Security News > 2024 > December

70% of open-source components are poorly or no longer maintained
2024-12-04 04:30

The geographic distribution of open-source contributions introduces geopolitical risks that organizations must urgently consider, especially with rising nation-state attacks, according to Lineaje....

65% of office workers bypass cybersecurity to boost productivity
2024-12-04 04:00

High-risk access exists throughout the workplace, in almost every job role, proving that the time has come for organizations to re-think the way they protect their workforce, according to...

FTC scolds two data brokers for allegedly selling your location to the meter
2024-12-04 02:29

'Where we go is who we are' totally isn't a creepy ad slogan at all The FTC has reached a settlement with two data brokerages over allegations they harvested precise location data that shows when...

Perfect 10 directory traversal vuln hits SailPoint's IAM solution
2024-12-03 23:45

20-year-old info disclosure class bug still pervades security software It's time to rev up those patch engines after SailPoint disclosed a perfect 10/10 severity vulnerability in its identity and...

Vodka maker Stoli files for bankruptcy in US after ransomware attack
2024-12-03 22:00

Stoli Group's U.S. companies have filed for bankruptcy following an August ransomware attack and Russian authorities seizing the company's remaining distilleries in the country. [...]

Cloudflare’s developer domains increasingly abused by threat actors
2024-12-03 21:00

Cloudflare's 'pages.dev' and 'workers.dev' domains, used for deploying web pages and facilitating serverless computing, are being increasingly abused by cybercriminals for phishing and other...

Major energy contractor reports 'limited' access to IT after ransomware locks files
2024-12-03 20:00

ENGlobal customers include the Pentagon as well as major oil and gas producers American energy contractor ENGlobal disclosed that access to its IT systems remains limited following a ransomware...

US shares tips to block hackers behind recent telecom breaches
2024-12-03 19:49

​CISA released guidance today to help network defenders harden their systems against attacks coordinated by the Salt Typhoon Chinese threat group that breached multiple major global...

Exploit released for critical WhatsUp Gold RCE flaw, patch now
2024-12-03 19:00

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon...

Veeam warns of critical RCE bug in Service Provider Console
2024-12-03 18:07

​Veeam released security updates today to address two Service Provider Console (VSPC) vulnerabilities, including a critical remote code execution (RCE) discovered during internal testing. [...]