Blog
How to Secure Your Information on AWS: 10 Best Practices
By Katrina Thompson on Wed, 03/19/2025
About one in three organizations that leverage cloud service providers (CSPs) use Amazon Web Services (AWS), according to November 2024 research from Synergy Research Group. This means two things. One is that when attackers are looking to get the most out of a single exploit, they will likely craft them to target AWS systems. And two, that AWS data security best practices are a timely topic for a...
Blog
What Is the ISA/IEC 62443 Framework?
By Michael Betti on Mon, 11/04/2024
Cybersecurity threats to manufacturing and process plants come from a wide range of attack vectors, including supply chain, logistics, enterprise computing, remote connections, operator stations, programmable logic controllers, distributed control systems (DCSs), smart sensors, and new smart devices. Internet of Things (IoT) technologies offer greater connectivity and endless applications, but...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of July 25, 2022
By Andrew Swoboda on Mon, 08/01/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of July 25, 2022. I’ve also included some comments on these stories.
SonicWall fixed critical SQLi in Analytics and GMS...
Blog
VERT Threat Alert: April 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/12/2022
Today’s VERT Alert addresses Microsoft’s April 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-996 on Wednesday, April 13th.
In-The-Wild & Disclosed CVEs
CVE-2022-24521
While not previously publicly disclosed, Microsoft is reporting that they have seen active exploitation of this...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 14, 2022
By Editorial Staff on Mon, 03/21/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 14, 2022. I’ve also included some comments on these stories.
Most Orgs Would Take Security Bugs Over Ethical Hacking...
Guide
Threat Prevention is Foundational
How proper foundational controls help block today’s advanced threats
Blog
Understanding Managed Service Providers (MSPs): Choosing the Right Provider
By Jim Whiting on Wed, 08/21/2024
The demand for robust security, transparency, and accountability is at an all-time high, and many businesses are relying on managed service providers (MSPs) to manage their IT infrastructure, ensure data security, or provide seamless operational support. Concurrently, MSPs must continuously innovate and differentiate their offerings to meet the growing needs of businesses.The wide range of MSPs...
Blog
Delivering Electrons, Generating Data Lakes, and the Security & Privacy Considerations of Running a Modern Industrial Organization
By Editorial Staff on Thu, 09/30/2021
In this episode, Patrick Miller, Founder of Ampere Industrial Security, discusses what utilities and other industrial companies need to consider when it comes to the goldmines of data they're collecting from their machines and customers. He also explains why security and privacy needs to be incorporated in these operations by design.
https://open...
Blog
Sextortion Scams – How They Persuade and What to Watch for
By Martina Dove on Wed, 07/10/2024
"Sextortion" scams represent some of cybercriminals' most brazen attempts to extract money from unwitting victims. These extortion techniques rely on fear and shame to get targets to pay up. Similar to individualized ransomware attacks, if the party refuses to pay the demand, public exposure will follow.As these attacks target individuals rather than companies, it is important for all employees to...
Blog
VERT Threat Alert: December 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 12/14/2021
Today’s VERT Alert addresses Microsoft’s December 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-978 on Wednesday, December 15th.
In-The-Wild & Disclosed CVEs
CVE-2021-43890
Up first this month is a vulnerability in the Windows AppX Installer that could allow spoofing. This...
Blog
VERT Threat Alert: June 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/08/2021
Today’s VERT Alert addresses Microsoft’s June 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-947 on Wednesday, June 9th.In-The-Wild & Disclosed CVEsCVE-2021-31955This is one of two vulnerabilities fixed in today’s patch drop which were reported by Kaspersky Lab after detecting...
Blog
CIS Control 11: Data Recovery
By Matthew Jerzewski on Wed, 11/27/2024
Data loss can be a consequence of a variety of factors from malicious ransomware to hardware failures and even natural disasters. Regardless of the reason for data loss, we need to be able to restore our data. A data recovery plan begins with prioritizing our data, protecting it while it is being stored, and having a plan to recover data. Key Takeaways for Control 11Prioritize your data and come...
Blog
VERT Threat Alert: August 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 08/10/2021
Today’s VERT Alert addresses Microsoft’s August 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-959 on Wednesday, August 11th.In-The-Wild & Disclosed CVEsCVE-2021-36948This privilege escalation vulnerability that affects the Windows Update Medic Service (WaasMedic) has been actively...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 31, 2022
By Andrew Swoboda on Mon, 02/07/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 31, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
Update Force-Pushed to Protect...
Blog
WaterISAC: 15 Security Fundamentals You Need to Know
By Stefanie Shank on Wed, 01/24/2024
2023 saw two concerning attacks on public water systems, highlighting the fragility and risk to utility systems. In Pennsylvania, malicious hackers breached the Municipal Water Authority of Aliquippa system the night after Thanksgiving. The criminals were making a political statement: the technology used to manage water pressure was developed by...
Blog
10 Database Security Best Practices You Should Know
By Katrina Thompson on Mon, 04/29/2024
Statista shows a near doubling of data compromises between last year (3,205) and the year before (1,802). Cybercriminals go where the data goes, and there is more need than ever for effective database security measures.
These tactics differ from network security practices, which rely heavily on software solutions and even employee best practices....
Blog
Design & Implementation of OEM ICS Cybersecurity Frameworks: The Good, The Bad, and The Ugly
By Editorial Staff on Sun, 07/05/2020
The cyber threat landscape today continues to pose a myriad of unique challenges. This is especially the case for industrial organizations due to factors such as aging equipment, poor design or implementation, skills gaps and a lack of visibility. These shortcomings are exacerbated by the mean time to breach detection, which continues to hover above...
Blog
VERT Threat Alert: May 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 05/12/2020
Today’s VERT Alert addresses Microsoft’s May 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-884 on Wednesday, May 13th.
In-The-Wild & Disclosed CVEs
None of the vulnerabilities resolved this month have been publicly disclosed or exploited according to Microsoft.
CVE Breakdown by Tag
...
Blog
30 Ransomware Prevention Tips
By Guest Authors on Tue, 04/11/2023
Dealing with the aftermath of ransomware attacks is like Russian roulette. Submitting the ransom might seem like it’s the sole option for recovering locked data. Ransomware also continues to evolve as a threat category within the past year, with old names like REvil rearing their heads and new players like Black Basta emerging in 2022. Malicious...