Guide
Guide to Mastering Configuration Management
Download this free guide to learn best practices, how to use SCM to stay compliance and implementation steps.
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of July 25, 2022
By Andrew Swoboda on Mon, 08/01/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of July 25, 2022. I’ve also included some comments on these stories.
SonicWall fixed critical SQLi in Analytics and GMS...
Blog
VERT Threat Alert: April 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/12/2022
Today’s VERT Alert addresses Microsoft’s April 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-996 on Wednesday, April 13th.
In-The-Wild & Disclosed CVEs
CVE-2022-24521
While not previously publicly disclosed, Microsoft is reporting that they have seen active exploitation of this...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 14, 2022
By Editorial Staff on Mon, 03/21/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 14, 2022. I’ve also included some comments on these stories.
Most Orgs Would Take Security Bugs Over Ethical Hacking...
Guide
Threat Prevention is Foundational
How proper foundational controls help block today’s advanced threats
Blog
CIS Control 04: Secure Configuration of Enterprise Assets and Software
By Matthew Jerzewski on Wed, 01/29/2025
Key Takeaways for Control 4Most fresh installs of operating systems or applications come with preconfigured settings that are usually insecure or not properly configured with security in mind. Use the leverage provided by multiple frameworks such as CIS Benchmarks or NIST NCP to find out if your organization needs to augment or adjust any baselines to become better aligned with the policies your...
Blog
VERT Threat Alert: December 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 12/14/2021
Today’s VERT Alert addresses Microsoft’s December 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-978 on Wednesday, December 15th.
In-The-Wild & Disclosed CVEs
CVE-2021-43890
Up first this month is a vulnerability in the Windows AppX Installer that could allow spoofing. This...
Blog
VERT Threat Alert: June 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/08/2021
Today’s VERT Alert addresses Microsoft’s June 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-947 on Wednesday, June 9th.In-The-Wild & Disclosed CVEsCVE-2021-31955This is one of two vulnerabilities fixed in today’s patch drop which were reported by Kaspersky Lab after detecting...
Blog
VERT Threat Alert: August 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 08/10/2021
Today’s VERT Alert addresses Microsoft’s August 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-959 on Wednesday, August 11th.In-The-Wild & Disclosed CVEsCVE-2021-36948This privilege escalation vulnerability that affects the Windows Update Medic Service (WaasMedic) has been actively...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 31, 2022
By Andrew Swoboda on Mon, 02/07/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 31, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
Update Force-Pushed to Protect...
Blog
VERT Threat Alert: May 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 05/12/2020
Today’s VERT Alert addresses Microsoft’s May 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-884 on Wednesday, May 13th.
In-The-Wild & Disclosed CVEs
None of the vulnerabilities resolved this month have been publicly disclosed or exploited according to Microsoft.
CVE Breakdown by Tag
...
Blog
VERT Threat Alert: November 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/10/2020
Today’s VERT Alert addresses Microsoft’s November 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-915 on Wednesday, November 11th. Note: Microsoft has changed their advisory format and no longer provides basic vulnerability descriptions.In-The-Wild & Disclosed CVEsCVE-2020-17087This CVE...
Blog
Why Is Cyber Resilience Essential and Who's Responsible for It?
By Zoë Rose on Tue, 05/07/2024
In the first installment of our series on cyber resilience, we discussed what being a resilient organization means. In this installment, we'll explore why organizations need to consider how to become resilient, who's responsible for achieving this, and the processes organizations must have to prioritize actions and effectively spend their budgets.
...
Blog
Silent Heists: The Danger of Insider Threats
By Kirsten Doyle on Thu, 12/19/2024
When thinking about cybersecurity, we envision malicious actors working in dark basements, honing their tools to invent cunning new ways to breach our defenses. While this is a clear and present danger, it's also important to understand that another hazard is lurking much closer to home - the insider threat.These attacks have devastated entities in all sectors, with severe repercussions. These...
Blog
VERT Threat Alert: April 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/14/2020
Today’s VERT Alert addresses Microsoft’s April 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-880 on Wednesday, April 15th.
In-The-Wild & Disclosed CVEs
CVE-2020-0935
A vulnerability in the OneDrive for Windows desktop application could allow an attacker to overwrite a targeted file...
Blog
Developing an Effective Change Management Program
By John Salmi on Tue, 11/08/2022
Change detection is easy. What is not so easy, is reconciling change. Change reconciliation is where most organizations stumble. What was the change? When was it made? Who made it? Was it authorized? The ability to answer these questions are the elements that comprise change management.Historically, the haste of accomplishing a task consisted of a...
Guide
Beyond the Basics: Tripwire Enterprise Use Cases
Security, compliance, and IT operations leaders need a powerful and effective way to accurately identify security misconfigurations and indicators of compromise. Explore the many ways Tripwire Enterprise can protect your organization with superior security and
continuous compliance.
Blog
VERT Threat Alert: June 2023 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/13/2023
Today’s VERT Alert addresses Microsoft’s June 2023 Security Updates, which include a new release notes format. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1060 on Wednesday, June 14th.
In-The-Wild & Disclosed CVEs
There were no in-the-wild or disclosed CVEs in the June Patch Tuesday drop. CVE Breakdown...