Category: HelpnetSecurity

Atlassian reveals critical Confluence RCE flaw, urges "immediate action" (CVE-2023-22527)
16
Jan
2024

Atlassian reveals critical Confluence RCE flaw, urges “immediate action” (CVE-2023-22527)

Atlassian has patched a critical vulnerability (CVE-2023-22527) in Confluence Data Center and Confluence Server that could lead to remote code…

Geopolitical tensions combined with technology will drive new security risks
16
Jan
2024

Geopolitical tensions combined with technology will drive new security risks

Misinformation and disinformation are biggest short-term risks, while extreme weather and critical change to Earth systems are greatest long-term concern,…

10 cybersecurity frameworks you need to know about
16
Jan
2024

10 cybersecurity frameworks you need to know about

As cyber threats grow more sophisticated, understanding and implementing robust cybersecurity frameworks is crucial for organizations of all sizes. This…

3 ways to combat rising OAuth SaaS attacks
16
Jan
2024

3 ways to combat rising OAuth SaaS attacks

OAuth attacks are on the rise. In December, the Microsoft Threat Intelligence team observed threat actors misusing OAuth apps to…

Tsurugi Linux: Tailoring user experience for digital forensics and OSINT investigations
16
Jan
2024

Tsurugi Linux: Tailoring user experience for digital forensics and OSINT investigations

Tsurugi Linux is a heavily customized open-source distribution focused on supporting DFIR investigations. The project focuses mainly on live forensics…

Windows SmartScreen bug exploited to deliver powerful info-stealer (CVE-2023-36025)
15
Jan
2024

Windows SmartScreen bug exploited to deliver powerful info-stealer (CVE-2023-36025)

A vulnerability (CVE-2023-36025) that Microsoft fixed in November 2023 continues to be exploited by malware peddlers: this time around, the…

Juniper fixes critical RCE in its SRX firewalls and EX switches (CVE-2024-21591)
15
Jan
2024

Juniper fixes critical RCE in its SRX firewalls and EX switches (CVE-2024-21591)

Juniper Networks has fixed a critical pre-authentication remote code execution (RCE) vulnerability (CVE-2024-21591) in Junos OS on SRX firewalls and…

Flipping the BEC funnel: Phishing in the age of GenAI
15
Jan
2024

Flipping the BEC funnel: Phishing in the age of GenAI

For years, phishing was just a numbers game: A malicious actor would slap together an extremely generic (and usually poorly-written)…

Adalanche: Open-source Active Directory ACL visualizer, explorer
15
Jan
2024

Adalanche: Open-source Active Directory ACL visualizer, explorer

Adalanche provides immediate insights into the permissions of users and groups within an Active Directory. It’s an effective open-source tool…

Key elements for a successful cyber risk management strategy
15
Jan
2024

Key elements for a successful cyber risk management strategy

In this Help Net Security interview, Yoav Nathaniel, CEO at Silk Security, discusses the evolution of cyber risk management strategies…

Week in review: GitLab account takeover flaw, attackers exploiting Ivanti Connect Secure zero-days
14
Jan
2024

Week in review: GitLab account takeover flaw, attackers exploiting Ivanti Connect Secure zero-days

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Social engineer reveals effective tricks…

Akira ransomware attackers are wiping NAS and tape backups
12
Jan
2024

Akira ransomware attackers are wiping NAS and tape backups

“The Akira ransomware malware, which was first detected in Finland in June 2023, has been particularly active at the end…