New Article From Active Directory Series in 05/2021 Issue of iX Magazine

The eigth part of the article series, which is available in the 05/2021 issue of iX magazine, looks at Active Directory (AD) security from a new perspective: While the previous articles of the series dealt with possible attacks on the AD, Marco Wohler, Head of IT, now describes hardening measures that system administrators can use to increase the security of the Active Directory and protect it against such attacks.
[more]

Article in “Zürichsee-Zeitung”: How a Company Is Turned Upside Down by a Cyber Attack

The number of cyber attacks is steadily increasing. Once again, this is proven in the current issue of Zürichsee-Zeitung (30 March 2021, available in German only) featuring a family business that has been targeted by cybercriminals: A ransomware attack temporarily shut down their entire operation. Tobias Ellenberger, COO Oneconsult AG & Vice Chairman Oneconsult International AG, explains from the perspective of an experienced expert in this field why such attacks have become very common, what needs to be taken into account in the event of such an attack, and how a cyber security service provider can help companies prevent the worst case.
[more]

Article on Underestimated Cyber Risks in AXA’s Customer Magazine “Meine Firma”

SMEs are increasingly targeted by cybercriminals. In the current issue of “Meine Firma”, AXA’s customer magazine for SMEs, the head of an architecture firm, that was exposed to a ransomware attack, shares his experience. Tobias Ellenberger, COO Oneconsult AG & Vice Chairman Oneconsult International AG, assesses the situation from the perspective of a cyber security expert and explains why such incidents are not uncommon.
[more]

Article Series on Active Directory Security Continues in Latest Issue of iX Magazine

In the current issue 04/2021 of iX magazine, Yves Kraft, Branch Manager Bern and Senior Penetration Tester & Security Consultant, and Frank Ully, CTO Oneconsult Deutschland GmbH, continue the series of articles on Active Directory security. The latest article in the series provides an insight into how attackers can exploit insecure configurations and generously assigned rights, among other things, to first spread and then also gain persistence beyond the top-level layer (forest) – the actual security boundary of an Active Directory environment.
[more]

Zero-Day Vulnerabilities in Microsoft Exchange Actively Exploited – CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 & CVE-2021-27065

by Nadia Meichtry

Four zero-day vulnerabilities in Microsoft’s Exchange email solution have been fixed through updates released by Microsoft on 2 March 2021. This affects Microsoft Exchange Server, but not Exchange Online. [1]

The vulnerabilities, three of which have been classified as critical, are actively exploited, most notably by the Chinese hacker group “Hafnium”. The attackers gained access to the servers and were thus able to exfiltrate credentials and emails. [2]

[read the German article]

VMware vCenter Server Remote Code Execution Vulnerability – CVE-2021-21972

by Nadia Meichtry

On 23 February 2021, VMware published a Security Advisory. It indicates that VMware vCenter Server is vulnerable to an RCE (Remote Code Execution) vulnerability that has been rated critical.

[read the German article]

New Article From Active Directory Series in Current Issue 02/2021 of iX Magazine

In the latest issue of iX magazine (02/2021) you can find the next part of the series of articles about Active Directory security by Frank Ully, Chief Technical Officer of Oneconsult Deutschland GmbH. The sixth article picks up on the last (iX 12/2020) and penultimate (iX 11/2020) article of the series and describes further ways for attackers to gain higher privileges in the Active Directory beyond the possibilities explained so far.
[more]

Sunburst Hack: SolarWinds Orion Compromise

by Nadia Meichtry

Since the beginning of this week, one topic has been hitting the headlines: SolarWinds Orion IT monitoring and management software is currently being exploited by malicious attackers.

[read the German article]

Straight Into the Corporate Network

by Fabian Murer

In information security circles, one topic has again been very present since last week: A vulnerability (CVE-2018-13379) in Fortinet’s well-known VPN software from 2019 is being actively exploited by hackers.

[read the German article]

Active Directory Article Series Continued in New Issue 12/2020 of iX Magazine

In the current issue of iX magazine 12/2020 Frank Ully, Chief Technical Officer of Oneconsult Deutschland GmbH, continues the previous article of the series and explains further methods how attackers can use previously collected data to gain higher privileges in the Active Directory.
[more]

SMEs as Targets of Cyber Attacks

As part of the KMU Digital Webinar Yves Kraft, Branch Manager and Senior Penetration Tester & Security Consultant, in cooperation with AXA demonstrated various threat scenarios for SMEs using multiple live hackings and explained why cyber security is becoming increasingly important for SMEs. [more]

Cover Story About Active Directory in Issue 10/2020 of iX Magazine

Read the cover story written by Frank Ully, Chief Technical Officer of Oneconsult Deutschland GmbH, in the current issue 10/2020 of iX magazine (available in German only) to learn more about the reasons why Active Directory is becoming increasingly popular not only with administrators but also with attackers. [more]

We are hiring

(f/m, 100%): Your exciting new job at Oneconsult? If you are a native German speaker, we are looking for you to strengthen our top-flight cyber security team.

Job descriptions

Oneconsult is a member of FIRST

FIRST is a global network of incident response and security teams dedicated to promoting collaboration and coordination in this area and actively sharing information among members to respond more effectively to security incidents. FIRST has actually more than 550 members in 95 countries.
Further information about FIRST can be found here: https://www.first.org/
You will find information about our services in this area under the following link: https://www.oneconsult.com/de/incident-response-it-forensics/