現在のサイバーセキュリティ対策における 6 つの重要事項
Key vulnerabilities you can’t ignore. Best practices to improve operational technology (OT) cybersecurity. A reality check on shift left, DevSecOps and cloud security. Tackling the security skills gap. Healthcare data breaches. And much more!...
Tenable CTF 2022: 受賞者発表!
It’s time to crown the winners of this year’s Capture the Flag Event! This event presented a series of security-related challenges in a Jeopardy-style format. Challenges ranged in difficulty and topics including Web App, Reverse Engineering, Crypto, Stego, OSINT, Forensics, Code and more. Ther...
Microsoft の 2022 年 6 月月例セキュリティ更新プログラム、55 件の CVE を修正 (CVE-2022-30190)
Microsoft addresses 55 CVEs in its June 2022 Patch Tuesday release, including three critical flaws....
Microsoft、Azure Synapse Analytics における脆弱性を修正
Since March 10, Tenable Research has attempted to work with Microsoft to address two serious flaws in the underlying infrastructure of Azure Synapse Analytics....
Everybody Does Good Vulnerability Management When S#*t Hits the Fan
危機に直面するとセキュリティチームの効率性が急に高まることがありますが、You need to take the same approach to security all the time. To help you get started, here are four best practices — and a new Tenable.io feature. ...
AWS, Azure and GCP: The Ultimate IAM Comparison
AWS vs. Azure vs. GCP — how do these cloud providers compare when it comes to IAM? Read on to find out....
現在の脅威の状況: 最も注目すべき脆弱性
Among the thousands of vulnerabilities disclosed so far in 2022, we highlight five and explain why they matter....
Bit Discovery の買収により EASM (外部アタックサーフェス管理) 機能を広範囲に提供
外部アタックサーフェス管理 (EASM) は、サイバーセキュリティのベストプラクティスの重要な基盤です。Soon, you’ll be able to take advantage of automated attack surface discovery in Tenable products....
CVE-2022-26134: Atlassian Confluence Server と Data Center のゼロデイ脆弱性の悪用が確認される
A critical vulnerability in Atlassian Confluence Server and Data Center has been exploited in the wild by multiple threat actors. Organizations should review and implement mitigation guidance until a patch becomes available....
重要インフラのサイバーセキュリティ強化に向けて CISO、規制当局、ベンダー、市民ができること
A year after the ransomware attack against the Colonial Pipeline, what can we do to further harden the IT and OT systems of power plants, fuel pipelines, water treatment plants and similar facilities?...
CVE-2022-30190: マイクロソフト サポート診断ツール (MSDT) のゼロデイ・ゼロクリック脆弱性の悪用が確認される
Microsoft confirms remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool that has been exploited in the wild since at least April....
Twitter の暗号通貨詐欺:Bored Ape Yacht Club、Azuki、その他のプロジェクトが NFT や暗号通貨を盗むために偽装される
Scammers are using verified and unverified accounts to impersonate notable NFT projects like Bored Ape Yacht Club and others, tagging Twitter users to drive them to phishing websites....