Security Practitioner
SEARCH
CATEGORIES
TAGS
Mastering Cloud Security: Uncovering Hidden Vulnerabilities with NodeZero™
August 21, 2024
Master cloud security with NodeZero™ Cloud Pentesting. Easily uncover vulnerabilities across AWS and Azure, prioritize identity risks, and secure your environment in just minutes. Stay ahead of threats.
Ensuring Cybersecurity: Horizon3.ai’s Rapid Response Service in Action
July 10, 2024
How Horizon3.ai's Rapid Response Identified and Mitigated a Critical Mirth Connect Vulnerability A key consideration in cybersecurity is determining whether a known software vulnerability is actually exploitable. This often depends on how and where the at-risk software is deployed in your environment. To address the need to find what’s exploitable, Horizon3.ai developed and recently unveiled…
Enhancing Vulnerability Management: Integrating Autonomous Penetration Testing
June 17, 2024
Traditional vulnerability scanning tools are enhanced with NodeZero's autonomous penetration testing, revolutionizing Vulnerability Management by providing comprehensive risk assessment, exploitability analysis, and cross-host vulnerability chaining, empowering organizations to prioritize and mitigate security weaknesses strategically.
Exploiting File Read Vulnerabilities in Gradio to Steal Secrets from Hugging Face Spaces
June 14, 2024
This post walks through the vulnerabilities we disclosed affecting Gradio, and our work with Hugging Face to harden the Spaces platform after a recently reported potential breach.
Fireside Chat: Horizon3.ai and LYT.
DoD supply chain cyber threats are surging. Learn how CAPT helps suppliers find, fix & verify gaps with scalable, autonomous security testing.
Get Ahead of Emerging Threats with Horizon3.ai’s Rapid Response Service
April 30, 2024
In the ever-evolving landscape of cybersecurity, the speed of your response to emerging cyber threats can be the difference between a minor security incident and a catastrophic breach. Horizon3.ai provides you with a strategic advantage by enabling preemptive action in the steadily shrinking window of time between the public disclosure of a vulnerability and its…
Fix What Matters: Accelerating Cyber Defense Through the Eyes of an Attacker
April 30, 2024
The emergence of new attack vectors, the steady growth of attack surfaces, and the increasing speed at which vulnerabilities are exploited underscore the critical need for proactive defense strategies.
Fortifying the Chain: A Proven Strategy for Supply Chain Defense
April 24, 2024
Understanding the Landscape of Cyber Threats and the Innovations in Third-Party Risk Management
No waiting, no wondering: Streamline your PCI pentesting process with Horizon3.ai
Demand for #pentesting expertise is at an all-time high, and many orgs are struggling to meet their annual requirements for the PCI DSS v4.0. This webinar explains how our services fulfill your pentesting requirements and help you streamline your remediation efforts.
CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Deep Dive
March 21, 2024
Introduction In a recent PSIRT, Fortinet acknowledged CVE-2023-48788 - a SQL injection in FortiClient EMS that can lead to remote code execution. FortiClient EMS is an endpoint management solution for enterprises that provides a central location for administering enrolled endpoints. This SQL injection vulnerability is caused by user controlled strings that are passed directly into…
