Blog
The Four Stages to a Successful Vulnerability Management Program
By Mitch Parker on Wed, 04/20/2022
Have you ever been around someone who is just better at something than you are? Like when you were in grade school and there was this person who was effortless at doing things correctly, like getting high grades? They had great study habits, they arrived on time, they were prepared and confident in the materials that they studied in class, and they...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of April 4, 2022
By Editorial Staff on Mon, 04/11/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of April 4, 2022. I’ve also included some comments on these stories.
Borat RAT, a new RAT that performs ransomware and DDoS...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 28, 2022
By Editorial Staff on Mon, 04/04/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 28, 2022. I’ve also included some comments on these stories.
Muhstik Botnet Targeting Redis Servers Using Recently...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of February 14, 2022
By Andrew Swoboda on Mon, 02/21/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of February 14, 2022. I’ve also included some comments on these stories.
Microsoft Using New Security Rule to Prevent Windows...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 24, 2022
By Editorial Staff on Mon, 01/31/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 24, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
SonicWall Discloses Cause of...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 17, 2022
By Andrew Swoboda on Tue, 01/25/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 17, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
Root-Level RCE Vulnerability...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of May 16, 2022
By Andrew Swoboda on Mon, 05/23/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of May 16, 2022. I’ve also included some comments on these stories.
Watch Out! Hackers Begin Exploiting Recent Zyxel...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of May 2, 2022
By Editorial Staff on Mon, 05/09/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of May 2, 2022. I’ve also included some comments on these stories.
Microsoft Azure Vulnerability Exposes PostgreSQL Databases...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of September 5, 2022
By Andrew Swoboda on Mon, 09/12/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of September 5th, 2022. I’ve also included some comments on these stories.
Critical RCE Vulnerability Affects Zyxel NAS...
Datasheet
Tripwire Vulnerability Intelligence
There’s not enough time in the day to investigate every system change and remediate every vulnerability. Ever-evolving capabilities of cyber adversaries—coupled with the dynamic nature of corporate networks— makes security prioritization increasingly difficult. With Tripwire® Enterprise and Tripwire IP360™ managed service offerings, you can minimize the amount of time you spend addressing high...
Datasheet
Calculating the ROI of a Vulnerability Management Program
Return on investment on IT security infrastructure purchases (solutions and products) has traditionally been hard to quantify. However, there are some compelling aspects of securing an organization’s infrastructure that can be identified and quantified. This discipline will continue to evolve as organizations focus on managing and balancing their security expenses and strive to control the...
Datasheet
Tripwire ExpertOps and NIST 800-171
Federal security managers expect that most federally run systems are actively engaging with FISMA compliance for protecting federal data and systems. However, as we all know, federal information does not remain only in federally operated systems. Data and IT systems connect via the Internet and other networks for business, operations and research. Information about citizens, banking and finance,...
On-Demand Webinar
How to Protect Against the Ransomware Epidemic
Mon, 08/15/2022
Ransomware has developed from a niche attack to a booming criminal market over the last year because the simple, turn-key business model behind ransomware infections doesn’t require any real technical skill to execute. As a result ransomware will continue to evolve and will continue to escalate for the foreseeable future.
The good news is that there are simple steps you can take today using...
Blog
VERT at the Movies: Cybergeddon
By Tyler Reguly on Tue, 02/16/2021
While I was teaching, one of my students asked if I had seen Cybergeddon, a film distributed by Yahoo! in 2012. I had not, so I decided it would be fun for VERT to watch the film and review it, since my hobby is writing film reviews for RotundReviews.Cybergeddon is not talked about as much as it should be given some of the background around it. It...
Blog
Vulnerability Scanning vs. Penetration Testing
By Babar Mahmood on Fri, 05/03/2024
In the modern digital landscape, cybersecurity is paramount, making the differentiation between vulnerability scanning and penetration testing essential for safeguarding organizational assets. Vulnerability scanning offers a broad sweep for potential security weaknesses, serving as an early warning system. Penetration testing takes a more targeted...
Blog
VERT Research Tips: Byting into Python
By Tyler Reguly on Sun, 11/14/2021
The past few weeks, I’ve been spending a lot of my free time preparing for the OSCP exam, which means refreshing a lot of skills that I haven’t used in years. A large part of that is rebuilding muscle memory around buffer overflows, so that’s how I spent my four-day weekend. I logged about 70 hours compiling small programs, writing buffer overflows,...
Blog
VERT Threat Alert: November 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/09/2021
Today’s VERT Alert addresses Microsoft’s November 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-972 on Wednesday, November 10th.
In-The-Wild & Disclosed CVEs
CVE-2021-42292
Up first this month, we have a 0-day in Microsoft Excel that allows an attacker to bypass security features....
Blog
VERT Threat Alert: September 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 09/08/2020
Today’s VERT Alert addresses Microsoft’s September 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-903 on Wednesday, September 9th.
In-The-Wild & Disclosed CVEs
There were no in-the-wild or disclosed CVEs included in this month’s security guidance.
CVE Breakdown by Tag
While...