“Shift Left”: A case for threat-informed pentesting. [CyberWire-X]
CyberWire Daily5 Feb 2023

“Shift Left”: A case for threat-informed pentesting. [CyberWire-X]

Penetration testing is a vital part of a robust security program, but the traditional pentesting model is in a rut. Assessments happen infrequently, the scope is often very broad, and the report is usually overwhelming. What if you could increase the overall ROI of your pentesting program and avoid these limitations? Every penetration test should have specific goals. Coverage of the MITRE ATT&CK framework or the OWASP Top Ten is a great start, but a pentest could provide exponential value by applying a more strategic approach. In this episode of CyberWire-X, the CyberWire’s Rick Howard and Dave Bittner discuss what it means to "shift left" with your penetration testing by working on a threat-informed test plan with guests and Hash Table members Bob Turner, the Field CSO of Fortinet, Etay Maor, the Senior Director for Security Strategy at Cato Networks, and Dan DeCloss, the Founder and CEO of our episode sponsor PlexTrac.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3706)

You've been disconnected.

You've been disconnected.

A senator targets legacy VPNs. Minnesota water systems come under cyberattack. A 20-year-old flaw exposes 24,000 servers. Microsoft debuts its first cybersecurity AI model. A critical VeloCloud bug is...

28 Jul 26min

The world's least private hackers.

The world's least private hackers.

Hackers target Thailand’s Ministry of Finance with an autonomous AI agent.A new industry alliance hopes to improve AI security. Golden Chickens lay four new malware families. GitHub and PyPI introduce...

27 Jul 27min

How sovereign is Europe's space industry? [T-Minus: Space-Cyber Briefing]

How sovereign is Europe's space industry? [T-Minus: Space-Cyber Briefing]

As space becomes an increasingly important part of global communications, national security, and critical infrastructure, European governments are confronting a difficulty: How much control do they ne...

26 Jul 24min

Cold lures, hot targets. [Research Saturday]

Cold lures, hot targets. [Research Saturday]

This week, we are joined by Ondrej Kubovič, Security Awareness Specialist from ESET, discussing their work on "FrostyNeighbor: Fresh mischief and digital shenanigans." Ondrej walks us through ESET's l...

25 Jul 17min

Laundry Bear gets the spin cycle.

Laundry Bear gets the spin cycle.

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose ...

24 Jul 26min

Do not pass Go(ogle).

Do not pass Go(ogle).

Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian ag...

23 Jul 26min

The AI has entered the chat.

The AI has entered the chat.

GPT escapes the sandbox and hacks Huggingface. SolarWinds patches multiple critical flaws. CISA orders patching of a critical Langflow AI vulnerability. A Paidwork breach affects over 23 million users...

22 Jul 29min

The defense against the AI arts.

The defense against the AI arts.

Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware target...

21 Jul 25min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
popradet
stopp-verden
rss-gukild-johaug
fotballpodden-2
aftenpodden-usa
hanna-de-heldige
dine-penger-pengeradet
rss-ness
aftenbla-bla
det-store-bildet
nokon-ma-ga
e24-podden
lydartikler-fra-aftenposten
unitedno
oppdatert
bt-dokumentar-2
liverpoolno-pausepraten