Sat.Nov 16, 2024

article thumbnail

Weekly Update 426

Troy Hunt

I have absolutely no problem at all talking about the code I've screwed up. Perhaps that's partly because after 3 decades of writing software (and doing some meaningful stuff along the way), I'm not particularly concerned about showing my weaknesses. And this week, I screwed up a bunch of stuff; database queries that weren't resilient to SQL database scale changes, partially completed breach notifications I didn't notice until it was too late to easily fix, and some quer

Software 218
article thumbnail

Palo Alto Networks confirmed active exploitation of recently disclosed zero-day

Security Affairs

Palo Alto Networks confirmed active exploitation of a zero-day in its PAN-OS firewall and released new indicators of compromise (IoCs). Last week, Palo Alto Networks warned customers to limit access to their next-gen firewall management interface due to a potential remote code execution vulnerability (CVSSv4.0 Base Score: 9.3) in PAN-OS. The cybersecurity company had no further details on the vulnerability and was not aware of the active exploitation of the flaw.

Firewall 133
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

PAN-OS Firewall Vulnerability Under Active Exploitation – IoCs Released

The Hacker News

Palo Alto Networks has released new indicators of compromise (IoCs) a day after the network security vendor confirmed that a new zero-day vulnerability impacting its PAN-OS firewall management interface has been actively exploited in the wild.

Firewall 143
article thumbnail

CVE-2024-8856: WP Time Capsule Plugin Vulnerability Exposes 20,000+ Sites to TakeOver

Penetration Testing

A high-severity vulnerability in WP Time Capsule, a popular WordPress backup plugin, has left over 20,000 websites vulnerable to complete takeover. Discovered by security researcher Rein Daelman, the flaw (CVE-2024-8856)... The post CVE-2024-8856: WP Time Capsule Plugin Vulnerability Exposes 20,000+ Sites to TakeOver appeared first on Cybersecurity News.

Backups 109
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

NSO Group used WhatsApp exploits even after Meta-owned company sued it

Security Affairs

Court filing revealed that NSO Group used WhatsApp exploits after the instant messaging firm sued the surveillance company. NSO Group developed malware that relied on WhatsApp exploits to infect target individuals even after the Meta-owned instant messaging company sued the surveillance firm. “As a threshold matter, NSO admits that it developed and sold the spyware described in the Complaint, and that NSO’s spyware—specifically its zero-click installation vector called “Eden,” which was pa

Spyware 125
article thumbnail

Bitfinex Hacker Gets 5 Years for $10 Billion Bitcoin Heist

WIRED Threat Level

Plus: An “AI granny” is wasting scammers’ time, a lawsuit goes after spyware-maker NSO Group’s executives, and North Korea–linked hackers take a crack at macOS malware.

Spyware 120

More Trending

article thumbnail

CVE-2024-45784: Apache Airflow Vulnerability Exposes Sensitive Data in Logs

Penetration Testing

A vulnerability in the popular workflow management platform Apache Airflow could inadvertently expose sensitive configuration data, potentially compromising system security. The flaw, tracked as CVE-2024-45784 and assigned a CVSS score... The post CVE-2024-45784: Apache Airflow Vulnerability Exposes Sensitive Data in Logs appeared first on Cybersecurity News.

article thumbnail

This ultra-portable power station gives you AC power on the move (and now get $60 in this Black Friday deal)

Zero Day

Bigger than a power bank, smaller than a power station, this is the perfect choice for those wanting AC power when out and about.

Banking 98
article thumbnail

Two-Step Phishing Technique Leveraging Microsoft Visio Files Exposed by Researchers

Penetration Testing

Perception Point’s latest findings have uncovered an advanced two-step phishing technique exploiting Microsoft Visio files (.vsdx) and SharePoint to launch highly deceptive credential theft campaigns. Traditionally used for professional diagrams... The post Two-Step Phishing Technique Leveraging Microsoft Visio Files Exposed by Researchers appeared first on Cybersecurity News.

article thumbnail

One of the best noise-canceling earbuds I've tested isn't made by Sony or Apple

Zero Day

The latest Bose QuietComfort Earbuds boast powerful noise cancellation, a 30-hour battery life, and remarkable audio output.

97
article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Cyber Crisis Management Plan: Shield for Brand Reputation

Security Boulevard

Despite advances in security technology, cybersecurity attacks and data breaches are increasingly common as attackers keep discovering new vulnerabilities and infiltration methods. Organizations now understand that a cyberattack or data breach is often inevitable—it’s typically a question of when, not if. The positive side is that cybersecurity crisis management plans can help businesses prepare effectively […] The post Cyber Crisis Management Plan: Shield for Brand Reputation appeared first on

article thumbnail

This ultra-thin power bank is a must-have travel gadget (grab it cheap in this Black Friday deal)

Zero Day

The Auskang 5,000mAh power bank is only about as thick as a few credit cards, but it has enough power to reliably charge your smartphone or other USB-C device.

Banking 97
article thumbnail

Hacking Kia: Remotely Controlling Cars with Just a License Plate

Hacker's King

As vehicles become smarter and more connected, the risk of cyberattacks increases. A concerning vulnerability has been discovered in Kia cars, where hackers could potentially gain remote control of a vehicle using just its license plate number. This issue highlights a growing security threat in the automotive industry as more cars incorporate telematics, keyless entry, and remote-start features.

Hacking 52
article thumbnail

My favorite DeWalt cordless drill and impact driver set is 46% off for Black Friday

Zero Day

Save $80 on this brilliant DeWalt power tool kit -- the perfect for DIY beginners and tradespeople.

97
article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!

article thumbnail

DEF CON 32 – Sudos And Sudon’ts: Peering Inside Sudo For Windows

Security Boulevard

Authors/Presenters: Michael Torres Our sincere appreciation to DEF CON , and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center ; and via the organizations YouTube channel. Permalink The post DEF CON 32 – Sudos And Sudon’ts: Peering Inside Sudo For Windows appeared first on Security Boulevard.

article thumbnail

The best Lenovo laptops of 2024: Expert tested and reviewed

Zero Day

Lenovo is well known for making innovative, reliable devices. But with an extensive catalog of products, it can be hard to find the right one. Here are the best Lenovo laptops we've tested.

85
article thumbnail

A botnet exploits e GeoVision zero-day to compromise EoL devices

Security Affairs

A botnet employed in DDoS or cryptomining attacks is exploiting a zero-day in end-of-life GeoVision devices to grow up. Researchers at the Shadowserver Foundation observed a botnet exploiting a zero-day in GeoVision EOL (end-of-Life) devices to compromise devices in the wild. The GeoVision zero-day, tracked as CVE-2024-11120 (CVSS 9.8), is a pre-auth command injection vulnerability that was discovered by Shadowserver Foundation and verified with the help of TWCERT.

DDOS 136
article thumbnail

The best mini PCs of 2024: Expert recommended

Zero Day

We tested and researched the best mini PCs from Intel, Apple, and more that pack strong computing features into a small package.

85
article thumbnail

The Cloud Development Environment Adoption Report

Cloud Development Environments (CDEs) are changing how software teams work by moving development to the cloud. Our Cloud Development Environment Adoption Report gathers insights from 223 developers and business leaders, uncovering key trends in CDE adoption. With 66% of large organizations already using CDEs, these platforms are quickly becoming essential to modern development practices.

article thumbnail

Grab Microsoft Visual Studio Pro for $28 - the lowest price yet

Zero Day

Code faster and work smarter with a Microsoft Visual Studio Professional 2022 license, now on sale for 94% off.

81
article thumbnail

One of the most versatile power stations I've tested is now 50% off for Black Friday

Zero Day

The Bluetti AC180 delivers up to 1800W of output, with 11 ports for ultimate flexibility.

75
article thumbnail

Give your iPhone 16 thermal camera superpowers with this gadget (get 23% off in this Black Friday deal)

Zero Day

Apple won't add a thermal camera to the iPhone, but now you can!

75
article thumbnail

Join BJ's Wholesale Club for just $20 ahead of the holidays

Zero Day

Get an annual BJ's Wholesale Club membership for 63% off right now to save on groceries, gas, household items, and more.

75
article thumbnail

Bringing the Cybersecurity Imperative Into Focus

Tech leaders today are facing shrinking budgets and investment concerns. This whitepaper provides insights from over 1,000 tech leaders on how to stay secure and attract top cybersecurity talent, all while doing more with less. Download today to learn more!

article thumbnail

My everyday Anker power bank has a genius feature that makes it irreplaceable and it's up to 25% off for Black Friday

Zero Day

The fast USB-C charging is great, but the cable's layout makes the Anker Nano Power Bank a mainstay in my everyday carry. And it's currently on sale for $32 on Amazon.

Banking 75
article thumbnail

Buy a Sam's Club membership for just $25 right now - here's how

Zero Day

This deal gets you an annual Sam's Club membership for 50% off, so you can save even more ahead of the holidays.

75
article thumbnail

This 5-in-1 charging station replaced several desk accessories for me (and it's on sale)

Zero Day

The Baseus Nomos 5-in-1 charging station is a desktop powerhouse that is perfect for use at home or on the go. Just look at it!

75
article thumbnail

I highly recommend this 12-in-1 electric screwdriver, and it's on sale at Amazon for Black Friday

Zero Day

This top-rated electric screwdriver has served me well for over a year. And you can buy the Hoto Rechargeable Electric Screwdriver for $42 on Amazon.

75
article thumbnail

Introducing CDEs to Your Enterprise

Explore how enterprises can enhance developer productivity and onboarding by adopting self-hosted Cloud Development Environments (CDEs). This whitepaper highlights the simplicity and flexibility of cloud-based development over traditional setups, demonstrating how large teams can leverage economies of scale to boost efficiency and developer satisfaction.

article thumbnail

The Jackery Explorer 1000 V2 is one of the best entry-level portable power stations (and it's now half price for Black Friday)

Zero Day

This Jackery portable power station is a fantastic entry-level model for camping and RV trips, or for emergencies and power outages.

75
article thumbnail

You can still buy a 50-inch Hisense 4K TV for $138 at Walmart - here's how the deal works

Zero Day

The Hisense 50-inch Class R6 Series 4K TV is a top seller at Walmart for good reason: it's currently selling for nearly 50% off.

74
article thumbnail

This Bluetti power station is ideal for road-tripping - and now it's 37% off for Black Friday

Zero Day

The Bluetti AC70 is portable and delivers enough power for your basic energy-intensive devices.

74
article thumbnail

This power station has an irreplaceable emergency feature (and now get $350 off for Black Friday)

Zero Day

The Vtoman FlashSpeed 1500 is a portable power station with tons of power and thoughtful design. Its fast-charging feature is one of the best I've seen.

52
article thumbnail

IT Leadership Agrees AI is Here, but Now What?

IT leaders are experiencing rapid evolution in AI amid sustained investment uncertainty. As AI evolves, enhanced cybersecurity and hiring challenges grow. This whitepaper offers real strategies to manage risks and position your organization for success.