Learning Library

← Back to Library

IBM Cloud: Phishing Threats, Bare Metal VPC, Certification

Key Points

  • Researchers uncovered >1,200 phishing kits that act as reverse‑proxy “man‑in‑the‑middle” attacks to steal two‑factor authentication codes and session cookies, underscoring a surge in sophisticated phishing and the need for MFA combined with strong user education.
  • IBM announced “IBM Cloud Bare Metal Servers for VPC,” delivering classic bare‑metal performance with faster on‑demand provisioning, larger core/memory options, client‑managed virtualization, and improved network design—all without a gateway between Classic and VPC environments.
  • A new IBM Cloud Security Engineer Specialty certification was launched by the IBM Center for Cloud Training, offering an interactive curriculum on vulnerability remediation, incident escalation, and securing hybrid‑cloud, Kubernetes, and VMware workloads.
  • The episode provides links to a blog on the phishing kits and resources for getting started with the new bare‑metal‑for‑VPC offering and the security‑engineer certification.

Full Transcript

# IBM Cloud: Phishing Threats, Bare Metal VPC, Certification **Source:** [https://www.youtube.com/watch?v=s-xTauu2knA](https://www.youtube.com/watch?v=s-xTauu2knA) **Duration:** 00:03:27 ## Summary - Researchers uncovered >1,200 phishing kits that act as reverse‑proxy “man‑in‑the‑middle” attacks to steal two‑factor authentication codes and session cookies, underscoring a surge in sophisticated phishing and the need for MFA combined with strong user education. - IBM announced “IBM Cloud Bare Metal Servers for VPC,” delivering classic bare‑metal performance with faster on‑demand provisioning, larger core/memory options, client‑managed virtualization, and improved network design—all without a gateway between Classic and VPC environments. - A new IBM Cloud Security Engineer Specialty certification was launched by the IBM Center for Cloud Training, offering an interactive curriculum on vulnerability remediation, incident escalation, and securing hybrid‑cloud, Kubernetes, and VMware workloads. - The episode provides links to a blog on the phishing kits and resources for getting started with the new bare‑metal‑for‑VPC offering and the security‑engineer certification. ## Sections - [00:00:00](https://www.youtube.com/watch?v=s-xTauu2knA&t=0s) **Phishing Kit Threats & Bare Metal Launch** - The episode spotlights newly discovered phishing kits that bypass two‑factor authentication through reverse‑proxy attacks, then announces IBM Cloud’s latest bare‑metal servers for VPC and a new IBM Center for Cloud Training certification. ## Full Transcript
0:00fishing kits found in the wild the all 0:02new ibm cloud bare metal servers for vpc 0:05and a new certification from the ibm 0:07center for cloud training all on this 0:10episode of ibm cloud now 0:12what's up y'all my name is ian and i am 0:14back to bring you the latest and 0:15greatest news and announcements from ibm 0:17cloud 0:18i wanted to start this week with a bit 0:20of security related news a team of 0:23academics recently discovered more than 0:25twelve hundred fishing kits equipped 0:27with the ability to intercept users 0:29two-factor authentication codes 0:31many of the toolkits use 0:32man-in-the-middle phishing to bypass 0:35two-factor authentication procedures by 0:37working as reverse proxies 0:39this means that when the affected user 0:41did succeed in authenticating themselves 0:43on a legitimate service the reverse 0:45proxy also gave the attacker access to a 0:47copy of the authentication cookie 0:50with the cookie the attacker could 0:51access the account to steal information 0:54or even sell it on the dark net 0:56unfortunately phishing attacks reached 0:58unprecedented heights in 2021 it's 1:00important that organizations protect 1:02themselves by blending multi-factor 1:04authentication and other technical 1:06controls with stringent education for 1:08all employees 1:10to learn more about these phishing 1:11attacks and how to protect yourself 1:13check out the blog linked below 1:16next up you know what you get with bare 1:17metal servers on a classic 1:19infrastructure dedicated compute with 1:21direct hardware access for your 1:23performance oriented workloads 1:25but what about speed high availability 1:27and interconnectivity what about having 1:29a truer on-demand provisioning option 1:31for your most intense applications 1:34to meet these needs i'm excited to 1:36introduce you to the all-new ibm cloud 1:38bare metal servers for vpc 1:42bare metal servers for vpc give you the 1:44benefits of bare metal with faster 1:46provisioning and better network design 1:48and performance 1:49this solution takes the dedicated 1:51performance single tendency consistency 1:54and security of a bare metal server and 1:56introduces more quality of life 1:58improvements 1:59it also unlocks larger core and memory 2:01profiles client managed virtualization 2:03and faster network performance all 2:06without the need for a gateway to 2:07connect classic and vpc infrastructures 2:10to learn more about how to get started 2:12with ibm cloud bare metal servers for 2:13vpc hit the link below 2:17finally to wrap things up i want to 2:18shine a spotlight on the new ibm cloud 2:21security engineer specialty 2:22certification from the ibm center for 2:25cloud training 2:26this new program provides an interactive 2:28curriculum that trains professionals to 2:30identify and remediate vulnerabilities 2:33respond to security incident escalations 2:35and proactively engineer security and 2:37compliance best practices 2:40by following this learning path you'll 2:41learn how to secure infrastructure and 2:43hybrid cloud connections cloud compute 2:45kubernetes services and vmware solutions 2:48in ibm cloud you'll also explore how to 2:51manage access controls and authorization 2:53and the configuration of security and 2:54compliance solutions 2:56courses and exams are available now and 2:58you can learn more by clicking on the 2:59link below 3:01thanks so much for joining me today for 3:02this episode of ibm cloud now if you're 3:04interested in learning more about the 3:05topics i've covered make sure you 3:07explore the links in the description of 3:08this video and again please don't forget 3:10to subscribe to our channel to stay up 3:12to date on what's going on in the cloud 3:14now 3:25you