Security News > 2020 > October

SAP Patches Critical Vulnerability in CA Introscope Enterprise Manager
2020-10-15 08:48

The updates released by SAP for October 2020 include 15 Security Notes, including one that addresses a critical vulnerability. Featuring a CVSS score of 10, the critical flaw is an OS command injection vulnerability that affects CA Introscope Enterprise Manager version 10.7.0.304 or lower.

Microsoft would love to hear about 'critical bugs' in .NET 5.0 ahead of the 'unified' platform's November launch
2020-10-15 08:04

NET Core is crawling closer to its November launch with. NET Core, Microsoft is calling the upcoming release plain.

Remember when Zoom was rumbled for lousy crypto? Six months later it says end-to-end is ready
2020-10-15 07:33

News of the trial comes after April 2020 awkwardness that followed the revelation that Zoom was fibbing about its service using end-to-end encryption. "When we use the phrase 'End-to-end' in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point," the company said.

VMware NSX: A cheat sheet
2020-10-15 06:00

Why does VMware NSX matter? NSX is currently the leading network virtualization platform; also, it offers an interesting micro-segmentation security use case. When is VMware NSX available? NSX currently ships as version 6.3.2.How do I use VMware NSX? NSX comes in two major flavors: one for vSphere environments and one for non-vSphere environments.

Three best practices for responsible open source usage in the COVID-19 era
2020-10-15 05:00

Since well before the pandemic, software developers have leveraged open source code as a means to speed development cycles. Applications today are usually designed using hundreds of unique open source components, which then reside in their software and workspaces for years.

As attackers evolve their tactics, continuous cybersecurity education is a must
2020-10-15 04:30

As the Information Age slowly gives way to the Fourth Industrial Revolution, and the rise of IoT and IIoT, on-demand availability of computer system resources, big data and analytics, and cyber attacks aimed at business environments impact on our everyday lives, there's an increasing need for knowledgeable cybersecurity professionals and an increasing cybersecurity workforce skills gap. A year ago,² estimated that the global cybersecurity workforce numbered 2.8 million professionals, when there's an actual need for 4.07 million.

Theory and practice of web application security efforts in organizations worldwide
2020-10-15 04:00

75% of executives believe their organization scans all web applications for security vulnerabilities, while nearly 50% of security staff say they don't, a Netsparker survey reveals. Even more concerning, over 60% of DevOps respondents indicate that new security vulnerabilities are being found faster than they can be fixed, indicating that web application security efforts are insufficient.

State and local governments under siege from cyber threats
2020-10-15 03:30

With both security budgets and talent pools negatively affected by the ongoing pandemic, state and local governments are struggling to cope with the constant wave of cyber threats more than ever before, a Deloitte study reveals. Collaboration with local governments and public higher education is critical to managing increasingly complex cyber risk within state borders.

SMBs’ size doesn’t make them immune to cyberattacks
2020-10-15 03:00

78% of SMBs indicated that having a privileged access management solution in place is important to a cybersecurity program - yet 76% of respondents said that they do not have one that is fully deployed, a Devolutions survey reveals. SMBs are not immune, company size doesn't protect from cyberattacks.

ReliaQuest GreyMatter: An Open XDR approach that solves modern enterprise cybersecurity challenges
2020-10-15 02:30

ReliaQuest announced its "Open XDR" approach that solves modern enterprise cybersecurity challenges through its GreyMatter platform. "XDR is a new take on an old problem that aims to unify control points, security telemetry, analytics, and operations into one enterprise offering but requires the same vendor for all tools. ReliaQuest identified an opportunity to improve upon this model with Open XDR.".