Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 블로그

December 2, 2024

2분만 있다면: 위험 노출 대응 SLA를 설정하는 모범 사례

Keeping vulnerability management efforts focused on achievable goals is key to avoiding cybersecurity team burnout. Here’s how exposure response workflows and SLAs can help.


December 2, 2024

3분만 있다면: 효과적인 위험 노출 대응의 중요 요소

Learned helplessness and lack of prioritization are two vulnerability management pitfalls cybersecurity teams face. Here’s how an exposure response program can help.


November 29, 2024

사이버 보안 스냅샷: AI 보안 라운드업: 모범 사례, 리서치 및 통찰

In this special edition, we’ve selected the most-read Cybersecurity Snapshot items about AI security this year. ICYMI the first time around, check out this roundup of data points, tips and trends about secure AI deployment; shadow AI; AI threat detection; AI risks; AI governance; AI cybersecurity…


November 25, 2024

Walking the Walk: Tenable이 CISA에 "Secure by Design" 서약을 수용하는 방식

As a cybersecurity leader, Tenable was proud to be one of the original signatories of CISA’s “Secure by Design" pledge” earlier this year. Our embrace of this pledge underscores our commitment to security-first principles and reaffirms our dedication to shipping robust, secure products that our…


November 22, 2024

사이버 보안 스냅샷: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM Apps

Don’t miss OWASP’s update to its “Top 10 Risks for LLMs” list. Plus, the ranking of the most harmful software weaknesses is out. Meanwhile, critical infrastructure orgs have a new framework for using AI securely. And get the latest on the BianLian ransomware gang and on the challenges of protecting…


November 21, 2024

공격을 받는 중인 Active Directory: Five Eyes 참조 자료에서 중요 보안 공백에 대해 설명

A landmark global report from cybersecurity agencies emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the first of our two-part series, we offer five steps you can take today to shore up your AD defenses.


November 21, 2024

5개의 사이버 기관에서 Active Directory 공격에 대해 경고: Beyond the Basics

A landmark global report emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the second of our two-part series, we take you beyond the basics to highlight three key areas to focus on.


November 19, 2024

Volt Typhoon: 주 및 지역 정부 관리들이 알아야 하는 사항

Increased activity from the state-sponsored threat group Volt Typhoon raises concerns about the cybersecurity of U.S. critical infrastructure. Here’s how you can identify potential exposures and attack paths.


November 19, 2024

Volt Typhoon: U.S. 국가 정부에서 지원하는 행위자가 표적으로 삼는 미국 중요 인프라

Volt Typhoon, a state-sponsored actor linked to the People’s Republic of China, has consistently targeted U.S. critical infrastructure with the intent to maintain persistent access. Tenable Research examines the tactics, techniques and procedures of this threat actor.


November 18, 2024

CVE-2024-0012, CVE-2024-9474: Palo Alto PAN-OS에 제로데이 취약성이 널리 악용됨

Palo Alto Networks confirmed two zero-day vulnerabilities were exploited as part of attacks in the wild against PAN-OS devices, with one being attributed to Operation Lunar Peek.


November 18, 2024

새로 적용되는 AWS 제어 정책

AWS has released an important new feature that allows you to apply permission boundaries around resources at scale called Resource Control Policies (RCPs). Read on to learn what RCPs are all about and how to use them, as well as how Tenable Cloud Security already factors them into its analysis.


November 18, 2024

도메인별 언어의 어두운 측면: OPA 및 Terraform에서 새로운 공격 기술 발견하기

Check out our deep dive into both new and known techniques for abusing infrastructure-as-code and policy-as-code tools. You’ll also learn how to defend against them in this blog post which expands on the attack techniques presented at our fwd:cloudsec Europe 2024 talk “Who Watches the Watchmen?…


도움이 되는 사이버 보안 뉴스

이메일을 입력하여 Tenable 전문가에게서 적시에 알림을 받고 보안 참고 자료를 놓치지 마십시오.

Apache Log4j Flaw Puts Third-Party Software in the Spotlight

Get the Details >

× 영업 팀에게 문의