Blog
Sharing Mitiga’s latest threat intelligence and research, cloud IR insights, and company news
For Incident Response, Give Peacetime Value a Chance
As an IR vendor, it is important to keep your customers up to date and prepared between breach attempts. Learn how to increase your peacetime value now.
Stop Ransomware Attackers From Getting Paid to Play Double-Extortionware Games
In the past, many companies relied on backups to get back to business quickly if they were attacked. Reliable, secure backups separated from the primary environment made it much more difficult for an attacker to access and encrypt them. That long-standing process no longer deters double-extortionware actors — instead, today’s attackers not only encrypt the data but also exfiltrate it.
How Identifying UserData Script Manipulation Accelerates Investigation
UserData script manipulation by threat actors is a technique that has been known in the wild for several years and has been observed being exploited by many attack groups, but monitoring and detecting malicious manipulation of user data script is not trivial with standard AWS Cloudtrail logging.
How to Protect Your Business From the Most Dangerous Cyberthreats
Ransomware attacks are on the rise, and it now more important then ever to be prepared. Be prepared by having an up-to-date incident response plan. Learn more.
Lessons Learned from WannaCry: Are We Ready for Another Global Attack?
Five years ago, the WannaCry ransomware cryptoworm targeted computers running Microsoft Windows, encrypting data at organizations around the world. The attackers demanded a ransom of just $300 worth of bitcoins within three days or the files would be permanently deleted. The cryptoworm leveraged the EternalBlue exploit, which the National Security Agency developed to attack older Windows Systems.
SaaS Breaches: How to Think about Security in Cloud Apps and Services
The Okta breach is yet another indication of what we have been seeing for the past few years in the cybersecurity industry, particularly in the incident response practice, demonstrating the increased sophistication and capabilities of various attack groups.
Cyber Resilience - Why & How to Start Building It In Your Organization
Cyber resilience is the ability of an organization or entity to continue to deliver services or solutions even in the face of adverse cyber events, such as cyberattacks. Cyber resilience combines elements of information security, business continuity, and organizational resilience.
Microsoft Storm-0558 SaaS Breach: Hunting for Stealth Espionage Attacks
Uncover the Microsoft Storm 0558 SaaS breach and learn expert strategies for hunting stealth espionage attacks and strengthening your security posture.
Hidden Dangers in the Cloud Control Plane | Mitiga
The cloud control plane can be difficult to understand. In this article we examine attack scenarios and how to harden your GCP environment. Learn more.