Blog
Defense and Development: Key points from The Complete Guide to Application Security for PCI-DSS
By Guest Authors on Wed, 08/31/2022
The increasing popularity of online payment systems results from the world’s gradual transition to a cashless and contactless digital economy — an economy, projected in a recent Huawei white paper, to be worth $23 trillion by 2025. With digital commerce emerging as the largest segment in the projected $8.49 trillion global digital payments market in...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of August 1, 2022
By Andrew Swoboda on Mon, 08/08/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of August 1st, 2022. I’ve also included some comments on these stories.
Windows 11 Smart App Control blocks files used to...
Blog
VERT Threat Alert: September 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 09/13/2022
Today’s VERT Alert addresses Microsoft’s September 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1021 on Wednesday, September 14th.
In-The-Wild & Disclosed CVEs
CVE-2022-23960
The first disclosed vulnerability this month is Spectre-BHB that is discussed in great detail on arm...
Datasheet
Tripwire’s Solutions for Automated, Continuous PCI Compliance
The Payment Card Industry Data Security Standard (PCI DSS) was created to help organizations that process credit card payments secure the cardholder environment to prevent credit card fraud, cyber threats, and other security vulnerabilities. The latest version, 4.0, provides specific security guidance on handling, processing, transmitting, and storing credit card data to minimize the theft,...
Datasheet
Tripwire Resident Engineers
The cybersecurity skills gap can leave many organizations without adequate staffing for the operation of their security tools. High turnover rates can also cause an organization to lose essential knowledge when team members leave who were familiar with the tools. To complicate matters further, the pandemic is driving the need for temporary cybersecurity support as agencies navigate new, remote...
Datasheet
Tripwire Enterprise and Cisco AMP Threat Grid
Overview
There is mounting concern at the senior executive and board level regarding cybersecurity, driven by highly visible advanced targeted attacks. These attacks threaten precious IP, valuable customer information, company valuation and trade secrets. To truly protect valuable resources, organizations have to accept the nature of modern networked environments and devices, and start defending...
Blog
VERT Threat Alert: January 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 01/11/2022
Today’s VERT Alert addresses Microsoft’s January 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-981 on Wednesday, January 12th.
In-The-Wild & Disclosed CVEs
CVE-2022-21919
This vulnerability was a bypass to CVE-2021-34484, released by the same researcher, Abdelhamid Naceri. The...
Blog
CIS Control 14: Security Awareness and Skill Training
By Matthew Jerzewski on Wed, 11/06/2024
Users who do not have the appropriate security awareness training are considered a weak link in the security of an enterprise. These untrained users are easier to exploit than finding a flaw or vulnerability in the equipment that an enterprise uses to secure its network. Attackers could convince unsuspecting users to unintentionally provide access to the enterprise network or expose sensitive...
Blog
VERT Threat Alert: July 2021 Patch Tuesday Analysis
By Tyler Reguly on Wed, 07/14/2021
Today’s VERT Alert addresses Microsoft’s July 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-954 on Wednesday, July 14th.In-The-Wild & Disclosed CVEsCVE-2021-34527The vulnerability dubbed PrintNightmare was patched prior to the Tuesday patch drop, but it is still worth including here....
Blog
CIS Control 09: Email and Web Browser Protections
By Matthew Jerzewski on Wed, 12/11/2024
Web browsers and email clients are used to interact with external and internal assets. Both applications can be used as a point of entry within an organization. Users of these applications can be manipulated using social engineering attacks. A successful social engineering attack needs to convince users to interact with malicious content. A successful attack could give an attacker an entry point...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the week of September 27, 2021
By Tyler Reguly on Mon, 10/04/2021
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly reviewing the news for interesting stories and developments in the cybersecurity world. Here’s what stood out to us during the week of September 27, 2021. We’ve also included the comments from a few folks here at Tripwire VERT.
REvil Ransomware Group Goes...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of February 7, 2022
By Andrew Swoboda on Mon, 02/14/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of February 7, 2022. I've also included some comments on these stories.
Mac Trojan Comes with Expanded Ability to Drop...
Blog
VERT Threat Alert: February 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 02/08/2022
Today’s VERT Alert addresses Microsoft’s February 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-985 on Wednesday, February 9th.
In-The-Wild & Disclosed CVEs
CVE-2022-21989
This month, only a single vulnerability, CVE-2022-21989 has been publicly disclosed and Microsoft is not...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 21, 2022
By Editorial Staff on Mon, 03/28/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 21, 2022. I’ve also included some comments on these stories.
Misconfigured Firebase Databases Exposing Data In...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of May 30, 2022
By Andrew Swoboda on Mon, 06/06/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of May 30, 2022. I’ve also included some comments on these stories.
Vendor Refuses to Remove Backdoor Account That Can...
Blog
HITRUST: the Path to Cyber Resilience
By John Salmi on Wed, 05/22/2024
Much has been made of cyber resilience in recent years. And with good reason: failing to bounce back quickly from a security event can have dramatic financial consequences. In early 2023, Royal Mail took several days to recover from a Lockbit cyberattack, losing upwards of £10 million in the process. However, for all the talk about resilience, the industry seems to be overlooking one of its...
Blog
VERT Threat Alert: June 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/09/2020
Today’s VERT Alert addresses Microsoft’s June 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-888 on Wednesday, June 10th.
In-The-Wild & Disclosed CVEs
None of the vulnerabilities resolved this month have been publicly disclosed or exploited according to Microsoft.
CVE Breakdown by...
Blog
VERT Threat Alert: March 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 03/09/2021
Today’s VERT Alert addresses Microsoft’s March 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-933 on Wednesday, March 10th.
In-The-Wild & Disclosed CVEs
CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
These CVEs are part of the bundle of Exchange vulnerabilities that...