Skip to main content

Security News

Filter by:

Veeam Urges Updates After Discovering Critical Vulnerability

The vulnerability affects certain versions of the Veeam Service Provider Console that can only be fixed by updating with the latest patch.
Dark Reading 5 Dec 2024 936 Views

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

Cisco on Monday updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).
The Hacker News 4 Dec 2024 4722 Views

Exploit released for critical WhatsUp Gold RCE flaw, patch now

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon as possible.
Bleeping Computer 4 Dec 2024 1061 Views

BootKitty UEFI malware exploits LogoFAIL to infect Linux systems

The recently uncovered 'Bootkitty' UEFI bootkit, the first malware of its kind targeting Linux systems, exploits CVE-2023-40238, aka 'LogoFAIL,' to infect computers running on a vulnerable UEFI firmware. [...]
Bleepingcomputer 3 Dec 2024 1038 Views

Gen AI could speed up coding, but businesses should still consider risks

Organizations keen to fund gen AI-powered software development for the anticipated benefits should also understand that this may come with adverse effects.
ZDnet 28 Nov 2024 1582 Views

Hackers abuse popular Godot game engine to infect thousands of PCs

​Hackers have used new GodLoader malware exploiting the capabilities of the widely used Godot game engine to evade detection and infect over 17,000 systems in just three months. [...]
Bleepingcomputer 28 Nov 2024 1489 Views

Hackers exploit ProjectSend flaw to backdoor exposed servers

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]
Bleepingcomputer 28 Nov 2024 1443 Views

Microsoft re-releases Exchange updates after fixing mail delivery

​Microsoft has re-released the November 2024 security updates for Exchange Server after pulling them earlier this month due to email delivery issues on servers using custom mail flow rules. [...]
Bleepingcomputer 28 Nov 2024 1482 Views

New NachoVPN attack uses rogue VPN servers to install malicious updates

A set of vulnerabilities dubbed "NachoVPN" allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them. [...]
Bleepingcomputer 27 Nov 2024 1566 Views

BlackBasta Ransomware Brand Picks Up Where Conti Left Off

New analysis says law enforcement efforts against Russian-language ransomware-as-a-service (RaaS) infrastructure helped consolidate influence behind BlackBasta, but some experts aren't so sure the brand means that much.
Dark Reading 26 Nov 2024 1387 Views