Category: HelpnetSecurity

Put guardrails around AI use to protect your org, but be open to changes
04
Dec
2023

Put guardrails around AI use to protect your org, but be open to changes

Artificial intelligence (AI) is a topic that’s currently on everyone’s minds. While in some industries there is concern it could…

Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widens
03
Dec
2023

Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widens

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Vulnerability disclosure: Legal risks and…

Qlik Sense flaws exploited in Cactus ransomware campaign
01
Dec
2023

Qlik Sense flaws exploited in Cactus ransomware campaign

Attackers are exploiting three critical vulnerabilities in internet-facing Qlik Sense instances to deliver Cactus ransomware to target organizations, Arctic Wolf…

Critical Zyxel NAS vulnerabilities patched, update quickly!
01
Dec
2023

Critical Zyxel NAS vulnerabilities patched, update quickly!

Zyxel has patched six vulnerabilities affecting its network attached storage (NAS) devices, including several (OS) command injection flaws that can…

Apple patches two zero-days used to target iOS users (CVE-2023-42916 CVE-2023-42917)
01
Dec
2023

Apple patches two zero-days used to target iOS users (CVE-2023-42916 CVE-2023-42917)

With the latest round of security updates, Apple has fixed two zero-day WebKit vulnerabilities (CVE-2023-42916, CVE-2023-42917) that “may have been…

New infosec products of the week: December 1, 2023
01
Dec
2023

New infosec products of the week: December 1, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Amazon, Datadog, Entrust, Fortanix, GitHub,…

Bridging the gap between cloud vs on-premise security
01
Dec
2023

Bridging the gap between cloud vs on-premise security

With the proliferation of SaaS applications, remote work and shadow IT, organizations feel obliged to embrace cloud-based cybersecurity. And rightly…

Unhappy network professionals juggling more with less
01
Dec
2023

Unhappy network professionals juggling more with less

97% of US-based CIOs expressed serious concerns about at least one cybersecurity threat, according to Opengear. Failing to have the…

CISA urges water facilities to secure their Unitronics PLCs
30
Nov
2023

CISA urges water facilities to secure their Unitronics PLCs

News that Iran-affiliated attackers have taken over a programmable logic controller (PLC) at a water system facility in Pennsylvania has…

Nitrokey releases NetHSM, a fully open-source hardware security module
30
Nov
2023

Nitrokey releases NetHSM, a fully open-source hardware security module

German company Nitrokey has released NetHSM 1.0, an open-source hardware security module (HSM). Nitrokey NetHSM 1.0 features The module can…

Mosint: Open-source automated email OSINT tool
30
Nov
2023

Mosint: Open-source automated email OSINT tool

Mosint is an automated email OSINT tool written in Go designed to facilitate quick and efficient investigations of target emails….

Bridging the risk exposure gap with strategies for internal auditors
30
Nov
2023

Bridging the risk exposure gap with strategies for internal auditors

In this Help Net Security interview, Richard Chambers, Senior Internal Audit Advisor at AuditBoard, discusses the transformational role of the…