Exabeam and Armis Partner to Extend SIEM Visibility to Unmanaged and IoT Devices, Helping Security Teams Identify Malicious Activity Across All Devices

Partnership enables security teams to identify unmanaged assets connecting to the corporate network, detect lateral movement and prioritize IoT security alerts FOSTER CITY and PALO ALTO, Calif., July 7, 2020 – Exabeam, the Smarter SIEM™ company, and Ar… Continue reading Exabeam and Armis Partner to Extend SIEM Visibility to Unmanaged and IoT Devices, Helping Security Teams Identify Malicious Activity Across All Devices

OpenDXL Ontology: An open source language for connecting cybersecurity tools

The Open Cybersecurity Alliance (OCA) today announced the availability of OpenDXL Ontology, the first open source language for connecting cybersecurity tools through a common messaging framework. With open source code freely available to the security c… Continue reading OpenDXL Ontology: An open source language for connecting cybersecurity tools

CDPwn vulnerabilities open millions of Cisco enterprise devices to attack

If you have Cisco equipment in your enterprise network – and chances are good that you have – you should check immediately which feature the newly revealed CDPwn vulnerabilities in Cisco’ proprietary device discovery protocol and impl… Continue reading CDPwn vulnerabilities open millions of Cisco enterprise devices to attack

5 new vulnerabilities expose the ‘backbone’ of an enterprise network to data theft

A protocol that underpins widely used equipment made by telecommunications giant Cisco is vulnerable to multiple data-stealing attacks, researchers warned Wednesday. The five previously unreported vulnerabilities in implementations of the Cisco protocol — found by Armis Security, a California-based company — show the enduring challenge of keeping one insecure device from being a gateway to another for a hacker. The zero-day bugs affect the many voice-over-IP phones, routers, and switches at corporations around the world that use the protocol for communications. A hacker with enough skill and motivation to exploit the vulnerabilities could gain access to a company’s network and then, for example, take over the VOIP phones on the network to steal data or eavesdrop on calls. The routers and switches that are susceptible to the vulnerabilities form “the backbone of [an enterprise] network,” said Ben Seri, Armis’s vice president of research, who wrote a proof-of-concept for an attack on […]

The post 5 new vulnerabilities expose the ‘backbone’ of an enterprise network to data theft appeared first on CyberScoop.

Continue reading 5 new vulnerabilities expose the ‘backbone’ of an enterprise network to data theft

MDhex vulnerabilities open GE Healthcare patient monitoring devices to attackers

Researchers have discovered six critical and high-risk vulnerabilities – collectively dubbed MDhex – affecting a number of patient monitoring devices manufactured by GE Healthcare. The flaws may, according to GE Healthcare, allow an attacke… Continue reading MDhex vulnerabilities open GE Healthcare patient monitoring devices to attackers

Urgent11 flaws affect more medical, industrial devices than previously thought

When, in late July, Armis researchers revealed the existence of the so-called Urgent11 vulnerabilities in Wind River’s VxWorks real-time operating system, they noted that RTOS offerings by other vendors may also be vulnerable. As it turns out, th… Continue reading Urgent11 flaws affect more medical, industrial devices than previously thought

200 million enterprise, industrial, and medical devices affected by RCE flaws in VxWorks RTOS

Armis researchers have discovered 11 vulnerabilities (including 6 critical RCE flaws) in Wind River VxWorks, a real-time operating system used by more than two billion devices across industrial, medical and enterprise environments. Collectively dubbed … Continue reading 200 million enterprise, industrial, and medical devices affected by RCE flaws in VxWorks RTOS

Armis nabs $65M Series C as IoT security biz grows in leaps and bounds

Armis is helping companies protect IoT devices on the network without using an agent, and it’s apparently a problem that is resonating with the market, as the startup reports 700 percent growth in the last year. That caught the attention of investors, who awarded them with a $65 million Series C investment to help keep […] Continue reading Armis nabs $65M Series C as IoT security biz grows in leaps and bounds

Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack

Armis today announced the discovery of two critical vulnerabilities in Bluetooth Low Energy (BLE) chips made by Texas Instruments (TI) and used in Cisco, Meraki and Aruba wireless access points, called Bleedingbit. If exploited, they allow an unauthent… Continue reading Bleedingbit: Critical vulnerabilities in BLE chips expose millions of access points to attack