Security News

How to add two-factor authentication to the Bitwarden desktop client
2020-07-22 19:40

If you've added two-factor authentication to Bitwarden, but are wondering why it's not working on the desktop client, fear not. I've written about how to enable two factor authentication with Bitwarden, but that only applied to the web interface.

How to add two-factor authentication to the Bitwarden desktop client
2020-07-22 19:39

If you've added two-factor authentication to Bitwarden, but are wondering why it's not working on the desktop client, fear not. Jack Wallen shows you how to unlock this particular magic.

Critical Apache Guacamole Flaws Put Remote Desktops at Risk of Hacking
2020-07-08 00:01

A new research has uncovered multiple critical reverse RDP vulnerabilities in Apache Guacamole, a popular remote desktop application used by system administrators to access and manage Windows and Linux machines remotely. The reported flaws could potentially let bad actors achieve full control over the Guacamole server, intercept, and control all other connected sessions.

Holy Guacamole! Researchers find Apache remote desktop software was silently pwnable for snooping on sessions
2020-07-02 22:05

The Apache Project's popular Guacamole open-source remote desktop software contained vulns allowing remote attackers to steal login creds and hijack targeted machines, researchers have said. The Apache Foundation has issued patches for Guacamole following Check Point's research, which resulted in two CVEs.

How to protect your remote desktop environment from brute force attacks
2020-06-30 16:38

A report published on Monday by ESET discusses how attackers take advantage of RDP and what organizations can do to combat them. Though Remote Desktop Protocol can be enough of a security risk on its own, organizations often compound the vulnerabilities by failing to properly secure RDP accounts and services.

Adaptiva and OKTiK Technology help enterprise customers modernize desktop management
2020-06-14 23:30

Adaptiva announced that it has partnered with UK-based IT consultancy OKTiK Technology to provide its solutions as part of OKTiK's automation platform. "OKTiK has established itself as a digital transformation specialist over the last several years, and our on-premises and cloud-enabled products are an outstanding fit for OKTiK's automation platform. Together, Adaptiva and OKTiK can drive a painless transition to modern management."

Docker Desktop danger discovered, patch now
2020-05-26 14:56

Docker has fixed a vulnerability that could have allowed an attacker to gain control of a Windows system using its service. The bug, discovered by Ceri Coburn, a researcher at security consultancy Pen Test Partners, exposed Docker for Windows to privilege elevation.

70 Percent of Mobile, Desktop Apps Contain Open-Source Bugs
2020-05-25 13:00

A full 70 percent of applications being used today have at least one security flaw stemming from the use of an open-source library. Most JavaScript applications contain hundreds of open-source libraries - some have more than 1,000 different libraries.

How to combat cyberattacks that exploit Microsoft's Remote Desktop Protocol
2020-05-07 14:36

In many cases, IT staff and other employees need to remotely connect to workstations and servers at the office, and for that they typically rely on the Microsoft Remote Desktop Protocol built into Windows. In a blog post published on Thursday, McAfee explains how cybercriminals are taking advantage of RDP access and what organizations can do to protect themselves.

Brute force attacks against remote desktop apps skyrocket during pandemic lockdown
2020-04-30 13:00

Kaspersky Labs is reporting a massive increase in brute force attacks against Microsoft's RDP protocol since the beginning of March, coinciding perfectly with coronavirus lockdowns and increased numbers of people working from home. Brute force attacks are decidedly blunt in their approach: Rather than try to sneak in a backdoor or bypass security, a brute force attack simply tries logging in to a system with a known username and all possible passwords.