Security News > 2024 > December

What is Nudge Security and How Does it Work?
2024-12-11 11:02

In today’s highly distributed workplace, every employee has the ability to act as their own CIO, adopting new cloud and SaaS technologies whenever and wherever they need. While this has been a...

Researchers Uncover Espionage Tactics of China-Based APT Groups in Southeast Asia
2024-12-11 11:00

A suspected China-based threat actor has been linked to a series of cyber attacks targeting high-profile organizations in Southeast Asia since at least October 2023. The espionage campaign...

Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability
2024-12-11 07:16

Microsoft closed out its Patch Tuesday updates for 2024 with fixes for a total of 72 security flaws spanning its software portfolio, including one that it said has been exploited in the wild. Of...

U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls
2024-12-11 06:29

The U.S. government on Tuesday unsealed charges against a Chinese national for allegedly breaking into thousands of Sophos firewall devices globally in 2020. Guan Tianfeng (aka gbigmao and...

Open source malware up 200% since 2023
2024-12-11 05:30

Sonatype’s 2024 Open Source Malware Threat Report reveals that the number of malicious packages has surpassed 778,500 since tracking began in 2019. In 2024, researchers examined how threat actors...

US names Chinese national it alleges was behind 2020 attack on Sophos firewalls
2024-12-11 05:02

Also sanctions his employer – an outfit called Sichuan Silence linked to Ragnarok ransomware The US Departments of Treasury and Justice have named a Chinese business and one of its employees as...

Why crisis simulations fail and how to fix them
2024-12-11 05:00

In this Help Net Security interview, Allison Ritter, Head of Cyber Experiential Exercising at Cyberbit, shares her insights on the key differences between in-person and virtual cyber crisis...

Containers have 600+ vulnerabilities on average
2024-12-11 04:30

Containers are the fastest growing – and weakest cybersecurity link – in software supply chains, according to NetRise. Companies are struggling to get container security right. Issues from...

Ivanti Issues Critical Security Updates for CSA and Connect Secure Vulnerabilities
2024-12-11 02:59

Ivanti has released security updates to address multiple critical flaws in its Cloud Services Application (CSA) and Connect Secure products that could lead to privilege escalation and code...

Wyden proposes bill to secure US telecoms after Salt Typhoon hacks
2024-12-10 21:38

U.S. Senator Ron Wyden of Oregon announced a new bill to secure the networks of American telecommunications companies breached by Salt Typhoon Chinese state hackers earlier this year. [...]