CVE-2023-38035: Ivanti Sentry API Authentication Bypass Zero-Day Exploited in the Wild
For the third time in a month, Ivanti discloses a zero-day vulnerability in one of its products that has been exploited in the wild
Tenable 網路觀察:White House Tackles Cyber Skills Shortage, Cost of Data Breaches Keeps Rising, and more
This week’s edition of Tenable Cyber Watch unpacks the White House’s new initiative to tackle the cyber skills shortage and addresses the surge data breach costs. Also covered: NSA and CISA’s security guidance for 5G network slicing.
網路安全概要: CIS Guide Outlines How To Attain an Affordable Cyber Hygiene Foundation
The Center for Internet Security unpacks how to establish foundational cyber hygiene at a reasonable cost. Plus, the Cyber Safety Review Board issues urgent security recommendations on its Lapsus$ report – and announces it’ll next delve into cloud security. Moreover, are humans or AI better at…
The Next Step in the IMDSv1 Redemption Journey
Learn about AWS’s new open source library for enforcing IMDSv2 and Tenable Cloud Security’s new lab for trying it out.
2023 年 Tenable Capture the Flag 競賽:獲勝者是...
It's time to crown the winners of this year's Capture the Flag Event!
Tenable 網路觀察:Hot Takes from Black Hat USA, SANS Releases 2023 Report on Security Awareness, and more
This week’s edition of Tenable Cyber Watch dishes out five hot takes from Black Hat USA and provides guidance on how to better mitigate shadow IT risks. Also covered: How you can boost your security awareness program.
網路安全概要: U.S. To Award Millions in AI Cyber Tool Contest, While NIST Revamps Cybersecurity Framework
Got an idea for a new AI-based cybersecurity product? You could win millions in a new contest. Meanwhile, NIST has drafted a major revision to the CSF 2.0 and wants your opinion about it. Also, there’s a new free tool that flags security flaws in public AI models. Plus, most cloud breaches are…
Tenable One 中全新推出 ExposureAI:瞭解預防性網路安全的未來
Tenable One 曝險管理平台已使企業預防性網路安全措施的實施方式大為改變。 現在透過 ExposureAI,使用者可以發揮生成式人工智慧的最大潛力,達到制敵機先的效果。
Secure Your AWS EC2 Instance Metadata Service (IMDS)
Read this review of IMDS, an important AWS EC2 service component, to understand its two versions and improve your AWS security.
Microsoft 的 2023 年 8 月份 Patch Tuesday 解決了 73 個 CVE (CVE-2023-38180)
Microsoft addresses 73 CVEs, including one vulnerability exploited in the wild.
Password Management and Authentication Best Practices
Attackers are always looking for new ways to crack passwords and gain access to sensitive information. Keeping passwords secure is a challenging, yet critical task. Read this blog to learn several best practices for password management and authentication so you can keep your environment safe.
Tenable 網路觀察:SEC Issues New Cyber Disclosure Rules, MITRE’s Most Dangerous Software Weaknesses, and more
This week’s edition of Tenable Cyber Watch unpacks the new cybersecurity disclosures rules from the U.S. Securities and Exchange Commission and looks at MITRE’s list of the most dangerous software weaknesses. Also covered: Cloud adoption by financial institutions continues to increase. What one…