LATEST CYBER SECURITY NEWS AND VIEWS

Home > News

CVE-2022-34001 – XML External Entity (XXE) in Unit 4 ERP 7.9 (Also Known As “Agresso”)

Posted on

Prism Infosec Identified an XXE vulnerability within Unit4’s Enterprise Resource Planning (ERP) software. This has been assigned CVE-2022-34001. Unit4’s ERP software is a well-known enterprise management suite, which includes financial and project management tools. Prism Infosec discovered a blind XXE within a specific function of the ERP software. This would allow an authenticated attacker to […]

Read full post

What is the PSTI and will it improve IoT security?

Posted on

By Phil Robinson The new Product Security and Telecommunications Infrastructure (PSTI) Bill currently going through parliament comprises two parts. The first aims to put in place safeguards to regulate the secure design of the Internet of Things (IoT) while the second will ensure broadband and 5G networks are gigabit-grade. It’s the first part that has caused a […]

Read full post

Prism Infosec Exhibiting at the NCSC’s Flagship Event CYBERUK22

Posted on

Prism Infosec is delighted to announce that it will be exhibiting at the NCSC’s CYBERUK 2022 conference, in Newport on the 11th and 12th of May 2022 on stand A29. For more information on the conference see the NCSC website and agenda. Do come and visit our stand for a chat and to learn more […]

Read full post

Let’s Go Phishing

Posted on

Phishing

Prism Infosec’s security consultant Kian J, provides a detailed account of a successful simulated phishing attack

Read full post

ICO data reveals sharp rise in attacks

Posted on

Cyber Trends

Recent data from the Information Commissioner’s Office (ICO) Data Security Trends Analysis Q1 2021-22 (capturing incidents for the period 1 April – 30 June 2021) reveal there’s been a sharp rise in specific cyber attacks as attackers seek to capitalise on the disruption caused by the pandemic and working from home (WFH). The biggest leap […]

Read full post

Threats and priorities for 2022

Posted on

Phil Robinson, December 23rd 2021 Many businesses will still be grappling with the seismic shifts of the pandemic as they eye 2022. The rush to roll-out systems to support home working and to activate virtual versions of real-world business channels saw unprecedented digital transformation equivalent to years achieved in just a few months. But this […]

Read full post

Apache ‘Log4Shell’ Log4j (version 2) vulnerability (CVE-2021-44228)

Posted on

Our teams are actively responding to the Log4Shell (or LogJam) 0-day threat which has been reported in the Apache Log4j 2 Java library and has been awarded a severity rating of 10 out of 10 by NIST.  We are alerting customers to systems and services that may potentially be impacted and assisting with the investigation and remediation of any […]

Read full post

Alexis V elected to CREST-EU Council

Posted on

We’re proud to announce that Alexis V, Senior Security Consultant at Prism Infosec, has been elected to the newly formed CREST-EU Council.  CREST, an international not-for-profit accreditation and certification body that represents and supports the technical information security market, announced its intention to form the Council and an EU Chapter at the end of October. Due to meet in the […]

Read full post

Was the NSA’s Cyber Security director right to say attackers know networks best?

Posted on

By Phil Robinson There was an interesting spat on Twitter during September when Rob Joyce, Cyber Security Director of the National Security Agency, disputed the notion put forward by security researcher @RayRedacted that “Defenders think in lists, attackers think in graphs”. (Presumably suggesting that defenders are preoccupied with tick lists and compliance while attackers are looking at the data […]

Read full post

No Shell? No Problem!

Posted on

Enumerating internal networks via ssh-tunnels, Alexis V, November 2021 On a recent engagement, we were tasked to assess the security of an Secure File Transfer Protocol (SFTP) server. We were provided with a regular account to facilitate the file uploads, and so proceeded to work our way through the common checks. We tried to: Log […]

Read full post

FILTER RESULTS

Latest tweets

A great conference @BSidesLondon, thanks for having us at #BSidesLDN2024! Looking forward to continuing the relationship next year!

Prism Infosec is proud to be a gold sponsor of @BSidesLondon 2024! Come and visit us on our stand and join in our cyber scavenger hunt! #CyberSecurity #bsides

Sign up to our newsletter

  • Fields marked with an * are mandatory

  • This field is for validation purposes and should be left unchanged.