Oct. 6, 2023, 12:30 p.m. | /u/RobbRen

cybersecurity www.reddit.com

Our industry and the vendors love to talk about CVE’s… this can often feel like playing ‘whack-a-mole’.

The NSA published a list of misconfigurations, which if addressed, should limit the attack surface quite a bit.

Mitigation examples include ideas such as disabling LLMNR, requiring SMB signing, enforcing segmentation, and others.

https://media.defense.gov/2023/Oct/05/2003314578/-1/-1/0/JOINT_CSA_TOP_TEN_MISCONFIGURATIONS_TLP-CLEAR.PDF

attack attack surface cve cybersecurity ideas industry limit list llmnr love misconfigurations mitigation nsa segmentation signing smb vendors whack-a-mole

Associate Director Cyber Engineering

@ KBR, Inc. | CO102: 16800 E Centretech Pkwy,Aurora 16800 East Centretech Pkwy Building S75, Aurora, CO, 80011 USA

Application Security Engineering Manager - Security Operations (Boston)

@ Klaviyo | Boston, MA

Azure Security DevOps Engineer

@ Global Payments | North Carolina - Remote

Senior IT Planning Analyst - Cybersecurity PMO

@ Pacific Gas and Electric Company | Oakland, CA, US, 94612

Principal Business Value Consultant

@ Palo Alto Networks | Chicago, IL, United States

Sr. Specialist - Cyber Defence Operations

@ Diageo | Bengaluru Karle Town SEZ