CVE-2023-35078: Ivanti Endpoint Manager Mobile (EPMM) / MobileIron Core 승인되지 않은 API 액세스 취약성
Critical vulnerability in a popular mobile device management solution from Ivanti has been exploited in the wild in limited attacks
AI가 사이버 보안에 큰 영향을 줄 것임: 예상되는 사항
Generative AI will elevate the practice of successful preventive cybersecurity, but how will it manifest itself across cybersecurity products? Here are a few game-changers to look for.
Tenable Cyber Watch: 미국 정부에서 사이버 보안 투자 우선 순위를 설명, 연구에 의하면 사이비 팀은 과도하게 자신감이 있음 등
This week’s edition of Tenable Cyber Watch unpacks CISA and the NSA’s CI/CD defense guidance and explores the White House’s cybersecurity investment priorities. Also covered: why one study says cyber teams are too confident.
사이버 보안 스냅샷: CISO는 침해는 줄었지만 인력 충원은 여진히 어렵다고
Find out what’s working well for CISOs – and what could be better. Plus, why you should pay attention to the FTC’s investigation into ChatGPT-maker OpenAI. Also, check out a primer for C-level execs on adopting generative AI. Plus, the free cloud security tools CISA recommends you use. And much…
Oracle 2022년 7월 중요 패치 업데이트로 183개 CVE 해결
Oracle addresses 183 CVEs in its third quarterly update of 2023 with 508 patches, including 76 critical updates.
CVE-2023-3519: Netscaler ADC(Citrix ADC) 및 Netscaler Gateway(Citrix Gateway)에 중요 RCE
Citrix has released a patch fixing a remote code execution vulnerability in several versions of Netscaler ADC and Netscaler Gateway that has been exploited. Organizations are urged to patch immediately.
Tenable Cyber Watch: NAIAC에서 바이든 대통령에게 첫 보고서 제출, 80%의 직원이 회사에서 ChatGPT 금지를 반대 등
This week’s edition of Tenable Cyber Watch unpacks the NAIAC’s first report delivered to President Biden and explores Glassdoor’s survey finding that 80% of employees oppose ChatGPT bans at their workplace. Also covered: CISA releases two new guides aimed at helping cyber teams protect cloud apps. …
사이버 보안 스냅샷: CISA 및 NSA에서 CI/CD 보안에 집중, MITRE에서 최고 소프트웨어 약점 순위 지정
Learn about the guidance from the U.S. government for defending CI/CD pipelines. Plus, check out the 25 most dangerous software weaknesses. Also, what developers like about AI tools – and what they don’t. And much more!
CVE-2023-3595, CVE-2023-3596: Rockwell Automation ControlLogix 취약성 공개됨
Rockwell Automation issues advisory for multiple vulnerabilities, including a critical flaw that could lead to disruption or destruction of critical infrastructure processes.
OT 환경에서 Rockwell Automation Allen-Bradley 통신 모듈이 CVE-2023-3595 및 CVE-2023-3596에 영향을 받는 것을 발견
Identifying vulnerable systems in your industrial environment can be complex. Use the wrong tool and it will overlook affected devices. Find out how Tenable OT Security is designed to give you in-depth asset visibility to address these new vulnerabilities without disrupting productivity.
Microsoft의 2023년 7월 Patch Tuesday에서 130개의 CVE(CVE-2023-36884)를 처리
Microsoft addresses 130 CVEs including five that were exploited in the wild as zero-day vulnerabilities and guidance on the malicious use of Microsoft signed drivers.
Tenable Cyber Watch: 연구에 의하면 많은 CISO가 이사회 구성원으로 적격이 아닌 것으로 확인, 사이버 보안이 비즈니스를 향상하는 방식 등
This week’s edition of Tenable Cyber Watch unpacks the new comprehensive guide on LockBit, the world’s most deployed ransomware variant, and explores how cybersecurity can boost business. Also covered: a new study finds many CISOs to be unqualified to serve on boards.