This is the last of the four blogs (Help, I can’t see! A Primer for Attack Surface Management Blog Series, The Main Components of an Attack Surface Management (ASM) Strategy, and Understanding your Attack Surface: Different Approaches to Asset Discovery) covering the foundational elements of Attack Surface Management (ASM), and this topic covers one of the main drivers for ASM and why companies are investing in it, the context it delivers to inform better security decision making.
Read more…
Source: Rapid7
Related:
- Responding and Defending Against IdP Vendor Compromise
October 25, 2023
Based on Okta’s statement on October 20 regarding a recent security breach, it has been determined that the threat actor successfully gained access to Okta’s customer support system. Once inside the system, the threat actor was able to view files uploaded by Okta customers in relation to recent support cases with valid session tokens. By ...
- Microsoft to help Australia’s cyber spies amid $5bn investment in cloud computing
October 23, 2023
Microsoft says it will invest an additional $5bn in Australia over the next two years to expand hyperscale cloud computing capacity while collaborating with the Australian Signals Directorate (ASD) to boost domestic protection from cyber threats. Anthony Albanese confirmed the new investment on the opening day of his state visit to the United States during an ...
- Philippines to recruit ‘cyber warriors’ for online defence
October 19, 2023
The Philippine military is creating a cyber command to improve defences against almost daily cyber attacks and will relax recruitment rules to ensure it can attract online experts, the chief of the armed forces said on Thursday. Several government agencies, including the lower house of Congress, have recently reported cyber attacks and the chief of the ...
- Remediation for Citrix NetScaler ADC and Gateway Vulnerability (CVE-2023-4966)
October 17, 2023
On Oct. 10, 2023, Citrix released a security bulletin for a sensitive information disclosure vulnerability (CVE-2023-4966) impacting NetScaler ADC and NetScaler Gateway appliances. Mandiant has identified zero-day exploitation of this vulnerability in the wild beginning in late August 2023. Successful exploitation could result in the ability to hijack existing authenticated sessions, therefore bypassing multifactor authentication ...
- China’s cyber security association sets up special committee to bolster AI research
October 15, 2023
China has set up a professional committee focusing on governance of artificial intelligence (AI) security in a bid to build a sustained foundation for the sound development of the emerging industry, according to the country’s cyber security association. On Thursday, an inaugural meeting was held in Beijing for the AI security governance committee under the ...
- Update now! Atlassian Confluence vulnerability is being actively exploited
October 12, 2023
Microsoft Threat Intelligence has revealed that it has been tracking the active exploitation of a vulnerability in Atlassian Confluence software since September 14, 2023. At the time the attacks were first observed the vulnerability was a zero-day, meaning that no update was available, so defenders had “zero days” to patch the flaw. The vulnerability has since ...

