Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of July 25, 2022
By Andrew Swoboda on Mon, 08/01/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of July 25, 2022. I’ve also included some comments on these stories.
SonicWall fixed critical SQLi in Analytics and GMS...
Blog
VERT Threat Alert: April 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/12/2022
Today’s VERT Alert addresses Microsoft’s April 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-996 on Wednesday, April 13th.
In-The-Wild & Disclosed CVEs
CVE-2022-24521
While not previously publicly disclosed, Microsoft is reporting that they have seen active exploitation of this...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of March 14, 2022
By Editorial Staff on Mon, 03/21/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of March 14, 2022. I’ve also included some comments on these stories.
Most Orgs Would Take Security Bugs Over Ethical Hacking...
Tripwire Security and Compliance Services
Find the Right Cybersecurity Services For YouAre you just getting started with your Tripwire solution? Or are you a long-time customer seeking guidance on best practices? Tripwire service experts are ready to help you tackle your biggest cybersecurity and compliance challenges with a variety of flexible options tailored around you. Whether you need managed cybersecurity services, strategic advice,...
Blog
Understanding Managed Service Providers (MSPs): Choosing the Right Provider
By Jim Whiting on Wed, 08/21/2024
The demand for robust security, transparency, and accountability is at an all-time high, and many businesses are relying on managed service providers (MSPs) to manage their IT infrastructure, ensure data security, or provide seamless operational support. Concurrently, MSPs must continuously innovate and differentiate their offerings to meet the growing needs of businesses.The wide range of MSPs...
Blog
VERT Threat Alert: December 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 12/14/2021
Today’s VERT Alert addresses Microsoft’s December 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-978 on Wednesday, December 15th.
In-The-Wild & Disclosed CVEs
CVE-2021-43890
Up first this month is a vulnerability in the Windows AppX Installer that could allow spoofing. This...
Blog
VERT Threat Alert: June 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/08/2021
Today’s VERT Alert addresses Microsoft’s June 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-947 on Wednesday, June 9th.In-The-Wild & Disclosed CVEsCVE-2021-31955This is one of two vulnerabilities fixed in today’s patch drop which were reported by Kaspersky Lab after detecting...
Blog
VERT Threat Alert: August 2021 Patch Tuesday Analysis
By Tyler Reguly on Tue, 08/10/2021
Today’s VERT Alert addresses Microsoft’s August 2021 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-959 on Wednesday, August 11th.In-The-Wild & Disclosed CVEsCVE-2021-36948This privilege escalation vulnerability that affects the Windows Update Medic Service (WaasMedic) has been actively...
Blog
Extra, Extra, VERT Reads All About It: Cybersecurity News for the Week of January 31, 2022
By Andrew Swoboda on Mon, 02/07/2022
All of us at Tripwire’s Vulnerability Exposure and Research Team (VERT) are constantly looking out for interesting stories and developments in the infosec world. Here’s what cybersecurity news stood out to us during the week of January 31, 2022. We’ve also included the comments from a few folks here at Tripwire VERT.
Update Force-Pushed to Protect...
Blog
VERT Threat Alert: May 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 05/12/2020
Today’s VERT Alert addresses Microsoft’s May 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-884 on Wednesday, May 13th.
In-The-Wild & Disclosed CVEs
None of the vulnerabilities resolved this month have been publicly disclosed or exploited according to Microsoft.
CVE Breakdown by Tag
...
Blog
VERT Threat Alert: November 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/10/2020
Today’s VERT Alert addresses Microsoft’s November 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-915 on Wednesday, November 11th. Note: Microsoft has changed their advisory format and no longer provides basic vulnerability descriptions.In-The-Wild & Disclosed CVEsCVE-2020-17087This CVE...
Blog
VERT Threat Alert: April 2020 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/14/2020
Today’s VERT Alert addresses Microsoft’s April 2020 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-880 on Wednesday, April 15th.
In-The-Wild & Disclosed CVEs
CVE-2020-0935
A vulnerability in the OneDrive for Windows desktop application could allow an attacker to overwrite a targeted file...
Blog
VERT Threat Alert: June 2023 Patch Tuesday Analysis
By Tyler Reguly on Tue, 06/13/2023
Today’s VERT Alert addresses Microsoft’s June 2023 Security Updates, which include a new release notes format. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1060 on Wednesday, June 14th.
In-The-Wild & Disclosed CVEs
There were no in-the-wild or disclosed CVEs in the June Patch Tuesday drop. CVE Breakdown...
Blog
Increasing Your Business’ Cyber Maturity with Fortra
By Antonio Sanchez on Wed, 09/20/2023
When building a tower, it helps to start with a sturdy foundation. Cyber maturity is the tower, and there are three levels that build it:
Foundational IT/OT & Security Control Processes
Fundamental Security Control Capabilities
Advanced Security Control Capabilities
Fortra occupies a unique space in the industry because of the sheer size of...
Blog
VERT Threat Alert: September 2023 Patch Tuesday Analysis
By Tyler Reguly on Tue, 09/12/2023
Today’s VERT Alert addresses Microsoft’s September 2023 Security Updates, which includes a recently introduced release notes format. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1073 on Wednesday, September 13th.
In-The-Wild & Disclosed CVEs
CVE-2023-36761
Microsoft has indicated that a vulnerability...
Quote
Get a Custom Quote for Tripwire ExpertOps
Instant Expertise With Managed Cybersecurity
Does your security team have too much to do and too little time? Managed services are the perfect route to get all the benefits of a leading cybersecurity solution without having to operate it yourself.
Fortra’s Tripwire® ExpertOps℠ is a managed cybersecurity service that equips you with the advice and support needed to protect your data from...
Blog
VERT Threat Alert: November 2024 Patch Tuesday Analysis
By Tyler Reguly on Tue, 11/12/2024
Today’s VERT Alert addresses Microsoft’s November 2024 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1132 as soon as coverage is completed. In-The-Wild & Disclosed CVEsCVE-2024-43451A vulnerability that allows for NTLMv2 hash disclosure has been both publicly disclosed and actively exploited. According to Microsoft, only minimal...
Datasheet
Automating FISMA Compliance with Tripwire Security Configuration Management
FISMA requires federal agencies, and by extension, the foundations, educational institutions, organizations that receive federal funds as well as the contractors that do business with them, to develop, document, and implement information security programs to protect the confidentiality, integrity and availability of the data and systems that support government operations and assets.In meeting...
Datasheet
Meeting FISMA SI-7 with Tripwire Integrity Monitoring
To enhance your Federal Information Security Management Act (FISMA) compliance grade, you must implement one of the most challenging controls in NIST SP 800-53: the Controls, Family: System Information & Integrity (SI) 7 requirement. SI-7 states that organizations must employ automated and centrally managed integrity verification tools to detect unauthorized change. This level of visibility can be...