BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Filter:

Security Research

thumb_default

What Do You Think About eEye’s Zero-Day Tracker?

Posted June 15, 2011    The eEye Research Team

What Do You Think About eEye’s Zero-Day Tracker (www.eeye.com/zdt)?

patch-tuesday

Microsoft Patch Tuesday – June 2011

Posted June 14, 2011    Chris Silva

Another even month, another huge security bulletin release by Microsoft. Those who took my advice and convinced their bosses to let them take vacation this month avoided 16 security bulletins – hopefully your co-workers will have them fully tested and deployed before you return. For those of us not sitting on a beach somewhere, there…

broken chain

Insider Threats Aren’t Perpetrated By The Obvious: Part 2

Posted June 9, 2011    Peter McCalister

Insider threats are a global phenomenon. Every company in every part of the world is subject to some level of insider threat. And guess what? Insider villains are just as unidentifiable in the UK as they are in the US. They appear just as innocuous in Poughkeepsie as they do in Perth. If you have…

Break in

Insider Threats Aren’t Perpetrated By The Obvious: Part 1

Posted June 7, 2011    Peter McCalister

It would be nice if every villain inside your organization walked around wearing a big sign that broadcasts “bad guy looking to do bad things”, but alas it is only in the cartoons and movies of Hollywood where you can always find the stereotypical bad guy: black top hat, curled black mustache and sinister grin.

tablets-workplace

What Do You Think About the “In Configuration We Trust” Research Report?

Posted May 11, 2011    The eEye Research Team

Please use the Leave a Reply function below and send us your questions, comments, and thoughts regarding our research report “In Configuration We Trust.” – One person will be selected at random to win a new Amazon Kindle and $25 gift card. – Deadline to be entered into the contest is Friday 05/13/11 at noon PST….

patch-tuesday

Microsoft Patch Tuesday – May 2011

Posted May 10, 2011    Chris Silva

Oh how I am starting to enjoy the odd numbered months this year. Back in January Microsoft released 2 bulletins. February followed with 12, March with 3, and April with 17. Now May has arrived with only 2 bulletins. If you are looking to avoid piles of patch deployment work this summer, I’d bet on…

thumb_default

eEye Research Report: In Configuration We Trust

Posted May 9, 2011    Marc Maiffret

In configuration we trust. This statement couldn’t be truer to my research team and me, especially after discovering some of the findings in our latest report, which we publicly released last week. In the report, we describe simple configuration changes and software version upgrades that could mitigate many application vulnerabilities before patches are available. Some…

ducky

Life Is “Ducky” For Chief Security Officers

Posted May 6, 2011    Peter McCalister

Ever see how a duck glides through water? It looks effortless from the surface, but beneath the waterline is a different story. In reality the poor duck is paddling his web feet feverishly in order to move about. Now you know what it’s like to be a Chief Security Officer managing today’s enterprise security requirements.

broken chain

Could Your Business Partners Be Your Weakest Link?

Posted May 3, 2011    Peter McCalister

The drive for greater company-wide efficiencies and overall cost-savings has made the reality of outsourcing a significant part of 21st century business practices. But, by handing over your data and network access to third-parties, no matter how trustworthy, your enterprise could be at risk of suffering a serious and damaging data leak.

Win 7 logo

Microsoft Enters the Security Research Arena

Posted April 20, 2011    Marc Maiffret

This week Microsoft announced important updates to policies around discovering and disclosing third-party software application vulnerabilities. They’ve officially expanded their Coordinated Vulnerability Disclosure (CVD) policy (launched last summer as a replacement/renaming of their “responsible disclosure” policy) and have made public an internal employee policy (launched in November 2010), which requires in-house researchers to adhere to CVD guidelines, and report vulnerabilities in third-party products to the Microsoft Vulnerability Research (MSVR) program. MSVR then reports the vulnerability privately to the vendor and coordinates with the vendor on its investigation progress . In a related gesture, they released inaugural MSVR Advisories on vulnerabilities discovered by Microsoft employees in Chrome and Opera (fixed by the vendors in the latter part of 2010).