Massive Infection through 0-day in the Zimbra Email suite

Massive Infection through 0-day in the Zimbra Email suite

Incident Overview On October 7, the email server of a big commercial pharma organization was attacked. It was running Zimbra 8.x version on CentOS and got quickly compromised. Malicious actor exploited Internet-facing Zimbra Collaboration Suite using CVE-2022-41352...
Russian APT vs CrowdStrike + MDR + Zimbra

Russian APT vs CrowdStrike + MDR + Zimbra

Why This Is Important Ukrainian cyberwar has become a great platform where the US government and commercial sectors can learn the best protective measures.  Since the Russian-Ukrainian war broke out, Russian hackers have been focusing their attention and cyber...
Russian Сybercriminals Spreading New Tricky Phishing Emails

Russian Сybercriminals Spreading New Tricky Phishing Emails

On April 4, 2022, the government emergency response team of Ukraine CERT-UA has warned of a massive spear-phishing campaign launched by a hacking group UAC-0010 (Armageddon), which is linked to the FSB. It has been informed, that UAC-0010 disseminates malicious emails...
Splunk ES vs. Elastic (ELK) Stack

Splunk ES vs. Elastic (ELK) Stack

The modern digital and globalized world contributes to the fact that sooner or later, each business will meet Security information and event management systems (SIEM) or some individual elements of systems of this class. Let’s try to understand what it is...
Log4Shell: How to Mitigate Log4j Vulnerability

Log4Shell: How to Mitigate Log4j Vulnerability

In the end of 2021, the whole digital world has suffered the new cybersecurity flaw named Log4Shell. A new vulnerability is considered to be one of the worst that have been discovered during the last years. It scored 10 out of 10 points on the CVSS vulnerability...