Security News

Companies are rethinking their approach to privacy management
2020-06-22 03:00

"There are more than 900 global privacy laws to which organizations must adhere, making privacy management an ongoing and dynamic challenge," said Chris Babel, CEO, TrustArc. Though 90% of respondents agree or strongly agree that they are "Mindful of privacy as a business," many privacy professionals are left building privacy programs without automation.

IBM Maximo Asset Management servers patched against attacks
2020-06-19 13:44

To explain: SSRF is a way that someone with possibly very limited access to your network can send a legitimate looking query to one of your servers. If you can trick the vulnerable server into calling outside its own network by sending it an otherwise legimitate request, you may be able to capture server data such as secret authentication tokens or special HTTP headers that are usually only visible if you are already inside the network.

Flaw in IBM Asset Management Product Facilitates Attacks on Corporate Networks
2020-06-19 12:59

A high-severity vulnerability patched recently by IBM in its Maximo asset management solution makes it easier for hackers to move around in enterprise networks, cybersecurity firm Positive Technologies warned on Thursday. The security hole, tracked as CVE-2020-4529, has been described as a server-side request forgery issue that allows an authenticated attacker to send unauthorized requests from a system, which IBM says can facilitate other attacks.

RICOH Smart Integration platform enhancements address workforce health and cost management
2020-06-19 02:00

Ricoh announced major enhancements to its RICOH Smart Integration platform, a part of its RICOH Cloud Workflow Solutions portfolio. RICOH Smart Integration technology is available in a scalable, modular subscription model, from both direct and Ricoh Family Group dealer channels, to fit the evolving digital productivity requirements of any organization.

As IoT devices evolve, risk management needs improvement
2020-06-16 03:30

There's an acute need for IoT risk management improvement, as most organizations do not know what tracking and safeguards their third parties have in place, according to the Shared Assessments Program and the Ponemon Institute. "This is especially true when the use of IoT devices is extended to third parties, fourth parties, or even more concerning, when it's unknown where the use of IoT devices are being extended, or those extensions are unmanaged," observes Rocco Grillo, Managing Director, Global Cyber Risk Services, Alvarez & Marsal.

Simplify AWS user and permission management with jmpr
2020-06-15 02:00

EGlobalTech, A Tetra Tech Company, announced the launch of "Jmpr," a new software product which considerably simplifies Amazon Web Services user and permission management. AWS developers who have multiple accounts with different permissions, requiring repeated separate logins per day to complete required tasks.

Adaptiva and OKTiK Technology help enterprise customers modernize desktop management
2020-06-14 23:30

Adaptiva announced that it has partnered with UK-based IT consultancy OKTiK Technology to provide its solutions as part of OKTiK's automation platform. "OKTiK has established itself as a digital transformation specialist over the last several years, and our on-premises and cloud-enabled products are an outstanding fit for OKTiK's automation platform. Together, Adaptiva and OKTiK can drive a painless transition to modern management."

Abacode partners with Apptega to deliver cybersecurity management and compliance software
2020-06-11 23:30

Abacode announced a collaboration with Atlanta-based Apptega, a leader in cybersecurity management software. "Abacode continues to innovate and partner with great technology companies," said Greg Chevalier, SVP Partners and Sales Strategy for Abacode.

How to scale endpoint management, improve employee productivity and reduce costs
2020-06-11 06:00

These centred on the apparent difficulty in provisioning Intel AMT to endpoint devices and the management of some use cases such as remote wake-up and remote KVM. Such difficulties might easily arise when attempting to activate Intel AMT on new machines that may have been delivered to remote branch offices with no IT staff on-site, for example, or to workers that are connecting to the corporate network from outside the firewall. To address these issues, Intel has extended the Intel vPro® platform with a new software service known as Intel® Endpoint Management Assistant, which builds on and modernises the capabilities of Intel® AMT. Intel® EMA has been designed as a cloud-based point of control for managing endpoint devices wherever they may be, inside and outside the corporate firewall.

Critical Intel Flaws Fixed in Active Management Technology
2020-06-10 18:37

The critical flaws exist in Intel's Active Management Technology, which is used for remote out-of-band management of personal computers. The two critical flaws exist in the IPv6 subsystem of AMT. The flaws could potentially enable an unauthenticated user to gain elevated privileges via network access.