Why Exploitability Matters
The most common vulnerability scoring system used by vendors and regulatory initiatives is CVSS (the Common Vulnerability Scoring System). It provides a vendor agnostic open scoring standard to model vulnerability severity and provide guidance on prioritization of remediation efforts. The basic metrics allows for rating a vulnerability based on the severity of its components like…
Security Is Not One-Size-Fits-All
When it comes to security, specifically when it comes to vulnerability management, one size doesn’t fit all. Organizations need to customize their tools based on a wide variety of business requirements. These include everything from scan windows, frequently changing credentials, report distribution and most importantly the architecture and volume of data that needs to be…
Predicting Insider Threats
In the movie Minority Report, police have created a system which predicts crime before it happens in a nightmarish Orwellian scenario. But what if companies could predict who would attack their most valuable assets? What kinds of ethical considerations would arise? While insider threats are less in number, when they do happen the damage is…
Insider Hero Introduced: Secure Sam
In order to put a face on the depth and breadth of potential insiders that can be found throughout your enterprise, I will introduce you to three insider villains and three insider heroes. Each villain will represent one of the key misuse of privileges and each hero will represent key values delivered by least privilege. This fourth introduction will be of the most visible hero.
Insider Villain Introduced: Accident ProneAnnie
In order to put a face on the depth and breadth of potential insiders that can be found throughout your enterprise, I will introduce you to three insider villains and three insider heroes. Each villain will represent one of the key misuse of privileges and each hero will represent key values delivered by least privilege. This third introduction will be of the most unlikely villain.
Securing the Perimeter One Privileged User at a Time
You’ve heard it said before: “To some degree, you just have to trust your employees.” Ideally, yes. Trust between employee and employer is important, even necessary. But when this statement is made in the context of an employee’s access to a company’s most critical IT assets, the risk that accompanies it is simply too great…
Insider Hero Introduced: Least Privilege Lucy
In order to put a face on the depth and breadth of potential insiders that can be found throughout your enterprise, I will introduce you to three insider villains and three insider heroes. Each villain will represent one of the key misuse of privileges and each hero will represent key values delivered by least privilege. This second introduction will be of the most impactful and prevalent hero.
Microsoft Patch Tuesday – July 2011
I’m really starting to enjoy the “odd” months, Microsoft kept to their pattern and released only four security bulletins today. A welcome reprieve from last month’s sixteen bulletins. The only “Critical” rated vulnerability released today affects the Windows Bluetooth 2.1 stack. This particular vulnerability is somewhat interesting due to the attack vector. As you know,…
Corporate Security: The People’s Problem
Last week reports of a study done by the U.S. Department of Homeland Security were flying around the Internet, highlighting that if you simply drop a bunch of USB drives in your corporate parking lot, approximately 60 percent of your employees will pick up the drives, take them into the office and plug them into their computer. While the results of this study are being disputed, this tells us one thing definitively: employees are a huge security risk.
Right-click Metasploit Integration
At eEye we have been continuing an aggressive release schedule of major product updates that simplify your vulnerability management and compliance process. One of the ways that we continue to simplify vulnerability management is through new capabilities and reporting that allow for better prioritization of vulnerabilities from an overall risk management perspective. While other products…









