Latest news

Metasploit Community combines the open source Metasploit Framework with a basic version of the robust commercial user interface available in Metasploit Pro to provide an entry-level response to the evolving threat landscape.
The solution offers a simplified approach to vulnerability verification and penetration testing, enabling organizations of any size to begin the process of understanding and addressing their security posture without the need for deep technical knowledge.
Cyber criminals are successful in breaching networks of enterprises and government agencies every day, creating huge security concerns and compliance issues. Penetration testing is a critical step in assessing the risk posture of the IT infrastructure by complementing vulnerability scans to identify gaps, verify known vulnerabilities for prioritization and decrease false positives, and ensure proper remediation.
Metasploit Community makes security assessments more accessible to individual and commercial users through an intuitive interface that offers simplified network discovery and vulnerability verification for specific exploits. This increases the effectiveness of vulnerability scanners such as Nexpose to provide true security risk intelligence.
The capabilities of Metasploit Community include:
A simple graphical user interface, which makes it much easier to get started with vulnerability verification and security assessments than command-line based alternatives.
Network discovery, enabling users to map their networks by identifying hosts, scanning for open ports and fingerprinting their operating systems and services.
Integration with vulnerability scanners, so scan data from Rapid7 Nexpose, Nmap and a dozen other solutions can be imported directly into Metasploit Community. Nexpose scans can also be initiated and sites imported directly from within Metasploit Community.
Basic exploitation, enabling users to verify which vulnerabilities are actually exploitable and must be remediated - and which ones don't. This increases productivity and reduces the cost of a vulnerability management program and helps prevent data breaches.
Module browser, leveraging the world's largest database of quality-assured exploits so users can easily find the right exploit. Each module includes a reliability ranking, indicating its typical success rate and impact on the target system.
Security and IT professionals can easily upgrade from Metasploit Community to Metasploit Pro, continuing to work with the familiar interface on the existing installation. Metasploit Pro adds more powerful capabilities, including smart exploitation, password auditing, Web application scanning, post-exploitation, social engineering, team collaboration, comprehensive reporting and enterprise-level support.


Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





