BMT Announcement

Hacked WordPress Sites Abusing Visitors’ Browsers for Distributed Brute-Force Attacks

Threat actors are conducting brute-force attacks against WordPress sites by leveraging malicious JavaScript injections, new findings from Sucuri reveal. The attacks, which take the form of distributed brute-force attacks, "target WordPress websites from the browsers of completely innocent and unsuspecting site visitors," security researcher Denis Sinegubko said. The activity [...]

By |2024-03-08T10:27:42-05:00March 7th, 2024|Categories: BMT Announcement|

Hackers Exploit Misconfigured YARN, Docker, Confluence, Redis Servers for Crypto Mining

Threat actors are targeting misconfigured and vulnerable servers running Apache Hadoop YARN, Docker, Atlassian Confluence, and Redis services as part of an emerging malware campaign designed to deliver a cryptocurrency miner and spawn a reverse shell for persistent remote access. "The attackers leverage these tools to issue exploit code, [...]

By |2024-03-07T09:54:16-05:00March 6th, 2024|Categories: BMT Announcement|

Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware

North Korean threat actors have exploited the recently disclosed security flaws in ConnectWise ScreenConnect to deploy a new malware called TODDLERSHARK. According to a report shared by Kroll with The Hacker News, TODDLERSHARK overlaps with known Kimsuky malware such as BabyShark and ReconShark. "The threat actor gained access to [...]

By |2024-03-05T12:44:58-05:00March 5th, 2024|Categories: BMT Announcement|

What is Exposure Management and How Does it Differ from ASM?

Startups and scales-ups are often cloud-first organizations and rarely have sprawling legacy on-prem environments. Likewise, knowing the agility and flexibility that cloud environments provide, the mid-market is predominantly running in a hybrid state, partly in the cloud but with some on-prem assets. While there has been a bit of [...]

By |2024-03-05T12:26:52-05:00March 5th, 2024|Categories: BMT Announcement|

4 Instructive Postmortems on Data Downtime and Loss

More than a decade ago, the concept of the 'blameless' postmortem changed how tech companies recognize failures at scale. John Allspaw, who coined the term during his tenure at Etsy, argued postmortems were all about controlling our natural reaction to an incident, which is to point fingers: "One option [...]

By |2024-03-01T14:38:18-05:00March 1st, 2024|Categories: BMT Announcement|

Jump Into the World of AI! Get Started with Microsoft Copilot

For those not aware, Microsoft Copilot is a browser-based generative AI tool, similar to ChatGPT.  Whether you believe AI will be the salvation of humankind or the demise of it, you’re going to use it someday.  Currently, the full version of Copilot is only available for business customers willing [...]

By |2024-03-05T11:35:36-05:00February 29th, 2024|Categories: BMT Announcement, News, Partner|Tags: , , , , , |

New Silver SAML Attack Evades Golden SAML Defenses in Identity Systems

Cybersecurity researchers have disclosed a new attack technique called Silver SAML that can be successful even in cases where mitigations have been applied against Golden SAML attacks. Silver SAML "enables the exploitation of SAML to launch attacks from an identity provider like Entra ID against applications configured to use [...]

By |2024-02-29T12:23:45-05:00February 29th, 2024|Categories: BMT Announcement|
Go to Top