Security VPN Vulnerability
vulnerability in FortiOS SSL VPN

Paolo Alto VPN vulnerable to OpenSSL Bug

Palo Alto Networks warned customers yesterday that some of its firewall, VPN, and XDR products are vulnerable to a high severity OpenSSL infinite loop bug disclosed three weeks ago.Threat actors can exploit this security vulnerability (tracked as CVE-2022-0778) to trigger a denial of service state and remotely crash devices running unpatched software.Even though the OpenSSL […]

Hack Multifactor Authentication Password Management Security

Authentication provider Okta or customer(s) hacked?

A group of attackers calling themselves Lapsus$, and previously responsible for attacks on chip giant NVIDIA, Portuguese media giant Impresa and the Brazilian Ministry of Health, posted screenshots on their Telegram channel showing that they have access to Okta systems. Okta offers solutions for identity and access management. “More than 15,000 global brands entrust Okta […]

Infrastructure Security Network Security Security
OpenSSL

NSA: network infrastructure security guidance

Cybersecurity responsibilities to identify and disseminate threats in the network infrastructure:– Network architecture and design– Security maintenance– Authentication, authorization, and accounting (AAA)– Local administrator accounts and passwords– Remote logging and monitoring– Remote administration and network services– Routing– Interface ports– Notification and consent banners