Category: HelpnetSecurity

Week in review: 48k Fortinet firewalls open to attack, attackers "vishing" orgs via Microsoft Teams
26
Jan
2025

Week in review: 48k Fortinet firewalls open to attack, attackers “vishing” orgs via Microsoft Teams

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 48,000+ internet-facing Fortinet firewalls still…

Nearly half of CISOs now report to CEOs, showing their rising influence
24
Jan
2025

Nearly half of CISOs now report to CEOs, showing their rising influence

The CISO’s rise to the C-suite comes with more engagement with the boardroom, an audience with the CEO, and the…

GUI frontends for GnuPG, the free implementation of the OpenPGP standard
24
Jan
2025

GUI frontends for GnuPG, the free implementation of the OpenPGP standard

GnuPG is a free and comprehensive implementation of the OpenPGP standard. It enables encryption and signing of data and communications,…

Deepfakes force a new era in fraud detection, identity verification
24
Jan
2025

Deepfakes force a new era in fraud detection, identity verification

The rise in identity fraud over the past two years has significantly impacted all industries, especially finance, banking, fintech, and…

New infosec products of the week: January 24, 2025
24
Jan
2025

New infosec products of the week: January 24, 2025

Here’s a look at the most interesting products from the past week, featuring releases from Bitsight, DataDome, DigitalOcean, Lookout, and…

Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw
23
Jan
2025

Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw

Cisco has released patches for a critical privilege escalation vulnerability in Meeting Management (CVE-2025-20156) and a heap-based buffer overflow flaw…

DigitalOcean Per-Bucket Access Keys boosts object storage security
23
Jan
2025

DigitalOcean Per-Bucket Access Keys boosts object storage security

DigitalOcean announced Per-Bucket Access Keys for DigitalOcean Spaces, its S3-compatible object storage service. This feature provides customers with identity-based, bucket-level…

SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006)
23
Jan
2025

SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006)

A critical zero-day vulnerability (CVE-2025-23006) affecting SonicWall Secure Mobile Access (SMA) 1000 Series appliances is being exploited by attackers. “We…

Bitsight Instant Insights accelerates vendor risk assessments
23
Jan
2025

Bitsight Instant Insights accelerates vendor risk assessments

Bitsight unveiled Instant Insights, a new offering from the Bitsight IQ suite of AI-based capabilities. The new feature leverages generative…

Defense strategies to counter escalating hybrid attacks
23
Jan
2025

Defense strategies to counter escalating hybrid attacks

In this Help Net Security interview, Tomer Shloman, Sr. Security Researcher at Trellix, talks about attack attribution, outlines solutions for…

Web Cache Vulnerability Scanner: Open-source tool for detecting web cache poisoning
23
Jan
2025

Web Cache Vulnerability Scanner: Open-source tool for detecting web cache poisoning

The Web Cache Vulnerability Scanner (WCVS) is an open-source command-line tool for detecting web cache poisoning and deception. The scanner,…

CISOs are juggling security, responsibility, and burnout
23
Jan
2025

CISOs are juggling security, responsibility, and burnout

This article gathers excerpts from multiple reports, presenting statistics and insights that may be valuable for CISOs, helping them with…