Showing posts with label f5. Show all posts
Showing posts with label f5. Show all posts

Friday, July 23, 2021

What is Mutual TLS (mTLS)?

Mutual Transport Layer Security (#mTLS) establishes an encrypted TLS connection in which both parties use X.509 digital certificates to authenticate and verify each other. MTLS can help mitigate the risk of moving services to the cloud, and prevent malicious third parties from imitating genuine apps. So, let’s start the clock for What is mTLS?

Read the Article on F5 Labs.

Not only does F5 Labs provide freely available Threat Intelligence, they also have an Educational series covering many types of attacks, threats, and essential security concepts. If you are getting started in cyber security or there’s always been that one topic you’ve never quite understood, #F5Labs will help you learn the basics.

Tuesday, June 29, 2021

Cyberattacks at Banks and Financial Services Organizations

As part of the 2021 Application Protection Report, we looked at the top reported security incidents to the #F5 SIRT for the years 2018 through 2020. Now we’re taking a deeper dive into the reported security incidents at financial organizations, sometimes referred to as #BFSI for banking, financial services, and insurance institutions. Peter Silva starts the clock for Cyberattacks at Banks and Financial Services Organizations. Read the Report!


DDoS Attack Trends for 2020

Distributed Denial-of-service, or #DDoS, is a persistent threat facing businesses of all types, regardless of geographic location or target market. DDoS tools are becoming easier to use, while the attacks themselves are becoming more complex—frequently combining many different methods in one assault. With attack data from the F5 Silverline Security Operations Center and incidents logged by the F5 Security Incident Response Team (SIRT), I start the clock to check out DDoS Attack Trends for #2020 and read the article.


2021 Application Protection Report: Of Ransom and Redemption

 Now in its 4th year, the #F5Labs 2021 Application Protection Report (https://www.f5.com/labs/articles/thre...) is our effort to boil the application security risk landscape down to put the initiative back into the hands of defenders. We analyzed more than 700 data breaches from 2020. Peter Silva starts the clock for an extended edition of some the highlights from F5Labs 2021 #APR in this episode of 90 Seconds of Security.

Get your copy of the 2021 APR


Credential Stuffing Tools and Techniques

Credential stuffing is a type of cyberattack that uses credentials obtained from previous breaches to take over accounts on other web or mobile applications. This type of brute force attack relies on the fact that many people use the same usernames and passwords on multiple sites. See how attackers use #OpenBullet​ to create a Credential Stuffing attack. Let's start the clock for #CredentialStuffing Tools and Techniques including #OpenBullet in this 90 Seconds of Security episode. And learn more at F5Labs.com


F5 SIRT’s Top Reported Security Incidents, 2018-2020

The F5 Security Incident Response Team helps customers tackle security incidents in real time. In 2020, we talked about what happened in the beginning of the pandemic based on #F5 #SIRT cases. Now we're looking back at all F5 SIRT cases from the beginning of 2018 to the end of 2020 and break down what changed and what didn’t in the cyberthreat landscape because of the pandemic. So, let’s start the clock to look at SIRT’s Top Reported Security Incidents, 2018-2020. Go to the full article


Thursday, March 4, 2021

Credential Stuffing: Why It’s Here to Stay

Over the last few years, #F5​ security researchers have identified credential​ stuffing​ as one of today’s foremost threats. The value of stolen credentials has created a vicious circle: organizations suffer network intrusions in pursuit of credentials, and credential stuffing in pursuit of profits. Understanding both the supply and demand sides of the market for stolen credentials is, therefore, key to understanding the risk that cybercriminals pose to organizations today. With 5 years of data, it is definitive: credential spills are here to stay. So, let’s start the clock for some harrowing data from the 2021 Credential Stuffing Report.

Get your copy: https://www.f5.com/labs/articles/threat-intelligence/2021-credential-stuffing-report


Key Trends from F5 State of Application Strategy Report

Get your copy: www.f5.com/stateofappstrategy

We all know how much the world has changed in the last year. And, the results of the most recent #F5​ State of Application Strategy survey make it clear, the pandemic has vastly accelerated a global digital transformation that was already underway. Progress that might normally have taken a decade has leapt forward in a single year—with respondents maturing in their journeys toward digital expansion. So let’s start the clock and take a look at the astonishing progress apparent through several key markers revealed in our seventh annual survey. #SOAS

Tuesday, January 26, 2021

How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder

 

Ransomware attacks have reached the boiling point. They’ve gone from nuisance to significant financial burden—as well as a mortal threat to critical infrastructure. Financial damage from ransomware attacks is in the hundreds of millions of dollars for some organizations. And, of course, our F5 Labs threat researchers have something to say about it. So, let’s start the clock to explore How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder. 

Full article: https://www.f5.com/labs/articles/threat-intelligence/ransomware-how-it-has-evolved-to-be-faster-stealthier-and-strike-harder

Saturday, December 26, 2020

Phishing During a Pandemic

 #F5Labs 2020 Phishing and Fraud Report. #Phishing remains a popular method of stealing credentials, committing fraud, and distributing malware. In its crudest forms it might appear to be juvenile; but it’s often part of a well-orchestrated, multi-faceted, and sustained attack campaign by organized crime groups. Get all the details of Phishing & Fraud trends for 2020: https://www.f5.com/labs/articles/threat-intelligence/2020-phishing-and-fraud-report


How Cyber Attacks Changed During the Pandemic

 #F5 SIRT reviewed all the reported security incidents from January through August 2020 to see how the pandemic changed the cyberthreat landscape. Hint: #DDoS attacks dominated the pandemic lockdown. Learn more: https://www.f5.com/labs/articles/threat-intelligence/how-cyber-attacks-changed-during-the-pandemic

So let’s start the clock to see How Cyber Attacks Changed During the #Pandemic.


Friday, November 6, 2020

Cloud Interconnection with F5 & Equinix

 Learn how the simplified Interconnection Oriented Architecture (IOA) from #F5 and #Equinix helps IT departments solve the need for mobile and dispersed user access to their cloud infrastructure(s) in a multi-cloud environment.

Learn more: https://www.f5.com/services/resources/use-cases/a-secure-equinix-gateway-to-the-cloud
This architecture allows for services to be deployed at the edge of, or next to the cloud resulting in Fewer hops, Dramatically lower latency, Fault-proof security & Lower Network transport costs - as much as 80% lower. This ‘edge’ architecture provides a natural point for traffic control by having centralized policy control and Security policy enforcement, access control and other services like DDoS protection, AAA and WAF.


Sunday, April 5, 2020

Connect to the F5 VPN with BIG-IP Edge Client

Your organization may have F5 BIG-IP APM for VPN access. See how you can connect to your org's VPN using the BIG-IP Edge Client along with Chrome, Microsoft Edge and Firefox browsers. How to authenticate, do MFA, check settings and what is split-tunneling. You can also get the F5 Access mobile app for iOS, Android and Windows Phone from the respective app stores.


 

ps

Remote Desktop Protocol (RDP) using an SSL VPN

Returning to the F5 DevCentral Lightboard, I explain why its a bad idea to expose RDP to the internet and how using a SSL VPN like BIG-IP APM is a much safer and better idea.



ps

Wednesday, March 4, 2020

90 Seconds of Security: What is Common Vulnerability Scoring System (CVSS)

CVSS is an open framework for communicating the characteristics and severity of software vulnerabilities. Learn how a vulnerability gets scored by using the Base, Temporal, and Environmental metric groups. #CVSS helps organizations determine what’s the risk and what vulnerability do I patch first?!? F5 SIRT (https://f5.com/sirt) can also help if you have exposed vulnerabilities being exploited.


90 Seconds of Security: What is Common Vulnerabilities & Exposures (CVE)

The Common Vulnerability & Exposures or CVE provides definitions for all publicly known cybersecurity vulnerabilities and exposures. Understand what happens when a potential security vulnerability or exposure is reported, how it’s assigned a CVE ID by a CVE Numbering Authority and how they describe vulnerabilities. And if you're under attack, contact F5 SIRT: f5.com/sirt


Wednesday, January 29, 2020

90 Seconds of Security: Tales from the Darknet

What happens to your data once it’s been compromised by a phishing attack or data breach? In this episode Peter Silva explores where your data goes and how much it is worth once it’s stolen in a data breach or phishing attack. If you're under attack, visit f5.com/sirt to get immediate help!




#f5Labs #90SecondsOfSecurity

Saturday, December 14, 2019

90 Seconds of Security: Phishing Trends for 2019

Phishing has become the number one attack vector for good reason - it requires a low amount of effort for a very high reward. 

F5 Labs (f5labs.com) released their 2019 Phishing and Fraud Report showing that there's no slowing down in the amount or number of phishing attacks. In fact, we expect phishing to occur year-round, not just around the holidays. Download the full report at: https://www.f5.com/labs/articles/threat-intelligence/2019-phishing-and-fraud-report


90 Seconds of Security: Breach Trends for 2019

F5 Labs Threat Intelligence team (f5labs.com) recently published their 2nd annual Application Protection Report and we take a look at some of the highlights. We cover PHP vulnerabilities, Formjacking, magecart attacks, and the relationship between breach causes and industry sectors. Get your copy at F5Labs.com

 

Friday, December 13, 2019

F5 Cloud Services Early Access Program

F5's Cloud Services Team is excited to share an opportunity for customers test two new technologies! Essential App Protect is an instant, out-of-the-box protection from common web exploits, malicious IPs and coordinated attack types. Bot Protect is a bot management SaaS solution that identifies bots’ intent and prevents attacks, while maintaining access for the good bots that help your business.

Visit: https://www.f5.com/preview to help shape our roadmap and influence feature development!