CVE-2022-22948: VMware vCenter Server における機密情報流出の脆弱性
Researchers disclose a moderate severity vulnerability in VMware vCenter Server that can be used in an exploit chain with other vCenter Server flaws to take over servers.
脆弱性「Cr8escape」に対して Tenable がどのように役立つか (CVE-2022-0811)
CrowdStrike discloses container escape vulnerability affecting CRI-O for Kubernetes. Here’s how Tenable.cs can help you detect vulnerable pods. Background On March 15, CrowdStrike published technical details and a proof-of-concept for CVE-2022-0811, a vulnerability they have named cr8escape,…
ContiLeaks: チャットにより Conti ランサムウェアにより悪用されている 30 件以上の脆弱性が明らかになる
Private messages between Conti members uncover invaluable information about how the infamous ransomware group hijacks victims’ systems. Leaked internal chats between Conti ransomware group members offer a unique glimpse into its inner workings and provide valuable insights, including details on…
Access Undenied on AWS
Introducing our new open-source tool: Access Undenied on AWS. The tool parses AWS AccessDenied CloudTrail events, explains the reasons for them and offers actionable fixes.
2021 年の最も注目すべき脆弱性と上位に入らなかった脆弱性
Tenable が編纂した「脅威状況のまとめ (2021)」では、2021 年に発見された最も重要な脆弱性 5 件が取り上げられ解説されています。 本稿では、そこで取り上げられなかった他の影響度の高い脆弱性について詳細を探ります。When putting together the Threat Landscape Retrospective (TLR) for 2021, the Security Response Team had a particularly difficult…
The GCP Shared Responsibility Model: Everything You Need to Know
Do you know what your organization is accountable for under the Google Cloud Platform shared responsibility model?
マイクロソフト 2022 年 3 月月例セキュリティ更新プログラム、71 件の CVE を修正 (CVE-2022-23277、CVE-2022-24508)
<p>Microsoft addresses 71 CVEs in its March 2022 Patch Tuesday release, including three vulnerabilities that were publicly disclosed as zero-days.</p>
CNAPP: なぜ CNAPP を用いることがセキュリティリーダーにとって重要なのか
A Cloud-Native Application Protection Platform (CNAPP) offers four key benefits to reduce risk and improve visibility. 知っておくべき事柄は以下のとおりです。
3 Cloud IAM Security Questions You Must Be Able to Answer
It doesn’t matter if it’s AWS, GCP or Azure IAM, cloud deployment is redefining the work of IAM professionals.
米政府、ロシアのウクライナ侵攻に起因する APT 活動について勧告
Government agencies publish warnings and guidance for organizations to defend themselves against advanced persistent threat groups. As governments around the world call for heightened cyber vigilance, the reality of our digital world comes into stark relief: there are no boundaries when it…
Tenable による Cymptom の買収:「攻撃経路に基づく」サイバーセキュリティのアプローチ
Tenable の最近の買収はすべて、サイバー攻撃のアタックサーフェスに関するセキュリティについての深い知見をお客様に提供するという1つの包括的な目標に沿って実行されています。
Cloud Identities and the Not So Long and Slightly Winding Road to Governance
A look at Forrester’s roadmap for the deployment and use of CIG to decrease the cloud threat surface and the costs of cloud data protection.