Fog ransomware targets SonicWall VPNs to breach corporate networks (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 28 Oct 16:43
https://sh.itjust.works/post/27281538

#cybersecurity

threaded - newest

Telorand@reddthat.com on 28 Oct 17:21 collapse

Arctic Wolf notes that apart from operating unpatched endpoints, compromised organizations did not appear to have enabled multi-factor authentication on the compromised SSL VPN accounts and run their services on the default port 4433.

Y’all… It’s 2024, going on 2025. You have to enable at least MFA. Running without it is like going on the internet in the 90s–2000s without some kind of antivirus.