+44 (0)203 88 020 88

Author name: secureteampstg

NatWest offers free security software to customers

NatWest Bank has partnered with Malwarebytes to provide endpoint protection software to NatWest customers.  Malwarebytes Premium edition will be available to download for free from within NatWest customer’s online banking portal.  NatWest is the only UK bank to provide premium virus protection to their customers according to Alasdair MacFarlane, Head of Fraud Prevention at NatWest. […]

NatWest offers free security software to customers Read More »

Ransomware claims drop dramatically after mandatory scans

An innovative American insurance company, Corvus, has reported a drop of 65% in ransomware claims after they started insisting on vulnerability scans of the client’s network before providing cyber-insurance. Lauren Winchester of Corvus states in a recent blog post: Our automated scan locates threats like unprotected RDP upon quoting for new business and we notify

Ransomware claims drop dramatically after mandatory scans Read More »

How Return-Oriented Programming exploits work

Return-Oriented Programming is a security exploit technique used by attackers to execute code on their target system.  By obtaining control of the call stack, the attacker can control the flow of existing trusted software running on the computer and manipulate it to their own ends.  New research published this month has demonstrated how SPECTRE style vulnerabilities

How Return-Oriented Programming exploits work Read More »

NCSC Publishes Vulnerability Disclosure Toolkit

The UK National Cyber-Security Centre has published a toolkit to help organisations setup a vulnerability disclosure programme. A vulnerability disclosure programme makes it easy for someone to provide your organisation with information if they notice a vulnerability that could impact your security.  Without such a programme in place, concerned clients or researchers have to resort

NCSC Publishes Vulnerability Disclosure Toolkit Read More »

September patch Tuesday fixes 23 Critical Microsoft Vulnerabilities

The September 2020 patch Tuesday contain fixes for 23 Critical vulnerabilities in Microsoft products and 129 fixes in total – including a Microsoft Exchange vulnerability that can allow remote code execution simply by sending a specially crafted email to the server. A large patch bundle is a double edged sword – it’s reassuring that the

September patch Tuesday fixes 23 Critical Microsoft Vulnerabilities Read More »

Pass-the-hash attack discovered in Windows Themes

A new vector for pass-the-hash attacks has been discovered targeting Windows 10 personalisation themes. A security researcher has published details of a potential issue with the design of Windows 10 themes that can be exploited to harvest Windows and Microsoft Account login credentials. A Windows 10 theme is a collection of customisation settings for Windows

Pass-the-hash attack discovered in Windows Themes Read More »

Scroll to Top