Tenable 博客
Why Security and IT Disagree on Patching (and Why That's a Good Thing)
Tenable 网络观察:维持元宇宙治安、保护 AI 和 ML 安全、Daixin 对医疗机构的威胁以及改为使用集成式网络平台
To help you zap those Monday blahs, here’s a caffeinated shot of cyber news you can use: Police chiefs must get hip to the metaverse. CISOs are shifting to integrated cybersecurity platforms. There's new guidance for securing ML and AI systems. Hospitals face a ransomware threat from the Daixin…
網路安全快照: 网络钓鱼诈骗、薪资趋势、元宇宙风险、Log4J 问卷调查
Get the latest on worrisome phishing stats; businesses’ embrace of the metaverse, come what may; a (small) improvement in CISO job stability; the compensation cost of security leaders; and more!
Microsoft 的 2022 年补丁星期二解决了 48 个 CVE (CVE-2022-44698)
Microsoft addresses 48 CVEs including two zero-day vulnerabilities, one that has been exploited in the wild (CVE-2022-44698) and one that was publicly disclosed prior to a patch being available (CVE-2022-44710).
CVE-2022-27518:Citrix ADC 和网关中未经身份验证的 RCE
Citrix has patched a critical remote code execution vulnerability in its Gateway and ADC products. This vulnerability has reportedly been exploited as a zero day; organizations should patch urgently.
如何评估 IT 服务提供商和 MSP 的网络安全准备情况
Improperly evaluating the cybersecurity capabilities of prospective IT service providers and managed service providers (MSPs) can put your organization's data and systems at risk. A new guide from CompTIA can help you ask the right questions.
CVE-2022-42475:Fortinet 修补了 FortiOS SSL VPN 中的零日漏洞
Fortinet has patched a zero day buffer overflow in FortiOS that could lead to remote code execution. There has been a report of active exploitation and organizations should patch urgently.
当元宇宙进入您的攻击面时会发生什么?
Tenable polled 1,500 cybersecurity, IT and DevOps professionals about their top concerns in the nascent virtual reality worlds of the metaverse. Here's what we found out.
Tenable 网络观察:提早应对安全挑战、反勒索软件的努力、大量增加的风险和 CISO 焦虑
Beat the Monday blues with cyber news you can use | Shift-left efforts falling short. The White House’s war on ransomware. Everything you’ve ever wanted to know about CISOs. The quantum computing risk for critical infrastructure. Don’t miss the latest episode of the Tenable Cyber Watch. The…
網路安全快照: Log4j 周年纪念、CI/CD 风险、Infostealer、电子邮件攻击,OT 安全
Get the latest on the anniversary of the Log4j crisis; OWASP’s top CI/CD risks; a surge of infostealer malware; the fund transfer fraud — business email compromise connection; and more!