Our Vision

To give customers the most compelling IT Support experience possible.

Our Mission

Our mission is simple: make technology an asset for your business not a problem.

Our Values

We strive to make technology integrate seamlessly with your business so your business can grow. As your technology partner, when your business grows ours will grow with you, therefore, we will work hand in hand with you to support your growth.

Our Values

We develop relationship that makes a positive difference in our customers Business.

Our Values

We exibit a strong will to win in the marketplace and in every aspect of our Business

Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

The Difference Between Advising and Shaming

Imam Ibn Rajab Al-Hanbali's work, "The Difference Between Advising and Shaming," is a profound exploration of the subtle but crucial distinctions between offering constructive #advice and engaging in harmful #criticism. His insights are timeless, providing valuable guidance on how to interact with others in a manner that promotes growth and preserves dignity.


Here are ten key lessons from the book that resonate deeply:

1. Intent Matters: The intention behind advising should always be to help and support the individual. In contrast, shaming aims to belittle and demean. The purpose behind the words greatly influences how they are received.

2. Respect and Dignity: Effective advice honors the recipient's dignity and self-worth. Shaming, however, undermines a person's value and can inflict emotional harm.

3. Constructive vs. Destructive: Advising offers constructive feedback that promotes improvement and growth. Shaming is destructive, often leaving the individual feeling worse without offering a clear path forward.

4. Focus on Behavior, Not Person: Good advice targets specific behaviors or actions and suggests ways to improve them. Shaming attacks the person’s character or identity, making it personal and damaging.

5. Empathy and Understanding: Advising should come from a place of empathy and understanding, taking into account the person's circumstances and feelings. Shaming lacks empathy and often disregards the individual's context.

6. Encouragement vs Discouragement: Advising encourages and motivates the person to do better, offering support and upliftment. Shaming discourages, leading to decreased self-esteem and motivation.

7. Long-term Impact: Advising fosters positive long-term effects, building trust and encouraging continuous improvement. Shaming, on the other hand, can have lasting negative impacts, damaging relationships and causing emotional scars.

8. Promotes Growth: Advising is geared towards helping individuals grow and develop, focusing on their potential and strengths. Shaming stunts growth by fixating on faults and weaknesses.

9. Builds Trust: Consistent, respectful advising builds trust and strengthens relationships. Shaming erodes trust, creating distance and resentment.

10. Leads to Positive Change: When done correctly, advising can lead to meaningful and positive change. Shaming often results in defensiveness, denial, or withdrawal, preventing any constructive outcomes.

These lessons emphasize the importance of delivering #feedback with care, empathy, and respect. In doing so, we uplift others and contribute positively to their personal and professional development, rather than tearing them down.

This distinction is particularly relevant in today's world, where the lines between #constructive #criticism and harmful #shaming can easily blur. By applying the principles outlined by Imam Ibn Rajab Al-Hanbali, we can navigate our interactions more mindfully and contribute to a more supportive and understanding society.

The Lazarus Heist

 The 2016 #Bangladesh #Bank #cyber heist, where $81 million was stolen, ranks among the most significant cybercrimes. #Hackers infiltrated Bangladesh Bank’s #SWIFT #network and initiated unauthorized transfers from its account at the #Federal Reserve #Bank of New York. The stolen funds were dispersed through accounts in the #Philippines, where they were laundered via casinos with weak AML (anti-money laundering) regulations.



The #Lazarus Group, a #North #Korean state-sponsored #hacking syndicate, was identified as the primary perpetrator. They used custom #malware to gain access, bypassing inadequate security controls within #Bangladesh #Bank. Investigators, including those from #India, found that the attackers exploited weak network segmentation and #monitoring within the bank. According to Geoff White  "The Lazarus Heist"(pp. 109-116), the malware code used was highly advanced, further complicating detection and response.

The incident revealed critical issues in Bangladesh Bank’s #infrastructure, including outdated systems and lack of incident response planning, which delayed containment efforts. Adding to the suspicion, a fire broke out post-incident in a specific #office area, destroying potential evidence and hindering investigations. https://lnkd.in/gNctf6TK

This fire, combined with reports of potential data mishandling by the bank’s IT department, raised doubts about the transparency of the bank’s response.

International organizations, including #INTERPOL and the #FBI, were involved in the probe, linking the heist to #North Korea’s efforts to bypass global sanctions. The heist pressured SWIFT to improve its security standards and forced global financial institutions to reassess their #cybersecurity practices, particularly in high-stakes interbank #communication.

The heist underscores the need for robust #cybersecurity, stronger internal controls, and improved global AML regulations. The case remains a pivotal example of how cybercriminals can #exploit financial systems, emphasizing the need for vigilant, coordinated international cybersecurity efforts.

Cybersecurity from an Islamic Perspective: Bridging Faith and Digital Security

I'm incredibly excited to announce a significant milestone in my professional journey and passion! After much dedication and hard work, I've officially published my debut book, "Cybersecurity from an Islamic Perspective: Bridging Faith and Digital Security."



This book is a deep dive into how timeless Islamic ethical principles like Sidq (truthfulness/integrity) and Amanah (trustworthiness/custodianship) can offer unique insights and a robust framework for navigating the complex challenges of our digital world. It's a topic I believe is crucial for fostering a more secure and responsible cyberspace for everyone.

As my first book, this project has been a labor of love, drawing inspiration from my background and the esteemed works of many cybersecurity and Islamic scholars. I'm eager to share this unique perspective with my network and the broader community.

You can find "Cybersecurity from an Islamic Perspective" on Amazon here:
👉 https://lnkd.in/gZfrvWe5

For those with Kindle Unlimited, the Kindle version is available to read for free! You can also read a free sample chapter before purchasing.

I would be honored if you would consider reading it. Your insights and feedback are invaluable, especially as I embark on this new chapter as an author. Please feel free to share your thoughts, and let's continue the conversation around ethics and security in the digital age.

#Cybersecurity #IslamicEthics #DigitalSecurity #NewBook #FirstTimeAuthor #Infosec #FaysalHasan #EthicalAI #DigitalResilience #TechEthics #KindleUnlimited #CISSP #Policy #Islam #Frameworks #OT #GRC #Governance

First known ransomware that uses Artificial Intelligence to operate.

The game has changed. #ESETResearch has uncovered #PromptLock, the first known #ransomware that uses #artificial #intelligence to operate.

This isn't a pre-programmed #attack. Written in #Golang, this novel #malware leverages a local, #open-source #AI model (gpt-oss:20b) and the Ollama API to write its own #malicious Lua scripts on the fly.

They have identified both #Windows and #Linux variants of this #ransomware uploaded to VirusTotal.

This means the #attack #code can change with every #execution, making it incredibly difficult for traditional #security solutions to keep up.

ESET have named this threat Filecoder.PromptLock.A.
IoCs (Indicators of Compromise):
📄 24BF7B7B72F54AA5B93C6681B4F69E579A47D7C102
AD223FE2BB4563446AEE5227357BBFDC8ADA3797
BB8FB75285BCD151132A3287F2786D4D91DA58B8
F3F4C40C344695388E10CBF29DDB18EF3B61F7EF
639DBC9B365096D6347142FCAE64725BD9F73270
161CDCDB46FB8A348AEC609A86FF5823752065D2

This is a wake-up call for the cybersecurity industry.

We need to prepare for a new era of polymorphic, AI-driven threats.

#Ransomware #AI #Cybersecurity #PromptLock #ESETResearch #Threats #Infosec #Golang

Level up your OT skills with these live demos and learning resources.

 Level up your OT skills with these live demos and learning resources.

Whether you're an Cyber pro wants to know more about ICS and OT or IT professional, an engineer, or just starting in ICS/SCADA cybersecurity, these resources are a must-see.

I have got something for everyone, from live automation demos to guides on building your own cyber lab.

Live Automation Demo: Check out the Ecava IGX SCADA IGX Systems live demo. This is a great way to see a full-featured industrial control system in action, complete with real-time data, trends, and alarm management.
https://lnkd.in/g3XvUEmM

Nuclear Reactor Simulator: Test your operational skills with the Dalton Nuclear Reactor Simulator from The University of Manchester Faculty of Science and Engineering  TheUniversity of Manchester.

A unique and hands-on tool for understanding the complexities of critical infrastructure.
https://lnkd.in/gC3PZHSP

one more is ITrust  from Singapore which is the host of several world-class testbeds and training platforms. For Electric, water and IOT etc can be found here https://lnkd.in/gwajtsNH

Another one is Labshock by Zakhar Bernhardt which provides a ready-to-use environment to learn, simulate and test defensive strategies. https://lnkd.in/gkn_4gKT

and this is on of his great post on OT SIEM Mastery: Your Leveling Guide 1-60
https://lnkd.in/geHfR_vi?

Graphical Realism Framework for Industrial Control Simulation (GRFICS)
https://lnkd.in/gSqyyTk2

Virtual Lab Setup Guide: Ready to get hands-on? Rodrigo Cantera Pérez blog series provides a step-by-step guide to setting up a virtual lab to test SCADA protocols and attack Modbus TCP devices.
https://lnkd.in/geRNu9ZW

For OT compliance IEC62443 Simulator https://lnkd.in/eU-KwFRs

OT substation https://lnkd.in/gAgifT8f

and finally ICS/SCADA Cybersecurity Resources: Getting into OT security? @Robert M. Lee founder and CEO Dragos, Inc., has put together a legendary collection of resources for beginners, covering everything from foundational skills to specific training. this is an old post but a lot still relevent
https://lnkd.in/gcVfVGs4

Save this post , like, or Share your favorite resources in the comments!

#OT #OperationalTechnology #ICS #SCADA #Cybersecurity #Simulator #IEC62443  #IndustrialAutomation #Engineering #ProfessionalDevelopment #Energy #oil #gas #manufacturing #automation #cyberguide #pipeline #industry #Nuclear #rail #transport

Cyber Health Check Tool

Try the new Cyber Health Check Tool to get a tailored action plan to improve your cyber security. 

Whether as an individual, or for your business or not-for-profit, the free and anonymous online tool is a fast self-assessment to measure your cyber awareness. 

Once completed, you'll have personalised advice to improve your cyber security. You can also track your progress by implementing your action plan and re-assessing. 

Try the tool now: https://lnkd.in/g2EMp6YN



OT Cyber Resilience Summit

 A full day of deep insights at the #OT Cyber Resilience Summit in #Melbourne The energy was palpable, with a powerful gathering of #Australia's top leaders in operational technology security.

The consensus was clear: moving beyond theory to on the ground execution is key. My main takeaways:

🔷 Asset Inventory is Job Zero: But it must be intelligent. Context like system interdependencies and physical location is everything.

🔷 Close the Design Reality Gap: Resilience is built by engaging directly with site operations, not just from design documents.

🔷 Build the Right Structure: Dedicated roles, clear IT/OT frameworks, and hygiene focused KPIs are non negotiable for program maturity.

🔷 Lean on Proven Frameworks: The #SANS 5 Critical Controls and the new #ASD #ACSC "CI Fortify" guide provide an essential blueprint for action.

It was also a pleasure to reconnect with peers and discuss these critical topics.

The need for a principled, holistic approach is what inspired me to write

"The Ethical Guardian of Industry," - which merges advanced security strategies with ethical governance to protect our vital infrastructure available at #Amazon and #Kindle to check out follow this link https://lnkd.in/gxQ3_4Dm

Grateful for the knowledge shared by all and love your feedback on the book!

#OTCyberSecurity #CyberResilience #OperationalTechnology #ICSsecurity #Melbourne #CriticalInfrastructure #ASD #ACSC #SANS #CIFortify #ICS #OT #Scada #Stuxnet #Cyber

Defend your Microsoft Defender now

Defend your #Microsoft #Defender now

The #Microsoft #Defender Triad Your SOC Can't Afford to Ignore

When a disgruntled researcher (Nightmare-Eclipse/Chaotic Eclipse) drops three coordinated tools on GitHub in 18 days #BlueHammer, #RedSun, and #UnDefend the industry must pay attention.

The Three-Pronged Attack:

🔵 #BlueHammer (CVE-2026-33825, CVSS 7.8) Patched. A local privilege escalation (LPE) flaw chaining TOCTOU and path confusion to extract NTLM hashes and escalate to SYSTEM. Exploited in the wild since April 10.

🔴 #RedSun (Unpatched)  A privilege escalation with ≈100% reliability on fully updated Windows 10, 11, and Server 2019+. It abuses Defender’s "cloud tag" file restoration to overwrite a system binary (TieringEngineService.exe) and executes it as SYSTEM.

🔻 #UnDefend (Unpatched)  A denial-of-service tool that, from a standard user account, blocks Defender signature updates (passive) or disables the engine entirely (aggressive), leaving systems blind.

What This Means for Business:

Huntress has confirmed all three techniques are already weaponized in the wild. With #RedSun and #UnDefend unpatched, you have no official fix. A single initial access (phishing, stolen creds) can lead to:

· Unprivileged user → Full SYSTEM access
· NTLM hash extraction and lateral movement
· Defender blind spot for follow-on payloads

What This Means for the Attacker:

This isn't just a bug report, it's a complete offensive kill chain. Escalate (BlueHammer/RedSun), execute (SYSTEM payload), and blind detection (UnDefend). No memory corruption, no kernel exploit, just logic flaws in Defender's own trusted operations.

Your Action Plan:

· Hunt for indicators: Unexpected Cloud Files sync registrations, NTFS junction/reparse point creation, VSS snapshot enumeration from user-space processes

· Monitor privileged writes to C:\Windows\System32\TieringEngineService.exe

· Consider disabling Cloud-delivered protection as a temporary mitigation for RedSun

· Assume compromise if unpatched systems have had local code execution exposure

Run defender XDR queries published by Steven Lim https://lnkd.in/gFR5bFRz

💡 Bigger picture: This episode underscores the fragility of supply chain trust and the catastrophic consequences when vulnerability disclosure breaks down. Microsoft credited other researchers for CVE-2026-33825—not Nightmare-Eclipse—fueling an already volatile situation.

Zero-days are inevitable. Having three dropped in rapid succession by the same researcher, with two remaining unpatched, is a wake-up call for proactive threat hunting.

Stay vigilant. 🛡️

#cybersecurity #infosec #Microsoft #ZeroDay #WindowsDefender #PrivilegeEscalation #BlueHammer #RedSun #UnDefend #ThreatIntelligence

Critical EDR threats - RoguePlanet,Silent Choke

 🔻 Three critical #EDR threats dropped in the last couple of weeks that fundamentally break how we think about endpoint security.

If your strategy relies on "having #EDR installed and we are secure," know this below tools ready to break in your defence.

below are quick technical summary of the tools and techniques full details technical link in the comment section.

1. #EDRChoker (Silent Choke)
Throttles EDR outbound bandwidth to 8 bits/sec using Windows QoS.

How: Targets pacer.sys below WFP. TLS handshakes time out.
Result: EDR goes blind. Agent looks online. SOC sees nothing.

2. #AI Evasion Malware Lab Factory The attacker had not written a clever new piece of malware. They had built a factory. Wired into the Cursor AI coding IDE and driven by multiple Anthropic Claude Opus 4.5 agents, the setup mass-produced and tested EDR-evasion payloads.
Claude Opus 4.5 mass-produced 70+ evasion techniques against EDRs, #CrowdStrike, #Defender.

Reality is #AI hallucinated success rates, but productivity multiplier is real. One operator now does what took a team of Hackers.

3. #RoguePlanet  -NEW RoguePlanet Windows Defender Vulnerability.
Race condition in #Microsoft #Defender → Local Privilege Escalation to SYSTEM.

Impact: Works on fully patched Windows 10/11 (June 2026). Researcher warns: "More Defender vulns coming."

#SOC Actions to catch this tools
#EDRChoker
· Run Get-NetQosPolicy. Monitor Event IDs 4001, 4002.
· Alert on "Sensor Health Status Change."

#AI Factory:
· Hunt \Users\Documents\test\ or \build\out\ executables.
· Alert on >25 LDAP queries in 10 mins.
· Block api.telegram.org & *.workers.dev from workstations.

#RoguePlanet
· Alert on MsMpEng.exe spawning cmd.exe or powershell.exe with #SYSTEM token.
· Disable VHD/VHDX auto-mounting via GPO.
· Prioritize application allowlisting (blocks the exploit entirely).

💼 For Management

1. Tamper Protection: #Sensor dropout must trigger a paged alert.
2. Don't Trust #Defender Alone: More vulns unreleased. Layer controls.
3. Test Your Config: Haven't tested in 30 days? Assume failure.
4. #AI Multiplier is Here: Move from signatures to fundamentals: MFA, patching, allowlisting, segmentation.

Bottom Line is attackers now build factories to bypass your stack, choke telemetry, and weaponize Defender against you. Defend accordingly.

#cybersecurity #EDR #infosec #AI #ThreatHunting #BlueTeam #CISO #MicrosoftDefender #ZeroDay

A large-scale exploitation campaign targeting web content management systems (CMS


 A large-scale exploitation campaign targeting web content management systems (CMS), with many Australian businesses impacted.

The vulnerabilities being targeted affect CMS software and plugins which, if exploited, enable malicious actors to remotely access and control targeted web servers. 

Organisations, including small businesses, are encouraged to take immediate action to protect their web servers.

 

▶ Inspect your CMS for webshells.

▶ Examine your web access logs for any IP addresses making GET or POST requests to any webshell paths.

▶ Treat servers with identified webshells as compromised, isolate them and perform an audit for malicious activity.

▶ Review network logs for interactions with identified IP addresses. 

▶ Investigate logging and hosts for evidence of persistence, lateral movement or other malicious actions.

▶ Patch vulnerable systems to prevent re-infection.

▶ If there are indications that websites are compromised, restore websites from a recent known-good backup.

 

If a service provider maintains your website, point them to this alert and review our guidance at the below link for additional questions to ask. 

 

Read the full alert and take additional steps to protect your websites

 👉 https://lnkd.in/gkyDM4uY

Increased risk of phishing scams following CrowdStrike outage




The Australian Signals Directorate has issued a warning about an increased risk of phishing scams following yesterday's CrowdStrike outage.

According to the alert, ASD’s ACSC has identified numerous malicious websites and unofficial code claiming to assist entities in recovering from the widespread outages caused by the CrowdStrike technical incident.

ASD’s ACSC strongly advises all consumers to obtain their technical information and updates directly from official CrowdStrike sources only. [Learn more here]https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/widespread-outages-relating-crowdstrike-software-update?fbclid=IwZXh0bgNhZW0CMTEAAR1veIrKLYJrloZIx7AvqS6Nlqv3UfvENiPg6lVbHUhffjbS_7HBzNQEGdI_aem_TUaGcC36MEN9SJxw0OUTnQ


It appears that threat actors are exploiting the #CrowdStrike situation through #phishing and #spoofing campaigns.

Here is a list of newly created domains https://urlscan.io/search/#crowdstrike*

Before clicking on any links, use tools like Domain Dossier, URLscan.io, and VirusTotal to check their authenticity — because threat actors never miss an opportunity to exploit a disaster.

#threatactors #hackers #CrowdStrike #phishing #urlscan #cybertip #VirusTotal #ASD #ACSC #AISA #Australia

Crowdstrike Global IT outage affecting computers around the world

A current worldwide #CrowdStrike issue causing #BSOD. Seen reports from  AU, NZ ,Japan, India. And Europe. The global computer outage affecting airports, banks and other businesses.

CrowdStrike’s cybersecurity software — used by numerous Fortune 500 companies, including major global banks, healthcare and energy companies — detects and blocks hacking threats. Like other cybersecurity products, the software requires deep-level access to a computer’s operating system to scan for those threats. In this case, computers running Microsoft Windows appear to be crashing because of the faulty way a software code update issued by CrowdStrike is interacting with the Windows system.

This issue is not impacting Mac- or Linux-based hosts

Some servers on perm and cloud and devices are not resuming correctly and are getting stuck in boot loops that have #Crowdstrike.

Some seen successful reboots which work for about 15 mins and then they stop and then go back into a boot loop.

Technical Breakdown

1. Crowdstrike publishes a content update for their threat feed, which is basically a list of patterns of “bad things” 

2. Software agents get this update and apply the controls to block things that match this pattern 

3. The update has a pattern which matches a critical Windows process but the software blocks it anyway

4. Windows crashes with a Blue Screen of Death (BSOD) and reboots 

5. On reboot, CrowdStrike kills the process again and Windows reboots

6. And it’s now a loop… There are various ways of fixing this but for most systems it will involve physically visiting every affected system, booting into “safe mode” and fixing the problem manually. 

For some cloud systems though, such as AWS, “safe mode” is not even possible so this fix doesn’t work. The virtual servers will need to be shut down, their disks cloned, attached to another server, edited to remove the offending files and then finally reattach to the original server.

BUT, if you’re protecting your data and using encryption at rest, you need to manually decrypt the disk with a BitLocker Recovery Key, which is probably - for most companies


Updated workaround steps:

Boot Windows into Safe Mode or the Windows Recovery Environment

Navigate to the C:\Windows\System32\drivers\CrowdStrike directory

Locate the file matching “C-00000291*.sys”, and delete it.


Boot the host normally.

Crowdstrike published a post with updated details for quering machine and how to fix here

https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/


This is really just a good reminder of how MANY systems are dependent on IT. 

Technology is engrained in every part of our lives. We don’t notice it when it’s working well. We only notice when something goes wrong. No one talks about how many millions of attacks were stopped, or upgrades that went smoothly. Everyone remembers the ones that didn't.

#Crowdstrike #update #BSOD #EDR #outage #ITissue


Free cyber security course. Delve into essential cybersecurity NIST Risk management frameworks

 🌟 Exciting Announcement Alert! Last week, NIST took a significant step in advancing cybersecurity education by releasing four introductory courses covering their flagship publications for FREE! 🆓



📘 Delve into essential cybersecurity frameworks with courses on:

- NIST SP 800-37, Risk Management Framework (RMF) 

- NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations

- NIST SP 800-53A, Assessing Security and Privacy Controls in Information Systems and Organizations

- NIST SP 800-53B, Control Baselines for Information Systems and Organizations


🔍 These meticulously curated courses offer unparalleled insights into cybersecurity best practices, delivered in a concise format designed to optimize learning efficiency. With just 60 minutes required for each course, professionals can easily incorporate this valuable knowledge into their busy schedules.


But the excitement doesn't stop there! NIST has also unveiled a comprehensive crosswalk between NIST CSF 2.0 and NIST SP 800-53, providing invaluable guidance for cybersecurity practitioners navigating these frameworks.


Some common question and answer regarding the course

Q: Are these courses self-guided or instructor-led?

A: The courses provided are self-guided online courses.


Q: Is there a fee to access these courses?

A: No. The NIST materials provided on the CSRC website, including the RMF and SP 800-53 series introductory courses, are free to any interested party.


Q: Is registration required?

A: No. Registration is not required to access the courses.


Q: Is there a quiz at the end of each course?

A: No, there are no quizzes at the end of each course. The material in each course is provided for informational purposes only.


Q: Are certificates issued upon completion of the courses?

A: At the end of each course presented on this NIST website, a certificate of course completion is provided as a courtesy. The certificate only identifies that the course material was viewed and does not attest to any qualifications, knowledge, or skill level resulting from the completion of the course.


Q: How do I print the certificate of completion?

A: Use the browser's print option, generally found in the browser menu, to print or capture a PDF of the course certificate. Please add your name and the date of completion to the certificate.


🔗 Dive into these invaluable resources today! Links to the crosswalk and courses can be found in here https://csrc.nist.gov/Projects/risk-management/rmf-courses


.Let's elevate our cybersecurity expertise together!


 💼 #NIST #Cybersecurity #ProfessionalDevelopment #KnowledgeIsPower

Navigating the Path to a Cybersecurity Career in Australia or anywhere : Roles, Opportunities, and Guidance

Embarking on a career in cybersecurity is an exciting journey filled with opportunities for growth and learning. With the ever-evolving digital landscape, the demand for skilled cybersecurity professionals continues to rise, making it an ideal time to explore this dynamic field. 


In this post, we will delve into the various roles available in cybersecurity, including specialized positions, and provide guidance on how to pursue them effectively in the Australian market

1. Blue Team Roles

   Security Analyst: Responsible for monitoring and analyzing security events, investigating incidents, and implementing defensive measures to protect an organization's systems and data.

   Security Operations Center (SOC) Analyst: Works in a SOC environment, monitoring security alerts, triaging incidents, and responding to threats in real-time.

   Incident Responder: Focuses on incident detection, containment, and recovery, coordinating response efforts during security breaches or incidents.


 Getting Started: Entry-level positions often require foundational knowledge of cybersecurity principles and tools. Pursue certifications like CompTIA Security+ and gain experience through internships, entry-level roles, or hands-on projects.


2. Red Team Roles:

   Penetration Tester (Pen Tester): Conducts authorized simulated attacks on systems and networks to identify vulnerabilities and assess security posture.

   Ethical Hacker: Utilizes hacking techniques and methodologies to identify and address security weaknesses in systems and applications.

   Security Consultant: Provides expertise in assessing and improving security controls, conducting security assessments, and recommending remediation measures.


   Getting Started: Develop technical skills in penetration testing, network security, and ethical hacking through hands-on labs, capture-the-flag (CTF) competitions, and certifications like Certified Ethical Hacker (CEH) or Offensive Security Certified Professional (OSCP).


3. Compliance and Governance Roles:

   Governance, Risk, and Compliance (GRC) Analyst: Ensures adherence to regulatory requirements, industry standards, and internal policies, conducting risk assessments and developing compliance strategies.

   Security Auditor: Conducts audits of systems, processes, and controls to assess compliance with regulatory frameworks and industry standards.


   Getting Started: Gain knowledge of relevant regulations and standards such as GDPR, HIPAA, ISO 27001, and NIST Cybersecurity Framework. Pursue certifications like Certified Information Systems Auditor (CISA) or Certified Information Security Manager (CISM).


4. Specialized Roles:

   Cloud Security Specialist: Focuses on securing cloud environments, ensuring the confidentiality, integrity, and availability of cloud-based assets and services.

   IoT Security Specialist: Addresses security challenges associated with Internet of Things (IoT) devices, networks, and ecosystems, ensuring the protection of connected devices and data.

   Industrial Control Systems (ICS) Security Analyst: Secures operational technology (OT) environments, including supervisory control and data acquisition (SCADA) systems and industrial control systems, against cyber threats.


   Getting Started: Gain specialized knowledge and skills through training programs, certifications, and hands-on experience in specific domains such as cloud security, IoT security, or industrial cybersecurity.


To pursue these roles, it's essential to continuously expand your knowledge, develop practical skills, and stay updated on emerging technologies and threats. Engage in professional development activities, participate in relevant communities and forums, and leverage networking opportunities to connect with industry professionals and explore career paths in cybersecurity. Additionally, consider pursuing advanced certifications and higher education programs to deepen your expertise and advance your career in the field


Getting Started in Cybersecurity: Your Roadmap to Success


Embarking on a career in cybersecurity can seem daunting, especially for newcomers to the field. However, with the right approach and resources, anyone can start their journey towards becoming a skilled cybersecurity professional.

Here's a comprehensive roadmap to help you get started:

1. Gain Foundational Knowledge: Begin by building a strong foundation in cybersecurity principles, concepts, and technologies. Consider enrolling in formal education programs such as cybersecurity-related courses, diplomas, or degree programs offered by universities or technical colleges. These programs cover essential topics such as network security, cryptography, risk management, and ethical hacking, providing you with a solid understanding of the fundamentals.


2. Explore Different Areas of Cybersecurity: Cybersecurity is a broad field with various specializations and career paths. Take the time to explore different areas of cybersecurity to discover where your interests and strengths lie.

The spectrum of skills required in Cyber is larger than that of most professions.

We need people who understand:

➡️ People Management

➡️ Security Compliance and Regulations

➡️ Governance and Risk Management

➡️ Legal and Ethical Considerations

➡️ Security Awareness, Training and Psychology

➡️ Engineering

➡️ Architecture

➡️ Endpoints & Networks

➡️ Secure DevOps (DevSecOps)

➡️ Threat Intelligence

➡️ Detection & Investigation

➡️ Incident Response

➡️ Security Research and Innovation

➡️ and more…


Truth is, effective Cyber Security is a team sport. One where a diverse group of people are working together, communicating and playing to our strengths.

Research roles such as security analyst, penetration tester, security consultant, or compliance officer to understand their responsibilities, required skills, and career prospects. Engage with online communities, forums, and professional networking platforms to connect with experienced professionals and learn from their experiences.


3. Pursue Certifications and Training: Certifications play a crucial role in validating your knowledge and skills in cybersecurity and are highly valued by employers. Consider obtaining industry-recognized certifications such as CompTIA Security+, Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Certified Information Security Manager (CISM). These certifications demonstrate your expertise and commitment to the field, increasing your chances of landing a job in cybersecurity. Additionally, leverage online training platforms and resources such as Cybrary, Coursera, or Udemy to further enhance your skills and knowledge in specific areas of cybersecurity.


4. Gain Practical Experience: Hands-on experience is invaluable in cybersecurity and can significantly enhance your employability. Look for opportunities to gain practical experience through internships, co-op programs, or entry-level positions in cybersecurity-related roles. Many organizations offer internship programs specifically for cybersecurity students or recent graduates, providing valuable exposure to real-world cybersecurity challenges and environments. Additionally, consider participating in capture-the-flag (CTF) competitions, hackathons, or open-source projects to hone your technical skills and problem-solving abilities.


5. Network and Engage with the Cybersecurity Community: Networking is key to success in cybersecurity. Connect with professionals in the field, join online communities and forums, and attend industry events, conferences, and meetups to expand your network and learn from others. 

Join professional organizations like the Australian Information Security Association (AISA) or the Australian Computer Society (ACS) to connect with industry professionals and stay updated on the latest trends and developments. Attend events such as BSides, which offer networking opportunities and valuable insights into the cybersecurity community.

Engage with cybersecurity professionals on platforms like LinkedIn, Twitter, or Reddit, participate in discussions, ask questions, and seek mentorship opportunities. Building relationships with experienced professionals can provide valuable insights, guidance, and career opportunities in cybersecurity.


6. Continuously Learn and Stay Updated: Cybersecurity is a constantly evolving field, with new threats, technologies, and best practices emerging regularly. Stay updated on the latest trends, developments, and news in cybersecurity by following industry blogs, podcasts, and news sources. Subscribe to cybersecurity newsletters, join relevant online forums and communities, and participate in webinars, workshops, and training sessions to stay informed and expand your knowledge. Additionally, consider pursuing advanced certifications, attending conferences, or pursuing higher education programs to further develop your expertise and advance your career in cybersecurity.


By following this roadmap and taking proactive steps to build your skills, gain experience, and network with professionals in the field, you can kickstart your career in cybersecurity and embark on a rewarding and fulfilling journey in this dynamic and high-demand field.

Navigating a cybersecurity career in Australia requires dedication, continuous learning, and perseverance. By exploring different roles, gaining practical experience, and staying updated on industry trends, you can embark on a rewarding career path in cybersecurity and contribute to the protection of organizations against evolving digital threats.

For more guidance and resources on pursuing a cybersecurity career in Australia, stay connected with MaximisIT.net, your trusted partner in cybersecurity.

MGM Cyber Attack cost 110 Million

In September the hospitality and entertainment company #MGM Resorts was hit by a #ransomware attack that shut down its systems at MGM Hotels and Casinos.

The incident affected #hotel reservation systems in the United States and other IT systems that run the casino floors.

The company now revealed that the costs from the #ransomware attack have exceeded $110 million. The company paid third-party experts $10 million to clean up its systems.

Allegedly, a criminal gang made up of U.S. and U.K.-based individuals that cybersecurity experts call #Scattered Spider (aka Roasted 0ktapus, UNC3944 or Storm-0875) initiated a social engineering attack that led to the near shutdown of #MGM Resorts International.

Scattered Spider #encrypted several hundred of their #ESXi servers, which hosted thousands of VMs supporting hundreds of systems widely used in the hospitality industry. This caused cascading chaos. As the #ESXi hosts became encrypted one after another, the applications running on them crashed … one after another … after another. Hotel room keys no longer worked. Dinner reservation systems were down. Point-of-sale systems were unable to take payments. Guests were unable to check in or out. Slot machines were completely unavailable. At this point, MGM was hemorrhaging money – and potentially its credibility.

A nice deep technical Analysis by cyber #security company #CyberArk whic details the #attack based on the information currently available, analyze its root causes and discuss key takeaways to help organizations strengthen their security posture.

#cyber #databreach #socialengineering #ransomware #okta #security 

https://www.cyberark.com/resources/blog/the-mgm-resorts-attack-initial-anaysis




Developing and implementing security controls for Azure Active Directory (Azure AD)

Today we will share the list of things you need to consider for Developing and implementing security controls for Azure Active Directory (Azure AD):



1. Identify Azure AD Assets:

   - Create an inventory of all Azure AD assets, including user accounts, groups, applications, service principals, and Azure AD resources.

   - Document the purpose and sensitivity level of each asset.

   - Classify assets based on their importance and criticality to the organization, considering factors such as the data they provide access to or the applications they authenticate.


2. Perform a Risk Assessment:

   - Identify potential threats to your Azure AD environment, such as unauthorized access, identity theft, insider threats, or data breaches.

   - Assess vulnerabilities that could be exploited by conducting a comprehensive assessment of your Azure AD configuration and associated resources.

   - Evaluate the potential impact of each threat and vulnerability on the confidentiality, integrity, and availability of your Azure AD assets.

   - Determine the likelihood of each risk occurring based on historical data, industry trends, and the organization's threat landscape.

   - Prioritize risks based on their potential impact and likelihood, focusing on those with the highest potential risk to your Azure AD environment.


3. Define Security Objectives:

   - Review your organization's overall security strategy and compliance requirements, including any specific Azure AD security requirements.

   - Identify specific security objectives that align with these requirements and the risk assessment findings. Ensure these objectives are measurable and relevant to your organization's needs.

   - Examples of security objectives for Azure AD may include enforcing strong authentication policies, implementing conditional access controls, and protecting privileged accounts.


4. Select Security Controls:

   - Research and review Azure AD security best practices, Azure Security Center recommendations, and Azure AD-specific security frameworks.

   - Identify security controls available in Azure AD that address the identified risks and align with your security objectives.

   - Examples of security controls for Azure AD include enabling multi-factor authentication (MFA), implementing conditional access policies, using Azure AD Privileged Identity Management (PIM), and leveraging Azure AD Identity Protection.

   - Consider using Azure AD security features such as Azure AD Conditional Access, Azure AD Identity Governance, and Azure AD Privileged Identity Management to enhance your security posture.


5. Design Azure AD Security Architecture:

   - Plan the structure of your Azure AD tenant, considering factors such as the number of Azure AD directories, users, groups, and applications required.

   - Define the authentication and access models to be used, such as cloud-only identities, hybrid identities with Azure AD Connect, or federation with external identity providers.

   - Determine the appropriate Azure AD license level and edition based on your organization's needs for advanced security features.

   - Design RBAC roles and assignments for Azure AD resources, ensuring least privilege principles are followed.

   - Establish Azure AD security policies, including password policies, sign-in risk policies, and device compliance policies.


6. Implement Security Controls:

   - Enable multi-factor authentication (MFA) for Azure AD accounts, especially for privileged accounts and accounts with access to sensitive resources.

   - Implement conditional access policies to enforce granular access controls based on user, device, location, and risk factors.

   - Utilize Azure AD Identity Protection to detect and respond to suspicious sign-in activities and risky user behaviors.

   - Leverage Azure AD Privileged Identity Management (PIM) to manage and monitor privileged access to Azure AD and other Azure resources.

   - Regularly review and remediate risky sign-in events, risky users, and vulnerable configurations identified by Azure AD security features.


7. Provide User Training and Awareness:

   - Develop training materials and conduct sessions to educate users about Azure AD security best practices.

   - Train users on the importance of strong passwords, avoiding password reuse, and using MFA for enhanced security.

   - Educate users about recognizing and reporting phishing attempts, suspicious sign-in activities, and other potential security risks.

   - Raise awareness about the importance of safeguarding Azure AD credentials, avoiding sharing of accounts, and promptly reporting any unusual activities or potential security breaches.


8. Establish Incident Response Procedures:

   - Develop an incident response plan specifically for Azure AD security incidents.

   - Define roles and responsibilities for incident response team members, including those responsible for handling Azure AD security incidents.

   - Establish communication protocols and reporting mechanisms to ensure prompt detection, response, and resolution of Azure AD security incidents.

   - Document step-by-step procedures for isolating affected accounts, investigating potential breaches, resetting compromised credentials, and implementing necessary security measures to prevent future incidents.

   - Conduct regular drills and exercises to test the effectiveness of the incident response procedures and identify areas for improvement.


9. Implement Monitoring and Auditing:

   - Enable Azure AD auditing to track and monitor activities such as user sign-ins, application registrations, role assignments, and directory changes.

   - Utilize Azure AD logs and Azure Monitor to collect and analyze security-related events and alerts.

   - Configure alerts and notifications for suspicious activities, such as multiple failed sign-in attempts or privilege escalations.

   - Integrate Azure AD with a Security Information and Event Management (SIEM) system for centralized log management, analysis, and correlation.

   - Regularly review and analyze Azure AD logs and security reports to identify anomalies, detect security incidents, and take appropriate actions to mitigate risks.


10. Regular Assessment and Improvement:

   - Continuously assess the effectiveness of your Azure AD security controls.

   - Stay informed about Azure AD security updates, new security features, and best practices provided by Microsoft.

   - Conduct periodic security assessments and penetration testing to identify vulnerabilities and weaknesses in your Azure AD environment.

   - Monitor Azure Security Center recommendations and implement necessary security improvements.

   - Regularly review and update your Azure AD security controls, policies, and procedures to adapt to emerging threats, industry standards, and regulatory requirements.

Certainly! Here's an expanded and elaborated checklist for developing and implementing security controls in Azure AD and AWS:


Checklist for Azure AD Security:

------------------------------------

| Step                                      | Status 

1 Identify Azure AD Assets                  

  - List all Azure AD resources and services being used, such as users, groups, applications, and roles.      

2 Perform a Risk Assessment                

   - Identify potential threats and vulnerabilities specific to Azure AD.                                     

   - Assess the impact and likelihood of each risk.                                                        

3 Define Security Objectives               

  - Clearly define and document the desired security objectives for Azure AD.                             

  - Ensure objectives align with organizational requirements and compliance standards.                      

4 Select Security Controls                  

   - Research and identify Azure AD-specific security controls provided by Microsoft.                        

  - Choose controls that address identified risks and align with security objectives.                        

5 Design Azure AD Security Architecture    

   - Plan the structure of Azure AD, including directory structure and role assignments.                    

   - Define secure connectivity options and network configurations.                                          

  - Establish data encryption strategies for Azure AD.                                                     

6 Implement Security Controls               

   - Enable multi-factor authentication (MFA) for Azure AD users.                                          

   - Configure strong password policies and password rotation requirements.                                

   - Implement Azure AD Privileged Identity Management (PIM) for access management.                        

   - Enable auditing and logging for Azure AD activities.                                                          

7 Provide User Training and Awareness              

   - Educate users about Azure AD security best practices and potential threats.                            

   - Train users on recognizing and reporting security incidents or suspicious activities.                          

7 Establish Incident Response Procedures    

  - Develop an incident response plan specific to Azure AD security incidents.                                    

  - Define roles and responsibilities for incident response team members.                                          

  - Establish communication protocols and reporting mechanisms for incidents.                                    

9 Implement Monitoring and Auditing                  

  - Enable Azure AD auditing and configure logs for monitoring and analysis.                                       

   - Set up alerts and notifications for suspicious activities or policy violations.                                

   - Integrate Azure AD logs with a centralized logging and monitoring system.                                     

10 Regular Assessment and Improvement             

   - Conduct regular security assessments and vulnerability scans for Azure AD.                                    

  - Stay informed about Azure AD security updates and best practices.                                            

  - Continuously review and update Azure AD security controls and policies.                                     

Remember that security is an ongoing process, and it's important to regularly evaluate and improve the security posture of your Azure AD environment to stay ahead of potential threats and ensure the protection of your organization's identity and access management infrastructure.

Finally here is an excellent blogpost by Mandiant for cloud platform compromise with multiple components that would require investigation

https://www.mandiant.com/resources/blog/cloud-bad-log-configurations


Explore Microsoft Bing Chat

 

Explore Microsoft Bing Chat is a new feature that allows business users to interact with Microsoft Bing in a conversational way. You can ask Microsoft Bing questions, get insights, create content, and more in natural language. Microsoft Bing responds with informative, intuitive, logical, and actionable responses to help you get things done faster and easier.   In this blog post, we'll show you how to use Discover chat on Microsoft Bing and how it can benefit your work.

 

 Here are some steps to get started: 

  • Go to https://www.bing.com and click  the chat icon in the lower right corner of the screen. 

  •  Select your preferred language and mode from the options.You can switch between Balanced, Creative, and Precision modes according to your needs and preferences. 

  • Type or speak your request or message to Microsoft Bing. 

  • You can use voice input by clicking  the microphone icon next to the text box. 

  • Microsoft Bing will respond with  relevant and engaging feedback, which can include web results, images, tables, lists, code blocks, LaTex expressions, and more. You can also see suggestions for the next user  at the bottom of the chat box.  

  • You can continue the conversation by following the suggestions or by typing or speaking your own request or message. You can also click on the link or reference in the Microsoft Bing response to explore more information.

 

 

 

 

 

Chat on Microsoft Bing is a feature that allows you to interact with Bing in a conversational way. You can ask questions, get information, and even generate content using natural language. Chat on Microsoft Bing has three main components:

- Chat: This is where you can type your messages and see Bing's responses. You can also switch between different modes, such as Balanced, Creative, and Precise, to get different types of responses from Bing.


- Compose: This is where you can use Bing's creativity and intelligence to help you write or improve your own content. You can ask Bing to generate poems, stories, code, summaries, lyrics, and more. You can also ask Bing to rewrite, optimize, or enhance your content.


- Insights: This is where you can see additional information and details related to your chat messages. You can see web search results, question answering results, advertisements, and suggestions for the next user turn.


Microsoft Bing chat discovery is designed to help you find answers, create content, and complete tasks naturally and intuitively. Whether you need to research a topic, write a report, create a presentation, or just have  fun, you can use the Explore chat on Microsoft Bing to boost your productivity and creativity. Try it  today and let us know what you think.

Recommendations for Mitigating BianLian Ransomware Group attack



To enhance your organization's cybersecurity posture and counter the activities of the BianLian Ransomware Group, we advise implementing the following mitigations. These measures align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and NIST (the National Institute of Standards and Technology). The CPGs outline a minimum set of practices and protections recommended for all organizations, based on existing cybersecurity frameworks and guidance that target common and impactful threats and tactics.


1. Reduce the risk of malicious actors using remote access tools by taking the following actions:

   - Conduct an audit of remote access tools on your network to identify authorized and currently used software.

   - Review logs to detect abnormal use of portable executable programs running remote access software.

   - Utilize security software capable of detecting instances where remote access software is loaded only in memory.

   - Allow authorized remote access solutions strictly from within your network, using approved methods like virtual private networks (VPNs) or virtual desktop interfaces (VDIs).

   - Block inbound and outbound connections on common remote access software ports and protocols at the network perimeter.

   - Implement application controls to manage and control the execution of software, including allowing only approved remote access programs.

   - Employ application allowlisting to prevent the installation and execution of unauthorized remote access software, including portable versions that evade traditional antivirus solutions.


For additional guidance, refer to the NSA Cybersecurity Information Sheet on enforcing signed software execution policies.


2. Strictly limit the use of Remote Desktop Protocol (RDP) and other remote desktop services. If RDP is necessary, adhere to best practices such as:

   - Conduct network audits to identify systems using RDP.

   - Close unused RDP ports.

   - Enforce account lockouts after a specified number of failed login attempts.

   - Implement phishing-resistant multifactor authentication (MFA).

   - Log RDP login attempts.

   - Disable command-line and scripting activities and permissions.

   - Restrict the use of PowerShell to specific users who manage the network or Windows operating systems.

   - Keep PowerShell updated to the latest version and uninstall older versions.

   - Enable enhanced PowerShell logging to capture valuable data for monitoring and incident response.


3. Review domain controllers, servers, workstations, and active directories to identify any new or unrecognized accounts. Audit user accounts with administrative privileges and configure access controls based on the principle of least privilege.


4. Reduce the risk of credential compromise by implementing the following measures:

   - Place domain admin accounts in the protected users' group to prevent local caching of password hashes.

   - Implement Credential Guard for Windows 10 and Server 2016, or enable Protected Process Light for Local Security Authority (LSA) on Windows Server 2012R2.

   - Avoid storing plaintext credentials in scripts.

   - Implement time-based access for admin-level accounts using methods like Just-in-Time (JIT) access provisioning.


In addition to the above recommendations, the FBI, CISA, and ACSC suggest the following mitigations to limit the adversarial use of system and network discovery techniques and reduce the impact and risk of ransomware or data extortion:


1. Develop and maintain a recovery plan that includes multiple copies of sensitive data and servers stored in physically separate, segmented, and secure locations. Maintain offline backups of data, following the 3-2-1 backup strategy (three copies, two media types, one off-site).


2. Ensure that all accounts with password logins comply with NIST standards for password policies. Use longer passwords, store passwords in hashed format using recognized password managers, add password user "salts" to shared login credentials, avoid password reuse, implement multiple failed login attempt account lockouts, disable password hints, and limit

Are you ready to break into the exciting and dynamic world of cybersecurity?





Are you ready to break into the exciting and dynamic world of cybersecurity? It's not just a job, it's a lifestyle that attracts a passionate and innovative community of professionals. If you're eager to join their ranks, follow these 10 steps to cheat your way to success!

1.Build a Strong Foundation - turbocharge your career with a comprehensive education in cybersecurity, available through a variety of programs like bootcamps, online courses, degrees, or certifications.

2. Master Technical Skills - impress potential employers by developing a wide range of technical proficiencies, including hardware, software, Windows/Linux, networking, vulnerability scanners, packet sniffers, Nmap, and other cutting-edge professional tools.

3.Network Like a Pro - build relationships with cybersecurity experts by joining local or online groups, meeting like-minded individuals, finding mentors, and learning from the best.

4.Gain Real-World Experience - demonstrate your value by volunteering your skills to help your community and participating in Capture the Flag events to gain hands-on experience.

5.Choose Your Specialty - customize your career path by specializing in a specific area of cybersecurity, such as offense, defense, GRC, sales, or other specialties.

6.Stay Ahead of the Curve - stay up-to-date with the latest cybersecurity trends, techniques, and tools by attending security conferences, reading blogs, and constantly improving your skillset.

7.Build Your Reputation - establish your professional presence online through social media, websites, blogs, podcasts, and other outlets. Give back to the cybersecurity community by sharing your knowledge and expertise.

8.Get Involved - gain exposure by participating in cybersecurity events and workshops, and volunteering to speak or teach whenever possible.

9.Stay Ethical - maintain a sterling reputation by always adhering to industry standards and best practices, and never attempting to breach security systems without permission.

10.Hone Your Soft Skills - sharpen your communication, problem-solving, and teamwork skills, which are essential to your success in the fast-paced world of cybersecurity.

By following these 10 steps, you'll be well on your way to building a successful and rewarding career in cybersecurity. Don't just dream about it – cheat your way to the top with these powerful tips and tricks!

Twitter Facebook Favorites More