Security News > 2024 > December

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785)
2024-12-04 11:16

Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution vulnerability affecting Progress WhatsUp Gold, a popular network monitoring solution...

How to Plan a New (and Improved!) Password Policy for Real-World Security Challenges
2024-12-04 10:30

Many organizations struggle with password policies that look strong on paper but fail in practice because they're too rigid to follow, too vague to enforce, or disconnected from real security...

Researchers Uncover Backdoor in Solana's Popular Web3.js npm Library
2024-12-04 09:48

Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users'...

Eurocops take down 'secure' criminal chat system known as Matrix
2024-12-04 08:32

They took the red pill French and Dutch police have taken down the Matrix chat app, which was designed by criminals for criminals to be a secure encrypted messaging tool.…

Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom Networks
2024-12-04 06:07

A joint advisory issued by Australia, Canada, New Zealand, and the U.S. has warned of a broad cyber espionage campaign undertaken by People's Republic of China (PRC)-affiliated threat actors...

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console
2024-12-04 05:34

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The...

SafeLine: Open-source web application firewall (WAF)
2024-12-04 05:30

SafeLine is an open-source and self-hosted Web Application Firewall (WAF) that protects websites from cyber attacks. “SafeLine WAF was created to protect web applications for small and...

Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access
2024-12-04 05:08

A critical security vulnerability has been disclosed in SailPoint's IdentityIQ identity and access management (IAM) software that allows unauthorized access to content stored within the...

Securing AI’s new frontier: Visibility, governance, and mitigating compliance risks
2024-12-04 05:00

In this Help Net Security interview, Niv Braun, CEO at Noma Security, discusses the difficulties security teams face due to the fragmented nature of AI processes, tools, and teams across the data...

Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses
2024-12-04 04:48

Cybersecurity researchers have called attention to a novel phishing campaign that leverages corrupted Microsoft Office documents and ZIP archives as a way to bypass email defenses. "The ongoing...