Remove category threat-advisories-advisories
article thumbnail

AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

Tenable

AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475 A joint Cybersecurity Advisory examines the exploitation of two critical vulnerabilities by nation-state threat actors. The vulnerability is caused by the use of an outdated version of Apache Santuario, an XML security software library.

article thumbnail

Cybersecurity Snapshot: Cyber Pros Say How AI Is Changing Their Work, While the FBI Reports Ransomware Hit Critical Infrastructure Hard in 2023

Tenable

Meanwhile, MITRE updated a database about insider threats. Meanwhile, investment fraud topped all crime categories with investment scams losses rising 38% to $4.57 More than 40% of ransomware attacks last year impacted critical infrastructure. Plus, a survey shows how artificial intelligence is impacting cybersecurity jobs. What’s new?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Cybersecurity Snapshot: SANS Offers Tips for Maximizing Smaller OT Security Budgets

Tenable

Essentially, budgets are down in just about every category we analyzed,” the SANS Institute report reads. For more information about ICS/OT security, check out these Tenable blogs and videos: “ Three U.S. Federal Bureau of Investigation (FBI), which detailed this trending technique known as dual ransomware in a recent advisory.

Budget 65
article thumbnail

Cybersecurity Snapshot: CISA Pinpoints Vulnerabilities in Critical Infrastructure Orgs that Ransomware Groups Could Exploit

Tenable

government advisory with the latest on LockBit 3.0. Security Spotlight - Episode 1: The Ransomware Ecosystem (Tenable) How the Nation’s Energy Organizations Can Stand Up to Ransomware Threats (CISA) 2 - FBI shines light on ransomware threat to critical infrastructure And continuing with this topic, we’re also learning from the U.S.

article thumbnail

Prisma Cloud Achieves FedRAMP High Impact Level Status

Prisma Clud

The FedRAMP Joint Advisory Board (JAB) has announced that Prisma Cloud has achieved FedRAMP High Impact Level Ready status. As the demand for cloud computing accelerates, the cyber threat landscape becomes increasingly complex. Over the last few years, we’ve observed tremendous progress in cloud-native transformations across U.S.

Cloud 92
article thumbnail

Oracle January 2021 Critical Patch Update Includes Fixes for Five Critical WebLogic Flaws (CVE-2021-2109)

Tenable

The Oracle Fusion Middleware category contained the highest number of patches at 60, representing just over 18% of the patches from this quarter. This is supported in the findings from our 2020 Threat Landscape Retrospective Report , where we highlight four noteworthy vulnerabilities in Oracle WebLogic Server that were exploited in-the-wild.

Backup 99
article thumbnail

Mind the Gap: A Closer Look at the Vulnerabilities Disclosed in 2022

Tenable

While attackers can devote their time to monitoring CVE advisories ahead of their placement on NVD, most time-strapped cybersecurity practitioners have little choice but to rely on NVD as their primary source for vulnerability awareness. Attackers monitor advisories looking for vulnerabilities. The CVE database is managed by MITRE.