Security News > 2024 > June

Exploit Attempts Recorded Against New MOVEit Transfer Vulnerability - Patch ASAP!
2024-06-26 14:57

A newly disclosed critical security flaw impacting Progress Software MOVEit Transfer is already seeing exploitation attempts in the wild shortly after details of the bug were publicly disclosed....

Hackers target new MOVEit Transfer critical auth bypass bug
2024-06-26 14:49

Threat actors are already trying to exploit a critical authentication bypass flaw in Progress MOVEit Transfer, less than a day after the vendor disclosed it. MOVEit Transfer is a managed file transfer solution used in enterprise environments to securely transfer files between business partners and customers using the SFTP, SCP, and HTTP protocols.

Windows 11 KB5039302 update released with 9 changes or fixes
2024-06-26 14:47

The June 2024 optional update for Windows 11 is now available. The latest update, KB5039302, is for Windows 11 version 22H2 and newer and brings several new features and fixes.

Windows 10 KB5039299 update released with 10 changes or fixes
2024-06-26 14:32

The June 2024 optional update for Windows 10 is now available. Today's update brings KB5039299 for Windows 10 version 22H2 with up to ten bug fixes or changes.

Snowblind malware abuses Android security feature to bypass security
2024-06-26 13:33

A novel Android attack vector from a piece of malware tracked as Snowblind is abusing a security feature to bypass existing anti-tampering protections in apps that handle sensitive user data. [...]

Batten down the hatches, it's time to patch some more MOVEit bugs
2024-06-26 13:32

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Information regarding which content is presented to you and how you interact with it can be used to determine whether the content e.g. reached its intended audience and matched your interests.

Malware peddlers experimenting with BPL sideloading and masking malicious payloads as PGP keys
2024-06-26 12:34

"The LNK file triggered the first element of the novel technique used in this infection chain for distributing IDAT Loader. The LNK file was using mshta.exe to execute what appeared to be a 'PGP Secret Key,' hosted again on Bunny CDN," Kroll's threat analysts found. Static analysis of that file showed that it was not a PGP key, but a combination of junk bytes, an embedded HTA file and an embedded EXE file.

The 6 Best LastPass Alternatives for 2024
2024-06-26 12:30

Looking for LastPass alternatives? Check out our list of the top password managers that offer secure and convenient options for managing your passwords.

Fortinet vs Palo Alto (2024): Which NGFW Is Best for Your Team?
2024-06-26 12:00

As two top NGFWs, Fortinet FortiGate seems to best fit small businesses, while Palo Alto works best for larger organizations. Find out in our comparison below.

Developer errors lead to long-term exposure of sensitive data in Git repos
2024-06-26 12:00

By scanning the most popular 100 organizations on GitHub, which collectively includes more than 50,000 publicly accessible repositories, researchers found active secrets from open source organizations and enterprises such as Cisco and Mozilla providing access to sensitive data and software. The exposed secrets could lead to significant financial losses, reputational damage, and legal consequences.