AttackIQ Blog

    Don’t treat cybersecurity hygiene like your car engine light

    October 21, 2021
    ESG has just released the key findings of its cybersecurity hygiene and posture management survey, and in a poll of 400 cybersecurity professionals in North American enterprises, the number one action respondents said would improve cybersecurity hygiene? You guessed it: continuous security control validation.
    Read More

    What To Do in the Case of Brand Reputation Impersonation

    October 15, 2021
    Recently, AttackIQ was notified that an Iranian threat actor had created a fake domain and fraudulent website (attackiq[.]ir) impersonating AttackIQ and abusing the company brand. This blog is an account of what happened and how AttackIQ responded, and it aims to provide insights to help organizations prepare to deal with similar Brand Reputation Abuse situations.
    Read More

    Our message to cybersecurity teams: We’ve got your six.

    October 6, 2021
    The rapid growth in our company isn’t just because we have the best platform for breach and attack simulation (we do). It’s because no other company is as invested as we are in helping you build a threat-informed defense practice that delivers measurable results.
    Read More

    “Zero Trust But Validate.” It’s not enough to deploy a zero trust architecture. You need to continuously validate that it works.

    October 4, 2021
    To echo a famous Russian proverb, “trust but verify,” it’s not enough to implement a zero trust architecture. Continuous testing is the only way to achieve real cybersecurity readiness.
    Read More

    Meet AttackIQ Vanguard: Helping security teams identify control gaps before the adversary does.

    September 30, 2021
    As organizations react to constantly changing and challenging situations today, they need to be confident they can still meet their business objectives while controlling risk.
    Read More

    DeepSurface Security Advisory: LPE in Firefox on Windows

    September 28, 2021
    Firefox is vulnerable to local privilege escalation (LPE) attacks under certain conditions on Windows platforms. This would allow an attacker to perform a local privilege escalation attack against Firefox users using the same Windows system. Through our responsible disclosure program Mozilla was contacted, and full technical details were provided, but has ultimately chosen not to fix this vulnerability.
    Read More
    Ransomware: Revealed

    Ransomware and Targeted Attacks in the Healthcare Sector

    September 23, 2021
    Although ransomware can have devastating effects regardless of which industry vertical an organisation is part of, the healthcare industry has particularly paid a heavy price in recent times.
    Read More

    Cloud platforms can stop adversaries. Here’s how. 

    September 22, 2021
    A landmark innovation from MITRE Engenuity’s Center for Threat-Informed Defense maps cloud security controls in AWS and Azure to MITRE ATT&CK®, elevating cybersecurity effectiveness.
    Read More

    DeepSurface Security Advisory: LPE in Adobe Reader on Windows

    September 16, 2021
    Older versions of Adobe Acrobat Reader are vulnerable to local privilege escalation (LPE) attacks under certain conditions on Windows platforms. This would allow an attacker to perform a local privilege escalation attack against Acrobat Reader users using the same Windows system. Through our responsible disclosure program Adobe was contacted and provided a fix for this issue. Adobe also issued CVE-2021-35982 to track the vulnerability.
    Read More

    Is Your Healthcare Organization Following These Four Ransomware Best Practices?

    August 24, 2021
    Healthcare is the most targeted sector for data breaches, and ransomware attacks were responsible for almost 50 percent of all healthcare data breaches in 2020. How should healthcare companies proceed? Our guest blogger in this ransomware series is Tracy Cohen, a cybersecurity expert with over a decade of experience managing cybersecurity risk in the healthcare and biopharma sector. She is also a licensed skydiver,
    Read More

    20,000 Strong for AttackIQ Academy. And It’s Just the Beginning.

    August 24, 2021
    With over 20,000 students in AttackIQ Academy, our mission is strong as ever to provide a free education on how to build and implement a threat informed defense.
    Read More
    Ransomware: Revealed

    Azure Security Stack Mappings: The Top Native Security Controls for Ransomware

    August 23, 2021
    For the first time, organisations can visually see what Azure security controls can offer in terms of protection, detection and response. With 45 native Azure security control mappings, defenders can start focusing on not only TTPs in the context of Azure threats, but also how each native Azure security control might shield them from related TTPs in Azure.
    Read More

    Standing Up for Our Principles: AttackIQ Signs the Respect In Security

    August 16, 2021
    Read More

    Teamwork Making the Dream Work!

    August 13, 2021
    Why I’m Particularly Proud AttackIQ Made the 2021 Fortune Great Place to Work List
    Read More

    DeepSurface 2.4

    August 13, 2021
    We’re excited to announce our latest version of the DeepSurface product – DeepSurface 2.4. The latest version of our vulnerability management platform expands our reporting capabilities to enable exportable reports to XLSX and PDF to make reporting your vulnerable hosts and missing patches even easier, added support for Thycotic Secret Server PAM, easier setup/administration including emailing of generated reports, and enhancements of our windows agent.
    Read More

    Healthcare Under Siege: Should Hospitals Pay Hackers Ransom?

    August 9, 2021
    In 2020, three of the top 10 most searched terms were, unsurprisingly, healthcare-related. (Coronavirus, coronavirus update, coronavirus symptoms.) We’ve never been so attuned to what’s happening in our healthcare systems and hospitals.
    Read More

    Purple Teaming for Cybersecurity Effectiveness: 10 Lessons

    July 29, 2021
    How do you improve your security posture by standing up a purple team strategy? Here are 10 important things to keep in mind from the Purple Teaming for Dummies eBook.
    Read More

    How purple team operations helped defend the Pentagon — and can help your security team today.

    July 16, 2021
    The purple team construct is changing cybersecurity for the better. Here is how you build, lead, and manage effective purple team operations.
    Read More

    The Kaseya VSA REvil Ransomware Supply Chain Attack: How It Happened, How It Could Have Been Avoided

    July 13, 2021
    On July 2, 2021, the REvil ransomware group successfully exploited a zero-day vulnerability in the on-premise Kaseya VSA server, enabling a wide-scale supply chain cyber attack. Let’s dig in and see how the attack happened, how attack emulation could have helped, and what you can do to implement a threat-informed defense strategy to prepare yourself for similar threat actor behavior.
    Read More

    How to Pitch Your CFO on Automated Security Control Validation

    July 9, 2021
    CFOs are often perceived as gatekeepers to the company’s cash coffers. With different functional leaders vying for project investments, it is true that the role of the CFO is to help prioritize the company’s spend, based on the business growth plan and trajectory.
    Read More

    DeepSurface Security Advisory: LPEs in Node.js on Windows (CVE-2021-22921)

    July 2, 2021
    Node.js is a popular back-end JavaScript runtime environment built on the V8 engine. As part of our internal security research, we discovered numerous products in production environments installed with insecure permissions. One of these products was Node.js, and we decided to investigate further.
    Read More

    Purple Hats 2021: It was an Event “Brimming” with Cybersecurity Goodness

    June 24, 2021
    This past week, AttackIQ launched its inaugural Purple Hats Conference—where more than 3,000 cybersecurity practitioners, partners, and pros joined to collaborate, share ideas, and learn how to evolve from a reactive to proactive threat informed defense strategy.
    Read More

    Put MITRE ATT&CK® to work through Workbench

    June 22, 2021
    For years, users struggled to put MITRE ATT&CK into practice. With the release of ATT&CK Workbench today, defenders can far better ensure that their threat intelligence is continually aligned with the public ATT&CK knowledge base. See how and why.
    Read More

    10 Ways to Apply the MITRE ATT&CK Framework in Your Cybersecurity Strategy

    June 22, 2021
    There are a number of ways that the MITRE ATT&CK framework can be used in your cybersecurity practice. Here are 10 of the most important as laid out in the MITRE ATT&CK for Dummies eBook.
    Read More