Tenable 部落格
CVE-2025-64446: Fortinet FortiWeb Zero-Day Path Traversal Vulnerability Exploited in the Wild
如何讓您的 SOC 意識到身分的重要性並且有效率地執行工作
While an attacker only needs to be right once, security teams must be right every time. That's why it's critical for SOC teams to stop ransomware attackers from exploiting AD weaknesses.
提早納入安全性的實用做法
Learn how you can adopt a shift left approach that boosts the security of your software releases by helping DevOps teams detect and fix vulnerabilities and misconfigurations early in your software development lifecycle.
自 Colonial Pipeline 攻擊事件後一年來的安全性現況
During a recent podcast, Tenable's VP of Operational Technology Marty Edwards discussed the cyber threats faced by critical infrastructure providers and the importance of OT security, topics he'll address again next week during a LinkedIn Live with CNN. The recent cyberattacks against…
CVE-2022-22972: VMware 修補了更多 Workspace ONE 存取弱點 (VMSA-2022-0014)
我們強烈建議企業和政府機構遵循 VMware 和美國網路安全暨基礎架構安全局的警告,修補兩個最新公布的 VMware 產品弱點。
Securing Your Cloud with Zero Trust and Least Privilege
Zero trust could be the solution for your modern security perils. Read on to discover what zero trust and least privilege are – and how to get started.
Hidden Risk in the Default Roles of Google-Managed Service Accounts
Some Google-managed service accounts are binded by default to a role granting access to storage.objects.read. This hidden risk is yet another great reason to use customer-managed KMS keys to encrypt your sensitive data stored in buckets.
The Advanced Risk of Basic Roles In GCP IAM
Basic roles in GCP allow data-level actions, even though at first glance it might seem like they don’t. Avoid using basic roles, and if you must use them, make a special effort to protect any sensitive data you store in your GCP projects.
小心 (溝通) 落差:何以資安主管會成為 Dev 和 Ops 的告密者
開發人員、操作人員和 DevOps 團隊必須將安全性結合在他們的流程當中,但對於他們來說,這通常是強迫推銷。 這篇文章將告訴您資安主管如何成功地讓他們達成共識,將安全性結合在他們的工具與工作流程當中。
Terrascan 加入 Nessus 社群,讓 Nessus 能夠驗證現代化雲端基礎架構
Terrascan 加入 Nessus 系列產品可協助使用者透過掃描基礎架構即程式碼存放庫,找出錯誤設定、安全弱點以及違反原則的情形,而更妥善地保護雲端原生基礎架構。