LATEST CYBER SECURITY NEWS AND VIEWS

Home > News

Was the NSA’s Cyber Security director right to say attackers know networks best?

Posted on

By Phil Robinson There was an interesting spat on Twitter during September when Rob Joyce, Cyber Security Director of the National Security Agency, disputed the notion put forward by security researcher @RayRedacted that “Defenders think in lists, attackers think in graphs”. (Presumably suggesting that defenders are preoccupied with tick lists and compliance while attackers are looking at the data […]

Read full post

No Shell? No Problem!

Posted on

Enumerating internal networks via ssh-tunnels, Alexis V, November 2021 On a recent engagement, we were tasked to assess the security of an Secure File Transfer Protocol (SFTP) server. We were provided with a regular account to facilitate the file uploads, and so proceeded to work our way through the common checks. We tried to: Log […]

Read full post

Apache Webserver Directory Traversal Vulnerability (CVE-2021-41773)

Posted on

CVE-2021-41773 Apache Web 0day  A new apache 0day vulnerability has just been announced that affects Apache version 2.4.49. “A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root.” Further information can […]

Read full post

Prism Infosec Statement on NPCC Police CyberAlarm

Posted on

Operated by the National Police Chief’s Council (NPCC) and Pervade Software, the Police CyberAlarm service is a free tool to assist organisations with monitoring malicious cyber activity.  The service helps to detect and provide regular reports of suspected malicious activity, enabling organisations to respond to potential cyber attacks.  The NPCC and Pervade Software engaged Prism […]

Read full post

Prism Infosec Information & Cyber Security Forum

Posted on

From May 2020, Prism Infosec has been running quarterly cyber security forums for security leaders across our client base.   We created this forum to allow our clients the opportunity to connect, discuss and exchange experiences on common cyber security challenges, and that this shared experience would help our clients as they navigate the security […]

Read full post

Prism Infosec gains NCSC CHECK Green Light Status

Posted on

CHECK Logo

Prism Infosec is delighted to announce that following a rigourous review by the UK National Cyber Security Centre (NCSC) of our people, delivery / reporting standards and methodologies we have become an NCSC CHECK Green Light organisation.  This enables Prism Infosec to deliver our high quality penetration testing services and IT Health Checks to UK […]

Read full post

Microsoft Windows Active Directory Critical Vulnerability (CVE-2020-1472)

Posted on

Exploit Code

Given the nature of the vulnerability and that it is likely that exploits will be released in the coming days, Prism Infosec are making its clients aware of a critical vulnerability affecting Microsoft Windows Active Directory (AD) servers. The vulnerability takes advantage of a weak cryptographic algorithm used in the Netlogon authentication process and is described in CVE-2020-1472.

Read full post

Prism Infosec achieves CREST STAR Certification

Posted on

CREST awards Prism Infosec CREST STAR status

Read full post

Prism Infosec joins the Civil Aviation Authority ASSURE Framework

Posted on

Prism Infosec CAA ASSURE approved

Read full post

Blog Post: Top 3 Common Networking Attacks

Posted on

Prism Infosec’s Senior Security Consultant, Aaron, reviews the “Top 3 Common Networking Attacks”​

Read full post

FILTER RESULTS

Latest tweets

What a Day 1 at #CyberUK, from Networking Events to Technical Masterclasses!
We're excited for Day 2, our CEO and sales team are currently exhibiting our Customer Platform LuxisAI. Drop by our stand (M2 on Floor 5 in Hall 4) for a demo, chat and a Prism Infosec Notebook!

Why is the #insiderthreat rising and how can standards such as #ISO27001 and #ISO42001 help to mitigate it? Alun Cadogan shared his insights  with @isms_online. #CyberSecurity

Sign up to our newsletter

  • Fields marked with an * are mandatory

  • This field is for validation purposes and should be left unchanged.