Security News

Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecast
2024-12-08 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) Veeam has...

New Windows zero-day exposes NTLM credentials, gets unofficial patch
2024-12-06 16:32

A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer. [...]

December 2024 Patch Tuesday forecast: The secure future initiative impact
2024-12-06 06:00

It seems like 2024 just started, but the final Patch Tuesday of the year is almost here! In retrospect, it has been a busy year with continued Windows 11 releases, the new Server 2025 release, and...

Microsoft says premature patch could make Windows Recall forget how to work
2024-12-04 14:03

Installed the final non-security preview update of 2024? Best not hop onto the Dev Channel Microsoft has pinned down why some eager Windows Insiders could not persuade the Recall preview to save...

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console
2024-12-04 05:34

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The...

Exploit released for critical WhatsUp Gold RCE flaw, patch now
2024-12-03 19:00

A proof-of-concept (PoC) exploit for a critical-severity remote code execution flaw in Progress WhatsUp Gold has been published, making it critical to install the latest security updates as soon...

Over Two Dozen Flaws Identified in Advantech Industrial Wi-Fi Access Points – Patch ASAP
2024-11-28 16:57

Nearly two dozen security vulnerabilities have been disclosed in Advantech EKI industrial-grade wireless access point devices, some of which could be weaponized to bypass authentication and...

CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active Attacks
2024-11-26 05:03

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched critical security flaw impacting Array Networks AG and vxAG secure access gateways to its Known...

Apple Releases Urgent Updates to Patch Actively Exploited Zero-Day Vulnerabilities
2024-11-20 04:37

Apple has released security updates for iOS, iPadOS, macOS, visionOS, and its Safari web browser to address two zero-day flaws that have come under active exploitation in the wild. The flaws are...

Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
2024-11-18 22:29

If you didn't fix this a month ago, your to-do list probably needs a reshuffle Two VMware vCenter server bugs, including a critical heap-overflow vulnerability that leads to remote code execution...