Blog
Open Source vs. Enterprise: Why Not All Exploits are Created Equal
By Pablo Zurro on Wed, 11/11/2020
A common tactic of attackers trying to breach an environment is to use an exploit against a known vulnerability in an application or device present in a targeted infrastructure. Exploiting a vulnerability can provide an attacker with privileges or capabilities they would not normally be granted. In order to provide insight into what threat actors might be able to do, pen testers also use exploits....
Video
3 Fundamental Pen Tests Every Organization Should Run
Tue, 11/10/2020
A penetration test is often referred to broadly as an evaluation of an organization’s cybersecurity through the uncovering and exploitation of security weaknesses. However, this doesn’t mean there is only one way to pen test. Since vulnerabilities can exist anywhere—operating systems, services and application flaws, improper configurations, or even risky end-user behavior—multiple types of pen...
Blog
Getting Inside the Mind of an Attacker Part 3: Internal Attacks on Active Directory
Thu, 10/22/2020
Authored by: Julio Sanchez
In part 2 of this series, we examined a penetration testing engagement that the Core Security Services team performed, simulating an external attacker with no internal access finding entry using a password spray attack, eventually gaining control of Active Directory. Continuing our exploration of Active Directory attacks, we’ll share another scenario in order to further...
Video
Meeting Compliance Goals and Beyond: Virus Protection on IBM Systems
Thu, 10/22/2020
When it comes to cybersecurity, the old proverb “what you don’t know can’t hurt you” could not be further from the truth. Unfortunately, despite hosting mission-critical applications and data, IBM Systems like IBM i, AIX, LinuxPPC, and Linux on Z are often neglected and left unprotected. While these systems are beloved for their performance and reliability, none of them are immune to malware.
As...
Blog
What You Don’t Know About Access Management Is Hurting You
Tue, 10/20/2020
The impact of COVID-19 has been far-reaching across nearly every sector. Millions of employees now work remotely, making companies particularly vulnerable when it comes to external access risks. Many organizations lack a centralized process to manage user access to accounts and resources. They often have limited visibility into access levels users possess to data and systems within their network....
Video
What It Takes for Small and Mid-Sized Organizations to Steer Clear of Critical Access Risks
Tue, 10/13/2020
For small and mid-sized organizations, mitigating identity-related access risks may seem like a never-ending struggle they face on their own. They are tasked with supporting countless systems, networks, and applications with access to key data. They have limited staff, frequently rely on manual user provisioning and deprovisioning, and depend on decentralized processes for managing accounts...
Article
Low-level Reversing of SIGred (CVE-2020–1350)
Authored by: Ricardo Narvaja
Note: This work was originally done by Cristian Rubio and Ricardo Narvaja of Core Labs on Windows Server 2008 SP1 32 and 64-bit. There are not many differences in other versions of Windows.
While the basis of the SIGred bug is quite simple, it’s critical to explore exactly how this vulnerability can exploited.
All of our work was based on the Checkpoint blogpost and...
Case Study
From Surviving to Thriving: How a Large Healthcare Organization Established a Comprehensive Identity and Access Management Approach
Overview
Healthcare organizations today face extraordinary challenges in a dynamic, complex landscape. During the last two decades, the healthcare industry has seen increasing regulations, an acceleration of technology and workforce growth, acquisitions and consolidation, and the pressure to increase operational efficiencies and decrease overall costs, while meeting growing patient demands....
Blog
Five Major Drivers of IGA and PAM for Financial Services Organizations Today
Fri, 09/25/2020
Financial services information security continues to be a top priority across the entire financial sector—and for good reason. The Verizon Data Breach Investigations Report found that financial profit or gain was the primary motivation in 71 percent of all information security incidents, making financial services organizations a prime target for attack.
According to the Bitglass’ Financial Breach...
Video
The COVID-19 Impact: 6 Critical Access Risks to Watch Out For with a Remote Workforce
Thu, 09/24/2020
The impact of COVID-19 has been far-reaching across nearly every sector. Millions of knowledge workers now work remotely, making companies particularly vulnerable when it comes to external access risks. Many organizations lack a centralized process to manage user access to accounts and resources. They often have limited visibility into access levels users possess to data and systems within their...
Blog
Three Ways Enterprise-Grade Identity Governance Now Works for Small and Mid-Sized Organizations
Wed, 09/23/2020
For small and mid-sized organizations, mitigating identity-related access risks may seem like a never-ending struggle they face on their own. Tasked with supporting countless systems, networks, and applications with access to key data, they frequently have limited staff and rely on manual user provisioning and deprovisioning. They may depend on decentralized processes for managing accounts...
Blog
Getting Inside the Mind of an Attacker Part 2: External Attacks on Active Directory
Tue, 09/22/2020
Authored by: Julio Sanchez
In part 1 of this series, we explored what makes Active Directory so appealing to threat actors, and how attacks can severely harm an organization. For the remainder of the series, we’ll walk through several examples taken from penetration testing engagements the Core Security Services team has performed to explore ways attackers may target Active Directory, and discuss...
Article
Are your Domain Controllers Protected from CVE-2020-1472 Zerologon Attacks?
What You Need to Know About Netlogon and Zerologon
On September 11th, 2020, researchers at Secura published information on a critical vulnerability in Microsoft’s Netlogon authentication process which they dubbed “Zerologon." It is a cryptographic flaw that has a clear path to full takeover of an Active Directory domain.
The vulnerability allows an attacker to reset the machine account password of...
Blog
The Intersection of RPA and IGA: Why Automation and Identity Governance Go Hand-in-Hand
Wed, 09/16/2020
The rise of robotic process automation (RPA) during the last several years has enabled organizations to adopt new technologies that drive efficiencies across their business. RPA solutions leverage software robots that communicate with business systems and applications to streamline processes and reduce the burden on employees for completing mundane, repetitive tasks. Embracing new technologies...
Blog
3 Reasons Every Organization Should Leverage Third-Party Pen Testers
Tue, 09/15/2020
Penetration testing, also known as a pen test, is a security exercise that reveals an organization’s security vulnerabilities through a defined testing process. A penetration test may focus on networks, applications, physical facilities, individuals, and more. As cybersecurity breaches continue to plague organizations, compliance mandates are expanding, more organizations are attempting to deploy...
Blog
Perspectives on the Changing Linux Ecosystem
Thu, 09/10/2020
In the early 1990s the Open Software Foundation formed a committee to select and standardize a new Management Platform Toolset for and from the UNIX ecosystem. After much soul searching over a few months the OSF Management Platform never arrived. One of the committee, from the team that invented The Newcastle Connection (1980s *NIX history, go Google it) made a compelling presentation explaining...
Blog
The Six Ws of Granular Access Control
Thu, 09/10/2020
Learn how to protect your organization with PAM
Blog
Three Signs You’ve Outgrown Password Vault
Thu, 09/10/2020
Have you outgrown your password vault?
Blog
Navigating Toward a Password-Free Future with Privileged Access Management
Thu, 09/10/2020
Ready to move beyond passwords and embrace the future?