Security News > 2024 > November

MITRE shares 2024's top 25 most dangerous software weaknesses
2024-11-20 20:37

MITRE has shared this year's top 25 list of the most common and dangerous software weaknesses behind more than 31,000 vulnerabilities disclosed between June 2023 and June 2024. [...]

US charges five linked to Scattered Spider cybercrime gang
2024-11-20 19:22

The U.S. Justice Department has charged five suspects believed to be part of the financially motivated Scattered Spider cybercrime gang with conspiracy to commit wire fraud. [...]

Ubuntu Linux impacted by decade-old 'needrestart' flaw that gives root
2024-11-20 19:04

Five local privilege escalation (LPE) vulnerabilities have been discovered in the needrestart utility used by Ubuntu Linux, which was introduced over 10 years ago in version 21.04. [...]

Mega US healthcare payments network restores system 9 months after ransomware attack
2024-11-20 18:01

Change Healthcare’s $2 billion recovery is still a work in progress Still reeling from its February ransomware attack, Change Healthcare confirms its clearinghouse services are back up and...

Google's AI bug hunters sniff out two dozen-plus code gremlins that humans missed
2024-11-20 17:01

OSS-Fuzz is making a strong argument for LLMs in security research Google's OSS-Fuzz project, which uses large language models (LLMs) to help find bugs in code repositories, has now helped...

Microsoft confirms game audio issues on Windows 11 24H2 PCs
2024-11-20 16:48

​Microsoft says a Windows 24H2 bug causes game audio to unexpectedly increase to full volume when using USB DAC sound systems. [...]

New Ghost Tap attack abuses NFC mobile payments to steal money
2024-11-20 16:44

Cybercriminals have devised a novel method to cash out from stolen credit card details linked to mobile payment systems such as Apple Pay and Google Pay, dubbed 'Ghost Tap,' which relays NFC card...

Steve Bellovin’s Retirement Talk
2024-11-20 16:22

Steve Bellovin is retiring. Here’s his retirement talk, reflecting on his career and what the cybersecurity field needs next.

D-Link tells users to trash old VPN routers over bug too dangerous to identify
2024-11-20 14:32

Vendor offers 20% discount on new model, but not patches Owners of older models of D-Link VPN routers are being told to retire and replace their devices following the disclosure of a serious...

Amazon and Audible flooded with 'forex trading' and warez listings
2024-11-20 13:47

Amazon, Amazon Music, and Audible, an Amazon-owned online audiobook and podcast service, have been flooded with bogus listings that push dubious "forex trading" sites, Telegram channels, and...