Security News > 2024 > November

GitHub Secure Open Source Fund: Project maintainers, apply now!
2024-11-20 13:38

GitHub is calling on maintainers of open source projects to apply for the newly opened Secure Open Source Fund, to get funding and knowledge to improve the security and sustainability of their...

Oracle Linux 9 Update 5 brings security updates, OpenJDK 17, .NET 9.0
2024-11-20 13:33

Oracle Linux offers a secure, streamlined platform for deploying and managing applications across on-premises, cloud, and edge environments. Designed for demanding workloads, it includes tools for...

Ghost Tap: Hackers Exploiting NFCGate to Steal Funds via Mobile Payments
2024-11-20 13:09

Threat actors are increasingly banking on a new technique that leverages near-field communication (NFC) to cash out victim's funds at scale. The technique, codenamed Ghost Tap by ThreatFabric,...

NHIs Are the Future of Cybersecurity: Meet NHIDR
2024-11-20 11:30

The frequency and sophistication of modern cyberattacks are surging, making it increasingly challenging for organizations to protect sensitive data and critical infrastructure. When attackers...

Apple fixes 2 zero-days exploited to breach macOS systems (CVE-2024-44309, CVE-2024-44308)
2024-11-20 10:48

Apple has released emergency security updates for macOS Sequoia that fix two zero-day vulnerabilities (CVE-2024-44309, CVE-2024-44308) that “may have been actively exploited on Intel-based Mac...

Decades-Old Security Vulnerabilities Found in Ubuntu's Needrestart Package
2024-11-20 09:16

Multiple decade-old security vulnerabilities have been disclosed in the needrestart package installed by default in Ubuntu Server (since version 21.04) that could allow a local attacker to gain...

Data is the new uranium – incredibly powerful and amazingly dangerous
2024-11-20 07:15

CISOs are quietly wishing they had less data, because the cost of management sometimes exceeds its value I recently got to play a 'fly on the wall' at a roundtable of chief information security...

Microsoft Launches Windows Resiliency Initiative to Boost Security and System Integrity
2024-11-20 07:00

Microsoft has announced a new Windows Resiliency Initiative as a way to improve security and reliability, as well as ensure that system integrity is not compromised. The idea, the tech giant said,...

China-Backed Hackers Leverage SIGTRAN, GSM Protocols to Infiltrate Telecom Networks
2024-11-20 06:58

A new China-linked cyber espionage group has been attributed as behind a series of targeted cyber attacks targeting telecommunications entities in South Asia and Africa since at least 2020 with...

Five backup lessons learned from the UnitedHealth ransomware attack
2024-11-20 06:00

The ransomware attack on UnitedHealth earlier this year is quickly becoming the healthcare industry’s version of Colonial Pipeline, prompting congressional testimony, lawmaker scrutiny and...