GET A DEMO

What we know about the MongoDB data breach

Update: The login issue has been resolved as of Monday, December 18, 2023. MongoDB is a key player in the database software industry, catering to a vast array of businesses and individual users worldwide. However, this reputation for innovation and reliability faced a challenge when the company encountered a significant security incident.   This blog post delves… Continue reading What we know about the MongoDB data breach

Automated vulnerability remediation: Insights from SANS, IBM and more

With remote work, cloud migration, and reliance on third-party software all playing a part, security teams are facing a multi-directional challenge to protect company data. While vulnerability management processes are growing more mature as we head into 2024 – especially when it comes to automated vulnerability remediation – many organizations continue to struggle with the… Continue reading Automated vulnerability remediation: Insights from SANS, IBM and more

What 2022 and 2023 taught us about cloud security

In 2023, security issues have increased in cloud assets, leading to more data breaches involving cloud environments. But, despite the growing threats and attached cyber risk, organizations are undeterred in migrating to the cloud with greater acceleration than ever before.  But is the greater exposure to cyber risk matched by organizations taking the steps to… Continue reading What 2022 and 2023 taught us about cloud security

Mitigating CVE-2023-6345 in Google Chrome

Google Chrome, the near-ubiquitous web browser, has recently faced a critical security challenge, with the high-severity zero-day vulnerability identified as CVE-2023-6345 having been discovered, posing a significant threat to users worldwide. Here’s what you need to know: What is CVE-2023-6345? CVE-2023-6345 is a severe security flaw in Google Chrome, categorized as an integer overflow bug… Continue reading Mitigating CVE-2023-6345 in Google Chrome

Vulcan Cyber closes $55 million series B with additional $34 million to solidify position as a leader in cyber risk management

Latest round led by Maor Investments and Ten Eleven Ventures bolsters Vulcan Cyber vulnerability risk management leadership position, and promotes expansion into cyber risk and attack path management markets TEL AVIV – Nov. 15, 2023 – Vulcan Cyber®, developers of the market-leading cyber risk management platform, today announced it has closed its $55 million Series… Continue reading Vulcan Cyber closes $55 million series B with additional $34 million to solidify position as a leader in cyber risk management

How to fix CVE-2023-46747 in F5 BIG-IP

This blog has been updated to include new-found instances of exploitation of this vulnerability. A critical vulnerability identified as CVE-2023-46747 has been discovered in F5’s BIG-IP systems. This vulnerability poses a significant risk as it allows unauthorized attackers to bypass authentication and execute system commands. Immediate action is advised.   What is CVE-2023-46747? CVE-2023-46747 is… Continue reading How to fix CVE-2023-46747 in F5 BIG-IP

How to fix CVE-2023-22518 in Atlassian Confluence

CVE-2023-22518 has recently been observed to be exploited in Atlassian Confluence, affecting millions of users wordlwide.  Here’s what you need to know: What is CVE-2023-22518? CVE-2023-22518 is an improper authorization vulnerability that affects Confluence Data Center and Confluence Server. It was first disclosed by Atlassian in an advisory on October 31, 2023. This vulnerability allows… Continue reading How to fix CVE-2023-22518 in Atlassian Confluence

How to fix zero-day CVE-2023-20198 in Cisco IOS XE software

On October 16, Cisco’s Talos group highlighted an active threat campaign exploiting a zero-day vulnerability, CVE-2023-20198, in the web UI component of Cisco IOS XE software. This software operates on a broad spectrum of Cisco networking devices. The exploitation of this vulnerability can lead to a total system takeover by an attacker. What is CVE-2023-20198?… Continue reading How to fix zero-day CVE-2023-20198 in Cisco IOS XE software

How to fix CVE-2023-22515 in Confluence

A critical zero-day vulnerability identified as CVE-2023-22515 has emerged, affecting on-premises installations of Confluence Server and Data Center. This vulnerability poses a significant risk as it could potentially allow malicious actors to escalate their privileges within the system, leading to unauthorized access and control. In this post, we delve into what CVE-2023-22515 is, its impact,… Continue reading How to fix CVE-2023-22515 in Confluence

No-code security automation 101

There is no shortage of cyber security solutions on the market today. But often, these valuable tools do not work together. Moreover, juggling multiple solutions, where special training is required for each disparate platform can lead to inefficiencies within the security incident response workflow. Even if teams create their own integrated automated workflows, these customized… Continue reading No-code security automation 101