Resources

Cybersecurity white papers, data sheets, webinars, videos and more

Resource Library

Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat

Blog

Fortinet Fortigate Vulnerability CVE-2023-27997: How to Surface Exposed Devices and Mitigate the Threat
Recently, a critical vulnerability tracked as CVE-2023-27997 was identified in Fortinet Fortigate appliances. This vulnerability has been exploited by the Chinese APT group Volt Typhoon, among others, targeting governments and organizations worldwide. \r\n\r\nAs a result, Fortinet has released an urgent patch for affected systems. For a more detailed understanding of this vulnerability and the corresponding patch, you can read this Fortinet blog post.\r\n
Cyber Threat Intelligence
Building a Strong Defense: Red Team Insights for Cybersecurity

Webinars

Building a Strong Defense: Red Team Insights for Cybersecurity
Learn more in this resource.
Fighting Together: TSA, Critical Infrastructure, And Cyber Risk Management

Webinars

Fighting Together: TSA, Critical Infrastructure, And Cyber Risk Management
Learn more in this resource.
Public Sector
Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory

Blog

Cybersecurity Risk is a Business Risk: Upcoming SEC Regulations Make Security Transparency Mandatory
During an interview on Nasdaq Trade Talks, SecurityScorecard CEO, Aleksandr Yampolskiy, discussed the impact of upcoming regulations by the SEC.
Services
Android Malware on the Rise – A case study of AhMyth RAT

Research

Android Malware on the Rise – A case study of AhMyth RAT
The malicious application is based on the open-source Android RAT called AhMyth. The following commands are implemented: taking pictures, exfiltrating phone call logs and phone contacts, stealing files and SMS messages from the phone, tracking the device’s location, recording audio, and sending SMS messages. The network communication with the C2 server is done by switching from HTTP to WebSocket via the Socket.IO library.
SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation

Blog

SecurityScorecard Identifies Infrastructure Linked to Widespread MOVEit Vulnerability Exploitation
SecurityScorecard shares its findings into a widespread MOVEit exploit which affected a number of high profile organizations.
Cyber Threat Intelligence
Uniting Against the MOVEit Exploit Campaign

Webinars

Uniting Against the MOVEit Exploit Campaign
Learn more in this resource.
Close Encounters in the Insurance Sector

Data Sheet

Close Encounters in the Insurance Sector
Learn more in this resource.
Cyber Insurance
Close Encounters in the Insurance Sector

Data Sheet

Close Encounters in the Insurance Sector
Learn more in this resource.
Cyber Insurance
Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations

Blog

Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations
Learn about SecurityScorecard’s investigation into the Zellis breach, which uncovered over 2.500 vulnerable servers across 790 organizations.
Cyber Threat Intelligence
Metrics That Matter: Measuring And Communicating Progress In Cyber In 2023

Webinars

Metrics That Matter: Measuring And Communicating Progress In Cyber In 2023
Learn more in this resource.
Using Artificial Intelligence to Manage Cyber Risk

Webinars

Using Artificial Intelligence to Manage Cyber Risk
Learn more in this resource.
SecurityScorecard Capabilities Statement

Data Sheet

SecurityScorecard Capabilities Statement
Learn more in this resource.
Public Sector
Close Encounters in the Healthcare Sector

Research

Close Encounters in the Healthcare Sector
Learn more in this resource.
Healthcare
Close Encounters in the Public Sector

Research

Close Encounters in the Public Sector
SecurityScorecard and the Cyentia Institute recently teamed up to analyze data collected on over 230,000 organizations for clues about the underlying conditions exacerbating third- and fourth-party risk. We measured the extent of digital supply chains, investigated the prevalence of security incidents among third- and fourth-party vendors, and explored the effects of that exposure to gain insights on better managing risk.\r\n\r\nThis document summarizes key findings from that research using a subset of the data focusing on 7,347 public sector organizations.
Public Sector
Close Encounters in the Finance Sector

Research

Close Encounters in the Finance Sector
It’s often said that cyber defenses are only as strong as\r\nthe weakest link, which applies equally to individual\r\norganizations and their supply chains. Headlines of\r\nbreaches stemming from third (and fourth) parties\r\nroutinely testify to the truth behind the adage. As a result,\r\nmost finance firms know the risks imposed by these\r\n“close encounters” with third and fourth parties. But what\r\ncan be done about those risks?\r\nSecurityScorecard and the Cyentia Institute recently\r\nteamed up to analyze data collected on over 230,000\r\norganizations for clues about the underlying conditions\r\nexacerbating third- and fourth-party risk. We measured\r\nthe extent of digital supply chains, investigated the\r\nprevalence of security incidents among third- and fourthparty vendors, and explored the effects of that exposure\r\nto gain insights on better managing risk.
A Deep Dive Into Medusa Ransomware

Research

A Deep Dive Into Medusa Ransomware
Medusa ransomware appeared in June 2021, and it became more active this year by launchingthe “Medusa Blog” containing data leaked from victims that didn’t pay the ransom. The malwarestops a list of services and processes decrypted at runtime and deletes the Volume ShadowCopies.
SecurityScorecard’s Partnership with the TSA Helping to Secure the Nation’s Critical Infrastructure

Blog

SecurityScorecard’s Partnership with the TSA Helping to Secure the Nation’s Critical Infrastructure
As part of our continued commitment to making the world a safer place, SecurityScorecard recently partnered with the Transportation Security Administration (TSA). This partnership will enable the agency to more accurately monitor and assess the cyber health of the nation’s pipeline, rail, and aviation transportation systems.
SecurityScorecard Achieves AWS Level 1 Managed Security Service Provider Competency Status

Press

SecurityScorecard Achieves AWS Level 1 Managed Security Service Provider Competency Status
SecurityScorecard is the First SaaS Provider to Achieve Competency in Business Continuity and Ransomware Readiness Specification Category.
AWS
Transportation Security Administration Chooses SecurityScorecard to Deliver New Era of Resiliency for Critical Infrastructure

Press

Transportation Security Administration Chooses SecurityScorecard to Deliver New Era of Resiliency for Critical Infrastructure
TSA partners with SecurityScorecard to enhance critical infrastructure resilience through automated cyber ratings and threat intelligence.
Beyond the Breach: Partnering with the FBI to fight Cybercrime

Webinars

Beyond the Breach: Partnering with the FBI to fight Cybercrime
Learn more in this resource.
Public Sector