Updated: Kubernetes Hardening Guide

Updated: Kubernetes Hardening Guide https://ift.tt/2KrcxLg Original release date: March 15, 2022 The National Security Agency (NSA) and CISA have updated their joint Cybersecurity Technical Report (CTR): Kubernetes Hardening Guide, originally released in August 2021, based on valuable feedback and inputs from the cybersecurity community.  Kubernetes is an open-source system that automates deployment, scaling, and management […]

CaddyWiper: New wiper malware discovered in Ukraine

CaddyWiper: New wiper malware discovered in Ukraine https://ift.tt/zFySCr4 This is the third time in as many weeks that ESET researchers have spotted previously unknown data wiping malware taking aim at Ukrainian organizations ESET researchers have uncovered yet another destructive data wiper that was used in attacks against organizations in Ukraine. Dubbed CaddyWiper by ESET analysts, […]

‘Dirty Pipe’ Linux Flaw Affects a Wide Range of QNAP NAS Devices

‘Dirty Pipe’ Linux Flaw Affects a Wide Range of QNAP NAS Devices https://ift.tt/FalWtG9 Network-attached storage (NAS) appliance maker QNAP on Monday warned of a recently disclosed Linux vulnerability affecting its devices that could be abused to elevate privileges and gain control of affected systems. “A local privilege escalation vulnerability, also known as ‘Dirty Pipe,’ has […]

@RockyPabillore As aways it depends… normally@we also choose to wipe and enroll the device with autopilot… but sometimes its difficult… https://t.co/L6KrzMPv3J. Of course you must make sure there arent any enrollment restrictions :)

@RockyPabillore As aways it depends… normally@we also choose to wipe and enroll the device with autopilot… but sometimes its difficult… https://t.co/L6KrzMPv3J. Of course you must make sure there arent any enrollment restrictions 🙂 from Mister_MDM twit https://twitter.com/Mister_MDM/status/1503461722912436225

CVE-2022-26503

CVE-2022-26503 https://ift.tt/rxuMTK4 CVE-2022-26503 KB ID: 4289 Product: Veeam Agent for Microsoft Windows | 2.0 | 2.1 | 2.2 | 3.0.2 | 4.0 | 5.0 Published: 2022-03-12 Last Modified: 2022-03-12 Challenge Vulnerability (CVE-2022-26503) in Veeam Agent for Microsoft Windows allows local privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code with LOCAL SYSTEM privileges. […]

CVE-2022-26500 | CVE-2022-26501

CVE-2022-26500 | CVE-2022-26501 https://ift.tt/uyJM8oh CVE-2022-26500 | CVE-2022-26501 KB ID: 4288 Product: Veeam Backup & Replication | 9.5 | 10 | 11 Published: 2022-03-12 Last Modified: 2022-03-12 Challenge Multiple vulnerabilities (CVE-2022-26500, CVE-2022-26501) in Veeam Backup & Replication allow executing malicious code remotely without authentication. This may lead to gaining control over the target system. Severity: critical […]