Security News

SolarWinds fixes critical RCE bugs in access rights audit solution
2024-02-16 18:32

SolarWinds has patched five remote code execution flaws in its Access Rights Manager solution, including three critical severity vulnerabilities that allow unauthenticated exploitation.Access Rights Manager allows companies to manage and audit access rights across their IT infrastructure to minimize insider threat impact and more.

Product showcase: DCAP solution FileAuditor for data classification and access rights audit
2023-12-21 07:30

According to the security policies, established in the organization, only 100 users had legitimate access rights to the file. Only a specialized advanced DCAP system is capable of revealing that a document with confidential content is kept in publicly available storage and that users inside corporate perimeter, who don't have legitimate access rights to the file, access or process it.

Internal audit leaders are wary of key tech investments
2023-11-17 08:42

As the digital transformation of business accelerates, risk and internal audit leaders shift their focus to managing technology-driven risk, according to AuditBoard. In a continuation of a trend identified by the 2023 survey, the top 2024 risk cited by internal audit leaders is cyber and data security, with more than 80% of respondents not only rating this risk highly but also giving it the top spot for expected audit efforts in 2024.

Google Play adds security audit badges for Android VPN apps
2023-11-03 16:48

Google Play, Android's official app store, is now tagging VPN apps with an 'independent security reviews' badge if they conducted an independent security audit of their software and platform. Starting with VPN apps, which Google considers critical for user privacy and security due to handling sensitive data, the Play Store will display the "Independent security review" badge in the Data Safety Section.

EPA Won’t Force Water Utilities to Audit Their Cybersecurity
2023-10-24 11:02

Despite the EPA's willingness to provide training and technical support to help states and public water system organizations implement cybersecurity surveys, the move garnered opposition from both GOP state attorneys and trade groups. Republican state attorneys that were against the new proposed policies said that the call for new inspections could overwhelm state regulators.

Critical RCE flaws found in SolarWinds access audit solution
2023-10-20 14:59

Security researchers found three critical remote code execution vulnerabilities in the SolarWinds Access Rights Manager product that remote attackers could use to run code with SYSTEM privileges. SolarWinds ARM is a tool that enables organizations to manage and audit user access rights across their IT environments.

Microsoft extends Purview Audit log retention after July breach
2023-10-19 20:21

Microsoft is extending Purview Audit log retention as promised after the Chinese Storm-0558 hacking group breached dozens of Exchange and Microsoft 365 corporate and government accounts in July.The changes to audit logging retention announced today will roll out to Microsoft Purview Audit customers with Standard licenses in the coming weeks, starting with enterprise tenants this month and government customers in November.

Exploring the traits of effective chief audit executives
2023-09-01 03:00

Chief audit executives have identified risk orientation, stakeholder management, and team leadership as the top three characteristics of the most effective individuals, according to Gartner. In April 2023, Gartner surveyed 114 CAEs across 180 areas to identify the most important measures of an effective CAE, and the six that were the most significant included: management satisfaction; CAE and audit department performance; perception of the CAE; audit engagement quality; CAE impact; and team engagement.

VMware fixes bug exposing CF API admin credentials in audit logs
2023-07-25 15:45

VMware has patched an information disclosure vulnerability in VMware Tanzu Application Service for VMs and Isolation Segment caused by credentials being logged and exposed via system audit logs. Tracked as CVE-2023-20891, the security flaw addressed today by Vmware would allow remote attackers with low privileges to access Cloud Foundry API admin credentials on unpatched systems in low-complexity attacks that don't require user interaction.

Top priorities for chief audit executives in 2023
2023-07-14 03:00

The top focus areas for chief audit executives in 2023 are advancing data analytics, assuring proliferating digital risks, and talent management, according to Gartner. "In 2023 most CAEs are focusing on organizational and departmental digital transformation initiatives and improving team engagement and performance in response to growing assurance needs," said Leslee McKnight, VP in the Gartner Risk & Audit Practice.