Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, December 26, 2020

How Cyber Attacks Changed During the Pandemic

 #F5 SIRT reviewed all the reported security incidents from January through August 2020 to see how the pandemic changed the cyberthreat landscape. Hint: #DDoS attacks dominated the pandemic lockdown. Learn more: https://www.f5.com/labs/articles/threat-intelligence/how-cyber-attacks-changed-during-the-pandemic

So let’s start the clock to see How Cyber Attacks Changed During the #Pandemic.


Wednesday, March 4, 2020

90 Seconds of Security: What is Common Vulnerability Scoring System (CVSS)

CVSS is an open framework for communicating the characteristics and severity of software vulnerabilities. Learn how a vulnerability gets scored by using the Base, Temporal, and Environmental metric groups. #CVSS helps organizations determine what’s the risk and what vulnerability do I patch first?!? F5 SIRT (https://f5.com/sirt) can also help if you have exposed vulnerabilities being exploited.


90 Seconds of Security: What is Common Vulnerabilities & Exposures (CVE)

The Common Vulnerability & Exposures or CVE provides definitions for all publicly known cybersecurity vulnerabilities and exposures. Understand what happens when a potential security vulnerability or exposure is reported, how it’s assigned a CVE ID by a CVE Numbering Authority and how they describe vulnerabilities. And if you're under attack, contact F5 SIRT: f5.com/sirt


Saturday, December 14, 2019

90 Seconds of Security: Phishing Trends for 2019

Phishing has become the number one attack vector for good reason - it requires a low amount of effort for a very high reward. 

F5 Labs (f5labs.com) released their 2019 Phishing and Fraud Report showing that there's no slowing down in the amount or number of phishing attacks. In fact, we expect phishing to occur year-round, not just around the holidays. Download the full report at: https://www.f5.com/labs/articles/threat-intelligence/2019-phishing-and-fraud-report


Friday, December 13, 2019

F5 Cloud Services Early Access Program

F5's Cloud Services Team is excited to share an opportunity for customers test two new technologies! Essential App Protect is an instant, out-of-the-box protection from common web exploits, malicious IPs and coordinated attack types. Bot Protect is a bot management SaaS solution that identifies bots’ intent and prevents attacks, while maintaining access for the good bots that help your business.

Visit: https://www.f5.com/preview to help shape our roadmap and influence feature development!


Tuesday, October 29, 2019

90 Seconds of Security: Malware Primer

My latest 90 Seconds covers the different types of malware, how infections happen and what to do if you get infected. Slightly extended edition courtesy of F5's Security Incident Response Team. https://f5.com/sirt




ps

Wednesday, October 2, 2019

F5's State of Application Services Survey




Since 2015, F5 has been surveying the tech industry to learn the key issues surrounding application deployment and delivery. Again for 2020, we’d love to understand your company’s current application architectures to help shape F5’s application services strategy. We will be taking responses until Oct 10, 2019.

If you are interested in taking the survey, please continue to this link:
https://f5.co1.qualtrics.com/jfe/form/SV_0JJY1SQZyiufT7v?URL_SOURCE=F5DevCentral

Thursday, September 26, 2019

90 Seconds of Security: F5 SIRTs Top Tip for Keeping Your BIG-IP and Your Network Secure

Learn why locking down the Management Port is F5 SIRT’s Top Tip for keeping your BIG-IP and your network secure from intruders. From their SecOpsCave deep within F5 headquarters, the F5 SIRT (f5.com/sirt) monitors all kinds of attacks and shares the bad things that can happen, like a DDoS attack, if BIG-IP is not secure.

For more information about SIRT’s specialized service please visit: https://www.f5.com/sirt


Tuesday, September 10, 2019

90 Seconds of Security: F5 SIRT's Top Threat for Summer 2019

Find out what threats topped F5 Security Incident Response Team's (SIRT) emergency response list for Summer 2019. F5 SIRT sees all sorts of attacks against F5 devices and the services they protect. 

For more information about this specialized service visit: https://www.f5.com/sirt


Friday, August 30, 2019

90 Seconds of Security: F5 Security at Black Hat USA 2019

Learn about RedTunnel, how to explore internal networks via the DNS rebinding tunnel, and how we used the new SODA (Simulation of DDoS Attacks) tool to defend against rapidly morphing DDoS attacks. You can also download the sessions the F5 Security team delivered at #BHUSA by going to f5.com/blackhat.


Friday, August 16, 2019

Bot Management with F5'S Advanced WAF

Automated attacks are a huge threat to organizations. Half of internet traffic are bots and 30% of those are sending malicious payloads. Learn how F5's Adv. WAF helps protect your applications from automated attacks, optimizes your business intelligence and improves performance, availability, and infrastructure costs. Visit f5.com/bots to learn more.


90 Seconds of Security: Security Stories for July 2019

A 90 second recap of some of the recent security stories for July 2019. The F5 SIRT (f5.com/sirt) shares some of the security incidents that caught their attention in July. In this episode we cover recent GDPR enforcements, yet another Magecart attack on S3 buckets and Overwhelmed IT personnel.


Thursday, July 18, 2019

90 Seconds of Security: Security Incidents for June 2019

A 90 second recap of some of the recent security incidents for June 2019. The F5 SIRT shares some of the security incidents that caught their attention in June. In this episode we cover the recent Mozilla vulnerability, the GandCrab decryptor and Linux Exim issue.


Wednesday, May 29, 2019

90 Seconds of Security: In the Wild Malware for April 2019

A 90 second recap of 'In the Wild' Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in April 2019.

Get the details at: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities--exploits--and-malware-driving-attack-campaigns-in-april-2019




ps

Thursday, April 4, 2019

TLS 1.3 Enterprise Adoption

With the new TLS 1.3 specification published by the IETF in August 2018, many organizations are adopting plans for the new specification. F5, together with Enterprise Management Associates, conducted research to better understand how enterprises are impacted by the growing use of encryption.

Get your copy today at: https://interact.f5.com/TLS-13-adoption-in-enterprise.html

 

ps

Tuesday, March 26, 2019

How Malware Evades Detection

Malware loves encryption since it can sneak around undetected. F5Labs 2018 Phishing & Fraud Report explains how malware tricks users and evades detection. 

Let's light up how evasion happens & get your F5 Labs 2018 Phishing & Fraud Report today.

Tuesday, February 26, 2019

F5 at RSA 2019



A Preview of F5 activities at #RSAC19. You can visit F5 March 4-8 in Booth S643 and www.f5.com/rsac for more details. See you in San Francisco!

Thursday, December 13, 2018

F5 Labs 2018 Phishing & Fraud Report

The F5 Labs 2018 Phishing & Fraud Report is out!

In this report, the F5 Labs team specifically investigated the rise of phishing and fraud during the 'holiday shopping season,' beginning in October and continuing through January. Fraud and phishing attempts increase 50% right now, from October to January and phishing was the root cause of 48% of the data breaches that F5Labs investigated. It's important to check out the report because it explains how phishing works, how to defend yourself against phishing attacks and the importance of training employees to recognize malicious emails.

Some of the crazy stats they found include 93% of phishing domains offered a secure (https) version of the site to appear more legitimate and 68% of malware sites used encryption certificates (https), meaning 68% of Command & Control servers use port 443. The crooks are going through the trouble of getting SSL certificates for their fake, but real looking sites.


Take a look at some of these. Do any of these web logins look familiar?


How about this one?

Or maybe this one?


If so then you need to check out the 2018 Phishing and Fraud report from F5 Labs because they were all fake. Attackers are getting so good at creating fake websites that impersonate the real thing, most people can’t tell the difference. One thing is for certain, employee click-through rates on phishing emails drop from 33% to 13% with security awareness training:
  • 33% — 1-5 training events
  • 28% — 6-10 training events
  • 13% — 11 or more training events
You can check out the Preview Video here and get your report at https://www.f5.com/labs


ps




Monday, July 2, 2018

DevCentral's Featured Member for July - Rhazi Youssef

Our Featured Member series is a way for us to show appreciation and highlight active contributors in our community. Communities thrive on interaction and our Featured Series gives you some insight on some of our most active folks.

Rhazi Youssef has been a very active DevCentral member since 2012 and the third engineer we've featured from e-Xpert Solutions SA. Initially Rhazi was a bit reluctant to participate as he's a quiet, humble guy and we're thrilled that he's DevCentral's Featured Member for July!
Let's learn a bit more about Rhazi.

DevCentral: Please explain to the DevCentral community a little about yourself, what you do and why it’s important.
Rhazi: I’m a security engineer since 2009 working in Geneva (Switzerland), a region with several security projects involving F5 BIG-IP (GTM, LTM, ASM, APM). My interest began early when I started and installed several security equipment like Mail relay, FW, SIEM&SEM, web proxy… 
But I admit that my job became more interesting when I started to approach the application part. I am talking about WAF (ASM), perimeter security (APM), LTM (LB, optimization,)… 
I immediately bonded with this product since it is very rich, complete and scalable with its time. It is for this reason that I invested heavily on this product by passing for example all my certificates which gives me today the title of “Security Solution Expert” (401).
DC: You are a very active contributor in the DevCentral community. What keeps you involved?
RY: First off, like everyone else I admit that Devcentral has already allowed me to get out of trouble and not just once, and I thank the community for this. The DevCentral community is very much involved in sharing, helping and informing members. This work done by the community helped me a lot in my work (I upgraded my skills) so I think it is normal for me to give back to the community that helped me...and offer advice that will help with experience and knowledge the community to move forward.
My investment in the community is even easier since F5 is a product that is very important to me. 
Today I work primarily on F5 BIG-IP (APM, ASM, LTM, GTM, WebSafe) which allows me to have an important experience on the potential problems that one can meet during a deployment, so it's the least of the things to help the community when I can.
DC: Tell us a little about the areas of BIG-IP expertise you have.
RY: These last 6 years I worked mainly on F5, I had the chance to work with some very great customers that I cannot mention :-). I deployed all types of hardware until VIPRION. And today I work on almost all of the BIG-IP modules (ASM, APM, LTM, GTM, VCMP, LC, WebSafe). 
The advantage with F5 is that you cannot get tired of this product. It is rich, complete and scalable. For example the APM that allowed me to meet the needs of our customers by going from the identity federation (SAML) to Oauth&OpenID connect. But still it's the same thing for ASM and other modules. We do not say it often enough but this product allows us to be up to date in terms of security; I'm talking about authentication protocols that the APM offers, different security methods carried by the ASM ... all these aspects allow us to maintain our level and to learn ...
DC: You are a Sr. Security Engineer with e-Xpert Solutions SA. Can you describe your typical workday, how you manage work/life balance and the strong support of F5 solutions?
RY: As everyone knows the job of Security Engineer is not easy. We must manage several clients, several projects, manage customer support, communicate with clients (vulnerabilities, news), schedule management, project tracking,... 
So every morning I spend quite some time to manage my emails, my calendar and answer to my customers. I am registered to F5 RSS feed, which keep me updated on CVE, I also follow many f5 webinars (I usually watch them later when they are online).
At e-Xpert solutions I am product manager of F5 solution, so I have to inform my colleagues about vulnerabilities or any new features, I must also regularly write news that we publish on our website. The other PMs do the same thing with their own products which also allows me to be informed about the other products of our portfolio. 
During my working day I connect regularly to DevCentral when I have some time to help or learn about some interesting topics. For me, helping the community is not binding. On the contrary, certain questions allow us to update ourselves on certain subjects and to exchange on our different points of view. 
I finished my work day in the evening by doing a small check of my mails and a pass on my usual information sites which included DevCentral. I almost forgot I work out every 3 days and I try to run at least every 2 days (no excuse for gym time!). 
If you are interested, here is the website of the company in which I evolve: https://www.e-xpertsolutions.com/

DC: You have a number of F5 Certifications. Why are these important to you and how have they helped with your career?
RY: 8 months ago I had my last certification “Security Solution Expert” (401). Having all these certifications was very important to me. First of all in order to guarantee a high level of expertise to our customer. Moreover this certification process obliges us to study and consequently to update us on the different modules. 
These certifications are like a quality label, our customers appreciate when the engineers who intervene has the higher level of certification. 
Moreover with the experience that I have, I think that the passage of these certifications allow us to have a richer view of the product and consequently to propose to our customers the best possible alternatives according to their needs.
DC: Describe one of your biggest BIG-IP challenges and how DevCentral helped in that situation.
RY: DC allowed me several times to solve the different problems I encountered. Things that seem simple to me today but that was not at the time I posted them and caused me quite some problems (Kerberos delegation, Kerberos authentication, Sideband, DDOS using iRule with session table …). 
I remember that I had to set up a perimeter of security to protect an application using the APM (I know it looks pretty simple). But I realized that the application was contextual (Web and JNLP) and that the APM session cookies were not propagated on to other contexts, so JNLP part could not connect. 

I will not go into the technical details but I had to create an iRule that used a table of correspondence between the cookie APM and the JNLP JSessionID that I stocked in a table session. Later I made an SSO on the backend application using the sideband (SSO profiles APM was not suitable). DC allowed me to build my iRule and sincerely without DC I would have had a lot of trouble and it would have taken me took a lot of time. And lastly DC allowed me to set up a fakeadfs using iRulesLX (and without DC, I do not think I could have done it alone).
DC: Finally, if you weren’t an IT admin – what would be your dream job? Or better, when you were a kid – what did you want to be when you grew up?
RY: When I was little and did not have school I spent my whole day on the football fields. I could play for 6 hours of suites without stopping. I loved football and I still do. So as you guessed I wanted to become a professional. But reality has taken over the dreams. Growing up I discovered computer science I started to build/dismantle my pc to add ram, change the hard drive, buy new graphics card for games... and little by little, I ended up in IT and I really do not regret it, but I admit that if I could have had the career of Ronaldo and also his salary I would not have mind either.
Thanks Rhazi!
Check out all of Rhazi's DevCentral contributions, connect on LinkedIn and follow e-xpert Solutions on LinkedIn.

If there is a DevCentral member you think should be featured, let us know in the comments section!

Monday, April 2, 2018

DevCentral's Featured Member for April - Daniel Varela

Our Featured Member series is a way for us to show appreciation and highlight active contributors in our community. Communities thrive on interaction and our Featured Series gives you some insight on some of our most active folks.

Daniel Varela has been one of those engaged members and amassed 374 points in February alone! Answering bunches of questions about SAML, SSO, Cookies and more, we're proud to name Daniel as our Featured Member for April.

DevCentral: Hi Daniel and thanks for helping many of our members! Please explain to the DC community a little about yourself, what you do and why it’s important.
Daniel: I am an ADC/GSLB/WAF SME currently working for Centrica PLC. My job entails load balancing applications, availability and security. My work experience is mainly around network security. I chose to work in security because you never get bored of it, there is always something new to learn which is what I love. I have been actively working with F5 devices for the last 10 years. I still remember when I first heard about iRules, I was really impressed with the possibilities it provided. Additionally, with a BIG-IP you can learn about a lot of technologies: HTTP, TLS, DNS, SAML, OAuth, Web acceleration, Web Application Firewall… I am probably missing technologies here but you get the idea. This is one of the reasons I am working with F5, fun is guaranteed.
DC: You are a former F5 employee (2014-17) and continue to be a very active contributor in the DevCentral community. What keeps you involved?
DV: I have always thought (and I always say to my customers) that DevCentral makes a difference in respect to any other vendor. The amount of information someone can find there is incredible and if what you are looking for is not there you just have to ask, people from all around the world will help you to do whatever you want to do (event the craziest things), there is always an iRule for that 😊. For this reason I like to participate as much as I can, I have found a lot of help there and I feel like I have to return the favor (and it is also fun to see what people are trying to do with F5).
DC: Tell us a little about the areas of BIG-IP expertise you have and your F5 Certifications. Why are these important and how have they helped with your career?  
DV: My experience with F5 has been pretty much with all the modules: LTM, ASM, APM, GTM, AFM, Silverline and a bit of WebSafe. I was an F5 consultant for 3 years meaning it gave me a great opportunity to learn a lot about all those modules. This provided me with a lot of knowledge and helped me to get the F5 Certification F5-CSE Security. I would recommend to everyone to make an effort and get it, in my experience companies really value this accreditation.
DC: Describe one of your biggest BIG-IP challenges and how DevCentral helped in that situation.
DV: The biggest challenges for me have always been around BIG-IP APM. APM is probably the module which you can expand on the most, some things are not there by default but with the help of iRules you always find a way to get what you need. The last challenge was to expand SAML IDP capabilities by providing step-up authentication using authentication contexts available in the protocol itself. It may sound simple but just because how APM and SAML is designed it was tricky.
DC: Lastly, if you weren’t an IT admin – what would be your dream job? Or better, when you were a kid – what did you want to be when you grew up?
DV: Finally, I have always wanted to work in IT but if I wasn’t doing this I think I would be a fireman. I love sports and being active so I think it’s a job I could do.
Thanks Daniel! Check out all of Daniel's DevCentral contributions and connect with him on LinkedIn.

If there is a DevCentral member you think should be featured, let us know in the comments section!