Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

February 2024

Unraveling the Third-Party Supplier Web: Managing Generational Complexity || Razorthorn Security

In this video, we dive into the intricate layers of third-party supplier networks, transcending the immediate concerns of dealing with organizations to confront the complexities of second, third, and even fourth generations of suppliers. Join us as we navigate through the evolving landscape of supplier relationships and explore strategies for managing the labyrinthine "mishmash" of third-party involvement.

Risk Management in Aviation Logistics: Mitigating Challenges for Seamless Operations

As a trusted partner to the United States Government, aviation logistics consists of and involves the complex coordination of various activities to ensure the timely and efficient movement of goods and movement of people by way of air. With increased demand for faster, more expeditious forms of transportation, air transportation has grown exponentially and therefore the logistics sector faces multiple challenges that can disrupt operations and even sometimes result in jeopardizing safety.

Top tips: 3 ways to achieve Fort-Knox-level security in your multi-cloud environment

Top tips is a weekly column where we highlight what’s trending in the tech world and list ways to explore these trends. This week, we’re looking at three ways you can secure your multi-cloud environment. Several years ago, the cloud was something new, but times have changed. Now, organizations are making full use of the cloud environment. Organizations are also looking in the direction of a multi-cloud environment.

ScreenConnect Compromise: Hackers Are Watching, Are You Ready? | Threat SnapShot

We know threat actors use RMM tools for command and control and to blend in with other legitimate activity in networks. But how about exploiting RMM tools for fun, profit, and remote code execution? In this week's Threat SnapShot, we'll look at two recent vulnerabilities in ConnectWise ScreenConnect (CVE-2024-1708 and CVE-2024-1709) an authentication bypass and directory traversal that can be combined together to achieve remote code execution.

5 Things to Consider Before Using SSVC Vulnerability Prioritization Framework

Vulnerability prioritization is one of the most important steps in managing cybersecurity risks effectively. Ideally, security teams would address every vulnerability immediately upon detection. However, the reality is far from ideal because of the overwhelming number of vulnerabilities and their escalating volume among other challenges, like severity spectrum differences requiring nuanced assessment, evolving threats, or resource constraints.