How To Make Your SOC Identity-Aware and Efficient
May 23, 2022While an attacker only needs to be right once, security teams must be right every time. That's why it's critical for SOC teams to stop ransomware attackers from exploiting AD weaknesses.
A Practical Approach for Shifting Left
May 23, 2022Learn how you can adopt a shift left approach that boosts the security of your software releases by helping DevOps teams detect and fix vulnerabilities and misconfigurations early in your software development lifecycle.
The State of OT Security, a Year Since Colonial Pipeline
May 19, 2022During a recent podcast, Tenable's VP of Operational Technology Marty Edwards discussed the cyber threats faced by critical infrastructure providers and the importance of OT security, topics he'll add...
CVE-2022-22972: VMware Patches Additional Workspace ONE Access Vulnerabilities (VMSA-2022-0014)
May 18, 2022Organizations and government agencies are strongly advised to patch two newly disclosed vulnerabilities in VMware products, following warnings from VMware and the Cybersecurity and Infrastructure Security Agency.
Securing Your Cloud with Zero Trust and Least Privilege
May 18, 2022Zero trust could be the solution for your modern security perils. Read on to discover what zero trust and least privilege are – and how to get started.
Hidden Risk in the Default Roles of Google-Managed Service Accounts
May 17, 2022Some Google-managed service accounts are binded by default to a role granting access to storage.objects.read. This hidden risk is yet another great reason to use customer-managed KMS keys to encrypt your sensitive data stored in buckets.
The Advanced Risk of Basic Roles In GCP IAM
May 17, 2022Basic roles in GCP allow data-level actions, even though at first glance it might seem like they don’t. Avoid using basic roles, and if you must use them, make a special effort to protect any sensitive data you store in your GCP projects.
Mind the (Communication) Gap: How Security Leaders Can Become Dev and Ops Whisperers
May 17, 2022Developers, Ops and DevOps teams must incorporate security into their processes – often a hard sell. Here’s how security leaders can successfully align with them to weave security into their tools and workflows.
Terrascan Joins the Nessus Community, Enabling Nessus To Validate Modern Cloud Infrastructures
May 17, 2022The addition of Terrascan to the Nessus family of products helps users better secure cloud native infrastructure by identifying misconfigurations, security weaknesses, and policy violations by scanning Infrastructure as Code repositories.
Identity Access Management in Google Cloud Platform (GCP IAM): What Security Pros Need to Know
May 17, 2022An introduction to GCP’s RBAC mechanism for permission assignments — and how to apply the principles of least privilege to keep your organization secure.
Tenable.io Achieves StateRAMP Authorization as Part of Our Commitment to Protect State and Local Governments
May 16, 2022StateRAMP-authorized cloud solutions like Tenable.io meet stringent security and compliance standards.
Locate Tenable Compliance Templates Faster with Revamped Portal
May 13, 2022Following a portal relaunch, Tenable’s Audit Files are now easier to find and manage, thanks to a new search engine that supports a variety of search query criteria.