This was a fairly quiet week as organisations prepare for summer breaks. Even the normal traffic around Black Hat and Defcon has been much lower than in previous years. One likely cause is the increased number of security conferences this year.
Qualys published details of a vulnerability in OpenSSH called regreSSHion. It claims that it has the potential to be as far-ranging and disruptive as Log4J. What will worry many is that this is not a new vulnerability. Instead, it was previously dealt with but reintroduced due to new changes to the OpenSSH code. The company has called for better regression testing for software patches and updates.
Adaptive Shield has expanded its operations in France and promoted Albert Anconina from Country to Regional Director. The expansion comes as a result of increased sales activity and a need to better address the needs of customers.
Security training company Junglemap has announced that the second quarter sales of its products are up 35%. This follows a 20% increase in the first quarter. It shows that there is still a strong demand for training products in the security and compliance space. Junglemap has also added an AI element to its training platform to help courseware developers deliver better products.
NIST has picked Post-Quantum to join the National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography (PQC) project. The project is focused on helping organisations migrate to a new world of cryptography.
The NCA joined with other law enforcement agencies to help degrade illegal versions of the penetration testing solution, Cobalt Strike. Working with Fortra, who developed Cobalt Strike, almost 600 instances were taken offline, dealing a blow to cybercrime gangs who use it to attack organisations.
Europol
Europol has warned that privacy-enhancing technologies such as Home Routing limit law enforcement’s ability to gather evidence. The paper is aimed at legislatures, national authorities and telecommunication service providers. It wants them to mitigate the challenge that Home Routing poses to lawful interception. It also suggests ways to safeguard privacy while not impacting investigatory powers.
It is an interesting intervention by Europol but again raises the problem of personal privacy and protection versus the right of law enforcement to access personal communications. As new PET technologies arrive and are adopted by citizens and criminals, this will be a major battleground for legislators.
ManageEngine
ManageEngine held its 2024 User Conference in Mexico and claims it was a big success. The company announced that its sales grew 20% in the first half of 2024 and expects that to continue throughout the rest of the year. It also focused on new product updates at the conference, such as ADSelfService Plus, Identity360, and SaaS Manager Plus.
ThreatQuotient
With the Paris Olympics just a few weeks away, Marc Solomon, CMO at ThreatQuotient, published a blog about how intelligence sharing can help keep major worldwide sporting events on track. The blog is timely if a little late to the market. Other security companies have published blogs about the security threats to the Paris Olympics for several months.
Solomon calls out previous attacks on the Olympic Games in Beijing, Sochi, Rio and Pyeongchang. The latter caused serious issues with the opening ceremony, one of the most prized parts of the Olympic Games by host countries. He also warns that it is important to focus on events outside the games, such as social engineering, phishing scams and misinformation targeting attendees.

















