Skip to content

We’ve earned the SOC 2 Type 2 attestation

We’re back with an exciting update — we want to inform you that Nord Security, the provider of NordPass Business, has successfully passed the SOC 2 Type 2 audit.

The SOC 2 Type 2 attestation, received not too long after obtaining the Type 1, further underscores Nord Security’s commitment to the highest standards of data privacy and operational excellence.

Let us now explain what this achievement means for NordPass Business and its clients.

Why is passing the SOC 2 Type 2 audit a big deal?

SOC is short for System and Organization Controls, which refers to the framework developed by the American Institute of Certified Public Accountants (AICPA). In basic terms, SOC 2 is a report with an auditor’s opinion that helps verify whether organizations have implemented effective controls and measures to ensure the security, availability, and privacy of customer data.

A company that participates in a voluntary SOC 2 audit and successfully receives certification proves to its customers and stakeholders that it can be trusted to handle sensitive information with the utmost care and responsibility.

The SOC 2 framework is divided into two categories: Type 1 and Type 2. Type 1 focuses on examining whether the organization’s controls and documentation are designed following the relevant trust principles and comply with established standards. Meanwhile, Type 2 delves into the practical aspects, evaluating how efficiently these controls operate in real life.

So, when an organization earns the SOC 2 Type 2 attestation, it means that the organization’s security measures proved to be consistently effective and efficient over time.

What does passing the SOC 2 Type 2 audit mean for NordPass Business?

Receiving the SOC 2 Type 2 attestation is the latest proof that Nord Security’s products, including NordPass Business, are designed with the highest data security standards and are highly effective in ensuring the privacy and confidentiality of sensitive information.

Since 2021, NordPass has been compliant with the ISO/IEC 27001:2017, another internationally recognized standard that verifies the company’s strong information security management system.

In 2022, we passed the SOC 2 Type 1 audit, which confirmed that our organization’s products are designed in line with the relevant trust principles. Therefore, it was only natural that we aspired to undergo the SOC 2 Type 2 audit, aiming to further demonstrate the effectiveness of our security measures. And now, we’ve made it happen.

So, if you are a NordPass Business customer — or someone considering using it in the future — we hope you take this SOC 2 Type 2 attestation announcement as confirmation that we have the necessary measures to protect your sensitive information.

Our goal is to continually improve our platforms to give our customers the peace of mind they expect. So, you can anticipate more updates like this one coming soon.

Stay safe!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

ESET Threat Intelligence unveiling Portal 2.0

Navigating the intricacies of today’s world is a complex task that requires accurate and timely knowledge as well as a contextual understanding of the geopolitical landscape. This becomes particularly sensitive when the digital security of critical infrastructure is considered, specifically for enterprises operating in the sectors of energy, finance, utilities, or petrochemical industries — or even for governmental institutions themselves.

Every day, ESET detects over 300,000 potential threats, providing our customers with unique insights from our own pool of more than 110 million sensors around the world, delivering a global understanding that is the foundation for any organization to anticipate, counter, and contextualize potential threats. Alongside our extensive visibility, ESET has built relevant industry partnerships and honeypots that source data where we don’t have direct telemetry.

The research focus ESET has pursued remains at the heart of the company, which has decades of experience in mapping and tracking major APT groups. ESET has been committed to proactively sharing targeted intelligence with the security community, being one of the most referenced and active contributors to the MITRE ATT&CK knowledge base, serving as a member of the Joint Cyber Defense Collaborative (JCDC) established by CISA, and regularly contributing to the work of law enforcement bodies such as the FBI and national CERTS.

A more intuitive interface for a better user experience

To provide even more comprehensive access to all the knowledge provided by ESET Threat Intelligence, ESET is launching a new portal that allows for a fully automated experience of the platform. From the start, customers can access the terms of agreement, including the NDA, managing licenses, or user activity. The portal also presents an intuitive view of ESET APT and Threat Reports, the latest research blogs and podcasts, and relevant infographics. If subscribed, users can view private reports compiled by ESET Research upon request. Users can also define the periodicity of notifications of new reports, selecting the ones they want to be notified of.

ESET is also bundling its six Threat Intelligence data feeds, allowing customers to choose those that best fit their needs under one unique license. Once the agreement is active, the data feeds are configured automatically by simply enabling them right from the portal.

The new portal also provides ESET Connect-ready APIs, and all functionalities can be easily discovered with a new Online Help section detailing each of the APIs and how to integrate them.

SOC analysts using ETI will also take advantage of ESET MISP as the main integration platform for APT Reports, enabling them to go through the listing of events, run retrospective intelligence analyses and queries, filter results based on labels, and, ultimately, search sightings and find correlation using correlation graphics.

ESET proprietary intelligence data feeds: Real-time global knowledge

Originating from our 13 research centers dispersed globally, ESET Threat Intelligence comprises the knowledge and expertise of ESET researchers into six different and highly curated feeds with unique telemetry that can be accessed based on an organization’s specific needs and size.

Simply put, the feeds are lists of Indicators of Compromise (IoC) and metadata, covering various aspects of cybersecurity, including tracking malicious files, botnets, and APTs; identifying potentially harmful domains or URLs and IPs considered malicious; and tracking the associated data.

To ensure compatibility and easy integration, the feeds are provided in widely used formats, such as JSON and STIX 2.1. Recently, ESET also announced the integration of its proprietary data feeds with the widely used SIEM and SOAR platform MS Sentinel, taking advantage of the built-in TAXII client of Microsoft Sentinel. Other already existing integrations are IBM QRadar, OpenCTI, Anomali, and ThreatQuotient.

Building a long-term strategy

Cyber threats evolve rapidly to stay ahead of emerging technology. ETI sits on top of all the work done at ESET, bringing together ESET’s unique visibility and research not only to provide deep technical analysis but also to provide a wider knowledge through the private APT reports that offer extensive tactical and strategic context to some of the most common questions: Why is this happening and who is behind it?

Moreover, ETI customers also have access to ESET researchers who will be ready to answer any questions arising from these reports, including technical follow-ups for a deeper understanding of the threat landscape.

The new portal will start rolling out in November.

For more information on ESET Threat Intelligence, visit our product page here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Understanding the Use of Captive Portal Detection

In the dynamic landscape of cybersecurity, organizations continually seek innovative ways to safeguard their networks from potential threats. One crucial aspect of network security that has gained prominence is captive portal detection. Today, we’ll delve into the depths of captive portal detection, exploring what it is, how it works, and how organizations leverage it to fortify access to their networks.

Understanding Captive Portal Detection

Captive portal detection is a pivotal component of network security designed to authenticate and authorize users before granting them access to a network. Essentially, it acts as a gateway, ensuring that only authorized individuals can connect to the network. Captive portals are commonly employed in public Wi-Fi networks, such as those in airports, hotels, and coffee shops, to regulate and manage user access.

How Captive Portal Detection Works

  • User Connection:
    • The process begins when a user attempts to connect to a network, often through Wi-Fi.
    • Upon connecting, the user is redirected to a captive portal page instead of gaining immediate access to the internet.
  • Captive Portal Page:
    • The captive portal page typically contains an authentication mechanism, such as a login form.
    • Users must provide the necessary credentials or comply with specific terms and conditions to proceed.
  • Authentication and Authorization:
    • The provided credentials are verified, and the user is authenticated.
    • Authorization is granted based on predefined policies and permissions.
  • Access Granted:
    • Once authenticated and authorized, the user is granted access to the network and the internet.

Organizations’ Use of Captive Portal Detection

  • Enhanced Security:
    • It serves as an additional layer of security by ensuring that only authorized users can access the network.
    • This is particularly crucial in public spaces where open Wi-Fi networks are susceptible to unauthorized access.
  • User Authentication:
    • Organizations use captive portals to enforce user authentication, requiring individuals to log in with valid credentials.
    • This helps in tracking user activities and associating network usage with specific individuals.
  • Policy Enforcement:
    • Captive portal detection allows organizations to enforce network usage policies.
    • Users may need to agree to terms of service, acceptable use policies, or other conditions before gaining access.
  • Guest Network Management:
    • Many organizations utilize captive portals for managing guest access to their networks.
    • Guests are often redirected to a portal where they must authenticate or accept terms, ensuring controlled and secure access.
  • Data Collection and Analytics:
    • Captive portal solutions often come equipped with data collection and analytics tools.
    • Organizations can gather insights into user behavior, preferences, and demographics, aiding in targeted marketing or network optimization.
  • Compliance Requirements:
    • In certain industries, compliance regulations necessitate strict control over network access.
    • Organizations meet these requirements by ensuring that only compliant devices and users connect to the network.

Challenges and Considerations

While this approach offers significant advantages, it comes with its own set of challenges and considerations:

  • User Experience:
    • Redirecting users to a captive portal page can disrupt the user experience, leading to frustration.
    • Organizations must strive to make the authentication process seamless and user-friendly.
  • Security Risks:
    • Captive portals can be susceptible to various security risks, including phishing attacks that mimic legitimate login pages.
    • Robust security measures, such as encryption and multi-factor authentication, are crucial to mitigate these risks.
  • Scalability:
    • Ensuring seamless user authentication becomes more challenging as the scale of the network increases.
    • Organizations must invest in scalable solutions capable of handling a growing number of users.
  • Integration with Existing Systems:
    • Integrating captive portal solutions with existing network infrastructure and authentication systems can be complex.
    • Compatibility and interoperability issues must be carefully addressed during implementation.

Future Trends in Captive Portal Detection

Several trends are shaping the future of this crucial aspect of network security:

  • Integration with Zero Trust Architecture:
    • The Zero Trust model, which assumes no trust by default and verifies every user, is gaining traction.
    • Captive portal detection is expected to integrate seamlessly with Zero Trust architectures to enhance network security.
  • Machine Learning and Behavioral Analysis:
    • Advanced captive portal solutions are incorporating machine learning algorithms and behavioral analysis.
    • These technologies enable the identification of anomalous behavior, enhancing security against emerging threats.
  • Cloud-Based Solutions:
    • Cloud-based captive portal solutions are becoming more prevalent, offering flexibility and scalability.
    • Organizations can centrally manage and deploy captive portals across multiple locations through the cloud.
  • Improved User Experience:
    • Future developments in captive portal detection will focus on improving the user experience.
    • Technologies like single sign-on and biometric authentication may become more prominent to streamline the authentication process.
  • Enhanced Security Protocols:
    • To counter evolving cyber threats, captive portal detection will incorporate enhanced security protocols.
    • This may include stronger encryption, continuous monitoring, and adaptive authentication mechanisms.

Conclusion

In the ever-evolving landscape of cybersecurity, organizations must adapt to new challenges and leverage innovative solutions to protect their networks. Captive portal detection stands as a stalwart guardian, ensuring that only authorized users gain access to valuable network resources. By understanding how captive portal detection works and how organizations are utilizing it today, we can navigate the intricate web of network security and fortify our digital infrastructure against emerging threats. As we look toward the future, the continued evolution of captive portal detection promises to play a pivotal role in shaping the security landscape of tomorrow.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。

23.12.0 ‘Voyager’ released

Changes compared to 23.11.1

New Features

  • Added a new Java SDK which allows customers to access the Comet Server API via JDK version 11+

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

ESET Research: Official Python repository served cyberespionage backdoor, gathered 10,000+ downloads

ESET Research discovered 116 malicious packages in PyPI, the official repository of software for the Python programming language, uploaded across 53 projects. Victims have downloaded these packages over 10,000 times.
The malware delivers a backdoor capable of executing remote commands, exfiltrating files, and taking screenshots. In some cases, the W4SP Stealer or a clipboard monitor that steals cryptocurrency, or both, is delivered instead.
The backdoor component is implemented for both Windows, in Python, and Linux, in Go.

BRATISLAVA, MONTREAL — December 12, 2023 — ESET Research has discovered a cluster of malicious Python projects being distributed via PyPI, the official Python (programming language) package repository. The threat targets both Windows and Linux systems and usually delivers a custom backdoor with cyberespionage capabilities. It allows remote command execution and file exfiltration, and sometimes includes the ability to take screenshots. In some cases, the final payload is a variant of the infamous W4SP Stealer, which steals personal data and credentials, or a simple clipboard monitor to steal cryptocurrency, or both. ESET discovered 116 files (source distributions and wheels) across 53 projects that contain malware. Over the past year, victims downloaded these files more than 10,000 times. From May 2023 onward, the download rate was around 80 per day.

PyPI is popular among Python programmers for sharing and downloading code. Since anyone can contribute to the repository, malware – sometimes posing as legitimate, popular code libraries – can appear. “Some malicious package names do look similar to other, legitimate packages, but we believe the main way they are installed by potential victims isn’t via typosquatting, but social engineering, where they are walked through running pip to install an ‘interesting’ package for whatever reason,” says ESET researcher Marc-Étienne Léveillé, who discovered and analyzed the malicious packages.

Most of the packages had already been taken down by PyPI at the time of the publication of this research. ESET has communicated with PyPI to take action concerning those remaining; presently, all of the known malicious packages are offline.

ESET has observed the operators behind this campaign using three techniques to bundle malicious code into the Python packages. The first technique is to place a “test” module with lightly obfuscated code inside the package. The second technique is to embed PowerShell code in the setup.py file, which is typically run automatically by package managers such as pip to help install Python projects. In the third technique, the operators make no effort to include legitimate code in the package, so that only the malicious code is present, in a lightly obfuscated form.

Typically, the final payload is a custom backdoor capable of remote command execution, file exfiltration, and sometimes the ability to take screenshots. On Windows, the backdoor is implemented in Python. On Linux, the backdoor is implemented in the Go programming language. In some cases, a variant of the infamous W4SP Stealer is used instead of the backdoor, or a simple clipboard monitor is used to steal cryptocurrency, or both. The clipboard monitor targets Bitcoin, Ethereum, Monero, and Litecoin cryptocurrencies.

“Python developers should vet the code they download before installing it on their systems. We expect that such abuse of PyPI will continue and advise caution in installing code from any public software repository,” concludes Léveillé.

For more information about the malicious Python projects in PyPI, check out the blog post “A pernicious potpourri of Python packages in PyPI.” Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×