Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of July 25, 2022
By Andrew Swoboda on Mon, 08/01/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of July 25, 2022. I’ve also included some comments on these stories.
SonicWall fixed critical SQLi in Analytics and GMS...
Blog
VERT Threat Alert: April 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/12/2022
Today’s VERT Alert addresses Microsoft’s April 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-996 on Wednesday, April 13th.
In-The-Wild & Disclosed CVEs
CVE-2022-24521
While not previously publicly disclosed, Microsoft is reporting that they have seen active exploitation of this...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 14, 2022
By Editorial Staff on Mon, 03/21/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 14, 2022. I’ve also included some comments on these stories.
Most Orgs Would Take Security Bugs Over Ethical Hacking...
Blog
VERT Threat Alert: December 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 12/14/2021
Today’s VERT Alert addresses Microsoft’s December 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-978 on Wednesday, December 15th.
In-The-Wild & Disclosed CVEs
CVE-2021-43890
Up first this month is a vulnerability in the Windows AppX Installer that could allow spoofing. This...
Blog
VERT Threat Alert: June 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/08/2021
Today’s VERT Alert addresses Microsoft’s June 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-947 on Wednesday, June 9th.In-The-Wild & Disclosed CVEsCVE-2021-31955This is one of two vulnerabilities fixed in today’s patch drop which were reported by Kaspersky Lab after detecting...
Blog
VERT Threat Alert: August 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 08/10/2021
Today’s VERT Alert addresses Microsoft’s August 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-959 on Wednesday, August 11th.In-The-Wild & Disclosed CVEsCVE-2021-36948This privilege escalation vulnerability that affects the Windows Update Medic Service (WaasMedic) has been actively...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 31, 2022
By Andrew Swoboda on Mon, 02/07/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 31, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
Update Force-Pushed to Protect...
Blog
VERT Threat Alert: May 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 05/12/2020
Today’s VERT Alert addresses Microsoft’s May 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-884 on Wednesday, May 13th.
In-The-Wild & Disclosed CVEs
None of the vulnerabilities resolved this month have been publicly disclosed or exploited according to Microsoft.
CVE Breakdown by Tag
...
Blog
30 Ransomware Prevention Tips
By Guest Authors on Tue, 04/11/2023
Dealing with the aftermath of ransomware attacks is like Russian roulette. Submitting the ransom might seem like it’s the sole option for recovering locked data. Ransomware also continues to evolve as a threat category within the past year, with old names like REvil rearing their heads and new players like Black Basta emerging in 2022. Malicious...
Blog
VERT Threat Alert: November 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/10/2020
Today’s VERT Alert addresses Microsoft’s November 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-915 on Wednesday, November 11th. Note: Microsoft has changed their advisory format and no longer provides basic vulnerability descriptions.In-The-Wild & Disclosed CVEsCVE-2020-17087This CVE...
Blog
VERT Threat Alert: April 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/14/2020
Today’s VERT Alert addresses Microsoft’s April 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-880 on Wednesday, April 15th.
In-The-Wild & Disclosed CVEs
CVE-2020-0935
A vulnerability in the OneDrive for Windows desktop application could allow an attacker to overwrite a targeted file...
Blog
Root Cause Analysis for Deployment Failures
By Chris Hudson on Tue, 04/25/2023
Root Cause Analysis (RCA) is a technique used to identify the underlying reasons for a problem, with the aim of trying to prevent it from recurring in the future. It is often used in change management processes to help identify the source of any issues that arise following any modifications to a system or process.
RCA is something Tripwire...
Blog
VERT Threat Alert: June 2023 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/13/2023
Today’s VERT Alert addresses Microsoft’s June 2023 Security Updates, which include a new release notes format. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1060 on Wednesday, June 14th.
In-The-Wild & Disclosed CVEs
There were no in-the-wild or disclosed CVEs in the June Patch Tuesday drop. CVE Breakdown...
Blog
Do you Work in a SOC Noise Factory?
By Anthony Israel-Davis on Mon, 05/22/2023
Gabrielle is a security engineer. She deploys tools to scan for threats and vulnerabilities, read logs, and manage the security risks for her company, but is all that data really helping? Sometimes, it seems like she works in a noise factory instead of a SOC. The cacophony of all the log and event data and vulnerability scans are pouring into the...
Blog
VERT Threat Alert: September 2023 Patch Tuesday Analysis
By Tyler Reguly on Tue, 09/12/2023
Today’s VERT Alert addresses Microsoft’s September 2023 Security Updates, which includes a recently introduced release notes format. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1073 on Wednesday, September 13th.
In-The-Wild & Disclosed CVEs
CVE-2023-36761
Microsoft has indicated that a vulnerability...
Blog
Defending Against Ransom DDoS Attacks
By Guest Authors on Wed, 10/23/2024
DDoS attacks have become an annoyance most companies assume they may have to deal with at some point. While frustrating, minor website disruptions from small-scale hacktivist campaigns rarely create substantial business impacts. However, a particularly insidious DDoS spinoff has emerged over the past decade – one aimed at blackmail.This evolutionary milestone stems from what's called Ransom DDoS ...
Blog
Low-Hanging Fruits Vs. Those at the Top of the Tree: Cybersecurity Edition
By Joe Pettit on Tue, 07/16/2024
Companies often go for high-end cybersecurity solutions because dealing with complex problems looks impressive. The appeal of fancy tech and advanced security challenges gives them a sense of achievement and a chance to show off their skills - and says they're serious about staying ahead of cyber crooks.However, this isn't always the best strategy. Many significant risks arise from simple...
Blog
VERT Threat Alert: November 2024 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/12/2024
Today’s VERT Alert addresses Microsoft’s November 2024 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1132 as soon as coverage is completed. In-The-Wild & Disclosed CVEsCVE-2024-43451A vulnerability that allows for NTLMv2 hash disclosure has been both publicly disclosed and actively exploited. According to Microsoft, only minimal...