🎉 Announcement! I've just signed with @WileyGlobal to publish my upcoming book. This book demystifies complex concepts and guides businesses in transforming security strategies into real-world solutions. Thanks to @stiennon and @jimminatel for their incredible support.
After delving into Dan Sullivan's insightful "The Gap and the Gain," I'm eager to explore how its principles, with a unique twist, can profoundly influence our approach to operationalising cybersecurity for enhanced effectiveness. linkedin.com/posts/hartjason…
Our latest @rapid7 analysis details CVE-2023-22515, "a critical privilege escalation vulnerability affecting on-premises instances of Confluence Server and Confluence Data Center" more details here: rapid7.com/blog/post/2023/10…#infosec#cybersecurity
In February 2023, a well-known initial access broker called “Bassterlord” was observed in XSS forums selling a guide on breaking into corporate networks. The guide, which included chapters on SSL VPN brute forcing, was being sold for $10,000 USD.
When several other forums started leaking information from the guide, Bassterlord posted on Twitter about shifting to a content rental model rather than selling the guide wholesale.
Rapid7 obtained a leaked copy of the manual and analyzed its content. Notably, the author claimed they had compromised 4,865 Cisco SSL VPN services and 9,870 Fortinet VPN services with the username/password combination test:test
Anonymised log entry where an attacker attempts a (failed) login to the ASA SSL VPN service. The analysis of log files across different incident response cases, frequently observed failed login attempts occurring within milliseconds of one another, pointing at automated attacks
ALT Read the full blog here: https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/
Today, I bring to your attention a compelling case that underscores the critical need for Operationalising Cybersecurity 🚀. The recent findings from @Rapid7's Managed Detection and Response (MDR) teams provide a poignant example.
rapid7.com/blog/post/2023/08…
We're pleased to share that Rapid7 CTO @Hart_Jason helped to secure @EM360Tech's Most Popular Podcast of Q2, 2023!
See why it reached breaking numbers with the EM360 audience here: r-7.co/3OlHZfb
🚨💻 Exciting news! Check out my latest Forbes article on "Maximizing Cybersecurity Impact with Protection Level Agreements" 🔒🔥 Learn how Protection Level Agreements (PLAs) can bolster your Cybersecurity defenses and reduce risks. Read it here hubs.li/Q01ZMpDN0