Security News

Microsoft fixes exploited zero-day (CVE-2024-49138)
2024-12-10 20:59

On December 2024 Patch Tuesday, Microsoft resolved 71 vulnerabilities in a variety of its products, including a zero-day (CVE-2024-49138) that’s been exploited by attackers in the wild to execute...

Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws
2024-12-10 18:33

Today is Microsoft's December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability. [...]

New Cleo zero-day RCE flaw exploited in data theft attacks
2024-12-10 15:09

Hackers are actively exploiting a zero-day vulnerability in Cleo managed file transfer software to breach corporate networks and conduct data theft attacks. [...]

Fully patched Cleo products under renewed 'zero-day-ish' mass attack
2024-12-10 13:32

Thousands of servers targeted while customers wait for patches Researchers at security shop Huntress are seeing mass exploitation of a vulnerability affecting three Cleo file management products,...

New Windows zero-day exposes NTLM credentials, gets unofficial patch
2024-12-06 16:32

A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer. [...]

Mitel MiCollab zero-day and PoC exploit unveiled
2024-12-05 14:24

A zero-day vulnerability in the Mitel MiCollab enterprise collaboration suite can be exploited to read files containing sensitive data, watchTowr researcher Sonny Macdonald has disclosed, and...

Mitel MiCollab zero-day flaw gets proof-of-concept exploit
2024-12-05 11:00

Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem. [...]

Japan warns of IO-Data zero-day router flaws exploited in attacks
2024-12-04 15:28

Japan's CERT is warning that hackers are exploiting zero-day vulnerabilities in I-O Data router devices to modify device settings, execute commands, or even turn off the firewall. [...]

New Windows Server 2012 zero-day gets free, unofficial patches
2024-11-29 17:00

Free unofficial security patches have been released through the 0patch platform to address a zero-day vulnerability introduced over two years ago in the Windows Mark of the Web (MotW) security...

Zero-day data security
2024-11-27 05:00

In this Help Net Security video, Carl Froggett, CIO of Deep Instinct, discusses the complexities of modern cloud architectures and why current defenses are falling short. He talks about the rise...