Newsletter

Networking Monitoring News – June 2016

Network Segmentation

As we build out our networks, we should start thinking about how to properly segment users and assets. Segmenting networks has been best practice for a long time now, but is rarely implemented. With the new normal of malware, we can greatly reduce our attack surface by limiting exposure to our critical systems. This also allows us to focus monitoring efforts where they will be most effective.

Flat networks are simple and have little management overhead, but this comes at a cost. Flat networks offer little protection as well.

Lenovo

The Lenovo Accelerator Application software package which is meant to speed up the launch of some Lenovo applications, has been found to be vulnerable to a man in the middle attack. The vulnerability lies within the “update mechanism where a Lenovo server is queried to identify if application updates are available.” Lenovo recommends removing this software immediately.

The full list of machines that are impacted is vast but include Lenovo Notebook 305, Edge 15, Flex2 Pro and Yoga product lines. Additionally, IdeaCenter and Yoga Home 500 are amongst the 39 desktop models impacted.

A full list of machines can be found here:

Lenovo Support

Microsoft

A Microsoft Windows zero-day exploit has hit the market with a $90,000 price tag. This unpatched vulnerability is being sold with claims that it works against all versions of Windows from Windows 2000 to the current Windows 10 OS. The purchase gets you all the source code and two proof of concept videos that show the exploit working. There is big money in malware, from finding the exploits on down to using them. Let ContentCatcher NSM help protect your network.

Ron Samson

Share
Published by
Ron Samson

Recent Posts

EDR Alert Fatigue: Which Endpoint Alerts Need Human Investigation and Which Need Better Tuning

Cut EDR alert fatigue without creating blind spots. Learn to prioritize high-risk signals, automate enrichment,…

3 days ago

Third-Party Vendor Access Security: How to Monitor Remote Support Accounts and Reduce Supply Chain Risk

Secure third-party remote access with MFA, accountable owners and complete visibility—critical as vendors feature in…

57 years ago

PCI DSS 4.0.1 Security Monitoring: What Merchants Must Operationalize Beyond Annual Compliance

Turn PCI DSS 4.0.1 monitoring into faster payment threat response—master Requirements 10, 11 and 12,…

57 years ago

OT Security Monitoring for Manufacturers: How to Protect Plant Networks Without Disrupting Production

Protect plant uptime with passive OT security monitoring. Map legacy assets, baseline traffic, and detect…

57 years ago

Business Email Compromise Response: The First 24 Hours After a Microsoft 365 Account Takeover

Contain a Microsoft 365 BEC in 24 hours: revoke sessions, preserve evidence, stop payment fraud,…

57 years ago