Affected Product
Cisco UCS Central Software versions 1.2 and earlier
If you are currently running Cisco UCS Central Software you should update the software immediately.
If you are currently running Cisco UCS Central Software you should update the software immediately.
Topics: Device Management, Information Security, Threat Advisory
In March 2015, the PCI Council released their Information Supplement for Penetration Testing Guidance. This is a fantastic move as previous guidelines were centered on the completion of penetration tests and left the methodology for completing those up to the auditor. With this guidance in place, we now have a clear definition to what qualifies as a penetration test in the eyes of the Council. There isn’t a need to rehash the document for you here, and I encourage everyone to read it. I would like to focus on a few key highlights that I’m happy to see added.
Topics: Ethical Hacking, Compliance, Penetration Testing
In light of new PCI-DSS requirements stating that SSLv3 no longer meets the specification for “strong cryptography” prescribed by PCI standards, we wanted to give you a brief history of how the industry got here and why SSLv3 is no longer considered secure.
Topics: Ethical Hacking, Information Security, Security Architecture Review, Penetration Testing
In this post, I'd like to talk about how to actually apply the concept of “red teams” in your enterprise. First, and foremost, red teaming for cyber security refers to the concept of a small team of hackers reviewing an organization to determine if they can gain access to critical assets. This may not sound much different than a penetration test, but one crucial piece is almost non-existent in a red team exercise: scope. A red team will utilize a web application, mobile platform, physical, social engineer, and network tester as part of a team whose goal is to profile the organization and gain access.
Topics: Security Monitoring, Managed Detection & Response, Ethical Hacking, Penetration Testing
I had a completely different article typed up, however after catching up on my morning news and seeing a huge amount of controversy regarding Coordinated Vulnerability Disclosure (CVD) from Microsoft, I decided to reach out to the NetWorks Group Community and help our customers (past, current, and prospective) understand what that means to them.
Topics: Managed Detection & Response, Ethical Hacking, Vulnerability Management, Threat Management
Whether you are a veteran security executive who has received hundreds of penetration testing reports, or a part-time security manager whose primary roles lay in traditional business management, it can be difficult to decipher the encrypted text held within some penetration testing reports. The problem exists because there is not a standard for penetration testing reporting inside of the industry. I’ve seen literary works that range anywhere from Dr. Seuss to William Shakespeare. I have peer reviewed reports for associates whose bad grammar could make a first grader wince. The goal here is to identify what makes a penetration test report good, how to interpret the results, and finally how to put them to use in your strategic planning to improve organizational security.
Topics: Ethical Hacking, Penetration Testing
IT Security is thriving in the Detroit Metro area and we're proud to be sponsoring BSides Detroit 2013 this year! Security BSides is an innovative new un-conference style meetup that brings local security professionals together to share experiences, knowledge, and network.
Topics: Information Security, Events
After a string of high-profile account compromises that included the Associated Press and Burger King, Twitter has added an additional (but optional) layer of authentication to help protect users from being the next big-name account that's compromised.
When it comes to the Internet, keeping your organization's presence online is crucial to the accessibility of resources for customers, potential and existing. At NetWorks Group, we understand that despite the best of intentions and planning, downtime will likely still occur, at least a few minutes per year. Many teams put forth a goal of 100% uptime for their web site, but often get a dose of reality when a large storm hits their data center or other issues pop-up that may be out of their direct control. To this end, we wanted a way to minimize full-downtime so that our presence on the Internet would only be down as minimally as possible, without going over-the-top on infrastructure to do so.
Topics: Information Security
If you're a fan of delicious restaurants, awesome concert venues, Big 10 sports, or just a bike-friendly city, then you should probably be working with us in beautiful downtown Ann Arbor, Michigan. The team at NetWorks Group works at the corner of Main and Huron, a central-point to blocks of great places to shop, eat, and relax at. Located a short distance from the University of Michigan, NetWorks Group benefits from the feeling of both a college-town and an active business hub for southeastern Michigan. For a vibrant mixture of cultures, architecture, and activities, Ann Arbor is hard to beat!
Topics: Security Monitoring, Managed Detection & Response, Ethical Hacking, Device Management, Information Security, Threat Hunting, Vulnerability Management, Security Architecture Review, Compliance, Penetration Testing, Incident Response, Threat Management
NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.
(888) 798-1012
info@networksgroup.com
www.networksgroup.com
© 2017 - NetWorks Group