Instantánea de ciberseguridad: la última actualización de MITRE ATT&CK ofrece conocimiento de seguridad en GenAI, identidad, nube y CI/CD
Check out what’s new in Version 15 of the MITRE ATT&CK knowledge base of adversary tactics, techniques and procedures. Plus, learn the latest details about the Change Healthcare breach, including the massive scope of the data exfiltration. In addition, why AI cyberthreats aren’t impacting CISOs’ bud...
CVE-2024-20353, CVE-2024-20359: preguntas frecuentes acerca de ArcaneDoor
Frequently asked questions about CVE-2024-20353 and CVE-2024-20359, two vulnerabilities associated with “ArcaneDoor,” the espionage-related campaign targeting Cisco Adaptive Security Appliances....
CVE-2024-4040: vulnerabilidad de escape de entorno aislado de CrushFTP Virtual File System (VFS) explotada
A zero-day vulnerability in CrushFTP was exploited in the wild against multiple U.S. entities prior to fixed versions becoming available as the vendor recommends customers upgrade as soon as possible....
Tecnología operativa en el Departamento de Defensa de los EE. UU.: garantizar una red eléctrica segura y eficiente
In an evolving threat landscape, the DoD must make sure that its mission-critical operations don’t experience power outages....
Instantánea de ciberseguridad: Cyber Agencies Offer Secure AI Tips, while Stanford Issues In-Depth AI Trends Analysis, Including of AI Security
Check out recommendations for securing AI systems from the Five Eyes cybersecurity agencies. Plus, Stanford University offers a comprehensive review of AI trends. Meanwhile, a new open-source tool aims to simplify SBOM usage. And don’t miss the latest CIS Benchmarks updates. And much more!...
Tenable and Thales Collaborate to Provide Cyber Defense Simulations to Better Secure Operational Technology Environments
The heart of the Welsh Valleys is home to the Thales Ebbw Vale campus, a world-class facility jointly funded by the Welsh government as part of its regeneration program for the region. At the core of the facility is the Cyber Range, a simulation and virtualization platform for training, testing, exe...
Actualización de parche crítica de abril de 2024 de Oracle aborda 239 CVE
Oracle addresses 239 CVEs in its second quarterly update of 2024 with 441 patches, including 38 critical updates....
Fortalecimiento de la cadena de suministro del software Nessus con SLSA
You know Tenable as a cybersecurity industry leader whose world-class exposure management products are trusted by our approximately 43,000 customers, including about 60% of the Fortune 500. But sometimes we like to give you a peek behind the curtain to share how we protect our own house against cybe...
Navegando por los desafíos de seguridad alrededor de la OT en las líneas de fabricación del Departamento de Defensa de los EE. UU.
How operational technology can revolutionize logistics, supply chain management, and overall efficiency....
CVE-2024-3400: vulnerabilidad de día cero en PAN-OS GlobalProtect Gateway de Palo Alto Networks explotada en la realidad
A critical severity command injection vulnerability in Palo Alto Networks PAN-OS has been exploited in limited targeted attacks. While a fix is not yet available, patches are expected to be released on April 14 and mitigation steps are available....
Instantánea de ciberseguridad: CISA Says Midnight Blizzard Swiped U.S. Gov’t Emails During Microsoft Hack, Tells Fed Agencies To Take Immediate Action
Check out CISA’s urgent call for federal agencies to protect themselves from Midnight Blizzard’s breach of Microsoft corporate emails. Plus, a new survey shows cybersecurity pros are guardedly optimistic about AI. Meanwhile, SANS pinpoints the four trends CISOs absolutely must focus on this year. An...
El Martes de parches de Microsoft de abril de 2024 aborda 147 CVE (CVE-2024-29988)
Microsoft addresses 147 CVEs in its April 2024 Patch Tuesday release with three critical vulnerabilities and no zero-day or publicly disclosed vulnerabilities....