Search/emc
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
elan match-on-chip fpr solution firmware
Connections
174 relationships
Hacker Conversations: Tal Kollander’s Journey From Black Hat to Hack Blocker
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so. Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers. A ‘bad’ hacker accesses a computer for personal gain: such as money, kudos, or political advantage. These are black hat hackers. They do not report their findings to the computer owner, but they may circulate or sell the access method to other hackers or brokers on the criminal underground. The two basic categories of computer hacker can thus be viewed as either moral or immoral. But just as morality has a third category, amoral (neither one nor the other, perhaps both), so there is a third color to hackers – grey hats who play both sides, sometimes white and sometimes black. However, not all black hat hackers are bad people. Good people can be pressured or brainwashed by their government to hack core targets in foreign countries. In some countries they are persuaded it is a patriotic act for the sake of their country, and in other countries they can be threatened with dire consequences for both themselves and their families if they refuse. It is the act, not the psychology of the person, that defines the hacker. This clear categorization assists in classifying edge cases. A pentester working with the agreement of the computer owner is not a hacker. A pentester working without that agreement is a hacker, even though he might be a moral white hat hacker. A nation state actor, whether working for the NSA, GCHQ, FSB, MSS or IDF, is automatically an immoral black hat hacker when he doesn’t have authorization from the target computer’s owner. Patriotism is not a factor in hacker classification. Becoming a hacker Kollander was too young to recognize it was hacking when she first started. She was just a girl doing Flash gaming on the internet and was in first place. “One day I woke up to find that I was no longer in first place; I was second. Someone had come out of nowhere. So, I said to myself, he must have cheated. And I wanted to know how.” Intense and ongoing curiosity was a key factor in creating the young hacker. It’s what drove her to understand computer hardware and software at a deep level, so she could answer the continuous questions: why did that happen, what if I do this, what else is over there or hidden under here…? This was the initial trigger – the same trigger that created most young hackers: curiosity within gaming. “In one game, I contacted one of the other players, and we became friends. Then we used ICQ and we became good friends. Together we built something to help us win at gaming and earn prizes.” Later, they built something else that would prevent anyone else doing the same thing, and they sold it to the companies. “That’s how I earned my first million dollars”, she comments. She got her first computer when she was 13, during junior high and high school. She learned basic coding, first html and then Pascal, C and C#, and was taught at school how to build a project. “But remember,” she says, “when you are hacking, you don’t go to the things you know. There are other things, other corners you need to see, what’s beyond the visible and obvious, what’s behind that.” This curiosity didn’t just stay within gaming. Social media arrived with a new challenge to her curiosity. Another friend had her Facebook account hacked. “I looked at Facebook and discovered how easy it was to hack social media back then; and it’s still easy-ish today. From there, one thing led to another, and I always wanted to do it bigger and wider and to get into new areas.” In my teenage years, she says in her LinkedIn profile, I was a professional hacker, always on the hunt to crack open what seemed impossible, always on the lookout for IT challenges. “What got me into this? The money was good, but it was a side effect. I was just curious to do so many things. I was curious to take advantage of games, to break the email server, to get into the bigger companies that claim they are secure. I wanted to go against the odds. If somebody said, ‘You can’t do this’, it became my drive. All it took was for someone to tell me this can’t be done, and I would want to do it.” Then everything changed. Military service, compulsory in Israel, beckoned and she joined the Army. The Army factor “When I joined the Army, I took the fighter pilot course, and then I continued to the computer units – first the IDF’s Mamram computer unit, and then the Rafael Advanced Defense Systems. I became a hacker for the IDF. Instead of getting another million dollars in the bank, I got 100 bucks per month – which was very embarrassing, but it was the money you got in the Army back then.” The IDF adopted her skills but changed the onus from using them for her own benefit to using them for her country’s benefit. “Start helping your country now, start helping us protect our weapons, the Iron Dome or whatever. There were numerous projects where I needed to think like a hacker in order to protect them. I had to be way more sophisticated than a regular pentester. I had to hack into our own critical infrastructure and super high clearance networks to learn how to stop them from being hacked by the country’s enemies.” The experience changed her mindset. “Doing this for the Army and my country changed me. Instead of breaking computer networks, I started wanting to protect them. That was the ‘wow’ moment for me. Oh, wow, I can actually do something good with my abilities.” Becoming legit With this change in mindset, she began her career in defensive cybersecurity. She left the IDF in 2011 and became deputy CISO at MalamTeam Ltd, which could be described then primarily as an IT integrator and outsourcing provider, and now as one of Israel’s national IT backbones. One year later she became security architect and CISO at the Israeli subsidiary of Avnet. In 2013 she moved to EMC and became Dell EMC’s IT security architect and CISO following the 2016 acquisition by Dell Technologies. This time she stayed for a total of 5 ½ years – but it’s clear she still had the heart and mindset of a hacker. In May 2019 she co-founded and bootstrapped a firm called Gytpol along with Gilad Raz and Yaakov Kogan. In September 2025, Gytpol changed its name to Remedio and raised its first external funding of $65 million. Kollander is both CEO and CISO at Remedio. “We were under the radar for several years but were now ready for more rapid expansion,” she explains. Within months of that funding, the firm doubled in size. “At Remedio, we want to teach you how hackers operate. Because you may have the best EDRs or whatever in the market, but you still get breached, you still get hacked. Once hackers find an entry point, they move laterally abusing configuration and compliance drifts.” Configuration drift is unseen but almost inevitable in modern infrastructures. It is the unnoticed, slow but incremental process of small changes accumulating until the system no longer matches its original specifications or deployment configuration. Users don’t see this, but hackers find it. “Ninety-nine percent of the time, you will find hackers move laterally, obviously faster today with AI, but they move laterally abusing something that Remedio not only knows about, but can fix,” she says. “We don’t want to just find these problems before the hackers do; we want to fix them. The company is my family, but the customers are my drive. We’re almost like the hackers themselves seeking out these flaws but fixing them before they can be abused. We fill that gap between just knowing about something and addressing it.” She understands the hackers because for many years she was one. She understands how to fix these problems because for the last 15 years she has been a cybersecurity defender. Today, Kollander is no friend to black hat hackers. Even though she grew up among them, she wants things to change. “I think people, inside, are good. Maybe it’s the environment they live in or the brainwashing they receive, but people can be good. It’s patience that is hard.” Related: Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker Related: Hacker Conversations: Joey Melo on Hacking AI Related: Hacker Conversations: Inti De Ceukelaire, Raging Against the Machine Creatively
securityweek.comJul 28, 2026extracted
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. The monthly report aggregates security advisories from major infrastructure vendors and highlights the vulnerabilities administrators should prioritize based on a flaw's exploitability, exposure, and real-world risk rather than severity scores alone. The inaugural July 2026 InfraTrust Pulse by Paul Asadoorian, Principal Security Researcher at Eclypsium, tracked 61 infrastructure advisories from 14 vendors, including six critical advisories and 26 remotely exploitable, unauthenticated vulnerabilities. The report also highlights several advisories containing actively exploited vulnerabilities or flaws tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog. Eclypsium also argues that organizations should prioritize vulnerabilities based on exploitability, reachability, and exposure rather than CVSS scores alone. The focus on infrastructure security comes as Russian and Chinese state-sponsored threat actors have increasingly targeted vulnerable network edge devices. In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers, including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typhoon. What to patch first The report highlights several advisories that admins should prioritize because they affect internet-exposed infrastructure, are already exploited, or can be compromised remotely without authentication. Below are the infrastructure advisories Eclypsium says administrators should prioritize based on active exploitation, exposure, and the potential impact of a compromise. In SonicWall's case, attackers were exploiting the SMA1000 flaws, tracked as CVE-2026-15409 and CVE-2026-15410, to install custom malware weeks before SonicWall disclosed the flaws and before they were added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The Fortinet FortiSandbox advisories (FG-IR-26-100 / FG-IR-26-141) include two older critical command injection vulnerabilities tracked as CVE-2026-39808 and CVE-2026-25089. While these vulnerabilities were disclosed in April 2026 and June 2026, they were later added to CISA's KEV catalog on July 16, after exploitation was detected. While these advisories were not published in the 30-day reporting period, Eclypsium highlighted them because organizations may not have patched them or known they were exposed to attacks. "These two Fortinet CVEs were in advisories released before our 30-day window opened. Still, we are including them because CISA added both to the Known Exploited Vulnerabilities catalog on July 16, 2026, with a federal remediation deadline of July 19 under BOD 26-04," explains Eclypsium. The Dell advisories (DSA-2026-240 and DSA-2026-317) address critical vulnerabilities in EMC Networking OS10 and SmartFabric Manager. Eclypsium notes that the OS10 advisory alone includes hundreds of upstream fixes, illustrating that network operating systems are full Linux distributions with large attack surfaces. The F5 BIG-IP advisory (K000153397) addresses critical unauthenticated vulnerabilities affecting internet-exposed application delivery controllers (ADCs) and load balancers. Eclypsium highlights these devices because they frequently sit at the edge of enterprise networks, making them attractive targets for attackers. The Juniper Networks advisory (JSA110083 and JSA110086) addresses remotely exploitable flaws in Junos OS that can crash affected routers and switches, potentially disrupting network availability. The NVIDIA advisory (NVIDIA Security Bulletin 5865) addresses vulnerabilities in BlueField DPUs and ConnectX SmartNICs used in AI and data-center infrastructure. Eclypsium also noted firmware and hardware vulnerabilities, warning that updates for these components commonly lag behind upstream security fixes because they depend on hardware vendors to integrate and distribute them. As an example, HP's Poly Video advisory shipped four months after an included Qualcomm GPU driver vulnerability (CVE-2026-21385) had already been exploited in attacks and added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Unlike many vulnerability roundups that count individual CVEs, InfraTrust tracks vendor advisories because a single infrastructure advisory can contain dozens or even hundreds of vulnerabilities. While the July report contains six critical advisories, it also identifies 26 vulnerabilities that can be exploited remotely without authentication, noting that an internet-reachable flaw with a lower CVSS score may present a greater risk to organizations than a higher-scoring vulnerability that requires an attacker to have local administrator access. July 2026 infrastructure reference Below is a complete list of the 61 infrastructure advisories tracked by Eclypsium in its inaugural July 2026 InfraTrust Pulse report. The table includes the affected vendor and product, advisory identifier, severity, whether the advisory contains an actively exploited vulnerability, and a brief explanation of why it matters. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 22, 2026extracted
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support
The new release adds automated replication, support for newer VMware vSphere and Proxmox versions, and modern authentication for faster, safer recovery. Sparks, Nevada – April 3rd, 2026 – NAKIVO Inc., trusted by over 16,000 organizations in 191 countries, announced the general availability of NAKIVO Backup & Replication v11.2, focused on fast, reliable, and proactive data protection. As ransomware attacks evolve and downtime costs rise, v11.2 provides IT teams with tools to quicken recovery, support next-generation infrastructure, and maintain secure data protection without added complexity. Automated Real-Time Replication At the core of v11.2 is an automated real-time replication engine. It keeps replica VMs synchronized with production workloads, allowing organizations to fail over to a recent replica within minutes after hardware failures, ransomware, or human error. For businesses where every minute of downtime carries measurable financial or reputational consequences, this capability closes one of the most dangerous blind spots in traditional backup strategies: The window between the last scheduled job and the moment of failure. Support for VMware vSphere 9 and Proxmox VE 9.0 and 9.1 Keeping your backup stack aligned with hypervisor versions is mission-critical for teams managing VMware, Proxmox, or hybrid environments. NAKIVO Backup & Replication v11.2 addresses that directly while also tightening security and laying the groundwork for faster disaster recovery. Full VMware vSphere 9 Support The most significant update for VMware administrators: v11.2 delivers complete, production-ready support for vSphere 9, including vCenter Server 9.0.1.0, ESXi 9.0.1.0, and VDDK 9.0.1.0. Earlier builds introduced initial compatibility, but v11.2 provides full readiness, enabling teams to upgrade their VMware infrastructure with confidence that NAKIVO will operate without disrupting existing jobs. All core capabilities are fully operational under vSphere 9: Agentless image-based backup and replication using Changed Block Tracking (CBT) for efficient, low-impact incrementals Instant VM recovery to restore workloads in minutes, not hours Granular file-level and application-object recovery for Exchange and SQL workloads, without restoring the entire VM Built-in DR orchestration with failover, failback, and non-disruptive testing via Site Recovery Ransomware resilience through immutable backups, AES-256 encryption, air-gapped copies, and pre-recovery malware scanning Fast, deduplicated, compressed backups to minimize storage footprint across repositories For organizations tracking the licensing shift away from standalone vSphere Standard and Enterprise Plus editions toward VMware vSphere Foundation 9.0, this update ensures NAKIVO keeps pace with where VMware is heading. NAKIVO v11.2: OAuth 2.0 authentication, immutable backups, real-time replication, and ransomware resilience. Stay ahead of evolving cyber threats with enterprise-grade security. Start your 15-day free trial now Proxmox VE 9.0 Support, with 9.1 Already in Scope NAKIVO's Proxmox support continues to mature. v11.2 brings full compatibility with Proxmox VE 9.0, and support for Proxmox VE 9.1 is already built in, letting Proxmox environments upgrade without risking protection gaps. For environments running Proxmox at the edge, in cost-sensitive production, or as a VMware alternative, the full feature set includes: Agentless host-level backup and replication with no guest agents required, keeping VM overhead minimal Block-level incrementals via native change tracking, matching the efficiency of CBT in VMware environments Instant VM and file-level recovery for rapid restoration of individual machines or specific files Automated verification with screenshot confirmation to validate recoverability without manual intervention Immutable backups on S3-compatible and object storage targets, including AWS S3, Wasabi, Azure Blob, and Backblaze B2 AES-256 encryption at source, in transit, and at rest with air-gapped copy options via tape or detached storage For hybrid environments running VMware and Proxmox side by side, NAKIVO's unified management interface provides a single workflow that covers both platforms, which matters as infrastructure grows in complexity. Ransomware Defense Across the Board Ransomware protection in v11.2 is integrated into the architecture rather than isolated as a single feature. Immutability is supported across a wide range of targets, including AWS S3, Wasabi, Azure Blob, Backblaze B2, HPE StoreOnce, NEC HYDRAstor, and Dell EMC Data Domain. Pre-recovery malware scanning catches threats before they re-enter production. Air-gapped options — tape, detached USB, or offline NAS — provide a last line of defense when network-connected copies are compromised. "Our priority is to give customers a smooth and secure path forward as their environments evolve," said Bruce Talley, CEO of NAKIVO. "v11.2 focuses on compatibility, security, and consistent performance as virtualization platforms advance." Matt Mitchell, Web Developer at SEHD at the University of Colorado Denver, said: "With NAKIVO Backup & Replication, I can recover VMware VMs within 10 minutes. With data deduplication, we were able to decrease storage space by 80%." OAuth 2.0: Secure Email Notifications by Default v11.2 introduces native OAuth 2.0 authentication for email notifications, replacing the deprecated basic authentication that major providers like Google Workspace and Microsoft 365 are actively phasing out. The shift to token-based authentication removes stored plain-text credentials from the equation, delivering a meaningful compliance and security improvement, particularly for organizations under regulatory scrutiny. HPE StoreOnce users gain full support for VSA Gen 5, improving deduplication appliance integration and repository performance. The platform has also been updated to Java SE 24 and the latest Spring Framework, delivering stability improvements, security patches, and incremental gains in backup and restore throughput — benefits that compound over time in high-frequency backup environments. Enhanced MSP Direct Connect for Multi-Tenant Management Managed service providers running multi-tenant environments gain efficiency through enhanced MSP Direct Connect. The updated interface provides single-pane visibility across multiple tenants, reducing overhead and accelerating response times. For MSPs scaling their service portfolios, this improvement directly supports growth without a proportional increase in administrative burden. The Bottom Line NAKIVO Backup & Replication v11.2 is an operationally important release. It removes the compatibility friction that holds teams back from upgrading infrastructure, strengthens ransomware resilience, and tightens security in areas that are easy to overlook until they become a problem. For VMware administrators preparing for a vSphere 9 migration, Proxmox environments approaching a version upgrade, or any organization seeking to enhance recovery capabilities, v11.2 provides a robust foundation for operational stability. Availability NAKIVO Backup & Replication v11.2 is available now. Organizations can download the fully featured free trial at nakivo.com. Resources: About NAKIVO NAKIVO is a US-based corporation dedicated to delivering the ultimate backup, ransomware protection, and disaster recovery solution for virtual, physical, cloud, and SaaS environments. Over 16,000 customers in 191 countries trust NAKIVO with protecting their data, including global brands like Coca-Cola, Honda, Siemens, and Cisco. Visit: www.nakivo.com Sponsored and written by NAKIVO.
bleepingcomputer.comApr 18, 2026extracted
The £9 billion question: To Microsoft or not to Microsoft?
REGISTER DEBATE SERIES The UK government's five-year Strategic Partnership Agreement (SPA24) with Microsoft is set to see public sector bodies spend around £1.9 billion each year—nearly £9 billion in total over half a decade. It's a vast sum for software and services, and one that deserves close scrutiny. The key question is whether this represents genuine value for taxpayers — or whether it's simply the continuation of the status quo under a new label. Discounts or revenue boost? SPA24 is marketed as delivering "enhanced value," bundling Microsoft 365, Azure, Business Applications, and, for the first time, Microsoft Copilot. Consolidating procurement can simplify operations, particularly for departments managing complex legacy systems. But Microsoft's recent earnings show a 17 percent year-on-year revenue increase, with Azure revenue up 39 percent. Meanwhile, profit remains sky-high: net margins are about 36 percent and have not dipped under 30 percent in more than five years. Revenue growth and margins together are propelling the company’s staggering valuation of more than $3.5 trillion. Against that backdrop, it's fair to ask: are UK public sector negotiators achieving substantial discounts, or is this multi-billion-pound spend helping fuel an already surging profit line? If the savings are minimal or opaque, the deal risks reinforcing rather than challenging entrenched market power – leaving the government with limited choice and little leverage. The Copilot question The inclusion of Copilot, Microsoft's AI productivity tool, adds another dimension. There is no doubt AI-driven features could boost efficiency, but without transparent comparative pricing, it's impossible to tell whether this is an affordable enhancement or a costly lock-in. By adopting Copilot as the default AI engine through SPA24, departments could be committing themselves more deeply to Microsoft's ecosystem —potentially at the expense of open-source or cloud-agnostic alternatives. This "default by convenience" approach risks stifling innovation, reducing future negotiating power, and embedding proprietary systems that are expensive to replace. A government-wide policy on AI adoption, focused on interoperability, data sovereignty, and long-term value, would be a prudent step. CCS: Enabler or status quo guardian? The Crown Commercial Service (CCS) operates SPA24 as part of its framework portfolio. Its role as a trading fund means it takes a small percentage from suppliers — on a £9 billion deal, about £30 million over the contract term. While CCS argues this model supports efficient procurement and risk management, the margin may also create an incentive to preserve vendor stability and the status quo rather than pursue aggressive cost-cutting. What else could £9 billion deliver? The SPA24 framework represents a major commitment of public funds and raises the question of whether the UK taxpayer is truly getting best value. If technology modernisation using other platforms was considered, even a modest 10 percent improvement in replacing Microsoft — around £900 million — could have a major impact elsewhere. It could pay for thousands of additional NHS staff or police officers, modernize critical government IT, or accelerate digital projects in health, transport, and education. Poorly negotiated terms don't just mean lost savings — they represent missed opportunities to improve services and invest in innovation. Is Microsoft the only practical path? Microsoft offers scale, reliability, and familiarity – qualities vital for large organizations delivering essential public services. Migration to alternative platforms is neither simple nor risk-free, and transformation costs can be significant. Yet relying solely on what's familiar risks stagnation. Small-scale pilots, trials of open source software, or hybrid vendor strategies could create competition and generate savings while maintaining service continuity. International examples illustrate both potential and pitfalls: France's Gendarmerie Nationale saved millions by migrating 70,000 desktops to Ubuntu Linux, while Munich's LiMux project faltered due to political changes, interoperability challenges, and weak support. In other words, moving away from Microsoft is possible — but it requires careful planning, skills investment, and strong governance to succeed. Lessons learned or forgotten? The UK has tried to rein in IT costs before. The 2004 Gershon Review aimed to cut back-office inefficiency, and in 2010, the Cabinet Office under Francis Maude imposed a moratorium on new IT spend to drive cost discipline and encourage competition. As Deputy Government CIO and Director of IT Strategy & Policy during that period, I helped deliver the moratorium and saw first-hand how it could strengthen value-for-money oversight. It's disappointing to see how many of those hard-won disciplines appear to have been eroded. Today, while the structures for efficient procurement remain, the drive for genuine competition and innovation seems to have been squandered. Towards a more balanced approach Securing real value from major technology deals like SPA24 requires far greater transparency about the discounts achieved, ideally via independent review. The government should run pilot programmes to test credible alternatives, with clear metrics and exit strategies to keep options open. Shared accountability across HM Treasury, the Cabinet Office/DSIT, CCS, and the National Audit Office is essential, with regular testing of commercial arrangements for efficiency – not just compliance. Above all, procurement should focus on competition and open standards, ensuring the public sector retains bargaining power and avoids over-dependency on a single supplier. Conclusion – pragmatic, complacency or scrutiny? SPA24 brings tangible benefits in terms of scale and service integration, and Microsoft's deep presence in government IT makes it a logical partner. But pragmatism must not become complacency. Without ongoing scrutiny of pricing, supplier choice, and transformation incentives, taxpayers may end up paying a "convenience premium" rather than securing the best possible deal. Given the scale of expenditure, even a modest improvement in terms could unlock funding for vital public services. It is time for policymakers and watchdogs to revitalise genuine value-for-money oversight - ensuring the public purse is not just a revenue stream for global tech giants, but a catalyst for smarter, more sustainable digital transformation. ® The Register presented an opposing view yesterday and readers can have their say on Friday. Bill McCluggage is a seasoned technology advisor and senior executive with extensive experience across both public and private sectors. He served as the first Chief Information Officer for the Irish Government beginning in 2013, previously holding roles such as Deputy UK Government CIO, Executive Director for IT Policy & Strategy in the UK Cabinet Office, Director of eGovernment and CIO in Northern Ireland, and CTO for EMC (Dell EMC) Systems in the UK and Ireland.
go.theregister.comAug 14, 2025extracted