CVE-2022-47523: ManageEngine Password Manager Pro, PAM360 and Access Manager Plus SQL Injection Vulnerability
Zoho patches a newly disclosed high-severity SQL injection flaw in several ManageEngine products; attackers have historically targeted several ManageEngine products over the last three years.
Vedere l'ignoto: scoprire l'EASM e capire in cosa può essere un aiuto
External attack surface management (EASM) is difficult and oftentimes confusing, especially in a world of poor inventory controls and a growing attack surface. This blog discusses what's required to do EASM successfully.
Tenable Cyber Watch: cosa predicono gli esperti per il 2023?
Banish the post-holiday blues with news you can use: this week's episode of Tenable Cyber Watch takes a look at four cybersecurity trends to watch for 2023. Learn how extortion tactics will reshape ransomware, OT security, SaaS worries and protecting the cloud are top of mind for our experts.
Cybersecurity Snapshot: Dati chiave del 2022 per la sicurezza del cloud, la gestione delle vulnerabilità, EASM, la sicurezza delle app web e molto altro ancora
As 2022 ends, we highlight important data points that shine a light on the trends, challenges and best practices that matter to cybersecurity leaders eager to boost their exposure management and reduce their organizations’ cyber risk.
CVE-2022-47939: Vulnerabilità critica RCE nel kernel Linux
A critical remote code execution vulnerability in the Linux kernel has been publicly disclosed by Trend Micro's Zero Day Initiative in its ZDI-22-1690 advisory. The vulnerability has been given a CVSSv3 of 10.0. There are no reports of active exploitation.
Cybersecurity Snapshot: sei previsioni di Tenable per il 2023
As 2022 draws to a close, we asked Tenable experts what they expect for the new year. After reading the tea leaves, they’re forecasting developments in extortion attacks, OT security, SaaS threats, metaverse risks and more!
L'impatto di Patch Tuesday sulla sicurezza informatica nel corso degli anni
Dive into the history of Patch Tuesday and learn how it continues to influence the ways security teams manage patches.
CVE-2022-37958: FAQ sulla vulnerabilità critica di Microsoft SPNEGO NEGOEX
Microsoft recently reclassified a vulnerability in SPNEGO NEGOEX, originally patched in September, after a security researcher discovered that it can lead to remote code execution. Organizations are urged to apply these patches as soon as possible.
Cloud Native Application Protection Platform (CNAPP): An Evolving Approach to Cloud Security
A look at how IAM works and how CIEM enhances IAM security in the cloud.
Your Guide to IAM – and IAM Security in the Cloud
A look at how IAM works and how CIEM enhances IAM security in the cloud.
Tenable Cyber Watch: Controllo del metaverso, protezione di AI e ML, minaccia di Daixin per gli ospedali e passaggio a piattaforme informatiche integrate
To help you zap those Monday blahs, here’s a caffeinated shot of cyber news you can use: Police chiefs must get hip to the metaverse. CISOs are shifting to integrated cybersecurity platforms. There's new guidance for securing ML and AI systems. Hospitals face a ransomware threat from the Daixin…
Cybersecurity Snapshot: Truffe di phishing, dinamiche evolutive di mercato, rischi del metaverso, sondaggio Log4J
Get the latest on worrisome phishing stats; businesses’ embrace of the metaverse, come what may; a (small) improvement in CISO job stability; the compensation cost of security leaders; and more!