Security News > 2024 > October

Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch
2024-10-23 19:30

Plus, a POC to make it extra easy for attackers A Microsoft SharePoint bug that can allow an attacker to remotely inject code into vulnerable versions is under active exploitation, according to...

WhatsApp now encrypts contact databases for privacy-preserving synching
2024-10-23 18:52

The WhatsApp messenger platform has introduced Identity Proof Linked Storage (IPLS), a new privacy-preserving encrypted storage system designed for contact management. [...]

Are Automatic License Plate Scanners Constitutional?
2024-10-23 18:16

An advocacy groups is filing a Fourth Amendment challenge against automatic license plate readers. “The City of Norfolk, Virginia, has installed a network of cameras that make it functionally...

Lazarus hackers used fake DeFi game to exploit Google Chrome zero-day
2024-10-23 18:03

The North Korean Lazarus hacking group exploited a Google Chrome zero-day tracked as CVE-2024-4947 through a fake decentralized finance (DeFi) game targeting individuals in the cryptocurrency space. [...]

New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection
2024-10-23 17:33

New variants of a banking malware called Grandoreiro have been found to adopt new tactics in an effort to bypass anti-fraud measures, indicating that the malicious software is continuing to be...

Threat Actors Are Exploiting Vulnerabilities Faster Than Ever
2024-10-23 16:15

It only takes five days on average for attackers to exploit a vulnerability, according to a new report.

Google to let businesses create curated Chrome Web Stores for extensions
2024-10-23 16:01

Google has announced it will soon allow organizations to create their own curated "Enterprise Web Store" of company-sanctioned browser extensions for Chrome and ChromeOS, aimed at improving...

Fortinet warns of new critical FortiManager flaw used in zero-day attacks
2024-10-23 15:05

Fortinet publicly disclosed today a critical FortiManager API vulnerability, tracked as CVE-2024-47575, that was exploited in zero-day attacks to steal sensitive files containing configurations,...

Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland
2024-10-23 14:01

On the first day of Pwn2Own Ireland, participants demonstrated 52 zero-day vulnerabilities across a range of devices, earning a total of $486,250 in cash prizes. [...]

Permiso State of Identity Security 2024: A Shake-up in Identity Security Is Looming Large
2024-10-23 13:03

Identity security is front, and center given all the recent breaches that include Microsoft, Okta, Cloudflare and Snowflake to name a few. Organizations are starting to realize that a shake-up is...