Security News > 2024 > November

US seizes PopeyeTools cybercrime marketplace, charges administrators
2024-11-21 15:44

The U.S. has seized the cybercrime website 'PopeyeTools' and unsealed charges against three of its administrators, Abdul Ghaffar, Abdul Sami, and Javed Mirza, for selling stolen data. [...]

'Alarming' security bugs lay low in Linux's needrestart utility for 10 years
2024-11-21 15:03

Update now: Qualys says flaws give root to local users, 'easily exploitable', default in Ubuntu Server Researchers at Qualys refuse to release exploit code for five bugs in the Linux world's...

'Alarming' bugs lay low in Ubuntu Server utility for 10 years
2024-11-21 15:03

Update now: Qualys says vulnerabilities give root and are 'easily exploitable' Researchers at Qualys refuse to release exploit code for five bugs in Ubuntu Server's needrestart utility that allow...

Fortinet VPN design flaw hides successful brute-force attacks
2024-11-21 14:38

A design flaw in the Fortinet VPN server's logging mechanism can be leveraged to conceal the successful verification of credentials during a brute-force attack without tipping off defenders of...

Active network of North Korean IT front companies exposed
2024-11-21 14:13

An analysis of the websites belonging to companies that served as a front for getting North Korean IT workers remote jobs with businesses worldwide has revealed an active network of such companies...

Proton VPN Review: Is It Still Reliable in 2024?
2024-11-21 13:00

ProtonVPN is an all-around VPN that operates under Switzerland’s strong privacy laws, setting it apart from other services in the market.

10 Most Impactful PAM Use Cases for Enhancing Organizational Security
2024-11-21 12:23

Privileged access management (PAM) plays a pivotal role in building a strong security strategy. PAM empowers you to significantly reduce cybersecurity risks, gain tighter control over privileged...

North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
2024-11-21 12:04

Threat actors with ties to the Democratic People's Republic of Korea (DPRK) are impersonating U.S.-based software and technology consulting businesses in order to further their financial...

Secret Service Tracking People’s Locations without Warrant
2024-11-21 12:03

This feels important: The Secret Service has used a technology called Locate X which uses location data harvested from ordinary apps installed on phones. Because users agreed to an opaque terms of...

Cyber Story Time: The Boy Who Cried "Secure!"
2024-11-21 11:30

As a relatively new security category, many security operators and executives I’ve met have asked us “What are these Automated Security Validation (ASV) tools?” We’ve covered that pretty...