Security News

Vendor Quickly Patches Serious Vulnerability in NATO-Approved Firewall
2021-03-01 11:24

A critical vulnerability discovered in a firewall appliance made by Germany-based cybersecurity company Genua could be useful to threat actors once they've gained access to an organization's network, according to Austrian cybersecurity consultancy SEC Consult. Genua Genugate is a firewall designed for protecting internal networks against external threats, segmenting internal networks, and protecting machine-to-machine communications.

You don't have clearance for that: Microsoft ups the paranoia with a preview of Azure Firewall Premium
2021-02-17 16:30

Microsoft has unveiled a preview of Azure Firewall Premium, aimed at highly sensitive and regulated environments. Azure Firewall was Microsoft's attempt to sling a virtual arm over the shoulders of harassed administrators while whispering "There now, don't worry about all that pesky firewall configuration stuff, let us take care of it" in its most seductive tone.

Microsoft releases Azure Firewall Premium in public preview
2021-02-16 21:20

Microsoft has announced that the new Premium tier for its managed cloud-based network security service Azure Firewall has entered public preview starting today. The Azure Firewall Premium public preview adds new capabilities required by highly sensitive and regulated environments.

Fortinet fixes critical vulnerabilities in SSL VPN and web firewall
2021-02-07 14:31

The vulnerabilities range from Remote Code Execution to SQL Injection, to Denial of Service and impact the FortiProxy SSL VPN and FortiWeb Web Application Firewall products. Multiple advisories published by FortiGuard Labs this month and in January 2021 mention various critical vulnerabilities that Fortinet has been patching in their products.

Hackers steal StormShield firewall source code in data breach
2021-02-04 18:41

Leading French cybersecurity company StormShield disclosed that their systems were hacked, allowing a threat actor to access the company's support ticket system and steal source code for Stormshield Network Security firewall software. StormShield is a French cybersecurity firm that develops UTM firewall devices, endpoint protection solutions, and secure file management solutions.

If you want to leg it through China's Great Firewall, don't forget to pull on your newly darned Shadowsocks
2021-01-28 02:22

China's recent upgrades to its content-blocking Great Firewall can be circumvented, according to censorship fighters from the Great Firewall Report. Members of the group last year published a paper [PDF] detailing how China had improved the firewall to detect the use of Shadowsocks, a tool for using SOCKS5 proxies outside the Middle Kingdom to avoid the nation's internet blockades.

SonicWall firewall maker hacked using zero-day in its VPN device
2021-01-23 17:14

SonicWall is a well-known manufacturer of hardware firewall devices, VPN gateways, and network security solutions whose products are commonly used in SMB/SME and large enterprise organizations. On Friday night, SonicWall released an 'urgent advisory' stating that hackers used a zero-day vulnerability in their Secure Mobile Access VPN device and its NetExtender VPN client in a "Sophisticated" attack on their internal systems.

SonicWall firewall maker attacked using zero-day in its VPN device
2021-01-23 12:14

SonicWall is a well-known manufacturer of hardware firewall devices, VPN gateways, and network security solutions whose products are commonly used in SMB/SME and large enterprise organizations. On Friday night, SonicWall released an 'urgent advisory' stating that hackers used a zero-day vulnerability in their Secure Mobile Access VPN device and its NetExtender VPN client in a "Sophisticated" attack on their internal systems.

Apple Removes macOS Feature That Allowed Apps to Bypass Firewall Security
2021-01-17 22:42

Apple has removed a controversial feature from its macOS operating system that allowed the company's own first-party apps to bypass content filters, VPNs, and third-party firewalls. Called "ContentFilterExclusionList," it included a list of as many as 50 Apple apps like iCloud, Maps, Music, FaceTime, HomeKit, the App Store, and its software update service that were routed through Network Extension Framework, effectively circumventing firewall protections.

Apple Kills MacOS Feature Allowing Apps to Bypass Firewalls
2021-01-15 17:02

Apple has removed a contentious macOS feature that allowed some Apple apps to bypass content filters, VPNs and third-party firewalls. The feature, first uncovered in November in a beta release of the macOS Big Sur feature, was called "ContentFilterExclusionList" and included a list of at least 50 Apple apps - including Maps, Music, FaceTime, the App Store and its software update service.