.

CLOUD-BASED SECURITY IS OUR EXPERTISE

We’ll support you through your migration and provide service optimisation

WE ONLY PROVIDE SOLUTIONS YOU CAN TRUST

We’ve researched and tested the services for you and only offer services we know you can trust

SECURITY IS IN OUR DNA

We know about security and security is part of DNA of our founders and our team of professionals

YOUR SUPPORT NEEDS ARE OUR CORE COMMITTMENT

We’re focused on meeting your technical support needs through our online support portal

PARTNERS OF KEY CLOUD SECURITY PROVIDERS

We have excellent partner relationships with the leading security-as-a-service vendors

Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

2014-11-02

Help your customers to undestand their threats


Surely you have a clear understanding of new generation of hidden and emergent threats, including recently discovered exploits as "shellshock", "heartbleed" and "poodle". They are just the latest threats in cyber security landscape where attacks as SQL Injection, Cross Site Scripting (XSS), Advanced Malware artifacts are in most case conducted in conjunction with "phishing" and "social engineering" tecniques to increase effectiveness.

Do your customers have a clear understanding of this landscape ?
Do they are aware of vulnerabilities they are exposed ?
Do they are correctly addressing vulnerabilities and managing risk ?

To help you and your customers to give an answer to indicated question, CloudWALL is able to supply you a comprehensive portfolio od security auditing and assessment services including Vulnerability Assessment, Penetration Testing and Application Security Testing.

Together, through a remote security auditing services portfolio we are able to detect vulnerabilities your customers are exposing on public and private subnets and application and to supply all support to understand the risk level and to address remediation activities.

CloudWALL works as an extension of your company making available for you the strong expertise of our engineers in the cyber security space as well as our industry standard approach and methodology, while the full set of reporting deliverables are customized with your logo and color frame.

Cohoperating with us in delivering security auditing services to your customers may be interesting for your company in several fields, including but not limited to :

  • starting deliver a new portfolio of value added services without any investiment
  • increase revenues for professional services to addresss detect vulnerabilities
  • increase your brand awareness with your customers becoming a trusted advisor in security

For more details please visit our website at www.cloudwall.tk/services where you can find a catalog of our security auditing and assessment services and of course feel free to contact us for any inquiry.

2014-07-04

Hotel Hippo booking site taken down


HotelHippo has been taken offline after security expert finds various flaws in its IT systems. A hotel booking site has been condemned by a security expert after leaving users personal details easily accessible to hackers. Scott Helme, an information security consultant, uncovered several flaws in the HotelHippo site while trying to book accommodation for a trip to the Lake District.

They included the presence of an SQL injection vulnerability on the site, as well as PCI compliance breaches and HTTPS configuration issues. He was able to test this out further by creating several bookings featuring fake credit card data, which he stressed was information that was irretrievable when pulling out other people’s bookings. Once a booking is made, the site then emails users confirmation of the transaction, which Helme discovered could potentially provide cyber criminals with the ammunition needed to launch a convincing phishing attack.

This is just the last case when high severity vulnerabilities are found in web applications and web sites. This is why at CloudWALL Italia we offers an innovative platform to perform automated security tests against any website as well as web and mobile applications.

CloudWALL WAS | Web Application Security is a Cloud service you use through your browser, so there’s no software to install or maintain. You can accurately and efficiently test your apps, no matter where they are – on internal networks, hosted on the Internet or in Cloud platforms such as Amazon. Relied on by leading companies with some of the most demanding web apps in the world, CloudWALL WAS | Web Application Security will help you safeguard your apps, whether you have just a few apps or many thousands.

Find more details at www.cloudwall.tk/was .

Microsoft takes offline 4M Malicious Websites


Microsoft has gotten pretty good at using the legal system to combat the spread of malware and online fraud. It appears, however, that they need to work on their finesse game a little. In their latest assault, the collateral damage knocked around 4 million sites offline.

It all started after a Nevada court temporarily gave Microsoft control of 23 domains belonging to No-IP.com. In case you’re not familiar with No-IP, it’s a service that assigns static subdomain and domain names to dynamic IP addresses. Geeky types like us often use them to make remotely accessing servers that we run at home (only in accordance with our ISPs TOS, of course).

Malware authors, however, like to leverage services like No-IP to distribute and control their malicious software. They can constantly change IP addresses for CNC servers without knocking their network offline. These sites make up a tiny percentage of the total, of course. According to Microsoft’s court papers, around 18,000 No-IP names were part of the njrat and njworm malware network.

To protect users for malicious website both from home and corporate PCs as well as mobile devices, CloudWALL Italia offers an innovative web security platform in the cloud that prevent access to unauthorized contents and malicious websites from your users.

CloudWALL WCF | Web Content Filtering lets you manage the Internet experience on and off your network with acceptable use or compliance policies, putting you in control. Fully delivered through the cloud, CloudWALL WCF | Web Content Filtering allow to secure and take control of Internet activities from users anywhere and anytime, when they are connected to the corporate networks as well as they are at home or on the road, through an unified dashboard accessible anywhere and anytime from any browser web or mobile device.

Find more details at www.cloudwall.tk/wcf .

2014-07-03

Phishing websites up 10% in Q1 2014


The number of overall phishing sites observed in the first quarter of 2014 was 125,215, marking a more than 10 percent increase over the final quarter of 2013, during which 111,773 phishing sites were observed, according to the APWG Phishing Activity Trends Report for the first quarter of 2014.

The U.S. hosted more than 40 percent of those sites in each of the first three months of the year, according to the report. Close to 50 percent of phishing attacks were aimed at payment services in the first quarter of 2014, making it still the most targeted industry, and the financial industry was a target about 20 percent of the time, according to the report. The ISP, gaming, auction, government and social networking industries were each targeted less than 10 percent of the time.

To protect their users from Phishing attacks, CloudWALL Italia offers an innovative strong authentication platform in the cloud to enforce authentication processes for protected resources. CloudWALL OTP | One Time Password provides the fastest path to identity management and strong authentication in the cloud with an on-demand solution consisting of single sign-on, multi-factor authentication, directory integration and user provisioning.

CloudWALL OTP | One Time Password  delivers unparalleled usability by working with all major smartphone platforms and letting users to perform multi-factor authentication with the click of a button to any of your applications and services by integrating your existing Directory Services.

Find more details at www.cloudwall.tk/otp.