‘Wormable’ Flaw Leads January 2022 Patch Tuesday

Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another. Continue reading ‘Wormable’ Flaw Leads January 2022 Patch Tuesday

Alkira partners with Exclusive Networks to expand its cloud market share

Alkira has appointed Exclusive Networks, a global trusted cybersecurity specialist for digital infrastructure, as a distributor for its cloud networking as-a-service platform (CNaaS). The deal makes Alkira’s CNaaS platform Cloud Services Exchange (CSX)… Continue reading Alkira partners with Exclusive Networks to expand its cloud market share

Lightspin adds four executive members to its Advisory Board and Board of Directors

Lightspin announced the addition of four strategic executive members to its advisory board and board of directors: Guarav Kumar, Srinath Kuruvadi, Steve Pugh, and Ron Zoran. The new members each have an established track record as industry CISOs and cl… Continue reading Lightspin adds four executive members to its Advisory Board and Board of Directors

deepwatch appoints two cybersecurity industry executives to Board of Advisors

deepwatch announced the appointment of two prominent cybersecurity industry executives to its newly formed board of advisors, which will provide support and guidance for deepwatch’s strategic growth initiatives. The advisors include Jody Len, previousl… Continue reading deepwatch appoints two cybersecurity industry executives to Board of Advisors

Plug critical VMvare vCenter Server flaw before ransomware gangs start exploiting it (CVE-2021-22005)

VMware has fixed 19 vulnerabilities affecting VMware vCenter Server and VMware Cloud Foundation, the most critical of which is CVE-2021-22005. “This vulnerability can be used by anyone who can reach vCenter Server over the network to gain access,… Continue reading Plug critical VMvare vCenter Server flaw before ransomware gangs start exploiting it (CVE-2021-22005)

Vulnerabilities allow attackers to remotely deactivate home security system (CVE-2021-39276, CVE-2021-39277)

A DiY home security system sold to families and businesses across the US sports two vulnerabilities (CVE-2021-39276, CVE-2021-39277) that, while not critical, “are trivially easy to exploit by motivated attackers who already have some knowledge o… Continue reading Vulnerabilities allow attackers to remotely deactivate home security system (CVE-2021-39276, CVE-2021-39277)

Unpatched Fortinet FortiWeb vulnerability allows remote OS command injection

An unpatched vulnerability in the management interface for FortiWeb, Fortinet’s web application firewall, could allow a remote, authenticated attacker to execute arbitrary commands on the system, Rapid7 researcher William Vu has discovered. Tod B… Continue reading Unpatched Fortinet FortiWeb vulnerability allows remote OS command injection

VCs are betting big on Kubernetes: Here are 5 reasons why

At times, Kubernetes can feel like a superpower, but with all of the benefits of scalability and agility comes immense complexity. The truth is, few developers understand how Kubernetes works. Continue reading VCs are betting big on Kubernetes: Here are 5 reasons why

Code42 partners with Rapid7 to help security teams prioritize risks and strengthen compliance

Code42 announced it has integrated the Code42 Incydr product with Rapid7 InsightIDR. Security teams using InsightIDR with the Code42 Incydr integration will have the ability to identify, prioritize and triage the most critical insider threat events – d… Continue reading Code42 partners with Rapid7 to help security teams prioritize risks and strengthen compliance

Rapid7 Acquires IntSights to Gain External Threat Intelligence

Rapid7, Inc. this week announced it has acquired IntSights Cyber Intelligence Ltd. for $335 million as part of an effort to provide more visibility into potential external threats as they unfold on the dark web. Richard Perkett, vice president of dete… Continue reading Rapid7 Acquires IntSights to Gain External Threat Intelligence