CVE-2021-44228: prueba de concepto para ejecución de código remota crítica de Apache Log4j disponible (Log4Shell)
Una vulnerabilidad crítica en la popular biblioteca de registros Log4j 2 afecta a diversos servicios y aplicaciones, incluyendo Minecraft, Steam y Apple iCloud. Los atacantes han comenzado a escanear e intentar explotar activamente la falla.
How to Start Up Your Cloud Security
Startups may think they can postpone implementing a cloud security program but should in fact take early action — here’s why, and easy steps for doing so.
Presentación de Tenable.cs: ciclo de vida completo, seguridad nativa en la nube
La nueva oferta amplía la plataforma recientemente adquirida de Accurics para permitir DevSecOps y aceleración de la detección (Shift Left) en la seguridad, con controles integrados para flujos de trabajo de desarrollo y tiempo de ejecución centrados en Infrastructure as Code (IaC).
Protección de los entornos de TI-TO: por qué los profesionales de seguridad de TI tienen problemas
Al proporcionar ciberseguridad en entornos convergentes de TI y tecnología operativa, es fundamental que los profesionales de infosec comprendan las diferencias entre ambos y utilicen un conjunto de herramientas que ofrezca una visión completa de los dos en una sola vista.
#GivingTuesday: Favorite Charities of Tenable Employees
This year for #GivingTuesday, we highlight some of the causes that Tenable employees have championed this year and invite you to do the same.
Not Just Buckets: Are You Aware of ALL Your Public Resources?
A misconfiguration of resource-based policies can inadvertently make resources public. Do you have such misconfigured policies present in your environment?
Fake Bitcoin, Ethereum, Dogecoin, Cardano, Ripple and Shiba Inu Giveaways Proliferate on YouTube Live
Scammers are leveraging compromised YouTube accounts to promote fake cryptocurrency giveaways for Bitcoin, Ethereum, Dogecoin, Cardano, Ripple, Shiba Inu and other cryptocurrencies.
Identifying Server Side Request Forgery: How Tenable.io Web Application Scanning Can Help
Learn how SSRF flaws arise, why three common attack paths are so challenging to mitigate and how Tenable.io Web Application Scanning can help.
Cuatro preguntas para minimizar el riesgo cibernético de sus activos y aplicaciones web orientados al público
Formule las cuatro preguntas a continuación para ayudar a reducir el riesgo cibernético en sus activos y aplicaciones web orientados al público.
New Data Reveals Company Size May Be Tied To Remote-Worker Cybersecurity Practices
Employees at the largest firms are least likely to adhere to wifi and password security guidelines.
Tales Of Zero-Day Disclosure: Tenable Researchers Reveal Recommendations for a Successful Experience
Real life stories of vulnerability discovery and disclosure from Tenable’s Zero Day Research team offer guidance you can use to refine your organization's policies.
CISA Directive 22-01: How Tenable Can Help You Find and Fix Known Exploited Vulnerabilities
While U.S. federal agencies are required to remediate the vulnerabilities outlined in the U.S. Cybersecurity and Infrastructure Security Agency's Binding Operational Directive 22-01, any organization would do well to consider prioritizing these flaws as part of their risk-based vulnerability…