Imprudente, sem sofisticação ou lógica: como entender o grupo de extorsão LAPSUS$
Depois de receber a atenção do setor nos primeiros meses de 2022, o grupo de extorsão LAPSUS$ está quieto há algum tempo. O que podemos aprender com a história e as táticas desse grupo de extorsão?
Cybersecurity Snapshot: 6 Things That Matter Right Now
Topics that are top of mind for the week ending July 15 | Government cybersecurity efforts tripped by technical debt. Neglect SaaS security at your own risk. A ranking of the most dangerous software weaknesses. Lessons learned about critical infrastructure security. And much more!
Securing Critical Infrastructure: What We've Learned from Recent Incidents
Learn about well-known vulnerabilities and attacks and how they affected critical infrastructure —from Phone Phreaking to recent ransomware.
Microsoft’s July 2022 Patch Tuesday Addresses 84 CVEs (CVE-2022-22047)
Microsoft addresses 84 CVEs in its July 2022 Patch Tuesday release, including four critical flaws and one zero day that has been exploited in the wild.
Apresentamos o Nessus Expert, agora projetado para a superfície de ataque moderna
O Nessus tem sido o líder indiscutível na avaliação de vulnerabilidades. Com o lançamento do Nessus Expert, agora você pode proteger-se contra novas ameaças cibernéticas emergentes na infraestrutura de nuvem e entender o que está em sua superfície de ataque externa.
Cloud and Data Security for Financial Services
Financial service organizations are adopting the cloud at a rapid pace. A robust solution for compliance and cloud security will ensure they enjoy all the benefits.
Cybersecurity Snapshot: 6 Things That Matter Right Now
Topics that are top of mind for the week ending July 1 | Cybersecurity budgeting priorities. All you ever wanted to know about ransomware. CISOs weigh best-of-breed vs. platforms. The epidemic of identity-related breaches. And much more!
CVE-2022-28219: Proof-of-Concept Published for Unauthenticated RCE in Zoho ManageEngine ADAudit Plus
New information and technical details, including a proof-of-concept have been published for a remote code execution flaw in Zoho ManageEngine ADAudit Plus that was patched last month.
OT:ICEFALL Research from Forescout Explores Insecure-by-Design State of Operational Technology
The latest research from Forescout’s Vedere Labs explores the state of risk management in operational technology through the lens of 56 insecure-by-design vulnerabilities.
Análise do ecossistema de ransomware: de bloqueador de telas a uma empresa criminosa que vale milhões de dólares
O ransomware é uma ameaça cibernética em constante evolução, e é por meio de sua evolução que o ransomware conseguiu não apenas sobreviver, mas prosperar.
Identifying XML External Entity: Como o Tenable.io Web Application Scanning pode ajudar
XML External Entity (XXE) flaws present unique mitigation challenges and remain a common attack path. Learn how XXE flaws arise, why some common attack paths are so challenging to mitigate and how Tenable.io Web Application Scanning can help.
CVE-2022-27511, CVE-2022-27512: Patches for Two Citrix Application Delivery Management Vulnerabilities
Citrix patches a “nasty bug” in its Application Delivery Management solution that is difficult to exploit.