ESKA Security

ESKA Security

Share

Cybersecurity Services for SMB to Enterprise Level Companies

09/15/2026

If your company has no CISO, these are the 7 decisions someone still needs to own.
Not every company needs a full-time CISO.
But every company needs someone who can answer:

🔸 Which cybersecurity risks are we willing to accept?
🔸 What systems, data, and processes should we protect first?
🔸 Who should have access to critical systems?
🔸 Which security controls do we actually need?
🔸 What happens when a security incident occurs?
🔸 Which security and compliance requirements must we meet?
🔸 How do we know our security controls actually work?

In many growing companies, these decisions are split between the CTO, IT, DevOps, Legal, and management.

The problem is when no one owns the whole picture.

You may not need the CISO title yet. But you do need clear security ownership.

Read the full article https://www.eskasecurity.com/post/if-your-company-has-no-ciso-these-are-the-7-decisions-someone-still-needs-to-own to see what that ownership should look like and when a vCISO can fill the gap.

09/14/2026

What Red Team Specialists Check in the First 30 Minutes of a Pe*******on Test?Usually, they don’t start by exploiting vulnerabilities.

First, they try to understand the environment from an attacker’s perspective:

🔸 What systems and services are exposed to the Internet?
🔸 Are there forgotten subdomains, staging environments, or admin panels?
🔸 What technologies and software are running?
🔸 Where are the authentication entry points?
🔸 Are there obvious misconfigurations or information leaks?
🔸 Which assets could become the easiest path to something more valuable?

By the end of those first 30 minutes, a pentester is already forming the first attack hypotheses and deciding where to dig deeper.

Because a good pentest isn’t about finding as many vulnerabilities as possible.

It’s about finding the ones an attacker could actually use and understanding where they could lead.

Read the full article https://www.eskasecurity.com/post/what-pentesters-check-in-the-first-30-minutes-of-an-engagement to see what happens at the beginning of a professional pe*******on test.

09/08/2026

What is a BEC attack?
BEC stands for Business Email Compromise — a type of social engineering attack where criminals impersonate a CEO, CFO, employee, supplier, or business partner to trick someone into transferring money, changing bank details, or sharing sensitive information.

Unlike traditional phishing, BEC emails often contain no malware, no suspicious attachment, and no malicious link.

That is exactly what makes them dangerous.

Attackers may study how a company communicates, who approves payments, which suppliers it works with, and even how executives write emails. In some cases, they compromise a real corporate mailbox and send fraudulent instructions from a legitimate account.

A typical scenario looks simple:

🔸 a finance employee receives an urgent email from the “CEO”
🔸 the message asks to use new banking details
🔸 the request looks legitimate and time-sensitive
🔸 the payment is made
🔸 the money goes to an attacker-controlled account

SPF, DKIM, and DMARC are important, but they cannot stop every BEC attack, especially when a legitimate mailbox has already been compromised.

Effective BEC protection requires several layers: MFA, email security, employee awareness, account monitoring, SIEM/SOC visibility, and clear payment verification procedures.

In our new article https://www.eskasecurity.com/post/business-email-compromise-bec-how-attackers-impersonate-executives-and-steal-company-funds, we explain how BEC attacks work, why employees fall for them, how attackers bypass common email protections, and what companies can do to reduce the risk.

06/11/2026

A cyber incident is only the beginning of the story. After containment, organizations face the most important questions:

🔸 What exactly happened?
🔸 How did the attackers gain access?
🔸 What systems and data were affected?
🔸 How long were they inside the environment?
🔸 What is the real business impact?

Without forensic analysis, these questions often remain unanswered, leaving organizations exposed to repeated attacks, regulatory issues, legal disputes, and reputational damage.

Digital forensics helps reconstruct the attack timeline, identify compromised assets, preserve evidence, determine the root cause, and provide the facts needed for remediation and decision-making.

In many cases, understanding what happened is just as important as stopping the attack itself.

In our latest article https://www.eskasecurity.com/post/after-the-breach-how-forensic-analysis-determines-what-happened-who-did-it-and-what-it-cost, we explain how forensic investigations work, what evidence analysts collect, and how organizations can use forensic findings to reduce future risks.

06/09/2026

We are getting more and more requests for a service that barely existed three years ago: helping companies respond to security questionnaires from potential clients and partners.

This is a direct consequence of supply chain requirements. GDPR, DORA, NIS2 push large companies to verify vendors before signing. That pressure flows to everyone in the supply chain.

The problem is that many companies encounter these questionnaires for the first time mid-deal, answer optimistically, or run them through an AI tool. The issue is not the formatting. It is that the answers become part of the contractual record — and clients can audit you during the contract.

Newer agreements include penalty clauses and liability provisions tied specifically to third-party incidents. An inaccurate answer is no longer just a reputational risk.

Someone needs to understand the consequences of each formulation and be accountable for it.

We handle this as part of our vCISO service. Full article https://www.eskasecurity.com/post/what-you-don-t-know-can-hurt-you-cybersecurity-due-diligence-in-m-a-and-business-partnerships

06/04/2026

Meta recently introduced an AI-powered support assistant designed to help users recover accounts, update contact information, and resolve common Instagram and Facebook support issues.

Researchers discovered that attackers could manipulate the AI assistant into making account changes without properly verifying the identity of the legitimate account owner.

In simple terms, the bot could be tricked into replacing the victim's recovery email with an attacker-controlled address, allowing the attacker to reset the password and take over the account.

The key point is that hackers did not compromise Instagram's infrastructure or exploit a traditional software vulnerability. Instead, they persuaded the AI agent to perform the actions for them.

This incident may become one of the first high-profile examples of what security professionals call an Agentic AI Security Failure.

The issue was not the AI model itself. The problem was that the AI agent was granted authority to perform high-risk operations, including:

• Changing account contact details
• Recovering user accounts
• Resetting passwords

In practice, the AI was given Tier 1/Tier 2 support privileges without sufficient security controls and verification mechanisms.

As organizations increasingly deploy AI agents within Service Desk, Help Desk, and Identity & Access Management (IAM) processes, this case serves as an important reminder: AI agents must be treated as privileged users and governed accordingly.

The lesson for cybersecurity is clear: the risk is no longer limited to vulnerabilities in code. It also extends to the business processes and permissions we delegate to autonomous AI systems.

06/02/2026

A recent Booking security incident serves as another reminder that even the world's largest platforms can become part of a cyberattack chain.

Booking recently confirmed an incident involving unauthorized access to booking-related data. Following the incident, researchers reported numerous cases of so-called "reservation hijacking" attacks.

Here's how the scheme worked:
1. A customer makes a legitimate hotel reservation through Booking
2. Attackers gain access to booking information or compromise hotel accounts.
3. The guest then receives a message that appears completely legitimate: "To confirm your reservation, please update your payment details." or "Your booking requires payment verification."

The message contains real information:
• Guest name
• Hotel name
• Check-in dates
• Reservation details

From the customer's perspective, everything looks authentic.
And that's exactly why these attacks are so effective.

The problem is that attackers are using legitimate data to build trust.

This incident highlights an important trend in modern cybercrime:
Attackers are no longer relying solely on mass phishing campaigns. Instead, they leverage data breaches, compromised partners, and supply-chain weaknesses to make their attacks highly convincing.

For businesses, the lesson is clear:
Your cybersecurity posture depends not only on your own infrastructure but also on the security of your vendors, partners, and SaaS providers.

Ask yourself:
🔸Do you assess third-party security risks?
🔸Do you evaluate vendors before integrating their services?
🔸Are employees trained to recognize highly targeted social engineering attacks?
🔸Do you have a response plan if a critical supplier is compromised?

05/29/2026

Before attacking a company, threat actors conduct research and gather information from open sources.

A few Google searches are often enough to find:
• exposed services and admin panels
• old or forgotten subdomains
• leaked credentials
• the company’s technology stack
• employee email addresses
• information about internal infrastructure

Shodan helps attackers identify publicly exposed servers, VPNs, RDP services, open ports, and internet-facing systems the company may have forgotten about.

LinkedIn reveals team structure, employee roles, technologies in use, and people with privileged access, making it a valuable source for targeted phishing attacks.

GitHub repositories sometimes expose API keys, internal configurations, secrets, or code that helps attackers understand the architecture and identify potential entry points.

This is why external pentesting should always start with because real attackers almost always start there too.

More details in the article 👇
https://www.eskasecurity.com/post/what-attackers-see-when-they-google-your-company

05/28/2026

A “Clean Vulnerability Scan Report” does not mean your company is secure.
A vulnerability scanner is designed to identify known vulnerabilities, misconfigurations, exposed services, and unpatched software based on a database of known signatures. It is useful for continuous monitoring, patch management, and identifying common weaknesses across infrastructure.

But scanners cannot detect:
🔸 business logic flaws
🔸 complex multi-step attack paths
🔸 authentication and session weaknesses
🔸 password reuse across systems
🔸 human factors and social engineering risks

They only find what they have been taught to recognize.

That is why a clean scan report is not proof of security. It only confirms that, at the time of the scan, the tool did not find matches against known vulnerability signatures.

To understand whether an environment can actually be compromised, organizations still need pe*******on testing, where a human tester thinks like an attacker, chains weaknesses together, and identifies risks that automated tools cannot see.

and *******ontesting are complementary, not interchangeable. And that is exactly why regular pentests still matter, even when the scan report looks “clean.”

Read more in our Blog https://www.eskasecurity.com/post/a-clean-vulnerability-scan-report-does-not-mean-you-are-secure

05/14/2026

Phishing is often seen as the main entry point for cyberattacks. In reality, it is only one part of a much broader threat landscape. A growing number of real incidents start somewhere else entirely: through unpatched vulnerabilities or overtrusted third party access.

What this means in practice:
🔸 Old vulnerabilities remain one of the most reliable ways to gain initial access when they are not patched in time
🔸 Attackers often rely on known technical weaknesses rather than social engineering as the first step
🔸 Third party access is frequently less controlled than internal systems, which creates blind spots
🔸 Compromise of a supplier or partner can directly impact multiple organizations in the same chain
🔸 The most effective attacks often combine multiple vectors, such as vulnerability exploitation and stolen credentials, followed by lateral movement inside the environment

The key takeaway is simple. Modern attacks are rarely based on a single method. They exploit whatever is least controlled, especially technical debt and external trust relationships.

This is why security focus is shifting from defending only against phishing to continuous risk management, including patch management, access control, and third party risk oversight.

In the article we explore:
• how outdated vulnerabilities become real entry points
• why third party access is often underestimated
• how these two factors are combined in real attack scenarios

Read more: https://www.eskasecurity.com/post/why-old-vulnerabilities-and-third-party-access-are-as-dangerous-as-phishing

Want your business to be the top-listed Computer & Electronics Service in Vaughan?
Click here to claim your Sponsored Listing.

Address

2900 Highway 7, Concord, Ontario
Vaughan, ON
L4K0G3

Alerts

Be the first to know and let us send you an email when ESKA Security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Subscribe

We will notify you when anything happens in Vaughan.