Shujinko AuditX expands compliance automation to all major clouds and regulatory frameworks

Shujinko announced a major update to AuditX, the system of record for enterprise compliance data. This update significantly broadens the platform’s automated data collection to cover firewall configuration, vulnerability scans, encryption certificates … Continue reading Shujinko AuditX expands compliance automation to all major clouds and regulatory frameworks

Microsoft Patch Tuesday, March 2021 Edition

On the off chance you were looking for more security to-dos from Microsoft today…the company released software updates to plug more than 82 security flaws in Windows and other supported software. Ten of these earned Microsoft’s “critical” rating, meaning they can be exploited by malware or miscreants with little or no help from users. Continue reading Microsoft Patch Tuesday, March 2021 Edition

March 2021 Patch Tuesday: Microsoft fixes yet another actively exploited IE zero-day

As system administrators and security teams around the world are working on ascertaining whether they’ve been breached and compromised via vulnerable Microsoft Exchange Server installations, on this March 2021 Patch Tuesday: Microsoft has fixed 8… Continue reading March 2021 Patch Tuesday: Microsoft fixes yet another actively exploited IE zero-day

How do I select a cloud security solution for my business?

Attackers increasingly strive to leverage cloud weaknesses that enable them to deliver malware to end users, gain unauthorized access to production environments or their data, or completely compromise a target environment. This strategy is known as a w… Continue reading How do I select a cloud security solution for my business?

Tenable launches an all-in-one, risk-based vulnerability management platform

Tenable launched Tenable.ep, all-in-one, risk-based vulnerability management platform designed to scale as dynamic compute requirements change. Tenable.ep combines the company’s products — Tenable.io Vulnerability Management, Tenable.io Web Application… Continue reading Tenable launches an all-in-one, risk-based vulnerability management platform

Tenable acquires Alsid to provide users with a more complete approach to cyber preparedness

Tenable announced that it has entered into a definitive agreement to acquire Alsid SAS. Alsid for Active Directory is a Software as a Service (SaaS) solution with an on-premises deployment option that monitors the security of Active Directory in real t… Continue reading Tenable acquires Alsid to provide users with a more complete approach to cyber preparedness

These 3 enterprise deals show there’s plenty of action in smaller acquisitions

Since the start of the year, I’ve covered nine M&A deals already, the largest being Citrix buying Wrike for $2.25 billion. But not every deal involves a huge price tag. Today we are going to look at three smaller deals that show there is plenty of activity at the lower-end of the acquisition spectrum. As […] Continue reading These 3 enterprise deals show there’s plenty of action in smaller acquisitions

February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-days

On this February 2021 Patch Tuesday: Adobe has fixed a Reader flaw used in limited attacks, as well as delivered security updates for a variety of products, including Acrobat and Reader, Dreamweaver, and Magento Microsoft has plugged 56 security holes,… Continue reading February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-days

A light December 2020 Patch Tuesday for a no-stress end of the year

On this December 2020 Patch Tuesday: Microsoft has plugged 58 CVEs Adobe has delivered security updates for Lightroom, Experience Manager, and Prelude, and has announced that updates for Acrobat and Reader will be released sometimes this week SAP has r… Continue reading A light December 2020 Patch Tuesday for a no-stress end of the year

After years of work, Congress passes ‘internet of things’ cybersecurity bill — and it’s kind of a big deal

Congress last week did something that it rarely does: It passed a meaningful cybersecurity bill. The legislation is aimed at enhancing the safeguards of internet-connected devices — also known as the internet of things (IoT) — such as smart sensors that monitor water quality or control ships in waterway locks. The bill is also a major step toward the federal government encouraging vulnerability disclosure policies that implement programs for organizations to work with security researchers to fix software flaws. “It is arguably the most significant U.S. IoT-specific cybersecurity law to date, as well as the most significant law promoting coordinated vulnerability disclosure in the private sector to date,” said Harley Geiger, director of public policy at Rapid7, a cybersecurity company. All it took to get across the finish line was more than three years of bipartisan work, encroaching state and foreign government IoT rules, a ticking legislative clock, goodwill toward […]

The post After years of work, Congress passes ‘internet of things’ cybersecurity bill — and it’s kind of a big deal appeared first on CyberScoop.

Continue reading After years of work, Congress passes ‘internet of things’ cybersecurity bill — and it’s kind of a big deal