Blog

Vulnerability Research

Patch Tuesday Update - February 2024

Fortra VM will include the Microsoft Patch Tuesday checks in the NIRV 4.36.0 and Fortra VM Agent 2.4 releases.Microsoft addressed 73 vulnerabilities in this release, including 5 rated as Critical and 30 Remote Code Execution vulnerabilities.This release also includes fixes for CVE-2024-21351 and CVE-2024-21412 that have been exploited in the wild.Internet Shortcut Files Security Feature Bypass...
Blog

Cybersecurity and the Law: Taking Proactive Steps Before Needing Legal Action

How the justice system deals with cybercrime is still relatively new and finding its footing. How cybercriminals are leveraging the legal system is relatively new, too. Imagine a world where your organization gets hacked, and then, to add insult to injury, gets reported by the hackers for being out of compliance. Well, you don’t have to imagine too hard because those days are upon us. While the...
Vulnerability Research

Patch Tuesday Update - January 2024

Fortra VM will include the Microsoft Patch Tuesday checks in the NIRV 4.34.0 and Agent 2.3 releases.Microsoft addressed 49 vulnerabilities in this release, including 2 rated as Critical and 12 Remote Code Execution vulnerabilities.CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly DisclosedCVE-2024-20666BitLocker Security Feature Bypass VulnerabilityWindows...
Blog

ENISA’s New Report Highlights Cyber Investments and Pushes Vulnerability Management

This past November, the European Union Agency for Cybersecurity (ENISA) released its NIS Investments Report 2023, a rundown of how critical EU operators have been investing in cybersecurity pursuant to the NIS Directive. It not only covers how dollars have been spent, but suggest how they ought to be going forward. One particular point of emphasis? Vulnerability management. Vulnerability...
Blog

Create Chaos to Engineer Security Testing

What is Chaos Testing?Application chaos testing does its best to counteract Murphy’s Law, where anything that can go wrong will go wrong, and at the worst possible time.Chaos testing and engineering is a proactive test methodology that identifies system errors prone to misuse before they can cause damage and security concerns for an application. This style of testing was developed and made...
Blog

Patch Tuesday Update December 2023

It would seem that Microsoft was feeling particularly festive and wanted to give admins around the world a bit of a break this holiday season. This month, we see 36 Microsoft CVEs and six non-Microsoft CVEs for a total of 42 CVEs and eight of those CVEs are Edge (Chromium-based) vulnerabilities that were announced last week.
Vulnerability Research

Patch Tuesday Update - December 2023

Fortra VM will include the Microsoft Patch Tuesday checks in the NIRV 4.32.0 and Agent 2.2 releases.Microsoft addressed 33 vulnerabilities in this release, including 4 rated as Critical and 8 Remote Code Execution vulnerabilities.CVE/AdvisoryTitleTagMicrosoft Severity RatingBase ScoreMicrosoft ImpactExploitedPublicly DisclosedCVE-2023-36696Windows Cloud Files Mini Filter Driver Elevation of...
Blog

Debunking Popular Myths About Vulnerability Management

“Vulnerability Management” can be a security term that carries a lot of unnecessary weight. The irony is that the right vulnerability management (VM) solutions can actually take the weight off – your security team, your organization, and your other assets. Understanding how means debunking some of the more popular myths around this topic and discovering the truth behind one of security’s most...
Blog

What’s New on Release Day 2023.4

In this issue discover how Fortra has strengthened email security and phishing protection with new rules and automation. Additionally, offensive security has added new capabilities, while data security has improved incident workflows for better threat remediation.