CERT NZ

CERT NZ

Information Technology & Services

We're the government authority on cyber security. Report incidents at http://cert.govt.nz/report or call 0800 CERT NZ.

About us

We're here to build a more cyber resilient Aotearoa. By working alongside an extensive and trusted partnership network - both locally and internationally - we're able to provide New Zealand businesses and organisations with timely information about potential cyber threats and offer relevant guidance on how they can protect themselves. Prevention is the best form of defence. If you experience a cyber security incident, please report to us at https://www.cert.govt.nz/individuals/report-an-issue/ In 2023 we launched the Own Your Online platform. Own Your Online is part of the New Zealand government's work to raise understanding of cyber security issues for individuals and businesses. For cyber security advice and resources please visit www.ownyouronline.govt.nz/business/

Website
https://www.cert.govt.nz
Industry
Information Technology & Services
Company size
11-50 employees
Headquarters
Wellington
Type
Government Agency
Founded
2017
Specialties
cyber security, online threats, help and guidance, malware, ransomware, business email compromise, password practise, two-factor authentication, phishing, unauthorised access, Denial-of-service, Scams and fraud, Privacy settings, data, and incident response

Locations

Employees at CERT NZ

Updates

  • View organization page for CERT NZ, graphic

    6,097 followers

    Stay cyber safe this holiday season! 🎅   The CERT NZ reporting tool will remain open over the holiday period 👉 https://lnkd.in/ggSJXgUx Any incidents reported after Friday 20 December 2024 will be responded to from Monday 6 January 2025 onward.   If your incident is of potential national significance, report it via the National Cyber Security Centre website which will continue to be monitored over this period 👉 https://lnkd.in/gpXWFs_d Scammers don’t take a break during this period, so there may be some Christmas and holiday themed scams out there.   Check out Own Your Online for advice and information on how to reduce the risk of cyber-attacks for you and your business 👉https://lnkd.in/gtYt6eqf

    • No alternative text description for this image
  • View organization page for CERT NZ, graphic

    6,097 followers

    Our latest Cyber Security Insights Report is here! This quarter (Q3), the NCSC responded to 1,905 incident reports, a 58% increase on the previous quarter. There were several trends to note within the numbers. Incidents of unauthorised access almost doubled, and we also saw a notable rise in scams while buying and selling online. Read the full report- https://lnkd.in/g6GNpN6H

    • Graphic of two computers with a cookie in one and a blue cookie monster hand reaching out of the other to grab the cookie. The words: Between July and September, the number of cyber security incidents reported to CERT NZ went up 58%. And the logo NCSC.
  • ADVISORY: We are aware of two critical vulnerabilities affecting Mitel MiCollab. CVE-2024-41713 (CVSS 9.8) is an authentication bypass vulnerability that could allow an unauthenticated attacker unauthorised access to the system and user data. CVE-2024-35286 (CVSS 9.8) is an SQL injection vulnerability that could allow an unauthenticated attacker to retrieve sensitive information and execute unauthorised database and management commands. An upgrade to the latest version is required. If you are a customer, additional mitigations are available in the KMS article found via the vendor advisory. Link to vendor advisory (CVE-2024-41713) 🔗 https://lnkd.in/gdgWmwwp Link to vendor advisory (CVE-2024-35286) 🔗 https://lnkd.in/gKxmXavu

    View organization page for National Cyber Security Centre, graphic

    4,065 followers

    Cyber security alert ⚠️ The NCSC would like to draw your attention to two critical vulnerabilities affecting Mitel MiCollab.   👉 CVE-2024-41713 (CVSS 9.8) is an authentication bypass vulnerability, that could allow an unauthenticated attacker unauthorised access to the system and user data. This vulnerability affects the NuPoint Unified Messaging (NPM) component of Mitel MiCollab versions up to 9.8 SP1 FP2 (9.8.1.201). The NCSC is aware of a proof of concept (PoC) for the chaining of CVE-2024-41713 with a separate arbitrary file read zero-day vulnerability that could then allow an unauthenticated attacker to access sensitive files and information.   👉 CVE-2024-35286 (CVSS 9.8) is an SQL injection vulnerability, that could allow an unauthenticated attacker to retrieve sensitive information and execute unauthorised database and management commands. This vulnerability affects the NuPoint Unified Messaging (NPM) component in Mitel MiCollab versions up to 9.8.0.33. The NCSC encourages organisations in New Zealand that use the affected product to review the vendor advisories, apply the mitigations as soon as possible and patch immediately once future updates become available.   Link to vendor advisory (CVE-2024-41713) 🔗 https://lnkd.in/gdgWmwwp Link to vendor advisory (CVE-2024-35286) 🔗 https://lnkd.in/gKxmXavu   #cybersecurity #infosec

    • No alternative text description for this image
  • Set your devices up for year-round protection this holiday season! Keeping the devices and software you use for your business up to date is one of the easiest and most effective ways you can protect yourself online. Software manufacturers routinely release updates for applications and operating systems which tend to fix vulnerabilities. Turning on automatic updates will ensure your systems stay safe against them.    Scroll for three tips to keep your systems up to date this holiday season.

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • During Cyber Smart Week 2024, we hosted a series of free interactive webinars for a range of sectors and groups, including seniors, small business, healthcare, financial services, individuals and more.   Hundreds of people tuned in to watch the webinars, and we received super positive feedback from participants. We’d like to give people another chance to view these webinars, but get in quick as they are only available for a limited time – register to watch them using the link below:   🔗 https://lnkd.in/gd8nQ4Xu   If you’re a seasoned professional or just starting out on your cyber security journey, our experts share invaluable tips, tricks, and practical advice you can use right away to protect yourself online.   #watch #freewebinar #OwnYourOnline

    • Purple tile with writing in white that says Sit back and watch our webinar replays. Available for a limited time. Own Your Online.
  • Last year’s Cyber Smart Week campaign saw us go in a brave, new direction to encourage New Zealanders to be more secure online. The ‘EXPOSED: through the lens of a hacker’ campaign not only put people at the forefront of cyber security but was an extremely effective campaign that has made a real difference. Our market research showed us that 70% of people who saw the campaign chose to take a cyber security action. We’re so proud to round out the year by winning two awards for this campaign. An Effie for the Most Effective PR/Experiential Campaign and the 2024 iSANZ Award for Security Project / Awareness Initiative of the year. We couldn’t be more proud knowing this has resonated with New Zealanders and industry. Thanks again to all who took part in supporting the 2023 campaign and help make a difference.  

    • Gallery wall with EXPOSED and campaign copy
  • It’s Fraud Awareness Week!   Last year, New Zealanders lost nearly $200 million to scammers. There’s a lot of work to do together as a nation to:   ✅ build awareness of online scams and fraud ✅ teach people how to protect themselves against cyber crime ✅ know where to go to report. If you’re concerned you’re being scammed, use our quick tool to see if there’s something you need to be wary of, and find out what to do next.   🔗https://lnkd.in/gDZsDKh5 #fraudweek #consumerprotection 

    • Image of a man wearing a cap on a mobile phone looking concerned. The Text says Stop them before they start. If something's not right, it could be scam. It's OK to hang up, walk away, ignore, move on. Own Your Online logos and Fraud Awareness Week logo.
  • View organization page for CERT NZ, graphic

    6,097 followers

    Thank you very, very, very very much! Another Cyber Smart Week done and dusted and we’re thrilled by the response, feedback and support we’ve received. With a record-breaking number of organisations taking part and strong attendance at our webinars, we know the important message of being secure online is getting out to all New Zealanders. Thanks to all the businesses and organisations who have helped share our message to help #StopTheScamathon, we’ve loved seeing what you all did. As we know, The Scamathon never ends. New Zealanders continue to lose $3.8m every week so our advertising will continue. We encourage everyone to have long and unique passwords and two-factor authentication enabled across all main accounts. Please share and engage with these messages. Our webinar replays are also available to watch here: https://lnkd.in/gd8nQ4Xu and of course you can watch all the videos here at Own Your Online https://lnkd.in/g4Pwts9c. This was a fun and bold idea which was not only fun to work on (so quotable) but it had a lot of nostalgia built into it, so thank you Special New Zealand, MBM, and Honeymoon Films very very much for helping this campaign come to life and be what it was! #OwnYourOnline #CSW24

    • four people standing on a set with a sign hanging above saying 'Scamathon.'
  • Small businesses are the target for nearly half of all cyber crime in New Zealand, and incidents are costly – not just financially – but to your reputation and customers too. We know the tricky part is finding the time to write an incident response plan, but being able to respond quickly to an online security incident can limit the impact one would have on your business considerably. We’ve designed an editable PDF template to help get you started today. 👉 https://lnkd.in/g24a-eEY #ownyouronline 

    • Purple background with white writing that says "Does your business have a plan in place to guide you through an online security incident? We've designed a template to get you started. Own Your Online". And an illustrative graphic of a plan in the bottom right-hand corner.

Similar pages