fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Hackers Steal StormShield Firewall Source code In Data Breach

Hackers Steal StormShield Firewall Source code In Data Breach

Leading French cybersecurity company StormShield disclosed that their systems were hacked, allowing a threat actor to access the company’s support ticket system and steal source code for Stormshield Network Security firewall software.

StormShield is a French cybersecurity firm that develops UTM (Unified Threat Management) firewall devices, endpoint protection solutions, and secure file management solutions.

StormShield’s SNi40 is the only industrial firewall to receive First Level Security Certification (CSPN) from France’s Agence nationale de la sécurité des systèmes d’information (ANSSI).

StormShield discloses a data breach

In a new security advisory released today, StormShield disclosed that their technical portal used as a support ticket system had been breached and may have allowed threat actors to review technical exchanges.

“Recently, the Stormshield teams detected a security incident that resulted in an unauthorized access to a technical portal used, in particular, by our customers and partners for the management of their support tickets on our products.”

Also Read: How to Send Mass Email Without Showing Addresses: 2 Great Workarounds

“Personal data and technical exchanges associated with certain accounts may have been consulted. We immediately alerted the account owners on the portal and we notified the French authorities. As a precaution, the passwords of all accounts were reset and we applied additional measures to the portal in order to reinforce its security.”

“All the support tickets and technical exchanges in the accounts concerned have been reviewed and the results have been communicated to the customers,” StormShield disclosed in the security advisory.

StormShield discovered that threat actors accessed some of the source code for their SNS (Stormshield Network Security) source code during the attack after further investigation. Their investigations do not indicate that the source code has been modified.

“Further investigations in the context of this incident have revealed the leakage of some parts of the SNS (Stormshield Network Security) source code. This information has also been communicated to our customers,” StormShield warned its customers.

As the Stormshield Network Security (SNS) firmware powers the company’s UTM firewalls, the leak of the company’s source code may make it easier for threat actors to find bugs that attackers can use to exploit the devices. This leak is particularly concerning as StormShield SNS devices are commonly used by the French government, defense agencies, and the European SMB market.

To be safe, StormShield anticipates changing the code signing certificate used to ensure the integrity of the SNS (Stormshield Network Security) firmware releases and updates.

Also Read: How a Smart Contract Audit Works and Why it is Important

After being informed about the attack, ANSSI released a security advisory where they state that they have “decided to place the qualifications and approvals of SNS and SNI products under observation.”

BleepingComputer has contacted StormShield with questions about the attack.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us