Security News > 2024 > November

5 SaaS Misconfigurations Leading to Major Fu*%@ Ups
2024-11-01 10:20

With so many SaaS applications, a range of configuration options, API capabilities, endless integrations, and app-to-app connections, the SaaS risk possibilities are endless. Critical...

Microsoft Warns of Chinese Botnet Exploiting Router Flaws for Credential Theft
2024-11-01 09:48

Microsoft has revealed that a Chinese threat actor it tracks as Storm-0940 is leveraging a botnet called Quad7 to orchestrate highly evasive password spray attacks. The tech giant has given the...

Microsoft Delays Windows Copilot+ Recall Release Over Privacy Concerns
2024-11-01 08:48

Microsoft is further delaying the release of its controversial Recall feature for Windows Copilot+ PCs, stating it's taking the time to improve the experience. The development was first reported...

Hack Nintendo's alarm clock to show cat pics? Let's-a-go!
2024-11-01 08:32

How 'Gary' defeated Bowser broke into the interactive alarm clock A hacker who uses the handle GaryOderNichts has found a way to break into Nintendo's recently launched Alarmo clock, and run code...

50% of financial orgs have high-severity security flaws in their apps
2024-11-01 06:00

Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 76% of organizations in the financial services sector, with 50% of organizations carrying...

How open-source MDM solutions simplify cross-platform device management
2024-11-01 05:30

In this Help Net Security interview, Mike McNeil, CEO at Fleet, talks about the security risks posed by unmanaged mobile devices and how mobile device management (MDM) solutions help address them....

OpenPaX: Open-source kernel patch that mitigates memory safety errors
2024-11-01 05:00

OpenPaX is an open-source kernel patch that mitigates common memory safety errors, re-hardening systems against application-level memory safety attacks using a simple Linux kernel patch. It’s...

Threat actors are stepping up their tactics to bypass email protections
2024-11-01 04:30

Although most organizations use emails with built-in security features that filter out suspicious messages, criminals always find a way to bypass these systems. With the development of AI...

Infosec products of the month: October 2024
2024-11-01 04:00

Here’s a look at the most interesting products from the past month, featuring releases from: Action1, Balbix, BreachLock, Commvault, Dashlane, Data Theorem, Edgio, ExtraHop, Fastly, Frontegg,...

New Phishing Kit Xiū gǒu Targets Users Across Five Countries With 2,000 Fake Sites
2024-11-01 03:50

Cybersecurity researchers have disclosed a new phishing kit that has been put to use in campaigns targeting Australia, Japan, Spain, the U.K., and the U.S. since at least September 2024. Netcraft...