Week in review

Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engine

Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engine 2024-12-01 at 11:03 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Researchers reveal exploitable flaws in corporate VPN clients Researchers have discovered vulnerabilities in the update process of Palo […]

React to this headline:

Loading spinner

Week in review: Exploitable flaws in corporate VPN clients, malware loader created with gaming engine Read More »

Week in review: 0-days exploited in Palo Alto Networks firewalls, two unknown Linux backdoors identified

Week in review: 0-days exploited in Palo Alto Networks firewalls, two unknown Linux backdoors identified 2024-11-24 at 11:03 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 2,000 Palo Alto Networks devices compromised in latest attacks Attackers have compromised around 2,000 Palo Alto Networks firewalls

React to this headline:

Loading spinner

Week in review: 0-days exploited in Palo Alto Networks firewalls, two unknown Linux backdoors identified Read More »

Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked

Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked 2024-11-17 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes actively exploited zero-days (CVE-2024-43451, CVE-2024-49039) November 2024 Patch Tuesday is here, and Microsoft has dropped fixes for

React to this headline:

Loading spinner

Week in review: Microsoft patches actively exploited 0-days, Amazon and HSBC employee data leaked Read More »

Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability

Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability 2024-11-10 at 11:03 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443) Synology has released fixes for an unauthenticated “zero-click” remote

React to this headline:

Loading spinner

Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability Read More »

Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams

Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams 2024-11-03 at 11:03 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patching problems: The “return” of a Windows Themes spoofing vulnerability Despite two patching attempts, a security issue that may allow

React to this headline:

Loading spinner

Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams Read More »

Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE

Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE 2024-10-27 at 11:19 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Fortinet releases patches for publicly undisclosed critical FortiManager vulnerability In the last couple of days, Fortinet has released critical security

React to this headline:

Loading spinner

Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE Read More »

Week in review: 87k+ Fortinet devices still open to attack, red teaming tool used for EDR evasion

Week in review: 87k+ Fortinet devices still open to attack, red teaming tool used for EDR evasion 2024-10-20 at 11:10 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 87,000+ Fortinet devices still open to attack, are yours among them? (CVE-2024-23113) Last week, CISA added

React to this headline:

Loading spinner

Week in review: 87k+ Fortinet devices still open to attack, red teaming tool used for EDR evasion Read More »

Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools

Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools 2024-10-13 at 11:03 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) For October 2024 Patch Tuesday, Microsoft has

React to this headline:

Loading spinner

Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools Read More »

Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast

Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast 2024-10-06 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: October 2024 Patch Tuesday forecast: Recall can be recalled October arrived, and Microsoft started the month by announcing the release of Windows

React to this headline:

Loading spinner

Week in review: Critical Zimbra RCE vulnerability exploited, Patch Tuesday forecast Read More »

Week in review: Windows Server 2025 gets hotpatching option, PoC for SolarWinds WHD flaw released

Week in review: Windows Server 2025 gets hotpatching option, PoC for SolarWinds WHD flaw released 2024-09-29 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows Server 2025 gets hotpatching option, without reboots Organizations that plan to upgrade to Windows Server 2025 once

React to this headline:

Loading spinner

Week in review: Windows Server 2025 gets hotpatching option, PoC for SolarWinds WHD flaw released Read More »

Week in review: Critical VMware vCenter Server bugs fixed, Apple releases iOS 18

Week in review: Critical VMware vCenter Server bugs fixed, Apple releases iOS 18 2024-09-22 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Critical VMware vCenter Server bugs fixed (CVE-2024-38812) Broadcom has released fixes for two vulnerabilities affecting VMware vCenter Server that can

React to this headline:

Loading spinner

Week in review: Critical VMware vCenter Server bugs fixed, Apple releases iOS 18 Read More »

Week in review: Veeam Backup & Replication RCE could soon be exploited, Microsoft fixes 4 0-days

Week in review: Veeam Backup & Replication RCE could soon be exploited, Microsoft fixes 4 0-days 2024-09-15 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam Backup & Replication RCE flaw may soon be leveraged by ransomware gangs (CVE-2024-40711) CVE-2024-40711, a critical

React to this headline:

Loading spinner

Week in review: Veeam Backup & Replication RCE could soon be exploited, Microsoft fixes 4 0-days Read More »

Week in review: Vulnerability allows Yubico security keys cloning, Patch Tuesday forecast

Week in review: Vulnerability allows Yubico security keys cloning, Patch Tuesday forecast 2024-09-08 at 11:02 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Vulnerability allows Yubico security keys to be cloned Researchers have unearthed a cryptographic vulnerability in popular Yubico (FIDO) hardware security keys

React to this headline:

Loading spinner

Week in review: Vulnerability allows Yubico security keys cloning, Patch Tuesday forecast Read More »

Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE

Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE 2024-09-01 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SonicWall patches critical flaw affecting its firewalls (CVE-2024-40766) SonicWall has patched a critical vulnerability (CVE-2024-40766) in its next-gen

React to this headline:

Loading spinner

Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE Read More »

Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploited

Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploited 2024-08-25 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: PostgreSQL databases under attack Poorly protected PostgreSQL databases running on Linux machines are being compromised by cryptojacking attackers. Vulnerabilities in Microsoft

React to this headline:

Loading spinner

Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploited Read More »

Week in review: MS Office flaw may leak NTLM hashes, malicious Chrome, Edge browser extensions

Week in review: MS Office flaw may leak NTLM hashes, malicious Chrome, Edge browser extensions 2024-08-18 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched MS Office flaw may leak NTLM hashes to attackers (CVE-2024-38200) A new MS Office zero-day vulnerability (CVE-2024-38200)

React to this headline:

Loading spinner

Week in review: MS Office flaw may leak NTLM hashes, malicious Chrome, Edge browser extensions Read More »

Week in review: Tips for starting your cybersecurity career, Patch Tuesday forecast

Week in review: Tips for starting your cybersecurity career, Patch Tuesday forecast 2024-08-11 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: August 2024 Patch Tuesday forecast: Looking for a calm August release August 2024 July ended up being more ‘exciting’ than many

React to this headline:

Loading spinner

Week in review: Tips for starting your cybersecurity career, Patch Tuesday forecast Read More »

Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android users

Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android users 2024-08-04 at 10:31 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Why a strong patch management strategy is essential for reducing business risk In this Help Net Security interview, Eran Livne,

React to this headline:

Loading spinner

Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android users Read More »

Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROI

Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROI 2024-07-28 at 11:02 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft releases tool to speed up recovery of systems borked by CrowdStrike update By now, most people are aware of – or

React to this headline:

Loading spinner

Week in review: CrowdStrike-triggered outage insights, recovery, and measuring cybersecurity ROI Read More »

Week in review: CrowdStrike update causes widespread IT outage, critical Splunk Enterprise flaw

Week in review: CrowdStrike update causes widespread IT outage, critical Splunk Enterprise flaw 2024-07-21 at 11:01 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Faulty CrowdStrike update takes out Windows machines worldwide Thousands and possibly millions of Windows computers and servers worldwide have been

React to this headline:

Loading spinner

Week in review: CrowdStrike update causes widespread IT outage, critical Splunk Enterprise flaw Read More »

Scroll to Top