Blog
Sharing Mitiga’s latest threat intelligence and research, cloud IR insights, and company news
How Transit Gateway VPC Flow Logs Help Incident & Response Readiness
Heading
In this blog, we will focus on the security and forensic aspects of Transit Gateway VPC flow logs and expand the way they can be used by organizations to respond to cloud incidents.
For Incident Response, Give Peacetime Value a Chance
Heading
As an IR vendor, it is important to keep your customers up to date and prepared between breach attempts. Learn how to increase your peacetime value now.
Stop Ransomware Attackers From Getting Paid to Play Double-Extortionware Games
Heading
In the past, many companies relied on backups to get back to business quickly if they were attacked. Reliable, secure backups separated from the primary environment made it much more difficult for an attacker to access and encrypt them. That long-standing process no longer deters double-extortionware actors — instead, today’s attackers not only encrypt the data but also exfiltrate it.
How Identifying UserData Script Manipulation Accelerates Investigation
Heading
UserData script manipulation by threat actors is a technique that has been known in the wild for several years and has been observed being exploited by many attack groups, but monitoring and detecting malicious manipulation of user data script is not trivial with standard AWS Cloudtrail logging.
How to Protect Your Business From the Most Dangerous Cyberthreats
Heading
Ransomware attacks are on the rise, and it now more important then ever to be prepared. Be prepared by having an up-to-date incident response plan. Learn more.
Lessons Learned from WannaCry: Are We Ready for Another Global Attack?
Heading
Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world. The attackers demanded a ransom of just $300 worth of bitcoins within three days or the files would be permanently deleted. The cryptoworm leveraged the EternalBlue exploit, which the National Security Agency developed to attack older Windows Systems.
SaaS Breaches: How to Think about Security in Cloud Apps and Services
Heading
The Okta breach is yet another indication of what we have been seeing for the past few years in the cybersecurity industry, particularly in the incident response practice, demonstrating the increased sophistication and capabilities of various attack groups.
Cyber Resilience - Why & How to Start Building It In Your Organization
Heading
Cyber resilience is the ability of an organization or entity to continue to deliver services or solutions even in the face of adverse cyber events, such as cyberattacks. Cyber resilience combines elements of information security, business continuity, and organizational resilience.
Microsoft Storm-0558 SaaS Breach: Hunting for Stealth Espionage Attacks
Heading
Uncover the Microsoft Storm 0558 SaaS breach and learn expert strategies for hunting stealth espionage attacks and strengthening your security posture.