On-Demand Webinar
How to Protect Against the Ransomware Epidemic
Mon, 08/15/2022
Ransomware has developed from a niche attack to a booming criminal market over the last year because the simple, turn-key business model behind ransomware infections doesn’t require any real technical skill to execute. As a result ransomware will continue to evolve and will continue to escalate for the foreseeable future.
The good news is that there are simple steps you can take today using...
Blog
VERT at the Movies: Cybergeddon
By Tyler Reguly on Tue, 02/16/2021
While I was teaching, one of my students asked if I had seen Cybergeddon, a film distributed by Yahoo! in 2012. I had not, so I decided it would be fun for VERT to watch the film and review it, since my hobby is writing film reviews for RotundReviews.Cybergeddon is not talked about as much as it should be given some of the background around it. It...
Blog
Vulnerability Scanning vs. Penetration Testing
By Babar Mahmood on Fri, 05/03/2024
In the modern digital landscape, cybersecurity is paramount, making the differentiation between vulnerability scanning and penetration testing essential for safeguarding organizational assets. Vulnerability scanning offers a broad sweep for potential security weaknesses, serving as an early warning system. Penetration testing takes a more targeted...
Blog
VERT Research Tips: Byting into Python
By Tyler Reguly on Sun, 11/14/2021
The past few weeks, I’ve been spending a lot of my free time preparing for the OSCP exam, which means refreshing a lot of skills that I haven’t used in years. A large part of that is rebuilding muscle memory around buffer overflows, so that’s how I spent my four-day weekend. I logged about 70 hours compiling small programs, writing buffer overflows,...
Blog
VERT Threat Alert: November 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/09/2021
Today’s VERT Alert addresses Microsoft’s November 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-972 on Wednesday, November 10th.
In-The-Wild & Disclosed CVEs
CVE-2021-42292
Up first this month, we have a 0-day in Microsoft Excel that allows an attacker to bypass security features....
Blog
VERT Threat Alert: September 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 09/08/2020
Today’s VERT Alert addresses Microsoft’s September 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-903 on Wednesday, September 9th.
In-The-Wild & Disclosed CVEs
There were no in-the-wild or disclosed CVEs included in this month’s security guidance.
CVE Breakdown by Tag
While...
Blog
Five “W’s” for Vulnerability Management
By Ben Layer on Sun, 12/01/2019
As we wind down 2019, it is a great time to think about your vulnerability management plans for the coming year. The five W’s can help guide our efforts as we resolve to improve our digital security for the coming new year.What Is Vulnerability Management?Vulnerability assessments are useful for detecting security issues within your environment. By...
Blog
Climbing the Vulnerability Management Mountain: Gearing Up and Taking Step One
By Lamar Bailey on Sun, 07/14/2019
As I discussed in the first blog in this series, the purpose of this series is to guide you on your journey up the Vulnerability Management Mountain (VMM). Like climbing a mountain, there is a lot of planning and work required, but when you get to the top, the view is amazing and well worth the journey. For the first phase, let's start by planning...
Blog
What’s New and Changing in the World of Vulnerability Management?
By Lamar Bailey on Sun, 06/23/2019
According to CIS, “Organizations that do not scan for vulnerabilities and proactively address discovered flaws face a significant likelihood of having their computer systems compromised.” While vulnerability management (VM) isn’t new, I’ve seen it evolve a lot over my 22 years in the industry. Here are some big trends:Assets are Diversifying. Fast.The idea of an asset has changed and grown over...
Blog
To Agent or Not to Agent: That Is the Vulnerability Management Question
By Irfahn Khimji on Wed, 02/13/2019
With the evolution of technology comes new approaches to solving problems. Sometimes a new approach fixes the problem; sometimes it creates new ones. The good thing is as folks who work in fast-paced, high-tech environment, we information security professionals are great at quickly analyzing the new technologies and applying them to our daily lives. ....
Blog
Tech-Forward Countermeasures in the Fight Against Identity Theft
By Guest Authors on Thu, 11/17/2022
Technology has expanded the avenues bad actors use to steal identities and sensitive data. However, digital tools are also giving users innovative countermeasures to protect themselves.
Here are seven tactics anyone can use to help prevent identity theft.
1. Leverage Multifactor Authentication
Strong passwords have always been an identity...
Blog
Cyberattacks are targeting smaller healthcare companies and specialty clinics. But why?
By Guest Authors on Mon, 11/28/2022
The healthcare industry has been a favored target for cybercriminals for many years. In the first half of 2022 alone, 324 attacks against healthcare organizations have been reported. Attackers have primarily focused on large hospitals in years past, but there has been a sudden switch to smaller healthcare companies and specialty clinics.
There...
Blog
WEF Report Details Best Practices for Zero Trust Deployment
By Guest Authors on Wed, 11/09/2022
Cybersecurity, like broader technological disciplines, is an ever-changing landscape that industry professionals must adapt to. The zero-trust model of cybersecurity has grown recently as organizations update their security practices to keep pace with, and stay ahead of evolving threats. Zero Trust Network Access (ZTNA) increased by 230% from 2019...
Blog
Vulnerability Management: Just Turn It Off! Part II
Wed, 08/06/2014
Our last post in the “Turn It Off!” blog series discussed some of the most common and yet unnecessary features that can make your environment more vulnerable, including JBoss JMX consoles, server banners and the Apache HTExploit.
These risks are often encountered by our Vulnerability and Exposure Research Team (VERT), even on well-defended networks and many of which have been around for quite...
Blog
Protecting Sensitive Data from Insider Threats in PCI DSS 4.0
By Guest Authors on Tue, 08/08/2023
Safeguarding sensitive data is a huge concern for organizations. One of the biggest challenges they face is the threat posed by insiders who work for the organization. In fact, a report found that 74% of organizations are at least moderately vulnerable to threats from insiders.
This has increased spending towards protecting against insider threats...
Blog
The CIA Debate: Which is the Most Important?
By Anastasios Arampatzis on Mon, 08/21/2023
The Confidentiality, Integrity and Availability (CIA) Triad is a crucial information security model that guides and assesses how an organization manages data during storage, transmission, and processing. Each component of the triad plays a vital role in maintaining information security:
Confidentiality means that data should not be accessed...
Blog
Why No Business in 2023 Can Grow without APIs
By Ross Moore on Tue, 08/22/2023
The Importance of APIs
Businesses of all sizes are increasingly relying on APIs to connect with their customers, partners, and other systems. APIs, or application programming interfaces, are the building blocks of the modern web, and they allow businesses to share data and functionality in a secure and efficient way.
Without APIs, businesses are...
Blog
Tripwire Patch Priority Index for August 2023
By Lane Thames on Fri, 09/08/2023
Tripwire's August 2023 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft.
First on the patch priority list this month are patches for Microsoft Office, Excel, Visio, Teams, and Outlook. The patches resolve 10 issues including remote code execution, information disclosure, security feature bypass, and spoofing...
Blog
General Data Protection Regulation (GDPR) – The Story So Far
By Gary Hibberd on Tue, 09/19/2023
Do you remember where you were on 25th May 2018? Perhaps you were enjoying a Friday night drink with friends. Perhaps you were with family, relaxing after a busy week at work.
I was actually having a GDPR Birthday party with friends and colleagues because 25th May 2018 was a landmark day for the world of Data Protection (yes, seriously, we had a...