< ciso
brief />
Tag Banner

All news with #network security tag

175 articles · page 2 of 9

AWS Direct Connect 100G expansion in Lima, Peru

📢 AWS has expanded 100 Gbps dedicated Direct Connect capacity at the Cirion data center in Lima, Peru. This location now supports private connections to all public AWS Regions (excluding China), AWS GovCloud, and AWS Local Zones, and is the first in Peru to offer 100 Gbps with MACsec encryption. Direct Connect provides private, physical links between AWS and customer data centers, offices, or colocation environments to deliver more consistent network performance than the public internet.
read more →

Securing 2026 World Cup Stadium Networks

⚠️ Stadiums hosting the 2026 World Cup face massive cybersecurity challenges as tens of thousands of unmanaged fan devices join venue networks alongside payment systems, displays and operations platforms. Real-time visibility, network segmentation and identity-centric Zero Trust controls are essential to keep fan devices isolated from critical systems. SIEM, endpoint management and automated patching help accelerate detection and response, ensure compliance and reduce the risk of disruptive attacks during matches.
read more →

Governments urge enterprises to improve router security

🔒 A multinational cybersecurity advisory warns that Russian government-sponsored actors are exploiting poorly configured routers and legacy protocols to steal device configurations and credentials. Attackers scan for devices using SNMPv1/v2, default community strings, and vulnerable Cisco features like Smart Install, then exfiltrate config files to attacker-controlled servers. Agencies recommend migrating to SNMPv3, disabling legacy protocols and Cisco Smart Install, enforcing strong passwords and MFA, blocking SNMP at firewalls, updating software, and retiring EOL devices.
read more →

Friday Squid Blogging: Squidbleed Vulnerability

🦑 A decades-old bug in the Squid proxy can leak HTTP request data, a flaw dubbed "Squidbleed." This post mixes a lighthearted squid image with serious security discussion, noting the vulnerability's age and potential impact on privacy. The author also invites readers to discuss other current security news not yet covered.
read more →

Study: Many Free Android VPNs Fail Basic Security

🔎 Researchers tested 281 popular free Android VPN apps using a new framework and found widespread, basic security failures. The study, using MVPNalyzer, identified traffic leaks, plaintext transmissions, weak encryption, and apps that reveal identifying data to trackers. Those flagged have over 2.4 billion installs combined, and several apps enable tunnel hijacking by fetching configuration files in the clear. The paper and appendix list affected apps and the team plans to release the tool for broader use.
read more →

Enterprises favor convenience, increasing lateral movement risk

🔒 Zero Networks’ 2026 report, analyzing 54 trillion activities across 312 enterprise environments, finds that most internal servers remain broadly reachable and rely on legacy protocols. The study highlights that >80% of servers are accessible from anywhere inside networks, with 87% accepting RDP/SSH and 78% reachable via SMB/WinRM, while 43% still use NTLM. Experts warn this widespread internal connectivity enables easy lateral movement for attackers and call for segmentation, identity controls, and containment strategies.
read more →

Top BGP Route Policy Uses by Customer Demand

🛡️ Cloud Router's BGP route policies give administrators programmatic control to filter, modify, and propagate routes using CEL expressions. Customers now use these policies to enforce strict route filtering, implement traffic steering via MED and AS-PATH prepending, and achieve stateful traffic symmetry through BGP community tagging. Policy named sets simplify managing large lists of prefixes and communities across multiple routers.
read more →

Secure container workloads with attribute-based rules

🛡️ AWS Network Firewall now supports container attribute-based rules for Amazon EKS and Amazon ECS, enabling firewall policies based on native container attributes (namespaces, pod names, labels, cluster names) instead of ephemeral IPs. This feature automatically discovers and tracks matching pods, dynamically updates IP-to-attribute mappings, and enriches alert logs with container context for easier troubleshooting and auditing. It integrates with Suricata-compatible rules, exports logs to CloudWatch Logs and S3, and can be configured via the AWS Console, CLI, or SDK with no additional feature charge.
read more →

Amazon Neptune adds dual‑stack IPv6 support

🔷 Amazon Neptune now supports dual‑stack mode, allowing database clusters to accept connections over IPv4, IPv6, or both simultaneously. This enables organizations to adopt IPv6 while preserving compatibility with existing IPv4 deployments. Dual‑stack offers Private mode for internal, non‑internet IPv6 endpoints and Public mode for internet‑accessible IPv6 endpoints to support hybrid and internet‑facing applications. The feature is available in all AWS Regions that support Amazon Neptune.
read more →

Amazon GameLift Servers adds DDoS protection SDKs

🛡️ Amazon GameLift Servers now includes DDoS Protection client SDKs for C# and Unity, enabling developers to protect session-based multiplayer games from denial-of-service and distributed denial-of-service attacks. The service co-locates a relay network with game servers and uses access token-based authentication to allow only authorized client traffic. It enforces per-player UDP traffic limits, offers negligible latency, and is provided at no extra cost to GameLift Servers customers. The new SDKs complement existing C++ and Unreal Engine support and are available in multiple AWS regions.
read more →

AWS Network Firewall changes default stateful action

🚨 AWS Network Firewall now sets the default stateful action for newly created firewall policies to Application drop established (server-directed only), replacing the previous Application drop established (bidirectional). This safer default prevents silent drops of legitimate server-to-client TCP packets (for example, window updates, keep-alives, and resets) that caused intermittent connection issues. No action is required for new policies; existing environments that rely on bidirectional behavior for post-quantum cryptography (PQC) fragmented TLS handshakes should consult the documentation for guidance on switching or adding the to_server flag to TCP drop rules.
read more →

Amazon MQ for RabbitMQ adds private networking support

🔒 Amazon MQ for RabbitMQ now supports private networking connectivity, allowing brokers to connect to private resources in your VPC without exposing them publicly. This simplifies secure access to private identity providers (such as LDAP and OAuth 2.0), other Amazon MQ brokers, or self-hosted RabbitMQ brokers. AWS manages the underlying infrastructure using Amazon VPC Lattice, AWS RAM, and AWS PrivateLink, replacing prior NLB and NAT Gateway workarounds. Private networking is available in Regions where VPC Lattice is supported.
read more →

Cloud Network Insights: Cross-Cloud Network Observability

🔍 Cloud Network Insights is now generally available as a Google Cloud-native solution, delivered in partnership with Broadcom AppNeta, to provide end-to-end visibility across multi-cloud and hybrid networks. It uses lightweight Monitoring Points and active synthetic probes to measure RTT, packet loss, jitter, and application-level metrics like DNS and page-load times. The service integrates with Cloud Monitoring, Cloud Logging, and supports OpenTelemetry, enabling proactive alerting, SLA validation, and rapid root-cause analysis.
read more →

VPC Flow Logs Adds EC2 Tags and Next-Hop Metadata

🔍 Amazon VPC Flow Logs now supports EC2 resource tag embedding and next-hop interface metadata to simplify network monitoring and troubleshooting. With tag support you can include values from network interfaces, EC2 instances, and Auto Scaling groups, removing the need to join log data with external tag metadata. Next-hop metadata captures interface ID, subnet, AZ, VPC, and interface type to clarify traffic paths through NAT Gateways, NLBs, and Transit Gateways.
read more →

AWS May 2026 Security Digest and Updates

🛡️ This monthly AWS Security Blog digest highlights May 2026 posts on AI security, network protection, identity management, compliance guides, and supply chain defense. It summarizes new capabilities, hands-on samples, and workshops that demonstrate practical controls — from Cedar-based policy for agentic AI to URL category filtering in Network Firewall and post-quantum readiness checks.
read more →

Research shows free apps turn smart TVs into proxies

🔍 A reverse-engineered iOS SDK from Bright Data reveals free apps can turn devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic. The SDK, embedded behind opt-in screens, uses peer channels with weak authentication and can bypass VPNs on iOS, allowing background relays that consume home bandwidth. Blocking a handful of SDK domains at the router or scanning apps on managed devices can stop the behavior.
read more →

AI and Evasion Force Rethink of Network Prevention

🔍 For years network security relied on content inspection and static threat intelligence, but the rise of agentic AI and evasive techniques has upended that model. Unit 42 research shows attackers exploit the IP layer and use anonymizers, rapid infrastructure rotation, and AI-enabled stealth to bypass legacy controls. Security strategies must augment deep inspection with real-time IP-layer monitoring and continuous verification to defend at machine speed.
read more →

Enforce First AS to Prevent BGP Path Forgery

🔍 Recent route hijacks exploited unused ASNs and forged AS_PATHs to misdirect traffic and conceal attackers. Cloudflare analyzed incidents reported by Spamhaus and found implausible AS relationships indicating path fabrication, including forged paths that inserted Cloudflare’s ASN. The post explains how enforcing the First AS in an AS_PATH, per RFC 4271 and RFC 7606 guidance, would block such manipulations. Cloudflare also conducted safe tests against Tier 1 peers to measure First AS enforcement and observed variation in vendor and operator behavior.
read more →

Assessment of public Wi‑Fi security in Mexico

🔍 Kaspersky analyzed public Wi‑Fi across Mexico City, Guadalajara, and Monterrey ahead of the 2026 World Cup. The team wardrove to log 84,500 signals and 69,500 unique SSIDs, finding about 82% use WPA2/WPA3 but over 10% are unsecured. WPS was enabled on roughly 45% of access points, often even when WPA2/WPA3 was in use, increasing attack risk. The report also warns of other travel threats like malicious QR codes, public USB chargers, NFC/Bluetooth exploits, and evil‑twin networks. Kaspersky recommends using cellular data or an eSIM and a VPN to stay safe when connecting to public networks.
read more →

AWS Direct Connect adds VIF Rate Limiters

🛡️ AWS Direct Connect now supports Virtual Interface (VIF) Rate Limiters on dedicated connections to prevent a single VIF from consuming all bandwidth and causing congestion. You can cap bandwidth for up to 10 VIFs per dedicated connection with increments from 50 Mbps to 1.6 Tbps when using a link aggregation group. Rate limiting applies to both ingress and egress, and excess packets are dropped. New CloudWatch metrics include utilization as a percentage of configured capacity and dropped packet counts, and the feature is available in all supported commercial and China Regions via console, API, or SDK.
read more →