Blog
Mastering Cybersecurity Incident Communication Part 1: A Proactive Approach
By Guest Authors on Mon, 04/07/2025
Cybersecurity threats are no longer a matter of "if" but "when." While companies invest heavily in technical defenses, one important aspect often gets overlooked — communication.How an organization communicates during a cybersecurity incident determines the speed and effectiveness of its response, as well as the level of trust it maintains with stakeholders.Here, we’ll walk through the...
Blog
April 2025 Patch Tuesday Analysis
By Tyler Reguly on Tue, 04/08/2025
Today’s Patch Tuesday Alert addresses Microsoft’s April 2025 Security Updates. We are actively working on coverage for these vulnerabilities and expect to ship ASPL-1151 as soon as coverage is completed.In-The-Wild & Disclosed CVEsCVE-2025-29824A vulnerability in the Windows Common Log File System (CLFS) Driver could allow a malicious actor to elevate their privileges to SYSTEM. Microsoft has...
Blog
Tripwire Patch Priority Index for March 2025
By Lane Thames on Fri, 04/04/2025
Tripwire's March 2025 Patch Priority Index (PPI) brings together important vulnerabilities for Microsoft and Google.Up first on the list are patches for Microsoft Edge (Chromium-based) and Google Chromium that resolve spoofing, out of bounds read, use after free, and other vulnerabilities.Next on the list are patches for Microsoft Office, Excel, Word, and Access. These patches resolve 12 remote...
Blog
As Vishing Gains Momentum, It’s Time to Fight Back
By Guest Authors on Tue, 05/06/2025
The mechanisms and dangers of email phishing are well known, as are the best practices for hardening organizations against it. Its spin-off, called vishing, is nothing new, but it’s both rapidly evolving, and unlike the more mainstream counterpart, too often overlooked by security professionals. According to the CrowdStrike 2025 Global Threat Report, these offbeat attacks saw a 442% increase in...
Blog
Getting Email Security Right
By Zachary Travis on Mon, 05/05/2025
Let’s face it: your inbox is a warzone. Email security is a constant battle between evolving threats and the defenses designed to stop them. Every day, attackers bombard user inboxes with increasingly sophisticated phishing attempts, malware, and social engineering attacks. So, how do we win the battle? It’s not as simple as slapping on a piece of software; it’s about implementing a multi-layered...
Blog
Tripwire & FoxGuard: Patching for compliance and security
By David Bruce on Wed, 04/13/2022
There’s a saying in the cybersecurity community which states that just because you are compliant doesn’t mean that you are secure. Over the years, many images have been used to illustrate the point. One memorable image is that of a nude bicyclist wearing a helmet. By all standards, that is the epitome of “compliant, but not secure”. Many organizations...
Blog
A CISO's Guide to Minimizing Healthcare Risk
By Guest Authors on Sun, 01/14/2018
There are many actionable items and methods a CISO can use to minimize risk in the healthcare industry. After all, there are all kinds of tools, project management resources, and resource management solutions that can help keep businesses in order and safe. However, there just a few areas in which action should be taken. As simple as it might sound,...
Blog
How to Spot a Winning NERC CIP Project
By Paul Stewart on Wed, 06/19/2024
The North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) regulations often make exacting demands of Fortra Tripwire's customers, requiring them to update or create new change processes and document those processes in order to comply. In any NERC CIP-centered IT\OT project, there are always crucial indicators of success - even before the project gets...
Blog
Expanding on ADHICS v2.0: A Closer Look at Healthcare Cybersecurity in the UAE
By Kirsten Doyle on Mon, 06/09/2025
As digital transformation sweeps across the healthcare sector, there has never been more at stake. Healthcare data is worth a lot on the black market. Unlike financial data, which has a short shelf life (accounts can be frozen, and fraud alerts issued), medical records stay fresh for a long time.They contain a host of personal information, like medical histories, insurance data, and payment...
Blog
US Senators Push for Stronger Cybercrime and Computer Fraud Legislation
By Josh Breaker-Rolfe on Thu, 04/17/2025
It’s been a pretty divisive few months in US politics. The Trump administration has made sweeping changes in almost all areas of policy, ranging from international relations to domestic regulations and everything in between. However, some areas of American politics aren’t so contentious; in fact, a few cybersecurity policies have received bipartisan support. The Cyber Conspiracy Modernization Act,...
Blog
Tips for Defending Against Adversarial Actions Regardless of Their Origin
By Editorial Staff on Wed, 01/19/2022
When an unfortunate event occurs, people tend to be curious about who was responsible for the event. It can be interesting and helpful to know who your enemy is and what their motives might be. But in cybersecurity, the primary focus is ultimately on preventative and detective measures to avoid similar issues. Let’s use a recent example to illustrate...
Blog
Essential Features to Look for in a VM Solution
By Katrina Thompson on Mon, 06/30/2025
Why Choosing the Right VM Tool MattersYour vulnerability management solution is the fuel that powers the rest of your strategic cybersecurity objectives. Put good in, get good out.That's why the vulnerability management tool you choose matters. And there are a lot of features that are necessary to protect a modern environment today that weren't on the list before.Done right, VM provides a stable...
Blog
Who Is Responsible for Your Cloud Security?
By Kim Crawley on Tue, 08/27/2019
The cloud is a tremendous convenience for enterprises. Running a data center is expensive – doing so not only requires buying a lot of servers, cable and networking appliances but also electricity, labor costs, cooling and physical space. Services like Amazon’s AWS, Microsoft’s Azure, Oracle’s Cloud and Google’s Cloud Platform give businesses the...
Datasheet
Tripwire Enterprise Commander
Many enterprise applications lack a native command line interface. This can be a challenge if you want to automate and integrate basic operations, which is a necessary function in most enterprise IT environments. Tripwire® Enterprise (TE) Commander is a cross-platform CLI for Tripwire Enterprise that allows unlimited integration and workflow possibilities. It offers a consistent, flexible and...
Quote
Request Tripwire Pricing Information
Ready for a quote? Let's transform your security and compliance efforts with Tripwire solutions, trusted by the cybersecurity community for over 25 years and counting. Build a strong foundation for security, compliance, and operational excellence. 1,600+ Customers Aroundthe World65+ Security-RelatedPatents4,000+ PoliciesSupported
Complete the form...
Blog
5 Critical Security Risks Facing COBOL Mainframes
By Gilad David Maayan on Tue, 07/01/2025
COBOL remains deeply embedded in the infrastructure of global enterprises, powering critical systems in banking, insurance, government, and beyond. While its stability and processing efficiency are unmatched, legacy environments running COBOL face a growing challenge: Security.As cyber threats evolve and legacy systems continue to age, COBOL-based mainframes present attractive targets due to their...
Blog
Securing Against Phishing Beyond Email
By Isla Sibanda on Mon, 07/14/2025
Phishing is no longer just an email problem. Reports state that 40% of phishing campaigns now span channels beyond email, hitting collaboration tools like Slack and Teams, plus SMS, and social media platforms. Voice phishing (“vishing”) in particular is on the rise: 30% of surveyed organizations reported at least one instance of attackers using spoofed or AI-cloned calls to steal credentials in...