TechTalk

After a two-year implementation period, EU financial institutions are obliged to implement the DORA (Digital Operational and Resilience Act) by the deadline of January 17, 2025. Chapter II of DORA focuses on the risk management framework, which consists of several elements.
After a two-year implementation period, EU financial companies are obliged to implement the DORA (Digital Operational and Resilience Act) by the deadline of January 17, 2025.
The SECUINFRA Falcon team has investigated the “Nitrogen” ransomware variant. We discovered that significant parts of the implementation originate from the leaked source code of CONTI Ransomware.
After a two-year implementation period, EU financial companies are obliged to implement the DORA (Digital Operational and Resilience Act) by the deadline of 17.01.2025. DORA focuses on the identification and risk management of information assets that support critical or important business functions.
The threat situation for companies is also becoming more complex this year. In addition to state-sponsored attacks - primarily from Russia, China and increasingly also North Korea - we are seeing more and more commercially motivated attacks that are carried out highly professionally using the CaaS model (Cybercrime as a Service). It is noticeable that the speed with which stolen data is offered for sale or exploited is constantly increasing. It is not uncommon for compromised accounts to be taken over after just a few minutes. Phishing campaigns, which are becoming increasingly reliable thanks to the use of AI, pose a further potential threat. Last but not least, criminals are increasingly using cross-platform malware that targets Linux and Mac OS in addition to Windows. How can companies meet these new challenges?
Ever faster and more sophisticated cyber attacks make a Security Operations Center (SOC) mandatory for every company. However, this is too much for most companies and they therefore start looking for an external partner. We explain what is important when choosing a provider and which criteria are important for small, medium-sized and large companies.
A free survival game called "PirateFi" on the Steam online game store has been distributing the information-stealing malware Vidar to unsuspecting players. Last week, Valve removed a game from its online store because users raised concerns about malware warnings from anti-virus software after launching the game. After removing the game, the SECUINFRA Falcon team analyzed the malware and determined that the game was an attempt to trick players into installing an infodump called "Vidar". As the game advertisement contained references to cryptocurrencies and blockchain technology, we believe this was a lure specifically targeting players interested in these topics.
Phishing continues to be a major issue in IT security. Cyber criminals are increasingly using new, dynamic methods to sneak their fraudulent emails past the installed security filters unnoticed in order to deceive their victims and use them as door openers for malicious activities. In this article, you will find out more about the latest tricks and how you can protect your company even better against serious deceptive maneuvers.
Sometimes you read about cyber attacks and think that something like this couldn't happen to you - until it does. Just such a case occurred recently. The attack vividly demonstrates how social engineering works and how even a rather inexperienced attacker could cause considerable damage.
In a recent case, we tried to reconstruct the attacker's activities on an ESXi hypervisor. The logs available on the system were very limited, which made it difficult to analyze the attacker's activities. The ESXi hypervisor in particular offers detailed logs that can be used for forensic analysis if configured accordingly. The topic of forensic readiness in general was covered in a previous article, which is highly recommended reading. This article focuses on hypervisors, the risks they are exposed to and how to protect them.
Cookie Consent with Real Cookie Banner