Categoria: sicurezza

Nextcry or how a hacker tried to exploit a NGINX issue with 2 Nextcloud servers out of 300.000 hit and no payout

As you might have read in various news outlets, an attacker has been trying to use a known and reported NGINX/PHP-FPM bug (CVE-2019-11043) to break into servers. After breaking into the server and gaining control, the attacker used a compiled python script that encrypts data…

Per saperne di più

Urgent security issue in NGINX/php-fpm

Dear system administrators, In the last 24 hours, a new security risk has emerged around NGINX, documented in CVE-2019-11043. This exploit allows for remote code execution on some NGINX and php-fpm configurations. If you do not run NGINX, this exploit does not effect you. Unfortunately…

Per saperne di più

Nextcloud 17 scales up and improves data protection with Remote Wipe, collaborative text editor, 2FA updates, IBM Spectrum Scale support and Global Scale improvements

Fresh from the Nextcloud conference stage, we are proud to announce a major release of Nextcloud, the easiest solution for secure, on-premises collaboration on documents, calendars and communication! Nextcloud 17 will introduce a series of secure collaboration features including a collaborative text editor, remote wipe,…

Per saperne di più

Nextcloud Conference News: Nextcloud GmbH doubling HackerOne security bug bounties!

Just before the Nextcloud Conference in Berlin, Nextcloud GmbH has decided to double the security bug bounty, going up to USD 10.000 for a remote execution vulnerability! We will talk more about this tomorrow during the conference, but for now read on for details. Nextcloud:…

Per saperne di più

In a world with rising ransomware costs, Nextcloud saves your business millions

Can your company afford to pay $600.000 to recover its data and put its employees back to work? What does it cost if your employees can’t work for a week? $50.000? $100.000? At what point will you decide to pay those who keep your data…

Per saperne di più

Nitrokey and Nextcloud collaborate on securing private clouds

Nitrokey develops fully open and auditable security USB keys for two-factor authentication, cryptographic key storage and much more. Their devices are developed and produced in Germany, primarily in Berlin. No overseas manufacturing is used to ensure quality and avoid hardware security breaches. The installed firmware…

Per saperne di più

Nextcloud 16 becomes smarter with Machine Learning for security and productivity

Nextcloud 16 introduces a number of intelligent features designed to make the users’ lives easier and keep data safe. Suspicious Login Detection uses a locally trained neural network to detect attempts to login by malicious actors. Share recommendations suggests people and groups the user frequently…

Per saperne di più

EU and US government agencies converge on conclusion: US cloud platforms not GDPR compliant

We have covered the risks of public clouds frequently and governments seem to take notice. While the German Federal Government has already decided to rely on a Nextcloud-provided, private cloud solution, other governments are still searching. Many rely on US cloud services and, like the…

Per saperne di più

Time to update: Nextcloud 15.0.4, 14.0.7 and 13.0.11 are here!

Today we have made available security and stability updates to Nextcloud 15, 14 and 13. These aim to improve the stability, security and reliability of your server. We restrict minor updates to bug fixes and minor, non-intrusive improvements because both home and enterprise users need…

Per saperne di più