Security News

18-year-old security flaw in Firefox and Chrome exploited in attacks
2024-08-08 16:28

A vulnerability disclosed 18 years ago, dubbed "0.0.0.0 Day", allows malicious websites to bypass security in Google Chrome, Mozilla Firefox, and Apple Safari and interact with services on a local...

Automated Security Validation: One (Very Important) Part of a Complete CTEM Framework
2024-08-08 11:00

One of these categories is Automated Security Validation, which provides the attacker's perspective of exposures and equips security teams to continuously validate exposures, security measures, and remediation at scale. Traditional security methods can miss hidden assets or fail to account for vulnerabilities hiding in user accounts or security policies.

Unlock the Future of Cybersecurity: Exclusive, Next Era AI Insights and Cutting-Edge Training at SANS Network Security 2024
2024-08-08 07:23

In an era of relentless cybersecurity threats and rapid technological advancement, staying ahead of the curve is not just a necessity, but critical. SANS Institute, the premier global authority in cybersecurity training, is thrilled to announce Network Security 2024, a landmark event designed to empower cybersecurity professionals with groundbreaking skills, knowledge and insights.

SSHamble: Open-source security testing of SSH services
2024-08-08 06:24

This tool helps security teams validate SSH implementations by testing for uncommon but dangerous misconfigurations and software bugs. Activities intended to aid in responding to the incident led runZero's research team to discover weaknesses across SSH implementations and applications that impact critical network security devices and software.

Critical Security Flaw in WhatsUp Gold Under Active Attack - Patch Now
2024-08-08 05:13

A critical security flaw impacting Progress Software WhatsUp Gold is seeing active exploitation attempts, making it essential that users move quickly to apply the latest. The vulnerability in question is CVE-2024-4885, an unauthenticated remote code execution bug impacting versions of the network monitoring application released before 2023.1.3.

AI security 2024: Key insights for staying ahead of threats
2024-08-08 04:00

In this Help Net Security interview, Kojin Oshiba, co-founder of Robust Intelligence, discusses his journey from academic research to addressing AI security challenges in the industry. What motivated you to specialize in the security aspects of AI systems?

Download: CIS Critical Security Controls v8.1
2024-08-08 02:45

Version 8.1 of the CIS Critical Security Controls is an iterative update to version 8.0. Included new and expanded glossary definitions for reserved words used throughout the Controls Revised asset classes alongside new mappings to CIS Safeguards.

Faulty instructions in Alibaba's T-Head C910 RISC-V CPUs blow away all security
2024-08-07 17:00

Black Hat Computer security researchers at the CISPA Helmholtz Center for Information Security in Germany have found serious security flaws in some of Alibaba subsidiary T-Head Semiconductor's RISC-V processors. Thus the security issues here with the C910 lie with T-Head's own implementation of the ISA, specifically its non-standard implementation of the vector extension, and not the specs themselves nor other RISC-V chips.

Benefits of Adopting Zero-Trust Security
2024-08-07 16:00

A credit card or PayPal account is required for purchase. You will be billed the total shown above and you will receive a receipt via email once your payment is processed.

Sports venues must vet their vendors to maintain security
2024-08-07 04:30

The sports and entertainment sectors are distinct from other industries and continue to face numerous threats and challenges. In our highly connected world, the rise of digital twins and collaboration across various platforms is transforming the sports landscape into an interconnected business network.