Critical Vulnerabilities Expose mbNET.mini, Helmholz Industrial Routers to Attacks

Critical and high-severity vulnerabilities that can lead to full device compromise have been found in mbNET.mini and Helmholz industrial routers. 

The post Critical Vulnerabilities Expose mbNET.mini, Helmholz Industrial Routers to Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

NordVPN Review (2024): Is NordVPN Worth the Cost?

Is NordVPN worth it? How much does it cost and is it safe to use? Read our NordVPN review to learn about pricing, features, security, and more.

Security | TechRepublic – ​Read More

BlackCat Ransomware Successor Cicada3301 Emerges

The Cicada3301 ransomware shows multiple similarities with BlackCat and is believed to mark the reemergence of the threat.

The post BlackCat Ransomware Successor Cicada3301 Emerges appeared first on SecurityWeek.

SecurityWeek – ​Read More

Latrodectus Malware Increasingly Used by Cybercriminals

Latrodectus malware has been increasingly used by cybercriminals, with recent campaigns targeting the financial, automotive and healthcare sectors. 

The post Latrodectus Malware Increasingly Used by Cybercriminals appeared first on SecurityWeek.

SecurityWeek – ​Read More

Palo Alto Networks Adds New Capabilities to OT Security Solution

Palo Alto Networks has added new remote access, virtual patching and firewall capabilities to its OT Security solution.

The post Palo Alto Networks Adds New Capabilities to OT Security Solution appeared first on SecurityWeek.

SecurityWeek – ​Read More

Pharma Giant Johnson & Johnson Discloses Data Breach

Johnson & Johnson has disclosed a data breach impacting the personal information of thousands of people.

The post Pharma Giant Johnson & Johnson Discloses Data Breach appeared first on SecurityWeek.

SecurityWeek – ​Read More

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution.
The vulnerability, tracked as CVE-2024-38812 (CVSS score: 9.8), concerns a case of heap-overflow vulnerability in the implementation of the DCE/RPC protocol.
“A malicious actor with network access to vCenter Server may trigger this vulnerability by

The Hacker News – ​Read More

CISA Adds ScienceLogic SL1 Vulnerability to Exploited Catalog After Active Zero-Day Attack

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting ScienceLogic SL1 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation as a zero-day.
The vulnerability in question, tracked as CVE-2024-9537 (CVSS v4 score: 9.3), refers to a bug involving an unspecified third-party component that could

The Hacker News – ​Read More

Russia-Linked Hackers Attack Japan’s Govt, Ports

Russia-linked hackers have taken aim at Japan, following its ramping up of military exercises with regional allies and the increase of its defense budget.

darkreading – ​Read More

Unmanaged Cloud Credentials Pose Risk to Half of Orgs

These types of “long-lived” credentials pose a risk for users across all major cloud service providers, and must meet their very timely ends, researchers say.

darkreading – ​Read More