Security News

Read about the latest security news. News about computer security malware, and other threats to your computer.

Juniper: Customer routers infected with malware via default passwords

Several Juniper customers have had to deal with compromised routers because the devices were still using standard passwords, the network company said. Last Wednesday, several customers reported suspicious behavior on their Session Smart Routers (SSR). The devices were found to be infected with a variant of the Mirai malware and were used to carry out […]

Juniper: Customer routers infected with malware via default passwords Read More »

Judge holds NSO liable for spyware attack on WhatsApp users

An American judge has ruled that NSO Group is responsible for the spyware attack on fourteen hundred WhatsApp users in 2019. WhatsApp director Will Cathcart calls the ruling a ‘major victory’ for privacy. Citizen Lab security researcher and spyware expert John Scott-Railton calls it a big win for spyware victims and a big loss for

Judge holds NSO liable for spyware attack on WhatsApp users Read More »

Critical flaw in Sophos firewalls enables remote code execution

A critical vulnerability in Sophos’ firewalls allows remote code execution or could give an attacker SSH access. The company has released security updates to fix the problem. The first critical vulnerability (CVE-2024-12727) allows an unauthenticated attacker to perform SQL Injection, thereby gaining access to a firewall database. If the firewall has a specific configuration and

Critical flaw in Sophos firewalls enables remote code execution Read More »

Microsoft Halts Rollout of Update for Exchange Server Spoofing Vulnerability

Microsoft has announced that it is stopping for the time being the distribution of a security update focused on a spoofing vulnerability in Exchange Server. This is due to customer issues that lead set transport rules to malfunction which is detrimental to mail delivery. The vulnerability (CVE-2024-49040) allows an attacker to weaponize the Exchange servers

Microsoft Halts Rollout of Update for Exchange Server Spoofing Vulnerability Read More »

Apple Under Fire for Limiting Web App Distribution to Top Developers

Apple recently unveiled a policy allowing developers to distribute iPhone apps directly from their websites, a move that has met with backlash due to its restrictive eligibility criteria. Developers are only considered for this ‘web distribution’ route if they have an app listed in the Apple App Store with over a million downloads and have

Apple Under Fire for Limiting Web App Distribution to Top Developers Read More »

Ledger Users Lose Hundreds of Thousands in Crypto to Phishing Attack

Ledger, a provider of cryptocurrency wallets, has reported a significant loss for its users. Criminals distributed a malicious version of the Ledger Connect Kit through a phishing attack on a former employee. This kit is a crucial JavaScript library that links Ledger crypto wallets to third-party applications, also known as wallet-connected websites.

Ledger Users Lose Hundreds of Thousands in Crypto to Phishing Attack Read More »

Proton Mail Launches Desktop App for Enhanced Email Experience

Proton Mail, a well-known email service provider, has expanded its offerings by launching a desktop application for macOS and Windows users. They also announced plans to introduce a version for Linux users in the early part of next year. Proton’s CEO, Andy Yen, stated that although many users typically access email through a browser on

Proton Mail Launches Desktop App for Enhanced Email Experience Read More »