Information Security Buzz
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Top Posts
Iran Nuclear Facility Potential Cyber Attack – What...
Industry Leaders On Android.Joker Malware
Expert Reaction On Pulse Secure VPN Users Can’t...
New Vulnerabilities Put Millions Of IoT Devices At...
Expert Comment On Darktrace Set For IPO
Fake App Attacks On The Rise, As Malware...
Expert On Study That Brits Using Pets’ Names...
Expert Reaction On Europol Publishes Its Serious And...
Fake Netflix App Allows Hackers to Hijack WhatsApp
Hackers Pretend To Be Your Friend In The...
Information Security Buzz
Connecting Security Experts
  • HOME
  • Domains
    • Data Breach
    • Malware
    • Application Security
    • IoT
    • Cloud Security
    • Privacy
  • InfoSec Deals
  • Companies
  • Security Experts
  • ISB Conference 2021
  • Register
  • Log In
Expert(s): November 30, 2020
Andy Norton
uropean Cyber Risk Officer feature_status*/ ?>
Armis

Comments Dotted : 1
April 07, 2021

Expert Commentary On CISA Warns Of APTs Exploiting Fortinet Vulnerabilities

There are strong and robust practises in place within the NHS.

This is a major challenge to organisations as there is a never ending stream of vulnerable devices that need immediate patching to mitigate the threat of serious negative consequences. It’s a perpetual fire drill for organisations - not only taking time to ensure the devices are patched correctly, but more so, not knowing if and where they have these devices in the first place. There has been huge emphasis on SSL VPN solutions enabling us all to work during the pandemic, and many business

.....Read More

This is a major challenge to organisations as there is a never ending stream of vulnerable devices that need immediate patching to mitigate the threat of serious negative consequences. It’s a perpetual fire drill for organisations - not only taking time to ensure the devices are patched correctly, but more so, not knowing if and where they have these devices in the first place. There has been huge emphasis on SSL VPN solutions enabling us all to work during the pandemic, and many business units and departments have sourced VPN solutions at speed, and often outside of the normal IT procurement process.

 

Therefore, fixing the possibility of actively attempted unauthorised access to their networks, from a trivially exploitable hole, will be a priority. In addition to patching the FortiOS devices, it will be important to compare the patterns of behaviours of the devices themselves to highlight any changes in behaviour over time. Similarly, organisations should compare each device against other Fortinet devices to spot deviations from a profile of expected behaviours, that will act as an indicator to the possibility that an attack may of occurred.

 

With VPNs a commonly abused entry point for attackers - and Fortinet having an existing partnership with the NHS - we can probably expect to see an NHS Cyber Alert in the coming hours and days. There are strong and robust practises in place within the NHS. The common issue we see is not the lack of ability or speed to patch, it is in finding the devices in the first place from what is often a forgotten piece of the puzzle, the asset inventory. It is these forgotten or unknown devices that will be the major source of concern.

  Read Less
Like(0)  (0)

Linkedin Message

@Andy Norton, uropean Cyber Risk Officer , provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"There are strong and robust practises in place within the NHS...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-commentary-on-cisa-warns-of-apts-exploiting-fortinet-vulnerabilities

Copy this message and share on your Linkedin profile. Thanks!

Facebook Message

@Andy Norton, uropean Cyber Risk Officer , provides expert commentary for "dot your expert comments" at @Information Security Buzz.
"There are strong and robust practises in place within the NHS...."
#infosec #cybersecurity #isdots
https://informationsecuritybuzz.com/expert-comments/expert-commentary-on-cisa-warns-of-apts-exploiting-fortinet-vulnerabilities

Copy this message and share on your Facebook profile. Thanks!
    No Comments Yet ....
Please login to comment.

SECURELY DOTTED BY

Steve Forbes, Government Cyber Security Expert, Nominet States

"It is vital that governments pay close attention to the resilience of their critical infrastructures. "

Iran Nuclear Facility Potential Cyber Attack – What Expert Says

Saryu Nayyar, CEO, Gurucul

"The good news is that it appears the only damage is financial, and likely temporary. "

Industry Leaders On Android.Joker Malware

Eddie Glenn, Senior Product Manager, Venafi

"These timestamps indicate that the code signing certificate was valid at the time it was used to sign the code. "

Expert Reaction On Pulse Secure VPN Users Can’t Login Due To Certificate Related Outage

Jake Moore, Cybersecurity Specialist, ESET

"IoT remains a huge burden on potential victims, but the industry is slowly catching up. "

New Vulnerabilities Put Millions Of IoT Devices At Risk

Sri Sundaralingam, VP of Security and Cloud Solutions, ExtraHop

"The growth of the NDR category underscores the unique value that the network vantage point can provide for security teams. "

Expert Comment On Darktrace Set For IPO

Doug Davis, Senior Product Manager, Semperis

"Hybrid Identity Management Requires Critical Security Adjustments "

Experts Comments On Identity Management Day – Tuesday 13th April

Alan Grau, VP of IoT , Sectigo

"Attackers dupe individuals through a number of methods. "

Fake App Attacks On The Rise, As Malware Hides In Plain Sight

David Emm, Principal Security Researcher , Kaspersky

"Our passwords are the gateway to a plethora of valuable personal data that should never be openly shared. "

Expert On Study That Brits Using Pets’ Names As Online Passwords

Colin Truran, Senior Risk, Compliance and Governance Advisor , Quest

"Many of us recognise this problem, but as human beings we will continue to opt for easy passwords. "

Expert On Study That Brits Using Pets’ Names As Online Passwords

Ian Pitt, CIO, LogMeIn

"Online security risks have risen substantially over the past year. "

Expert On Study That Brits Using Pets’ Names As Online Passwords

Ilia Kolochenko, CEO, ImmuniWeb

"It is likewise a myth that governments cannot control cryptocurrencies. "

Expert Reaction On Europol Publishes Its Serious And Organised Crime Threat Assessment 2021

Jake Moore, Cybersecurity Specialist, ESET

"Being able to send rogue messages from another app installed on a device is impressive and extremely dangerous. "

Fake Netflix App Allows Hackers to Hijack WhatsApp

Burak Agca, Security Engineer, Lookout

"It is imperative that individuals and organisations keep their mobile operating systems and apps up to date. "

Hackers Pretend To Be Your Friend In The Latest WhatsApp Scam.

Adenike Cosgrove, Cyber Security Strategist, International, Proofpoint

"A password’s complexity is irrelevant if people use the same password for everything. "

Millions Of Brits Still Using Pet’s Names As Passwords Despite Risk

Richard Blech, Founder & CEO, XSOC CORP

"The LI capability was co-opted and exploited by one or more malicious actors. "

Advertised Sites May Appear Genuine On First Glance

WORKING WITH US

About Us

Advertise With Us

Information Security Companies

Contact Us

ISB CONFERENCE

ISB Conference 2021

THE PAGES

Privacy Policy

Terms & Conditions

RSS Feeds

INFORMATION SECURITY EXPERTS

Information Security Experts: Comments Dotted

Register and Comments

Categories

  • Facebook
  • Twitter

Copyright © 2020 ISBuzz Pty Ltd is a company registered in Australia with company number 605 203 772 whose registered office is 14 Alanvale Street, Harrison, ACT 2914.


Back To Top
Information Security Buzz
  • Home
  • Experts Comments on News
  • Security Articles
  • Vendor News
  • Study & Research
  • ISBuzz Expert Panel