Connect with us
CCW 2024

Cyber Security

Sophos Partners with Tenable to Launch New Sophos Managed Risk Service

Published

on

Sophos has announced a strategic partnership with Tenable, to provide Sophos Managed Risk, a worldwide vulnerability and attack surface management service. The new service features a dedicated Sophos team that leverages Tenable’s exposure management technology and collaborates with the security operations experts from Sophos Managed Detection and Response (MDR) to provide attack surface visibility, continuous risk monitoring, vulnerability prioritization, investigation, and proactive notification designed to prevent cyberattacks.

The modern attack surface has expanded beyond traditional on-premises IT boundaries, with organizations operating frequently unknown numbers of external and internet-facing assets that are unpatched or under-protected, leaving them vulnerable to cyberattackers. This is evident in the newest Sophos Active Adversary Report, which identifies three tasks that organisations must prioritize to minimize the risk of brazen intrusions that lead to ransomware or other types of attacks. These include closing exposed Remote Desktop Protocol (RDP) access, enabling multi-factor authorization and patching vulnerable servers, all of which were top entry points in breaches handled by Sophos Incident Response in 2023. The Sophos Managed Risk service can assess an organization’s external attack surface, prioritize the riskiest exposures, such as open RDP, and provide tailored remediation guidance to help eliminate blind spots and stay ahead of potentially devastating attacks.

“Sophos and Tenable are two industry security leaders coming together to address urgent, pervasive security challenges that organizations continuously struggle to control. We can now help organisations identify and prioritize the remediation of vulnerabilities in external assets, devices and software that are often overlooked. Organisations must manage these exposure risks, because unattended, they only lead to more costly and time-consuming issues and are often the root causes of significant breaches,” said Rob Harrison, senior vice president for endpoint and security operations product management at Sophos. “We know from Sophos’ worldwide survey data that 32% of ransomware attacks start with an unpatched vulnerability and that these attacks are the most expensive to remediate. The ideal security layers to prevent these issues include an active approach to improving security postures by minimizing the chances of a breach with Sophos Managed Risk, Sophos Endpoint, and 24×7 Sophos MDR coverage.”

“While the latest zero-day may dominate the headlines, the biggest threat to organizations, by a large margin, is still known vulnerabilities – or vulnerabilities for which patches are readily available,” said Greg Goetz, vice president of global strategic partners and MSSP, Tenable. “A winning approach includes risk-based prioritization with context-driven analytics to proactively address exposures before they become a problem. Sophos Managed Risk, powered by the Tenable One Exposure Management Platform, delivers outsourced preventive risk management, enabling organizations to anticipate attacks and reduce cyber risk.”

Sophos Managed Risk is available as an extended service with Sophos MDR, which already protects more than 21,000 organizations globally. The Sophos Managed Risk team is Tenable-certified and works closely with Sophos MDR to share essential information about zero-days, known vulnerabilities and exposure risks to assess and investigate possibly exploited environments.

“Organizations benefit through regular interaction, including scheduled meetings with Sophos experts to review recent discoveries, insights into the current threat landscape, and recommendations for remediation and prioritizing actions. Additionally, organizations can initiate inquiries via the Sophos Central platform, allowing users to directly engage with the Sophos Managed Risk team for tailored support, and reports and to review their latest prioritized alerts,” the company said.

Sophos Managed Risk is available with a term license through Sophos’ global network of channel partners and Managed Service Providers (MSPs). A Sophos MSP Flex version will be available in 2024.

Cyber Security

Data Stealers Are Hunting for User Credentials, Says Kaspersky

Published

on

As the malware development market continues to flourish with new stealers such as Lumma, for the last three years Redline still remains the dominant data-stealing malware used by cybercriminals. More than half of every device (55%) targeted by password-stealer attacks in 2023 has been infected with the Redline malware, Kaspersky Digital Footprint Intelligence finds.

Infostealers infiltrate devices to illicitly obtain sensitive credentials such as logins and passwords, which are then peddled on the shadow market, posing significant cybersecurity threats to personal and corporate systems. According to information gleaned from log files traded or distributed freely on the dark web, Redline was used in 51% of infostealer infections from 2020 to 2023. Other notable malware families included Vidar (17%) and Raccoon (nearly 12%). In total, around 100 distinct infostealer types were identified by Kaspersky Digital Footprint Intelligence between 2020 and 2023 using metadata from log files.

The underground market for data-stealing malware development is expanding, evident from the rising popularity of new stealers. Between 2021 and 2023, the portion of infections caused by new stealers grew from 4% to 28%. Specifically, in 2023, the new “Lumma” stealer alone was responsible for more than 6% of all infections.

“Lumma emerged in 2022 and gained popularity in 2023, through a Malware-as-a-Service (MaaS) distribution model. This means any criminal, even those without advanced technical skills, can purchase a subscription for a pre-made malicious solution and use this stealer to carry out cyberattacks. Lumma is primarily designed for stealing credentials and other information from cryptocurrency wallets, commonly spread through email, YouTube, and Discord spam campaigns,” said Sergey Shcherbel, an expert at Kaspersky Digital Footprint Intelligence.

To guard against data-stealing malware, individuals are advised to use a comprehensive security solution for any device. This will help prevent infections and alert them to dangers, such as suspicious sites or phishing emails that can be an initial vector for infection. Companies can help their users, employees and partners protect themselves from the threat by proactively monitoring leaks and prompting users to change leaked passwords immediately.

Continue Reading

Channel Talk

AmiViz Joins Signs Up with Abstract Security

Published

on

AmiViz has forged a partnership with Abstract Security, a cyber threat operations platform offering a revolutionary approach to security analytics that allows organisations to improve efficiency, reduce SIEM-related storage costs, and enhance detection and response capabilities across multi-cloud and on-premise environments. The Abstract platform disrupts traditional cybersecurity analytics with its innovative approach, challenging the limitations of conventional Security Analytics systems. Abstract Security offers a transformative cyber threat operations platform in an era marked by compliance-induced data swamps and redundant data storage.

“Engineered to streamline security analytics, it enhances detection and response capabilities across diverse IT environments, including multi-cloud and on-premise setups. By integrating tactical artificial intelligence (AI), Abstract empowers security analysts to decode complex cloud security data, improving detection strategies and filling visibility gaps. Pioneering initiatives like the decentralized edge computing platform and a one-click data lake further solidify Abstract Security’s position as a visionary player in cybersecurity,” the company said.

“The strategic expansion into Middle Eastern markets aligns with the region’s growing demand for advanced cybersecurity measures. With rapid digital transformation and increased cyber threats, the Middle East presents a significant opportunity for Abstract Security. Government investments in cybersecurity infrastructure and the adoption of IoT technologies amplify the demand for efficient, AI-driven security solutions,” the company added.

Ilyas Mohammed, COO at AmiViz, said, “Our partnership with Abstract Security heralds a new era in cybersecurity analytics. By leveraging their innovative solutions, we empower our clients with proactive threat management capabilities that surpass traditional systems. Together, we redefine industry standards, ensuring robust protection against evolving cyber threats and bolstering our position as leaders in the cybersecurity landscape.”

Richard Betts, Vice President of International Business at Abstract Security, commented on the strategic alliance, stating, ‘Our collaboration with AmiViz in the Middle East is more than a partnership; it’s a synergy of strengths. This venture not only amplifies our presence in a region but also marks a significant step in our journey to broaden Abstract Security’s international reach.

The companies claimed that the solutions are tailored for large enterprises in critical sectors like finance, oil and gas, telecommunications, MSSP and government, to address unique cyber threats. Abstract Security said it aims to integrate its solutions in local markets deeply through a channel-focused distribution strategy, empowering channel partners and addressing evolving security needs. The company added that it has partnered with AmiViz to provide comprehensive support, including technical training, marketing assistance, and dedicated account management, further strengthening Abstract Security’s position in the GCC markets.

Abstract Security’s partnership with AmiViz allows Middle Eastern channel partners to revolutionize security analytics, transcending traditional SIEM systems and compliance burdens. Together, they set a new standard for cybersecurity analytics, paving the way for proactive and predictive security measures. This partnership aims to position the Middle East as a cybersecurity stronghold, contributing to its global leadership in cybersecurity.

Continue Reading

Cyber Security

Check Point Software Technologies to Participate at GISEC 2024

Published

on

Check Point Software Technologies has announced its participation at the Gulf Information Security Expo & Conference (GISEC) 2024, scheduled from April 23rd to April 25th, 2024, at the Dubai World Trade Centre. As cyber threats continue to evolve rapidly, the need for advanced cybersecurity solutions has never been more pressing. With the United Arab Emirates experiencing an average of 1,207 cyberattacks per organization each week over the last six months—surpassing the global average—Check Point Software is set to showcase its flagship Check Point Infinity Platform at GISEC 2024.

This platform, which is at the forefront of AI-powered, cloud-delivered cybersecurity, has been specifically designed to meet the modern challenges of an evolving threat landscape, providing comprehensive protection, consolidated operations, and collaborative communication capabilities. Visitors can explore these solutions at booth #C39 in Hall 7, where the following highlights will be featured:

  1. Check Point Infinity Playblocks: Automatically triggers preventive actions upon detecting an attack, swiftly containing threats through a consolidated, cloud-based security platform.
  2. Check Point Infinity AI Copilot: Enhances the efficiency of security teams by leveraging AI to automate complex tasks and deliver proactive security solutions.
  3. Check Point UAE Infinity Portal: Tailored to meet the needs of organizations of all sizes while fully adhering to the UAE’s data privacy regulations.

Ram Narayanan, Country Manager at Check Point Software Technologies Middle East, commented, “Our participation at GISEC 2024 underscores our commitment to bolstering cybersecurity defences in the region. The Check Point Infinity Platform, with its AI-powered threat prevention and cloud-delivered threat intelligence, is critical for organizations needing robust solutions to protect their assets. We look forward to engaging with customers and partners to discuss how these innovations can enhance cybersecurity resilience.”

Additionally, at GISEC 2024, Check Point Software will focus on strengthening relationships with customers and partners. This commitment highlights the company’s ongoing effort to provide advanced cybersecurity solutions in the region. Check Point Software is eager to meet with attendees, discuss their security challenges, and explore how it can help organizations enhance their defences, prevent cyber-attacks, and protect their critical assets.

Continue Reading
Advertisement CCW 2024

Follow Us

Trending

Copyright © 2021 Security Review Magazine. Rysha Media LLC. All Rights Reserved.