Blog
Cybersecurity in the Cloud: The Challenging Hurdles It Has To Overcome
By Guest Authors on Wed, 05/03/2023
Cloud Security Challenges
Organizations embracing cloud environments must understand that cloud applications and services have become popular targets for cybercriminals. A few notable and inherent risks with cloud deployments include:
API Vulnerabilities
Unfortunately, API exploits are on the rise, costing organizations dearly. Whether it’s...
Blog
Tripwire Patch Priority Index for September 2022
By Lane Thames on Mon, 11/21/2022
Tripwire's September 2022 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft.
First on the patch priority list this month are patches for Chromium and Microsoft Edge based on Chromium. These patches resolve over 20 issues such as user-after-free, insufficient policy enforcement, out-of-bounds write, and heap buffer...
Blog
Staying protected from cybercriminals this holiday season
By Guest Authors on Tue, 11/22/2022
As we approach the holiday season, we wanted to focus this month’s post on you (and your family). Bad guys don’t just wait until the holidays to start causing havoc, they also relentlessly target all of us all throughout the year. Judging by our perseverance, nothing is going to keep us from a good holiday deal, and attackers love to use this season...
Blog
Insight into The 2022 Vulnerability Management Report
By Guest Authors on Wed, 12/21/2022
This year marks the release of the first 2022 Vulnerability Management Report from Fortra. The report, which was conducted in September 2022, is based on a comprehensive survey of over 390 cybersecurity professionals with the goal of gaining insights into the latest trends, key challenges, and vulnerability management solution preferences.
...
Blog
The prevalence of RCE exploits and what you should know about RCEs
By Guest Authors on Tue, 01/17/2023
Recent headlines have indicated that some major companies were affected by Remote Code Execution (RCE) vulnerabilities, just in the month of October. RCE flaws are largely exploited in the wild, and organizations are continually releasing patches to mitigate the problem. RCE is a type of an Arbitrary Code Execution (ACE) attack where the threat...
Blog
Tripwire Enterprise Use Cases- Advanced Control
By David Bruce on Fri, 12/09/2022
During my time as a cybersecurity admin, I had the authority to decide what was going to be done, but I didn’t have the access to configure or install my own software. To make matters worse, despite having authority over the implementation, I was also held accountable for failures but again, without the necessary access to fix issues. This created a...
Blog
VERT Threat Alert: December 2022 Patch Tuesday Analysis
By Tyler Reguly on Tue, 12/13/2022
Today’s VERT Alert addresses Microsoft’s December 2022 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-1034 on Wednesday, December 14th.
In-The-Wild & Disclosed CVEs
CVE-2022-44698
This vulnerability allows a malicious individual to bypass SmartScreen, which does a reputation check based...
Blog
Beware a Swarm of Scams this Holiday Season
By Guest Authors on Tue, 12/20/2022
Call her Linda Leesburg. Fresh out of graduate school and starting her first serious job, she decided to buy some kitchen utensils and related items, including a dish set, cookware, silverware and a coffee maker, to outfit the kitchen of her new apartment. She could easily buy these products at a local store, but she discovered a store online that...
Blog
CISOs and their Boards of Directors: Viewing Cyber Risk Differently
By Guest Authors on Tue, 01/03/2023
CISOs – the senior level executives responsible for developing and implementing cybersecurity programs for corporations and other organizations – are not happy campers these days. And it’s not just because they are chronically understaffed and under constant pressure.
As it turns out, Chief Information Security Officers (CISOs) often don’t see eye...
Blog
Don't click too quick! FBI warns of malicious search engine ads
By Graham Cluley on Thu, 12/22/2022
The FBI is warning US consumers that cybercriminals are placing ads in search engine results that impersonate well-known brands, in an attempt to spread ransomware and steal financial information.
In a public service announcement issued this week, the FBI describes how cybercriminals are purchasing ads that show up at the very top of search engine...
Blog
Air-Gapped Computers Can Be Compromised Using EM Side-Channel Attacks, Say Researchers
By David Bisson on Fri, 01/30/2015
Researchers at the Georgia Institute of Technology have developed a methodology that uses electromagnetic (EM) side-channel signals to attack a computer, regardless of whether or not it’s been air-gapped. In their research paper, Robert Callan, Alenka Zajic, and Milos Prvulovic discuss that their metric, which they call Signal Available to Attacker ...
Blog
Don’t be Shellshocked by GHOST
By Editorial Staff on Wed, 01/28/2015
If you’re following threat feeds, you’ve probably heard about GHOST (CVE 2015-0235), the new critical vulnerability that Qualys disclosed yesterday. This vulnerability has been found in glibc, the GNU C library, and it affects all Linux systems dating back to 2000. Redhat listed it on their CVE database as ‘critical’ with a CVSS v2 score of 6.8....
Blog
Data Privacy Day Raises Awareness on Consumer Privacy, Cybersecurity Best Practice
By Editorial Staff on Tue, 01/27/2015
On Wednesday, January 28, the National Cyber Security Alliance (NCSA) will launch its eighth annual Data Privacy Day in the United States in an effort to emphasize the importance of “respecting privacy, safeguarding data and enabling trust.” The annual day of awareness aims to encourage consumers to become educated on how to strengthen the privacy...
Blog
Marriott Customers' Personal Details Exposed by Simple Web Flaw
By Graham Cluley on Tue, 01/27/2015
Here's a piece of advice for anyone responsible for securing a corporation's data: If you discover security researcher Randy Westergren is using your app, you had best take a long hard look at whether you are protecting your users' information properly. Because, if you're not, there's a good chance that he might be about to tell you what you're...
Blog
Thousands of U.S. Gas Stations Found Vulnerable to Dangerous Internet Attacks
By Editorial Staff on Fri, 01/23/2015
More than 5,000 devices used to operate gas stations across the United States were found vulnerable to dangerous Internet attacks, revealed a security researcher this week. The flaw was found in the gas stations’ automated tank gauges, or ATGs, which raise alarms indicating an issue with the tank or gauge, such as a fuel spill. The devices also...
Blog
Kim Dotcom Reveals His End-to-End Encrypted Video Chat Service, MegaChat
By Graham Cluley on Thu, 01/22/2015
The ever-controversial hacker-turned-millionaire-entrepreneur Kim Dotcom has announced the public beta launch of an end-to-end encrypted audio and video chat service, which he calls MegaChat. Anyone with an account on Mega's file-sharing file-syncing service can now access what is claimed to be a more secure alternative to Skype, boasting end-to-end...
Blog
VERT Vuln School: XSS versus XSRF
By Craig Young on Tue, 01/20/2015
Cross-site scripting, commonly referred to as XSS, is listed third in the OWASP Top 10 for 2013 Web Application Security risks. Unlike SQL injection attacks, which target data on the server, XSS provides a vector for attacking the users of a vulnerable web site. At a general level, XSS is when an attacker can cause a web site to render with...
Blog
Vulnerability Scoring 102
By Tyler Reguly on Wed, 01/14/2015
In my last post, I talked about the basics of vulnerability scoring in vulnerability management and the disparity that can exist when you score the subjective elements of a vulnerability. We looked at the variance that can exist within CVSSv2 and how a properly developed score can show a clear difference between two unique issues. This time, I want...