Skip to main content

Ever got hacked by your Anti Virus?

I just got the funniest call from a client, back story; we're doing a compliance audit for a customer. In doing so, we reviewed some security control integration, including integrating Slack notifications for failed attempts on network-attached devices. (This small detail is amusing in a second)

Our client's Slack kept reporting a Windows machine brute forcing failed login attempts on different network devices. Well, in this land of Mac computers, just like with many Mac-only organizations, there's always the one accounting PC that runs the Windows-only accounting software. 

However, in this case, the one PC's AVG install was the culprit for all of the Slack alerts for failed login attempts from different devices on their network. 

Our client's head of IT needed clarification about why AVG was port scanning and brute-forcing his internal network and did some research to learn about AVG's Traffic Inspector Tool, only to find out that it is indeed its intended function. 

I feel bad because it was a false positive, but it's nice to know all the new alerting was making management more painless for our client, so at least we did our job, right?

Comments

Popular posts from this blog

Why traditional Pen Testing is dead.

Annual, bi-annual, and quarterly penetration testing schedules will be a thing of the past.  The advent of sophisticated cyber threats has necessitated a paradigm shift in vulnerability management. In this transformative digital era, the static, once-a-year model of traditional penetration testing is becoming increasingly obsolete. Instead, it's time for businesses to embrace a dynamic model of continual vulnerability detection and mitigation - Penetration Testing as a Service (PTaaS) by Xcape, Inc. This innovative service combines the precision of automated remote pen testing with the strategic oversight of seasoned penetration testers, creating a comprehensive solution for the latest cybersecurity concerns. The Case for Internal and External Network Testing In a conventional cybersecurity setup, the focus is often on safeguarding the external network, the so-called perimeter. However, this perimeter-centric approach, while essential, is not sufficient in today's threat land...

Revolutionizing Security: Embracing PTaaS for Agile Risk Management and Maturing Security Programs

Organizations face constant threats to their information systems and data in today's rapidly evolving digital landscape. Traditional quarterly pen testing, although valuable, may no longer be sufficient to safeguard against emerging vulnerabilities adequately. This article explores the concept of Pen Testing as a Service (PTaaS) imagined by the team at Xcape, Inc. , and its potential to revolutionize how organizations manage risk and strengthen their security programs. PTaaS offers a proactive and continuous approach to vulnerability management and risk mitigation by establishing a collaborative relationship between information security teams and IT leads. The Limitations of Traditional Quarterly Pen Testing: Traditional quarterly pen testing has been a staple in organizations' security strategies, providing valuable insights into vulnerabilities and weaknesses. However, the rapidly changing threat landscape and evolving attack vectors render this periodic approach inadequate....