Such lagging vulnerability remediation for ProxyLogon significantly contrasts patching activities for a pair of Ivanti flaws also leveraged in Salt Typhoon attacks, tracked as CVE-2023-46805 and CVE-2024-21887, which have been addressed in over 92% of affected Ivanti devices, findings from Tenable revealed.
Andy Jaquith joins us to discuss how to prioritize vulnerabilities and remmediation in the real-world, including asset management and more! In the security news: ESP32s in the wild and security, Google oAuth flaw, DDoS targets, Ban on auto components, Bambu firmware updates, Silk Road founder is free, one last cybersecurity executive order, US Trea...
Attacks with the chained vulnerabilities have been thwarted by three organizations, with the first preventing compromise following sysadmin identification of suspicious user accounts and the second averting the breach after an endpoint protection platform detected web shell-creating base64-encoded scripts, according to a joint CISA and FBI advisory.
While both Exchange Server versions will continue to be operational past the end date, Microsoft urged admins to immediately upgrade to Exchange Online or prepare for the upcoming Exchange Server Subscription Edition as the outdated iterations will no longer be given technical support, security patches, and time zone updates past Oct. 14.
Aside from warning against the use of archaic cryptographic platforms and unencrypted data storage, such guidance also cautioned about the utilization of hardcoded secrets in critical infrastructure software source code and inadequate communications regarding product support periods.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.