Security News

Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
2024-12-10 20:48

Twas the night before Christmas, and all through the house, patching was done with the click of a mouse Microsoft hasn't added too much coal to the stocking this Patch Tuesday, with just 72 fixes,...

Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws
2024-12-10 18:33

Today is Microsoft's December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability. [...]

Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged
2024-12-10 15:57

Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitation of a vulnerability affecting...

Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecast
2024-12-08 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) Veeam has...

New Windows zero-day exposes NTLM credentials, gets unofficial patch
2024-12-06 16:32

A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer. [...]

December 2024 Patch Tuesday forecast: The secure future initiative impact
2024-12-06 06:00

It seems like 2024 just started, but the final Patch Tuesday of the year is almost here! In retrospect, it has been a busy year with continued Windows 11 releases, the new Server 2025 release, and...

Microsoft says premature patch could make Windows Recall forget how to work
2024-12-04 14:03

Installed the final non-security preview update of 2024? Best not hop onto the Dev Channel Microsoft has pinned down why some eager Windows Insiders could not persuade the Recall preview to save...

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console
2024-12-04 05:34

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The...

Exploit released for critical WhatsUp Gold RCE flaw, patch now
2024-12-03 19:00

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon...

Over Two Dozen Flaws Identified in Advantech Industrial Wi-Fi Access Points – Patch ASAP
2024-11-28 16:57

Nearly two dozen security vulnerabilities have been disclosed in Advantech EKI industrial-grade wireless access point devices, some of which could be weaponized to bypass authentication and...