Armchair risk analysis frequently defaults to "patch all the things," but the data shows that trying to chase after every vulnerability isn't always the best strategy for a CISO. How should CISOs look at Kenna Security and Cyentia Institute's research on what kind of patching model works best?
The open source Struts web application framework has a target on its back. Attackers are likely developing exploits. Is it time to stop using Struts?
It hasn’t even been a year since the Equifax breach was made public, and Apache has fixed yet another another critical vulnerability in the Struts web application framework. Does your incident response plan include assessing the risk exposure and deploying defenses on top of patch management?
The WannaCry debacle and most recent MaybeNotPetya attack has revealed that there are countless unpatched systems - no big surprise. Here’s what’s keeping organizations vulnerable, and what we can do about it.