Výsledky hledání

téma: identita× typ: novinka v produktu× v celém archivu zrušit filtry

18 karet z 18 položek CZ · EN/orig

1

Cisco Identity Services Engine Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco…

EPSS 0.00 CVE-2026-20130 CVE-2026-20192 CVE-2026-20194 CVE-2026-20234 CVE-2026-20237 CVE-2026-20287 Cisco US

tg: zneužíváno tg: zranitelnost tg: novinka v produktu tp: identita

· Cisco PSIRT · Cisco Identity Services Engine Hardening Release: September 2026

2

Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…

US

tg: novinka v produktu tg: návod tp: identita

· Rapid7 · Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

Security Advisory Ivanti Sentry (CVE-2026-83527)

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.0: 8.1, CVEs: CVE-2026-83527, Summary: Ivanti has released updates for Ivanti Sentry that address one high severity vulnerability. This vulnerability impacts deployments managed by EPMM and Ivanti Neurons for MDM. We are not aware of any customers being exploited by this vulnerability at the time of disclosure. CVE-2026-83527 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.0 8.1 An Authentication Bypass…

EPSS 0.01 CVSS 8.1 CVE-2026-83527 Ivanti FI

tg: zranitelnost tg: novinka v produktu tp: identita

· NCSC-FI · Security Advisory Ivanti Sentry (CVE-2026-83527)

1

1

Protect your WhatsApp account with new passkey and 2FA upgrades

WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now firmly mainstream, with the FIDO Alliance estimating that 5 billion are in use worldwide and 75% of consumers have enabled one on at least one…

WhatsApp US

tg: novinka v produktu tg: návod tp: phishing tp: identita

· Malwarebytes Labs · Protect your WhatsApp account with new passkey and 2FA upgrades

2

​​​​​​What’s new in Microsoft Security: August 2026

As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. Here’s what’s new: Extend expert-led protection with new capabilities…

Microsoft US

tg: novinka v produktu tp: AI tp: identita

· Microsoft Security Blog · ​​​​​​What’s new in Microsoft Security: August 2026

2

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Open the entity analytics (EA) graph in Elastic Security and you'll see a user wired to the hosts they log in to and the devices they own, along with scattered accounts that turn out to be the same user. While interesting on its own, it provides a critical piece of context during a threat hunting or incident investigation. This post gives an overview of EA fundamentals and opens the hood to see how edges are drawn and accounts are resolved. Why is that important? Well, everything downstream,…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · How a team of entity maintainers monitors, connects and scores entities in Elastic Security

How a team of entity maintainers monitors, connects and scores entities in Elastic Security

Open the entity analytics (EA) graph in Elastic Security and you'll see a user wired to the hosts they log in to and the devices they own, along with scattered accounts that turn out to be the same user. While interesting on its own, it provides a critical piece of context during a threat hunting or incident investigation. This post gives an overview of EA fundamentals and opens the hood to see how edges are drawn and accounts are resolved. Why is that important? Well, everything downstream,…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · How a team of entity maintainers monitors, connects and scores entities in Elastic Security

1

Audit Fix: Audit Readiness for the Post-Mythos Era

Key Takeaways Human-speed compliance is dead. Attackers utilizing modern, autonomous AI tools can chain enterprise misconfigurations and weaponize vulnerabilities in under 25 minutes, rendering manual, periodic audit cycles completely obsolete. The “Configuration Gap” is your biggest blind spot. Organizations take an average of 14 months to remediate basic identity, access control, and logging flaws, leaving a massive, open window of exposure for automated exploitation. Hyper-prioritization is…

Qualys US

tg: rozbor tg: novinka v produktu tg: propagace tp: AI tp: identita

· Qualys · Audit Fix: Audit Readiness for the Post-Mythos Era

1

​​​​What’s new in Microsoft Security: July 2026

Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on.…

Microsoft US

tg: novinka v produktu tg: propagace tp: AI tp: identita

· Microsoft Security Blog · ​​​​What’s new in Microsoft Security: July 2026

1

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

AAD Graph Activity Logs are now ingestible into Elastic and usable for threat detection within the SIEM/XDR solution. That sentence shouldn't be exciting, but it is. For most of the past decade, this slice of telemetry simply didn't exist as a customer-accessible log stream. Microsoft Graph Activity Logs (the modern graph.microsoft.com surface) went GA in April 2024. The legacy graph.windows.net surface, the one adversary tooling actually hits, stayed dark until early 2026. This post walks the…

Microsoft Elastic US

tg: rozbor tg: novinka v produktu tg: návod tp: identita

· Elastic Security · Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

1

1

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a new capability in the Entity Analytics suite that lets security teams create named, weighted lists of users, hosts, and services and feed that context directly into the platform's risk scoring pipeline. The gap this closes isn't awareness, as most security teams already know which entities deserve elevated scrutiny. The gap is that SIEMs have had no way to express that organizational knowledge as a risk signal. Watchlists do that…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · Know who to watch before the incident finds you

1

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching

1

1

1