Focus on What Matters Most: Exposure Management and Your Attack Surface

August 23, 2024 at 07:30AM Exposure management goes beyond attack surface management by including data assets, user identities, and cloud account configurations. It ensures continuous evaluation of digital assets’ visibility, accessibility, and vulnerability. Unlike traditional vulnerability management, exposure management considers all threat vectors, including misconfigurations and unpatched vulnerabilities, allowing prioritization and strategic focus on critical … Read more

Atlassian Patches Vulnerabilities in Bamboo, Confluence, Crowd, Jira

August 22, 2024 at 08:45AM Atlassian’s August 2024 security bulletin outlines nine high-severity vulnerabilities affecting Bamboo, Confluence, Crowd, and Jira products. Patches have been released for issues such as remote code execution, denial-of-service, cross-site scripting, and server-side request forgery. The company advises users to promptly update their installations to address these vulnerabilities. Based on the … Read more

Why LinkedIn Developed Its Own AI-Powered Security Platform

August 21, 2024 at 11:00AM LinkedIn, responsible for a billion global users and a large hardware estate, seeks an effective vulnerability management system to counter cybersecurity threats. By developing the Security Posture Platform (SPP) AI project, it aims to harness the power of AI to create a single source of truth for its assets and … Read more

Cisco, Microsoft Disagree on Severity of macOS App Vulnerabilities 

August 20, 2024 at 08:24AM Cisco discovered vulnerabilities in multiple Microsoft applications for macOS, including Outlook, Teams, PowerPoint, OneNote, Excel, and Word. Attackers could exploit these flaws to bypass system permissions, allowing unauthorized activities such as sending emails, recording audio or video, and accessing sensitive information. Microsoft acknowledges the bugs but considers them low risk, … Read more

ICS Patch Tuesday: Advisories Released by Siemens, Schneider, Rockwell, Aveva

August 14, 2024 at 04:51AM Siemens, Schneider Electric, Rockwell Automation, Aveva, and the US cybersecurity agency CISA published ICS security advisories. Siemens addressed 9 advisories covering around 50 vulnerabilities, including critical and high-severity flaws in SINEC NMS. Schneider Electric addressed vulnerabilities in EcoStruxure and Accutech Manager. Aveva published 3 high-severity advisories, while Rockwell Automation addressed … Read more

Critical Ivanti vTM Bug Allows Unauthorized Admin Access

August 13, 2024 at 04:34PM Ivanti has addressed a critical vulnerability in its Virtual Traffic Manager (vTM) related to an authentication algorithm, with a major potential impact. While no attacks have been observed, a proof-of-concept exploit is publicly available. Ivanti has provided patches and recommends limiting vTM access to trusted IP addresses to reduce the … Read more

Microsoft August 2024 Patch Tuesday fixes 9 zero-days, 6 exploited

August 13, 2024 at 02:44PM Today, Microsoft’s August 2024 Patch Tuesday addresses 89 flaws with security updates, including six actively exploited and three publicly disclosed zero-days. Additionally, Microsoft is in the process of addressing a tenth publicly disclosed zero-day. Based on the meeting notes, the key takeaways are: – It is Microsoft’s August 2024 Patch … Read more

CISA Adds Six Known Exploited Vulnerabilities to Catalog

August 13, 2024 at 02:23PM CISA has added six new known exploited vulnerabilities to the catalog, including remote code execution, memory corruption, and privilege escalation issues in Microsoft products. These are common attack vectors for cyber actors and pose risks to the federal enterprise. BOD 22-01 mandates remediation to protect FCEB networks from active threats, … Read more

In Other News: KnowBe4 Product Flaws, SEC Ends MOVEit Probe, SOCRadar Responds to Hacking Claims

August 9, 2024 at 09:30AM SecurityWeek’s cybersecurity news roundup offers a concise compilation of important stories. This week’s stories include Chinese hackers exploiting an old Windows vulnerability, the creation of a new maturity model for cyber threat intelligence, vulnerabilities in Johnson Controls’ exacqVision, a significant browser vulnerability, findings by CrowdStrike, and more notable updates from … Read more

Homebrew Security Audit Finds 25 Vulnerabilities

August 1, 2024 at 08:06AM A security audit sponsored by the Open Tech Fund in August 2023 found 25 security defects in Homebrew, a popular package manager for macOS and Linux. The vulnerabilities allowed for code execution, privilege escalation, and secrets exfiltration. Trail of Bits notes the lack of explicit security documentation and the informal … Read more