Security News > 2024 > November

Malicious NPM Packages Target Roblox Users with Data-Stealing Malware
2024-11-08 11:53

A new campaign has targeted the npm package repository with malicious JavaScript libraries that are designed to infect Roblox users with open-source stealer malware such as Skuld and...

The vCISO Academy: Transforming MSPs and MSSPs into Cybersecurity Powerhouses
2024-11-08 11:53

We’ve all heard a million times: growing demand for robust cybersecurity in the face of rising cyber threats is undeniable. Globally small and medium-sized businesses (SMBs) are increasingly...

Critical Palo Alto Networks Expedition bug exploited (CVE-2024-5910)
2024-11-08 11:36

A vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, a firewall configuration migration tool, is being exploited by attackers in the wild, the Cybersecurity and Infrastructure...

Top Vulnerability Management Tools: Reviews & Comparisons 2024
2024-11-08 08:13

There are a great many vulnerability management tools available. But which is best? Here are our top picks for a variety of use cases.

New CRON#TRAP Malware Infects Windows by Hiding in Linux VM to Evade Antivirus
2024-11-08 07:15

Cybersecurity researchers have flagged a new malware campaign that infects Windows systems with a Linux virtual instance containing a backdoor capable of establishing remote access to the...

Apple’s 45-day certificate proposal: A call to action
2024-11-08 06:00

In a bold move, Apple has published a draft ballot for commentary to GitHub to shorten Transport Layer Security (TLS) certificates down from 398 days to just 45 days by 2027. The Apple proposal...

Am I Isolated: Open-source container security benchmark
2024-11-08 05:30

Am I Isolated is an open-source container security benchmark that probes users’ runtime environments and tests for container isolation. The Rust-based container runtime scanner runs as a...

CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability
2024-11-08 05:17

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical security flaw impacting Palo Alto Networks Expedition to its Known Exploited...

A closer look at the 2023-2030 Australian Cyber Security Strategy
2024-11-08 05:00

In this Help Net Security video, David Cottingham, CEO of Airlock Digital, discusses the 2023-2030 Australian Cyber Security Strategy and reviews joint and individual cybersecurity efforts,...

Why AI-enhanced threats and legal uncertainty are top of mind for risk executives
2024-11-08 04:30

AI-enhanced malicious attacks are the top emerging risk for enterprises in the third quarter of 2024, according to Gartner. Key emerging risks for enterprises It’s the third consecutive quarter...