Category: HelpnetSecurity

Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)
27
Aug
2024

Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)

Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a…

Behind the scenes of Serious Cryptography
27
Aug
2024

Behind the scenes of Serious Cryptography

In this Help Net Security interview, Jean-Philippe Aumasson, discusses the writing and research process for Serious Cryptography, his latest book….

How to prioritize data privacy in core customer-facing systems
27
Aug
2024

How to prioritize data privacy in core customer-facing systems

Evolving global data privacy regulations are keeping marketers on their toes. In April 2024, the American Privacy Rights Act (APRA)…

Half of enterprises suffer breaches despite heavy security investments
27
Aug
2024

Half of enterprises suffer breaches despite heavy security investments

Data breaches have become an increasingly severe threat, with recent reports highlighting a surge in their frequency and cost. Understanding…

Lateral movement: Clearest sign of unfolding ransomware attack
27
Aug
2024

Lateral movement: Clearest sign of unfolding ransomware attack

44% of unfolding ransomware attacks were spotted during lateral movement, according to Barracuda Networks. 25% of incidents were detected when…

SonicWall patches critical flaw affecting its firewalls (CVE-2024-40766)
26
Aug
2024

SonicWall patches critical flaw affecting its firewalls (CVE-2024-40766)

SonicWall has patched a critical vulnerability (CVE-2024-40766) in its next-gen firewalls that could allow remote attackers unauthorized access to resources…

Two strategies to protect your business from the next large-scale tech failure
26
Aug
2024

Two strategies to protect your business from the next large-scale tech failure

The CrowdStrike event in July clearly demonstrated the risks of allowing a software vendor deep access to network infrastructure. It…

Nuclei: Open-source vulnerability scanner - Help Net Security
26
Aug
2024

Nuclei: Open-source vulnerability scanner – Help Net Security

Nuclei is a fast and customizable open-source vulnerability scanner powered by YAML-based templates. With its flexible templating system, Nuclei can…

Adversaries love bots, short-lived IP addresses, out-of-band domains
26
Aug
2024

Adversaries love bots, short-lived IP addresses, out-of-band domains

Fastly found 91% of cyberattacks – up from 69% in 2023 – targeted multiple customers using mass scanning techniques to…

GenAI buzz fading among senior executives
26
Aug
2024

GenAI buzz fading among senior executives

GenAI adoption has reached a critical phase, with 67% of respondents reporting their organization is increasing its investment in GenAI…

Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploited
25
Aug
2024

Week in review: PostgreSQL databases under attack, new Chrome zero-day actively exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: PostgreSQL databases under attackPoorly protected…

Another critical SolarWinds Web Help Desk bug fixed (CVE-2024-28987)
23
Aug
2024

Another critical SolarWinds Web Help Desk bug fixed (CVE-2024-28987)

A week after SolarWinds released a fix for a critical code-injection-to-RCE vulnerability (CVE-2024-28986) in Web Help Desk (WHD), another patch…