CVE-2022-47939: Vulnerabilidad crítica RCE en Linux Kernel
A critical remote code execution vulnerability in the Linux kernel has been publicly disclosed by Trend Micro's Zero Day Initiative in its ZDI-22-1690 advisory. The vulnerability has been given a CVSSv3 of 10.0. There are no reports of active exploitation....
Instantánea de ciberseguridad: Seis predicciones de Tenable para 2023
Mientras el año de 2022 llegaba a su fin, preguntamos a los expertos de Tenable lo que esperaban para el nuevo año.After reading the tea leaves, they’re forecasting developments in extortion attacks, OT security, SaaS threats, metaverse risks and more!...
Patch Tuesday’s Impact on Cybersecurity Over the Years
Dive into the history of Patch Tuesday and learn how it continues to influence the ways security teams manage patches....
CVE-2022-37958: Preguntas frecuentes para vulnerabilidad crítica de Microsoft SPNEGO NEGOEX
Microsoft recently reclassified a vulnerability in SPNEGO NEGOEX, originally patched in September, after a security researcher discovered that it can lead to remote code execution. Organizations are urged to apply these patches as soon as possible....
Plataforma de protección de aplicaciones nativas en la nube (CNAPP): An Evolving Approach to Cloud Security
A look at how IAM works and how CIEM enhances IAM security in the cloud....
Your Guide to IAM – and IAM Security in the Cloud
A look at how IAM works and how CIEM enhances IAM security in the cloud....
Tenable Cyber Watch: Vigilancia del metaverso, protección de IA y ML, la amenaza de Daixin para los hospitales y el cambio a las plataformas cibernéticas integradas
To help you zap those Monday blahs, here’s a caffeinated shot of cyber news you can use: Police chiefs must get hip to the metaverse. CISOs are shifting to integrated cybersecurity platforms. There's new guidance for securing ML and AI systems. Hospitals face a ransomware threat from the Daixin cybe...
Instantánea de ciberseguridad: Estafas de phishing, tendencias de salarios, riesgos del metaverso, Log4J Poll
Get the latest on worrisome phishing stats; businesses’ embrace of the metaverse, come what may; a (small) improvement in CISO job stability; the compensation cost of security leaders; and more!...
El Martes de parches de diciembre de 2022 de Microsoft aborda 48 CVE (CVE-2022-44698)
Microsoft addresses 48 CVEs including two zero-day vulnerabilities, one that has been exploited in the wild (CVE-2022-44698) and one that was publicly disclosed prior to a patch being available (CVE-2022-44710)....
CVE-2022-27518: RCE sin autenticar en Citrix ADC y puerta de enlace
Citrix has patched a critical remote code execution vulnerability in its Gateway and ADC products. This vulnerability has reportedly been exploited as a zero day; organizations should patch urgently....
Cómo evaluar la preparación de la ciberseguridad de proveedores de servicios de TI y MSP
Improperly evaluating the cybersecurity capabilities of prospective IT service providers and managed service providers (MSPs) can put your organization's data and systems at risk. A new guide from CompTIA can help you ask the right questions....
CVE-2022-42475: Fortinet coloca parches de día cero en VPN de FortiOS SSL
Fortinet has patched a zero day buffer overflow in FortiOS that could lead to remote code execution. There has been a report of active exploitation and organizations should patch urgently....