Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 19 December

New Alerts for Hitachi Energy and Mozilla. Hitachi Energy  A vulnerability exists in the RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. If the client does not validate the parameters of the certificate, then attackers could be able to spoof the identity of the service. CVSSv3 score...

0
  671 Hits

New Vulnerabilities Monday 18 December

New Alerts for IBM, WatchGuard, Panasonic, and OpenSSH. IBM  IBM QRadar SIEM includes vulnerable components that could be identified and exploited with automated tools. Highest CVSSv3 score of 9.4More info. WatchGuard  BGP software such as FRRRouting FRR and Quagga included as part of Fireware OS enable a remote attacker to incorrectly re...

0
  632 Hits

New Vulnerabilities Friday 15 December

New Alerts for Unitronics, Microsoft Edge, HP, Tenable, and Linux. Unitronics  Unitronics Vision Series PLCs and HMIs has been updated to correct the use default administrative passwords. A remote attacker can take administrative control of the system. CVSSv3 score of 9.8More info. And here. Microsoft  Microsoft has updated Edge with the ...

0
  639 Hits

New Vulnerabilities Thursday 14 December

Monthly Patches are out for Palo Alto Networks. New Alerts for IBM, Dell, Squid, HPE, NetApp, and Linux. Palo Alto Networks  Palo Alto Monthly Patches include 7 bulletins, 1 rated High and 6 rated Medium. Highest CVSSv3 score of 7.5More info. IBM  IBM Maximo Application Suite uses gevent, which contains a vulnerability that can be exploit...

0
  806 Hits

New Vulnerabilities Wednesday 13 December

Monthly Patches are out for Microsoft, Adobe, Fortinet, and Atlassian. New Alerts for Bosch and Linux. Microsoft  Microsoft Monthly Patches include 35 new patches, 4 are rated Critical, 30 are rated Important, and 1 is rated Moderate. There are also 5 chromium vulnerabilities fixed in Edge. Highest CVSSv3 score of 9.6. One vulnerability was pu...

0
  670 Hits

New Vulnerabilities Tuesday 12 December

Monthly Patches are out for SAP, Siemens, and Schneider Electric. New Alerts for Apple (Exploit), Phoenix Contact, and Linux. Monthly Patches for Microsoft and Adobe are expected later today. SAP  SAP Monthly Patches include 15 new bulletins and 2 updates. Of the new bulletins 2 is rated Hot News, 4 are rated High, 7 are rated Medium, and 2 ar...

0
  665 Hits

New Vulnerabilities Monday 11 December

New Alerts for HashiCorp, JTEKT, Beckhoff, Atos Unify, and NetApp. HashiCorp  Vault and Vault Enterprise are vulnerable to DoS through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. CVSSv3 score of 7.5More info. JTEKT  Multiple vulnerabilities were found in HMI GC-A2 series...

0
  822 Hits

New Vulnerabilities Friday 08 December

New Alerts for Johnson Controls, Microsoft Edge, and HPE. Johnson Controls  A vulnerability in Metasys and Facility Explorer allows a remote attacker to send invalid authentication credentials to the login endpoint and cause a DoS. CVSSv3 score of 7.5More info. And here. Microsoft  Microsoft has updated Edge to include the latest chromium...

0
  833 Hits

New Vulnerabilities Thursday 07 December

New Alerts for Apache Struts, Google Pixel, Dell, and Linux. Apache  A vulnerability in Struts allows a remote attacker to manipulate file upload params and enable paths traversal. This can lead to uploading a malicious file which can be used to perform RCE. CVSSv3 score of 9.8More info. Google  Monthly Patches for Google Pixel are out wi...

0
  664 Hits

New Vulnerabilities Wednesday 06 December

New Alerts for Atlassian, IBM, FreeBSD, Google Chrome, and Linux. Atlassian  Atlassian has published several bulletins covering RCE vulnerabilities in Confluence Data Center and Server, Companion App for MacOS, Assets Discory, and products with the SnakeYAML library. Highest CVSSv3 score of 9.8More info. IBM  Multiple vulnerabilities in R...

0
  664 Hits
Sierra:21 - Flaws in Sierra Wireless Routers Expose Critical Sectors to Cyber Attacks

Sierra:21 - Flaws in Sierra Wireless Routers Expose Critical Sectors to Cyber Attacks

A collection of 21 security flaws have been discovered in Sierra Wireless AirLink cellular routers and open-source software components like TinyXML and OpenNDS. Collectively tracked as Sierra:21, the issues expose over 86,000 devices across critical sectors like energy, healthcare, waste management, retail, emergency services, and vehicle tracking to cyber threats, according

0
  868 Hits
Scaling Security Operations with Automation

Scaling Security Operations with Automation

In an increasingly complex and fast-paced digital landscape, organizations strive to protect themselves from various security threats. However, limited resources often hinder security teams when combatting these threats, making it difficult to keep up with the growing number of security incidents and alerts. Implementing automation throughout security operations helps security teams alleviate these challenges by streamlining repetitive tasks, reducing the risk of human error, and allowing them to focus on higher-value initiatives.

While automation offers significant benefits, there is no foolproof method or process to guarantee success. Clear definitions, consistent implementation, and standardized processes are crucial for optimal results. Without guidelines, manual and time-consuming methods can undermine the effectiveness of automation.

This blog explores the challenges faced by security operations teams when implementing automation and the practical steps needed to build a strong foundation for successful implementation.

The Automation Challenge

Organizations often struggle with automation due to a lack of well-documented processes and limited resources. With constant alerts and fires to put out, security teams are often spread thin, and only have time to focus on the task in front of them. This leaves them little to no time for proper documentation of processes and procedures. This, along with other factors such as maturity and process monitorability, contributes to the challenges security teams face when implementing automation. Successful automation requires a pragmatic approach, where teams identify and prioritize processes that are feasible and provide the greatest impact on efficiency and risk reduction.

0
  824 Hits

New Vulnerabilities Tuesday 05 December

Monthly Patches are out for Google Android and Samsung. New Alerts for Pilz, Wago, CODESYS, Dell, Ivanti, and Linux. Google  Google Android patches are out with 34 vulnerabilities along with Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm patches. Of the Android patches, 4 are rated Critical and 30 are rated High.More info. Samsu...

0
  706 Hits

New Vulnerabilities Monday 04 December

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Squid, Samsung, Dell, Peplink, and Linux. Squid  Several vulnerabilities in Squid allow a DoS attack by a remote attacker. CVSSv3 score of 8.6More info. And here. And here. Samsung  There are several vulnerabilities in Exynos products that could allow Information Disclosure...

0
  720 Hits

New Vulnerabilities Friday 01 December

New Alerts for VMware, PTC, Yokogawa, Apple (Exploit), IBM, NetApp, and Linux. VMware  VMware Cloud Director Appliance contains an authentication bypass vulnerability in the case where VMware Cloud Director Appliance was upgraded to 10.5 from an older version. CVSSv3 score of 9.8More info. PTC  PTC Kepware products are affected by vulnera...

0
  921 Hits

New Vulnerabilities Thursday 30 November

New Alerts for Tenable, Medtronic, Microsoft Edge, and Zyxel. Tenable  Nessus Network Monitor has been updated to correct vulnerabilities in third-party software including HandlebarsJS, OpenSSL, and jquery-file-upload. Highest CVSSv3 score of 9.8More info. Medtronic  Mainspring Data Express and Vital Sync Virtual Patient Monitoring Platfo...

0
  1005 Hits

New Vulnerabilities Wednesday 29 November

New Alerts for Delta Electronics, Google Chrome, Sierra Wireless, IBM, Dell, and Linux. Delta Electronics  InfraSuite Device Master contains several vulnerabilities, including Path Traversal, Deserialization of Untrusted Data, and Exposed Dangerous Method or Function. Successful exploitation could allow a remote attacker to remotely execute ar...

0
  724 Hits

New Vulnerabilities Tuesday 28 November

New Alerts for Zyxel, Festo, F5, NETGEAR, Hitachi Energy, Xerox, Apache Tomcat, and Linux. Zyxel  Zyxel Firewall and AP products contain several vulnerabilities, one of which could be exploited by a remote attacker to trigger a DoS. CVSSv3 score of 7.5More info. Festo  Festo products use WIBU CodeMeter Runtime. A remote attacker exploitin...

0
  763 Hits

New Vulnerabilities Monday 27 November

New Alerts for HPE, Arcserve, and Control iD (0-Day). HPE  Vulnerabilities in curl have been addressed in OSS Network Utilities (T1204). Highest CVSSv3 score of 9.8More info. Arcserve  Several vulnerabilities in Arcserve UDP allow a remote attacker to upload and execute arbitrary files, and bypass authentication with a valid UUID.More inf...

0
  890 Hits

New Vulnerabilities Friday 24 November

New Alerts for Philips, Hikvision, NetApp, and Linux. Philips  IntelliSpace PACS 2 and Universal Data Manager are affected by a BIG-IP Configuration utility unauthenticated remote code execution vulnerability. CVSSv3 score of 9.8No patches yet.More info. Hikvision  Hikvision products have been affected by an authentication bypass vulnerab...

0
  754 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/