Kurt

Archive

Blast-RADIUS: A Critical Threat to Your Network – Green Rocket Security releases update to mitigate vulnerability

The recent discovery of the Blast-RADIUS vulnerability (CVE-2024-3596) poses a significant risk to networks worldwide. This flaw in the RADIUS authentication protocol can be exploited by attackers to gain unauthorized access, launch denial-of-service attacks, and...

OpenSSH Vulnerability Patched in GreenRADIUS

SUMMARY This notice covers CVE-2024-6387 OpenSSH vulnerability (nicknamed “regreSSHion”) and its impact related to GreenRADIUS. GreenRADIUS is accessed using SSH from an internal (on prem) origin and therefore normally protected by an external firewall. This...

Okta MFA Cloud Service Hack Exposed Customer Data

The Lapsus$ hacking group allegedly hacked into Okta, a major provider of cloud-based identity and access management services early this year. The Lapsus$ group has leaked screenshots of data from Okta’s internal systems. The Lapsus$...

GreenRADIUS not vulnerable to Log4j vulnerabilities

Summary CVE-2021-44228 and CVE-2021-45046 (Log4Shell or LogJam) are both zero-day vulnerabilities in the widely used Apache Log4j Java-based logging library. Since it is widely used in many popular products, customers have contacted Green Rocket Security...

Green Rocket Security Now Offers YubiKey OTP Validation Only Support (Alternative to YK-VAL and YK-KSM)

In April 2021, Yubico announced “YK-VAL, YK-KSM and YubiHSM 1 End-of-Life”, referencing that the libraries used outdated/vulnerable technologies. As an alternative – in the same article, Yubico continues – “Yubico recommends customers who use these...

LokiBot Trojan: Information Thief, Key capture (keylogger) and more…

LokiBot Trojan Malware (a.k.a LukiBot, Lokibot, Loki PWS, and Loki-bot) is active again stealing sensitive information such as usernames, passwords, cryptocurrency wallets, and other credentials. It was first discovered in 2015 and has been used...

Green Rocket Security introduces our GRS ADFS Plugin enabling MFA in ADFS environments

Microsoft ADFS (Active Directory Federation Service) offers a Single Sign On (SSO) solution to users for applications, services and resources inside the organization (such as Web apps and disparate apps and resources) as well as...

Be Sure To Add 2FA to Internal Systems As Well

Generally, when we think of securing our organization, we usually focus on securing the perimeter with firewalls, VPNs, limiting access points, and maybe some mail filtering to block malicious attachments. But some attacks that have...

GreenRADIUS enhancements for 2017? It’s up to you!

2016 has been an exciting year for GreenRADIUS. Apart from security-related updates and bug fixes, your feedback has been the basis of over 50 new features and improvements to GreenRADIUS during the year! The top...

Top 10 New GreenRADIUS Features and Improvements in 2016

It was a busy, but successful 2016 for us! The following list of new GreenRADIUS features and improvements in 2016 were almost all based on customer feedback and requirements. So we would love to hear...