.

CLOUD-BASED SECURITY IS OUR EXPERTISE

We’ll support you through your migration and provide service optimisation

WE ONLY PROVIDE SOLUTIONS YOU CAN TRUST

We’ve researched and tested the services for you and only offer services we know you can trust

SECURITY IS IN OUR DNA

We know about security and security is part of DNA of our founders and our team of professionals

YOUR SUPPORT NEEDS ARE OUR CORE COMMITTMENT

We’re focused on meeting your technical support needs through our online support portal

PARTNERS OF KEY CLOUD SECURITY PROVIDERS

We have excellent partner relationships with the leading security-as-a-service vendors

2015-04-28

Non c'e' sicurezza senza controllo!

Proteggere i propri sistemi e le proprie applicazioni significa innanzitutto garantirne la disponibilita' e la corretta operativita' 24 ore al giorno, 7 giorni alla settimana. Tuttavia, ambienti applicativi sempre piu' basati su architetture distribuite, integrazioni sempre piu' spinte tra diverse piattaforme e, non ultimo, l'avvento del "cloud" e delle applicazioni fruite in modalita' "SaaS" rendono oggi necessarie ma non piu' esaustive le tradizionali procedure di monitoraggio basate su controlli di tipo sistemistico. 
 
In questo contesto, CloudWALL MON - System & Application Monitoring mette a disposizione un'infrastruttura totalmente basata su "cloud" e fornita in modalita' SaaS (Software As A Service) per il monitoraggio completo delle applicazioni, delle reti e dei sistemi che costuiscono il proprio sistema informativo.
 
Contattaci per una evaluation gratuita e per cominciare da subito a tenere sotto controllo le tue applicazioni oppure visitaci sul nostro sito www.cloudwall.tk.

2015-01-07

Nuove architetture per l'autenticazione degli utenti

Il tradizionale assunto "qualcosa che sai, qualcosa che hai e qualcosa che sei" è stato considerato per molto tempo un modello utile per distinguere i meccanismi di autenticazione. Storicamente, il modello basato su  "qualcosa che sai" - ovvero la password - ha dominato il panorama di mercato con la propria semplicita' di utilizzo e di realizzazione ma anche con i propri problemi noti,  dal phishing agli innumerevoli casi di violazione gli archivi delle password.


Riflettendo i problemi di sicurezza, oggi la tendenza di mercato si sta progressivamente spostando dalla gestione della password al modello basato su "qualcosa che hai" attraverso l'utilizzo di telefoni cellulari che in questa nuova veste rappresentano il "secondo fattore" del processo di autenticazione e possono quindi essere sfruttati per integrare o sostituire l'utilizzo delle tradizionali password statiche.

Uno smartphone è effettivamente un computer portatile potente, con le seguenti caratteristiche importanti relative all'autenticazione:

  • Connettività. Per definizione, i dispositivi mobili sono costantemente connessi alla rete mobile supportano processi di autenticazione tramite un messaggio SMS o attraverso sistemi di notifica del sistema operativo mobile.
  • Potenza di elaborazione. Questo permette calcoli di bordo, a sostegno di crittografia e così via.
  • Interfaccia utente. Questa interfaccia consente che venga richiesto all'utente di immettere le proprie credenziali di autenticazione.
  • Archiviazione sicura. L'archiviazione sicura consente la memorizzazione delle credenziali utilizzate in schemi di autenticazione all'interno di archivi sicuri perche' crittografati.
  • Biometria. Sempre più dispositivi hanno componenti hardware che permettono un controllo di alcuni fattori biometrici dell'utente, per esempio, un'impronta digitale o la retina.
  • Singolo utente. I dispositivi sono in genere associati a un singolo utente. Di conseguenza, l'autenticazione effettuata attraverso il dispositivo consente di avere una ragionevole certezza che l'utente autenticato sia effettivamente chi riteniamo debba essere.

Diversi schemi di autenticazione basati su dispositivi mobili sfruttano queste caratteristiche in diverse maniere. Ad esempio, CloudWALL OTP | One Time Password autentica gli utenti inviando una codice univoco al dispositivo mobile precedentemente registrato tramite  Google Cloud Messaging for Android o Apple Push Notification Services attraverso una apposita "app" installata sul dispositivo mobile.

Un modello diverso di autenticazione basata mobile viene normalizzato dal FIDO (Fast Identity Online) Alliance. Le specifiche FIDO standardizzano un modello che sfrutta le funzionalita' di riconoscimento biometrico dei dispositivi. Nel modello FIDO, l'utente si autentica al dispositivo tramite un controllo biometrico che consente di sbloccare una chiave crittografica che viene poi utilizzato per l'autenticazione verso il server.

Mentre schemi di autenticazione basati su dispositivi mobili come quelli descritti possono migliorare in modo significativo l'esperienza di autenticazione degli utenti, e' ragionevole pensare che l'esecuzione di una procedura di autenticazione così esplicito per l'accesso a applicazione possa essere impattante per il tradizionale modo di lavorare degli utenti. Di conseguenza, vi e' un forte valore aggiunto nel combinare un processo di autenticazione sul dispositivo mobile con meccanismi di Single sign-On che cosentano di sfruttare un unico processo di autenticazione dell'utente per garantire l'accesso dell'utente a diverse applicazioni.

Meccanismi standardizzati per abilitare SSO per applicazioni browser mobili sono ben stabiliti. Il Security Asserzioni Markup Language (SAML) abilita SSO per un browser mobile esattamente nella stessa forma come un browser desktop.

Esistono altri protocolli SSO, come OpenID® e WS-Federation. Più di recente, OpenID Connect (Connect) è emerso come un protocollo che, come si è costruito sulla cima di OAuth, può consentire entrambi i browser web e applicazioni native.

Sia OAuth e Connect possono essere utilizzati per proteggere le applicazioni mobili native (a differenza SAML e altri protocolli Web SSO). Ma né OAuth né Connect possono, fuori dalla scatola, abilitare un'esperienza SSO

La combinazione di procedure di autenticazione forte basata sull'utilizzo di dispositivi mobili con funzionalita' di Single Sign-On consente di incrementare i livelli di sicurezza delle procedure di autenticazione degli utenti e di semplificare l'esperienza degli utenti nell'accesso alle applicazioni aziendali e nella gestione della propria identita' digitale.

CloudWALL OTP | One Time Password e CloudWALL SSO | Single Sign-On rappresentano la proposta di CloudWALL Italia per proteggere l'identita' digitale degli utenti aziendali attraverso l'integrazione di procedure di Single Sign-On per applicazioni basate su web con servizi di autenticazione forte che sfruttano i dispositivi mobili come "secondo fattore" nel processo di autenticazione.

Per maggiori informazioni visitaci sul nostro sito all'indirizzo http://www.cloudwall.tk/otp e http://www.cloudwall.tk/sso.

Come resiste il tuo business a virus, bot e attacchi informatici?

Ogni giorno i virus, bot e strumenti automatizzati cercano di sfruttare le vulnerabilità e miconfigurations più comuni come la mancanza di aggiornamenti del software, password deboli e configurazioni o vulnerabilità del codice.

Che cosa accadrebbe a sistemi e applicazioni della vostra azienda in caso di un attacco informatico? E che dire della reputazione danneggiata della società? Un test di penetrazione e di un'analisi di vulnerabilità possono prevenire i danni di un attacco informatico prima che sia troppo tardi.


CloudWALL Italia dispone di tutte le competenze individuali e di tutti gli strumenti per aiutare le Aziende ad identificare ed indirizzare le Vulnerabilità 'dei propri sistemi e di mitigrare la propria esposizione agli attacchi provenienti dall'esterno ma also dall'interno dell'azienda.

La nostra offerta prevede su  un servizio di analisi della sicurezza volta a verificare la conformità dei sistemi connessi a Internet e delle applicazioni web pubblicate per identificare potenziali minacce per la vostra attività.  La valutazione individua, violazioni rango e indirizzo e vulnerabilità sui servizi e le applicazioni a vista, fornendo un'analisi neutra e suggerimenti di bonifica per consentire agli amministratori di sistema e sviluppatori di software di risolvere rapidamente qualsiasi problema rilevato.

Per maggiori informazioni visitateci sul nostro sito www.cloudwall.tk [#cloudwall]

Il nuovo malware SoakSoak Compromette siti 100.000 Wordpress

Questa Domenica è iniziata con il botto : Google ha inserito nella lista nera oltre 11.000 domini a seguito dell'ultima campagna di malware basata sull'attacco denominato SoakSoak.ru. La nostra analisi mostra impatti dell'ordine di centinaia di migliaia di siti web WordPress. Non possiamo confermare l'esatto vettore, ma analisi preliminare mostra la correlazione con la vulnerabilità Revslider riportata dagli analisti lo scorso mese di Settembre 2014.  L'impatto sembra interessare ancora una volta la maggior parte dei siti basati sulla nota piattaforma WordPress. Questo malware durante la decodifica javascript carica un malware dal dominio SoakSoack.ru, precisamente questo file: hxxp: //soaksoak.ru/xteas/code.


Nel caso che la vostra azienda stia utilizzando la piattaforma WordPress per la pubblicazione dei propri contenuti aziendali considerateci a disposizione per un consulto.

Grazie ai servizi CloudWALL MDS | Malware Detection Service e CloudWALL WAF | Web Application Firewall siamo in grado di supportare i nostri clienti sia nella rilevazione di attacchi e infezioni all'interno del proprio sito sia di garantirne una protezione costante per prevenire il verificarsi di ulteriori attacchi.

Per maggiori informazioni visitateci sul nostro sito www.cloudwall.tk [#cloudwall]

2014-12-19

We wish you a Merry Chistmas and a Happy New Year


We wish you a Merry Chistmas
and Happy New Year

2014-11-02

Help your customers to undestand their threats


Surely you have a clear understanding of new generation of hidden and emergent threats, including recently discovered exploits as "shellshock", "heartbleed" and "poodle". They are just the latest threats in cyber security landscape where attacks as SQL Injection, Cross Site Scripting (XSS), Advanced Malware artifacts are in most case conducted in conjunction with "phishing" and "social engineering" tecniques to increase effectiveness.

Do your customers have a clear understanding of this landscape ?
Do they are aware of vulnerabilities they are exposed ?
Do they are correctly addressing vulnerabilities and managing risk ?

To help you and your customers to give an answer to indicated question, CloudWALL is able to supply you a comprehensive portfolio od security auditing and assessment services including Vulnerability Assessment, Penetration Testing and Application Security Testing.

Together, through a remote security auditing services portfolio we are able to detect vulnerabilities your customers are exposing on public and private subnets and application and to supply all support to understand the risk level and to address remediation activities.

CloudWALL works as an extension of your company making available for you the strong expertise of our engineers in the cyber security space as well as our industry standard approach and methodology, while the full set of reporting deliverables are customized with your logo and color frame.

Cohoperating with us in delivering security auditing services to your customers may be interesting for your company in several fields, including but not limited to :

  • starting deliver a new portfolio of value added services without any investiment
  • increase revenues for professional services to addresss detect vulnerabilities
  • increase your brand awareness with your customers becoming a trusted advisor in security

For more details please visit our website at www.cloudwall.tk/services where you can find a catalog of our security auditing and assessment services and of course feel free to contact us for any inquiry.

2014-10-25

Which Antispam solution do you sell ?

Did you ever sold products and solutions to protect mail servers from viruses and spam? I'm sure yes, of course. And I'm also sure that in your experience you've sold products that has allowed you a very limitated margins and have been also very complex in the installation process, with additional costs for your company.

At CloudWALL we've a clear undestanding of those issues. For this reason, in cohoperation with our technological partners, we've built a platform to protect mail servers from viruses and spam that is ready to use, requiring no investiments to purchase hardware, software and infrastructures, and supplied in a "as a service" model and a "pay-per-use" pricing referred to the number of protected mailboxes.

Leveraging the value of this platform may give some benefits to your company, as: 
  • a new services in your offering portfolio
  • a margin grow than typical resale of products
  • recursive revenues from your subscribers
  • a standard offering with standard skills to manage
  • the opportunity to sell new services for management
For more details please visit our website at www.cloudwall.tk/mcf

We've created a NOC to share with your company

Did you ever considered which value services your company could supply to your customers by leveraging the value of a Network Operation Centre ?  Just for example:
  • health and fault monitoring for phisical and virtual systems
  • availability monitoring for network services
  • availability monitoring for local and hosted web applications
  • service level agreement monitoring for critical applications
  • monitoring of the expiration date of SSL certificates
  • send alarms by email in the case of incidents and anomalies
  • build reports for availability and SLA management
At today, the opportunity to supply those type of services was limitated to big players in the IT and TLC industry, due to the large investments required to build an manage a Network Operation Centre infrastructure.

Today, by leveraging the value of cloud technologies, your company may have your own Network Operation Centre infrastructure ready to use, requiring no investiments to purchase hardware, software and infrastructures, and supplied in a "as a service" model and a "pay-per-use" pricingreferred to the number of monitored devices and applications for your customers.

Find more details at  www.cloudwall.tk/mon.

Security "as a service" for your customers

CloudWALL is a new player in the IT Security industry and in this field we are able to supply your company with top level expertise to evaluate risks for your customers against most emergent threats - including most recent vulnerabilities as Heartbleed and Shellshock - and to suggest remediation activities through our portfolio of security platforms "in the cloud" supplied with a "as a service" approach

Through our portfolio of security auditing and risk assessment services as well as our security platforms "in the cloud" your company may be able - without any investment - to supply your customers with new value services able to differentiate your company from competition, to enforce your "grip" to your customers and to increase your revenues through a new range of value added services working around our cloud-based technology portfolio.

Find more details at www.cloudwall.tk.

Leverage your business with cloud security

At CloudWALL, we are providers of leading Cloud Security Technologies and best practices to enable channel partners, resellers and service providers to quickly deliver and onboard users to a Cloud-Based Security Portfolio of service offerings.
 
CloudWALL mission is focused in helping partners of all types to deliver security and compliance solutions to their customers and our offering of software-as-a-service security solutions may allow your company to provide your customers with a valuable and comprehensive solution that is easy to sell, deploy and deliver.
 
Bringing your company with a valuable portfolio of innovative IT security solutions delivered in the cloud accomplished with a specific background to support your company in enrolling, delivering and promoting those services to your customers, CloudWALL allow your company to increase your revenues and retain your most profitable customers with additional managed services and solutions.
 
Actually based in Italy and actively working with some key partners in the IT Security industry, we are working to grow the network of system integration companies and IT service providers in the EMEA region interested in delivering new and innovative value added services through our cloud-based portfolio of security solutions.
 
Together, we can help your customers benefit from the cost savings and collaboration benefits that can be realized by leveraging the value of the cloud while maintaing a strong information security stance and meeting operational and regulatory requirements.

Find more details at www.cloudwall.tk/partners

2014-07-16

New vulnerability for WPTouch Wordpress plug-in


A research team found a very serious vulnerability in the WPTouch Plugin for WordPress that allows an attacker to upload files remotely to websites running the plugin that have not updated to VERSION 3.4.3 (the version the WPTouch team just put out to patch the vulnerability). This vulnerability may be very userful for an attacker to upload malicious contents in your websites.

In order to secure your website if you’re using the WPTouch Plugin (and over 5 million sites are), make sure to update the plugin immediately.

To detect malicious contents in your websites you can use CloudWALL MDS | Malware Detection Service but if you are interested to prevent your website to be vulnerable to next threats you may consider CloudWALL WAF | Web Application Firewall that allow to protect your websites from any network and application level attack.

Find more details at www.cloudwall.tk/mds.

Think twice before selling your smartphone!


A study published last week by Avast (AVST) suggests the vulnerability of Android smartphones goes beyond malware. As it turns out, wiping the devices fails to remove sensitive data.

Avast is in the business of selling security software, so anything the company says about smartphone security should be taken with a grain of salt. Still, the evidence that Avast offered is shocking and should serve as a wake-up call, especially to those who are selling their Android smartphone in preparation for buying the next must-have mobile device.

Avast purchased 20 used smartphones that sellers assumed had been wiped of personal data because they used Android’s “Factory Reset” option. This is what was found:

  • 40,000+ photos
  • More than 1,000 Google searches
  • 750+ e-mails
  • 250+ contacts
  • The personal identity of four of the previous device owners
  • One completed loan application

While this sample might not be representative of what data you have on your mobile phone, it serves as a stark reminder that selling your smartphone comes with risks. And this may be just the tip of the iceberg when it comes to smartphone security issues.

This is a security issue affecting not only personal users, but also corporates and enterprises that allow access to their confidential data both from corporate owned and BYOD devices. And this is also the reason why at CloudWALL Italia we are offering CloudWALL MDM | Mobile Device Management that allow to secure sensitive data on mobile devices.

CloudWALL MDM | Mobile Device Management offloads IT organizations from the arduous task of managing and securing corporate- and employee-owned mobile devices (BYOD). CloudWALL MDM | Mobile Device Management provides IT administrators with a rich set of capabilities to secure and manage both small and large-scale deployments of business and personal mobile devices. Our solutions offer organisations real-time visibility and control of connected mobile devices from a single administrative console.

Find more details at www.cloudwall.tk/mdm.

CNET attacked by Russian hackers


Russian hacker group that has attacked some of the biggest news and business sites in the world claims it penetrated CNET's website over the weekend and stole a database of registered reader data.

A representative from the group calling itself W0rm told CNET News in a Twitter conversation that it stole a database of usernames, emails, and encrypted passwords from CNET's servers.

W0rm is claiming that the database of stolen information includes data on more than 1 million users.

A CBS Interactive spokeswoman said that "a few servers were accessed" by the intruder. "We identified the issue and resolved it a few days ago. We will continue to monitor," for potential impact, she said.

W0rm said it found its way into CNET's servers through a security hole in CNET.com's implementation of the Symfony PHP framework, a popular programming tool that provides a skeleton on which developers can construct a complex website.

Once again, application level attacks are demonstrating to be for hackers an effective way to have unauthorized access to published web applications and services. 

This is why CloudWALL Italia is offering CloudWALL WAF | Web Application Firewall that allow to protect your web sites and web application from application level attacks aimed to have unauthorized access to sensitive data working behind of your systems. 

CloudWALL WAF | Web Application Firewall protects Web applications at the very edge of the Internet as opposed to inside the datacenter. Our solution shields an organization’s network from the growing number of application-layer attacks and prevents the loss of valuable corporate and customer data. In addition to proven attack defenses, the CloudWALL WAF | Web Application Firewall aids in compliance with information security regulations, such as PCI-DSS.

Find more details at www.cloudwall.tk/waf .

2014-07-04

Hotel Hippo booking site taken down


HotelHippo has been taken offline after security expert finds various flaws in its IT systems. A hotel booking site has been condemned by a security expert after leaving users personal details easily accessible to hackers. Scott Helme, an information security consultant, uncovered several flaws in the HotelHippo site while trying to book accommodation for a trip to the Lake District.

They included the presence of an SQL injection vulnerability on the site, as well as PCI compliance breaches and HTTPS configuration issues. He was able to test this out further by creating several bookings featuring fake credit card data, which he stressed was information that was irretrievable when pulling out other people’s bookings. Once a booking is made, the site then emails users confirmation of the transaction, which Helme discovered could potentially provide cyber criminals with the ammunition needed to launch a convincing phishing attack.

This is just the last case when high severity vulnerabilities are found in web applications and web sites. This is why at CloudWALL Italia we offers an innovative platform to perform automated security tests against any website as well as web and mobile applications.

CloudWALL WAS | Web Application Security is a Cloud service you use through your browser, so there’s no software to install or maintain. You can accurately and efficiently test your apps, no matter where they are – on internal networks, hosted on the Internet or in Cloud platforms such as Amazon. Relied on by leading companies with some of the most demanding web apps in the world, CloudWALL WAS | Web Application Security will help you safeguard your apps, whether you have just a few apps or many thousands.

Find more details at www.cloudwall.tk/was .

Microsoft takes offline 4M Malicious Websites


Microsoft has gotten pretty good at using the legal system to combat the spread of malware and online fraud. It appears, however, that they need to work on their finesse game a little. In their latest assault, the collateral damage knocked around 4 million sites offline.

It all started after a Nevada court temporarily gave Microsoft control of 23 domains belonging to No-IP.com. In case you’re not familiar with No-IP, it’s a service that assigns static subdomain and domain names to dynamic IP addresses. Geeky types like us often use them to make remotely accessing servers that we run at home (only in accordance with our ISPs TOS, of course).

Malware authors, however, like to leverage services like No-IP to distribute and control their malicious software. They can constantly change IP addresses for CNC servers without knocking their network offline. These sites make up a tiny percentage of the total, of course. According to Microsoft’s court papers, around 18,000 No-IP names were part of the njrat and njworm malware network.

To protect users for malicious website both from home and corporate PCs as well as mobile devices, CloudWALL Italia offers an innovative web security platform in the cloud that prevent access to unauthorized contents and malicious websites from your users.

CloudWALL WCF | Web Content Filtering lets you manage the Internet experience on and off your network with acceptable use or compliance policies, putting you in control. Fully delivered through the cloud, CloudWALL WCF | Web Content Filtering allow to secure and take control of Internet activities from users anywhere and anytime, when they are connected to the corporate networks as well as they are at home or on the road, through an unified dashboard accessible anywhere and anytime from any browser web or mobile device.

Find more details at www.cloudwall.tk/wcf .

APTs Pose a Major Challenge for Enterprise Security


One of the biggest concerns that confront large and small enterprises alike is what is known as Advanced Persistent Threats (APT). An APT is a network attack in which an unauthorized person gains access to a network and stays there undetected for a long period of time. Unlike the basic or mass market threats that everyone should be blocking, APTs are unknown threats that cannot be detected by traditional signature-based defences such as firewalls, IPSs, and secure web and email gateways.

According to a recently released report by Verizon, in the year 2013, 92% of data- breaches were perpetrated by outsiders while 84% of attackers were able to compromise their targets in seconds, minutes or hours, however 78% of data-breach incidents took weeks, months or years to discover. This leaves a significant window that is used by the attackers leaving the organisations vulnerable during this period which can be more than years.

APTs have both the capability and the intent to persistently and effectively target a specific entity. The motive behind such threats is to steal confidential data and information from a specific person. For instance, this person could be an employee of a large organization be it a bank or a government body. APT attacks target organizations in sectors with high-value information, such as National defense, aerospace, oil and gas, manufacturing, banking, financial services, and insurance among others.

While you don't know how the APT against your company is working, a detection process require a deep analisys and correlation of suspicious events in your IT infrastructures.

To do this, CloudWALL Italia offers an innovative event and incident management in the cloud, able to help you in analyzing and correlating events to detect incidents and suspicious activities.

CloudWALL LOG | Event Log Management is the enterprise service that enables you to gain insights from your data without having to wait for hardware or staffing resources. Use CloudWALL LOG to prevent outages, troubleshoot problems and investigate security incidents, in real time. Do all of this regardless of where your data is generated.

Find more details at www.cloudwall.tk/log .

IDC survey finds DNS servers still sitting ducks


DNS servers remain an unprotected sitting duck in many organisations despite good awareness of the risks posed by external attacks, a survey carried out by IDC for EfficientIP has found. IDC's survey of 244 IT staff in the US, UK and France suggests a paradox in the rise in importance of DNS infrastructure; organisations know how important they are and yet often use older and inadequate forms of protection such as conventional packet firewalls to keep them safe.

Anxiety about the possibility of a DNS attack was high with 63 percent of respondents in France describing it as significant or very significant, ahead of 50 percent in the US and 47 percent in the UK. The most often mentioned effect of an attack was disruption to the business, with the leakage of sensitive customer data, reputational damage, and legal issues not far behind on the list of worries.

CloudWALL DNS | Domain Name Security is the DNS security platform in the cloud that prevent DDoS and other DNS-specific attacks.  CloudWALL DNS | Domain Name Security offers specific DNS security features, enhanced performance and availability within an open architecture.

CloudWALL DNS | Domain Name Security provides a globally load-balanced DNS solution that addresses the capacity, scalability and reliability needs of any customer. Leveraging a global Any-cast mesh infrastructure,  CloudWALL DNS | Domain Name Security eliminates any single point of failure. This architecture ensure availability of your domain name infrastructure and the ability for your users to get in your application and services 24x7x365 from anywhere in the world.

Find more details at www.cloudwall..tk/dns .

2014-07-03

Russian hackers the biggest threat fr UK Cyber Cop


The biggest cyber security threat facing the U.K. and Europe is from Russian hackers, a top British cyber official has said. Speaking at a cyber-security conference last week in London, Lee Miles, Deputy Head of the U.K. National Cyber Crime Unit, emphasized that most of the significant cyber security threats his office works on emanate from Russia.

Sally Scutt, Deputy Chief Executive of the British Banker Association, said at the same conference that foreign governments were looking for ways to defraud banks and hold them to ransom. She wouldn’t elaborate. She said that most of the banks her association represents, some 180 of them, have been on the receiving end of cyber-attacks. She added that banks have been investing heavily in cyber defense, and that some 70% of Bank CEOs identify cyber security as major problem.

Through a wide offering of cloud-based security solutions CloudWALL Italia allow company to enforce their defense lines against cybercrime with a scalable and flexible "software-as-a-service" approach.

We are focused on delivering security services that meet your requirements, are fully integrated into your organisation and provide all the benefits of a cloud delivery model, while managing data privacy, residency and industry compliance. We are providers of leading Cloud Security Technologies and best practices to enable channel partners, resellers and service providers to quickly deliver and onboard users to a Cloud-Based Security Portfolio of service offerings.

Find more details at www.cloudwall.tk

Cloud technologies as a risk to your business


From Google Docs to Dropbox, these programs make it easier for employees to access data on a range of devices in multiple locations.

This could be anything from sharing content to sending internal messages, uploading pictures to storage and backing up data. But with more and more people using this technology, transferring data to cloud technology can put security at risk, without even realising they are doing so.

Many employees may not even realise they are putting their companies’ data at risk by using programs and applications like iCloud, Dropbox, and Evernote – but these are all cloud-based services that have the potential to be hacked. If employees use them to store valuable data, it poses big security risks.

This is the main reason why at CloudWALL Italia we offers an innovative cloud-based solutions that supply users with access anywhere and anytime to their documents and file and to share them with collegues and partners while CIOs avoid the headache thanks to strong encryption and full tracking of accesses to files and documents.

CloudWALL SFS | Secure File Sharing provides the ability to utilize cloud technologies while retaining that precious right we call privacy. Our zero-knowledge privacy and encryption environment ensures only you can see your data. No one else can gain access.  CloudWALL SFS | Secure File Sharing gives you the power of control and ownership over all your data.

Find more details at www.cloudwall.tk/sfs.

Canada’s Anti-Spam Law Takes Effect


Institutions or individuals fond of sending spam mail to Canadian electronic mailboxes should ought to think twice sending those missives or otherwise risk getting sued in court for millions of dollars. Canada's new anti-spam law (CASL) already took effect on Tuesday. 

Essentially, the CASL law bars businesses and organisations from sending commercial electronic messages, including texts, emails and social media messages, without first seeking and receiving the recipient's approval. Companies violating the new legislation can be fined by as much as $10 million for sending unsolicited emails. 

Anyway, for those who are not living in Canada, CloudWALL Italia offers his fully cloud-based Spam Prevention and Mail Content Filtering solutions. Email is the most important means of communication in today’s business world. Spam remains however the most serious threat to productivity and resource efficiency in email communication. Cyber-criminals are motivated by financial gain, the challenge, ideology or simply mischief.  

CloudWALL MCF | Mail Content Filtering works for you directly from the cloud and applies its proprietary self-learning smart technologies to filter all incoming email and to prevent spam and malicious messages from reaching your mail systems.

Find more details at www.cloudwall.tk/mcf.

Phishing websites up 10% in Q1 2014


The number of overall phishing sites observed in the first quarter of 2014 was 125,215, marking a more than 10 percent increase over the final quarter of 2013, during which 111,773 phishing sites were observed, according to the APWG Phishing Activity Trends Report for the first quarter of 2014.

The U.S. hosted more than 40 percent of those sites in each of the first three months of the year, according to the report. Close to 50 percent of phishing attacks were aimed at payment services in the first quarter of 2014, making it still the most targeted industry, and the financial industry was a target about 20 percent of the time, according to the report. The ISP, gaming, auction, government and social networking industries were each targeted less than 10 percent of the time.

To protect their users from Phishing attacks, CloudWALL Italia offers an innovative strong authentication platform in the cloud to enforce authentication processes for protected resources. CloudWALL OTP | One Time Password provides the fastest path to identity management and strong authentication in the cloud with an on-demand solution consisting of single sign-on, multi-factor authentication, directory integration and user provisioning.

CloudWALL OTP | One Time Password  delivers unparalleled usability by working with all major smartphone platforms and letting users to perform multi-factor authentication with the click of a button to any of your applications and services by integrating your existing Directory Services.

Find more details at www.cloudwall.tk/otp.

Critical flaws in Wordpress Plugins


If you own a WordPress site, make sure you are staying on top of updates—not just for the core platform, but for all the themes and plugins, too. WordPress powers over 70 million Websites around the world, making it an attractive target for cyber-criminals. Attackers frequently hijack vulnerable WordPress installations to host spam pages and other malicious content. Researchers have uncovered a number of serious vulnerabilities in these popular WordPress plugins over the last few weeks.

WordPress has a fairly painless update process for its plugins as well as core files. Site owners need to regularly check for and install updates for all the updates. It's also worth checking through all the directories, such as wp-includes, to make sure unknown files haven't taken up residence.

CloudWALL MDS | Malware Detection Service allows organizations to proactively scan their web sites for malware, providing automated alerts and in-depth reporting to enable prompt identification and resolution and enables organizations to protect their customers from malware infections and safeguard their brand reputations. Organizations that use CloudWALL MDS will be able to quickly identify and eradicate malware that could infect their web site visitors and lead to loss of data and revenue.

Find more details at www.cloudwall.tk/mds.

New site catalogs XSS vulnerabilities


A new online archive is gaining popularity among security researchers as a go-to source to anonymously submit cross-site scripting vulnerabilities uncovered from across the Web. In less than two weeks, the site has amassed enough reported vulnerabilities to cast doubt on the security of dozens of high-profile companies' websites.

Having only received its first confirmed submission on June 18, XSSposed.org has tallied more than 300 confirmed cross-site scripting (XSS) vulnerabilities across hundreds of sites since its inception.

A typical submission provides the vulnerable URL, information on when the vulnerability was verified by the site's as-yet-unnamed administrators, whether the flaw has been fixed since it was first disclosed and the Google and Alexa rankings of the vulnerable domain.

CloudWALL WAF | Web Application Firewall protects Web applications at the very edge of the Internet as opposed to inside the datacenter. Our solution shields an organization’s network from the growing number of application-layer attacks and prevents the loss of valuable corporate and customer data. In addition to proven attack defenses, the CloudWALL WAF | Web Application Firewall aids in compliance with information security regulations, such as PCI-DSS.

Find more details at www.cloudwall.tk/waf

Android RAT attacks mobile banking apps


A new remote access Trojan malware for Android devices, dubbed com.II, is threatening users’ mobile banking data, SMS messages and contact lists.

According to a blog by security vendor FireEye, the offending RAT is able to disable anti-virus systems Android users have in place, before scanning for banking apps and replacing them with fake ones. The malware then installs malicious app updates, steals and sends SMS messages and gains access to contact lists.

CloudWALL MDM | Mobile Device Management delivers the first ever cloud-based SaaS (Software-as-a-Service) security for mobile devices, including smartphones and tablets. Our platform is hosted on Amazon cloud, providing the highest level of readiness and scalability protection against cyber threats anytime, anywhere. By it mobile antivirus protection or device management, CloudWALL MDM | Mobile Device Management brings the best mobile security solutions with no compromise on quality of service.

Find more details at www.cloudwall.tk/mdm

DDoS is a key threat for 58% of companies


The past few years have seen rapid progression in the scale and complexity of Distributed Denial of Service (DDoS) attacks, making them one of the biggest security concerns for business organisations. A study conducted by BT has revealed that 36% of UK companies rank DDoS attacks among their key concerns and the proportion is even higher on a global scale (58%).

The survey involved IT managers from 11 countries, gauging their attitudes to DDoS attacks and assessing their preparedness to deal with such incursions. BT found that 41% of companies had become the target of a DDoS attack in the past year and over 75% of them had been subjected to attacks at least twice. For 20% of enterprises, the cyber offensive had taken their systems offline for a whole working day.

CloudWALL DOS | Denial of Service Prevention offers 24x7 DDoS protection from the cloud. Our cloud-based protection blocks high-bandwidth DDoS attacks that flood your network as well as low-bandwidth, hard-to-detect attacks that bypass existing security devices like firewalls and intrusion prevention systems, and target the applications that keep your business running.  

With a virtually unlimited mitigation capacity working on our 17 data centers around the world, you can rely on our fully reduntant datacenters to ensure network availability of your critical systems and services.

Find more details at www.cloudwall.tk/dos