What’s New and Changing in the World of Vulnerability Management?

According to CIS, “Organizations that do not scan for vulnerabilities and proactively address discovered flaws face a significant likelihood of having their computer systems compromised.” While vulnerability management (VM) isn’t new,… Continue reading What’s New and Changing in the World of Vulnerability Management?

Things You Need to Know About Open Source – The FAQ Edition

Open Source projects can be a great asset, or they can be a curse. It is all in how you manage it. To be successful in using open source, there are several things to keep in mind, from licensing to updates. And if you ignore any of them, it can cause p… Continue reading Things You Need to Know About Open Source – The FAQ Edition

Vulnerability Management and Patch Management Are Not the Same

Vulnerability management and patch management are not products. They are processes, and the products are tools used to enable the process. You cannot buy a hammer, nails and wood and expect them to just become a house, but you can go through the proces… Continue reading Vulnerability Management and Patch Management Are Not the Same

VERT Threat Alert: CPU Vulnerabilities – Meltdown and Spectre

Vulnerability Description Meltdown and Spectre are hardware design vulnerabilities in CPUs utilizing speculative execution. While the defect exists in the hardware, mitigations in operating systems are possible and are currently available. CPU hardware… Continue reading VERT Threat Alert: CPU Vulnerabilities – Meltdown and Spectre

Super X-Ray Vision for Vulnerabilities into Non-Running Containers

Containers can be traced back to 1979 with chroot but the advent of Docker has exponentially increased the popularity and usefulness of this technology. Any technology that becomes popular and useful also becomes a target for attacks. Containers are designed to provide isolated environments rather than full virtual machines, but they make great targets for […]… Read More

The post Super X-Ray Vision for Vulnerabilities into Non-Running Containers appeared first on The State of Security.

Continue reading Super X-Ray Vision for Vulnerabilities into Non-Running Containers