Nightfall 2022 in Review: A Look at the Exciting Developments in the Past Year

The demand for cloud security continues to increase in the face of supply chain attacks affecting the security of hundreds of thousands of organizations on platforms like GitHub. These concerning developments are among the reasons why we’re building Nightfall and are top of mind as we pursue our vision of enabling data security everywhere in the cloud. 2022 has been a busy and exciting year for us here at Nightfall as we’ve built out the platform in response to these developments.

Kubernetes network policy best practices

Controlling and filtering traffic when containerizing a workload within Kubernetes Pods is just as crucial as a firewall in a more traditional network setup. The difference is that, in this scenario, those capabilities are provided by the Kubernetes NetworkPolicy API. This article will explore Kubernetes NetworkPolicy by creating an example network policy and examining its core parameters. Then, we’ll look at some common NetworkPolicy use cases and learn how to monitor them using kubectl.

New Microsoft Exchange Exploit Chain via "OWASSRF" Leads to RCE

On Wednesday, December 21, 2022, security researchers shared that they observed ransomware threat actors using a new exploit chain that bypasses the ProxyNotShell URL rewrite mitigations that were shared by Microsoft in September and October. This new exploit chain works by abusing CVE-2022-41080 & CVE-2022-41082 and leads to remote code execution on affected Exchange servers through Outlook Web Access (OWA).

Arctic Wolf Labs Named Open-Source Tool Creator of the Year by SANS Institute

“It’s about doing good and doing it exceedingly well.” This was how Daniel Thanos, Head of Arctic Wolf Labs, described the work of Arctic Wolf Labs when accepting the award for Open-Source Tool Creator of the Year, as voted by the SANS Insitute community at the 2022 Difference Makers Awards. This prestigious awards program “honors individuals and teams in the cyber security community who have made a measurable and significant difference in security.”

Insights dashboard

Now you can track how much time you save with Torq and monitor key workflow statistics in one convenient dashboard. Set Torq's TimeBack benchmark for each published workflow and calculate the total time saved across all workflows. The compiled metrics allow you to track different workflow analytics, see the results of your efforts, and monitor any runs that may require attention. Start configuring your Insights dashboard by clicking Review at the top of the Insights dashboard. Adjust each workflow's slider to reflect the time the use case would have taken manually.

What Are The Key Considerations for Vulnerability Prioritization?

When it comes to open source vulnerabilities, we seem to be in permanent growth mode. Indeed, data from Mend’s Open Source Risk Report showed 33 percent growth in the number of open source software vulnerabilities that Mend added to its vulnerability database in the first nine months of 2022 compared with the same time period in 2021. However, while some vulnerabilities pose a severe business risk — hello, log4j — others can be safely ignored.

Keeper Enterprise Demo 2022

Keeper is the best way to protect your enterprise from password-related data breaches and cyberthreats. This 30-minute demo will show you how to prevent data breaches with Keeper Enterprise - a Zero-Knowledge and Zero-Trust password management and privileged account management cybersecurity platform. We'll review the end-user workflow, user provisioning and advanced topics including the Advanced Reporting & Alerts module, BreachWatch dark web monitoring and Commander tools.