensions (WDH)</strong></td><td  >241 x 165 x 44mm</td></tr><tr><td  ><strong>Weight</strong></td><td  >780g</td></tr><tr><td  ><strong>Warranty</strong></td><td  >2yr RTB warranty</td></tr></tbody></table></div>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gov to force through tough telecoms regulations to boost network security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/368914/gov-to-force-through-tough-telecoms-regulations-to-boost-network</link>
                                                                            <description>
                            <![CDATA[ Regulator Ofcom will have powers to monitor, investigate and fine providers that fail to meet the new requirements ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Qz2DgopD5aMdvMs4g4oN7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Bpf4MWYynHCtAjgSu6p9tj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Aug 2022 15:03:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy and Legislation]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Bpf4MWYynHCtAjgSu6p9tj-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Shutterstock]]></media:description>                                                            <media:text><![CDATA[Photo of London mocked up to show internet traffic flowing in and out of it]]></media:text>
                                <media:title type="plain"><![CDATA[Photo of London mocked up to show internet traffic flowing in and out of it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Bpf4MWYynHCtAjgSu6p9tj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Ofcom will have the power to fine telecom providers £100,000 per day for poor network security under new government regulations. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367253/third-uk-businesses-weekly-cyber-attack" data-original-url="/security/367253/third-uk-businesses-weekly-cyber-attack">DCMS: A third of businesses experience "weekly" cyber attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/360107/dcms-launches-ps30-million-competition-to-diversify-5g-supply-chain" data-original-url="/mobile/5g/360107/dcms-launches-ps30-million-competition-to-diversify-5g-supply-chain">DCMS launches £30 million competition to diversify 5G supply chain</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/367494/cityfibre-raises-alarm-over-uk-telecoms-overbuilding" data-original-url="/infrastructure/network-internet/367494/cityfibre-raises-alarm-over-uk-telecoms-overbuilding">CityFibre raises alarm over UK telecoms overbuilding that could lead to broadband market regression</a></p></div></div><p>New elements of the Telecommunications Security Act, which became law in November 2021, will be laid as secondary legislation in Parliament today, in a bid to force providers to increase the security of the UK's broadband and mobile networks. These will be presented alongside a draft code of practice that will provide a guide for how vendors can comply.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X45j9iJmNPhLBRNurdifFT" name="X45j9iJmNPhLBRNurdifFT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" mos="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cyber resiliency and end-user performance</strong></p><p class="fancy-box__body-text">Reduce risk and deliver greater business success with cyber-resilience capabilities</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368832/cyber-resiliency-and-end-user-performance" data-original-url="/security/368832/cyber-resiliency-and-end-user-performance">FREE DOWNLOAD</a></p></div></div><p>The new regulations and code of practice have been developed jointly by the <a href="https://www.itpro.com/security/national-cyber-security-centre-ncsc/368668/ncsc-launches-startup-incubator-to-protect-against-national-cyber-threats" target="_blank" data-original-url="https://www.itpro.com/security/national-cyber-security-centre-ncsc/368668/ncsc-launches-startup-incubator-to-protect-against-national-cyber-threats">National Cyber Security Centre</a> and Ofcom and they set out the specific actions that public telecom providers must fulfil as legally binding duties. The aim is to improve cyber resilience in the UK by forcing providers to embed strong security practices within all their long-term investment decisions and also their general day-to-day operations.</p><p>As the relevant industry regulator, Ofcom will have powers to enforce new legal duties and carry out inspections of a provider's premises and systems to assess whether it has met the new obligations. The regulator will also be able to issue fines of up to 10% of turnover or £100,000 per day if it is a continuing contravention. </p><p>A final draft of the regulation has been confirmed by the Department of Culture, Media and Sport (DCMS) and follows a public consultation. The regulations will force providers to <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">protect data</a> processed by their networks and services and secure the critical functions which allow them to be operated and managed. It will also require them to protect software and equipment which monitor and analyse their networks and services. Providers will also need to take account of supply chain risks and understand and control who can access and make changes to the operation of their networks and services to enhance security.</p><p>The new rules will come into force in October with providers expected to have achieved all the necessary outcomes by March 2024. The code of practice will set out further time frames for the completion of other measures and will be updated periodically, according to the government, to ensure it keeps pace with any evolving cyber threats.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NEC and Fortinet partner to deliver high-performance security for 5G networks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/5g/368870/nec-and-fortinet-partner-to-deliver-high-performance-security-5g-networks</link>
                                                                            <description>
                            <![CDATA[ The carrier solution will ensure end-to-end security while CSPs contend with increased traffic ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9Hr1UaWvXFV9XRp4rsfDFc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JkCseP5KDC5VwZBtnfqkLS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Aug 2022 14:34:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[5g]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Mobile Networks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JkCseP5KDC5VwZBtnfqkLS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Fortinet sign on a grey building]]></media:description>                                                            <media:text><![CDATA[Fortinet sign on a grey building]]></media:text>
                                <media:title type="plain"><![CDATA[Fortinet sign on a grey building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JkCseP5KDC5VwZBtnfqkLS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NEC Corporation and Fortinet have joined forces to offer secure 5G networks for communication service providers (CSPs).</p><p>Under their global agreement, NEC and Fortinet will set their focus on a series of key network security use cases and services, including radio access network (RAN), mobile roaming, and Gi-LAN/N6, to help service providers gain a comprehensive view into users, applications, and threats.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BbVVrTTnf3oYk7djsMSZAH" name="BbVVrTTnf3oYk7djsMSZAH.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BbVVrTTnf3oYk7djsMSZAH.png" mos="https://cdn.mos.cms.futurecdn.net/BbVVrTTnf3oYk7djsMSZAH.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Connectivity and collaboration</strong></p><p class="fancy-box__body-text">The future of work</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/collaboration/368861/connectivity-and-collaboration" data-original-url="/business-strategy/collaboration/368861/connectivity-and-collaboration">FREE DOWNLOAD</a></p></div></div><p>Fortinet’s high-performance security solutions, featuring automation and AI-driven threat intelligence, will add to NEC’s carrier-grade services spanning over 150 nations, as part of the deal.</p><p>"<a href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="https://www.itpro.com/mobile/28081/what-is-5g">5G</a> success and growth depends on service providers' ability to deliver innovative enterprise-facing use cases while meeting their security requirements," said John Maddison, EVP of products and CMO, Fortinet.</p><p>“We’re pleased to partner with NEC to deliver the required solutions and expertise to facilitate enterprises' 5G adoption and CSPs' success," added Maddison.</p><p>NEC Centers of Excellence (CoEs) and NEC Open Networks will also be leveraged to meet the unique and often dynamic requirements of CSPs.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/366303/agilitas-adds-fortinet-security-solutions-to-channel-offering" data-original-url="/cloud/366303/agilitas-adds-fortinet-security-solutions-to-channel-offering">Agilitas adds Fortinet security solutions to channel offering</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368773/bt-nokia-crack-four-carrier-aggregation-on-a-5g-network-in-europe" data-original-url="/infrastructure/network-internet/368773/bt-nokia-crack-four-carrier-aggregation-on-a-5g-network-in-europe">BT, Nokia crack four carrier aggregation on a 5G network in first for Europe</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/5g/368715/telstra-backs-down-over-spectrum-hoarding-and-impeding-optus-5g-rollout" data-original-url="/mobile/5g/368715/telstra-backs-down-over-spectrum-hoarding-and-impeding-optus-5g-rollout">Telstra backs down over spectrum hoarding and impeding Optus’ 5G rollout</a></p></div></div><p>“The global partnership with Fortinet is a perfect fit for NEC Open Networks’ ecosystem to enable our services to meet the customer’s urgent and diverse needs for network security in the 5G era,” said Hideyuki Ogata, general manager, service provider solutions department, NEC Corporation.</p><p>“NEC CoEs already have rich experience in network security, including the recent success with Fortinet for CETIN and others. This partnership promises to further enrich our service portfolio facing customers as a global network integrator.”</p><p>Earlier this month, <a href="https://www.itpro.com/security/firewalls/368739/fortinet-unveils-fastest-compact-firewall-for-hyperscale-data-centers-and" data-original-url="https://www.itpro.com/security/firewalls/368739/fortinet-unveils-fastest-compact-firewall-for-hyperscale-data-centers-and">Fortinet launched</a> the “fastest” compact firewall for hyperscale data centers and 5G networks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 200,000 DrayTek routers vulnerable to total device takeover ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368725/over-200000-draytek-routers-vulnerable-to-total-device-takeover</link>
                                                                            <description>
                            <![CDATA[ The routers are popular with small and medium businesses, but are easily exploitable by threat actors seeking to steal data or launch ransomware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">v7jZNoubzL3RnR53DCTV6k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oX9XyayN63jXpqGSoj5zdB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 03 Aug 2022 12:24:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oX9XyayN63jXpqGSoj5zdB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital render of a blue padlock fragmenting into a cloud of data]]></media:description>                                                            <media:text><![CDATA[A digital render of a blue padlock fragmenting into a cloud of data]]></media:text>
                                <media:title type="plain"><![CDATA[A digital render of a blue padlock fragmenting into a cloud of data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oX9XyayN63jXpqGSoj5zdB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over 200,000 routers made by DrayTek are subject to a serious vulnerability, which could open companies up to network breaches.</p><p>The DrayTek Vigor 3910 is currently vulnerable to complete compromise by threat actors and is particularly at risk if it has an internet-facing management interface. </p><p>Researchers from cybersecurity firm Trellix identified the vulnerability within the model in a <a href="https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html">blog post</a>, as well as within 28 other devices from DrayTek that share the same code base. They stressed that at present, there are no examples of threat actors in the wild using the vulnerability. </p><p>The researchers have warned companies that once routers are compromised, they leave a network open to malicious action such as <a href="https://www.itpro.com/security/368470/mi5-and-fbi-warn-businesses-over-mass-chinese-ip-theft" data-original-url="https://www.itpro.com/security/368470/mi5-and-fbi-warn-businesses-over-mass-chinese-ip-theft">intellectual property theft</a>, stolen passwords, <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" data-original-url="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">data breaches</a>, or a <a href="https://www.itpro.com/security/28084/what-is-ransomware" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">ransomware attack</a>.</p><p>DrayTek is a Taiwanese manufacturer of <a href="https://www.itpro.com/networking/27835/best-wi-fi-routers" data-original-url="https://www.itpro.com/networking/27835/best-wi-fi-routers">routers</a> that cater to so-called <a href="https://www.itpro.com/business-strategy/startups/359786/bt-to-launch-new-smb-and-startup-focused-business-unit" data-original-url="https://www.itpro.com/business-strategy/startups/359786/bt-to-launch-new-smb-and-startup-focused-business-unit">‘SoHo’</a> small and medium businesses (SMBs), with their products often used to provide remote-working employees with <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">virtual private network (VPN)</a> access.</p><p>Because of a logic bug in its code, threat actors can exploit the management interface of the affected routers by inputting a base64 encoded string as username and password when prompted. This causes a buffer overflow on its login page, allowing a takeover of the router’s ‘DrayOS’.</p><p>The attack can be undertaken over the router’s local area network (LAN). If the management interface of the router is configured to be internet facing, the attack can be carried out remotely over the internet.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368699/european-energy-company-and-gas-pipeline-hacked-by-alphv-ransomware" data-original-url="/security/ransomware/368699/european-energy-company-and-gas-pipeline-hacked-by-alphv-ransomware">European energy company and gas pipeline hacked by AlphV ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368497/return-of-the-intranet-making-a-comeback" data-original-url="/infrastructure/network-internet/368497/return-of-the-intranet-making-a-comeback">Return of the intranet: The age-old platform is making a comeback</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368709/first-choice-community-healthcare-hit-by-data-breach" data-original-url="/security/data-breaches/368709/first-choice-community-healthcare-hit-by-data-breach">First Choice Community Healthcare hit by data breach</a></p></div></div><p>Researchers have issued several recommendations, including keeping firmware up-to-date, preventing the management interface from being exposed to the internet if possible, and changing the password to any affected devices.</p><p>The vulnerability has been filed under CVE-2022-32548 and Trelix was quick to praise DrayTek for releasing a <a href="https://www.draytek.com/support/latest-firmwares">firmware patch</a> within 30 days of being made aware of the issue.</p><p>“A firewall or other piecemeal cybersecurity tool is not a cybersecurity strategy. Small businesses must not underestimate their value to an attacker and adopt a mindset and strategy centred on when they will be targeted versus if," commented Philippe Laulheret, senior security researcher at Trellix. </p><p>"SMBs can't underestimate the value of their data and IP, or the potential for their edge devices to be leveraged in botnet attack, or even the risk of becoming a steppingstone for attackers to compromise SMBs' customer networks.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloudflare unveils new One Partner Program with zero trust at its core ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/channel/368357/cloudflare-unveils-new-one-partner-program-with-zero-trust-at-its-core</link>
                                                                            <description>
                            <![CDATA[ Cloudflare CEO Matthew Prince says the initiative aims to take the complexity out of zero trust architecture ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fWuhosCGAxctrWPP6AU1T7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZBmCFzk8RtkLCDfncgD8xm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jun 2022 10:16:37 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Apr 2025 18:16:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZBmCFzk8RtkLCDfncgD8xm-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Cloudflare CEO and co-founder Matthew Prince]]></media:description>                                                            <media:text><![CDATA[A close up photo of Matthew Prince, CEO and co-founder of Cloudflare, speaking on a stage]]></media:text>
                                <media:title type="plain"><![CDATA[A close up photo of Matthew Prince, CEO and co-founder of Cloudflare, speaking on a stage]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZBmCFzk8RtkLCDfncgD8xm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloudflare has revealed details of its new One Partner Program, which it says presents a new way for the channel to integrate and extend its Cloudflare One platform.</p><p>The initiative builds on the solution’s comprehensive <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust" data-original-url="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">zero trust</a>, network as a service, and cloud <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services" data-original-url="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">email security</a> services, providing architecture designed to help customers to stay secure and efficient.</p><p>Cloudflare said the new programme bundles together the tools and services that partners need to ensure swift deployment, fast performance, as well as robust security across endpoints, networks, and email.</p><p>“In order to keep today’s business environment protected and productive, organisations need a unified solution to secure their distributed workforces and at the same time accelerate employee systems,” explained Matthew Prince, co-founder and CEO of Cloudflare. “But another key piece is broad adoption, and that’s why we’ve been working to seamlessly layer this into organisations without interruptions.</p><p>“Critical architectures like Zero Trust shouldn’t be complex, yet we hear every day from businesses that don’t know where to start. That’s why we have modernised how partners can fully implement and deliver what organisations of all sizes need most today.”</p><p>One of the most interconnected networks on the market, Cloudflare One spans 270 cities in over 100 countries. Over the last twelve months, the number of customers using the platform has grown by 100%, while daily average traffic has increased sixfold.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/368325/cloudflare-fixes-outage-major-web-services-offline" data-original-url="/infrastructure/network-internet/368325/cloudflare-fixes-outage-major-web-services-offline">Cloudflare fixes outage that knocked major web services offline</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/distributed-denial-of-service-ddos/368295/cloudflare-mitigates-biggest-ever-https-ddos-attack" data-original-url="/security/distributed-denial-of-service-ddos/368295/cloudflare-mitigates-biggest-ever-https-ddos-attack">Cloudflare mitigates biggest ever HTTPS DDoS attack</a></p></div></div><p>The platform boasts a number of integrated products such as ZTNA, Secure Web Gateway, CASB, DLP, Browser Isolation, IoT Security, and now Cloud Email Security.</p><p>With its new partner programme, Cloudflare says partners will now be able to better guide customers, deliver comprehensive solutions, protect users from <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a>, as well as secure every connection with zero trust controls.</p><p>“With this new Cloudflare One Partner Program for Zero Trust, Cloudflare has launched a first-of-its-kind set of integrated product suites and partner services packages that will give our Trusted Advisors a compelling set of solutions to take to market,” commented Shane McNamara, EVP of Engineering and Operations at AVANT Communications.</p><p>The news comes just days after a <a href="https://www.itpro.com/infrastructure/network-internet/368325/cloudflare-fixes-outage-major-web-services-offline" data-original-url="https://www.itpro.com/infrastructure/network-internet/368325/cloudflare-fixes-outage-major-web-services-offline">Cloudflare outage</a> resulted in a number of major websites being knocked offline for around two hours, including those operated by Shopify, NordVPN, and gaming platform Steam.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Network detection and response market to hit $5.3bn by 2028 ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/network-security/368169/network-detection-and-response-market-to-hit-53bn-by-2028</link>
                                                                            <description>
                            <![CDATA[ North America is estimated to hold the largest market share over the forecast period ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cq8cfZcbNtvVs9zqM52G27</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MvfBmVw9XrmMsnEbcPt4FE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 08 Jun 2022 12:40:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Praharsha Anand ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/MvfBmVw9XrmMsnEbcPt4FE-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Finger pointing towards malware on a piece of code]]></media:description>                                                            <media:text><![CDATA[Finger pointing towards malware on a piece of code]]></media:text>
                                <media:title type="plain"><![CDATA[Finger pointing towards malware on a piece of code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MvfBmVw9XrmMsnEbcPt4FE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The worldwide network detection and response (NDR) market is slated to reach $5370.4 million by 2028, according to a recently published report by Industry Research.</p><p>The market research firm also estimates a growth worth $2485.7 million in 2022, attributable to the COVID-19 pandemic. Additionally, a compound annual growth rate (CAGR) of 13.7% is anticipated for the NDR market between 2022 and 2028.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="4tEvunnhNH3hyoz8H9hNLe" name="4tEvunnhNH3hyoz8H9hNLe.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/4tEvunnhNH3hyoz8H9hNLe.jpg" mos="https://cdn.mos.cms.futurecdn.net/4tEvunnhNH3hyoz8H9hNLe.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Six myths of SIEM</strong></p><p class="fancy-box__body-text">Things have changed when it comes to SIEM solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/367048/six-myths-of-siem" data-original-url="/security/security-information-and-event-management-siem/367048/six-myths-of-siem">FREE DOWNLOAD</a></p></div></div><p>Commenting on NDR’s significance, Industry Research stated, “NDR solutions primarily use non-signature-based techniques (for example, machine learning or other analytical techniques) to detect suspicious traffic on enterprise networks. </p><p>“NDR tools continuously analyze raw traffic and/or flow records (for example, NetFlow) to build models that reflect normal network behavior.”</p><p>“When the NDR tools detect suspicious traffic patterns, they raise alerts. In addition to monitoring north/south traffic that crosses the enterprise perimeter, NDR solutions can also monitor east/west communications by analyzing traffic from strategically placed network sensors.”</p><p>Gigamon, FireEye, Darktrace, and Cisco are among the major vendors influencing the NDR market.</p><p>By region, North America holds the largest market share (70%), followed by Europe (20%) and Asia-Pacific (20%).</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Five Eyes leaders issue guidance for MSPs to prevent second SolarWinds attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367644/five-eyes-leaders-issue-guidance-for-msps-to-prevent-second-solarwinds-attack</link>
                                                                            <description>
                            <![CDATA[ The joint advisory published today said MSPs and customers need more vigilant in the wake of Russia's invasion of Ukraine ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4yPmZbL8J7fDhbv2ZKodY8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DNvGL2Jd4dGCQ4aarB4ZLW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 May 2022 12:26:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DNvGL2Jd4dGCQ4aarB4ZLW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A group of hackers behind the Russian flag]]></media:description>                                                            <media:text><![CDATA[A group of hackers behind the Russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[A group of hackers behind the Russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DNvGL2Jd4dGCQ4aarB4ZLW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A joint advisory issued by members of the Five Eyes international alliance has set out the latest practical cyber security recommendations for managed service providers (MSPs) to ensure supply chains remain secure.</p><p>Citing the high-profile supply chain attack on SolarWinds in 2020, leaders from the UK’s National Cyber Security Centre (NCSC) and equivalent organisations from the US, Australia, Canada, and New Zealand said the advice applies to MSPs especially now Russia has invaded Ukraine.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack" data-original-url="/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack">Microsoft: ‘More than 1,000 engineers’ executed SolarWinds attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/367633/national-security-leaders-fear-ukraine-conflict-could-inform-a-blueprint-cyber-war" data-original-url="/security/367633/national-security-leaders-fear-ukraine-conflict-could-inform-a-blueprint-cyber-war">National security leaders fear Ukraine conflict could inform a 'blueprint' for cyber war</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks" data-original-url="/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks">Five Eyes and US governments finally confirm Russia was behind Ukrainian government, Viasat cyber attacks</a></p></div></div><p>The <a href="https://www.ncsc.gov.uk/files/AA22-131A_Protecting_Against_Cyber_Threats_to_MSPs_and_their_Customers.pdf">advisory’s release</a> coincides with the second and final day of the NCSC’s annual CYBERUK conference during which on Tuesday, the alliance <a href="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks" data-original-url="https://www.itpro.com/security/cyber-attacks/367634/five-eyes-and-us-governments-confirm-russia-behind-attacks">officially attributed cyber attacks on Ukraine earlier this year to Russia</a>.</p><p>Microsoft previously <a href="https://www.itpro.com/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack" data-original-url="https://www.itpro.com/security/cyber-warfare/358612/more-than-1000-engineers-executed-solarwinds-attack">claimed</a> the Russian-linked attack on SolarWinds was the most sophisticated cyber attack in history, executed by more than 1,000 engineers.</p><p>The message from Five Eyes’ cyber security officials is that the attack complexity shouldn’t be the focal point. Instead, MSPs should consider the overall impact of the attack which targeted up to 18,000 corporate and governmental networks, although SolarWinds said the number of impacted organisations was closer to 100.</p><p>“Our joint advisory with international partners is aimed at raising organisations’ awareness of the growing threat of supply chain attacks and the steps they can take to reduce their risk,” said Lindy Cameron, CEO, NCSC.</p><p>“Supply chain vulnerabilities are amongst the most significant cyber threats facing organisations today,” said Lisa Fong, director at New Zealand’s NCSC.</p><p>“Organisations need to ensure they are implementing effective controls to mitigate the risk of cyber security vulnerabilities being introduced to their systems via technology suppliers such as managed service providers. They also need to be prepared to effectively respond to when issues arise.”</p><h2 id="security-leaders-recommendations">Security leaders’ recommendations</h2><h3 class="article-body__section" id="section-prevent-initial-compromise"><span>Prevent initial compromise</span></h3><p>Securing against common cyber attacks is an important first step in preventing supply chain attacks and the alliance pointed to resources on how to secure against some of the most common and dangerous.</p><ul><li>Improve vulnerable device security</li><li>Secure internet-facing devices</li><li>Defend against brute force attacks and password spraying</li><li>Prevent phishing</li></ul><h3 class="article-body__section" id="section-enable-or-improve-existing-logging-capabilities"><span>Enable or improve existing logging capabilities</span></h3><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ebWTwtZnKEPD3hvMervZkk" name="ebWTwtZnKEPD3hvMervZkk.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" mos="https://cdn.mos.cms.futurecdn.net/ebWTwtZnKEPD3hvMervZkk.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The truth about cyber security training</strong></p><p class="fancy-box__body-text">Stop ticking boxes. Start delivering real change.</p><p class="fancy-box__body-text">FREE DOWNLOAD</p></div></div><p>Cyber security professionals have espoused the benefits of keeping comprehensive logs for years and the same advice applies today. The five security agencies said it can be months before a cyber attack or intrusion is detected so the recommendation is to store their most important logs for at least six months.</p><p>MSPs are advised to log the delivery infrastructure activities used to provide services to their customers and also log both internal and customer network activity, as contractually agreed upon.</p><p>Customers are also encouraged to enable <a href="https://www.itpro.com/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for" data-original-url="https://www.itpro.com/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for">monitoring and logging</a> and should ensure their contract with their MSP mandates it to implement a logging plan and provide visibility into the customer’s network.</p><h3 class="article-body__section" id="section-mandatory-mfa"><span>Mandatory MFA</span></h3><p>Multi-factor authentication (MFA) is considered one of the measures organisations can easily take to drastically improve their cyber security posture and secure remote access to critical systems or infrastructure.</p><p>MSPs are advised to recommend the adoption of <a href="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution" data-original-url="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution">MFA</a> across all customer services and products, while customers should ensure their MSP contracts mandate MFA across all products and services they receive.</p><h3 class="article-body__section" id="section-manage-internal-architecture-risks-and-segregate-internal-networks"><span>Manage internal architecture risks and segregate internal networks</span></h3><p>Where possible, MSPs should ensure they have critical business systems isolated on their networks and verify all connections between internal systems, customer systems, and other networks to limit the impact of a single-vector attack, the advisory said.</p><p>Customers are also advised to review and verify network connections, making sure to use a dedicated <a href="https://www.itpro.com/security/27098/best-vpn-services" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> to connect to MSP’s infrastructure. They should also ensure networks used for trust relationships between them and the MSP are segregated and that the contractual agreement forbids MSPs’ reuse of credentials.</p><h3 class="article-body__section" id="section-assign-the-lowest-level-of-privileges-possible"><span>Assign the lowest level of privileges possible</span></h3><p>Organisations should ensure that internal and external users receive the correct user privileges and not allow undue access to users who do not need it - the alliance calls this applying the principle of least privilege.</p><h3 class="article-body__section" id="section-proactively-manage-obsolete-accounts-and-infrastructure"><span>Proactively manage obsolete accounts and infrastructure</span></h3><p>MSPs and customers should periodically review their registered user accounts and network infrastructure to remove or deprecate any unused user accounts or disable any unused network systems and services.</p><h3 class="article-body__section" id="section-apply-updates"><span>Apply updates</span></h3><p>Another cyber security rule that is repeatedly re-iterated to organisations is to stay on top of their patch and vulnerability management strategies, ensuring all software is secure against the latest attack methods.</p><p>Customers are advised to enquire about their MSP’s patching policies and request updates are applied promptly.</p><h3 class="article-body__section" id="section-effective-backup-strategies"><span>Effective backup strategies</span></h3><p><a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">Ransomware</a> victims are often criticised for not having comprehensive <a href="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy" data-original-url="https://www.itpro.com/back-up/29084/how-to-enhance-your-backup-strategy">backup plans</a> which then lead to the likelihood of paying a ransom, against industry advice.</p><p>These backups should be updated regularly and isolated away from the network connections that could be used to spread ransomware throughout an organisation.</p><h3 class="article-body__section" id="section-develop-incident-response-and-recovery-plans"><span>Develop incident response and recovery plans</span></h3><p>Every individual in an organisation that could feasibly be required to assist in <a href="https://www.itpro.com/disaster-recovery-dr/33803/tips-to-improve-your-disaster-recovery-strategy" data-original-url="https://www.itpro.com/disaster-recovery-dr/33803/tips-to-improve-your-disaster-recovery-strategy">disaster recovery</a> after a cyber attack should be fully aware of their role and responsibilities should an attack strike. </p><p>These plans should have both digital and physical copies should staff lose access to systems, and ideally keep the digital versions isolated so potential attackers can’t study them to inform their attacks.</p><p>These plans should also be exercised regularly, ensuring all the people involved in the recovery strategy are fully trained in how to respond appropriately.</p><h3 class="article-body__section" id="section-understand-and-manage-the-supply-chain-risk"><span>Understand and manage the supply chain risk</span></h3><p>MSPs are advised to be fully aware of their own <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1" data-original-url="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">supply chain</a> risk, and use risk assessments across security, legal, and procurement to prioritise the allocation of resources. Customers should also be aware of their MSP’s risk including with third-party vendors and subcontractors.</p><h3 class="article-body__section" id="section-transparent-contracts"><span>Transparent contracts</span></h3><p>During the contract negotiation phase, MSPs need to be clear about what service they will be providing to the customer. The customer should also be fully aware of the service they are expected to receive and clarify any misunderstandings or queries before signing.</p><h3 class="article-body__section" id="section-account-authentication-and-authorisation"><span>Account authentication and authorisation</span></h3><p>The level of access an MSP is afforded should be clearly defined and restricted where appropriate. Customers should ensure MSP accounts are not added to any company administrator groups and restrict their accounts only to services managed by the MSP. MSPs should ensure that the customer has made these checks.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vector Capital acquires majority ownership of WatchGuard ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/367541/vector-capital-acquires-majority-ownership-of-watchguard</link>
                                                                            <description>
                            <![CDATA[ Global private equity firm gobbles up shares from co-investors as it doubles down on its commitment to the cyber security platform provider ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aK75x329HE4YHtbeo9N1u9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 Apr 2022 09:46:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Acquisition]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                                                                                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A neon blue digital padlock against a black background]]></media:description>                                                            <media:text><![CDATA[A neon blue digital padlock against a black background]]></media:text>
                                <media:title type="plain"><![CDATA[A neon blue digital padlock against a black background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NAEo9aFrDcWStQQY4fKaCC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Vector Capital has made a fresh equity investment in WatchGuard to become the company’s majority shareholder, snapping up shares previously owned by Francisco Partners and other co-investors.</p><p>The private equity firm has held joint ownership of <a href="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy" target="_blank" data-original-url="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy">WatchGuard</a> for more than a decade, overseeing the business transform from a network security vendor to a fully-fledged cyber security platform provider. </p><p>The company’s Unified Security Platform is now, in fact, used by more than 17,000 <a href="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service" data-original-url="https://www.itpro.com/business-operations/31711/what-is-a-managed-it-service">managed service providers (MSPs)</a> to protect the environments, users and networks of more than 250,000 businesses worldwide.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy" data-original-url="/security/unified-threat-management-utm/367258/watchguard-firebox-t40-w-review-powerful-yet-classy">WatchGuard Firebox T40-W review: Powerful yet classy</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a" data-original-url="/security/unified-threat-management-utm/362948/watchguard-firebox-m290-review-stiff-security-at-a">WatchGuard Firebox M290 review: Stiff security at a great price</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/mergers-and-acquisitions/361872/most-significant-tech-industry-moves-2021" data-original-url="/business-strategy/mergers-and-acquisitions/361872/most-significant-tech-industry-moves-2021">The most significant industry moves of 2021</a></p></div></div><p>WatchGuard CEO Prakash Panjwani said the move was a sign of Vector’s belief in the company’s portfolio, partners, employees and vision.</p><p>“This transaction is a testament to WatchGuard’s current success and the opportunity ahead,” he said. “We believe Vector is well-positioned to further accelerate WatchGuard’s growth strategy while preserving our company culture and commitment to security delivery through the MSP community.”</p><p>Looking forward, WatchGuard said it’ll continue to invest in critical areas, including cloud transformation, <a href="https://www.itpro.com/cloud/cloud-computing/360692/ibm-launches-sase-services" target="_blank" data-original-url="https://www.itpro.com/cloud/cloud-computing/360692/ibm-launches-sase-services">secure access service edge (SASE)</a>, extended detection and response (XDR), managed detection and response (MDR), as well as further innovation in security automation and simplification.</p><p>Sandy Gill, managing director of Vector Capital, highlighted the importance of a bespoke platform that’s built to suit MSP needs.</p><p>“MSPs represent the future of security delivery, but to be successful, they need a bespoke platform built for their needs,” he said. “WatchGuard is uniquely positioned to lead the market in enabling those MSPs with its Unified Security Platform.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="UHpmfdoQgu8aNQQmYiLXBa" name="UHpmfdoQgu8aNQQmYiLXBa.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UHpmfdoQgu8aNQQmYiLXBa.png" mos="https://cdn.mos.cms.futurecdn.net/UHpmfdoQgu8aNQQmYiLXBa.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Ransomware and Microsoft 365 for business</strong></p><p class="fancy-box__body-text">What you need to know about reducing ransomware risk</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/367294/ransomware-and-microsoft-365-for-business" data-original-url="/security/367294/ransomware-and-microsoft-365-for-business">FREE DOWNLOAD</a></p></div></div><p>“We are excited to further invest both organically and via acquisitions in the company’s mission to deliver security-focused MSPs one vendor, one platform and one vision to build their business upon.”</p><p>Alex Slusky, founder, managing director and chief investment officer of Vector Capital, added: “We are proud of the foundation of success we’ve built with WatchGuard’s management team and look forward to fuelling the next phase of growth and transformation for the company.”</p><p>The transaction is expected to close by the end of the third quarter of 2022, subject to customary closing conditions. Financial terms were not disclosed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Auvik Network Management review: A breeze to deploy ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/infrastructure/network-internet/367287/auvik-network-management-review-a-breeze-to-deploy</link>
                                                                            <description>
                            <![CDATA[ Auvik’s cloud-hosted monitoring is quick to provide a complete picture of your network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eUgpDpuUzU4f64iQuN8x9b</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hp5Kggeo6wkJqHwD85gJGX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Apr 2022 12:27:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dave Mitchell ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hp5Kggeo6wkJqHwD85gJGX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Auvik Network Management screenshot]]></media:description>                                                            <media:text><![CDATA[Auvik Network Management screenshot]]></media:text>
                                <media:title type="plain"><![CDATA[Auvik Network Management screenshot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hp5Kggeo6wkJqHwD85gJGX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are plenty of cloud-hosted network-monitoring options to choose from, but Auvik can claim to be one of the fastest to deploy. Two versions are available: the Essentials edition provides network mapping, monitoring, alerting and device configuration management, while the Performance edition adds features such as Syslog collection and flow data analysis for detailed application visibility.</p><p>To use it you simply need to install a collector agent in each site – and this is painless as it’s a lightweight service that will run on any version of Windows. The back-end, meanwhile, is hosted in AWS data centres, and protected by both single sign-on and 2FA procedures. All collector data is encrypted, and outbound communications are only permitted with its cloud servers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/362823/brocade-and-emc-form-cloud-based-network-management-partnership" data-original-url="/business/business-strategy/362823/brocade-and-emc-form-cloud-based-network-management-partnership">Brocade and EMC form cloud-based network management partnership</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/362750/how-to-choose-the-right-network-monitoring-solution" data-original-url="/infrastructure/network-internet/362750/how-to-choose-the-right-network-monitoring-solution">How to choose the right network monitoring solution</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for" data-original-url="/network-internet/34780/network-monitoring-what-every-admin-should-be-looking-out-for">Network Monitoring: What every admin should be looking out for</a></p></div></div><p>Onboarding is a piece of cake. After creating our <a href="https://www.itpro.com/cloud" data-original-url="https://www.itpro.com/cloud">cloud</a> account we used Microsoft’s Authenticator app to confirm secure administrative access, created our first site and downloaded the agent installer. After running this on a Windows Server 2019 host, we were prompted to provide a unique API key, and then a secure connection to our cloud account was created.</p><p>Auvik kicks off its discovery process immediately, and while it’s scanning you can enter credentials for SNMP, WMI, SSH, telnet, and VMware. We were impressed to see that it took only around 16 minutes to build a fully populated network map for a complete subnet.</p><p>From now on the network is continuously scanned – you can set an interval in seconds – while the map shows your network layout. Coloured link lines between devices distinguish between Layer 1, Layer 3, and <a href="https://www.itpro.com/networking/27210/do-i-need-a-vpn" data-original-url="https://www.itpro.com/networking/27210/do-i-need-a-vpn">VPN</a> connections, while dotted lines denote wireless links. We found the map quickly updated itself to reflect network or device state changes, and each device icon is active, so you can hover over a node to see a pop-up status window, or click to load its details in the panel below. </p><p>The home dashboard panel provides a handy activity overview with tables of the busiest devices, open alerts, SSL VPN status and the condition of <a href="https://www.itpro.com/virtualisation/34516/vmware-vsphere-vs-proxmox-which-is-best-for-your-business" data-original-url="https://www.itpro.com/virtualisation/34516/vmware-vsphere-vs-proxmox-which-is-best-for-your-business">VMware</a> host hardware components. The software offered full visibility into our Hyper-V host, showing details such as CPU, memory, storage and virtual switch utilisation, traffic throughput, and individual VM status. </p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="93a62Jo6EFkrbMS8oEwD5B" name="" alt="Auvik Network Managemen dashboard" src="https://cdn.mos.cms.futurecdn.net/93a62Jo6EFkrbMS8oEwD5B.jpg" mos="https://cdn.mos.cms.futurecdn.net/93a62Jo6EFkrbMS8oEwD5B.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>To help you keep on top of any emergent issues, Auvik provides 58 preconfigured alerts, ranging from a down device or service to high storage usage, as well as the option to set your own. Notifications can be sent by email or via various messaging platforms, including Teams, <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" data-original-url="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a>, and FreshDesk.</p><p>While Auvik’s main focus is clearly on network, service, and device availability, it can also keep <a href="https://www.itpro.com/security/cyber-attacks/367220/uk-us-uncover-russia-role-cyber-attacks-on-critical-infrastructure" data-original-url="https://www.itpro.com/security/cyber-attacks/367220/uk-us-uncover-russia-role-cyber-attacks-on-critical-infrastructure">critical infrastructure</a> devices safe with automated configuration backups, restores and comparisons. The Performance edition adds a TrafficInsights dashboard where NetFlow, sFlow, and J-Flow data is ingested, analysed, and presented as informative graphs.</p><p>Auvik’s per-device licensing initially looks expensive, but it’s not hard to customise the configuration so that only your important devices are monitored, and you save by not having to provide a dedicated on-premises host. Since it’s so versatile, so easy to deploy, and so simple to manage, it’s a good choice for SMBs that want a clear picture of their network.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New MFA security standards for online payments come into force ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/two-factor-authentication-2fa/367276/mfa-security-standards-updated-for-online-payments</link>
                                                                            <description>
                            <![CDATA[ Version 4.0 of PCI DSS also reforms password requirements and broadens its terminology to address other network access controls ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sXSf1xGxn4dA13ejE1qAo9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/coGqn2jbqaBrZw8kc6U5Mo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 31 Mar 2022 17:08:52 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Networking]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danny Bradbury ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/coGqn2jbqaBrZw8kc6U5Mo-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man holding credit card making online payment on a tablet]]></media:description>                                                            <media:text><![CDATA[Man holding credit card making online payment on a tablet]]></media:text>
                                <media:title type="plain"><![CDATA[Man holding credit card making online payment on a tablet]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/coGqn2jbqaBrZw8kc6U5Mo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Companies accepting credit card payments online have a new set of standards to abide by as of today.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/mobile-phones/362080/iphones-to-accept-direct-contactless-payments" data-original-url="/mobile/mobile-phones/362080/iphones-to-accept-direct-contactless-payments">Apple will let businesses accept payments on iPhones without the need for extra hardware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/two-factor-authentication-2fa/33812/what-is-strong-customer-authentication-sca-under-psd2" data-original-url="/two-factor-authentication-2fa/33812/what-is-strong-customer-authentication-sca-under-psd2">What is Strong Customer Authentication (SCA) under PSD2?</a></p></div></div><p>The Payment Card Industry Security Standards Council has issued version 4.0 of its PCI Data Security Standard (PCI DSS), a standard <a href="https://www.itpro.com/two-factor-authentication-2fa/33812/what-is-strong-customer-authentication-sca-under-psd2" data-original-url="https://www.itpro.com/two-factor-authentication-2fa/33812/what-is-strong-customer-authentication-sca-under-psd2">defining security measures</a> to protect payment card information.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="BvaxdVesrBPpDZeCYx49S" name="BvaxdVesrBPpDZeCYx49S.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" mos="https://cdn.mos.cms.futurecdn.net/BvaxdVesrBPpDZeCYx49S.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Multi-factor authentication deployment guide</strong></p><p class="fancy-box__body-text">A complete guide to selecting and deploying your MFA authentication guide</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide" data-original-url="/security/two-factor-authentication-2fa/361517/multi-factor-authentication-deployment-guide">FREE DOWNLOAD</a></p></div></div><p>Anyone holding this data, such as online retailers or service providers, must comply with the standard.</p><p>The new version of PCI DSS features several changes. It expands its access control requirements to make <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a> mandatory for all access into the cardholder data environment, and also updates <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">password requirements</a>.</p><p>Companies following the standard will also have to implement new protections against <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a>.</p><p>The latest document also introduces more flexibility for organizations to demonstrate their compliance. Whereas the previous version focused on firewall protection, version 4.0 has broadened its terminology to address other network security controls.</p><p>The Council has also added support for targeted risk analyses. These let companies define how frequently they perform some security-related activities, it said.</p><p>The PCI will translate the new version of PCI DSS into different languages over the next few months. Assessors - the companies that verify compliance with the standard - also have to train in the new version.</p><p>The current version, 3.2.1, will remain active until 31 March 2024, the Council said. After that, version 4.0 will be the only active version of the standard. Some requirements in the new version are defined as best practices, but will become mandatory. Organizations will have an extra year - until March 31 2025 - to phase those in.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Vodafone and Ericsson complete UK's first 5G network slicing trial ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/mobile/5g/366979/vodafone-ericsson-complete-first-5g-network-slicing-trial</link>
                                                                            <description>
                            <![CDATA[ Network slicing allows businesses and app developers to carve out a ‘slice’ of the network suited to specific use cases ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">atMri9dP2CRxc7rQTsU73</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CgjR23HvspGZRnoTfGBnsG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Mar 2022 10:52:23 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[5g]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Mobile Networks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CgjR23HvspGZRnoTfGBnsG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of people walking in different directions of pattern, painted on asphalt as visual representation of network slicing]]></media:description>                                                            <media:text><![CDATA[Top view of people walking in different directions of pattern, painted on asphalt as visual representation of network slicing]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of people walking in different directions of pattern, painted on asphalt as visual representation of network slicing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CgjR23HvspGZRnoTfGBnsG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Vodafone and <a href="https://www.itpro.com/business-strategy/acquisition/361620/ericsson-to-acquire-vonage-for-62-billion" data-original-url="https://www.itpro.com/business-strategy/acquisition/361620/ericsson-to-acquire-vonage-for-62-billion">Ericsson</a> have completed a successful lab trial of 5G network slicing – a first for the UK telecoms and technology industry.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/network-internet/364549/uk-and-japan-cooperate-on-diversifying-telecoms-networks" data-original-url="/infrastructure/network-internet/364549/uk-and-japan-cooperate-on-diversifying-telecoms-networks">UK and Japan cooperate to reduce reliance on Nokia, Ericsson for 5G infrastructure</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/mobile/28081/what-is-5g" data-original-url="/mobile/28081/what-is-5g">What is 5G and how far are we from rollout?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/31750/what-is-latency" data-original-url="/network-internet/31750/what-is-latency">What is latency?</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gSCksczWaVZioTtDeALM4D" name="gSCksczWaVZioTtDeALM4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" mos="https://cdn.mos.cms.futurecdn.net/gSCksczWaVZioTtDeALM4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Introducing the zero trust edge model for security and network services</strong></p><p class="fancy-box__body-text">Get a better understanding of emerging zero trust solutions</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/365567/introducing-the-zero-trust-edge-model-for-security-and-network-services" data-original-url="/security/365567/introducing-the-zero-trust-edge-model-for-security-and-network-services">FREE DOWNLOAD</a></p></div></div><p>Enabled by Standalone 5G, network slicing is a new service aimed at businesses and app developers that involves carving out a ‘slice’ of the network to in order to cater it to specific use cases. This can be based on geographical location, download and upload speeds, latency, capacity, and even specific <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">cyber security</a> needs.</p><p>For instance, the trial successfully conducted by Vodafone and Ericsson involved creating and configuring an on-demand 5G network slice for a retail store that would have the enough <a href="https://www.itpro.com/broadband/30274/what-is-bandwidth" data-original-url="https://www.itpro.com/broadband/30274/what-is-bandwidth">bandwidth</a> to support <a href="https://www.itpro.com/technology/354456/virtual-reality-is-dead-long-live-vr" data-original-url="https://www.itpro.com/technology/354456/virtual-reality-is-dead-long-live-vr">virtual reality (VR)</a>.</p><p>The slice, which took 30 minutes to complete, was able to deliver a guaranteed download speed of 260Mbps and latency of 12.4 milliseconds.</p><p>5G network slicing has the potential to enable a number of different 5G use case scenarios, ranging from <a href="https://www.itpro.com/business-strategy/automation/360546/have-driverless-cars-stalled" data-original-url="https://www.itpro.com/business-strategy/automation/360546/have-driverless-cars-stalled">automotive</a> and healthcare to mobile gaming and smart cities.</p><p>In the case of the latter, 5G network slicing could be combined with <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot" data-original-url="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT</a> technology to deploy smart electricity sensors that can be adjusted by demand, or in order to track and manage emergency services in real-time. Due to the sensitive nature of the data, network slicing would enable a separate, more secure ‘slice’ of the network separate from the public internet.</p><p>Businesses could benefit from 5G network slicing by creating slices that would be tailored to individual teams based on their specific network demands, without sacrificing the quality of connectivity of one team in favour of another.</p><p>According to Ericsson UK & Ireland VP of digital services, Andrea Spaccapietra, the technology will play a crucial role in enabling new and innovative 5G services for consumers and enterprises alike. </p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/aKNmvtPZJbQ" allowfullscreen></iframe></div></div><p>“With the tools to efficiently manage network resources and provide differentiated services with dedicated performance, leading network operators like Vodafone can enable new business model innovation and use cases across different sectors and unlock new revenue opportunities to realise the full potential of 5G,” he said.</p><p>According to tech, media & telco analyst Paolo Pescatore, network slicing is "best-suited for enterprises and specific verticals" and "provides telcos with a significant means to help recoup the investment in 5G".</p><p>"For now, it seems unlikely that consumers will pay a premium for a superior experience," he told <em>IT Pro</em>.</p><p>The news comes less than two years after Vodafone delivered the UK’s <a href="https://www.itpro.com/mobile/5g/356342/vodafone-to-deliver-the-uks-first-standalone-5g-network" data-original-url="https://www.itpro.com/mobile/5g/356342/vodafone-to-deliver-the-uks-first-standalone-5g-network">first Standalone 5G network</a>, with Coventry University becoming the first to use the new network as part of a new VR learning option for student nurses and allied health professionals.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>