Skip to content

Topic

Privileged Access Management

Cybersecurity discipline covering access controls for privileged accounts, including just-in-time grants and session monitoring.

Current stories

build1 publisher

Fortra's BoKS lets an attacker rederive AD service-account passwords offline

Fortra disclosed eight vulnerabilities in its BoKS privileged-access manager, three of them critical and one rated CVSS 9.9. Because the predictable passwords can be verified offline, applying the fix does not retire service-account credentials an attacker may already hold.

Publishers:dev.to

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60