3 Ways to Reduce the Risk from Misused AWS IAM User Access Keys
Used incorrectly, AWS IAM user access keys can pose high risk; the good news is that great alternatives, explored here, exist....
マイクロソフトの 2022 年 8 月月例更新プログラム、118 件の脆弱性に対処 (CVE-2022-34713)
Microsoft addresses 118 CVEs in its August 2022 Patch Tuesday release, including 17 critical flaws....
現在のサイバーセキュリティ対策における 6 つの重要事項
Topics that are top of mind for the week ending Aug. 5 | Don’t take your eye off the Log4j ball. The dangers of unsupported software. Why low MFA adoption is everyone’s problem. Preventing ransomware attacks. And much more!...
2021 年マルウェア上位リストに関連する脆弱性の分析
国際的なサイバーセキュリティ機関は、2021 年に観測された上位のマルウェアの種類について説明する共同サイバーセキュリティアドバイザリ (CSA) を発表しました。We identified vulnerabilities associated with these strains....
CVE-2022-31656: VMware、複数の製品における複数の脆弱性にパッチを適用 (VMSA-2022-0021)
VMware has patched another set of serious vulnerabilities across multiple products including VMware Workspace ONE Access. Organizations should patch urgently given past activity targeting vulnerabilities in VMware products....
現在のサイバーセキュリティ対策における 6 つの重要事項
Topics that are top of mind for the week ending July 29 | Boost your security awareness program. Why fire drills hurt security teams. A quick temperature check on attack surface management. Protecting smart factories from cyberattacks. And much more!...
3 Types of Cyber Attackers: Which Organizations Do They Target?
Is an attacker interested in your organization? Probably. Deconstructing the PoV of cyberattackers is key to defending your turf....
ランサムウェアのエコシステム: 名声と富を求める
The key players within the ransomware ecosystem, including affiliates and initial access brokers, work together cohesively like a band of musicians, playing their respective parts as they strive for fame and fortune....
国家安全保障電気通信諮問委員会(NSTAC)、米国連邦政府機関によるゼロトラスト導入を奨励
Kudos to the National Security Telecommunications Advisory Committee for its report on boosting zero trust and ID management. As the Biden administration looks to implement its recommendations, a strong focus on vulnerability management would optimize opportunities for success....
オラクル、2022 年 7月 「Critical Patch Update」で 188 件の CVE を修正
Oracle addresses 188 CVEs in its third quarterly update of 2022 with 349 patches, including 66 critical updates....
図々しく荒削りで非論理的: 恐喝グループ「LAPSUS$」を理解する
2022 年の最初の数か月で業界の注目を集めた後、恐喝グループ「LAPSUS$」は息をひそめていますが、 What can we learn from this extortion group’s story and tactics?...
現在のサイバーセキュリティ対策における 6 つの重要事項
7 月 15 日までの週の主要トピックス: 技術的負債が政府のサイバーセキュリティ対策の成功を妨げる。SaaS のセキュリティ対策を怠ると被害に結び付く。最も危険なソフトウェアの弱点のランキング。重要インフラ保護対策について学んだこと。And much more!...