Skip to main content

Security News

Filter by:

Microsoft Expands Access to Windows Recall AI Feature

The activity-recording capability has drawn concerns from the security community and privacy experts, but the tech giant is being measured in its gradual rollout, which is still in preview mode.
Dark Reading 7 Dec 2024 651 Views

Veeam Urges Updates After Discovering Critical Vulnerability

The vulnerability affects certain versions of the Veeam Service Provider Console that can only be fixed by updating with the latest patch.
Dark Reading 5 Dec 2024 953 Views

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability

Cisco on Monday updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).
The Hacker News 4 Dec 2024 4746 Views

Exploit released for critical WhatsUp Gold RCE flaw, patch now

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon as possible.
Bleeping Computer 4 Dec 2024 1076 Views

BootKitty UEFI malware exploits LogoFAIL to infect Linux systems

The recently uncovered 'Bootkitty' UEFI bootkit, the first malware of its kind targeting Linux systems, exploits CVE-2023-40238, aka 'LogoFAIL,' to infect computers running on a vulnerable UEFI firmware. [...]
Bleepingcomputer 3 Dec 2024 1060 Views

Gen AI could speed up coding, but businesses should still consider risks

Organizations keen to fund gen AI-powered software development for the anticipated benefits should also understand that this may come with adverse effects.
ZDnet 28 Nov 2024 1598 Views

Hackers abuse popular Godot game engine to infect thousands of PCs

​Hackers have used new GodLoader malware exploiting the capabilities of the widely used Godot game engine to evade detection and infect over 17,000 systems in just three months. [...]
Bleepingcomputer 28 Nov 2024 1499 Views

Hackers exploit ProjectSend flaw to backdoor exposed servers

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]
Bleepingcomputer 28 Nov 2024 1497 Views

Microsoft re-releases Exchange updates after fixing mail delivery

​Microsoft has re-released the November 2024 security updates for Exchange Server after pulling them earlier this month due to email delivery issues on servers using custom mail flow rules. [...]
Bleepingcomputer 28 Nov 2024 1505 Views

New NachoVPN attack uses rogue VPN servers to install malicious updates

A set of vulnerabilities dubbed "NachoVPN" allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them. [...]
Bleepingcomputer 27 Nov 2024 1596 Views