SecurityScorecard Blog
Read the latest blog posts published weekly.
-
Blog, Learning Center
3 Takeaways: New SEC Cyber Risk Disclosure Rules
July 27, 2023Blog: New rules require a detailed assessment of supply chain and organizational resilience
More DetailsServices -
Blog, Learning Center
What is Cyber Threat Hunting?
July 12, 2023Threat hunting is a strategy used to find threats before they can cause damage. Learn more about cyber threat hunting and how to incorporate it into your organization.
More DetailsCyber Threat Intelligence, Tech Center -
Blog, Learning Center
Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat
June 23, 2023Recently, a critical vulnerability tracked as CVE-2023-27997 was identified in Fortinet Fortigate appliances. This vulnerability has been exploited by the Chinese APT group Volt Typhoon, among others, targeting governments and organizations worldwide. As a result, Fortinet has released an urgent patch for affected systems. For a more detailed understanding of this vulnerability and the corresponding patch, you can read this Fortinet blog post.
More DetailsCyber Threat Intelligence -
Blog
Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory
June 22, 2023During an interview on Nasdaq Trade Talks, SecurityScorecard CEO, Aleksandr Yampolskiy, discussed the impact of upcoming regulations by the SEC.
More DetailsServices -
Blog
SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation
June 20, 2023SecurityScorecard shares its findings into a widespread MOVEit exploit which affected a number of high profile organizations.
More DetailsCyber Threat Intelligence -
Blog
Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations
June 7, 2023Learn about SecurityScorecard's investigation into the Zellis breach, which uncovered over 2.500 vulnerable servers across 790 organizations.
More DetailsCyber Threat Intelligence -
Blog
Prepare for Zero-Day Threats: Military and Private Sector Leaders Share Their Insights
April 14, 2023Leading cybersecurity experts Major General John F. Wharton, (US Army retired); Oleg Strizhak, Shell’s Digital Supply Chain Risk Manager; and Sam Curry, the CISO of Zscaler, recently sat down with SecurityScorecard’s President of International Operations Matthew McKenna to discuss how organizations can prepare themselves and their supply chains for zero-day attacks, preventing and responding to them, as well as best practices for supply chain risk management.
More DetailsCyber Threat Intelligence, Public Sector -
Blog
7 Factors that Drive Cyber Risk: New Research from Marsh McLennan and SecurityScorecard
April 12, 2023Cyber risk is dynamic and influenced by a wide range of variables, quantifying it requires numerous, continuously updated data points.
More DetailsCyber Insurance -
Blog
6 Ways To Use SecurityScorecard APIs and Integrations
April 4, 2023Optimize your security workflows and deliver intelligence with the largest ecosystem of integrated technology partners. Learn more.
More DetailsSecurity Ratings -
Blog
SecurityScorecard releases list of Killnet open proxy IP addresses
February 7, 2023In the wake of Killnet’s latest DDoS attack on U.S. hospitals on January 30, SecurityScorecard has made its KillNet open proxy IP blocklist available to the public. This list is the product of the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team’s ongoing research into KillNet. We released this list to help organizations better defend themselves against KillNet and other groups like it by preventing traffic from exploitable assets. In this blog, we’ll explain how we developed this proxy list and our recommendations for preventing DDos attacks.
More DetailsCyber Threat Intelligence -
Blog
Close Encounters of the Third- (and Fourth-) Party Kind: The Blog
February 1, 2023Let’s dive deeper into some other insights that help us understand the true extent of exposure from third- and fourth-party relationships.
More DetailsSupply Chain Cyber Risk -
Blog
What Drives Cyber Risk? Cyber Insurers and SecurityScorecard Reveal Answers
October 19, 2022Seeking to stay ahead of hackers, many researchers have asked themselves what drives cyber risk. And many cyber insurance carriers have wondered how to accurately underwrite and price the risk. According to preliminary results from SecurityScorecard’s joint work with our cyber insurance partners, the answer is clear but multi-faceted.
More DetailsCyber Insurance