Security News

JetBrains' build automation software eyed as possible enabler of SolarWinds hack
2021-01-07 05:53

The SolarWinds security breach disclosed last month, which US authorities believe was of Russian origin and led to the compromise of at least 18,000 organizations, may have been enabled in part by software from JetBrains. One of these, build management and continuous integration system TeamCity, is used by SolarWinds as part of its application build process.

How companies can use automation to secure cloud data
2020-12-29 12:00

Chris DeRamus: Providing a platform that secures cloud data through automation has resulted in companies becoming enablers of the cloud. Chris DeRamus: Cloud operations will improve and become more secure once automation is implemented early on in the cloud development lifecycle, significantly decreasing the potential for human error.

Security automation: Time for a new playbook
2020-12-16 06:00

Without proper planning, organizations adopting security automation tools can fall victim to common missteps that quickly lead to less efficiency and a weaker security posture. Start by examining the processes and procedures your organization's security team already has in place and identify the tasks that consume the majority of team member's time.

Flaws in Rockwell Automation Product Expose Engineering Workstations to Attacks
2020-12-01 16:03

Vulnerabilities discovered by researchers in Rockwell Automation's FactoryTalk Linx product can allow attackers to compromise engineering workstations in industrial environments. FactoryTalk Linx, formerly known as RSLinx Enterprise, is a widely used product designed for connecting Allen Bradley programmable logic controllers to Rockwell applications, including for programming, data acquisition and HMI interaction.

Automation to shape cybersecurity activities in 2021
2020-11-26 05:30

Automation will play a major role in shaping cybersecurity attack and defence activities in 2021, WatchGuard predicts. Traditionally a high-investment, high-return targeted attack, in 2021 automation tools will replace manual techniques to help cybercriminals launch spear phishing campaigns at record volumes, by harvesting victim-specific data from social media sites and company web pages.

Rockwell Automation improves security of visualization apps with new industrial PCs and software
2020-11-25 02:30

Rockwell Automation announced the release of new industrial PCs and software to markedly improve the reliability and security of visualization applications. The new industrial Allen-Bradley VersaView 6300 PCs and thin clients combine with FactoryTalk View human-machine interface software and ThinManager thin-client management software to create a complete visualization system.

Researchers Warn of Critical Flaw Affecting Industrial Automation Systems
2020-11-19 03:26

A critical vulnerability uncovered in Real-Time Automation's 499ES EtherNet/IP stack could open up the industrial control systems to remote attacks by adversaries. RTA's ENIP stack is one of the widely used industrial automation devices and is billed as the "Standard for factory floor I/O applications in North America."

Flashpoint acquires CRFT to build automation around actionable threat intelligence
2020-11-19 00:00

Flashpoint already produces the industry's highest-quality threat intelligence from online illicit communities. By integrating CRFT's no-code security automation into Flashpoint's product suite, the company is now positioned to empower Cyber Threat Intelligence, Fraud, and Security teams to take rapid, automated action from inbound intelligence and event-based alerts.

Automation software slinger SaltStack warns of stop-watching-the-election-and-patch-now bugs
2020-11-04 02:45

SaltStack has officially revealed three bugs in its code - two of them seemingly critical - and told users: "We strongly recommend that you prioritize this update." But the biz appears to have known about the bugs for months and quietly patched them over the summer. SaltStack offers open-source, Python-based automation tools.

CyberSaint adds automation functionality to its CyberStrong platform to reduce manual intervention
2020-10-21 00:30

CyberSaint announced new updates to the CyberStrong platform allowing customers to drastically reduce manual intervention previously necessary to assess, manage, and communicate cyber and IT compliance and risk posture. CyberStrong is purpose-built for enterprises looking to transform their cyber risk management programs through automation in the wake of extensive digital transformation initiatives.