Tenable ブログ
Active Directory の信頼関係の誤分類: 古い信頼が安全でない外部信頼のように見える理由
マイクロソフトの 2022 年 4 月月例セキュリティ更新プログラム、117 件の CVE を修正 (CVE-2022-24521)
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521) Microsoft addresses 117 CVEs in its April 2022 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild and reported to Microsoft by the National Security Agency. …
How to Operationalize a Cloud Security Solution
How to successfully operationalize your cloud security solution in 4 easy steps — and why fast and effective operationalization matters.
VMware、Workspace ONE、Identity Manager、Lifecycle Manager、および vRealize の複数の脆弱性にパッチを適用 (VMSA-2022-0011)
VMware cautions organizations to patch or mitigate several serious vulnerabilities across multiple products.
重要インフラ保護対策: 保護対策
In his testimony before the U.S. House Committee on Homeland Security on April 5, Amit Yoran, Tenable’s chairman and CEO, highlighted real-world challenges and offered guidance on how government can help.
Spring Framework におけるリモートコード実行の脆弱性 (Spring4Shell) に関するよくある質問
Spring4Shell (CVE-2022-22965) に関するよくある質問のリストです。
CVE-2022-22948: VMware vCenter Server における機密情報流出の脆弱性
Researchers disclose a moderate severity vulnerability in VMware vCenter Server that can be used in an exploit chain with other vCenter Server flaws to take over servers.
脆弱性「Cr8escape」に対して Tenable がどのように役立つか (CVE-2022-0811)
CrowdStrike discloses container escape vulnerability affecting CRI-O for Kubernetes. Here’s how Tenable.cs can help you detect vulnerable pods. Background On March 15, CrowdStrike published technical details and a proof-of-concept for CVE-2022-0811, a vulnerability they have named cr8escape,…
ContiLeaks: チャットにより Conti ランサムウェアにより悪用されている 30 件以上の脆弱性が明らかになる
Private messages between Conti members uncover invaluable information about how the infamous ransomware group hijacks victims’ systems. Leaked internal chats between Conti ransomware group members offer a unique glimpse into its inner workings and provide valuable insights, including details on…
Access Undenied on AWS
Introducing our new open-source tool: Access Undenied on AWS. The tool parses AWS AccessDenied CloudTrail events, explains the reasons for them and offers actionable fixes.