Is your pentesting provider moonlighting as a malicious cybercrime group?

Formal and regular penetration testing has become a must-have in the pantheon of security best-practice – but how do you know your pen-testing company isn’t moonlighting as a hacking group, or using its services as a pretext to compromise your network? What should be a clear distinction is anything but, according to a new BlackBerry Cylance report that found common penetration-testing tools are being leveraged as advanced persistent threat (APT) vectors by a range of cybercriminal groups – some of which run parallel operations as purportedly legitimate penetration-testing providers.

Read full article on CSO

 


Date:

Categorie(s):