Tenable.cs prevents cloud security risk and improves developer productivity

Tenable released Tenable.cs, adding new cloud-native security capabilities to its platform. Coming on the heels of its acquisition of Accurics, Tenable.cs enables organizations to accelerate innovation by aligning development, operational and security … Continue reading Tenable.cs prevents cloud security risk and improves developer productivity

Attackers exploit another zero-day in ManageEngine software (CVE-2021-44515)

A vulnerability (CVE-2021-44515) in ManageEngine Desktop Central is being leveraged in attacks in the wild to gain access to server running the vulnerable software. About CVE-2021-44515 CVE-2021-44515 is an authentication bypass vulnerability that coul… Continue reading Attackers exploit another zero-day in ManageEngine software (CVE-2021-44515)

New infosec products of the week: December 3, 2021

Here’s a look at the most interesting products from the past week, featuring releases from Castellan Solutions, Cossack Labs, Immuta, IriusRisk, Tenable, ThreatConnect, Verimatrix and Zerto. Open source cloud native security analyzer Terrascan embeds s… Continue reading New infosec products of the week: December 3, 2021

Open source cloud native security analyzer Terrascan embeds security into native DevOps tooling

Tenable enhanced Terrascan, an open source cloud native security analyzer that helps developers secure Infrastructure as Code (IaC). The new capabilities enable organizations to embed security into their DevOps tooling, pipelines and supply chains, mit… Continue reading Open source cloud native security analyzer Terrascan embeds security into native DevOps tooling

Infosec products of the month: November 2021

Here’s a look at the most interesting products from the past month, featuring releases from 1Password, Avast, Boxcryptor, Code42, ColorTokens, Cynamics, Fortanix, Hiya, Huntsman Security, Imperva, iStorage, Jetico, Netscout, Palo Alto Networks, Siren, … Continue reading Infosec products of the month: November 2021

Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)

It’s a light November 2021 Patch Tuesday from Microsoft: 55 fixed CVEs, of which two are zero-days under active exploitation: CVE-2021-42321, a Microsoft Exchange RCE, and CVE-2021-42292, a Microsoft Excel security feature bypass bug. Vulnerabili… Continue reading Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321, CVE-2021-42292)

New infosec products of the week: November 5, 2021

Here’s a look at the most interesting product releases from the past week, featuring releases from Cynamics, Imperva, Linux Foundation, Netscout and Tenable. Nessus 10 is out, with Raspberry Pi support Tenable has released Nessus 10 and extended suppor… Continue reading New infosec products of the week: November 5, 2021

Huntress launches endpoint protection capabilities to defend SMBs from cyberattacks

Huntress launched a series of platform enhancements designed to protect small and midsize businesses (SMBs) from modern cyberthreats. The release includes the general availability of the company’s Managed Antivirus (AV) service, new host isolation capa… Continue reading Huntress launches endpoint protection capabilities to defend SMBs from cyberattacks

Patch Tuesday, October 2021 Edition

Microsoft today issued updates to plug more than 70 security holes in its Windows operating systems and other software, including one vulnerability that is already being exploited in active attacks. This month’s Patch Tuesday also includes security fixes for the newly released Windows 11 operating system. Continue reading Patch Tuesday, October 2021 Edition

Microsoft patches actively exploited Windows zero-day (CVE-2021-40449)

On October 2021 Patch Tuesday, Microsoft has fixed 71 CVE-numbered vulnerabilities. Of those, only one was a zero-day exploited in attacks in the wild (CVE-2021-40449) and three were publicly known before the release of the patches. Vulnerabilities of … Continue reading Microsoft patches actively exploited Windows zero-day (CVE-2021-40449)