Category: Uncategorized
-
ESET Patches Privilege Escalation Vulnerabilities in Windows, macOS Products Ionut Arghire
ESET has released patches for two local privilege escalation vulnerabilities in security products for Windows and macOS. The post ESET Patches Privilege Escalation Vulnerabilities in Windows, macOS Products appeared first on SecurityWeek. Read More
-
Versa Networks Patches Vulnerability Exposing Authentication Tokens Ionut Arghire
Versa Networks has released patches for a Versa Director vulnerability for which proof-of-concept (PoC) code exists. The post Versa Networks Patches Vulnerability Exposing Authentication Tokens appeared first on SecurityWeek. Read More
-
THN Cybersecurity Recap: Last Week’s Top Threats and Trends (September 16-22) [email protected] (The Hacker News)
Hold on tight, folks, because last week’s cybersecurity landscape was a rollercoaster! We witnessed everything from North Korean hackers dangling “dream jobs” to expose a new malware, to a surprising twist in the Apple vs. NSO Group saga. Even the seemingly mundane world of domain names and cloud configurations had its share of drama. Let’s…
-
Why ‘Never Expire’ Passwords Can Be a Risky Decision [email protected] (The Hacker News)
Password resets can be frustrating for end users. Nobody likes being interrupted by the ‘time to change your password’ notification – and they like it even less when the new passwords they create are rejected by their organization’s password policy. IT teams share the pain, with resetting passwords via service desk tickets and support calls…
-
Microsoft issues first Secure Future Initiative report
Post ContentRead More
-
Cybersecurity Products Conking Out After macOS Sequoia Update Ionut Arghire
macOS Sequoia updates are causing cybersecurity software failures and breaking network connectivity for many. The post Cybersecurity Products Conking Out After macOS Sequoia Update appeared first on SecurityWeek. Read More
-
Critical Flaw in Microchip ASF Exposes IoT Devices to Remote Code Execution Risk [email protected] (The Hacker News)
A critical security flaw has been disclosed in the Microchip Advanced Software Framework (ASF) that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2024-7490, carries a CVSS score of 9.5 out of a maximum of 10.0. It has been described as a stack-based overflow vulnerability in ASF’s implementation of the…
-
Discord Introduces DAVE Protocol for End-to-End Encryption in Audio and Video Calls [email protected] (The Hacker News)
Popular social messaging platform Discord has announced that it’s rolling out a new custom end-to-end encrypted (E2EE) protocol to secure audio and video calls. The protocol has been dubbed DAVE, short for Discord’s audio and video end-to-end encryption (“E2EE A/V”). As part of the change introduced last week, voice and video in DMs, Group DMs,…
-
New PondRAT Malware Hidden in Python Packages Targets Software Developers [email protected] (The Hacker News)
Threat actors with ties to North Korea have been observed using poisoned Python packages as a way to deliver a new malware called PondRAT as part of an ongoing campaign. PondRAT, according to new findings from Palo Alto Networks Unit 42, is assessed to be a lighter version of POOLRAT (aka SIMPLESEA), a known macOS…
-
Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware [email protected] (The Hacker News)
A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. The intrusion activity, which was detected by Trend Micro in July 2024, has been attributed to a threat actor…