Category: HelpnetSecurity

Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)
04
Nov
2024

Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)

Synology has released fixes for an unauthenticated “zero-click” remote code execution flaw (CVE-2024-10443, aka RISK:STATION) affecting its popular DiskStation and…

Whispr: Open-source multi-vault secret injection tool
04
Nov
2024

Whispr: Open-source multi-vault secret injection tool

Whispr is an open-source CLI tool designed to securely inject secrets from secret vaults, such as AWS Secrets Manager and…

Hiring guide: Key skills for cybersecurity researchers
04
Nov
2024

Hiring guide: Key skills for cybersecurity researchers

In this Help Net Security interview, Rachel Barouch, an Organizational Coach for VCs and startups and a former VP HR…

Strong privacy laws boost confidence in sharing information with AI
04
Nov
2024

Strong privacy laws boost confidence in sharing information with AI

53% of consumers report being aware of their national privacy laws, a 17-percentage point increase compared to 2019, according to…

Week in review: Windows Themes spoofing bug "returns", employees phished via Microsoft Teams
03
Nov
2024

Week in review: Windows Themes spoofing bug “returns”, employees phished via Microsoft Teams

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patching problems: The “return” of…

How open-source MDM solutions simplify cross-platform device management
01
Nov
2024

How open-source MDM solutions simplify cross-platform device management

In this Help Net Security interview, Mike McNeil, CEO at Fleet, talks about the security risks posed by unmanaged mobile…

50% of financial orgs have high-severity security flaws in their apps
01
Nov
2024

50% of financial orgs have high-severity security flaws in their apps

Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in 76% of…

OpenPaX: Open-source kernel patch that mitigates memory safety errors
01
Nov
2024

OpenPaX: Open-source kernel patch that mitigates memory safety errors

OpenPaX is an open-source kernel patch that mitigates common memory safety errors, re-hardening systems against application-level memory safety attacks using…

Threat actors are stepping up their tactics to bypass email protections
01
Nov
2024

Threat actors are stepping up their tactics to bypass email protections

Although most organizations use emails with built-in security features that filter out suspicious messages, criminals always find a way to…

Infosec products of the month: October 2024
01
Nov
2024

Infosec products of the month: October 2024

Here’s a look at the most interesting products from the past month, featuring releases from: Action1, Balbix, BreachLock, Commvault, Dashlane,…

Sophos mounted counter-offensive operation to foil Chinese attackers
31
Oct
2024

Sophos mounted counter-offensive operation to foil Chinese attackers

Sophos conducted defensive and counter-offensive operation over the last five years with multiple interlinked nation-state adversaries based in China targeting…

Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups
31
Oct
2024

Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups

A supply chain compromise involving Lottie Player, a widely used web component for playing site and app animations, has made…